<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr3646+slackware+forth%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 13:18:16 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 13:18:16 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr3646+slackware+forth%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=hpr3646+slackware+forth%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Linus Torvalds on AI, Junk Patches, Humans, and Godzilla]]></title>
<description><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hope...]]></description>
<link>https://tsecurity.de/de/3693456/linux-tipps/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693456/linux-tipps/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</guid>
<pubDate>Sat, 25 Jul 2026 10:12:40 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hopefully it creates more productivity than it takes away," but "we certainly saw more junk being generated by LLMs than we saw useful code up until the like early this year.... it can actually be a huge drain on resources when it takes humans a lot of effort to figure out that, hey, this machine-generated report was not true." Even now, he said, "most of the good ones require more than just the LLM," because "we've had to push back quite a bit... if you find a bug with an LLM, it's not enough to just ask the LLM to make a bug report and then throw it over the fence to us. We want to see a suggested patch; we want to see the human who ran the LLM act as a kind of back-and-forth." 

Torvalds described many AI-generated patches as "mindless band-aid kind of patches... they may fix the immediate problem, but the kind of bug remains, and it just is waiting in the hallway to hit you in another place." For his own toy projects, he uses LLMs as prototypers: "I use them as a way to prototype things... quite often the code is not usable in that form, but it's a great way to try something out," while insisting that for kernel-level fixes, "LLMs, in my experience, have not been at that level yet." 

Torvalds acknowledged that some AI-found issues have been "absolutely, stunningly, I mean, interesting in a painful kind of way," especially security problems that "show up in the technology press two days later." Despite the embarrassment, he said, "I'm very much not a shoot-the-messenger kind of person. I think we're much better off with LLMs finding bugs, even when they are embarrassing, and they are things that we should probably have found two decades ago."

 

Torvalds also said he's using AI "for my own toy projects... Every time I travel to some new place, and this is the first time I've been to India, I send the kids pictures of where I am, and for some strange reason, Godzilla seems to follow me around and gets added to those pictures." 

ZDNet notes that Torvalds concluded, "There are many useful and less useful uses for AI," and "I think Godzilla is a great place to stop." 

Thanks to Slashdot reader joshuark for sharing the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds+on+AI%2C+Junk+Patches%2C+Humans%2C+and+Godzilla%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2Flinus-torvalds-on-ai-junk-patches-humans-and-godzilla%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/12/2053201/linus-torvalds-on-ai-junk-patches-humans-and-godzilla?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hefty stable kernel updates for Friday]]></title>
<description><![CDATA[Greg Kroah-Hartman has announced the release of the 7.1.5, 6.18.40, 6.12.97, 6.6.145, 6.1.178, 5.15.212, and 5.10.261 stable Linux kernels.

This batch of kernels includes a hefty set of updates, possibly the
the largest ever. 7.1.5-rc1,
for example, included more than 2,000 patches, 6.18.40-rc1
...]]></description>
<link>https://tsecurity.de/de/3692156/linux-tipps/hefty-stable-kernel-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692156/linux-tipps/hefty-stable-kernel-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 19:13:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Greg Kroah-Hartman has announced the release of the <a href="https://lwn.net/Articles/1084922/">7.1.5</a>, <a href="https://lwn.net/Articles/1084923/">6.18.40</a>, <a href="https://lwn.net/Articles/1084924/">6.12.97</a>, <a href="https://lwn.net/Articles/1084925/">6.6.145</a>, <a href="https://lwn.net/Articles/1084926/">6.1.178</a>, <a href="https://lwn.net/Articles/1084927/">5.15.212</a>, and <a href="https://lwn.net/Articles/1084928/">5.10.261</a> stable Linux kernels.</p>

<p>This batch of kernels includes a hefty set of updates, possibly the
the largest ever. <a href="https://lwn.net/ml/all/20260721152552.646164743@linuxfoundation.org/">7.1.5-rc1</a>,
for example, included more than 2,000 patches, <a href="https://lwn.net/ml/all/20260721152514.750365251@linuxfoundation.org/">6.18.40-rc1</a>
included 1,611 patches, and so forth. Users are advised to upgrade.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Automating Microsoft 365: Using WorkIQ with Microsoft Scout]]></title>
<description><![CDATA[Managing work across Microsoft 365 often means jumping between Teams, Outlook, SharePoint, OneDrive, and your calendar just to finish a single task. Those small interruptions quickly add up during a busy workday. Microsoft Scout WorkIQ integration helps reduce that back-and-forth by allowing Scou...]]></description>
<link>https://tsecurity.de/de/3691982/windows-tipps/automating-microsoft-365-using-workiq-with-microsoft-scout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691982/windows-tipps/automating-microsoft-365-using-workiq-with-microsoft-scout/</guid>
<pubDate>Fri, 24 Jul 2026 18:06:39 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="700" height="393" src="https://www.thewindowsclub.com/wp-content/uploads/2026/07/Connect-Scout-to-Your-Microsoft-365-Apps.png" class="attachment-full size-full wp-post-image" alt="Automating Microsoft 365: Using WorkIQ with Microsoft Scout" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/07/Connect-Scout-to-Your-Microsoft-365-Apps.png 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/07/Connect-Scout-to-Your-Microsoft-365-Apps-500x281.png 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/07/Connect-Scout-to-Your-Microsoft-365-Apps-300x168.png 300w" sizes="(max-width: 700px) 100vw, 700px">Managing work across Microsoft 365 often means jumping between Teams, Outlook, SharePoint, OneDrive, and your calendar just to finish a single task. Those small interruptions quickly add up during a busy workday. Microsoft Scout WorkIQ integration helps reduce that back-and-forth by allowing Scout to pull together information from your Microsoft 365 apps and handle repetitive […]</p>
<p>This article <a href="https://www.thewindowsclub.com/automating-microsoft-365-using-workiq-with-microsoft-scout">Automating Microsoft 365: Using WorkIQ with Microsoft Scout</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (glibc, java-21-openjdk, kernel, and libpq), Debian (imagemagick, spice-vdagent, and webkit2gtk), Fedora (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), Mageia (apache, cifs-utils, dnsmasq, lrzip, and s...]]></description>
<link>https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691648/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Jul 2026 15:13:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (glibc, java-21-openjdk, kernel, and libpq), <b>Debian</b> (imagemagick, spice-vdagent, and webkit2gtk), <b>Fedora</b> (cryptlib, dotnet8.0, dotnet9.0, firefox, python-black, python-lsp-black, and python-pytokens), <b>Mageia</b> (apache, cifs-utils, dnsmasq, lrzip, and socat), <b>Oracle</b> (.NET 10.0, .NET 9.0, 389-ds-base, cups, edk2, fence-agents, firefox, freeipmi, freerdp, git-lfs, glib2, gnutls, golang, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, libinput, libvirt, libxml2, memcached, nginx, openexr, perl-DBI, perl-XML-LibXML, php, php8.4, plexus-utils, postgresql16, python3.12, python3.14, sssd, tomcat, tomcat9, unbound, vim, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Red Hat</b> (container-tools:rhel8, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, host-metering, java-1.8.0-openjdk, java-11-openjdk with Extended Lifecycle Support, java-17-openjdk, java-21-openjdk, oci-seccomp-bpf-hook, rhc, rhc-worker-playbook, skopeo, xorg-x11-server, xorg-x11-server-Xwayland, and yggdrasil), <b>Slackware</b> (mozilla-thunderbird), <b>SUSE</b> (afterburn, alloy, apache-sshd, apache2, avahi, chromium, clamav, curl, dhcpcd, dnsmasq, docker-compose, ffmpeg-7, firefox-esr, gawk, glibc, gnutls, go1.26-openssl, google-osconfig-agent, gpg2, haproxy, ImageMagick, imagemagick, jline3, jq, kernel, libgcrypt, libgnt, meson, pidgin, nmap, nodejs24, pacemaker, patch, perl-HTML-Parser, perl-libwww-perl, perl-List-SomeUtils-XS, python-aiohttp, python-WebOb, qemu, rust-keylime, SVT-AV1, libyuv0, libaom3, trivy, ucode-intel, and wireshark), and <b>Ubuntu</b> (libhttp-date-perl, libxpm, linux-azure, linux-azure-fde, pam, and rsyslog).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3690696/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690696/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Fri, 24 Jul 2026 06:31:17 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI sued after ChatGPT used religious faith to convince a man to not talk to a doctor]]></title>
<description><![CDATA[ChatGPT leveraged faith to convince a man with a cardiac issue stay home instead of seeking medical help. Now, facing years of recovery and profound financial damage, the man is suing OpenAI over the ordeal.ChatGPT isn't a medical professional. Credit: OpenAIIn a lawsuit filed in San Francisco Su...]]></description>
<link>https://tsecurity.de/de/3689834/ios-mac-os/openai-sued-after-chatgpt-used-religious-faith-to-convince-a-man-to-not-talk-to-a-doctor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689834/ios-mac-os/openai-sued-after-chatgpt-used-religious-faith-to-convince-a-man-to-not-talk-to-a-doctor/</guid>
<pubDate>Thu, 23 Jul 2026 19:28:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ChatGPT leveraged faith to convince a man with a cardiac issue stay home instead of seeking medical help. Now, facing years of recovery and profound financial damage, the man is suing OpenAI over the ordeal.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68343-144049-Untitled-5-xl.jpg" alt="Light-themed chat interface with sidebar menu; a cursor hovers over Health. Main panel shows a heart icon and health-related options on a soft pink gradient background." height="738"><br><span>ChatGPT isn't a medical professional. Credit: OpenAI</span></div><br>In a lawsuit filed in San Francisco Superior Court, Florida pastor Scott Winters argues that ChatGPT used his faith against him. After asking the chatbot about his symptoms, he was told that they were likely "another minor piece of the long story" and that "God did not design your body to endlessly fail."<br><br>After going back and forth with <a href="https://appleinsider.com/articles/25/12/02/be-wary-of-the-rumored-connection-between-chatgpt-and-apple-health">ChatGPT's Health feature</a> for six weeks, Winters finally spoke to a real medical professional. He was then diagnosed with a dangerous blockage of arteries in both of his lungs.<br><br><br> <a href="https://appleinsider.com/articles/26/07/23/openai-sued-after-chatgpt-used-religious-faith-to-convince-a-man-to-not-talk-to-a-doctor?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245041?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Going back to Linux full-time after many years]]></title>
<description><![CDATA[I've been using PCs since 1998. Around 2000 I started with PCLOS. Because they had the friendliest user forum for noobs. Also back then PCLOS was like the Mint of today. The easiest distro for noobs. I had to buy an external modem to get dialup. And TexStar the creator personally held my hand to ...]]></description>
<link>https://tsecurity.de/de/3687873/linux-tipps/going-back-to-linux-full-time-after-many-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687873/linux-tipps/going-back-to-linux-full-time-after-many-years/</guid>
<pubDate>Thu, 23 Jul 2026 04:21:44 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've been using PCs since 1998. Around 2000 I started with PCLOS. Because they had the friendliest user forum for noobs. Also back then PCLOS was like the Mint of today. The easiest distro for noobs. I had to buy an external modem to get dialup. And TexStar the creator personally held my hand to get the modem configured.</p> <p>Back then laptops were outrageously expensive. So I built a desktop. I had removable drawers for the hard drives that I used to clone back &amp; forth. Because I would destroy my W98se installs. I created a PCLOS live CD. I removed both HDD. Booted to PCLOS. I started laughing like crazy because I was using my PC without a HDD! I was gobstruck.</p> <p>Fast forward to around the present day. I can't remember what year I started using Linux full-time. I'm old &amp; my memory is terrible. I think I lasted around a year then went back to Windows. And the reason I went backwards was so stupid it's shocking. It was because a fast Windows surfing session for me was 1hr-1.5hrs. Where as in Linux it was only 20minutes. I went back to Windows because Linux was too EASY!</p> <p>Anyways W7 was rock solid for me. After a Vista nightmare I went back to W7. Stayed on W7 till 2023. Then jumped to W11. Since W7 I think I borked 2-3 W installs. That was until W11 25H2. What a POS.</p> <p>In the last 5 weeks three W11 installs were borked. I blame M$ &amp; 25H2. I know when a bork is my fault. These were not.</p> <p>I got a new used ThinkPad X1 Carbon Gen 4 16GB 6th Gen i7 6600 2016. Installed Mint Cinnamon for a few days. It was clunky &amp; froze a couple on the ancient hardware.</p> <p>I then installed Debian LXQT 13.6. Wow Debian is much easier than 15 years ago. LOL. Everything is snappy except Zoom. My hardware won't run the Zoom app. But Zoom worked ok in a browser. I disabled a few unnecessary auto start services now Zoom &amp; everything runs well.</p> <p>I have one other primary laptop to install Linux.</p> <p>I hope I don't go backwards to Windows.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ReporterWise7445"> /u/ReporterWise7445 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v3wmq9/going_back_to_linux_fulltime_after_many_years/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v3wmq9/going_back_to_linux_fulltime_after_many_years/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), Debian (kernel, nss, roundcube, rtpengine, and xz-utils), Fedora ...]]></description>
<link>https://tsecurity.de/de/3686772/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686772/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 22 Jul 2026 17:09:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (389-ds-base, c-ares, dovecot, freerdp, glib2, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, hplip, kernel, kernel-rt, nodejs:22, perl-XML-LibXML, webkit2gtk3, and yggdrasil), <b>Debian</b> (kernel, nss, roundcube, rtpengine, and xz-utils), <b>Fedora</b> (btrbk, kernel, mupdf, nuclei, perl-Crypt-OpenSSL-X509, rust-fern, rust-ifcfg-devname, rust-routinator, rust-rpki, and rust-syslog), <b>Mageia</b> (tig), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, acl, dovecot, glib2, httpd, libtiff, pacemaker, perl-IO-Compress, plexus-utils, python3, and webkit2gtk3), <b>Slackware</b> (libssh and mozilla-firefox), <b>SUSE</b> (acl, avahi, aws-nitro-enclaves-cli, beets, chromium, firefox, go1.25-openssl, ImageMagick, iscsiuio, kernel, kubevirt1.8-container-disk, libgit2-1_9, libkrun, libsoup-3_0-0, nghttp2, opam, php7, python-aiohttp, python-tornado6, and vim), and <b>Ubuntu</b> (accountsservice, CUPS, imagemagick, jbig2dec, openssh, and snapd).]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Modern SOCs Need Multi-Layered Detections]]></title>
<description><![CDATA[The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Gl...]]></description>
<link>https://tsecurity.de/de/3686210/it-security-nachrichten/why-modern-socs-need-multi-layered-detections/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686210/it-security-nachrichten/why-modern-socs-need-multi-layered-detections/</guid>
<pubDate>Wed, 22 Jul 2026 13:59:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-modern-socs-need-multi-layered-detections/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-modern-socs-need-multi-layered-detections/">Why Modern SOCs Need Multi-Layered Detections</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Modern SOCs Need Multi-Layered Detections]]></title>
<description><![CDATA[The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.

The CrowdStrike G...]]></description>
<link>https://tsecurity.de/de/3686147/it-security-nachrichten/why-modern-socs-need-multi-layered-detections/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686147/it-security-nachrichten/why-modern-socs-need-multi-layered-detections/</guid>
<pubDate>Wed, 22 Jul 2026 13:39:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.

The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-firefox (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3685243/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685243/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</guid>
<pubDate>Wed, 22 Jul 2026 06:30:48 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in libssh (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3685239/unix-server/security-mehrere-probleme-in-libssh-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685239/unix-server/security-mehrere-probleme-in-libssh-slackware/</guid>
<pubDate>Wed, 22 Jul 2026 06:30:41 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 153 Released]]></title>
<description><![CDATA[Longtime Slashdot reader williamyf writes: FireFox 153 was released today. The most important user-facing changes are improvements to PDF handling (you can now merge PDFs and add images to them), and HDR video playback (on Windows, provided HDR is active systemwide). Other under-the-hood changes ...]]></description>
<link>https://tsecurity.de/de/3684870/it-security-nachrichten/firefox-153-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684870/it-security-nachrichten/firefox-153-released/</guid>
<pubDate>Tue, 21 Jul 2026 23:13:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Longtime Slashdot reader williamyf writes: FireFox 153 was released today. The most important user-facing changes are improvements to PDF handling (you can now merge PDFs and add images to them), and HDR video playback (on Windows, provided HDR is active systemwide). Other under-the-hood changes include browser-wide containers and QWAC support. The full list is in the change notes.

 But the most important feature is that this version is an ESR and, therefore, defines the ESR feature set for the next year. Why is being an ESR so important, you ask?

 1.) ESR, rather than "normal" (a.k.a. Rapid Release), Firefox is the out-of-the-box browser for many important distros, including Debian, RHEL, Kali, Tails, SUSE Linux Enterprise, Slackware, and others.

 2.) Many organizations, large and small, standardize on Firefox ESR as their default browser, regardless of the default browser included with their OS.

 3.) Firefox ESR is the basis for many downstream projects, such as Waterfox and KaiOS. All these projects will inherit, for a year, whatever ESR brings to the table today.

 4.) Many ISVs and SaaS providers, if they certify their wares for Firefox at all, certify for the ESR version only.

 Please note that ESR 153 will not be offered as an automatic update until two months from now (ESR 140 will still be supported). If you want it now, you will need to download and install it manually.

 Also of note, ESR 115 will be supported until March 2027. If you use an unsupported version of macOS or Windows (like Windows 7 or 8.x), this is the version to get. However, even Mozilla cautions against running a supported browser on an unsupported OS: "Note that Microsoft ended official support for Windows 7, 8, and 8.1 in January 2023. Unsupported operating systems receive no security updates and have known vulnerabilities. Without official support from Microsoft, maintaining Firefox for outdated operating systems becomes costly for Mozilla and risky for users."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Firefox+153+Released%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F21%2F2022247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F21%2F2022247%2Ffirefox-153-released%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/21/2022247/firefox-153-released?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Martin Thompson: Why in Building Protocols, Like Code, Starting Over Is Dumb]]></title>
<description><![CDATA[Today, the IETF held the CURRENT BoF,
where the goal was to develop a new protocol.
That protocol would be substantially like TLS,
reusing its record layer and basic structure,
but it would drop in MLS for key exchange.
This is somewhere between a pretty bad idea
and a horrible idea.
The wholesal...]]></description>
<link>https://tsecurity.de/de/3684807/tools/martin-thompson-why-in-building-protocols-like-code-starting-over-is-dumb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684807/tools/martin-thompson-why-in-building-protocols-like-code-starting-over-is-dumb/</guid>
<pubDate>Tue, 21 Jul 2026 22:58:58 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Today, the IETF held the CURRENT BoF,
where the goal was to develop a new protocol.
That protocol would be substantially like TLS,
reusing its record layer and basic structure,
but it would drop in MLS for key exchange.</p>
<p>This is somewhere between a pretty bad idea
and a horrible idea.</p>
<p>The wholesale replacement of a huge chunk of protocol architectures
is a hallmark of a lot of the AI-generated protocol proposals
that have flooded the IETF.
A small blemish is identified,
then the fix is a whole new protocol,
or a major piece of surgery.
No regard for the wisdom of Chesterton’s Fence
or the accumulated knowledge and usefulness embodied in what exists.</p>
<p>Experienced engineers know that rewriting a code module
is not something you do lightly.
There’s lots of literature out there about why this is a bad idea generally,
and some emerging discussion about how AI might just change that.</p>
<p>The reasons not to rewrite a software component still largely apply
to a protocol component.
The reasons that AI might make it easier to do that safely, less so.
Protocols are different.</p>
<h3>Wholesale Change Will Miss Use Cases</h3>
<p>Just like with a code change,
a protocol component that changes will miss use cases
that people really care about.</p>
<p>The usual concerns with code apply:</p>
<ul>
<li>The existing features you know about and can test for
can be handled.</li>
<li>The existing problems you know and care about can be fixed.</li>
<li>You inevitably introduce brand-new problems.</li>
<li>The existing features you don’t know about
get lost.</li>
</ul>
<p>Unlike code changes, you probably don’t have a test case
for existing features that you didn’t know about.
We found that with HTTP/2,
where a number of use cases got lost in the process
of “upgrading” HTTP.</p>
<p>In HTTP/1.1,
performing client authentication
in the middle of request was possible.
Losing that capability in HTTP/2
affected few enough people
that it was not badly damaging for the ecosystem.
It still sucked.</p>
<p>A lot of work was done to try to find these issues,
but we did not learn about these problems until fairly late in the process.</p>
<p>Proposing a protocol change means asking a whole lot of other people,
many of whom are not invested in your goals,
to do that work.</p>
<p>Changing a protocol by replacing a chunk of it,
no matter how much care is taken,
either asks the entire ecosystem to change with you.</p>
<p>That means asking everyone to move with you.
If they don’t, you are not changing the protocol,
you are forking it.</p>
<h3>Forking A Protocol Destroys Interoperability</h3>
<p>The real value of having a protocol like TLS
is that a great many things can all talk to each other.</p>
<p>Forking a protocol –
and sometimes profiling a protocol, a subject for another post –
destroys that.
You now have two ways to achieve the same goal,
and a choice to join one of two clubs.
You can join both, but that means constantly translating back and forth,
something that can only get harder over time
as protocol semantics diverge.</p>
<p>And yes, in case you were asking,
this applies to the entirety of the IETF IoT sphere,
which has parallel HTTP, TLS, and other analogues.
Ostensibly, these address the needs of highly constrained hardware,
but the cost is an ecosystem cut off from the mainstream.</p>
<h3>But Fixing Protocols Is Hard</h3>
<p>Yes, existing protocols come with baggage
or technical debt.
Maybe they aren’t perfectly optimized for your use.</p>
<p>The value that an existing protocol carries
is that you are sharing the burden of its maintenance
with a great many more people.
Fixing it, maybe by adding extensions to support your needs,
comes with opportunities to improve the protocol
even beyond that immediate need.
Every change is a chance to work off some of the accumulated cruft.</p>
<p>Major refreshes, like the TLS 1.3 reworking,
cleared out a ton of cruft in the process.
You get to benefit from the work that others do to improve that protocol too.</p>
<h3>Do the Work</h3>
<p>It is hard to be a responsible steward for the fabric of the Internet.
We do it because it is worthwhile.
Ignoring the lessons of the past is not helpful.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in netatalk (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3676345/it-security-nachrichten/mehrere-probleme-in-netatalk-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676345/it-security-nachrichten/mehrere-probleme-in-netatalk-slackware/</guid>
<pubDate>Fri, 17 Jul 2026 16:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), Fedora (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), Ora...]]></description>
<link>https://tsecurity.de/de/3676176/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676176/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 17 Jul 2026 15:26:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (cifs-utils, container-tools:rhel8, libreoffice, nodejs:24, perl-XML-LibXML, and python3.12), <b>Fedora</b> (ansible-collection-ansible-posix, firefox, freerdp, ImageMagick, mingw-glib2, perl-DBI, perl-HTTP-Date, rust-cargo-rpmstatus, and rust-opendal), <b>Oracle</b> (cifs-utils, gegl, gimp, git-lfs, go-toolset:ol8, hplip, kernel, libreoffice, maven:3.9, perl-XML-LibXML, python3, python3.12, python3.9, and uek-kernel), <b>Red Hat</b> (kernel, kernel-rt, and podman), <b>Slackware</b> (netatalk), <b>SUSE</b> (agama, aws-nitro-enclaves-binaryblobs-upstream, gimp, gpsd, grafana, hostapd, ImageMagick, jackson-databind, kernel, libssh2_org, nm-configurator, opennlp, perl-Mojolicious, python-Pillow, python-python-engineio, python-python-socketio, and tomcat11), and <b>Ubuntu</b> (ntfs-3g, python-authlib, ruby2.3, tar, and ubuntu-advantage-tools).]]></content:encoded>
</item>
<item>
<title><![CDATA[Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking]]></title>
<description><![CDATA[TL;DRThis one started from setting up the YouTube app on my PS5. The device authorization grant (RFC 8628) it uses, the flow TVs, consoles, and CLIs rely on when they don’t have a browser of their own, turned out to hide two stacked bugs in Google’s implementation.Two bugs stack together. First, ...]]></description>
<link>https://tsecurity.de/de/3675347/hacking/confused-deputy-google-idp-universal-account-takeover-via-device-code-flow-hijacking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675347/hacking/confused-deputy-google-idp-universal-account-takeover-via-device-code-flow-hijacking/</guid>
<pubDate>Fri, 17 Jul 2026 09:23:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>TL;DR</h3><p>This one started from setting up the YouTube app on my PS5. The device authorization grant (RFC 8628) it uses, the flow TVs, consoles, and CLIs rely on when they don’t have a browser of their own, turned out to hide two stacked bugs in Google’s implementation.</p><p>Two bugs stack together. First, the session that anchors a device-code sign-in is fully transferable: copy the sign-in URL from one browser to another and the second browser’s login satisfies the first device’s poll. Second, the authorization server never binds client_id and scope to the device_code server-side, so both can be swapped in the URL after the fact. Chain the two together with the prompt=none parameter and any link, opened by a victim who has ever used "Sign in with Google" anywhere, silently hands over an access token for an arbitrary Google-registered client, no click, no consent screen, no 2FA prompt, almost no trace in the victim's account activity.</p><p>Reported to Google’s VRP on Feb 25, 2026, initially closed twice as “won’t fix”: social engineering, reopened after a one-click PoC, fixed by Mar 28, 2026, and rewarded $13,337. Details on that back-and-forth are in the <a href="https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html#9-disclosure-timeline">disclosure timeline</a> below.</p><h3>1. Intro</h3><p>Most of the well-known attacks on OAuth go after the client or the resource server: a malicious app, an open redirect, a signing-algorithm mix-up. They leave the authorization server itself alone, because it’s the one party in the protocol that’s supposed to be unshakeable, the thing every other trust decision is anchored to. This is a story about going after that assumption directly, in the one corner of OAuth that’s explicitly designed to let the login happen on a completely different screen: the device authorization grant.</p><p>It started as a mundane afternoon setting up a TV app on a game console, and it ended with a way to silently take over accounts on virtually any site that offers “Sign in with Google.” Getting from one to the other took two separate findings stacked on top of each other, a rejected report, and a fix to the fix. What follows is that story, roughly in the order it actually happened, blockers included.</p><h3>2. The Device Authorization Grant</h3><p>Most OAuth flows assume the device asking for access has a browser sitting right there to redirect through. RFC 8628 exists for the case where it doesn’t: a smart TV, a games console, a headless CLI. The shape is different from the usual redirect dance:</p><ol><li>The device calls the authorization server directly (POST /device/code) and gets back a device_code (secret, stays on the device) and a user_code (short, shown on screen).</li><li>The device displays the user_code and tells the user to go to a URL, google.com/device in Google's case, on <em>any other</em> browser.</li><li>The user opens that URL on their phone or laptop, types the code, signs in, and consents.</li><li>Meanwhile the device has been polling POST /token with its device_code. Once the user finishes step 3, the next poll returns an access token.</li></ol><p>The whole point of the design is that the device and the browser doing the authenticating can be, and usually are, two completely different pieces of hardware. That’s also exactly what makes this flow interesting to attack: the protocol <em>already</em> expects the login to happen somewhere else. The only thing holding the model together is that the “somewhere else” has to be a browser <em>the legitimate device owner</em> is sitting at.</p><p>That’s the assumption. The rest of this write-up is what happened when I went looking for the place where Google’s implementation stops enforcing it.</p><h3>3. Setting Up YouTube TV on a PS5</h3><p>I was setting up the YouTube app on my PS5, ordinary first-run setup. The console has no keyboard and no way to type a password comfortably with a controller, so it does the sensible thing: it shows a short user_code on screen and tells you to go sign in on your phone instead. I typed the code into google.com/device, signed into Google, approved the consent screen, and a few seconds later the PS5 was logged in.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*qmQssZXzIn_0kJeh.png"><figcaption><em>The YouTube TV “Add your Google Account” screen: a QR code and a short user_code, with instructions to finish sign-in on a phone.</em></figcaption></figure><p>Nothing about that felt unusual as a user, but the flow itself was intriguing: a screen with no keyboard asking me to authenticate on a completely separate device, and coming back logged in seconds later. That disconnect between where I typed my password and where the session actually landed is what made me want to look at it more closely. Behind the scenes, that’s:</p><ul><li>POST https://oauth2.googleapis.com/device/code → device_code + user_code.</li><li>The PS5 polling POST https://oauth2.googleapis.com/token with that device_code.</li><li>My phone’s browser walking through https://accounts.google.com/o/oauth2/v2/auth?… to finalize consent once I typed the code and signed in.</li><li>The PS5’s next poll returning an access token.</li></ul><p>Standard, boring, RFC-compliant. The interesting part is what that accounts.google.com/o/oauth2/v2/auth URL is actually carrying, and what happens if you don't treat it as disposable. That question is exactly what kicked off everything that follows.</p><h3>4. The Transferable Session</h3><p>The obvious question with any flow where “the state lives in a URL” is: what happens if you just move the URL? If the entire sign-in step for a device_code can be handed to someone else, then whoever finishes that sign-in step ends up logged into <em>my</em> device, not theirs.</p><p>RFC 8628 §5.4 anticipates exactly this and tells implementers not to let it happen: the whole security model of the flow depends on the user completing verification on a device they’re <em>not</em> about to lose control of.</p><p>I started a fresh device flow on the PS5, walked through google.com/device on a laptop, and at the consent screen copied the resulting URL into a second browser. That failed outright: no session for the second browser to pick up.</p><p>But the device-code page asks for an email address <em>before</em> showing consent. Entering one forwards the browser to a different endpoint entirely: a <em>challenge</em> page at accounts.google.com/v3/signin/challenge/…, carrying a new parameter, TL=APouJz6T…. Sending <em>that</em> URL to a second browser worked. The second browser prompted a completely normal Google sign-in. Seconds after logging in, that account showed up on the PS5.</p><p>TL is an encrypted blob carrying the session state, practically certain to be the device_code, or something that resolves to it, given that it's the only thing left in the URL that could anchor the poll back to a specific device.</p><p><strong>Vulnerability #1: the device-code sign-in session is transferable via URL.</strong> RFC 8628 explicitly says it shouldn’t be. Send the link, get the account.</p><p>That’s a real account takeover, but a narrow one. YouTube TV’s scopes are capped by design, and that cap is the wall I hit next.</p><h3>5. Breaking the Scope Fence</h3><p>A YouTube TV account takeover is real, but Google fences the device flow to a short, deliberately low-risk scope allowlist. Per <a href="https://developers.google.com/identity/protocols/oauth2/limited-input-device">Google’s own docs</a>: <em>“This OAuth 2.0 flow supports a limited set of scopes.”</em> The complete list:</p><ul><li>openid, email, profile</li><li>youtube, youtube.readonly</li><li>drive.appdata, drive.file (app-scoped Drive only, not full Drive)</li></ul><p>No Gmail, no full Drive, no cloud-platform, no compute. The access token I got only worked against a YouTube TV–internal API: enough to like a video or subscribe to a channel. Not exactly a headline bug.</p><p>So I looked again at the transferable challenge URL:</p><pre>accounts.google.com/v3/signin/challenge/…<br>  ?TL=APouJz6T…              &lt;- encrypted session state<br>  &amp;response_type=none<br>  &amp;client_id=861556708454-…   &lt;- YouTube TV<br>  &amp;scope=…                    &lt;- YouTube scopes</pre><p>Two things stand out. response_type=none means this isn't a normal code/token redirect: there's nothing coming back to a callback at all. And there is <strong>no </strong><strong>redirect_uri anywhere in the URL</strong>. The entire boundary that OAuth normally relies on to pin where a grant goes is simply absent from this endpoint, because the grant never gets delivered through the browser; it gets delivered out-of-band, over the device's /token poll.</p><p>The only thing anchoring the session is TL. client_id and scope are just along for the ride in the query string. So: keep TL, swap client_id for a different application, and see which client the authorization server ends up authenticating.</p><p>I scripted the device-code issuance, took the resulting URL, and changed client_id from YouTube TV to Google's own <strong>Cloud SDK</strong> client, with scope changed to cloud-platform, compute, appengine.admin. The consent screen that came back said <strong>Google Cloud SDK</strong>, listing the elevated scopes. Approving it, my polling script, still polling with the <em>original</em> YouTube TV device_code, got back a token on its next call. Inspecting it: cloud-platform, compute, appengine.admin. Not YouTube.</p><p><strong>Vulnerability #2: the server never validates that the </strong><strong>client_id and </strong><strong>scope in the authorization URL match what the </strong><strong>device_code was actually issued for.</strong></p><p>Combined with vulnerability #1, the authorization server ends up issuing tokens under one client’s identity (Google Cloud SDK, or any other Google-registered client, first- or third-party) for a session that started under a completely different one (YouTube TV). redirect_uri isn't just weakly validated here: it's not present at all, because the grant never travels through a redirect in this flow to begin with.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*4UwF2sE4BZuwRTMM9aJo9w.gif"><figcaption><em>PoC: device-code hijack escalated from YouTube TV to Google Cloud SDK scopes</em></figcaption></figure><p>The escalation chain worked end to end, at least on paper. Only one step was left: telling Google about it, and finding out whether they’d agree it was a bug at all.</p><h3>6. From Consent Screen to One Click</h3><p>I filed this as a report. It came back rejected the next day, citing user interaction: the victim “consented.” Fair, in a narrow sense: the consent screen is genuinely rendered by Google, the click is a genuine click. But the <em>thing being consented to</em> was shaped entirely by parameter substitution in a link I built, and from the victim’s side there is nothing to notice that’s different from any other Google sign-in. Still, “user interaction” was the stated bar, so the next step was removing it.</p><p>OAuth has a prompt parameter for exactly the case of skipping the consent screen: set to none, it tells the authorization server not to show any UI if the user has already granted the requested scopes to that client before. It's meant to be narrow, restricted to low-risk scopes like openid, email, profile, and gated on prior consent.</p><p>In practice it isn’t narrow at all. “Sign in with Google” is everywhere, and most people have already granted openid email profile to dozens, sometimes hundreds, of apps over the years without ever thinking about it again.</p><p>Take the weaponized device-code URL, drop in Facebook’s client_id (any site using "Sign in with Google" works the same way), set scope=openid email profile, add prompt=none. The victim opens the link, and that's the only action required: no consent screen, no button to press. The browser silently completes the flow in the background, the polling script receives an id_token for that third-party application, and that token replays cleanly against the app's own "Sign in with Google" endpoint.</p><p><strong>One link. Opening it is the only interaction required. Account takeover on virtually any application that uses Sign in with Google.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/1*hHiWXmNkC5aWkKKDsmLD9w.gif"><figcaption><em>PoC: prompt=none one-click bypass against a third-party client</em></figcaption></figure><p>The technical bypass was solid. What I didn’t know yet was whether any of it would actually be visible, to the victim or to Google’s own monitoring, if it were used for real.</p><h3>7. Why the Victim Never Notices</h3><p>The natural follow-up: surely <em>something</em> surfaces to the victim: a login alert, a new entry under connected apps, a 2FA prompt? It doesn’t, and that’s not incidental. Every signal that would normally catch this gets routed around by the shape of the device-code flow itself.</p><p><strong>Audit trail pollution.</strong> myaccount.google.com/connections shows the <em>original</em> client bound to the device_code, YouTube TV, never the substituted application. To find any trace of the attack, a victim would have to open the connections page, scroll to find "YouTube TV" among however many connected apps they have, click into it, click "see details" to expand the granted scopes, and then recognize that YouTube TV requesting cloud-platform / compute / appengine.admin is not normal. Five deliberate steps and a piece of domain knowledge very few people have.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Nq78jsm8FNLJ6QFG.png"><figcaption><em>The “YouTube on TV” connections entry, expanded: Gmail read/compose/send/delete, Cloud SQL, App Engine, and Compute Engine, all under a client that’s supposed to only need YouTube scopes</em></figcaption></figure><p><strong>Implicit 2FA bypass.</strong> The victim goes through a completely ordinary Google sign-in, which already satisfies any 2FA they have configured. The token handoff to the attacker happens afterward, over the device poll, with no further prompt of any kind. The actual high-risk action, an OAuth grant under an arbitrary client’s identity, never trips a high-risk challenge, because as far as the authentication layer is concerned, nothing risky happened; a user just logged in normally.</p><p>Stealth, solved. The remaining question was reach: how far the same substitution trick could be pushed past YouTube TV’s own scopes.</p><h3>8. Extending the Primitive</h3><p>Stealth is one axis; reach is the other. The same client_id/scope substitution keeps paying out against different corners of the Google ecosystem.</p><p><strong>Persistent access via </strong><strong>accounts.reauth.</strong> Add that scope to the substitution and the resulting grant can refresh indefinitely, with no further victim interaction required: a shoot-and-forget backdoor rather than a one-time token.</p><p><strong>A Gmail backdoor via IMAP, not the REST API.</strong> Substituting a client_id that's allowed to request https://mail.google.com (Apple's iOS Mail client, for instance) gets a token scoped to full Gmail access. Hitting the Gmail REST API with it fails: <em>"Gmail API has not been used in project 861556708454 before or it is disabled."</em> That project ID belongs to YouTube TV, and the original device-code client never had the Gmail API enabled. That's a project-level gate, not a token-level one, so it's worth checking whether there's another door into the same mailbox. Gmail's IMAP server supports OAuth via the <strong>XOAUTH2</strong> SASL mechanism, using the exact same https://mail.google.com/ scope but going through imap.gmail.com:993 instead of the REST API's project-gated surface. It accepts the token without issue. Full inbox access, with the same token the REST API had just rejected.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*k7pQv3pDxP21l5DQ.png"><figcaption><em>Successful IMAP XOAUTH2 authentication over the substituted token, listing real Gmail folders and recent inbox messages</em></figcaption></figure><p>End to end: a transferable session, plus unvalidated client_id/scope binding, plus prompt=none, equals a link that's invisible to the person who opens it and ends in a fully compromised account, Gmail included.</p><p>Chain complete: transferable session, unbound client_id/scope, prompt=none, silent to the victim, and a Gmail backdoor at the end of it. Time to see what Google's VRP panel made of all that.</p><h3>9. Disclosure Timeline</h3><p><strong>Feb 25, 2026</strong> Report filed with Google VRP<br><strong>Mar 2, 2026</strong> Closed: Won’t Fix (Intended Behavior), citing “social engineering”<br><strong>Mar 2, 2026</strong> Pushed back same day<br><strong>Mar 3, 2026</strong> Reopened, then closed again: Won’t Fix (Infeasible)<br><strong>Mar 3, 2026</strong> Countered with a prompt=none one-click PoC against Facebook’s client_id<br><strong>Mar 4, 2026</strong> Reopened a second time and accepted; bug filed with the product team<br><strong>Mar 28, 2026</strong> Marked fixed<br><strong>Apr 2, 2026</strong> Rewarded $13,337</p><p>The two rejections both leaned on the same argument: that tricking a user into approving an OAuth prompt is a social-engineering problem, not a vulnerability in Google’s implementation. That didn’t hold up on either pass. The first rejection ignored that this is the exact sign-in flow every Google user already knows, on accounts.google.com, arriving at an app that has no business holding cloud-platform or appengine.admin scopes doing exactly that. The second treated it as equivalent to installing a malicious OAuth app, which the prompt=none PoC against Facebook's client_id directly disproved: there was no prompt to approve, and no app to install; the victim only had to open a link.</p><h3>10. Mitigations</h3><p>For a flow that’s explicitly designed to hand sign-in off to a second device, the fix has to happen server-side, since there’s nothing meaningful a client application can check on its own:</p><ol><li>Keep user_code, device_code, and any session reference that resolves to them out of URLs entirely. If a session can't be copied into a different browser, it can't be handed to a victim.</li><li>Bind client_id and scope to the device_code at issuance time, server-side. At the consent step, look those values up from that binding instead of trusting whatever the URL says; reject any mismatch.</li><li>On the consent screen, show device information (name, model) and require the user to actively confirm that device is the one in front of them.</li></ol><h3>11. Conclusion</h3><p>The device authorization grant is a narrow, deliberately low-trust flow, right up until the authorization server treats “who is asking” and “what are they asking for” as details that only need to be true at the <em>start</em> of the flow, not checked again by the time consent is granted. Once the session itself turned out to be transferable across browsers, the missing binding between device_code and client_id/scope stopped being a narrow YouTube TV bug and became a way to mint tokens for any Google-registered client, first-party or third-party, capped only by which scopes that client happens to be allowed to request.</p><p>Thanks for reading.</p><p>Originally published on <a href="https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html">https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=dc6ec2db35a9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/confused-deputy-google-idp-universal-account-takeover-via-device-code-flow-hijacking-dc6ec2db35a9">Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Niko Matsakis: Battery packs: Let's talk about crates, baby]]></title>
<description><![CDATA[This blog post describes an idea I’ve been kicking around called battery packs. Battery packs are a curated set of crates arranged around a common theme. For example, there’s a CLI battery pack that has everything you need to build a great CLI, an opinionated pack for creating a backend web servi...]]></description>
<link>https://tsecurity.de/de/3674266/tools/niko-matsakis-battery-packs-lets-talk-about-crates-baby/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674266/tools/niko-matsakis-battery-packs-lets-talk-about-crates-baby/</guid>
<pubDate>Thu, 16 Jul 2026 19:24:07 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img alt="Battery pack logo" class="float-right" src="https://smallcultfollowing.com/babysteps/%20/assets/2026-07-15-battery-packs.png">
<p>This blog post describes an idea I’ve been kicking around called <strong>battery packs</strong>. Battery packs are a curated set of crates arranged around a common theme. For example, there’s a CLI battery pack that has <a href="https://crates.io/crates/cli-battery-pack">everything you need to build a great CLI</a>, an opinionated pack for <a href="https://crates.io/crates/backend-service-battery-pack">creating a backend web service</a>, and <a href="https://crates.io/crates/embedded-battery-pack">one for embedded development</a> (based on the Embedded Working Group’s <a href="https://github.com/rust-embedded/awesome-embedded-rust">Awesome Rust repository</a>). We’ve also got some smaller ones, such as the <a href="https://crates.io/crates/error-battery-pack">error-handling battery pack</a> that shows how to handle errors in Rust. But this is just the beginning – a key part of the battery pack design is that anybody can create one.</p>
<p>Battery packs are meant to address one of the most common things I hear from new Rust adopters. Everyone loves the wealth of high-quality crates available on crates.io. And everyone hates having to spend a bunch of time researching and comparing alternatives. Battery packs can serve as a good set of default choices. And they don’t lock you in. At heart, they’re basically just a list of recommended crates, so you can always swap something out if you find an alternative.</p>

<p>We’ve got a prototype of the battery pack tool working today, so you can try it out if you’re curious. Just run <code>cargo install cargo-bp</code> and then try a few commands! For example,</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">&gt; cargo bp list
</span></span></code></pre></div><p>will show you the set of available battery packs, based on a crates.io search (as I’ll explain below, a battery pack is itself packaged and distributed as a crate, but not one that you take a direct dependency on). And <code>cargo bp add</code> will add batteries from a battery pack into your crate, so e.g.</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">&gt; cargo bp add cli
</span></span></code></pre></div><p>would let you select and add common CLI libraries. If you want to see a more involved demo, try out <code>cargo bp add embedded</code>, which is derived from the <a href="https://github.com/rust-embedded/awesome-embedded-rust">Awesome Embedded Rust</a> repository.</p>
<h3>Let’s talk about you and me</h3>
<p>One of the key ideas from battery packs is that <strong>anybody can publish one</strong>. They are just a crate named <code>X-battery-pack</code>; the dependencies of that crate are your recommendations. Features are designations of common sets of crates frequently used together. The examples are your templates. And so forth.</p>
<p>Letting anybody create a battery pack is in contrast to the previous ideas for an “extended standard library for Rust”<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:1">1</a></sup>, and it is intended to address some of Rust’s unique challenges. For one thing, it lets people publish battery packs that are tailored to specific requirements. For example, the <a href="https://crates.io/crates/cli-battery-pack">CLI</a> and <a href="https://crates.io/crates/backend-service-battery-pack">backend service</a> battery packs are targeting a “typical computer”. But I could imagine the <a href="https://rust-embedded.org/">Rust embedded working group</a> publishing a battery pack with libraries focused on no-std and binary size optimization.</p>
<p>Being open-ended also addresses the <em>“who decides?”</em> question. To my mind, the best people to recommend what libraries you ought to use are <strong>other people building systems like yours</strong>. This is why I mentioned the Embedded Working Group publishing an Embedded battery pack, for example, as I think they are clearly a set of people who know their space well. But even within the embedded space there are yet smaller groups, and I imagine that sometimes it’ll make sense to get narrower. For example, perhaps a battery pack targeted <a href="https://embassy.dev/">embassy</a> and its associated ecosystem? Unclear.</p>
<h4>Creating a battery pack</h4>
<p>If you wanted to create a battery pack, how do you do it? One answer is that you just create a new crate. But a better approach is to use the “battery-pack battery pack”<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:2">2</a></sup>, which bundles a template:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">cargo bp new battery-pack
</span></span></code></pre></div><p>This will prompt you for the name of the battery pack you want to create and a few other things and make your crate. Then you can just use <code>cargo add</code> dependencies to represent the libraries you want to recommend and publish.</p>
<h4>“Batteries” are more than dependencies</h4>
<p>The “batteries” that you can add to your project aren’t always dependencies. They can also be “recipes” or templates. For example, the CI battery pack<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:3">3</a></sup> can configure your project with the kind of “super neat-o” github actions you’ve always wanted but never wanted to bother configuring. To use it, select one or more of the templates to install:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-bash"><span class="line"><span class="cl">cargo bp add ci
</span></span></code></pre></div><p>I expect this kind of “actions to improve your crate” to become a rich source of things. Right now we’re using a relatively lightweight template system built on <a href="https://github.com/mitsuhiko/minijinja">minijinja</a>, but I think we’re going to want to expand on this.</p>
<h4>Giving it some structure</h4>
<p>Battery Packs also support more than just a flat listing of dependencies/features/templates. You can group dependencies and features into <em>categories</em> and then, for each category, distinguish between “pick at most one” or “pick any number”. For a fun example, try <code>cargo bp add embedded</code>, which is derived from the <a href="https://github.com/rust-embedded/awesome-embedded-rust">Awesome Embedded Rust</a> repository. If you run it, you’ll see something like this, which groups the choices thematically and, in some areas like “concurrency framework”, makes it clear that you want to pick one:</p>
<pre tabindex="0"><code>──────────────────────────────────────────────────────────────────
 ▼ Concurrency Framework (pick at most one)
 &gt; ○ ✦ embassy [embassy-executor, embassy-sync, embassy-time]
   ○ ✦ rtic [cortex-m, rtic]    RTIC — interrupt-driven real-time

 ▼ Display &amp; Graphics (pick any number)
   [ ] ✦ display-ssd1306 [embedded-graphics, ssd1306]    SSD1306
   [ ] ✦ display-st7789 [embedded-graphics, st7789]    ST7789 col

 ▼ Popular Drivers (pick any number)
   [ ] ✦ display-ssd1306 [embedded-graphics, ssd1306]    SSD1306
   [ ] ✦ display-st7789 [embedded-graphics, st7789]    ST7789 col
   [ ] ✦ sensor-bme280 [bme280]    BME280 temperature/humidity/pr
   [ ] ✦ sensor-lis3dh [lis3dh]    LIS3DH 3-axis accelerometer (I
   [ ] ✦ usb-device [usb-device, usbd-serial]    USB device stack

 ▼ Hardware Abstraction Layer (pick at most one)
   ○ ✦ atsamd [atsamd-hal, cortex-m-rt, critical-section-impl, co
   ○ ✦ esp32 [embedded-hal, esp-hal]    ESP32 (Xtensa, WiFi + BT,
   ○ ✦ esp32c3 [embedded-hal, esp-hal]    ESP32-C3 (RISC-V, WiFi
   ○ ✦ esp32s3 [embedded-hal, esp-hal]    ESP32-S3 (Xtensa, WiFi
   ○ ✦ nrf52832 [cortex-m-rt, critical-section-impl, cortex-m, em
   ○ ✦ nrf52840 [cortex-m-rt, critical-section-impl, cortex-m, em
   ○ ✦ nrf9160 [cortex-m-rt, critical-section-impl, cortex-m, emb
   ○ ✦ rp2040 [cortex-m-rt, critical-section-impl, cortex-m, embe
   ○ ✦ stm32f0 [cortex-m-rt, critical-section-impl, cortex-m, emb
 embedded-battery-pack v0.1.0  ↑↓/jk Navigate | Space Toggle | ←/→
</code></pre><h3>Let’s talk about all the good things…</h3>
<p>So why am I so keen on battery packs? It’s largely because I’ve heard so many would-be or recent Rust adopters talk about picking crates as a challenge. But I feel they would help with some other problems as well.</p>
<p>What I really want to see is working groups in the <a href="https://rustfoundation.org/rust-commercial-network/">Rust Commercial Network</a> banding together to publish battery packs and recommendations. These would cover the dependencies that they’re actually using.</p>
<h4>Supporting maintainers</h4>
<p>One of the reasons I want to have RCN-recognized battery packs is that they are a natural focal point to then prompt RCN members to fund the maintenance of those crates. I am imagining that for each sponsored battery pack vended within the RCN, there is an associated “ecosystem fund”. Companies or individuals could sponsor this fund to get access to early patches, security disclosures, etc or other perks. The money would be used to support the maintainers of those crates, to implement missing features, and so forth.</p>
<h4>Fostering interoperability</h4>
<p>Another value-add from battery packs is the ability to drive interop efforts. I think that as soon as we start talking about standardizing, we’re also going to recognize that there are some places where standardization is hard. For example, early conversations within the <a href="https://rust-commercial-network.github.io/rcn/network-services-wg.html">network service working group</a> (unsurprisingly) immediately identified that while most people are using <a href="https://tokio.rs/">tokio</a>, some major companies are using their own runtimes internally. It’s not like the need for “async runtime interop” is <a href="https://rust-lang.github.io/wg-async/vision/submitted_stories/status_quo/barbara_wishes_for_easy_runtime_switch.html">news</a>. But right now, every crate winds up effectively implementing their own set of little traits to make it work. Sponsored battery packs offer the possibility of a neutral home for that sort of thing.</p>
<h3>…and the bad things that could be</h3>
<p>There are some risks to people using battery packs. The most obvious is that the fact that anybody can publish a battery pack may mean that you just get a ton of battery packs, which doesn’t really help anybody! I’m not so worried about this because I think that there will be a few obvious places that most people go first, and then I think once people are oriented, they’ll get excited to explore what crates.io has to offer and start discovering more niche battery packs.</p>
<h4>Avoiding stagnation</h4>
<p>Battery packs are designed to evolve. I’ve seen it happen a number of times that there is a dominant crate for something, often taking a “traditional approach”, but then somebody else comes along and presents an interesting alternative that gradually takes off. I love that and I don’t want to put it at risk.</p>
<p>One example of evolution around CLI argument parsing. For a time, <a href="https://crates.io/crates/docopt">docopt</a> was a popular way to parse command-line options. Then <a href="https://crates.io/crates/clap">clap</a> came along and presented a more structured alternative; that was nice, but then structopt came along and connected clap to an auto-derive, so you could just write your data structure and be done. And <em>that</em> was awesome. (That is now the standard in clap.) I want to be sure that, even if there is a CLI battery pack, there’s room for the next clap to come along.</p>
<p>There are a few things about battery pack that I think will help us deal with this. First, they are a “thin abstraction”. You don’t “depend on” a battery pack, you depend on the crates within it. So if a new version comes out that uses clap instead of docopt, that doesn’t impact you at all. Your code keeps working same as it ever did. And of course it helps that <em>anybody</em> can publish a battery pack. You can now have variations on battery packs that are focused around a new approach to help it get started.</p>
<p>Done right, I think that standardized battery packs can also <em>help</em> the ecosystem evolve and pivot. As it is now, knowledge of new crates has to spread by word-of-mouth. But if everybody is aligned around a new approach, adopting that new approach within a battery packs sends a clear signal that your group is aligned that something is the new hotness.</p>
<h3>…Let’s talk about crates<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:4">4</a></sup></h3>
<h4>“Always bet on the ecosystem”</h4>
<p>I see <strong>always bet on the ecosystem</strong> as a key Rust design axiom. It’s the reason we chose a small standard library and a package manager in the first place. It’s also why battery packs are designed to be published by anyone.</p>
<p>But just like plants sometimes need a trellis to grow taller, any successful ecosystem reaches a point where it needs another layer of structure to help it keep growing. Without that, you have this “layer of tacic knowledge” (in <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/#example-the-wealth-of-crates-on-crates-io-are-a-key-enabler-but-can-be-an-obstacle">the words of a Rust Vision Doc interviewee</a>) that becomes an obstacle for folks. And I think we’ve reached that point with <code>crates.io</code>.</p>
<p>I am hopeful that battery packs can provide that next layer of structure. But at the end of the day, if there’s a better approach, that’s fine too, so long as we find a way to help people find (<em>and fund!</em>) the crates they need. So let’s talk about it!</p>
<div class="footnotes">
<hr>
<ol>
<li>
<p>My first recollection of it was the <a href="https://internals.rust-lang.org/t/proposal-the-rust-platform/3745">Rust Platform</a> idea we floated in 2016! <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:1">↩︎</a></p>
</li>
<li>
<p>Yo dawg… <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:2">↩︎</a></p>
</li>
<li>
<p>Hat tip to Jess Izen, who proposed and developed the CI battery pack. Neat idea. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:3">↩︎</a></p>
</li>
<li>
<p>Oh, and: my apologies to <a href="https://en.wikipedia.org/wiki/Let's_Talk_About_Sex">Salt-N-Peppa</a>. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:4">↩︎</a></p>
</li>
</ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva launches Code 2.0, offering AI website building to every user — including free accounts]]></title>
<description><![CDATA[Canva on Tuesday launched Canva Code 2.0, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the...]]></description>
<link>https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.canva.com/">Canva</a> on Tuesday launched <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a>, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the company's more than 265 million monthly users across every pricing tier, including free accounts.</p><p>The move is Canva's most aggressive push yet into the fast-growing "vibe coding" market, a category that barely existed 18 months ago but has already minted billion-dollar startups and reshaped how non-developers think about building software. But where rivals like <a href="https://lovable.dev/">Lovable</a>, <a href="https://replit.com/">Replit</a>, and <a href="https://bolt.new/">Bolt.new</a> have focused primarily on generating functional code from text prompts, Canva is making a different bet: that the real bottleneck isn't creating the code — it's making the output actually look good.</p><p>"Most vibe coding tools stop at functional — generating output that looks the same as everyone else's," Canva states in its announcement. "You might get a working prototype, but making it actually look like yours requires a complex editing surface, a separate design tool, a developer, or endless back-and-forth prompting that rarely lands where you want it.”</p><p>Danny Wu, Canva's Head of AI Products, framed the product's positioning in stark terms during an exclusive interview with VentureBeat ahead of the launch.</p><p>"We are deliberately targeting non-technical users," Wu said. "Canva Code isn't a tool we're building for developers. What we're trying to do is bring the power of AI coding — and really lightweight coding — into the Canva platform, while answering our users' requests for more interactivity, more customization, and more flexibility, from websites to interactive presentations."</p><h3><b>Canva Code 2.0 brings drag-and-drop editing, HTML import, and 75% faster generation to AI-built websites</b></h3><p>The update introduces several capabilities designed to collapse the distance between generating code and publishing a polished interactive experience. Users can now create Canva Code projects directly inside other design projects — embedding interactive elements within a whiteboard, presentation deck, or standalone page. <a href="https://www.canva.com/">Canva</a> has also added more than 50 new templates specifically designed for interactive designs, along with the ability to import raw HTML files from other AI coding tools and convert them into editable Canva designs.</p><p>The performance improvements are significant. Canva says it has reduced average code generation time by 75 percent and cut the median time from initial prompt to a published site by 30 percent. The company also reports that integrating <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> into the broader Canva editor — allowing users to treat coded outputs like any other design element — has increased active Code users by 25 percent.</p><p>Perhaps the most distinctive feature is the editing experience itself. Unlike most AI coding platforms, which require users to re-prompt or modify raw code to make visual changes, <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> lets users click directly into generated elements to change text, drag and drop images from Canva's built-in library of over 120 million templates and assets, update colors and fonts through a familiar toolbar, or select a specific element and refine it through conversational AI. Every output is fully interactive and automatically adapts to different screen sizes, with a built-in mobile preview.</p><p>Wu demonstrated the drag-and-drop editing during the interview, showing how a generated conference website could be modified in real time — swapping in photos, changing fonts to branded alternatives, and editing text directly on the canvas. "The key differentiator with Canva Code is the editability and the kindness of the outputs it generates," he said, though he noted one current limitation: "We don't support moving elements around. You still have to re-prompt for that."</p><h3><b>How Canva plans to compete with Lovable, Replit, and Bolt in the booming AI app builder market</b></h3><p>Canva's entry into vibe coding at this scale arrives at a pivotal moment for the category. According to <a href="https://www.useluminix.com/reports/industry-analysis/vibe-coding-tool-landscape-replit-v0-base44-bolt-lovable-vercel/source/0">market research published by Luminix AI in May 2026</a>, the vibe coding and AI app builder market has reached an estimated $4.7 billion in 2026, with projections pointing toward $12.3 billion by 2027 at roughly 38 percent compound annual growth. The research also estimates that AI-generated code now comprises approximately 41 percent of all code written globally — a figure that would have seemed inconceivable even two years ago.</p><p>The competitive landscape has grown ferocious. <a href="https://lovable.dev/dashboard">Lovable</a>, which focuses on conversational, design-forward app generation for non-technical founders, has achieved what may be the fastest revenue ramp in the category's history — reportedly reaching approximately $400 million in annual recurring revenue by early 2026, according to Luminix's analysis. <a href="https://replit.com/">Replit</a>, which transformed its browser-based IDE into a full vibe-coding engine through successive AI agent releases, has tripled its valuation to $9 billion and is targeting $1 billion in run-rate revenue by the end of 2026, per the same report. <a href="https://bolt.new/">Bolt.new</a>, which runs a full Node.js environment entirely in the browser, scaled from $4 million to $40 million in ARR within months of launching.</p><p>And then there is Canva, which brings something none of those platforms possess: a quarter-billion-user design ecosystem where brands, teams, and individuals already store their visual identities, collaborate on projects, and publish content.</p><p>Wu positioned <a href="https://bolt.new/">Canva Code</a> not as a direct competitor to these developer-focused tools but as something that fills a gap none of them have addressed. "A lot of the requests that we have been getting and the usage we're seeing is actually with using Canva Code not necessarily as just one artifact, but as part of an overall design, the visual communication they're trying to tell," Wu said. "Like when you have a sales deck, you're able to add a calculator, you're able to add a visualizer of what exactly your product does. That's something where an interactive slide can be worth a thousand pictures."</p><h3><b>Why Canva's HTML import feature could turn it into a 'finishing layer' for every AI coding tool</b></h3><p>One of the most strategically interesting features in <a href="https://bolt.new/">Canva Code 2.0</a> is its HTML import capability, which allows users to take code generated by any AI tool — including <a href="https://chatgpt.com/">ChatGPT</a>, <a href="http://claude.ai/">Claude</a>, <a href="https://lovable.dev/dashboard">Lovable</a>, or <a href="https://bolt.new/">Bolt</a> — and bring it into Canva as a fully editable design. The implication is unmistakable: Canva is positioning itself as the place where AI-generated code gets its finishing touches, regardless of where it was originally created.</p><p>When asked directly whether this amounts to positioning Canva as a "finishing layer on top of vibe coding," Wu offered a diplomatic but revealing response. "It's really a continuation of our goal to make all design as easy as possible," he said. "We've supported importing PDFs and translating them into docs, importing PowerPoint files — so in one way, it's an expansion of that. But in another way, it's really just listening to what our users want and making Canva both the most useful and the most compatible platform.”</p><p>He paused, then added: "It's not that we're deliberately positioning ourselves as a specific layer, say like a finishing layer after vibe coding. We just really want to make our platform the most accessible and the most pluggable."</p><p>That language — "most pluggable" — suggests a platform strategy that doesn't require Canva to win the AI code generation race outright. If Canva becomes the default destination for making AI-generated code look professional and on-brand, it captures value from the entire category regardless of which code generation engine users prefer. The strategy also echoes the broader import capabilities that already allow Canva to ingest PowerPoint decks and PDFs from competing platforms, gradually pulling users deeper into the Canva ecosystem without demanding they abandon existing workflows.</p><h3><b>What Canva Code can build — and where Danny Wu says it hits its limits</b></h3><p>Wu was notably candid about the product's boundaries — a refreshing departure from the typical Silicon Valley product launch. "Canva Code is great for anything that works as a front-end app, and it's especially good when you want to leverage data, data submissions, and interactivity at small to medium scale," he said. "I'll be honest about the limitations. Canva Code is probably not going to be suitable if you're trying to build a website with complex backends, or if you're handling hundreds of thousands of visitors per day."</p><p>This candor effectively draws a line between <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> and the more ambitious platforms in the space. While Lovable and Replit are pushing toward full-stack application development — complete with databases, authentication, and production-grade hosting — Canva is deliberately limiting its scope to interactive front-end experiences at modest scale. The question is whether that's a strategic weakness or a disciplined focus. For the teachers, small business owners, and marketing teams that make up the bulk of Canva's user base, complex backends and high-traffic scalability are irrelevant concerns. What matters is whether they can create an interactive event page, a property listing website, or a classroom hub that looks professional and works on mobile — without hiring a developer or learning a new tool.</p><p>When asked about the AI models powering <a href="https://www.canva.com/ai-code-generator/">Canva Code</a>, Wu confirmed the company uses a combination of proprietary and third-party models, including those from OpenAI and Anthropic, but declined to specify the exact mix. "We don't share the exact mix, and it does change over time," he said. "We also route differently depending on what you're asking for and which model family we think is best for handling certain requests."</p><h3><b>Canva's AI acquisition spree — from Affinity to Leonardo.ai — now powers its vibe coding push</b></h3><p>Canva's broader AI infrastructure has been significantly bolstered by an acquisition strategy that has accelerated over the past two years. In March 2024, <a href="https://www.canva.com/newsroom/news/affinity/">the company acquired Affinity</a>, the British creative software suite popular with Mac users, in a deal that Bloomberg reported was valued at "<a href="https://www.bloomberg.com/news/articles/2024-03-26/canva-acquires-affinity-design-suite-in-push-to-rival-adobe">several hundred million pounds</a>." Canva at the time positioned the deal as a way to compete with Adobe's flagship products — Illustrator, Photoshop, and InDesign — by gaining ownership of Affinity's Designer, Photo, and Publisher applications.</p><p>Just four months later, Canva acquired <a href="http://leonardo.ai/">Leonardo.ai</a>, an Australian generative AI startup with over 19 million registered users and more than a billion images generated. Canva co-founder Cameron Adams said at the time that Leonardo.ai's technology would be integrated into Canva's Magic Studio generative AI suite.</p><p>Together with these acquisitions, <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> is the company's attempt to layer interactive, code-driven capabilities on top of a visual design platform that has already been enhanced by professional-grade design tools and generative AI models. The company reports over 32 billion uses of its AI products to date — a staggering figure that underscores how deeply AI is now woven into everyday Canva workflows, even for users who may not think of themselves as using artificial intelligence.</p><h3><b>Six million sites published, but Canva's retention data remains an open question</b></h3><p>Canva's announcement highlights an impressive traction metric: users have created and published more than six million websites using Canva Code since the feature was first introduced a year ago. But the number deserves scrutiny.</p><p>Wu clarified in the interview that the six million figure represents published websites over the past year — meaning sites that were either made public or shared via password-protected or private links. "They may have published publicly, or behind a password, or as a private link. But that's the number of published websites," he said.</p><p>When asked about active retention — how many of those sites are still live and being maintained — Wu acknowledged the gap in his data. This is a meaningful distinction. In the vibe coding market, raw creation numbers can be misleading because the barrier to generating a site is so low. The more telling metric — which Canva does not yet provide — would be how many of those six million sites receive regular traffic or have been updated after initial publication.</p><p>The early use cases, however, suggest genuine utility beyond novelty. Educators and school administrators are using Canva Code to build classroom hubs, with one teacher creating bespoke webpages for each of their classrooms to keep students and parents updated on announcements. Small businesses, like Alt Marketing School, have built mini apps for fundraising training and interactive roadmaps for their members. For World Book Day, 50 readers created educational games across different subjects, complete with pedagogical guides for classroom use.</p><h3><b>Canva Code pricing, data governance, and what enterprise customers need to know</b></h3><p><a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> is available across all of Canva's pricing tiers, including its free plan — a notable decision given that competitors like Lovable, Bolt, and Replit reserve their most capable features for paid subscribers. "As you go from, say, free to pro to business to enterprise, you would get more AI credits and be able to have higher usage of Canva Code," Wu said. "But it is available and it is usable — even free Canva accounts as well as education and not-for-profit accounts."</p><p>This credit-based approach mirrors the pricing evolution happening across the entire vibe coding category, where platforms have converged on token or credit systems that meter AI generation capacity rather than gating features behind subscription tiers. The difference is that Canva's free tier serves as an acquisition funnel for a much larger design platform, not just for the coding feature itself.</p><p>For the institutional customers Canva increasingly courts — school districts, real estate brokerages, enterprise marketing teams — data governance is a threshold concern. Wu addressed this directly. "All users and customers have full control over how their data is used," he said. "They can choose whether their prompts and data are used for AI training in the settings. For businesses and enterprises, team admins can manage this at the organizational level and guarantee that their inputs, content, and outputs won't be used for training." This opt-out approach reflects a lesson the broader industry has learned the hard way. As The Verge reported when Canva acquired Leonardo.ai, Adobe suffered significant backlash over a policy update regarding user data and AI model training — a controversy Canva appears keen to avoid.</p><h3><b>Canva's long-term vision: closing the gap between imagination and what non-technical users can actually build</b></h3><p>When asked where <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> fits into the company's long-term trajectory — and whether Canva is building toward a full-stack app development platform — Wu steered the conversation back to the company's core audience.</p><p>"A huge part of it is reducing the gap between your imagination and what's possible, especially for everyday users — people who don't have a lot of time," he said. "They don't have time to figure out deploys or MCPs or APIs. They just want to design more interactive and more dynamic communication."</p><p>He pointed to the rapid improvement in AI model capabilities as a key accelerant. "The kind of things you can create today in one shot — like a 3D visualization of a solar system — you really couldn't have trusted the output a year ago. But today, you have a really high success rate."</p><p>Whether <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> becomes a durable product category or a feature that gets absorbed into the platform's broader AI workflow will depend on how quickly the company can close the gap between its current front-end focus and the full-stack capabilities that increasingly define the competition. Lovable is shipping Supabase-backed apps with authentication and databases built in. Replit's agents can execute autonomous long-running builds. Bolt.new runs entire Node.js environments in a browser tab. These are fundamentally different ambitions than making a conference landing page look good.</p><p>But Canva has never won by matching the technical depth of its competitors. A decade ago, it didn't try to out-feature Adobe — it made design accessible to the 99 percent of people who would never open Photoshop. Now, in a vibe coding market where every tool can generate a working prototype from a prompt, Canva is making the same wager it made in 2012: that for most people, the hardest part was never the building. It was making it look like it came from you.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, libxfont, mesa, opam, and wireless-regdb), Fedora (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-d...]]></description>
<link>https://tsecurity.de/de/3665263/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665263/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 13 Jul 2026 14:41:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, libxfont, mesa, opam, and wireless-regdb), <b>Fedora</b> (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-dulwich, python-idna, python-pillow, python-tornado, sssd, tmux, upower, webkitgtk, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Mageia</b> (libarchive and vim), <b>Oracle</b> (389-ds:1.4, buildah, cups, edk2, freerdp, golang, grafana, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libexif, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, nodejs:22, nodejs:24, oci-seccomp-bpf-hook, podman, postgresql:18, python-urllib3, tigervnc, tomcat, unbound, and xorg-x11-server), <b>Slackware</b> (p11-kit), and <b>SUSE</b> (agama, dash, dracut, flannel, go1.26, gsasl, gstreamer-plugins-good, ImageMagick, imagemagick, kernel, krb5, krb5, krb5-mini, libIex-3_4-33, libmbedtls23, libxfont2, nasm, nghttp2, perl-CGI-Session, perl-dbi, perl-List-SomeUtils-XS, python-pillow, python-social-auth-app-django, python-urllib3, python313-Django4, python313-Django6, python313-pytest-html, python313-sqlparse, python313-websockets, rclone, rust-keylime, rustup, sccache, spectre-meltdown-checker, sssd, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, thunderbird, tiff, traefik2, xorg-x11-server, and xwayland).]]></content:encoded>
</item>
<item>
<title><![CDATA[Linus Torvalds on AI, Junk Patches, Humans, and Godzilla]]></title>
<description><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hope...]]></description>
<link>https://tsecurity.de/de/3663853/it-security-nachrichten/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663853/it-security-nachrichten/linus-torvalds-on-ai-junk-patches-humans-and-godzilla/</guid>
<pubDate>Sun, 12 Jul 2026 23:05:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific,"
reports ZDNet. "That was pulled out of my ass number, obviously."


Today, he continued, "we're at the point where hopefully it creates more productivity than it takes away," but "we certainly saw more junk being generated by LLMs than we saw useful code up until the like early this year.... it can actually be a huge drain on resources when it takes humans a lot of effort to figure out that, hey, this machine-generated report was not true." Even now, he said, "most of the good ones require more than just the LLM," because "we've had to push back quite a bit... if you find a bug with an LLM, it's not enough to just ask the LLM to make a bug report and then throw it over the fence to us. We want to see a suggested patch; we want to see the human who ran the LLM act as a kind of back-and-forth." 

Torvalds described many AI-generated patches as "mindless band-aid kind of patches... they may fix the immediate problem, but the kind of bug remains, and it just is waiting in the hallway to hit you in another place." For his own toy projects, he uses LLMs as prototypers: "I use them as a way to prototype things... quite often the code is not usable in that form, but it's a great way to try something out," while insisting that for kernel-level fixes, "LLMs, in my experience, have not been at that level yet." 

Torvalds acknowledged that some AI-found issues have been "absolutely, stunningly, I mean, interesting in a painful kind of way," especially security problems that "show up in the technology press two days later." Despite the embarrassment, he said, "I'm very much not a shoot-the-messenger kind of person. I think we're much better off with LLMs finding bugs, even when they are embarrassing, and they are things that we should probably have found two decades ago."

 

Torvalds also said he's using AI "for my own toy projects... Every time I travel to some new place, and this is the first time I've been to India, I send the kids pictures of where I am, and for some strange reason, Godzilla seems to follow me around and gets added to those pictures." 

ZDNet notes that Torvalds concluded, "There are many useful and less useful uses for AI," and "I think Godzilla is a great place to stop." 

Thanks to Slashdot reader joshuark for sharing the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds+on+AI%2C+Junk+Patches%2C+Humans%2C+and+Godzilla%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F12%2F2053201%2Flinus-torvalds-on-ai-junk-patches-humans-and-godzilla%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/12/2053201/linus-torvalds-on-ai-junk-patches-humans-and-godzilla?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Guide to Loop Engineering: How ‘autoresearch’ and ‘Bilevel Autoresearch’ Turn AI Agents Into Autonomous Machine Learning ML Research Loops]]></title>
<description><![CDATA[Most people still use AI like a 2015 search box. You type, you read, you type again. A newer pattern replaces that manual back-and-forth with a loop. This guide explains loop engineering using two verified artifacts. The sources are Andrej Karpathy’s autoresearch repository and the Bilevel Autore...]]></description>
<link>https://tsecurity.de/de/3663827/ai-nachrichten/guide-to-loop-engineering-how-autoresearch-and-bilevel-autoresearch-turn-ai-agents-into-autonomous-machine-learning-ml-research-loops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663827/ai-nachrichten/guide-to-loop-engineering-how-autoresearch-and-bilevel-autoresearch-turn-ai-agents-into-autonomous-machine-learning-ml-research-loops/</guid>
<pubDate>Sun, 12 Jul 2026 22:33:03 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most people still use AI like a 2015 search box. You type, you read, you type again. A newer pattern replaces that manual back-and-forth with a loop. This guide explains loop engineering using two verified artifacts. The sources are Andrej Karpathy’s autoresearch repository and the Bilevel Autoresearch paper. The framing follows a write-up by @0xCodila. […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/12/guide-to-loop-engineering/">Guide to Loop Engineering: How ‘autoresearch’ and ‘Bilevel Autoresearch’ Turn AI Agents Into Autonomous Machine Learning ML Research Loops</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Not your ordinary Linux distributions!]]></title>
<description><![CDATA[Is it obvious, that I like to try out the more independent and not your ordinary Linux distributions? 😂 So spinning up a VM every now and then and install Linux distributions that do their own thing! At the moment I have installed 4 distributions that not everyone may know or use. Or do you? Kwor...]]></description>
<link>https://tsecurity.de/de/3662647/linux-tipps/not-your-ordinary-linux-distributions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662647/linux-tipps/not-your-ordinary-linux-distributions/</guid>
<pubDate>Sun, 12 Jul 2026 04:25:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Is it obvious, that I like to try out the more independent and not your ordinary Linux distributions? 😂</p> <p>So spinning up a VM every now and then and install Linux distributions that do their own thing! At the moment I have installed 4 distributions that not everyone may know or use. Or do you?</p> <p>Kwort Linux: based on CRUX Linux and is a very minimal distribution that doesn't hold your hand but kinda brings a breath of fresh air to you!</p> <p>Slackware Linux: The granddaddy of Linux! Nothing more to say!</p> <p>Lunar Linux: An independent source based distribution forked from Sorcerer with a unique package management system. Kinda easy to install but a PIA to set up after the initial installation.</p> <p>Source Mage: Also a source based distribution, forked from Sorcerer as well. Different to other distributions you're casting and dispelling programs, which are referred to as spells.</p> <p>Haven't installed Source Mage yet as I'm still trying to set up Lunar Linux. But has anyone ever heard or even used one of these distributions? Except Slackware, I guess everyone heard of Slackware. Any other distributions that you use that are niche and do their own thing?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/twistedmind1979"> /u/twistedmind1979 </a> <br> <span><a href="https://i.redd.it/mon5lpn9hkch1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1utfblk/not_your_ordinary_linux_distributions/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Denial of Service in p11-kit (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3661416/it-security-nachrichten/denial-of-service-in-p11-kit-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661416/it-security-nachrichten/denial-of-service-in-p11-kit-slackware/</guid>
<pubDate>Sat, 11 Jul 2026 09:04:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (aardvark-dns, cups, edk2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, oci-seccomp-bpf-hook, python-urllib3, and tomcat), Debian (rlottie), Fedora (c-...]]></description>
<link>https://tsecurity.de/de/3659934/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659934/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 10 Jul 2026 15:52:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (aardvark-dns, cups, edk2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, oci-seccomp-bpf-hook, python-urllib3, and tomcat), <b>Debian</b> (rlottie), <b>Fedora</b> (c-ares, k9s, kind, libXfont2, nmap, pam, perl-DBI, php, python-pendulum, tmux, and xorg-x11-server-Xwayland), <b>Mageia</b> (7zip and ack), <b>Slackware</b> (tigervnc), <b>SUSE</b> (alloy, cargo-c, chromium, clamav, cosign, dirmngr, firefox, flannel, fluidsynth, gnutls, go1.25, go1.26, gol, GraphicsMagick, helm, kernel-devel, libaom, libexif, openQA, os-autoinst, python-Django, python-idna, python-sqlparse, rust-keylime, rustup, sccache, SUSE Manager Client Tools, SUSE_Multi-Linux_Manager Client Tools, transmission, and warewulf4), and <b>Ubuntu</b> (curl, expat, golang-go.crypto, libheif, libidn, libraw, libsoup2.4, linux, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle, linux-aws, linux-aws-fips, linux-azure-fips, linux-fips, linux-raspi, linux-xilinx-zynqmp, and python2.7, python3.5).]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone Fold, AirPods with cameras, & time capsules all in question on the AppleInsider Podcast]]></title>
<description><![CDATA[Rumors continue to go back and forth on whether the iPhone Fold will launch on time, plus there is now a question on if AirPods will get cameras at all. This and more on the AppleInsider Podcast.iPhone 17 Pro Max slight damage after a year with no caseApple is placing an iPhone 17 Pro Max in a ti...]]></description>
<link>https://tsecurity.de/de/3659860/ios-mac-os/iphone-fold-airpods-with-cameras-time-capsules-all-in-question-on-the-appleinsider-podcast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659860/ios-mac-os/iphone-fold-airpods-with-cameras-time-capsules-all-in-question-on-the-appleinsider-podcast/</guid>
<pubDate>Fri, 10 Jul 2026 15:25:40 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rumors continue to go back and forth on whether the <a href="https://appleinsider.com/inside/iphone-fold" title="iPhone Fold" data-kpt="1">iPhone Fold</a> will launch on time, plus there is now a question on if AirPods will get cameras at all. This and more on the AppleInsider Podcast.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68205-143790-iPhone-17-Pro-Max-battle-damage-bottom-xl.jpg" alt="Dark-colored iPhone lying face down on a closed gray notebook, resting on a wooden surface, with blurred metallic objects in the background" height="738"><br><span>iPhone 17 Pro Max slight damage after a year with no case</span></div><br>Apple is placing an <a href="https://appleinsider.com/inside/iphone-17" title="iPhone 17" data-kpt="1">iPhone 17 Pro Max</a> in a time capsule, and presumably when it is opened in 250 years, there will have been a lighter and cheaper <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro</a>. However, rumors suggest Apple might me more focused on AI and glasses instead.<br><br>Those glasses might have cameras in them, and that could be a problem if regulators start pushing back against wearable cameras. At the least, rumors suggest that <a href="https://appleinsider.com/inside/airpods" title="AirPods" data-kpt="1">AirPods</a> won't actually get cameras after all.<br><br><br> <a href="https://appleinsider.com/articles/26/07/10/iphone-fold-airpods-with-cameras-time-capsules-all-in-question-on-the-appleinsider-podcast?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244924?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scot NHS Trust probes email stuffup involving maternity patients’ data]]></title>
<description><![CDATA[NHS Forth Valley is the latest health board to bungle basic email data protection principles This article has been indexed from www.theregister.com – Articles Read the original article: Scot NHS Trust probes email stuffup involving maternity patients’ data
Read more →
The post Scot NHS Trust prob...]]></description>
<link>https://tsecurity.de/de/3659274/it-security-nachrichten/scot-nhs-trust-probes-email-stuffup-involving-maternity-patients-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659274/it-security-nachrichten/scot-nhs-trust-probes-email-stuffup-involving-maternity-patients-data/</guid>
<pubDate>Fri, 10 Jul 2026 11:37:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NHS Forth Valley is the latest health board to bungle basic email data protection principles This article has been indexed from www.theregister.com – Articles Read the original article: Scot NHS Trust probes email stuffup involving maternity patients’ data</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/scot-nhs-trust-probes-email-stuffup-involving-maternity-patients-data/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/scot-nhs-trust-probes-email-stuffup-involving-maternity-patients-data/">Scot NHS Trust probes email stuffup involving maternity patients’ data</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scot NHS Trust probes email stuffup involving maternity patients' data]]></title>
<description><![CDATA[NHS Forth Valley is the latest health board to bungle basic email data protection principles]]></description>
<link>https://tsecurity.de/de/3659234/it-security-nachrichten/scot-nhs-trust-probes-email-stuffup-involving-maternity-patients-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659234/it-security-nachrichten/scot-nhs-trust-probes-email-stuffup-involving-maternity-patients-data/</guid>
<pubDate>Fri, 10 Jul 2026 11:22:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NHS Forth Valley is the latest health board to bungle basic email data protection principles]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in tigervnc (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3658738/it-security-nachrichten/zwei-probleme-in-tigervnc-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658738/it-security-nachrichten/zwei-probleme-in-tigervnc-slackware/</guid>
<pubDate>Fri, 10 Jul 2026 07:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Mehrere Probleme in libXfont2 (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3658192/it-security-nachrichten/mehrere-probleme-in-libxfont2-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658192/it-security-nachrichten/mehrere-probleme-in-libxfont2-slackware/</guid>
<pubDate>Thu, 09 Jul 2026 22:23:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in proftpd (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3658182/unix-server/security-mehrere-probleme-in-proftpd-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658182/unix-server/security-mehrere-probleme-in-proftpd-slackware/</guid>
<pubDate>Thu, 09 Jul 2026 22:16:26 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in xorg-server (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3658179/unix-server/security-zwei-probleme-in-xorg-server-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658179/unix-server/security-zwei-probleme-in-xorg-server-slackware/</guid>
<pubDate>Thu, 09 Jul 2026 22:16:23 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[The enterprise AI challenge nobody solves with code generation alone]]></title>
<description><![CDATA[Presented by SAPGenerating code with AI is fast, but getting that code to run reliably inside a large enterprise, integrated with live systems, governed for compliance, and maintainable over years requires foundational work that most organizations underestimate. While 81% of all organizations hav...]]></description>
<link>https://tsecurity.de/de/3657798/it-nachrichten/the-enterprise-ai-challenge-nobody-solves-with-code-generation-alone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657798/it-nachrichten/the-enterprise-ai-challenge-nobody-solves-with-code-generation-alone/</guid>
<pubDate>Thu, 09 Jul 2026 19:02:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by SAP</i></p><hr><p>Generating code with AI is fast, but getting that code to run reliably inside a large enterprise, integrated with live systems, governed for compliance, and maintainable over years requires foundational work that most organizations underestimate. </p><p>While 81% of all organizations have a detailed strategy, <a href="https://www.sap.com/research/most-companies-have-an-ai-strategy-only-1-in-8-can-execute-it">only 12–16% reach AI‑driven execution</a>, says SAP's Michael Ameling, CPO of SAP Business Technology Platform, and the reasons rarely come down to the quality of the generated code.</p><p>"Across industries, enterprises that have invested heavily in AI tooling are hitting a wall when generated code meets the reality of their existing environments, because generating code and operationalizing it are not the same problem," Ameling says. </p><p>There are specific requirements for deploying AI-generated logic at enterprise scale: what data and integration readiness actually look like, how governance works when AI agents move from producing recommendations to executing workflows, and how development teams are changing their role as AI takes over more of the coding work.</p><h2>Why AI code generation fails in enterprise production environments</h2><p>The productivity gains from AI code generation are real and well-documented, but the ease of prototyping has given many organizations a misleading sense of how far along they actually are. </p><p>"Generating code is one thing," Ameling says. "Enterprise customers, including multinationals and large organizations, need to ensure there are no compromises in compliance or security. Code that runs reliably for ten or twenty years, as it does at many of SAP's largest customers, also has to be maintained, patched, and understood by whoever inherits it. Life cycle management, in other words, does not generate itself."</p><p>The issue is rarely the generation quality. Teams build something compelling, then discover they lack access to the data it depends on, or the integrations it assumes, or the permissions required to run it in a real environment. The problem is essentially that AI amplifies an organization's existing data and process maturity, but it can't substitute for it.</p><p>This dynamic intensifies as AI moves from producing code to executing actions. Latency, cost, and system load all increase when logic runs continuously against live data rather than rendering a one-time output. The performance requirements of an autonomous agent operating across a multinational's transaction systems are categorically different from those of a developer copilot.</p><h2>How to connect AI-generated logic to fragmented enterprise systems</h2><p>The architecture challenge that most enterprise AI projects underestimate is integration. Real enterprise environments are not clean slates: they combine cloud systems, legacy on-premise infrastructure, fragmented data stores, and dozens of business applications that were never designed to talk to each other. Getting AI-generated logic to operate reliably across all of them requires a layer that unifies data access, process context, and governance, and it has to be in place before any agent starts executing. And organizations that see AI as a reason to defer infrastructure modernization are making a mistake. </p><p>"The question is not whether to modernize or not. Of course you need to modernize," Ameling says. "But the value you get on top of this is much higher with AI. Federated data access and harmonized process layers are not alternatives to upgrading a fragmented landscape, they're what make the upgrade worthwhile."</p><p>At the platform level, this translates into a set of practical requirements: structured data integration, end-to-end process visibility, and the ability to discover and connect to APIs across both modern and legacy systems. SAP's approach with the Business AI Platform draws on tools including its Joule Studio, Integration Suite, Business Data Cloud, and SAP AI Agent Hub enterprise architecture layer to provide that context. The goal is to give AI-generated logic accurate, current knowledge of what a business is doing and how, rather than just access to raw data.</p><p>AI agents handle large challenges by dividing them into smaller, autonomous tasks, with each agent responsible for a specific domain, and all coordinated toward a shared outcome. A financial close, for example, involves dozens of discrete sub-processes. Agents handling each task in parallel, within defined constraints, can compress cycle times dramatically, but only if the underlying systems they interact with are coherent and accessible.</p><h2>The governance and oversight that AI agents require in production</h2><p>When AI moves from assistant to operational actor, the governance questions loom large, because agents that trigger workflows, update records, and interact with live business systems need the same accountability framework that applies to human employees, i.e., identities, defined privileges, and auditable behavior.</p><p>There are two distinct models:</p><p>Principal propagation, where an agent acts on a user’s behalf, inheriting that user’s permissions and scope.</p><p>System-triggered agents, where the agent operates under its own identity and role-defined privileges, functioning more like an automated HR role than a personal assistant.</p><p>Both models require the same underlying infrastructure: an agent hub where operators can see which agents exist, what APIs they can access, and what they are authorized to do. Observability also needs to be operationalized correctly for AI, combined with both technical and business evals. </p><p>"In production, openness is very important," Ameling says. "We use OpenTelemetry as a framework, so we can integrate with other solutions, for end-to-end observability of the tool, third-party agents and the like."</p><p>On top of that, standard technical evals, which test whether an agent produces consistent outputs, are necessary but not enough. Business evals assess whether an agent is actually moving the performance indicators it was deployed to improve, but it has to work end-to-end.</p><p>Where the testing happens is equally important. The traditional software development cycle across dev, test, and production environments breaks down when a model produces different outputs depending on whether it is running against test data or live data. Getting to trustworthy AI in production means accepting that validation looks fundamentally different from what engineering teams have practiced for decades, with live environment testing, even A/B/C testing to ensure outcomes are reliable.</p><h2>How AI-driven code generation is changing software engineering roles</h2><p>The role of the developer is not disappearing in this environment, but its center of gravity is shifting. The productivity multiplier is significant when developers can run multiple coding agents in parallel across open terminals, each working on a separate problem and each taking several minutes to complete. But it introduces a new kind of cognitive demand, because humans have to stay in the loop. That means tracking context across concurrent workstreams, evaluating outputs that range across large codebases, and making architectural judgments that no agent can be trusted to make alone.</p><p>"The more specific and complete the prompt, the less intervention is required, and developers are learning that bringing more context upfront pays dividends in reduced back-and-forth," Ameling says. "But the output still needs to be understood, not just accepted."</p><p>The competitive edge will remain intellectual property, not tooling. The companies that pull ahead will be those that most effectively encode their domain knowledge into the systems they build.</p><p>"A manufacturer's process expertise, a financial institution's risk logic, a logistics firm's routing intelligence, these are the assets that AI can accelerate, but only if the organizations that hold them do the work to make them accessible and usable," Ameling says. "Protect that, and apply AI to accelerate your differentiation."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s real bottleneck isn’t compute. It’s distance.]]></title>
<description><![CDATA[A researcher has an idea worth testing before lunch. The model is ready. The data is sitting right there. But the data is sensitive — regulated, proprietary; the kind that legal has been very clear cannot leave the building. So it can’t go to the cloud cluster. And even if it could, the GPU queue...]]></description>
<link>https://tsecurity.de/de/3657618/it-nachrichten/ais-real-bottleneck-isnt-compute-its-distance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657618/it-nachrichten/ais-real-bottleneck-isnt-compute-its-distance/</guid>
<pubDate>Thu, 09 Jul 2026 18:02:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A researcher has an idea worth testing before lunch. The model is ready. The data is sitting right there. But the data is sensitive — regulated, proprietary; the kind that legal has been very clear cannot leave the building. So it can’t go to the cloud cluster. And even if it could, the GPU queue is hours deep, the meter is running, and by the time the run finishes and the bill lands, the spark of the idea has cooled into a ticket in a backlog. </p>



<p>This is the unglamorous reality behind a lot of enterprise AI. Not a shortage of talent or ambition, but friction — the quiet tax paid every time a brilliant question has totravel a long way to find the computer that can answer it. We’ve spent the better part of a decade assuming that distance didn’t matter, that everything important would happen in some vast facility hundreds of miles away. For a whole class of work, that assumption is now the thing holding teams back. </p>



<h3 class="wp-block-heading"><strong>The last mile of AI</strong> </h3>



<p>Cloud and hyperscale data centers did something extraordinary: they made a near-infinite compute available to anyone with a credit card. That scale is genuinely irreplaceable for training frontier models. But scale solved the wrong problem for a surprising number of teams. </p>



<p>Because a lot of real AI work isn’t a once-a-quarter mega run, it’s iteration — fine-tuning, experimenting, debugging, testing an agent’s behavior, running a model against data that’s too sensitive or too large to keep shipping back and forth. That work rewards <em>immediacy</em> and <em>control</em>, not raw scale. And on those two axes, the cloud-only model starts to strain in three ways. </p>



<p><strong>Governance is the first.</strong> The most valuable enterprise data is often the data that’s hardest to move — patient records, financial details, proprietary source code, designs under NDA. Sending it to a shared, off-premises environment can mean a compliance review, a risk sign-off, or simply a “no.” When the data can’t travel, neither can the AI work that depends on it — unless the compute comes to the data instead. </p>



<p><strong>Velocity is the second.</strong> AI progress is a function of how many experiments a team can run per week. Every cloud queue, every cold start, every round trip between a workstation and a remote cluster adds latency not just to a job but to <em>learning</em>. The teams that win aren’t the ones with the biggest single run; they’re the ones who can iterate fastest, privately, without asking permission. </p>



<p><strong>And then there’s the missing middle.</strong> Until recently, professionals had two options, and a chasm between them. On one side, a traditional workstation — convenient and local, but utterly unable to hold a trillion-parameter model in memory. On the other, a data center you don’t own, don’t control, and have to wait in line for. There was nothing in between: no way to put genuine, data-center-class AI power directly under the desk of the person doing the work. </p>



<p>That gap is exactly where the next wave of productivity is hiding. </p>



<h3 class="wp-block-heading"><strong>When the supercomputer comes back to the desk</strong> </h3>



<p>Computing has always swung between the central and the personal. The mainframe gave way to the PC. Now, after a decade of centralizing intelligence in the cloud, the pendulum is swinging again — and the supercomputer is coming back to the desk, this time built specifically for AI. </p>



<p>The implications for IT leaders are strategic, not just technical. A local, private AI supercomputer means sensitive workloads stay under the organization’s own governance. It means a predictable cost instead of a variable cloud meter. It means teams iterate at the speed of their own curiosity. And it means the data center is still there when a workload genuinely needs to scale — connected, not replaced. The goal isn’t to abandon the cloud. It’s to close the last mile. </p>



<h3 class="wp-block-heading"><strong>The deskside AI supercomputer: ASUS ExpertCenter Pro ET900N G3</strong> </h3>



<p>This is the gap the <strong>ASUS ExpertCenter Pro ET900N G3</strong> is engineered to close. Built on NVIDIA DGX Station architecture and powered by the NVIDIA GB300 Grace Blackwell Ultra Desktop Superchip, it brings data-center-class AI to a system that fits on a standard desk — a deskside AI supercomputer purpose-built for the way AI teams actually work. </p>



<p>What that delivers, mapped to the friction it removes: </p>



<ul class="wp-block-list">
<li><strong>Run the big models locally.</strong> With 748GB of coherent unified memory and up to 20 PFLOPS of AI performance, the ET900N G3 can develop and run trillion-parameter models and autonomous AI agents right at the deskside — far beyond the reach of a conventional workstation, and without a trip to a shared cluster. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Keep sensitive work private.</strong> Because the compute lives where the team and the data do, sensitive and regulated workloads can stay on-premises under the organization’s own governance. Full compatibility with NVIDIA AI Enterprise and NVIDIA NemoClaw enables enterprises to build and run always-on AI assistants and agents within a secure, local environment. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Iterate without waiting.</strong> A 72-core NVIDIA Grace CPU paired with an NVIDIA Blackwell Ultra GPU over high-bandwidth NVLink-C2C interconnect puts supercomputer-class iteration at a developer’s fingertips — no queue, no cold start, no round-trip. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Scale out when you need to.</strong> An integrated NVIDIA ConnectX-8 SuperNIC provides up to 800 Gbps of networking, so the deskside system bridges cleanly to data center infrastructure when a workload outgrows the desk. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Run it around the clock.</strong> Data-center-grade thermal design built for sustained 24/7 operation means the system maintains peak performance through long training and inference runs rather than throttling when the work gets serious. </li>
</ul>



<p>And it runs the NVIDIA AI software stack out of the box, giving development teams a turnkey environment for training, fine-tuning, inference, and agentic AI from day one. </p>



<h3 class="wp-block-heading"><strong>The question worth asking now</strong> </h3>



<p>For years, the strategic question in AI infrastructure was <em>how big a cluster can we reach.</em> For a growing share of the work that actually moves a business forward, the better question is: how close can we put the power in the hands of<em> the people doing the work?</em> </p>



<p>The idea was never the bottleneck. The distance was. Closing it is the next advantage. </p>



<p>Discover how the ASUS ExpertCenter Pro ET900N G3 brings data-center-class AI to the deskside. Visit us <a href="https://url.usb.m.mimecastprotect.com/s/EeB2Cxo0l0UrX9KNIvh9cyHZgE?domain=asus.com" target="_blank" rel="sponsored">here</a> to learn more.  </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (389-ds-base, aardvark-dns, buildah, compat-openssl10, freeipmi, frr, gnutls, grafana, grafana-pcp, kernel, kernel-rt, libyang, nginx, openexr, pcs, perl-HTTP-Daemon, postgresql:18, python3.14-pip, skopeo, tomcat9, and wireshark), Debian (chromium an...]]></description>
<link>https://tsecurity.de/de/3657135/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657135/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 09 Jul 2026 15:09:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (389-ds-base, aardvark-dns, buildah, compat-openssl10, freeipmi, frr, gnutls, grafana, grafana-pcp, kernel, kernel-rt, libyang, nginx, openexr, pcs, perl-HTTP-Daemon, postgresql:18, python3.14-pip, skopeo, tomcat9, and wireshark), <b>Debian</b> (chromium and pgextwlist), <b>Fedora</b> (openssh, opkssh, perl-CSS-Minifier-XS, python-jiter, python-nh3, python-pendulum, rust-jiter, and upower), <b>Mageia</b> (openvpn and vips), <b>Oracle</b> (389-ds-base, aardvark-dns, compat-openssl10, container-tools:ol8, freeipmi, kernel, libyang, perl-HTTP-Daemon, python3.14-pip, and skopeo), <b>Slackware</b> (libXfont2, proftpd, and xorg-server), <b>SUSE</b> (alloy, apache2, apptainer, assimp, chromium, clamav, docker, docker-compose, dracut, glib-networking, go-sendxmpp, go1.26-openssl, gstreamer-plugins-good, haproxy, hauler, jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent, kernel, krb5, kubevirt, libslirp, libXfont2, mpv, libkpipewirerecord6, ffmpegthumbs-kf5, netty, netty-tcnative, openqa, os-autoinst, podman, python-maturin, python-msgpack, python313-yt-dlp, radare2, rust-keylime, systemd, systemd, systemd-mini, tomcat11, trivy, xorg-x11-server, and xwayland), and <b>Ubuntu</b> (apache2, clamav, linux-raspi, and mailcap).]]></content:encoded>
</item>
<item>
<title><![CDATA[Need help get out tutorial hell. Develop pwn CTF skills, build a foundation in Vuln Exploit, RE, etc]]></title>
<description><![CDATA[Hi guys, recently Im in a loop, hop on and off different site different courses in and out, back and forth while feeling making ZERO progress.  Here, I want to share a bit about my goal, my background, my problem. And I hope I could have some advices to get out of this feeling MY GOAL: - Long ter...]]></description>
<link>https://tsecurity.de/de/3655757/malware-trojaner-viren/need-help-get-out-tutorial-hell-develop-pwn-ctf-skills-build-a-foundation-in-vuln-exploit-re-etc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655757/malware-trojaner-viren/need-help-get-out-tutorial-hell-develop-pwn-ctf-skills-build-a-foundation-in-vuln-exploit-re-etc/</guid>
<pubDate>Thu, 09 Jul 2026 04:03:07 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi guys, recently Im in a loop, hop on and off different site different courses in and out, back and forth while feeling making ZERO progress. </p> <p>Here, I want to share a bit about my goal, my background, my problem. And I hope I could have some advices to get out of this feeling</p> <p><strong>M</strong><strong>Y GOAL:</strong><br> - Long term: Get into cybersecurity field, especially roles that involve “low level” stuffs as I really interested in them. Thats it! For now, as Im pretty new to this + Im hyper focus on short term goal which I will talk right after<br> - Short term goal: Build foundation, knowledge, skills in Reverse Engineering (RE) and more excitingly Binary Exploitation, Pwn<br> - Shorter term goal: To prepare for upcoming CTF contests with my new team. More on this later </p> <p><strong>MY BACKGROUND:</strong><br> - I already familiar with Linux, CLI, some popular commands<br> - I know x86 assembly<br> - know C, C++<br> - know on surface level some basic vulnerabilities and have done very simple CTF challenges (ret2win, shellcode easy, …)<br> - do know how to use basic gdb, pwntools, ida/ghidra</p> <p>all of that is a result of following pwn.college + using Linux as daily basis + my college’s teaching on c, c++, etc</p> <p>by all means, I do not master any of these above skills I told. </p> <p><strong>MY PROBLEMS:</strong><br> So ofc Im very worrying the most about the upcoming CTF because Im new and feel like know nothing yet.<br> I also stucking into tutorial hell as I have too many resources of documentation/courses that I do not know which one is suit for my current situation </p> <p>Im aware of the pinning post in this sub, that is actually where I get these resources from</p> <p>But with 2 months left until the contest, I really want to make the most out of my time. So I need help with designing a road map so to speak.</p> <p>Currently, Im looking into ironstone’s pwn notes + Nightmare CTF collection. Whatd you recommend? </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/minhincs"> /u/minhincs </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqpb3o/need_help_get_out_tutorial_hell_develop_pwn_ctf/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1uqpb3o/need_help_get_out_tutorial_hell_develop_pwn_ctf/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to release delayed models Thursday amidst a sea of regulatory confusion]]></title>
<description><![CDATA[As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.



Initially, the US gov...]]></description>
<link>https://tsecurity.de/de/3655253/ai-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655253/ai-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</guid>
<pubDate>Wed, 08 Jul 2026 21:03:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.</p>



<p>Initially, the US government said that it was asking OpenAI to <a href="https://www.infoworld.com/article/4190089/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model-2.html" target="_blank">limit access to its top models</a>, including the three releasing Thursday, to a short list of companies. OpenAI seemingly agreed and held back their general availability.</p>



<p>But on Wednesday, OpenAI reversed its position, with <a href="https://x.com/OpenAI/status/2074704958419792299?s=20" target="_blank" rel="noreferrer noopener">a statement on X</a> saying simply: “GPT-5.6 Sol, along with Terra and Luna, will launch publicly this Thursday. We’re expanding preview access globally now.” No details were released about the extent of the expansion.</p>



<p>Then the White House issued a statement, a copy of which it emailed to <em>InfoWorld</em>, saying that the US government “did not give OpenAI a ‘green light,’ approval or clearance to release its models. No such permission is required or granted. The Administration does not provide approvals for private companies to release AI models – decisions on timing and scope of releases rest entirely with the companies.”</p>



<p>The statement then quoted from the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" target="_blank" rel="noreferrer noopener">June 2 White House executive order</a> that said, “nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” It also said, “any testing or meetings with government experts is voluntary. Participation is not required to release a model.”</p>



<p>Yet last month, the US Commerce Department weighed in <a href="https://www.cio.com/article/4186429/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to.html" target="_blank">on how Anthropic’s models can be distributed</a>. </p>



<h2 class="wp-block-heading">The ‘worst of both worlds’</h2>



<p><a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of software development firm Comp AI, said the statement is frustrating for IT executives on multiple fronts. </p>



<p>“Think about what that [White House statement] means. OpenAI stationed engineers in Washington for weeks, submitted to government testing, staggered its launch at the government’s request. And the official position is that none of that was required,” Carhart said. “We now have a de facto licensing regime that legally doesn’t exist. There’s no statute, no appeal process, no published criteria. Just [the US Department of] Commerce deciding model by model what ships and when.”</p>



<p>That’s the worst of both worlds, he noted: “All the friction of regulation with none of the predictability. Compliance people have a name for this – it’s an audit with no framework. And the precedent is now locked in for both frontier labs: if you build at the frontier, your launch calendar runs through Washington whether the law says so or not.”</p>



<p>Carhart argued that this regulatory reality should be of extreme concern to enterprise IT executives, given it indicates that model availability is now “a regulatory variable” not driven by the vendor roadmap.</p>



<p>“Anthropic’s most advanced models disappeared from the market for three weeks in June. It was not because of an outage, not because of a pricing change. It was because of an export control directive,” he pointed out. “If your AI architecture assumes the model you deployed today is available tomorrow, that assumption is now demonstrably false. Multi-model resilience just went from nice to have to a board-level risk item.”</p>



<p>It also offers an opportunity, given that a model that cleared government security testing is a model that auditors and boards sign off on faster. “Government review is quietly becoming a procurement asset,” he observed. “The CIOs who win here are the ones who treat ‘regulatory posture of the model itself’ as a line item in vendor risk assessments – most risk teams are still only looking at the provider’s SOC 2 attestation.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, agreed with Carhart and described the overall back-and-forth as “a bit of pageantry. OpenAI needs its model to look as powerful, potentially dangerous, as Anthropic’s so it can be a contender to be at the absolute frontier. It also helps to burnish OpenAI’s PR efforts to look more responsible than it has in the past.”</p>



<p>Furthermore, he added, “tech CEOs are acutely aware that flattery towards this administration could keep regulators or the threat of regulation at bay.”</p>



<h2 class="wp-block-heading">Criteria not clear</h2>



<p><a href="https://www.infotech.com/profiles/brian-jackson" target="_blank" rel="noreferrer noopener">Brian Jackson</a>, a principal research director at Info-Tech Research Group, echoed the political concerns. </p>



<p>“What’s still not clear is the actual criteria being used to deem the models safe for release. The government has said that it’s concerned about cybersecurity risk as well as the risk of AI being used to develop biological weapons,” he said. “But so long as the actual release criteria lack transparency, there will be some perception that the evaluation could be politically motivated.”</p>



<p>Jackson said that one, presumably unintended, result of the US government’s efforts to control AI rollouts is that it is making companies look far more seriously at using non-US vendors for AI strategies. </p>



<p>“Organizations are looking for alternatives to the private US-based cloud-delivered frontier models. That’s so they can maintain control over their AI supply chain,” he said. “Chinese open source models are one option that’s available, but there are other options too, from Canada and Europe. Companies can either set up AI access through other APIs not connected to US-based AI providers, or download open-source models to run locally.”</p>



<p>He noted that the added US regulatory risk means that some organizations will avoid becoming entrenched within OpenAI’s and Anthropic’s interfaces, where there’s no option to swap out the LLMs for an alternative.</p>



<h2 class="wp-block-heading">Impacts enterprise AI strategy</h2>



<p><a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity, shared the frustration that little to no actionable compliance data is being released. </p>



<p>“Nobody outside a closed room can tell you what standard [the model] passed because it was never written down. For two weeks, [US government officials] kept a model out of defenders’ hands that’s better at guarding your network than breaking into anyone else’s,” Lambros said. “Call that a security review if it helps you sleep better. But it reads to me like a bouncer working a velvet rope nobody hired him to run, waving people through today because he’s in a better mood than he was a couple of weeks ago.”</p>



<p>This unpredictability is likely to have impacts on AI strategy far beyond traditional compliance concerns, Lambros said.</p>



<p>“We’ve built way too much operational reliance on these models to hang it on a review with no rulebook,” he said, pointing out that hospitals, pipelines, banks and water utilities are relying on frontier AI whose availability “can swing from ‘on’ to ‘off’ to ‘on’ with no notice, no appeal, and no published standard behind any of it.”</p>



<p>“You can’t run critical infrastructure on a tool that runs fine Friday and is offline by Monday because an approval process nobody can see reached a verdict nobody can predict,” Lambros said. “That is a supply chain risk with a government hand on the switch, and almost nobody has priced it into a continuity plan.”</p>



<p>To protect themselves, companies need to adjust their expectations. “Treat model availability like any single point of failure you don’t own by standing up a fallback you’ve tested, getting a continuity clause in your contract, and drilling for the blackout, because ‘the government backed off this time’ is not a plan,” he advised.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI to release delayed models Thursday amidst a sea of regulatory confusion]]></title>
<description><![CDATA[As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.



Initially, the US gov...]]></description>
<link>https://tsecurity.de/de/3655243/it-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655243/it-nachrichten/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion/</guid>
<pubDate>Wed, 08 Jul 2026 21:02:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises struggle to manage their AI strategies, the US AI regulatory environment is sending a wide range of contradictory signals. OpenAI’s Wednesday announcement that it will now release GPT-5.6 Sol, along with Terra and Luna, on Thursday highlights the confusion.</p>



<p>Initially, the US government said that it was asking OpenAI to <a href="https://www.infoworld.com/article/4190089/us-tells-openai-to-restrict-access-to-its-most-powerful-ai-model-2.html" target="_blank">limit access to its top models</a>, including the three releasing Thursday, to a short list of companies. OpenAI seemingly agreed and held back their general availability.</p>



<p>But on Wednesday, OpenAI reversed its position, with <a href="https://x.com/OpenAI/status/2074704958419792299?s=20" target="_blank" rel="noreferrer noopener">a statement on X</a> saying simply: “GPT-5.6 Sol, along with Terra and Luna, will launch publicly this Thursday. We’re expanding preview access globally now.” No details were released about the extent of the expansion.</p>



<p>Then the White House issued a statement, a copy of which it emailed to <em>InfoWorld</em>, saying that the US government “did not give OpenAI a ‘green light,’ approval or clearance to release its models. No such permission is required or granted. The Administration does not provide approvals for private companies to release AI models – decisions on timing and scope of releases rest entirely with the companies.”</p>



<p>The statement then quoted from the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" target="_blank" rel="noreferrer noopener">June 2 White House executive order</a> that said, “nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” It also said, “any testing or meetings with government experts is voluntary. Participation is not required to release a model.”</p>



<p>Yet last month, the US Commerce Department weighed in <a href="https://www.cio.com/article/4186429/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to.html" target="_blank">on how Anthropic’s models can be distributed</a>. </p>



<h2 class="wp-block-heading">The ‘worst of both worlds’</h2>



<p><a href="https://www.linkedin.com/in/lewiscarhart/" target="_blank" rel="noreferrer noopener">Lewis Carhart</a>, CEO of software development firm Comp AI, said the statement is frustrating for IT executives on multiple fronts. </p>



<p>“Think about what that [White House statement] means. OpenAI stationed engineers in Washington for weeks, submitted to government testing, staggered its launch at the government’s request. And the official position is that none of that was required,” Carhart said. “We now have a de facto licensing regime that legally doesn’t exist. There’s no statute, no appeal process, no published criteria. Just [the US Department of] Commerce deciding model by model what ships and when.”</p>



<p>That’s the worst of both worlds, he noted: “All the friction of regulation with none of the predictability. Compliance people have a name for this – it’s an audit with no framework. And the precedent is now locked in for both frontier labs: if you build at the frontier, your launch calendar runs through Washington whether the law says so or not.”</p>



<p>Carhart argued that this regulatory reality should be of extreme concern to enterprise IT executives, given it indicates that model availability is now “a regulatory variable” not driven by the vendor roadmap.</p>



<p>“Anthropic’s most advanced models disappeared from the market for three weeks in June. It was not because of an outage, not because of a pricing change. It was because of an export control directive,” he pointed out. “If your AI architecture assumes the model you deployed today is available tomorrow, that assumption is now demonstrably false. Multi-model resilience just went from nice to have to a board-level risk item.”</p>



<p>It also offers an opportunity, given that a model that cleared government security testing is a model that auditors and boards sign off on faster. “Government review is quietly becoming a procurement asset,” he observed. “The CIOs who win here are the ones who treat ‘regulatory posture of the model itself’ as a line item in vendor risk assessments – most risk teams are still only looking at the provider’s SOC 2 attestation.”</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, agreed with Carhart and described the overall back-and-forth as “a bit of pageantry. OpenAI needs its model to look as powerful, potentially dangerous, as Anthropic’s so it can be a contender to be at the absolute frontier. It also helps to burnish OpenAI’s PR efforts to look more responsible than it has in the past.”</p>



<p>Furthermore, he added, “tech CEOs are acutely aware that flattery towards this administration could keep regulators or the threat of regulation at bay.”</p>



<h2 class="wp-block-heading">Criteria not clear</h2>



<p><a href="https://www.infotech.com/profiles/brian-jackson" target="_blank" rel="noreferrer noopener">Brian Jackson</a>, a principal research director at Info-Tech Research Group, echoed the political concerns. </p>



<p>“What’s still not clear is the actual criteria being used to deem the models safe for release. The government has said that it’s concerned about cybersecurity risk as well as the risk of AI being used to develop biological weapons,” he said. “But so long as the actual release criteria lack transparency, there will be some perception that the evaluation could be politically motivated.”</p>



<p>Jackson said that one, presumably unintended, result of the US government’s efforts to control AI rollouts is that it is making companies look far more seriously at using non-US vendors for AI strategies. </p>



<p>“Organizations are looking for alternatives to the private US-based cloud-delivered frontier models. That’s so they can maintain control over their AI supply chain,” he said. “Chinese open source models are one option that’s available, but there are other options too, from Canada and Europe. Companies can either set up AI access through other APIs not connected to US-based AI providers, or download open-source models to run locally.”</p>



<p>He noted that the added US regulatory risk means that some organizations will avoid becoming entrenched within OpenAI’s and Anthropic’s interfaces, where there’s no option to swap out the LLMs for an alternative.</p>



<h2 class="wp-block-heading">Impacts enterprise AI strategy</h2>



<p><a href="https://zenity.io/authors/rock-lambros" target="_blank" rel="noreferrer noopener">Rock Lambros</a>, director of AI standards and governance at AI agent vendor Zenity, shared the frustration that little to no actionable compliance data is being released. </p>



<p>“Nobody outside a closed room can tell you what standard [the model] passed because it was never written down. For two weeks, [US government officials] kept a model out of defenders’ hands that’s better at guarding your network than breaking into anyone else’s,” Lambros said. “Call that a security review if it helps you sleep better. But it reads to me like a bouncer working a velvet rope nobody hired him to run, waving people through today because he’s in a better mood than he was a couple of weeks ago.”</p>



<p>This unpredictability is likely to have impacts on AI strategy far beyond traditional compliance concerns, Lambros said.</p>



<p>“We’ve built way too much operational reliance on these models to hang it on a review with no rulebook,” he said, pointing out that hospitals, pipelines, banks and water utilities are relying on frontier AI whose availability “can swing from ‘on’ to ‘off’ to ‘on’ with no notice, no appeal, and no published standard behind any of it.”</p>



<p>“You can’t run critical infrastructure on a tool that runs fine Friday and is offline by Monday because an approval process nobody can see reached a verdict nobody can predict,” Lambros said. “That is a supply chain risk with a government hand on the switch, and almost nobody has priced it into a continuity plan.”</p>



<p>To protect themselves, companies need to adjust their expectations. “Treat model availability like any single point of failure you don’t own by standing up a fallback you’ve tested, getting a continuity clause in your contract, and drilling for the blackout, because ‘the government backed off this time’ is not a plan,” he advised.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4194598/openai-to-release-delayed-models-thursday-amidst-a-sea-of-regulatory-confusion.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, kernel-rt, libreoffice, nodejs:22, nodejs:24, opentelemetry-collector, perl-HTTP-Daemon, and python-markdown), Debian (dpkg, imagemagick, and postfix), Fedora (betterleaks, docker-compose, firefox, helm, perl-Compress-Raw-Bzip...]]></description>
<link>https://tsecurity.de/de/3654344/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654344/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 08 Jul 2026 14:53:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, kernel-rt, libreoffice, nodejs:22, nodejs:24, opentelemetry-collector, perl-HTTP-Daemon, and python-markdown), <b>Debian</b> (dpkg, imagemagick, and postfix), <b>Fedora</b> (betterleaks, docker-compose, firefox, helm, perl-Compress-Raw-Bzip2, perl-IO-Compress, perl-JavaScript-Minifier-XS, python-cramjam, python-fastar, python-pillow-jxl-plugin, python-rignore, and tor), <b>Oracle</b> (grafana, grafana-pcp, and ruby:4.0), <b>Slackware</b> (tftp), <b>SUSE</b> (gi-docgen, glibc, helm, helm3, json-c-devel, kubevirt-1.6, librpmbuild10, python313-dulwich, python313-lxml_html_clean, python313-openapi-spec-validator, and sdbootutil), and <b>Ubuntu</b> (ruby-addressable).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in tftp-hpa (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3653270/it-security-nachrichten/mehrere-probleme-in-tftp-hpa-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653270/it-security-nachrichten/mehrere-probleme-in-tftp-hpa-slackware/</guid>
<pubDate>Wed, 08 Jul 2026 06:54:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651654/ai-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651654/ai-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 15:19:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="noreferrer noopener">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<h3 class="wp-block-heading"><strong>Transaction and Operational Highlights</strong></h3>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="noreferrer noopener">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="noreferrer noopener">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651645/it-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651645/it-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 15:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="noreferrer noopener">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<h3 class="wp-block-heading"><strong>Transaction and Operational Highlights</strong></h3>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="noreferrer noopener">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="noreferrer noopener">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (nodejs22 and nodejs24), Fedora (clamav, hplip, kernel, kernel-headers, librabbitmq, mingw-expat, mir, perl-Imager, podman-tui, prometheus-podman-exporter, python-rpds-py, rust-ashpd, rust-busd, rust-gtk4-macros, rust-inferno, rust-quick-xml, rust-re...]]></description>
<link>https://tsecurity.de/de/3651621/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651621/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 07 Jul 2026 15:11:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (nodejs22 and nodejs24), <b>Fedora</b> (clamav, hplip, kernel, kernel-headers, librabbitmq, mingw-expat, mir, perl-Imager, podman-tui, prometheus-podman-exporter, python-rpds-py, rust-ashpd, rust-busd, rust-gtk4-macros, rust-inferno, rust-quick-xml, rust-reqsign-aws-v4, rust-wayland-scanner, and sandogasa), <b>Oracle</b> (container-tools:rhel8, kernel, mariadb:10.11, mariadb:11.8, nginx, perl:5.32, php, php:7.4, rrdtool, ruby:2.5, ruby:3.3, ruby:4.0, and uek-kernel), <b>Red Hat</b> (kernel, opentelemetry-collector, and python-urllib3), <b>Slackware</b> (c and openssh), <b>SUSE</b> (bind, chromedriver, cryptsetup, s390-tools, dnsmasq, jackson-annotations, jackson-core, jackson-databind, lcms2, pacemaker, perl-Cpanel-JSON-XS, perl-Crypt-SaltedHash, postfix, and python-mistune), and <b>Ubuntu</b> (gnutls28, gzip, openssh, php7.0, python-parsl, python3.10, python3.12, python3.14, request-tracker5, socat, sogo, and tar).]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651613/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651613/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 15:09:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="noreferrer noopener">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<h3 class="wp-block-heading"><strong>Transaction and Operational Highlights</strong></h3>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="noreferrer noopener">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="noreferrer noopener">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity]]></title>
<description><![CDATA[Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.



Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of ...]]></description>
<link>https://tsecurity.de/de/3651556/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651556/it-security-nachrichten/envirotech-vehicles-closes-merger-with-azio-ai-ahead-of-schedule-positioning-combined-company-to-capture-487-billion-2026-ai-infrastructure-opportunity/</guid>
<pubDate>Tue, 07 Jul 2026 14:52:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure.</em></p>



<p><a href="https://www.evtvusa.com/" target="_blank" rel="sponsored">Envirotech Vehicles</a>, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company to transform to an AI Datacenter Provider and meeting the growing market demand for artificial intelligence (“AI”) infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; a market that the International Data Corporation (IDC) projects will reach $487 billion in global spending in 2026 and exceed $1 trillion by 2029.<a href="http://docs.google.com/blank" rel="sponsored">[1]</a> The transaction marks a defining milestone in the Company’s strategic transformation and establishes the foundation for its next phase of commercial execution and long-term growth.</p>



<p>The parties amended the proposed transaction structure to expedite the closing timeline, allowing the combined company to begin operating as a fully integrated public company significantly sooner than originally anticipated. The accelerated closing enables management to immediately focus on commercialization across its expanding AI Datacenter strategy.</p>



<p>With the merger complete and the combined company operating as one organization, management is now fully focused on commercial execution, infrastructure deployment, strategic growth initiatives, and creating long-term shareholder value.</p>



<p>Over the past several months, the Company advanced development activities at its South Texas site and deployed six megawatts of off-grid power for its modular data centers. The Company further secured rights to a 548-acre site with the capacity to scale up to 500 MW, supporting the future development of AI hyperscale data centers.</p>



<p>Management believes these achievements demonstrate that the combined company is entering its next phase with meaningful operational momentum already in place rather than beginning from a standing start. Infrastructure deployment is underway, customer commitments have already been established, commercial execution is actively progressing, and the Company’s corporate structure is now aligned with an operating platform built to support long-term expansion.</p>



<p>The completion of the merger comes at a time when investment in AI infrastructure continues to accelerate globally as enterprises increasingly require access to high-performance computing resources, GPU infrastructure, and scalable digital power solutions. Management believes the combined company is well positioned to capitalize on these long-term industry trends through a diversified infrastructure strategy designed to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations.</p>



<p>Following the closing of the transaction, the Company intends to continue expanding its AI Infrastructure strategy through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships designed to maximize utilization of its power resources while creating multiple long-term revenue opportunities.</p>



<p>In connection with the closing of the merger, Phillip Oldridge has stepped down as Chief Executive Officer. Jason Maddox vacates the President position and is now the Chief Financial Officer. The Company’s Board of Directors appointed Simon Yu as President and Chris Young as Chief Executive Officer, effective immediately.</p>



<p>Mr. Yu is a serial entrepreneur and public markets operator with almost a decade of experience taking companies public, executing capital raises, and scaling businesses. He has previously served in founder, C-suite, and board roles at three publicly traded companies, two of which reached market capitalizations in excess of $1 billion. Mr. Yu has led legal, accounting, and advisory teams through Regulation A+ Tier 2 offerings, PCAOB audits, and public company reporting, alongside leading M&amp;A transactions. As an active early-stage venture investor, he has evaluated investment opportunities across artificial intelligence, SaaS, and B2B technology.</p>



<p>Mr. Young brings extensive experience in launching and leading public companies and investing in and advising emerging technology companies, with a particular focus on artificial intelligence, software innovation, and strategic growth initiatives. Prior to joining EVTV, he served as Chief Executive Officer of Clubhouse Media Group, a publicly traded social media company and an Entrepreneur in Residence at Amplify, where he worked alongside founders and venture-backed technology companies to accelerate commercialization and support the development of high-growth technology businesses.</p>



<p>“Today’s announcement represents far more than the completion of a merger—it marks the beginning of our next chapter,” said Chris Young, Chief Executive Officer of EVTV. “Over the past several months, our teams have been building the operational foundation of this business while simultaneously working toward completing this transaction. With the merger now finalized, we move forward as one company with one leadership team and one strategy, focused on executing against the opportunities in front of us. We believe demand for AI infrastructure, enterprise compute, and digital infrastructure will continue expanding for years to come. Our objective is to build a scalable platform capable of serving that demand while creating long-term value for our shareholders.”</p>



<p>Jason Maddox, Chief Financial Officer of EVTV, added, “Completing this transaction under the amended merger structure allows us to immediately focus on execution. We have already established meaningful operational momentum, and we believe operating as a unified public company enhances our ability to deploy infrastructure, serve customers, pursue strategic growth opportunities, and continue building long-term shareholder value.”</p>



<p>The transaction establishes a unified operating platform designed to support the Company’s long-term growth strategy through continued investment in AI infrastructure, enterprise computing, digital power assets, and digital infrastructure development. Management believes the completion of the merger provides the operational and organizational foundation necessary to pursue the next phase of commercialization while expanding its presence across some of the fastest-growing sectors of the global technology market.</p>



<p><strong>Transaction and Operational Highlights</strong></p>



<ul class="wp-block-list">
<li>Successfully completed the merger with Azio AI pursuant to an amended and restated merger agreement.</li>



<li>Approximately six megawatts of off-grid digital infrastructure deployed at the Company’s South Texas development site.</li>



<li>Development footprint exceeding 548 acres with the potential to support up to 500 MW of AI infrastructure capacity.</li>



<li>Combined company positioned to accelerate commercialization across AI infrastructure, enterprise GPU compute, digital power solutions, and digital asset mining operations.</li>



<li>Merger consideration consisted of 2,655,157 shares of common stock and 973,450 shares of non-voting convertible preferred stock in exchange for 100% of outstanding capital stock of Azio AI, of which 194,807 shares of common stock were reserved for convertible notes of Azio AI assumed by the Company upon closing.</li>



<li>Each share of preferred stock convertible into 100 shares of Company common stock subject to stockholder approval.</li>



<li>Chris Young appointed Chief Executive Officer and Chairman of the Board.</li>



<li>Simon Yu appointed President.</li>



<li>Jason Maddox appointed Chief Financial Officer.</li>



<li>Phillip Oldridge stepped down as Chief Executive Officer.</li>
</ul>



<p><strong>About Envirotech Vehicles, Inc.</strong></p>



<p>Envirotech Vehicles, Inc. (NASDAQ: EVTV) is a technology infrastructure company focused on developing, owning, and operating artificial intelligence data centers, enterprise GPU compute infrastructure, digital power solutions, and digital asset mining operations. Following its acquisition of Azio AI, the Company operates an integrated AI infrastructure business encompassing AI data center development, the sale and distribution of enterprise GPU systems and server infrastructure, high-performance computing solutions, power hosting, and strategic technology investments, serving enterprise and institutional customers across domestic and international markets. Through this diversified AI infrastructure strategy, the Company is positioned to capitalize on the rapidly expanding global demand for AI infrastructure, compute capacity, digital power, and next-generation AI technologies.</p>



<p>For more information please visit: <a href="http://www.azioai.ai/" target="_blank" rel="sponsored">www.azioai.ai</a> and for potential partnerships contact: <a href="mailto:AI@PhoenixMGMTconsulting.com" target="_blank" rel="sponsored">AI@PhoenixMGMTconsulting.com</a></p>



<p><strong>Forward-Looking Statements</strong></p>



<p>This press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. In some cases, you can identify forward-looking statements by words such as “may,” “will,” “could,” “expect,” “anticipate,” “believe,” “estimate,” “project,” “intend,” “continue,” “potential,” “ongoing,” or the negative of these terms or other comparable terminology, although not all forward-looking statements contain these words. Forward-looking statements include statements regarding the Company’s ability to capitalize on accelerating demand for AI infrastructure, enterprise GPU compute, digital power solutions, data center development, and digital asset infrastructure; the Company’s plans to continue expanding its digital infrastructure platform through AI data center development, enterprise GPU compute solutions, power hosting services, digital asset mining operations, strategic infrastructure investments, and additional commercial partnerships; the Company’s ability to maximize utilization of its power resources while creating multiple long-term revenue opportunities; the ability to continue deploying modular digital infrastructure at the Company’s South Texas site; the anticipated deployment and scaling of NVIDIA B200 and B300 GPU systems; the ability to advance and execute against the Company’s commercial infrastructure pipeline; the anticipated development of the Company’s footprint; the ability to monetize power assets across multiple complementary revenue streams, including AI data centers, enterprise compute infrastructure, power hosting, and digital asset mining operations; customer demand for AI infrastructure, enterprise compute, and digital infrastructure; the Company’s ability to build a scalable platform designed to serve that demand and create long-term shareholder value; and the Company’s broader business strategy and long-term growth objectives.</p>



<p>These statements are based on current expectations and assumptions that involve risks and uncertainties that could cause actual results to differ materially. Most of these factors are outside the Company’s control and are difficult to predict. Factors that may affect actual results include, but are not limited to, the Company’s limited operating history within AI infrastructure and compute operations, project scope, engineering challenges, supply chain constraints, installation timelines, energy availability, finalization of site usage rights, regulatory considerations, equipment performance, ability to raise capital required for expansion activities, changes in digital asset markets, evolving compute demand, market conditions, the Company’s ability to successfully integrate the combined business following the completion of the merger, the risk that the anticipated benefits and synergies of the merger are not realized, the risk of unexpected costs, charges, or expenses resulting from or relating to the merger, potential adverse reactions or changes to business relationships resulting from the completion of the merger, risks related to the diversion of management’s attention from ongoing business operations during the post-closing integration period, the risk that required stockholder approval for the conversion of preferred stock issued in the merger as required by rules of The Nasdaq Stock Market LLC (the “Conversion Proposal”) is not obtained, and additional risks and uncertainties described in the Company’s most recent Annual Report on Form 10-K and subsequent Quarterly Reports on Form 10-Q filed with the SEC, which are available at www.sec.gov. The Company undertakes no obligation to update forward-looking statements except as required by law.</p>



<p><strong><em>Important Information About the Merger and Where to Find it</em></strong></p>



<p>The Company expects to file a proxy statement with the SEC relating to the Conversion Proposal. The definitive proxy statement will be sent to all Company stockholders. Before making any voting decision, investors and security-holders of the Company are urged to read the proxy statement and all other relevant documents filed or that will be filed with the SEC in connection with the Conversion Proposal as they become available because they will contain important information about the amended and restated merger agreement between the parties and the related transactions and the Conversion Proposal to be voted upon by the Company’s stockholders. Investors and security-holders will be able to obtain free copies of the proxy statement and all other relevant documents filed or that will be filed with the SEC by the Company through the website maintained by the SEC at www.sec.gov.</p>



<p><strong><em>Participants in the Solicitation</em></strong></p>



<p>The Company and its directors and executive officers may be considered participants in the solicitation of proxies from EVTV’s stockholders with respect to the Conversion Proposal under the rules of the SEC. Information about the directors and executive officers of EVTV is set forth in its Annual Report on Form 10-K for the year ended December 31, 2025, which was filed with the SEC on April 13, 2026, and in subsequent Quarterly Reports on Form 10-Q and other documents filed by the Company from time to time with the SEC. Additional information regarding the persons who may be deemed participants in the proxy solicitation and a description of their direct and indirect interests, by security holdings or otherwise, will also be included in the proxy statement, and other relevant materials to be filed with the SEC when they become available. You may obtain free copies of these documents as described above.</p>



<p>¹ Source: International Data Corporation (IDC), “AI Infrastructure Spending Caps Historic Year at ~$90 Billion in Q4 2025; 2029 Spending to Eclipse $1 Trillion,” April 16, 2026. The Company has not independently verified the data or projections contained in this report, and there can be no assurance that the projections will be realized.</p>



<h5 class="wp-block-heading">Contact</h5>



<p><strong>Phoenix MGMT &amp; Consulting</strong></p>



<p><strong>Press@PhoenixMGMTConsulting.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in c-ares (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3650575/unix-server/security-ausfuehren-beliebiger-kommandos-in-c-ares-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650575/unix-server/security-ausfuehren-beliebiger-kommandos-in-c-ares-slackware/</guid>
<pubDate>Tue, 07 Jul 2026 07:46:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in openssh (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3650571/unix-server/security-mehrere-probleme-in-openssh-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650571/unix-server/security-mehrere-probleme-in-openssh-slackware/</guid>
<pubDate>Tue, 07 Jul 2026 07:46:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in php82 (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3649904/unix-server/security-ausfuehren-beliebiger-kommandos-in-php82-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649904/unix-server/security-ausfuehren-beliebiger-kommandos-in-php82-slackware/</guid>
<pubDate>Mon, 06 Jul 2026 23:32:08 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Operationalizing Agentic AI: from assisted to autonomous]]></title>
<description><![CDATA[Ever since ChatGPT made its public debut nearly four years ago, governance and security have largely lagged behind AI adoption.



Eager to experiment with AI tools and find ways to improve their work and personal lives, users have uploaded corporate data, financial records, and even their own he...]]></description>
<link>https://tsecurity.de/de/3649123/it-security-nachrichten/operationalizing-agentic-ai-from-assisted-to-autonomous/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649123/it-security-nachrichten/operationalizing-agentic-ai-from-assisted-to-autonomous/</guid>
<pubDate>Mon, 06 Jul 2026 16:54:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ever since ChatGPT made its public debut nearly four years ago, governance and security have largely lagged behind AI adoption.</p>



<p>Eager to experiment with AI tools and find ways to improve their work and personal lives, users have uploaded corporate data, financial records, and even their own health information to large language models (LLMs). While this freewheeling activity presents obvious risks, many users and businesses have so far been spared from catastrophic consequences.</p>



<p>Stephen Wilson, field chief technology officer for HashiCorp, an IBM company, notes that most people are still using AI tools largely as “assistants,” with the technology only taking action at the direction of human users. But, as AI agents are given more ability to act on their own, the risk calculus is changing. And so far, Wilson says, security and governance practices aren’t keeping up.</p>



<p>“Right now, what’s happening is that organizations are starting to use AI tools as full partners but governing the tools the same way they did when they were only using them as assistants,” Wilson says. “When AI is an assistant, the user is very close to the execution, and they’re handing over API keys, social media credentials, and bank information. But now we’re starting to ask AI to do things on our behalf autonomously.”</p>



<p>As organizations move from assisted use cases toward more autonomous workflows, Wilson says, they need to mature their governance models across three common adoption patterns: AI as assistant, AI as an agent, and AI as operator.</p>



<h1 class="wp-block-heading">AI as assistant</h1>



<p>The most basic and widespread form of enterprise AI adoption is AI as an assistant. In this model, a human remains close to the work, using the technology to summarize information, draft content, generate code, and complete other discrete tasks. The user enters a prompt, evaluates the response, and decides what to do next.</p>



<p>Although humans remain close to the execution at this stage, activity is not free from risk. When users interact with AI assistants, they can easily bring sensitive data, credentials, or permissions with them into the workflow. A user with privileged access might paste an API key into a prompt or even ask an LLM to analyze confidential records.</p>



<p>“You need to have a very tight handoff from the human identity to the machine identity,” Wilson says. “You also need to be able to govern what that machine can access from a machine-to-service perspective, because if I get elevated privilege, it’s not hard to inject that privilege into the context window.”</p>



<p>At the assistant stage, organizations largely need to ensure that AI activity is governed by the same boundaries already established for users. But as AI moves from answering prompts to completing work, those governance boundaries must expand.</p>



<h1 class="wp-block-heading">AI as an agent</h1>



<p>At this stage, human users begin asking AI tools to complete certain tasks autonomously. For example, instead of going back and forth with an LLM to outline and draft a piece of content, a user might simply give an AI tool a set of inputs and basic instructions and then ask the tool to generate the piece on its own. In fact, the writing agent may even pass off the finished draft to an editing agent or other AI tools before coming back to a human user.</p>



<p>“When that happens, the governance controls and the identity and auditability have to go up because you’re moving the human out of the loop even more,” Wilson says. “With AI assistants, the human is still the initiator of the request that happens back and forth. But with AI as agent, you’re making a request and then just letting it run.”</p>



<p>At this stage, Wilson says, organizations must determine what level of access different agents need to complete certain tasks, as well as how to confer identity upon AI agents. “How do you manage the persona? How do you accelerate its ability to be more correct often? These are the things you have to think about as you start to move to AI as an agent.”</p>



<h1 class="wp-block-heading">AI as operator</h1>



<p>This is the stage where AI agents take on not just individual tasks but entire projects. Instead of prompting agentic tools to write and edit a single article, an organization might ask a team of AI agents to design and execute an entire marketing campaign.</p>



<p>“The human comes back in two or three hours and has the entire project, including where to publish, individual social media posts, and engagement strategies,” Wilson says. “The level of governance and identity and auditing have to increase as your level of oversight decreases.”</p>



<p>Wilson notes that it is important at this stage to establish strong governance not only around data access but also around accuracy. For example, if an AI agent creates social media content, the organization needs to know that the content uses approved messaging, moves through the right review process, and is published only through authorized channels.</p>



<p>This is a complex challenge because AI agents are probabilistic systems, while many enterprise workflows are deterministic. Before giving agents the power to complete these workflows, Wilson says, leaders must think carefully about where AI-generated work should end and controlled execution should begin.</p>



<h1 class="wp-block-heading">The road ahead</h1>



<p>Most organizations are only beginning to deploy agentic AI beyond the assistant stage, and Wilson notes that security leaders are still debating the right governance, identity, auditability, and observability models for these systems.</p>



<p>But the overarching governance demand is clear: As AI systems gain more autonomy, organizations must implement more rigorous controls. An AI assistant can be governed largely as an extension of the individual user. An AI agent must be governed as part of a team, with clear visibility into the work it performs and the systems it touches. And an AI operator must be governed as a business function, with controls that span data access, workflow execution, approvals, and audit trails.</p>



<p>“Your scope of governance, identity, and observability has to increase at the same rate as if you were moving from an individual to a team to an organization,” Wilson says. </p>



<p>To learn more, visit us <a href="https://url.usb.m.mimecastprotect.com/s/JmXpCVJDNDFOzA4ZfGf1cEukO9?domain=ibm.com">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, grafana, grafana-pcp, kernel, ruby:2.5, and ruby:3.3), Debian (bird3, chromium, kernel, linux-6.1, mediawiki, nginx, openvpn, php-phpseclib, php8.2, php8.4, and sympa), Fedora (7zip, buildah, chromium, clamav, freerdp, leptoni...]]></description>
<link>https://tsecurity.de/de/3648889/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648889/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 06 Jul 2026 15:41:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, grafana, grafana-pcp, kernel, ruby:2.5, and ruby:3.3), <b>Debian</b> (bird3, chromium, kernel, linux-6.1, mediawiki, nginx, openvpn, php-phpseclib, php8.2, php8.4, and sympa), <b>Fedora</b> (7zip, buildah, chromium, clamav, freerdp, leptonica, mariadb10.11, mariadb11.8, nextcloud, nsd, openqa, openvpn, os-autoinst, pdns, pdns-recursor, perl-Crypt-ScryptKDF, podman, python-jupyter-server, and python-streamlink), <b>Mageia</b> (mariadb and yt-dlp), <b>Slackware</b> (libevent, libseccomp, mozilla, mutt, and php82), <b>SUSE</b> (apache2, containerd, dnsmasq, docker, dracut, firewalld-legacy, gimp, glibc, golang-github-docker-libnetwork, google-guest-agent, gstreamer-plugins-bad, helm, kernel, kernel-devel, keybase-client, kitty, krb5, libarchive, libnfs, libslirp, nilfs-utils, openCryptoki, openQA, openssl-3, pacemaker, pcr-oracle, perl-DBI, perl-List-SomeUtils-XS, podman, python-pip, python-pydata-sphinx-theme, python-tornado6, python3-lxml, python311-mistune, python313-joserfc, rmt-server, sg3_utils, systemd, tracker-miners, and xdg-dbus-proxy), and <b>Ubuntu</b> (cifs-utils, linux-nvidia, linux-nvidia-6.17, linux-raspi-realtime, and ncurses).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zahlenüberlauf in mutt (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3647787/unix-server/security-zahlenueberlauf-in-mutt-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647787/unix-server/security-zahlenueberlauf-in-mutt-slackware/</guid>
<pubDate>Mon, 06 Jul 2026 07:16:48 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3647309/it-security-nachrichten/mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647309/it-security-nachrichten/mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Sun, 05 Jul 2026 23:22:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Mehrere Probleme in libseccomp (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3647306/it-security-nachrichten/mehrere-probleme-in-libseccomp-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647306/it-security-nachrichten/mehrere-probleme-in-libseccomp-slackware/</guid>
<pubDate>Sun, 05 Jul 2026 23:22:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Mehrere Probleme in libevent (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3647305/it-security-nachrichten/mehrere-probleme-in-libevent-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647305/it-security-nachrichten/mehrere-probleme-in-libevent-slackware/</guid>
<pubDate>Sun, 05 Jul 2026 23:22:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[PorteuX 2.6 Released with Linux 6.19, TLP Support, and Smarter Hardware Optimization]]></title>
<description><![CDATA[by George Whittaker
      
            The PorteuX project has officially released PorteuX 2.6, bringing a new round of updates to the lightweight Slackware-based Linux distribution. Designed to be fast, portable, modular, and immutable, PorteuX continues to appeal to users who want a complete de...]]></description>
<link>https://tsecurity.de/de/3644630/unix-server/porteux-26-released-with-linux-619-tlp-support-and-smarter-hardware-optimization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644630/unix-server/porteux-26-released-with-linux-619-tlp-support-and-smarter-hardware-optimization/</guid>
<pubDate>Sat, 04 Jul 2026 04:01:08 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-history-node-id="1341441" class="layout layout--onecol">
    <div class="layout__region layout__region--content">
      
            <div class="field field--name-field-node-image field--type-image field--label-hidden field--item">  <img loading="lazy" src="https://www.linuxjournal.com/sites/default/files/nodeimage/story/porteux-2-6-released-with-linux-6-19-tlp-support-and-smarter-hardware-optimization.jpg" width="850" height="500" alt="PorteuX 2.6 Released with Linux 6.19, TLP Support, and Smarter Hardware Optimization" typeof="foaf:Image" class="img-responsive"></div>
      
            <div class="field field--name-node-author field--type-ds field--label-hidden field--item">by <a title="View user profile." href="https://www.linuxjournal.com/users/george-whittaker" lang="" about="https://www.linuxjournal.com/users/george-whittaker" typeof="schema:Person" property="schema:name" datatype="" xml:lang="">George Whittaker</a></div>
      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p>The PorteuX project has officially released <strong>PorteuX 2.6</strong>, bringing a new round of updates to the lightweight Slackware-based Linux distribution. Designed to be fast, portable, modular, and immutable, PorteuX continues to appeal to users who want a complete desktop operating system that can run efficiently from a USB drive or other removable media. The latest release introduces a newer Linux kernel, improved power management, updated desktop environments, and numerous performance and usability improvements.</p>

<p>Released just two months after PorteuX 2.5, version 2.6 focuses on refining the user experience while maintaining the distribution's minimalist philosophy.</p>

<h2><strong>Powered by Linux Kernel 6.19</strong></h2>

<p>At the heart of PorteuX 2.6 is the <strong>Linux 6.19 kernel series</strong>, bringing improved hardware compatibility, updated drivers, security fixes, and better support for modern processors and peripherals.</p>

<p>The updated kernel helps ensure smoother operation on both newer desktop hardware and laptops while continuing PorteuX's emphasis on speed and low resource usage.</p>

<h2><strong>Better Battery Life with TLP Support</strong></h2>

<p>One of the headline features in PorteuX 2.6 is <strong>support for TLP</strong>, the popular command-line utility used to optimize laptop battery life.</p>

<p>Available through the PorteuX AppStore, TLP automatically adjusts various power-saving settings, including CPU behavior and device power management, helping extend battery life without requiring constant manual tuning.</p>

<p>For laptop users, this addition makes PorteuX an even more attractive lightweight operating system.</p>

<h2><strong>Automatic CPU Microcode Loading</strong></h2>

<p>The release also introduces <strong>automatic loading of Intel and AMD CPU microcode</strong> when booting in non-fresh modes.</p>

<p>Microcode updates help address processor bugs, improve stability, and deliver security fixes directly from CPU manufacturers. Automating this process reduces the need for manual configuration while ensuring supported systems benefit from the latest firmware improvements.</p>

<h2><strong>Updated Desktop Environments</strong></h2>

<p>PorteuX continues to offer multiple desktop editions, each updated to recent upstream releases.</p>

<p>Version 2.6 includes:</p>

<ul><li>GNOME 49.4</li>
	<li>KDE Plasma 6.5.5</li>
	<li>Xfce 4.20</li>
	<li>Cinnamon 6.6</li>
	<li>LXQt 2.3</li>
	<li>MATE 1.28.2</li>
	<li>COSMIC 1.0.8</li>
	<li>LXDE 0.11.1</li>
</ul><p>This broad selection allows users to choose between modern feature-rich desktops and extremely lightweight environments depending on their hardware and workflow.</p>

<h2><strong>Performance Improvements Throughout the System</strong></h2>

<p>Although PorteuX has always emphasized performance, version 2.6 introduces additional optimizations behind the scenes.</p>

<p>Developers report improvements including:</p></div>
      
            <div class="field field--name-node-link field--type-ds field--label-hidden field--item">  <a href="https://www.linuxjournal.com/content/porteux-26-released-linux-619-tlp-support-and-smarter-hardware-optimization" hreflang="en">Go to Full Article</a>
</div>
      
    </div>
  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trunk Tools' stack cut document review from 60 days to 10 by ditching general-purpose models]]></title>
<description><![CDATA[Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. This prompted construction project management company Trunk Tools to build a specialized, three-la...]]></description>
<link>https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643726/it-nachrichten/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models/</guid>
<pubDate>Fri, 03 Jul 2026 15:46:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most verticals aren’t clean, well-oiled SaaS databases; the reality is ugly documents, proprietary schemas, implicit workflows, and long‑running tasks that most general-purpose models struggle with. </p><p>This prompted construction project management company Trunk Tools to build a specialized, three-layer architecture — perception, semantics, agents — based on highly-detailed data to support high-accuracy, highly-relevant industry automation.</p><p>Their purpose-built stack has shrunk review cycles from months to days, prevented costly field errors, and given autonomous agents the ability to reason over millions of pages of documentation, Trunk says. </p><p>“We really set out to take the data from dispersed systems, pre-process it, structure it, go through our ontology into a knowledge graph, and then train AI models,” said Sarah Buchner, Trunk’s founder and CEO and a former carpenter. </p><p>For builders in other verticals, Trunk’s approach could serve as a blueprint for transforming data chaos into agent‑ready, industry-specific workflows. </p><h2>Where general-purpose LLMs break down on industry data </h2><p>Foundation LLMs, while powerful, are optimized for breadth, not always depth. </p><p>“General-purpose LLMs are trained to be okay at everything, so they're weak at anything niche,” said Kriti Faujdar, a senior product manager working in AI infrastructure, agentic AI, security, and LLM platforms. For instance: Rare terms, domain-specific reasoning, the unspoken context that any practitioner “just knows.” </p><p>Web, app, and software developer Sébastien De Bollivier agreed that the biggest bottleneck is reliability on data that is “jargon-dense, abbreviation-heavy, and format-specific.” </p><p>“A GPT-4-class model can understand a French legal contract, but will fumble the specific article references practitioners need to cite,” he said. </p><p>Besides, the most valuable enterprise data never made it into pretraining anyway, Faujdar pointed out. It's sitting in internal systems and proprietary formats. “RAG helps a little,” she said. “But it's just giving better facts to a model that still can't reason properly in the domain.”</p><p>Pre-training on domain data is critical; enterprises should then fine-tune on good task examples and build their own evals. “A few thousand examples from real practitioners beats millions of scraped, noisy ones," Faujdar said. </p><p>Mixture-of-experts (MoE) can provide specialization without inference costs blowing up. Pairing RAG with fine-tuning also works well; RAG handles the factual long trail while fine-tuning fixes vocabulary and reasoning.</p><p>De Bollivier pointed to the advantage of hybrid stacks: A general-purpose model for reasoning and orchestration, a smaller fine-tuned model (or dense retrieval over a curated corpus) for domain-specific extraction. He advised: “Don't fine-tune to make the model 'smarter' about a domain, fine-tune to make it more reliable on the specific output format your workflow requires.”</p><p>The trades and construction are certainly industries seeing traction with these techniques, as are legal and healthcare, De Bollivier said. These verticals have “high stakes for errors plus standardized document formats, equaling clear domain-training ROI.”</p><p>One honest caveat worth mentioning, Faujdar said: Specialized models can often fall apart outside their domain, so they’re often not useful outside their expertise (unless they’re re-trained). </p><h2>Perception, semantics, agents: inside Trunk's three-layer stack</h2><p>In highly-specialized domains like construction, “data dumps” into large language models (LLMs) don’t cut it, said Trunk’s CTO Amrish Kapoor. This is because most transformers are probabilistic models: When given an image, they report back that it is “probably” a tree, or “probably” a child playing next to a tree. </p><p>This makes them insufficient for high‑precision symbolic interpretation. For instance, in construction documents, a 2-millimeter-wide symbol has a vastly different meaning depending on where it’s placed. </p><p>Further, constrained by context limits, probabilistic models struggle with long‑term project memory. “I don't mean a context window of a few tokens,” Kapoor said. “I'm talking about long term memory that stretches across months and years, because this is how long some of these projects are.”</p><p>Instead, Trunk’s three-layer system breaks workflows into: </p><ul><li><p>Perception (reading and extracting data from messy docs like PDFs, drawings, or scans)</p></li><li><p>A semantic/graph layer (making sense of that data and understanding their relationships).</p></li><li><p>LLMs and agents on top.</p></li></ul><p>Construction drawings are typically symbolic, Buchner said. A door isn't always labeled ‘door.’ Sometimes it's simply an arc on a wall that a trained eye learns to read based on years of practice. </p><p>“The perception layer is what teaches AI to read that language,” she said. The semantic layer then gives that information meaning; for instance, connecting the door to the drawing that details it, the spec that governs it, and the trade that installs it. This helps answer project engineers’ critical questions: Not "is there a door here?" but "does this door create a problem down the line?"</p><p>Particularly in construction, that shift matters because the cost of a problem compounds with time. “A conflict caught in design is relatively low cost to address,” Buchner said, “whereas the same problem caught in the field might cost tens of thousands of dollars.” </p><p>At a high level, the system identifies the document type and begins extracting information based on content (drawing, schedules, paragraph text). This data is then “transformed and augmented” in the platform, which triggers agentic workflows like knowledge graph relationships and end-user workflows. </p><p>For instance, an agent might review an architecture bulletin and produce a visual overlay comparing an older version and a newer version (flagging additions and removals), then generate written narratives that describe what those changes are in simple terms. This helps users understand what’s changed and coordinate with trade partners on updated pricing and change orders. </p><h2>The scale of construction’s data problem</h2><p>Construction workflows are “ripe with implicit assumptions and connections between data in its myriad of sources,” Buchner said. And the amount of unstructured data is “humanly impossible” to process or make sense of.</p><p>Buchner estimated the average high-rise building generates about 3.6 million pages of corresponding documentation. “If you print it into a stack of papers it would be as high as the building itself.” </p><p>All three layers of Trunk’s stack — perception, semantic, LLM — are trained on “very specific datasets” from customers with “explicit permissions” and auto‑labeling/IP, Kapoor explained. Customers who don’t want Trunk training on their data can opt out. </p><p>Data is deidentified and aggregated, and Trunk also collects “tons more” labeled data through other pipelines like 3D building information modeling (BIM). </p><p>Trunk says it only ships agents that achieve around 95% accuracy. The team maintains continuous evaluation pipelines based on ground truth data from customers and experts. They also employ an LLMs-as-a-judge model. </p><p>“This notion of an LLM as a judge is to score how well you're doing, both subjectively as well as objectively,” Kapoor said. Objectivity can be an easy ‘right’ or ‘not right,’ but subjectivity requires more nuance. </p><p>For instance, when creating an email or narrative or explanation, an LLM as a judge framework can create a composite score, or a numerical value that aggregates different metrics and tests a model's performance or risk.</p><p>There can be challenges, though, particularly with latency, Buchner noted; any time the reasoning capacity of underlying models increases, the risk of latency goes up, too. Trunk maintains a set of evaluation criteria to objectively measure latency whenever changes are made to underlying infrastructure, agents, and API calls. </p><p>Then, “before we release to customers, we ensure marginal changes to the end-user experience are well worth the performance enhancements,” Buchner said. </p><h2>From 60 days to 10: the measurable payoff</h2><p>Trunk’s platform powers seven AI agents purpose-built for construction, such as analyzing request for information (RFI) responses, overviewing bids, or reviewing drawings and submittals. </p><p>The submittal agent, for instance, flags missing, conflicting, or noncompliant information in product specs and RFIs. While it’s an essential step in the construction process, “it's a super annoying workflow,” Buchner said, because human reviewers have to compare documents “with a bunch of other parts of documents.” </p><p>But the agent is able to do this in seconds, and Trunk says it has reduced submittal cycles from 50 to 60 days to 10, “which has massive schedule and financial implications.” </p><p>Trunk is now at a place where these agents are communicating directly with each other, which is “quite exciting,” Buchner said. So, for example, one agent will review an architectural drawing for accuracy, then autonomously hand it over to agents handling RFIs and asking follow-up questions. </p><p>“If the drawings have problems, the RFI agent is taking over and is actively reaching out for clarification,” Buchner explained. </p><p>Trunk says its customers report savings of 20 to 40 minutes per field question. Buchner said that users in the field know better than anyone how much of a “time suck” it is to go back and forth from office trailers, dig through project documents in scattered systems or printed PDFs, reconcile discrepancies, and return to coordinate with trade partners. </p><p>Trunk says its customers report these additional outcomes:</p><ul><li><p>Average 8 minute time savings for single-document retrieval (status checks, location lookups, quantity queries).</p></li><li><p>Average 20 minute time savings for standard referencing (cross-referencing 2 to 3 spec sections to form an answer. </p></li><li><p>Average 40 minute time savings for multi-document research (listing and filtering queries, mapping relationships, analyzing RFIs and submittals across 4 to 6 documents).</p></li><li><p>Average 75 minute time savings for complex tasks (creating RFIs and other communication materials, deep cross-referencing across documents, change tracking). </p></li></ul><p>In one instance, Trunk’s drawing review agent flagged that a structural beam had been moved up 8.5 inches. However, this was not documented by the architect. If the change hadn’t been caught, the project manager would likely have had to strip out and reinstall the right size beam, Buchner said. This rework would have added $10,000 or more to the budget, and “certainly there would have been implications on the schedule.” </p><p>Buchner also pointed to other examples: an agent flagged $60,000 in exaggerated pricing with no justification from landscaping subcontractors; identified a fireplace that needed to be sealed prior to drywall installation, saving around $100,000 in labor, materials, and delays; and called out that an electric door required a panel that wasn’t included in electrical drawings. </p><h2>Learnings for other industries</h2><p>Trunk’s approach to building agents is applicable to any vertical working with high volumes of unstructured, industry-specific data. 

Builders working in specific verticals must understand the industry’s specific data challenges their end users face and build technical infrastructure that can transform unstructured data into something an “LLM can traverse and understand,” Buchner said. 

“Only then can you build the connections between data points that ultimately feed agentic workflows.”

A lot of money is being invested in foundational models, so enterprises should build modular systems that can leverage the strengths of various models as they continue to improve, Buchner advised. 

Then, “build your technical advantage where the generic models are not investing and not performing well,” she said. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I always keep PorteuX portable Linux distro on a USB - here's why]]></title>
<description><![CDATA[Ever longed for a Linux distro to have with you at all times? Consider the super-fast, modular, and immutable Slackware-based PorteuX.]]></description>
<link>https://tsecurity.de/de/3639375/it-security-nachrichten/i-always-keep-porteux-portable-linux-distro-on-a-usb-heres-why/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639375/it-security-nachrichten/i-always-keep-porteux-portable-linux-distro-on-a-usb-heres-why/</guid>
<pubDate>Wed, 01 Jul 2026 20:08:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ever longed for a Linux distro to have with you at all times? Consider the super-fast, modular, and immutable Slackware-based PorteuX.]]></content:encoded>
</item>
<item>
<title><![CDATA[Oh, behave! How Gemini can reshape the web for the way you work]]></title>
<description><![CDATA[Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.



Sure, services like Google’s Gemini and its contemporaries can be useful in certain limited, specific areas for productivity purposes. But working with them can also be pre...]]></description>
<link>https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</guid>
<pubDate>Mon, 29 Jun 2026 13:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.</p>



<p>Sure, services like Google’s Gemini and its contemporaries <a href="https://www.computerworld.com/article/4007736/gemini-android.html">can be useful</a> in <a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">certain limited, specific areas</a> for productivity purposes. But working with them can also be pretty disheartening and overwhelming — from <a href="https://www.computerworld.com/article/4047909/burned-out-by-bots-prompt-fatigue-in-workplace.html">prompt fatigue</a> and an onslaught of <a href="https://www.cio.com/article/4077448/ai-workslop-the-new-productivity-killer-only-training-can-stop.html" target="_blank">AI workslop</a> to the fear of <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">lost jobs</a> and even just the simple <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">inconsistencies and inaccuracies</a> these systems are <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">so prone to providing</a>. (And that’s to say nothing of <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">the ever-increasing creepy factor</a> that often accompanies this type of technology.)</p>



<p>More and more, it seems the most significant impact of these systems is in <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">areas like coding</a>, where AI is allowing ambitious tech-heads to <a href="https://www.fastcompany.com/91528164/claude-code-vibe-code-word-processor" target="_blank" rel="noreferrer noopener">create their own custom programs</a> with limited to no programming knowledge (but <a href="https://www.fastcompany.com/91345791/vibecoding-replit-debugging-claude" target="_blank" rel="noreferrer noopener">a <em>lot</em> of time, vision, and patience</a>) — as well as allowing accomplished coders to produce products more quickly by letting AI do the dirty work and then spending <em>their</em> time <a href="https://www.computerworld.com/article/4066260/why-we-need-human-developers.html">guiding, tweaking, and correcting its output</a>.</p>



<p>That’s all well and good, but the reality is that most of us mere mortals are never gonna mess with anything that daunting. That doesn’t, however, mean we can’t enjoy a slice of the custom-coding pie and the productivity advantages it offers — on a much simpler but still supremely useful level.</p>



<p>The average-worker answer lies in an oft-overlooked middle-ground possibility these AI chatbots possess to help us create relatively basic but extremely high-potential custom browser extensions. As their name suggests, these simple little programs run entirely in your browser — the same exact sorts of add-ons you’d typically find and install in a marketplace like <a href="https://chromewebstore.google.com/" target="_blank" rel="noreferrer noopener">Google’s Chrome Web Store</a>.</p>



<p>But with Gemini or any other similar genAI platform, you can dream up your <em>own </em>web-improving extension and turn it into reality in a matter of minutes — simply by describing your goal and then guiding the AI gently along the way. And given how much time most of us spend on the web these days, that opens up a tantalizing series of doors for taking total control of your work environment.</p>



<p>Hate all the extraneous bells and whistles gunking up the Google Docs interface? Gemini can create a Chrome extension that removes them. Annoyed by a glitchy web app? Ask Gemini for an extension that makes some under-the-hood improvements. The possibilities are endless.</p>



<p>Let me show you how exactly it works, how easy it is to approach and master, and how many work-enhancing possibilities are out there just waiting to be created.</p>



<h2 class="wp-block-heading"><a></a>The ins and outs of Gemini’s custom Chrome extensions</h2>



<p>First things first: You don’t need any special tools or subscriptions to make this happen. For the purposes of this article, we’ll focus on Google’s Gemini for the creation and the standard desktop Chrome browser for the installation — but the same basic process would work with most any AI chatbot, if you happen to prefer ChatGPT or Claude, as well as with any extension-supporting, <a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium-compatible browser</a> (a list that includes everything from Microsoft Edge to Brave, <a href="https://www.computerworld.com/article/4148888/8-advanced-ways-vivaldi-boosts-your-productivity.html">Vivaldi</a>, and beyond).</p>



<p>Google offers a dizzying array of <a href="https://blog.google/products-and-platforms/products/google-one/google-ai-subscriptions/" target="_blank" rel="noreferrer noopener">Gemini modes and options</a> and an equally overwhelming series of <a href="https://gemini.google/subscriptions/" target="_blank" rel="noreferrer noopener">AI subscription plans</a> that control how much you can use those capabilities, but you don’t need to worry about any of that to create custom Chrome extensions. You might sometimes see better results if you switch your Gemini model to “Pro” or your Gemini <em>thinking level</em> to “Extended” — designations that even Gemini itself has trouble deciphering (believe me, I asked!) — but just using the default Gemini settings with a free Google account will generally work quite well.</p>



<p>Getting going with a custom Chrome extension is as simple as <a href="https://gemini.google.com/" target="_blank" rel="noreferrer noopener">opening up a new Gemini chat</a> and telling the system what you want it to cook up for you. The hardest part is deciding what you want and what’d be helpful for you — something we’ll explore more in a moment, via specific examples and suggestions. Once you’ve got that, you can just ask Gemini to create a Chrome extension that’ll accomplish what you’re envisioning, with as much specificity as possible about what it’ll do and how it’ll look.</p>



<p>Gemini will spit back a series of plain-text code chunks with instructions to copy each cluster and paste it into a new plain text file with a certain specific name — things like “manifest.json,” “content.js,” and “styles.css.” All you’ll do is use the on-screen button to copy each segment, then open up any simple text editor (like Windows Notepad, macOS TextEdit, or any number of <a href="https://browserpad.org/" target="_blank" rel="noreferrer noopener">simple online text editors</a>) and paste the text in, then save it under the name Gemini gives you.</p>



<p>You’ll need to put all the files into a single isolated folder on your computer, and then you can go into Chrome, type <strong>chrome:extensions </strong>into its address bar, and install your shiny new creation by:</p>



<ul class="wp-block-list">
<li>Flipping the toggle next to “Developer mode” in the upper-right corner of the screen into the on and active position, if it isn’t already</li>



<li>Clicking the “Load unpacked” button</li>



<li>And selecting the folder you just created in the pop-up that appears</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-01-chrome-extension-controls.jpg?quality=50&amp;strip=all&amp;w=1024" alt="chrome extension controls including developer mode toggle and load unpacked button" class="wp-image-4185233" width="1024" height="114" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Chrome’s “Developer Mode” toggle and “Load unpacked” button are the keys to importing any extension you create.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>And that’s pretty much it: No complicated compiling or program publishing — the extension you envisioned will be alive and working right in your browser and ready to use.</p>



<p>Now, odds are, it won’t be <em>exactly</em> what you wanted in its first iteration, and you’ll have to go back to Gemini to request several rounds of updates and corrections. Each time, Gemini will create a new set of code chunks, and you simply overwrite the text in each file with its corresponding new code chunk.</p>



<p>It’s still a bit of a process. But you’ll rarely spend more than an hour on something simple and maybe a few hours on something especially multifaceted and specific, and whatever you create will then work to your advantage indefinitely from that point onward, on any computer where you install it.</p>



<p>Before we dive into specific slivers of inspiration, let’s just note the hopefully obvious asterisk that this’ll work only if you’re <em>either </em>(a) using a personal computer that isn’t associated with an organization or (b) using a work-connected computer where custom Chrome extensions are permitted. In either scenario, you’ll want to use your own best judgment to ensure that whatever you’re adding into your browser won’t expose any corporate data or cause your IT comrades any alarm if they see you using it in your workday.</p>



<p>With most common examples, though — including all the ones we’re about to go over — you shouldn’t have any problem or cause for concern.</p>



<p>Capisce? Capisce. Let’s get into it.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #1: The interface fixer</h2>



<p>Our first custom Chrome extension category is the one that won me over to this practice initially and has been the most shapeshifting for my own browser-based workflow — and that’s the simple-seeming but transformational ability to have AI remake any web app you rely on to remove unneeded elements and redesign the interface to <em>your</em> exact specifications.</p>



<p>The best example I can show you is what I did with my completely homemade, Gemini-created Docs Zen extension. Google Docs, to put it mildly, has devolved into <a href="https://www.computerworld.com/article/1723650/google-docs-cheat-sheet-how-to-get-started.html#work">a cluttered mess</a>. There are so many on-screen elements I never use and, ironically enough, irrelevant AI elements I’d rather not have in my hair. I just want a calm, simple, minimalist environment for writing — with Google’s second-to-none syncing, universal access, and collaboration systems beneath it.</p>



<p>So rather than try to reinvent the wheel, I described to Gemini all the elements I wanted to remove from Docs and all the ways I wanted to rethink how its interface appeared for me.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-02-initial-prompt.jpg?quality=50&amp;strip=all" alt="prompt asking gemini to make a chrome extension called docs fixer that minimizes and simplifies the google docs interface" class="wp-image-4185238" width="1007" height="621" sizes="auto, (max-width: 1007px) 100vw, 1007px"><figcaption class="wp-element-caption"><p>My original request to Gemini, followed by rounds of expansions and revisions (and eventually also a more poetic name).</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I went back and forth with numerous iterations and kept coming up with interesting new additions to further flesh out and improve the experience — and I ended up with a delightful setup that gives me a distraction-free view of my writing space with a simple toggle to reveal the main Docs menus and a palette icon that allows me to switch from one eye-pleasing theme to another.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="620" height="161" sizes="auto, (max-width: 620px) 100vw, 620px"&gt;<figcaption class="wp-element-caption"><p>Google Docs with my custom Docs Zen extension — a true delight for daily writing.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>My setup deliberately doesn’t include comments or other collaborative elements, as I’m mostly writing by myself these days — but when I do need those elements, the eye icon in the upper-right corner of the screen disables my custom adjustments and takes me back to the standard Docs interface. I can then click the eye icon again in <em>that</em> environment to switch back.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-google-docs-toggle-620.gif" alt="animated screenshot of toggling between simplified and full google docs interface" class="wp-image-4185725" width="620" height="117" sizes="auto, (max-width: 620px) 100vw, 620px"><figcaption class="wp-element-caption"><p>My custom extension includes a simple on-off toggle for times when I need the full Docs setup.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I used Gemini to create something similar for <a href="https://www.computerworld.com/article/1712947/what-is-trello-a-guide-to-atlassians-collaboration-and-work-management-tool.html">Trello</a>, with which I also have a love-hate relationship — loving the foundational functions and easy access everywhere but hating the interface that’s <a href="https://www.computerworld.com/article/3832819/atlassian-refocuses-trello-on-individual-task-management.html">lost focus</a>, gained bloat, and gotten noticeably clunky and slow over time.</p>



<p>With the same sort of step-by-step, plain-English guidance, I was able to transform Trello from this…</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-05-trello-before.jpg?quality=50&amp;strip=all" alt="screenshot of busy default trello interface" class="wp-image-4185239" width="999" height="639" sizes="auto, (max-width: 999px) 100vw, 999px"><figcaption class="wp-element-caption"><p>Trello, in its typical current-day state.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>…into <em>this</em>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-06-trello-after.jpg?quality=50&amp;strip=all" alt="screenshot of trello interface simplified by custom chrome extension written by gemini" class="wp-image-4185234" width="997" height="641" sizes="auto, (max-width: 997px) 100vw, 997px"><figcaption class="wp-element-caption"><p>Trello, with my custom modifications in place.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I couldn’t even begin to recount the number of superfluous features and elements I’ve removed, along with revamping the overall interface to make it both more efficient and more visually pleasing to my eye.</p>



<p>Whether it’s a web app you rely on regularly or even just a website you open often, the possibilities are practically endless for the ways you can reshape it and mold it to make it work better <em>for you</em>.</p>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #2: The feature creator</h2>



<p>In addition to the surface-level adjustments and feature removals in my aforementioned Trello-enhancing extension, I also <em>added in </em>several components — such as one-click buttons for archiving or moving cards — and I managed to speed up the site by making some under-the-hood adjustments Gemini suggested when I asked about its choppy performance. The same sort of concept can apply to any web-based interface you’re using, if there are any options that are annoyingly buried within menus, shortcuts that’d make your life easier, or other improvements you’ve longed to see.</p>



<p>You can also consider some simple standalone extensions for giving yourself on-demand features that aren’t necessarily associated with any one specific website but could be useful in plenty of productivity scenarios. For instance:</p>



<ul class="wp-block-list">
<li>I do a fair amount of basic image editing and frequently find myself needing to reference a hex color code that corresponds with a particular brand color, and I always end up having to open up a new tab and look in a note somewhere to find the code I need. Well, no more: I used Gemini to create a super-simple custom color code pop-up where I can store all the colors I need and then copy any of ’em onto my clipboard with a single click. <em>Major </em>time-saver.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-07-color-palette.jpg?quality=50&amp;strip=all" alt="screenshot of color palette selector - a custom chrome extension created by gemini " class="wp-image-4185237" width="478" height="555" sizes="auto, (max-width: 478px) 100vw, 478px"><figcaption class="wp-element-caption"><p>All the color codes I need are now never more than a couple clicks away.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<ul class="wp-block-list">
<li>I’m also constantly converting time zones, either for meetings with clients or colleagues or for trying to wrap my head around publishing systems that insist on using random time zones with no meaning to me. It’s infinitely easier for me to manage now, thanks to the custom Chrome extension I made that shows the current time in all the zones I need most often — as well as allowing me to put any <em>other </em>time into any field and have all the other zones instantly adjust to match. It also offers a brilliant plain-text conversion box where I can just type things like “1pm-3pm PT in MT” and have it cough back up an instant answer for any conversion I need.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-08-time-zone-converter.jpg?quality=50&amp;strip=all" alt="screenshot of time zone converter  - a custom chrome extension created by gemini " class="wp-image-4185235" width="432" height="542" sizes="auto, (max-width: 432px) 100vw, 432px"><figcaption class="wp-element-caption"><p>My custom time zone conversion extension comes in handy countless times a day.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Maybe what you want is the ability to interact with data on different websites more easily — to be able to save any table on a page in front of you as a CSV file, mayhap, or even to save any text you highlight on a page into a new Google Docs document. Whatever the case may be, Gemini can handle it — and that superpower that you’ve always wished for but never found the right tool to make possible can actually now be yours.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #3: The browser expander</h2>



<p>Our final category of custom Chrome extensions to consider moves beyond the web itself and into your actual browser. The browser is essentially the modern-day desktop, after all — and for the first time now, you can expand and enhance it in all sorts of interesting ways.</p>



<p>Some specific examples, to get your brain-motor whirring:</p>



<ul class="wp-block-list">
<li>You could walk Gemini through creating a smart auto-snooze system for your open browser tabs, both to clear clutter and help with <a href="https://www.computerworld.com/article/1666806/easy-steps-to-make-chrome-faster-and-more-secure.html">Chrome’s performance</a>. It could save any tab that hasn’t been touched in a certain amount of time to your local storage and then give you a simple searchable “Archive Dashboard” where you can find all those auto-closed tabs and re-open ’em as needed.</li>



<li>With the right guidance, Gemini could give you a custom browser research panel — where any info you highlight on a page gets beamed over into a sidebar-style panel that serves as a running scratchpad of notes from the day.</li>



<li>Or, if you find yourself often needing to see two tabs together side by side, you could have Gemini cook up a custom extension that instantly detaches any tab in front of you and puts it into a new tab window in a perfectly sized and spaced pattern. One keyboard shortcut could make that move happen, while another keyboard shortcut could recombine the two tabs into a single centered window.</li>
</ul>



<p>As with all the other ideas we’ve gone over, all you’ve gotta do is ask — and now, with the right inspiration in mind, you’re ready to get your custom extension adventures going and start bending the web to <em>your</em> will.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: Slackel 9.0 "MATE"]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  Dimitris Tzemos has announced the release of Slackel 9.0 "MATE" edition, the latest version of the project's Slackware-based live Linux distribution featuring the MATE desktop: "Slackel MATE 9.0 is the latest major release branch o...]]></description>
<link>https://tsecurity.de/de/3631770/unix-server/distribution-release-slackel-90-mate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631770/unix-server/distribution-release-slackel-90-mate/</guid>
<pubDate>Mon, 29 Jun 2026 03:45:58 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  Dimitris Tzemos has announced the release of Slackel 9.0 "MATE" edition, the latest version of the project's Slackware-based live Linux distribution featuring the MATE desktop: "Slackel MATE 9.0 is the latest major release branch of the Greek-developed Linux distribution, built on top of the Slackware 'Current' tree and....]]></content:encoded>
</item>
<item>
<title><![CDATA[Russia Demands Answers After Apple Removes Apps From The Store]]></title>
<description><![CDATA[The Russian government is currently asking questions after Apple decided to take down several popular software programs from its digital marketplace. Recently, the tech giant quietly deleted a group of applications made by VK, a state-controlled technology company, from the United States App Stor...]]></description>
<link>https://tsecurity.de/de/3630355/ios-mac-os/russia-demands-answers-after-apple-removes-apps-from-the-store/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630355/ios-mac-os/russia-demands-answers-after-apple-removes-apps-from-the-store/</guid>
<pubDate>Sun, 28 Jun 2026 02:08:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Russian government is currently asking questions after Apple decided to take down several popular software programs from its digital marketplace. Recently, the tech giant quietly deleted a group of applications made by VK, a state-controlled technology company, from the United States App Store. This sudden move has sparked a tense back-and-forth between the foreign government and the American device maker regarding access to daily digital tools.



The Kremlin wants answers about the sudden software removal



After the software disappeared, officials in Moscow quickly spoke up. A recent Reuters report sharing the official response notes that the Kremlin expects an explanation from the tech company about why these specific items were blocked. A government spokesperson stated that if the brand refuses to provide a good reason, the country will have to rethink how it cooperates with the firm moving forward.



The company behind the deleted software, VK, claims the removal happened without any warning. The group noted that this decision cuts off millions of regular users from social networks, messaging tools, and email platforms. While the company itself is not directly under Western sanctions, its top executive was previously sanctioned by the United States and European officials.



The iPhone maker defended its actions by stating it simply follows the laws of the countries where it operates. The brand explained that it took down the software to comply with current government sanctions. This event follows a similar situation just a few weeks ago, when the company also deleted two hidden banking tools from its digital shelves.



For now, users in the region are left waiting to see how this dispute unfolds. As global rules continue to shift, the tech giant finds itself caught between strict legal guidelines and international pressure over digital access.]]></content:encoded>
</item>
<item>
<title><![CDATA[Micron Exec Claims Apple Caused The Current Memory Chip Shortage]]></title>
<description><![CDATA[The ongoing memory chip shortage has forced the tech industry to raise prices, and one major supplier is pointing the finger at Apple. After announcing a massive jump in revenue this week, a top executive at Micron suggested that the aggressive buying tactics used by the smartphone maker during t...]]></description>
<link>https://tsecurity.de/de/3628499/ios-mac-os/micron-exec-claims-apple-caused-the-current-memory-chip-shortage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628499/ios-mac-os/micron-exec-claims-apple-caused-the-current-memory-chip-shortage/</guid>
<pubDate>Fri, 26 Jun 2026 22:10:50 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The ongoing memory chip shortage has forced the tech industry to raise prices, and one major supplier is pointing the finger at Apple. After announcing a massive jump in revenue this week, a top executive at Micron suggested that the aggressive buying tactics used by the smartphone maker during the last market downturn are partly to blame for the current lack of supply.



The comments arrive just after the tech giant bumped up the cost of several devices to offset rising component expenses.



Micron says cheap deals stopped it from funding new factories



Micron Chief Business Officer Sumit Sadana explained to The Wall Street Journal that the supplier could not invest in new production capacity a few years ago. During the last big slump in the memory market, certain buyers pushed hard for rock-bottom prices. This move caused Micron to lose money and forced it to halt investments in 2023. While the executive did not mention the brand by name, the timing and context clearly point toward the creator of the iPhone.



The tech giant is well known for driving a hard bargain with suppliers to keep costs low. Those long-term contracts helped it delay price hikes longer than competitors. However, the supplier claims those same deals created a bad environment for the whole industry. Because the memory sector was not making enough money, it could not afford to build out the extra capacity needed to meet demand today.



The situation came to a head recently when the tech giant announced sweeping price increases across the Mac and iPad lineups, along with the Apple TV and Vision Pro. CEO Tim Cook called the current component crunch a hundred-year flood, noting that the memory sector was passing along huge cost increases. Cook said the company had to raise shelf prices because the situation was no longer sustainable.



This back and forth shows how deeply connected the supply chain really is. While squeezing suppliers for better deals helps profit margins in the short term, it can clearly backfire when demand spikes. With memory costs expected to stay high for the foreseeable future, everyday buyers will be the ones footing the bill for this ongoing standoff.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mac Users Are Getting More Out of AI Creative Work]]></title>
<description><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't aban...]]></description>
<link>https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627699/ios-mac-os/how-mac-users-are-getting-more-out-of-ai-creative-work/</guid>
<pubDate>Fri, 26 Jun 2026 16:22:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For a long time, the Mac's reputation as a creative machine rested on its hardware and native apps — Final Cut, Logic, the tight integration between a Retina display and color-accurate tools. AI has started to quietly rewrite that equation.



The shift isn't dramatic. Most Mac users haven't abandoned their existing workflows. But something is changing in how people approach the early, messier stages of creative work — ideation, iteration, rapid visual exploration — and AI tools are filling a gap that native apps never really addressed.



The Friction Nobody Talks About



The real challenge with AI-assisted creative work isn't capability. The models are impressive. The friction is operational: too many platforms, too many tabs, too much manual handoff between steps.



A typical session might involve generating an image in one tool, downloading it, uploading it somewhere else for background removal, switching to another service for video conversion, and then losing track of which version came from which prompt. This kind of tool-hopping breaks the focused state that creative work depends on.



Mac users feel this acutely, because the platform has always rewarded deep, single-environment focus. The friction isn't a technical problem — it's a workflow problem.



What's Actually Changing







The most useful AI tools emerging right now aren't necessarily the ones with the most powerful models. They're the ones that minimize context-switching.



This is showing up in a few different ways:



Unified canvas environments. Some tools are moving toward a visual, node-based interface — where discrete AI tasks (image generation, background swap, video conversion) connect to each other on an infinite canvas, with outputs flowing directly from one step to the next. For Mac users who think spatially and work across large or multiple displays, this approach fits naturally. 



Multi-model access in one place. Rather than holding separate subscriptions to GPT Image 2, Seedance, Kling, Midjourney, or other services, users increasingly want a single interface where different models can be called on for different tasks within the same session. Banana Pro AI is one platform taking this direction — the model becomes a tool choice, not a platform commitment.



Reusable workflow templates. Once a pipeline is built — say, a product photo → model integration → short video sequence — it can be saved and rerun with new inputs. Tools like Workflow Studio make this possible without rebuilding from scratch each time. The setup cost is paid once, which matters most to anyone managing a content catalog or running regular production cycles.



The Mac Advantage in This Context



None of this is Mac-exclusive. But there are reasons Mac users tend to adopt these kinds of tools quickly.



The platform's culture has always favored deep tool mastery over constant app-switching. When a creative environment reduces friction and rewards learning its structure, Mac users lean in. The spatial thinking that makes tools like Figma, Miro, or even Xcode feel natural translates well to canvas-based AI workflows.



The device ecosystem matters too. Heavy work happens at a desk — MacBook Pro, external display, the full setup. But review, approval, and light adjustment increasingly happen on an iPhone. Tools that sync across both contexts fit into how Mac users already move through their day.



The Shift in Creative Roles



What AI actually changes isn't the final output — it's who can generate a first draft, and how quickly.



A solo designer can now run product photography variations, motion concepts, and visual alternates in a single session that would have previously required a photographer, a video editor, and several rounds of back-and-forth. The creative direction still comes from the person. The labor-intensive middle steps increasingly don't.



This doesn't collapse the value of craft. If anything, it raises the bar for creative judgment — because the bottleneck is no longer production capacity, it's the quality of decisions made at each step. Mac users who treat these tools as leverage for their existing skills, rather than replacements for them, tend to get the most out of them.



A Practical Reality



The honest version of this story isn't that AI has transformed creative work overnight. Most professionals are still figuring out where it fits and where it doesn't.



What has changed is that the experimentation cost has dropped. Trying a visual direction, running a quick motion test, exploring a product presentation format — these used to require either significant time or significant budget. They increasingly don't.



For Mac users with an existing creative practice, that's not a disruption. It's an expansion of what's possible in a single afternoon's work.]]></content:encoded>
</item>
<item>
<title><![CDATA[Folding iPhone hinge issues may have been worked out, rumored to ship in fall]]></title>
<description><![CDATA[Yet another report insists that the iPhone Fold launch will happen in September, after a rumor-monger back-and-forth about hinge issues. The iPhone rumor silly season has officially kicked off.A render of a potential iPhone Fold design - image credit: AppleInsiderApple is widely expected to bring...]]></description>
<link>https://tsecurity.de/de/3621572/ios-mac-os/folding-iphone-hinge-issues-may-have-been-worked-out-rumored-to-ship-in-fall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621572/ios-mac-os/folding-iphone-hinge-issues-may-have-been-worked-out-rumored-to-ship-in-fall/</guid>
<pubDate>Wed, 24 Jun 2026 15:52:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Yet another report insists that the <a href="https://appleinsider.com/inside/iphone-fold" title="iPhone Fold" data-kpt="1">iPhone Fold</a> launch will happen in September, after a rumor-monger back-and-forth about hinge issues. The iPhone rumor silly season has officially kicked off.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68053-143465-67943-143238-66570-139613-000-lead-iPhone-Fold-xl-xl-xl.jpg" alt="Foldable smartphone partly open, its bright screen showing colorful wavy lines and a small front camera hole in the top corner, against a softly blurred indoor background" height="720"><br><span>A render of a potential iPhone Fold design - image credit: AppleInsider</span></div><br>Apple is <a href="https://appleinsider.com/articles/26/06/16/strident-leaker-insists-iphone-fold-is-not-delayed-at-all">widely expected</a> to bring out its first foldable smartphone, the iPhone Fold, in September. In a Wednesday report about the supply chain, Apple is forging ahead with mass production in the next month.<br><br>According to <a href="https://www.thelec.kr/news/articleView.html?idxno=58537">interviews</a> with supply chain officials by <em>The Elec</em>, Apple has finalized key specifications for the iPhone Fold. After confirming the display, case, and mechanical components are up to task, it has started to prepare for the mass production phase.<br><br><br> <strong>Rumor Score:</strong> 🤯 Likely <br><br><br> <a href="https://appleinsider.com/articles/26/06/24/folding-iphone-hinge-issues-may-have-been-worked-out-rumored-to-ship-in-fall?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244762?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, firefox, kernel, kernel-rt, libpq, memcached, postgresql, postgresql16, postgresql:13, postgresql:16, python-urllib3, python3.14-urllib3, redis:6, skopeo, and vim), Debian (beets, gst-plugins-bad1.0, imagemagick, libmatio, python-urllib3, ...]]></description>
<link>https://tsecurity.de/de/3621514/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621514/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 24 Jun 2026 15:25:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, firefox, kernel, kernel-rt, libpq, memcached, postgresql, postgresql16, postgresql:13, postgresql:16, python-urllib3, python3.14-urllib3, redis:6, skopeo, and vim), <b>Debian</b> (beets, gst-plugins-bad1.0, imagemagick, libmatio, python-urllib3, and u-boot), <b>Fedora</b> (chromium, coturn, frr, grout, materialx, perl-Crypt-DSA, and yt-dlp), <b>Mageia</b> (opensc, perl-Archive-Tar, and podofo), <b>Oracle</b> (fence-agents, libpq, mysql:8.4, and postgresql:16), <b>Red Hat</b> (firefox, libpng, libpng12, libpng15, libreoffice, nginx:1.24, thunderbird, tigervnc, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Slackware</b> (libarchive), <b>SUSE</b> (amazon-ssm-agent, ansible-core, apache2, bind, bitcoin-qt6, containerized-data-importer, curl, distribution, docker-stable, dovecot24, dracut, editorconfig-core-c, exiv2, firefox, freeipmi, freerdp, ghc-aws, ghc-crypton-asn1-encoding, ghc-crypton-asn1-parse, ghc-crypton-asn1-types, ghc-crypton-pem, glib-networking, go1.25, go1.26, google-guest-agent, graphite2, hamlib, helm, himmelblau, ignition, ImageMagick, kernel, ldns, libarchive, libcaca, libheif, libinput, libjxl, libsolv, libzypp, zypper, LibVNCServer, libxslt, libyang, mcphost, mozjs128, ncurses, nginx, opensc, openssl-3, openvswitch, papers, perl-HTML-Parser, perl-HTTP-Daemon, perl-Protocol-HTTP2, podman, postgresql14, postgresql15, postgresql16, postgresql17, python-aiohttp, python-ecdsa, python-paramiko, python-PyJWT, python-starlette, rekor, sqlite3, strongswan, tiff, tomcat, tomcat10, tomcat11, unbound, webkit2gtk3, xwayland, and zypper, libzypp, libsolv), and <b>Ubuntu</b> (libcap2, libnfs, libvncserver, libxml2, and mysql-8.0).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in libarchive (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3620262/unix-server/security-mehrere-probleme-in-libarchive-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620262/unix-server/security-mehrere-probleme-in-libarchive-slackware/</guid>
<pubDate>Wed, 24 Jun 2026 07:16:19 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4668: Nuclear Power Technology Follow Up on Safety]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


--------------------






01 Introduction






This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:...]]></description>
<link>https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</guid>
<pubDate>Wed, 24 Jun 2026 02:03:28 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
--------------------</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:</p>

<p>

</p>

<p>
02</p>

<p>
--------------------</p>

<p>

</p>

<p>
Loving this series. Maybe Whiskey Jack could give some cost comparisons between large and small reactors. He could also give us a realistic look at nuclear plant safety/accidents compared to conventional power production. Looking forward to the episode on FORTH generation reactors ;-)</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
03</p>

<p>
End of quote.</p>

<p>

</p>

<p>
The first question I answered in my previous follow up, which was HPR4628. In this episode I will attempt to answer the second question, which was about the safety of nuclear power compared to other sources of electrical power generation.</p>

<p>

</p>

<p>
One of the HPR janitors encouraged me to make this episode, so I think we can thank him for getting another HPR episode made.</p>

<p>

</p>

<p>
04 Defining the Scope</p>

<p>
First, let's define the scope of the question. </p>

<p>

</p>

<p>
This will cover electrical power generation only.</p>

<p>
Within that scope I will consider only the following sources of energy.</p>

<p>

</p>

<p>
05</p>

<p>
Coal</p>

<p>
Oil</p>

<p>
Natural Gas</p>

<p>
Hydroelectric</p>

<p>
Nuclear</p>

<p>
Wind</p>

<p>
Solar</p>

<p>

</p>

<p>
I won't cover geothermal, wave, or tidal power as these are only used in very small amounts and so there simply isn't enough literature on them to base a discussion on . </p>

<p>

</p>

<p>
06 Foreshadow Conclusion</p>

<p>
I should mention right away that I cannot provide absolute answers to this question in the form of a nice, neat ranking table based on numbers from peer reviewed scientific sources. </p>

<p>
The reasons for this will become apparent, but to put it briefly, the data on which to base such a ranking simply doesn't exist. </p>

<p>

</p>

<p>
I will however provide context within which people can think about the issue.</p>

<p>
Wherever possible, I will provide links to the references that I used in the show notes so you can read further on this yourself.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
07 Energy Catastrophism versus Energy Uniformitarianism</p>

<p>

</p>

<p>
First though I need to go off on a slight geological detour in order to explain an important analogy that I will use.</p>

<p>

</p>

<p>
08</p>

<p>
In the 19th century there was a great debate among geologists over what is known as catastrophism versus uniformitarianism.</p>

<p>
In seeking to explain the origins of the earth and of the landscape that we see around us, there were two points of view.</p>

<p>

</p>

<p>
09</p>

<p>
One was "catastrophism". </p>

<p>
This is the belief that the mountains, valleys, and plains that we see around us were formed as a result of great catastrophes which occurred relatively recently in earth's history. </p>

<p>
This explanation was necessary in order to fit geological features into an earth that was believed to be only a few thousands of years old.</p>

<p>
This view was heavily influenced  by religious belief.</p>

<p>
In this view Noah's flood was the great catastrophe and the fossils of dinosaurs were the remains of animals who had not been saved on the ark and so had died in the flood.</p>

<p>

</p>

<p>
10</p>

<p>
The other point of view was uniformitarianism.</p>

<p>
This was the hypothesis that the landscape we see around us can be explained by the very slow accumulation of very small changes over very long periods of time. </p>

<p>
For this to be true however, the earth had to be far older than the few thousand years that a literal reading of the bible would suggest.</p>

<p>
The earth in fact had to be many, many, millions of years old.</p>

<p>

</p>

<p>
11</p>

<p>
Eventually, the uniformitarian view won out and people understood that while some catastrophes can take place, the shape of the landscape is overwhelmingly due to small changes over very long periods of time.</p>

<p>

</p>

<p>

</p>

<p>
12 How is this Relevant to this Episode You Ask?</p>

<p>
How this is relevant is that I will use this analogy to explain how we need to think about energy and safety.</p>

<p>
Very small numbers of deaths and injuries multiplied over many occurrences can add up to big numbers, comparable in scale or possibly even larger than a single catastrophe or even several of them.</p>

<p>

</p>

<p>
13</p>

<p>
I don't know if anyone else has used this analogy before, I have just thought of this when writing the script for this podcast.</p>

<p>
None the less, I think it is a very useful way of helping to understand the issues.</p>

<p>

</p>

<p>
14</p>

<p>
As an example of this, think about the well known case of the safety of flying versus the safety of travelling in your car.</p>

<p>
Air crashes are catastrophes that make the headlines.</p>

<p>
Automobile crashes are seldom more than local news at best.</p>

<p>
You have probably heard many times the claim that if you making a trip somewhere, you are safer to fly than to drive yourself in your car.</p>

<p>

</p>

<p>

</p>

<p>
15 Example - Hydro versus Solar</p>

<p>
I will now present an example of this.</p>

<p>
Hydro electric power has some notable large scale catastrophes associated with it.</p>

<p>
Roof top solar power does not have any notable catastrophes that I am aware of.</p>

<p>
However, which is safer?</p>

<p>

</p>

<p>
16 Hydro Catastrophes</p>

<p>
Here are three examples of hydro electric catastrophes in just one country, Italy.</p>

<p>

</p>

<p>
The Vajont Dam which collapsed in1963</p>

<p>
An estimated 1,917 to 2,500 people died.</p>

<p>

</p>

<p>
The Sella Zerbino dam which collapsed in 1935.</p>

<p>
More than 100 people died.</p>

<p>

</p>

<p>
The Gleno Dam which collapsed in 1923.</p>

<p>
An estimated 350 people died.</p>

<p>

</p>

<p>
https://damfailures.org/</p>

<p>
https://pmc.ncbi.nlm.nih.gov/articles/PMC4997708/</p>

<p>

</p>

<p>
17</p>

<p>
I haven't tried to compile a global list of the worst hydro electric dam collapses, as this sort of information is actually very difficult to find, even on web sites dedicated to dam failures.</p>

<p>
An additional problem is that information on whether a dam was used for electric power generation or not is often not available.</p>

<p>

</p>

<p>
18</p>

<p>
Dam failures where contradictory or insufficient information is available on whether there was an associated hydro power plant include the 1975 Banqian Dam failure, where death estimates range up to a quarter of a million.</p>

<p>

</p>

<p>
19 Solar Panel Slow Accumulation</p>

<p>
Contrast this with roof top solar panels.</p>

<p>
Many small accidents can add up to big numbers as well.</p>

<p>

</p>

<p>
20</p>

<p>
Health and safety literature discussing solar panel safety mention things such as</p>

<p>
Falls from roofs.</p>

<p>
Electric shock.</p>

<p>
Arc flash (burns from electrical arcing).</p>

<p>
Normal electrical safety procedures which are based around locking out sources of energy do not work with solar panels which makes safety more difficult.</p>

<p>
Heat stress due to working exposed in the hot sun.</p>

<p>

</p>

<p>
Warning from US government on falls by solar panel installers.</p>

<p>
https://stacks.cdc.gov/view/cdc/228946</p>

<p>
https://www.osha.gov/green-jobs/solar</p>

<p>

</p>

<p>

</p>

<p>
21 Why We Cannot Compare the Two</p>

<p>
Hydro catastrophes are not well documented, but we can at least find records of some of the most notable ones.</p>

<p>
However, even those have very large variations in estimates of deaths.</p>

<p>

</p>

<p>
22</p>

<p>
Roof top solar deaths however are largely undocumented.</p>

<p>
The industry is largely unregulated.</p>

<p>
There is no central authority which accumulates many individual deaths or injuries.</p>

<p>
At best there are worker and public safety bodies who simply accumulate those statistics into general construction or household injuries.</p>

<p>

</p>

<p>
23</p>

<p>
Thus we have no reliable means of comparing the two energy sources on a comparable basis.</p>

<p>
We face the same problem with all other major electrical energy sources. </p>

<p>
So far as I am aware, there are no peer reviewed scientific studies which compare the relative safety of all of the major electrical energy sources we are considering here based on actual numbers.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
24 Safety Risks</p>

<p>

</p>

<p>
I will now try to list some the major hazards for each of energy sources we are considering.</p>

<p>
There is however limited data available.</p>

<p>
In many cases we just have reference to worker safety organizations as to what the hazards are.</p>

<p>
I will not attempt here to put numbers to these here. </p>

<p>

</p>

<p>
Categories</p>

<p>

</p>

<p>
25 Coal, Oil, Natural Gas</p>

<p>
The hazards are</p>

<p>
Air pollution</p>

<p>
Mining and oil field accidents</p>

<p>
Pipeline explosions</p>

<p>
Transportation accidents. These- move a lot of material so these are significant.</p>

<p>

</p>

<p>
26 Hydroelectric</p>

<p>
These include</p>

<p>
Dam collapse</p>

<p>
Drowning</p>

<p>

</p>

<p>
27 Nuclear</p>

<p>
These include</p>

<p>
Radiation exposure</p>

<p>

</p>

<p>
28 Wind</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Confined space deaths (there is not much detail on this)</p>

<p>
Electric shock</p>

<p>
Ice throws (that is, throwing pieces of ice off the blades)</p>

<p>
This technology has a significant problem with people working alone which greatly increases risks associated with other dangers.</p>

<p>

</p>

<p>
29 Solar</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Electric shock</p>

<p>
Arc flash</p>

<p>
Heat stress</p>

<p>

</p>

<p>
30</p>

<p>
I have not tried to cover all possible risks associated with each category, just the ones which each industry considers to be the risks they concern themselves with.</p>

<p>
There does not exist any means by which risks of similar types are compared across different industries. </p>

<p>

</p>

<p>
31 Reliability of Supply is Also Safety</p>

<p>
In a completely electrified net zero society, reliability of supply is a safety matter.</p>

<p>
People will die in very large numbers in cold climates if they do not have heat.</p>

<p>
If we have no fossil fuels, we need to also consider how reliably does a grid based on any of the options work.</p>

<p>
I have not seen anyone attempt to address this question and will not attempt to address it here.</p>

<p>
However, it must be addressed in any comprehensive attempt to rank safety. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
32 Studies or Articles on Estimates of Relative Safety</p>

<p>

</p>

<p>
Despite the difficulties of comparing the safety of different sources of energy, some people have attempted this anyway.</p>

<p>
Different estimates done at different times had different focuses, so unfortunately we do not have a nice set of studies that we can neatly use to cross check one another.</p>

<p>
I will however list the names and the authors and summarize the results.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
33 The Health Hazards of Not Going Nuclear</p>

<p>
By Dr. Petr Beckman</p>

<p>
Published in 1976</p>

<p>

</p>

<p>
The author of this book tried to address the relative safety of different sources of energy in the mid 1970s.</p>

<p>
However, it is old at this point, so I won't bother digging through its pages to find his figures.</p>

<p>

</p>

<p>
34</p>

<p>
He mainly focused on comparing electric power generated with coal to nuclear. </p>

<p>
His conclusion was that if the goal was to prevent deaths or ill health in the process of generating electricity, then the logical conclusion was to replace coal fired power plants with nuclear.</p>

<p>

</p>

<p>
35</p>

<p>
The book was relatively well known at the time, as least as far as books on energy are concerned, so I thought it was still worth mentioning.</p>

<p>
I happen to have a copy of this book which I bought back in that time period</p>

<p>
It was the 8th printing of the book, so it would appear to have had relatively good sales. </p>

<p>

</p>

<p>
36</p>

<p>
The author did address the issue of what I have termed "catastrophism" in his comparison of different energy sources, although I don't know if he used this phrase.</p>

<p>
I don't know if he was the first to use this sort of analysis, but he certainly was very influential in terms of popularizing it.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
37 Risk of Energy Production</p>

<p>
by Herbert Inhaber</p>

<p>
Publication AECB 1119</p>

<p>
March 1978</p>

<p>

</p>

<p>
This study is a scientific paper from the same time period as the book "The Health Hazards of Not Going Nuclear".</p>

<p>

</p>

<p>
38</p>

<p>
He based his risk estimates largely on estimates of the amount of material which was used in the construction and operation of various power sources.</p>

<p>
While we could argue over whether or not this is a valid methodology, I think any such argument would be pointless as I think the age of the study alone renders it not relevant today anyway.</p>

<p>
Advancements in materials have changed the basis results significantly by now.</p>

<p>
However, as it exists I thought I would mention it to show that the idea of comparing energy sources to each other is not a new one.</p>

<p>
The author compared a wider variety of potential sources than Beckman did. </p>

<p>

</p>

<p>
39</p>

<p>
Here's his conclusions.</p>

<p>
He assumes equal amounts of energy produced by each method.</p>

<p>
The numbers are normalized such that the total sums to 100%.</p>

<p>
You can think of it in terms of what proportion of total deaths or injuries would result from each source if each were equally used. </p>

<p>

</p>

<p>
40</p>

<p>
Coal 27.5%</p>

<p>
Oil 25.6%</p>

<p>
Methanol 16.7%</p>

<p>
Wind 10.8%</p>

<p>
Solar photovoltaic 9.2%</p>

<p>
Thermal 8.1%</p>

<p>
Solar space heating 1.5%</p>

<p>
Ocean thermal 0.4%</p>

<p>
Nuclear 0.13%</p>

<p>
Natural Gas 0.08%</p>

<p>

</p>

<p>
41</p>

<p>
His natural gas estimate is drastically different from that of other authors. </p>

<p>
I am not going to worry about explaining it however, as the study is as I said old enough to be not very relevant anyway.</p>

<p>
I am mainly including this here out of historical interest. </p>

<p>

</p>

<p>
42</p>

<p>
As a footnote, the methanol he refers to would be synthesized from wood. This was a popular idea in that era as a means of providing liquid fuels for transportation. Practical battery electric cars in those days were strictly science fiction.</p>

<p>

</p>

<p>
43</p>

<p>
The ocean thermal category is a real blast from the past and I had forgotten all about that concept.</p>

<p>
It was a very popular idea at that time and was supposed to be *the* big and upcoming thing in renewable energy.</p>

<p>
It involved various means of attempting to extract energy from differences in water temperature at different depths in the ocean. </p>

<p>
It gradually faded away however, as despite great efforts being put into it, designs never proved to be practical.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
44 Electricity generation and health</p>

<p>
Anil Markandya, Paul Wilkinson</p>

<p>
Published in the Lancet, Vol 370, 15 September 2007</p>

<p>

</p>

<p>
45</p>

<p>
This is more recent than the previous one, although it is nearly 20 years old at this point.</p>

<p>
Unfortunately it doesn't cover wind or solar, just fossil fuels and nuclear.</p>

<p>
However it is still useful, and the Lancet is a very reputable peer reviewed journal.</p>

<p>

</p>

<p>
46</p>

<p>
I will present just the results rather than discussing the whole paper. </p>

<p>
The authors  break it down into deaths among the public, occupational deaths, and air pollution related deaths, serious illness, and minor illness.</p>

<p>

</p>

<p>
47</p>

<p>
They  break the energy sources down into lignite, coal, gas, oil, biomass, and nuclear. </p>

<p>
Lignite is a type of very low grade coal used mainly for electric power generation. </p>

<p>
In this paper biomass refers to energy crops and forest residues.</p>

<p>

</p>

<p>
48</p>

<p>
I will summarize the results by category rather than trying to describe a table that has 6 rows and 5 columns.</p>

<p>

</p>

<p>
All numbers are normalized in terms of deaths or cases per TWh.</p>

<p>

</p>

<p>
49</p>

<p>
Occupational deaths from accidents</p>

<p>
lignite 0.1 </p>

<p>
coal 0.1 </p>

<p>
gas 0.001</p>

<p>
 oil no data</p>

<p>
biomass - no data</p>

<p>
Nuclear is 0.019. </p>

<p>

</p>

<p>
50</p>

<p>
Deaths among the public from accidents</p>

<p>
lignite 0.02 </p>

<p>
coal 0.02 </p>

<p>
gas 0.02</p>

<p>
 oil 0.03</p>

<p>
biomass no data</p>

<p>
Nuclear 0.003</p>

<p>

</p>

<p>
51</p>

<p>
Air pollution deaths</p>

<p>
lignite 32.6</p>

<p>
coal 24.5</p>

<p>
gas 2.8</p>

<p>
 oil 18.4</p>

<p>
biomass 4.63</p>

<p>
Nuclear 0.052</p>

<p>

</p>

<p>
52</p>

<p>
Air pollution serious illnesses</p>

<p>
lignite 298</p>

<p>
coal 225</p>

<p>
gas 30</p>

<p>
 oil 161</p>

<p>
biomass 43</p>

<p>
Nuclear 0.22</p>

<p>

</p>

<p>
53</p>

<p>
Air pollution minor illnesses</p>

<p>
lignite 17,676</p>

<p>
coal 13,288</p>

<p>
gas 703</p>

<p>
 oil 9,551</p>

<p>
biomass 2,276</p>

<p>
Nuclear no data</p>

<p>

</p>

<p>
54</p>

<p>
Natural gas edges out nuclear power slightly in terms of occupational safety, but in every other category nuclear is drastically lower in terms of ill effects than any of the alternatives.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
55 2020 Fatalities for US Roofers Increased 15% as Solar Roof Installations Increase</p>

<p>
Published in The Next Big Future</p>

<p>
July 6, 2021 by Brian Wang</p>

<p>

</p>

<p>
56</p>

<p>
This seems to be written by someone who has a popular science blog.</p>

<p>
I'm not familiar with it personally, but he addresses the subject so I'll list it.</p>

<p>

</p>

<p>
The title implies that it's all about rooftop solar, but he provides comparative numbers for the other energy sources of interest, so that is useful for our purposes.</p>

<p>
However, he doesn't describe his methodology, so we need to treat them with some caution.</p>

<p>

</p>

<p>
Here are his results</p>

<p>
These are deaths per thousand terawatt hours.</p>

<p>

</p>

<p>
57</p>

<p>
Coal - 100,000</p>

<p>
Oil - 36,000</p>

<p>
Natural gas - 4,000</p>

<p>
Hydro - 1,400</p>

<p>
Rooftop solar - 440</p>

<p>
Wind - 150</p>

<p>
Nuclear - 90</p>

<p>

</p>

<p>
58</p>

<p>
If we plot these numbers on a bar chart, coal and oil are so large that all of the others are squished to the  bottom of the chart and are difficult to see at all.</p>

<p>

</p>

<p>
Let's therefore look at these in terms of orders of magnitude.</p>

<p>
Keep in mind that this is a logarithmic scale.</p>

<p>
This means that the difference between 4 and 5 is much greater in linear terms than the difference between 1 and 2. </p>

<p>

</p>

<p>
59</p>

<p>
Coal - 5</p>

<p>
Oil - 4</p>

<p>
Natural gas - 3</p>

<p>
Hydro - 3</p>

<p>
Rooftop solar - 2</p>

<p>
Wind - 2</p>

<p>
Nuclear - 1</p>

<p>

</p>

<p>
60</p>

<p>
Each of these numbers represents an order of magnitude, that is a power of ten. </p>

<p>
We can see that with rooftop solar, wind, and nuclear, the numbers are so close and the uncertainties are so great and their relative values so small compared to say coal that they can be seen as equivalent so far as safety is concerned.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
61 What are the safest and cleanest sources of energy?</p>

<p>
by Hannah Ritchie</p>

<p>
Published in Our World in Data</p>

<p>
First published in 2017, updated in 2022 and 2024</p>

<p>

</p>

<p>
62</p>

<p>
The author of this study addressed both deaths and greenhouse gas emissions.</p>

<p>
Deaths from accidents and air pollution are normalized to per TWh of electricity, while greenhouse gas emissions are normalized to GWh of electricity over the life cycle of the plant.</p>

<p>

</p>

<p>
63</p>

<p>
Here are the death figures.</p>

<p>
Coal 24.6</p>

<p>
Oil 18.4</p>

<p>
Biomass 4.6</p>

<p>
Natural Gas 2.8</p>

<p>
Hydro power 1.3</p>

<p>
Wind 0.04</p>

<p>
Nuclear 0.03</p>

<p>
Solar 0.02</p>

<p>

</p>

<p>
64</p>

<p>
For greenhouse gas emissions the figures are</p>

<p>
Coal 970 tons</p>

<p>
Oil 720 tons</p>

<p>
Natural gas 440 tons</p>

<p>
Biomass 78 to 230 tons</p>

<p>
Solar 53 tons</p>

<p>
Hydro power 24 tons</p>

<p>
Wind 11 tons</p>

<p>
Nuclear 6 tons</p>

<p>

</p>

<p>
65</p>

<p>
If we take the death figures and rank them by order of magnitude as we did with the previous article, we get the following.</p>

<p>

</p>

<p>
66</p>

<p>
Coal - 4</p>

<p>
Oil - 4</p>

<p>
Biomass - 3</p>

<p>
Natural Gas - 3</p>

<p>
Hydro power - 3</p>

<p>
Wind - 1</p>

<p>
Nuclear - 1</p>

<p>
Solar - 1</p>

<p>

</p>

<p>
67</p>

<p>
Keep in mind that the previous article covered only rooftop solar and not large industrial installations, and so is not directly comparable. </p>

<p>
Also the units are different, with the previous article being in terms of thousand TWh, and this one being in TWh. </p>

<p>
If we exclude solar (as the numbers are not comparable), Brian Wang's numbers are between 1.5 to 4 times higher than Ritchie's, except for hydro which are almost identical. I think this latter is due to both sets of numbers are dominated by one exceptionally big hydro accident. </p>

<p>

</p>

<p>
68</p>

<p>
Overall however, the relative rankings are quite comparable. </p>

<p>

</p>

<p>
Ritchie's numbers for deaths from coal, oil, and natural gas appear to be directly from the study by  Markandya and Wilkinson mentioned above.</p>

<p>

</p>

<p>
For the benefit of those who are wondering, Ritchie specifically states that her numbers for nuclear include the Chernobyl and Fukushima accidents. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
https://www.iaea.org/publications/magazines/bulletin/21-1/solar-power-more-dangerous-nuclear</p>

<p>
Direct link to file</p>

<p>
https://www.iaea.org/sites/default/files/publications/magazines/bulletin/bull21-1/21104091117.pdf</p>

<p>

</p>

<p>
https://ourworldindata.org/safest-sources-of-energy</p>

<p>

</p>

<p>
https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(07)61253-7/abstract</p>

<p>

</p>

<p>
https://www.nextbigfuture.com/2021/07/2020-fatalities-for-us-roofers-increased-15-as-solar-roof-installations-increase.html</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
69 Conclusion from Studies</p>

<p>

</p>

<p>
Remember that in engineering terms, when comparing groups of numbers which contain both both very small numbers and one or more very large numbers, the differences between the small numbers are often not significant. </p>

<p>
The differences between the small numbers may be the product of our ability to measure these things rather than any real differences. </p>

<p>

</p>

<p>
70</p>

<p>
For example, in the article by Ritchie wind power would appear to be twice as dangerous as nuclear.</p>

<p>
However, the difference between them is 0.02 compared to 24.6 for coal. </p>

<p>
In other words, the difference between apparently "dangerous" wind and apparently "safe" nuclear is equivalent to 0.08% of the total for coal. </p>

<p>
It's therefore meaningless and a red herring to even worry about.</p>

<p>

</p>

<p>
71</p>

<p>
With the above taken into consideration, generally the different sources of energy fall into two broad categories in terms of number of deaths, injuries, and illnesses.</p>

<p>
The fossil fuels and biomass fall into one group and wind, solar, and nuclear into another group.</p>

<p>

</p>

<p>
72</p>

<p>
Hydro power would seem to fall into the higher risk category or at least somewhere between the two,  but this I suspect is mainly due to one exceptionally large dam collapse in China, the Banqian Dam failure in 1975.</p>

<p>
This is mentioned as being specifically included in the article written by Ritchie.</p>

<p>
This was a multi-purpose dam, and information on this dam is difficult to find.</p>

<p>
It is not clear to me whether it had a hydro electric generator associated with either it or another dam that was part of the same system.</p>

<p>

</p>

<p>
73</p>

<p>
Some people therefor may argue for its exclusion from the numbers.</p>

<p>
Of course some people may argue for its inclusion anyway, as it was a dam regardless of whether it actually had an electric generator attached.</p>

<p>
If we exclude it, then I think the numbers for hydro power would fall into the same range as for nuclear, wind, and solar.</p>

<p>

</p>

<p>
74</p>

<p>
Most people would consider hydro power to be safe and clean enough regardless of this and I will rank it as such in any conclusions that I come to. </p>

<p>
As you can see, even if we have numbers, it can be a matter of opinion as to how to interpret them.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
75 Taking a Systems Approach</p>

<p>

</p>

<p>
Now let's take a look at the broader energy picture today and into the future.</p>

<p>
Many countries in many parts of the world have committed to the concept of "Net Zero", which means eliminating carbon emissions on a net basis.</p>

<p>
Net zero essentially means the complete electrification of society.</p>

<p>
We must therefore have electrical energy on demand and at low cost.</p>

<p>
We must as a result of this look at complete electrical systems rather than individual sources in isolation.</p>

<p>

</p>

<p>
76</p>

<p>
At one time many electrical systems were entirely coal or entirely hydroelectric.</p>

<p>
This is no longer the case.</p>

<p>
There are now major amounts of wind and solar involved in many countries.</p>

<p>
However these are inherently intermittent.</p>

<p>
This means that other sources of energy are inherently also required to have a functional system.</p>

<p>

</p>

<p>
77</p>

<p>
If any particular solution inherently requires fossil fuels to meet part of the demand, then the safety, pollution, and climate issues relating to those fossil fuels have to be factored in to that complete system when trying to come up with a relative ranking.</p>

<p>

</p>

<p>
Talking about Individual sources in isolation are therefore meaningless in these countries.</p>

<p>

</p>

<p>
78</p>

<p>
There are battery systems,  but these are mainly used to stabilize and regulate the grid plus to a lesser degree to smooth out short term daily peaks in demand. </p>

<p>
They do not have the ability to store large amounts of electricity on a large scale for an entire grid for days, weeks, and months to make up for intermittency. </p>

<p>

</p>

<p>
79</p>

<p>
So a serious attempt to rank sources of energy would need to look at a variety of representative countries and for each one come up with a plan that involves 'x' megawatts from source 'a', 'y' megawatts from source 'b', etc., and total up the values for each. </p>

<p>

</p>

<p>
80</p>

<p>
I am not aware of anyone who has studied this larger issue.</p>

<p>
However, the problem has to be addressed from this perspective in order for any answer to be useful.</p>

<p>
Not taking this into account is like ordering a diet soft drink to go with with a high calorie meal and assuring yourself that your plans to diet are fine. </p>

<p>

</p>

<p>
81</p>

<p>
This is not to imply there is anything inherently wrong with wind or solar.</p>

<p>
It does mean that if your goal is to achieve both net zero and a clean environment, you have to look at your entire energy system as a complete system rather than focusing on what you feel are the most reassuring parts of it while ignoring the rest.</p>

<p>

</p>

<p>
This does however add to the argument that it is in fact inherently very difficult to come up with a system of ranking energy sources for safety.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
82 Nuclear, Climate, and Clean Air - Contrasting Examples</p>

<p>

</p>

<p>
To give a tangible example we will now look at two different places that followed two divergent paths at roughly around the same time frame.</p>

<p>

</p>

<p>
These are the province of Ontario in Canada, and Germany. </p>

<p>

</p>

<p>
83</p>

<p>
Ontario had a mix of coal, hydro electric, and nuclear generating plants.</p>

<p>
Germany had a mix of coal, nuclear and natural gas plants.</p>

<p>

</p>

<p>
Ontario shut down their coal fired plants and kept their nuclear plants.</p>

<p>
Germany however shut down their nuclear plants and kept their coal fired plants.</p>

<p>

</p>

<p>

</p>

<p>
84 The Phase Out of Coal in Ontario</p>

<p>

</p>

<p>
In 2003 Ontario decided to close all of its coal fired generating plants, which consisted of 19 units (that is boilers and turbines) totalling 8,800 MW.</p>

<p>
This phase out was completed by 2014.</p>

<p>

</p>

<p>
85</p>

<p>
Here are the figures for amount of power generated by each energy source in 2003 and 2014.</p>

<p>
Nuclear went from 42% to 60%</p>

<p>
Hydro went from 23% to 24%</p>

<p>
Gas went from 11% to 9%</p>

<p>
Coal went from 25% to 0%</p>

<p>
Non-hydro renewable went from 0% to 7%.</p>

<p>

</p>

<p>
86</p>

<p>
As you can see, the bulk of that replacement came from increased use of nuclear power. </p>

<p>
Furthermore, this did not result in simply replacing coal with natural gas.</p>

<p>
While gas is cleaner than coal, it still has emissions and if you recall from the studies that we looked at earlier, had an estimated death rate roughly 2 orders of magnitude greater than nuclear, solar, or wind.</p>

<p>

</p>

<p>
87</p>

<p>
To put this in more practical terms, at one time Toronto regularly had clouds of smog obscuring it, to a large extent due to these coal fired power plants</p>

<p>

</p>

<p>
With the phase out of coal, smog days went to zero in 2015 compared to 53 a decade earlier.</p>

<p>

</p>

<p>
The 2023 figures for Ontario show carbon emissions of 53 grams per kWh of electricity generated.</p>

<p>
We can use this as a rough benchmark comparison for total emissions.</p>

<p>

</p>

<p>

</p>

<p>
88 The Phase out of Nuclear in Germany</p>

<p>
Until March of 2011, Germany generated one quarter of its electrical power from nuclear.</p>

<p>
Starting in 2011 however, they began shutting down their nuclear power plants.</p>

<p>
These were then phased out over the next decade.</p>

<p>
However, the coal plants were to be kept to 2038.</p>

<p>
In 2026 Germany began talking about increasing use of coal in order to save gas.</p>

<p>
In the same year the German chancellor Friedrich Merz stated that the phase out of nuclear was a </p>

<p>
quote  “serious strategic mistake”.</p>

<p>
EU Commission President Ursula von der Leyen said it was "a strategic mistake for Europe to turn its back on a reliable, affordable source of low-emissions power".</p>

<p>

</p>

<p>
89</p>

<p>
I won't go into the details of the phase out, but let's look at some emissions numbers for Germany.</p>

<p>
If we look at the official numbers from the European Environmental Agency for 2024, for Germany their emissions were 298 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Recall that we are using emissions as a very rough guide to amount of air pollution, and that this has a direct effect on the safety of the overall electrical energy system.</p>

<p>

</p>

<p>
90</p>

<p>
So, who actually made their people safer, Ontario who phased out their coal plants and kept their nuclear plants, or Germany who phased out their nuclear plants and kept their coal plants?</p>

<p>

</p>

<p>
91</p>

<p>
If you want a comparison directly within Europe, then Germany has one of the highest rates of emissions per kWh of electricity generated, whereas France, who use mainly nuclear power, have one of the lowest at 43 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Again, who is making their people safer, Germany or France?</p>

<p>

</p>

<p>
92</p>

<p>
I don't want to make it sound like I am picking on Germany.</p>

<p>
I am also not going to tell them how they ought to run their country. </p>

<p>
However they provide a good real world example of how we need to look at things in overall context when we are thinking about the choices that we make. </p>

<p>

</p>

<p>

</p>

<p>
https://www.ontario.ca/page/end-coal</p>

<p>
https://www.cbc.ca/news/canada/windsor/smog-study-shows-significant-decreases-in-pollutants-in-ontario-1.4151183</p>

<p>

</p>

<p>
https://www.eea.europa.eu/en/analysis/indicators/greenhouse-gas-emission-intensity-of-1</p>

<p>
https://world-nuclear.org/information-library/country-profiles/countries-g-n/germany</p>

<p>

</p>

<p>
https://www.politico.eu/article/friedrich-merz-is-right-to-reject-germanys-nuclear-phase-out-says-iea-chief-fatih-birol/</p>

<p>

</p>

<p>
https://www.politico.eu/article/germany-considers-ramping-up-coal-power-to-avert-energy-crisis/</p>

<p>

</p>

<p>
https://www.iea.org/countries/estonia/electricity</p>

<p>
https://www.iea.org/countries/malta/electricity</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>
 </p>

<p>
93 Conclusions</p>

<p>
As we can see, there don't appear to be an abundance of peer reviewed scientific studies that we can simply point to in order to answer the question of safety of all possible major different energy sources once and for all.</p>

<p>

</p>

<p>
Collecting the data to even attempt to answer the question is inherently very difficult as we cannot readily conduct experiments to answer the question, and sources of data are not collected or consolidated in a manner which can answer this question adequately.</p>

<p>

</p>

<p>
94</p>

<p>
The essence of the problem is that most energy industries are not as tightly regulated and monitored to the same degree that say nuclear power or commercial airliners are, so this data is simply not being systematically recorded.</p>

<p>

</p>

<p>
However, a number of people have attempted to make estimates.</p>

<p>

</p>

<p>
95</p>

<p>
Their conclusions would seem to be that nuclear, wind, and solar are roughly equivalent in terms of safety.</p>

<p>
All fossil fuels are much less safe than nuclear, wind, and solar, by as much as several orders of magnitude.</p>

<p>

</p>

<p>
96</p>

<p>
We can however say with a reasonable degree of certainty that if a country shut down their nuclear power plants and kept their fossil fuel plants, particularly coal, then they probably made their people less safe than if they had done things the other way around. </p>

<p>

</p>

<p>
97</p>

<p>
I hope that I have provided some context in which to think about the issue. </p>

<p>

</p>

<p>
Thanks again to brian in ohio for providing the question upon which this episode is based.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4668/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wikipedia Cofounder Larry Sanger Banned From Site for 'Canvassing']]></title>
<description><![CDATA[Wikipedia cofounder Larry Sanger has been indefinitely banned from editing the site after editors concluded that he violated its canvassing rules, "or in other words, calling on his followers off platform in order to influence Wikipedia's content," reports 404 Media. Sanger says the ban proves Wi...]]></description>
<link>https://tsecurity.de/de/3619597/it-security-nachrichten/wikipedia-cofounder-larry-sanger-banned-from-site-for-canvassing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619597/it-security-nachrichten/wikipedia-cofounder-larry-sanger-banned-from-site-for-canvassing/</guid>
<pubDate>Tue, 23 Jun 2026 23:07:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wikipedia cofounder Larry Sanger has been indefinitely banned from editing the site after editors concluded that he violated its canvassing rules, "or in other words, calling on his followers off platform in order to influence Wikipedia's content," reports 404 Media. Sanger says the ban proves Wikipedia suppresses ideological diversity, while editors argue he was trying to mobilize an outside audience to influence internal decisions and had ignored an earlier warning. From the report: The discussion that led to the decision to ban Sanger concluded with what an editor called a "clear consensus" to ban Sanger. "There is general agreement among participants that he has engaged in off-wiki canvassing and is not here to constructively build the encyclopedia," the editor said in a note closing the discussion. "There is also a significant concern shared by many editors that his actions constitute calls for outing."
 
While Sanger has been railing about bias on Wikipedia for years, the specific issue here is around his WikiProject Intellectual Diversity. WikiProjects are group efforts among Wikipedia volunteers to deal with certain issues on the site. [...] Sanger's WikiProject Intellectual Diversity, as its name implies, aims to bring more intellectual diversity to the site, mostly meaning more right-leaning perspectives. Sanger's WikiProject Intellectual Diversity and its goals alone do not merit a ban according to Wikipedia's policies. The problem, according to Wikipedia editors, is that during the discussion about whether to allow WikiProject Intellectual Diversity to become an official WikiProject, Sanger invited his 91,000 followers on X to influence that discussion.
 
Discussions about potential bans are supposed to remain open for at least 72 hours. While consensus that Sanger had violated Wikipedia policies was clear, Sanger was banned at some point before that deadline. He was then briefly unbanned, and then again indefinitely banned once 72 hours had elapsed and the discussion about the ban closed. "Wikipedia has become more of a mob-rule anarchy than ever," Sanger said in a statement sent to me by a spokesperson. "In the kangaroo court in which a mob ousted me, Wikipedia's administrators showed that they don't appear to value details like formal charges, a designated prosecutor, basic decorum, distinction between prosecution and judge, dispassionate adjudication, and so forth. They have no proper system other than triggering a mob to selectively enforce their hodgepodge of vague rules."
 
"Now that same mob has blocked me for trying to bring an intellectually diverse group of thinkers and editors to the site," Sanger continued. "Subscribing to their groupthink is now an official requirement of being a member in good standing. Something must change, and now. I only wonder if the system as it currently stands can even allow the discourse necessary to fix the system."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Wikipedia+Cofounder+Larry+Sanger+Banned+From+Site+for+'Canvassing'%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F23%2F1948242%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F23%2F1948242%2Fwikipedia-cofounder-larry-sanger-banned-from-site-for-canvassing%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/23/1948242/wikipedia-cofounder-larry-sanger-banned-from-site-for-canvassing?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 20 years of AWS taught me about agentic AI]]></title>
<description><![CDATA[This year marks the 20th anniversary of AWS — and my 20th year building at Amazon.



My entire career is for the sole purpose of making developers’ lives easier. As a developer, it is a bit of a self-serving purpose. For example, I was constantly distracted by operating databases, so I joined th...]]></description>
<link>https://tsecurity.de/de/3617835/it-nachrichten/what-20-years-of-aws-taught-me-about-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617835/it-nachrichten/what-20-years-of-aws-taught-me-about-agentic-ai/</guid>
<pubDate>Tue, 23 Jun 2026 12:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>This year marks the 20th anniversary of AWS — and my 20th year building at Amazon.</p>



<p>My entire career is for the sole purpose of making developers’ lives easier. As a developer, it is a bit of a self-serving purpose. For example, I was constantly distracted by operating databases, so I joined the DynamoDB team to build a service that handles that, so that other developers and I would never have to operate databases again.</p>



<p>I then went on to work on Lambda and API <a>Gateway</a>. I didn’t have to babysit servers or handle request routing, and on CloudWatch, so I could see what my code was doing in production. Each time, the goal was the same: remove the painful, repetitive work and turn it into a service that just works.</p>



<p>I’m still chasing the same goal, just with a very different set of tools.</p>



<h2 class="wp-block-heading">The rise — and limits — of vibe coding</h2>



<p>Large language models added the ability to describe what I want in natural language and have code synthesized on demand. At first, this looked like “<a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development-how-to-choose.html?utm=hybrid_search">vibe coding</a>” — ask for a change to the script, compile it, run it, copy the errors back and hope the next iteration was better.</p>



<p>Things got interesting when we wrapped the whole “vibe coding” workflow in agentic loops. Instead of me feeding back every error, an agent could call the model, run the code, see its own failures and keep iterating until tests passed. But there was a big problem: the agents wandered. That’s fine for side projects, not fine for large, critical codebases.</p>



<h2 class="wp-block-heading">Spec‑driven development for agents</h2>



<p>The way I’ve come <a href="https://kiro.dev/blog/kiro-and-the-future-of-software-development/" rel="nofollow">to keep agents focused is through spec‑driven development</a>. Instead of dropping an agent into a repo with a vague prompt, I co‑create three concrete artifacts with it before any serious coding begins: a requirements spec, a design document and a task breakdown, all in Markdown. These are a shared contract for what “done” means, written in a form that both humans and agents can read, critique and update.</p>



<p>In my day-to-day, I start with almost the same prompt I’d give any AI, but the agent expands it into a structured requirements document with clear “shall” statements and acceptance criteria. I review those requirements and chat with the agent until the document matches what I actually want. From there, the agent proposes a design, then breaks the work into tasks focused on getting something tangible running before adding polish and exhaustive tests.</p>



<p>What I like about this flow is not that it’s rigid. In practice, I bounce back and forth. I often see a design that reveals missing requirements, or I change my mind about the approach once I see code snippets. The point is that agents no longer “forget” what we agreed on. The spec, design and tasks are explicit, versioned and always visible. And when I want to tack on another feature or bugfix, I start with a fresh spec that describes exactly what I want to change.</p>



<h2 class="wp-block-heading">Property‑based testing and keeping agents honest</h2>



<p>Once the specs are explicit, you can turn them into invariants and <a href="https://kiro.dev/blog/property-based-testing-fixed-security-bug/" rel="nofollow">use property-based tests to keep agents honest</a>. Instead of writing one test for “given this exact input, expect this exact output,” I define properties that must hold across many inputs and sequences.</p>



<p>Without strong, spec-derived tests, I’ve seen agents game the system by “fixing” the tests instead of the code — commenting out assertions or weakening conditions just to get a green build. Property-based tests give me a way to encode my expectations once and have both humans and agents constantly prove we’re still meeting them.</p>



<p>This approach has clear implications for security as well. If security teams can encode expectations — about data handling, authorization and error behavior — as invariants in the same spec language the agent consumes, then property-based tests can hammer those invariants across many scenarios. That’s a much more robust way to shift security left than hoping every developer remembers every rule under deadline pressure.</p>



<h2 class="wp-block-heading">DevOps agents and the next decade of practice</h2>



<p>Over twenty years, I’ve learned that the key to incident response isn’t only about chasing the root cause — it’s systematically asking what changed, what callers changed, what limits were hit, what components failed as designed and what dependencies are involved.</p>



<p>A DevOps agent is becoming as important as any IDE. It <a href="https://aws.amazon.com/blogs/networking-and-content-delivery/automated-network-incident-response-with-aws-devops-agent/">plugs into the tooling teams already use and runs that investigation automatically whenever an alarm fires</a>. It reads logs, metrics, traces and code, and often has a diagnosis and plan ready by the time I open my laptop.</p>



<p>I’ve seen incidents that once took eight hours of human sleuthing reduced to fifteen minutes, with the agent explaining the bug, citing evidence, and recommending a rollback and follow-up fix.</p>



<p>Between incidents, the same system scans past outages and infrastructure to suggest preventative work — code hardening, better retries, alarm tuning — that teams rarely have time to prioritize on their own, and that’s the most important part. Reducing downtime is great, but avoiding it altogether is a big reason why we’re here.</p>



<p>Looking ahead, I think developers will learn to wear all sorts of other hats — the operator, product manager, customer support — while agents take on their routine tasks. The most valuable work becomes problem-solving and ensuring systems are built right and serve the right purpose.</p>



<p>Other things won’t change at all. “If you build it, you run it” still applies, even when an agent wrote part or all of the code. Developers will still own production and post‑incident retrospectives that focus on how to prevent issues. Some parts — like data collection, impact analysis, root cause analysis — get faster with agents doing the legwork, but developers still direct the investigation, decide the real fixes and share those lessons across teams.</p>



<p>Twenty years ago, the big shift was turning infrastructure into services, so developers didn’t have to think about <a>racking</a> servers or babysitting databases. In this new era, the move is turning our best practices, operational experience and security expectations into specs and agents that can execute them consistently, at any scale. The lesson from the first two decades still applies: The pain you tolerate today is the platform someone else will build tomorrow — only now, agents give us a much faster way to close that gap.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New supply chain source is sure iPhone Fold will launch in September 2026]]></title>
<description><![CDATA[The on/off back and forth about when the iPhone Fold will be released continues, but now a shaky report claims the first batches have been manufactured and will ship alongside the iPhone 18 Pro in September.Mockup of a possible design for the expected iPhone Fold - image credit: AppleInsiderThe l...]]></description>
<link>https://tsecurity.de/de/3615949/ios-mac-os/new-supply-chain-source-is-sure-iphone-fold-will-launch-in-september-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615949/ios-mac-os/new-supply-chain-source-is-sure-iphone-fold-will-launch-in-september-2026/</guid>
<pubDate>Mon, 22 Jun 2026 17:26:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The on/off back and forth about when the <a href="https://appleinsider.com/inside/iphone-fold" title="iPhone Fold" data-kpt="1">iPhone Fold</a> will be released continues, but now a shaky report claims the first batches have been manufactured and will ship alongside the iPhone 18 Pro in September.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68017-143383-000-lead-iPhone-Fold-xl.jpg" alt="Close-up of a sleek silver foldable smartphone, highlighting two large rear camera lenses and a small flash on a raised rectangular camera module against a dark background" height="720"><br><span>Mockup of a possible design for the expected iPhone Fold - image credit: AppleInsider</span></div><br>The likelihood of Apple launching an iPhone Fold in September 2026 seems to change depending on the day. The latest rotating rumors have been either that it's delayed <a href="https://appleinsider.com/articles/26/06/15/here-we-go-again-supply-chain-thinks-iphone-fold-will-ship-in-2027-not-2026">until 2027</a>, or that it is <a href="https://appleinsider.com/articles/26/06/16/strident-leaker-insists-iphone-fold-is-not-delayed-at-all">exactly on schedule</a>. Now according to <em>China Securities Journal</em>, a supplier <a href="https://jnzstatic.cs.com.cn/zzb/htmlInfo/8bcfd4227092074a1279ca3742b8c18e.html">has revealed</a> that Apple has begun shipping the iPhone Fold in small batches.<br><br>If correct, that would be a significant step considering that the iPhone Fold is believed to have only entered manufacturing testing in <a href="https://appleinsider.com/articles/26/04/06/iphone-fold-enters-manufacturing-test-phase-right-on-schedule">April 2026</a>. It's also variously been reported that this testing has uncovered serious problems <a href="https://appleinsider.com/articles/26/05/18/problematic-hinge-could-delay-the-iphone-fold">with the hinge</a>, and also the main <a href="https://appleinsider.com/articles/26/05/26/iphone-fold-now-reportedly-held-up-by-circuit-board-problems">circuit board</a>.<br><br><br> <strong>Rumor Score:</strong> 🤔 Possible <br><br><br> <a href="https://appleinsider.com/articles/26/06/22/new-supply-chain-source-is-sure-iphone-fold-will-launch-in-september-2026?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244724?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4666: How I got into tech]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


I started out with Basic on the TI-99/4A in 1984. The bare machine could not be programmed by the user in machine code. In 1985 I bought a ZX Spectrum, that gave me total control over the machine.


I wrote two FORTH systems on the ZX-Spectrum.

...]]></description>
<link>https://tsecurity.de/de/3614279/podcasts/hpr4666-how-i-got-into-tech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614279/podcasts/hpr4666-how-i-got-into-tech/</guid>
<pubDate>Mon, 22 Jun 2026 02:03:34 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
I started out with Basic on the <a href="https://en.wikipedia.org/wiki/TI-99/4A">TI-99/4A</a> in 1984. The bare machine could not be programmed by the user in machine code. In 1985 I bought a <a href="https://en.wikipedia.org/wiki/ZX_Spectrum">ZX Spectrum</a>, that gave me total control over the machine.</p>

<p>
I wrote two <a href="https://en.wikipedia.org/wiki/Forth_(programming_language)">FORTH</a> systems on the ZX-Spectrum.</p>

<p>
In 1988 I got my first <a href="https://en.wikipedia.org/wiki/Intel_8088">8088</a> PC, also programming it in <a href="https://en.wikipedia.org/wiki/Forth_(programming_language)">FORTH</a>.</p>

<p>
In 1992 I got an <a href="https://en.wikipedia.org/wiki/I386">80386</a> PC and I ran Linux on it. MCC Interim Release from v. This was the first Linux distro.</p>

<p>
I have been using <a href="https://en.wikipedia.org/wiki/Linux">Linux</a> ever since. </p>

<p>
From then on I obtained newer PCs, such as a <a href="https://en.wikipedia.org/wiki/Pentium">Pentium</a> in 1995, a <a href="https://en.wikipedia.org/wiki/Pentium_II">Pentium-2</a> in 1998, a <a href="https://en.wikipedia.org/wiki/Pentium_4">Pentium-4</a> in 2003 and a Core-2 Duo in 2006.</p>

<p>
I used several <a href="https://hackerpublicradio.org/eps/hpr4666/%3Ca%20href=" https:>Linux</a> distributions: but I always return to Debian.</p>

<h3>Links:</h3>


<ul>
<li><a href="https://github.com/ForthHub/F83">https://github.com/ForthHub/F83</a> F83.COM is the ready to run FORTH system. </li>
<li><a href="https://github.com/uho/F-PC">https://github.com/uho/F-PC</a> F-PC - a Forth system optimized for IBM-PC, XT and AT machines running DOS</li>
<li><a href="https://www.latte.org/latte.html">https://www.latte.org/latte.html</a>Latte The Language for Transforming Text</li>
<li><a href="https://en.wikipedia.org/wiki/Joe's_Own_Editor">https://en.wikipedia.org/wiki/Joe's_Own_Editor</a>           </li>
<li><a href="https://www.freebsd.org/">https://www.freebsd.org/</a></li>
<li><a href="https://www.debian.org/">https://www.debian.org/</a></li>
<li><a href="https://www.gentoo.org/">https://www.gentoo.org/</a></li>
<li><a href="https://en.wikipedia.org/wiki/Mac_Mini">https://en.wikipedia.org/wiki/Mac_Mini</a></li>
<li><a href="https://en.wikipedia.org/wiki/PowerPC">https://en.wikipedia.org/wiki/PowerPC</a></li>
<li><a href="https://en.wikipedia.org/wiki/Ivy_Bridge_(microarchitecture)">https://en.wikipedia.org/wiki/Ivy_Bridge_(microarchitecture)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Ubuntu">https://en.wikipedia.org/wiki/Ubuntu</a></li>
<li><a href="https://en.wikipedia.org/wiki/Firefox">https://en.wikipedia.org/wiki/Firefox</a></li>
<li><a href="https://en.wikipedia.org/wiki/Chromium_(web_browser)">https://en.wikipedia.org/wiki/Chromium_(web_browser)</a></li>
<li><a href="https://www.raspberrypi.com/products/raspberry-pi-400/">https://www.raspberrypi.com/products/raspberry-pi-400/</a></li>
<li><a href="https://www.intel.com/content/www/us/en/ark/products/series/217838/12th-generation-intel-core-i5-processors.html">https://www.intel.com/content/www/us/en/ark/products/series/217838/12th-generation-intel-core-i5-processors.html</a></li>
<li><a href="https://en.wikipedia.org/wiki/Windows_11">https://en.wikipedia.org/wiki/Windows_11</a></li>
</ul><p><a href="https://hackerpublicradio.org/eps/hpr4666/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I just installed LFS 4.1!]]></title>
<description><![CDATA[It took me around a week to install Linux From Scratch 4.1, and I finally did it! I used Debian 3.0 as the host OS (obviously on VirtualBox, I don't have access to any old PCs from the 2000s to run it on) to resolve any possible problems when compiling 20+ year old packages (which were really har...]]></description>
<link>https://tsecurity.de/de/3613907/linux-tipps/i-just-installed-lfs-41/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613907/linux-tipps/i-just-installed-lfs-41/</guid>
<pubDate>Sun, 21 Jun 2026 19:10:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>It took me around a week to install Linux From Scratch 4.1, and I finally did it!<br> I used Debian 3.0 as the host OS (obviously on VirtualBox, I don't have access to any old PCs from the 2000s to run it on) to resolve any possible problems when compiling 20+ year old packages (which were really hard to get, I had to use the Wayback Machine and Debian/Slackware archives to get the correct packages... Before I discovered a dedicated internet archive page with all the required packages)</p> <p>I'm absolutely happy with the result. At least the system boots up without crashing</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Lolscope_from_2020"> /u/Lolscope_from_2020 </a> <br> <span><a href="https://i.redd.it/1t1kydwcul8h1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ublqw0/i_just_installed_lfs_41/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (dracut, podman, postfix, rsync, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (atril, firefox-esr, and nginx), Mageia (libcap, perl, and python-pillow), Oracle (firefox, gstreamer-plugins-base and gstreamer-plugins-good, httpd:2.4, kernel, ...]]></description>
<link>https://tsecurity.de/de/3607926/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607926/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 18 Jun 2026 15:25:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (dracut, podman, postfix, rsync, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Debian</b> (atril, firefox-esr, and nginx), <b>Mageia</b> (libcap, perl, and python-pillow), <b>Oracle</b> (firefox, gstreamer-plugins-base and gstreamer-plugins-good, httpd:2.4, kernel, libpng12, libpng15, libxml2, libxslt, opencryptoki, openssl, postfix, rsync, webkit2gtk3, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Slackware</b> (bind, libidn, mozilla, and openssl), <b>SUSE</b> (alloy, docker, elemental-system-agent, glibc, grafana, helm, LibVNCServer, openssh8.4, perl-GD, perl-HTTP-Daemon, python-WebOb-doc, python311-google-adk, rustup, traefik2, wireshark, and xwayland), and <b>Ubuntu</b> (dolibarr, golang-go.crypto, graphite2, gst-plugins-bad1.0, kitty, libconfig-inifiles-perl, libnginx-mod-js, and webpy).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in libidn (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606731/unix-server/security-pufferueberlauf-in-libidn-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606731/unix-server/security-pufferueberlauf-in-libidn-slackware/</guid>
<pubDate>Thu, 18 Jun 2026 07:46:24 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-firefox (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606730/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606730/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</guid>
<pubDate>Thu, 18 Jun 2026 07:46:23 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in bind (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606729/unix-server/security-preisgabe-von-informationen-in-bind-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606729/unix-server/security-preisgabe-von-informationen-in-bind-slackware/</guid>
<pubDate>Thu, 18 Jun 2026 07:46:22 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606728/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606728/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Thu, 18 Jun 2026 07:46:20 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in openssl (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606703/unix-server/security-mehrere-probleme-in-openssl-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606703/unix-server/security-mehrere-probleme-in-openssl-slackware/</guid>
<pubDate>Thu, 18 Jun 2026 07:30:59 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Is Bringing Together AI Design and Coding in Claude]]></title>
<description><![CDATA[New updates mean you should be able to go back and forth between coding and designing without interruptions.]]></description>
<link>https://tsecurity.de/de/3605947/it-nachrichten/anthropic-is-bringing-together-ai-design-and-coding-in-claude/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605947/it-nachrichten/anthropic-is-bringing-together-ai-design-and-coding-in-claude/</guid>
<pubDate>Wed, 17 Jun 2026 21:47:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New updates mean you should be able to go back and forth between coding and designing without interruptions.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stanford's DeLM cuts multi-agent task costs 50% — without a central orchestrator]]></title>
<description><![CDATA[One of the assumptions behind today’s AI frameworks is that agents require a “boss” at the center; this orchestrator runs the show, routes requests, and makes sure the whole system doesn’t descend into chaos. That assumption may be wrong, and the cost of carrying it could be measured in inference...]]></description>
<link>https://tsecurity.de/de/3602933/it-nachrichten/stanfords-delm-cuts-multi-agent-task-costs-50-without-a-central-orchestrator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602933/it-nachrichten/stanfords-delm-cuts-multi-agent-task-costs-50-without-a-central-orchestrator/</guid>
<pubDate>Tue, 16 Jun 2026 20:47:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One of the assumptions behind today’s AI frameworks is that agents require a “boss” at the center; this orchestrator runs the show, routes requests, and makes sure the whole system doesn’t descend into chaos. </p><p>That assumption may be wrong, and the cost of carrying it could be measured in inference dollars and coordination latency. A new Stanford framework called a decentralized language model, or DeLM, is built on the premise that agents can coordinate directly, without routing every update through a central controller.</p><p>DeLM's shared knowledge base serves as a “common communication substrate” so that agents can build upon one another’s verified progress without having to route every interaction through a main agent to “merge, filter, and rebroadcast,” Yuzhen Mao and Azalia Mirhoseini, co-developers of the framework, explain in a <a href="https://arxiv.org/pdf/2606.10662">research paper</a>. </p><p>It’s a system that’s not only possible, but desirable in certain instances. “Agents can build on prior findings, avoid repeated failures, preserve constraints, and recover detailed evidence only when needed.”</p><h2>The challenges of traditional multi-agent systems</h2><p>In a typical centralized multi-agent system, a main agent breaks tasks into subtasks, assigns them out to multiple sub-agents in parallel, waits for responses, merges and summarizes intermediate progress, then launches a next wave of orders based on collected context. </p><p>While this is a natural way to scale LLM reasoning, the Stanford researchers argue that it scales poorly. Every useful finding, partial finding, and failure must be reported back to the main agent, which then determines what information to merge and rebroadcast to the agents below it. </p><p>“As the number of subtasks grows, this controller becomes a communication and integration bottleneck,” Mao and Mirhoseini write. Further, the main orchestrator may “dilute, omit, or distort” useful information, leading to lost progress. </p><p>This bottleneck also occurs in long-context reasoning scenarios. Once it receives reports back from subagents, a main agent will typically group related concepts, data points, and other materials together in an unsupervised learning loop. It may then pre-assign these "evidence clusters" to sub-agents before knowing what surfaced material is actually relevant or whether it’s combined correctly. </p><p>When a subagent receives this insufficient context, it will essentially get confused and return to the main agent, kicking off another retrieval or delegation round. “This back-and-forth makes coordination slower, more iterative, and increasingly constrained by a single overloaded main agent,” the researchers write. </p><div></div><h2>What DeLM addresses and how it works</h2><p>DeLM, by contrast, is built around parallel agents, a shared context, and a task queue. </p><p>Shared context is essentially a curated store of “gists,” or information summaries that other agents might find useful. These include verified and evidence-based findings alongside partial findings and documented failures; they also point to detailed evidence that agents can pull from based on their specific task. </p><p>A task queue is then a set of subsequent pending subtasks that agents can claim independently. </p><p>“Agents write compact, verified updates into a shared context that later agents can read directly,” the researchers write. Useful findings, failures, and constraints accumulate as a “shared problem state,” rather than passing through a central controller.</p><p>The pipeline looks like this: </p><ul><li><p><b>Initialization:</b> Inputs are broken into different work units and added to a queue; </p></li><li><p><b>Parallel execution: </b>Agents work independently and in tandem, pulling tasks and  reading shared context as they progress. </p></li><li><p><b>Compression and verification:</b> Results are compressed into reusable “gists” that are checked against supporting evidence. Only gists that are fully verified are shared with the group. </p></li><li><p><b>Additional work (if needed): </b>When the queue is emptied, the last agent to return an answer inspects all the shared context to determine whether further work is required. </p></li><li><p><b>Final step: </b>The last agent determines that no more steps are required and returns the final answer. </p></li></ul><p>Agents “exchange progress through shared state, asynchronously claim ready tasks, and scale more adaptively as the number of subtasks grows,” the researchers explain. </p><h2>How DeLM performs in the wild</h2><p>With DeLM, agents can avoid redundant exploration; reuse and build on each other’s discoveries and failures; and focus on unresolved issues.</p><p>The framework can be particularly useful in software engineering test-time scaling, when models are given time to “think” to improve their reasoning and problem-solving capabilities. Different agents can explore their own hypotheses or pursue reasoning paths in parallel, while still sharing intermediate progress. One example is concurrent de-bugging. </p><p>DeLM is also suitable for long-context reasoning and multi-document question-answering; agents can simultaneously examine their own evidence clusters (collections of papers, code, or other materials) at the same time, while maintaining a “global compact view” of accumulated evidence. </p><p>The researchers contend that it makes agentic tasks more accurate and significantly cheaper. This is backed by its performance on real-world benchmarks: On SWE-bench Verified — which evaluates how well AI models and agents solve real-world software engineering problems — it performed 10.5% better than the strongest baseline and reduced cost per task by roughly 50%. </p><p>But it can go beyond coding: On LongBench‑v2 Multi‑Doc QA — which assesses LLMs’ ability to handle long-context, real-world problems — DeLM had the highest accuracy across four model families, including GPT‑5.4, Claude Sonnet, Gemini Flash, and DeepSeek‑V4‑Pro. </p><p>DeLM outperforms other models on SWE-Bench <a href="https://x.com/Mao_Yuzhen/status/2064735740949622910">for a number of reasons</a>, as Mao detailed on X. </p><div></div><p>First, agents share failures. In ordinary parallel runs, when one agent follows the wrong path, that failure stays private, and subsequent agents may waste time (and money) pursuing the same dead end. But with DeLM, failed hypotheses are written into shared context. </p><p>“Later agents can read them as constraints, avoid repeated exploration, and redirect their search toward more promising fixes,” Mao said. </p><p>Additionally, constraints, once verified, are immediately added to agents’ shared context. This means they become a binding shared state. “Later agents inherit them, build around them, and avoid repeating globally invalid simplifications,” Mao said. </p><p>Crucially, DeLM keeps shared progress compact enough to reuse. It is unfoldable, meaning agents see short gists by default, but can choose to unfold them into more detailed summaries and raw evidence. </p><p>As the researchers note, providing all raw documents and traces gives agents the maximum amount of information, but that can overwhelm their context windows and ultimately increase costs. </p><p>“If agents shared full traces, each worker would need to read long command histories, file dumps, failed edits, and intermediate reasoning, turning coordination itself into another long-context bottleneck,” Mao said. </p><p>On the other hand, while sharing compact summaries is cheaper, important details and evidence can be lost, resulting in less reliable reasoning. </p><p>Unfolding, therefore, provides “coarse-to-fine” opt-in access. This can improve accuracy and cost.</p><p>Ultimately, with a framework like DeLM, agents can be more efficient because they are prevented from repeatedly reading the same documents or rerunning the same failed analysis; more effective because useful findings are propagated across parallel threads; and more robust because they only share verified claims. </p><p>For enterprise builders, DeLM challenges a core assumption: that every multi-agent workflow needs a central controller. The SWE-bench and LongBench-v2 results suggest the decentralized model isn't just theoretically cleaner — it's faster, more accurate, and roughly half the cost.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Strident leaker insists iPhone Fold is not delayed at all]]></title>
<description><![CDATA[The back and forth of conflicting claims about the iPhone Fold continues, as now a vocal leaker has repeatedly scorned reports of the device being delayed until 2027.iPhone Fold leakers continue to argue over whether it has been delayedJust to be clear, the previous most recent rumor about the iP...]]></description>
<link>https://tsecurity.de/de/3601515/ios-mac-os/strident-leaker-insists-iphone-fold-is-not-delayed-at-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601515/ios-mac-os/strident-leaker-insists-iphone-fold-is-not-delayed-at-all/</guid>
<pubDate>Tue, 16 Jun 2026 12:51:08 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The back and forth of conflicting claims about the <a href="https://appleinsider.com/inside/iphone-fold" title="iPhone Fold" data-kpt="1">iPhone Fold</a> continues, as now a vocal leaker has repeatedly scorned reports of the device being delayed until 2027.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67787-142868-Squat-Fold-11-xl.jpg" alt="Gold foldable iPhone render standing on a reflective surface beside a small glowing cat-shaped lamp, with warm lighting and wooden background creating a cozy, modern desk scene" height="738"><br><span>iPhone Fold leakers continue to argue over whether it has been delayed</span></div><br>Just to be clear, the previous most recent rumor about the iPhone Fold was that Apple <a href="https://appleinsider.com/articles/26/06/15/here-we-go-again-supply-chain-thinks-iphone-fold-will-ship-in-2027-not-2026">will announce</a> it as expected in September 2026, but it will not actually ship until early 2027. But now leaker Fixed Focus Digital on Chinese social media site Weibo says no, no, and <a href="https://weibo.com/5821279480/R4mt31FAo">four times no</a>.<br><br>It's an unusual post for the leaker in that it just quotes four headlines, without attribution, and says they're wrong. In translation, two of these apparent headlines are identical, but then so is the leaker's response. "Fake," he says next to those.<br><br><br> <a href="https://appleinsider.com/articles/26/06/16/strident-leaker-insists-iphone-fold-is-not-delayed-at-all?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244667?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[When deep research isn't enough for your business: Sakana AI launches 'ultra deep research' agent for 100+ page reports in 8 hours]]></title>
<description><![CDATA[Tokyo-based AI startup Sakana AI has officially launched its first commercial product, Sakana Marlin. Billed as a "Virtual CSO" (Chief Strategy Officer), Marlin is an autonomous, B2B research agent that deliberately abandons the instantaneous text generation of modern chatbots in favor of deep, l...]]></description>
<link>https://tsecurity.de/de/3600172/it-nachrichten/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600172/it-nachrichten/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tokyo-based AI startup Sakana AI has officially launched its first commercial product, <a href="https://sakana.ai/marlin/">Sakana Marlin</a>. </p><p>Billed as a "<a href="https://sakana.ai/marlin-release/#English">Virtual CSO</a>" (Chief Strategy Officer), Marlin is an autonomous, B2B research agent that deliberately abandons the instantaneous text generation of modern chatbots in favor of deep, long-horizon reasoning. </p><p>What sets Marlin apart from the current ecosystem of AI tools is its temporal scale: instead of returning an answer in seconds, it runs continuous, self-governing reasoning loops for up to eight hours at a time to deliver deeply researched, well cited, 100-page strategy reports and executive slides. The company posted sample reports generated my Marlin on its product website <a href="https://sakana.ai/marlin/">here</a>.</p><p>Available immediately via the company’s website with pricing starting at a pay-as-you-go tier, the platform is designed strictly for enterprise use—specifically targeting corporations, financial institutions, and think tanks. </p><p>The generative AI hype cycle has largely been defined by speed. For the past two years, the industry standard has been the ability to generate a poem, a line of code, or a surface-level summary in mere milliseconds. But the enterprise frontier is rapidly shifting from shallow, rapid generation to deep, methodical reasoning. </p><p>With Marlin, major businesses are no longer asking how fast an AI can answer, but how deeply it can think.</p><h2><b>The Product: A Virtual CSO</b></h2><p>What exactly is a business getting when they deploy Sakana Marlin? The workflow is fundamentally different from typical large language model (LLM) interactions. Rather than engaging in a tedious back-and-forth prompt engineering session, the user simply provides a core research topic. Following a brief initial exchange to sharpen the scope and direction of the investigation, the human steps away entirely.</p><p>For the next several hours, Marlin operates as a self-contained digital strategy team. It formulates its own initial hypotheses, navigates the web to gather data, cross-references sources to verify findings, and maps the causal dynamics within complex business environments. It is effectively searching for the "winning formula" within a sea of noise.</p><p>Think of it less like a search engine and more like a junior strategy consultant locked in a room with a whiteboard and an internet connection. You provide the strategic prompt in the morning, and by the end of the workday, the system delivers a comprehensive, professional-grade portfolio. </p><p>In Marlin's case, the final output is not a generic text blob; it is a structured set of strategic options, complete with executive summary slides, appendices, references, and a deeply researched report. </p><p>The company highlighted several real-world use cases to demonstrate Marlin's capacity for complex synthesis, including generating detailed resolution scenarios for a theoretical blockade of the Strait of Hormuz, mapping out the fragmented global AI regulation patchwork, and analyzing macroeconomic trends like the return of "bond vigilantes".</p><p>Sakana says Marlin relies on multiple AI models, but did not provide specific model names or providers. I've reached out on X to find out more and will update when I receive a repsonse.</p><h2><b>The Engine of Long-Horizon Reasoning</b></h2><p>Under the hood, Marlin is the commercial culmination of Sakana AI’s extensive laboratory breakthroughs over the past two years. </p><p>The product is powered by an exploration engine relying on Sakana's own prior research breakthrough, <a href="https://sakana.ai/ab-mcts/">Adaptive Branching Monte Carlo Tree Search (AB-MCTS)</a>, and leverages frameworks derived from "The AI Scientist," an earlier Sakana AI research project featured in the journal <i>Nature</i> that successfully automated the scientific discovery process from ideation to peer review.</p><p>To understand how this works in practice, consider a real-world analogy: modern chess engines. When a computer plays chess, it doesn't just look at the board and guess; it plays out thousands of potential future moves, evaluating the strength of each resulting position before committing to an action. </p><p>Marlin’s AB-MCTS engine does something similar for research. </p><h2><b>Inside the Engine: The Mechanics of AB-MCTS</b></h2><p>The chronology of this technology traces back to June 2025, when Sakana AI first introduced the framework to the public alongside the research paper <i>“</i><a href="https://arxiv.org/pdf/2503.04412"><i>Wider or Deeper? Scaling LLM Inference-Time Compute with Adaptive Branching Tree Search</i></a><i>”</i>. </p><p>At that time, to encourage developer experimentation with collective AI intelligence, the company released the underlying algorithm as an open-source software library called <b>TreeQuest</b>, distributed under the permissive <b>Apache 2.0 license</b>. This open-source milestone laid the technical foundation for what would eventually evolve into the proprietary, enterprise-grade Marlin product a year later.</p><p>Traditionally, when developers attempt to extract higher-quality reasoning from large language models, they rely on a brute-force method called "repeated sampling"—essentially running the model dozens of times in parallel and hoping one of the answers is correct. However, repeated sampling operates blindly; it cannot evaluate its own intermediate steps or pivot based on external feedback.</p><p>AB-MCTS replaces this paradigm with a principled, multi-turn approach driven by a Bayesian decision framework. As the AI constructs a strategy report, the system treats the research process as a branching tree of possibilities. At each node of the tree, the algorithm dynamically balances two distinct behaviors based on external feedback signals:</p><ul><li><p><b>Going Wider (Exploration):</b> Spawning entirely new, alternative hypotheses or candidate responses when the current path yields diminishing returns or unresolved contradictions.</p></li><li><p><b>Going Deeper (Exploitation):</b> Methodically refining, auditing, and building upon an existing candidate solution that shows high strategic promise.</p></li></ul><p>What transforms this from a laboratory experiment into a commercial engine is its extension into <b>Multi-LLM AB-MCTS</b>. </p><p>Sakana AI’s architecture introduces a critical third dimension to the search tree: the ability to dynamically choose <i>which</i> model to invoke for a specific sub-task, treating the industry’s leading frontier models as a plug-and-play collective intelligence network.</p><p>According to technical documentation published by the company, the engine can coordinate highly heterogeneous models—allowing an orchestration model to delegate initial ideation to one LLM, while utilizing a reasoning-heavy model to audit, verify, and correct intermediate errors generated earlier in the search tree.</p><p>By scaling up compute at inference time—leveraging the distinct "personalities" and strengths of multiple foundation models over thousands of automated cycles—AB-MCTS provides the mathematical guardrails Marlin requires. It ensures that the resulting 100-page strategy reports are not merely long-winded AI generations, but the highly vetted product of systemic, automated trial-and-error.</p><h2><b>Licensing, Data, and Enterprise Implications</b></h2><p>It is crucial to note that Sakana Marlin is distinctly not a general consumer tool; it is a commercial software-as-a-service (SaaS) offering restricted to corporate entities, organizations, and sole proprietors.</p><p>For enterprises, licensing and data handling terms are often the determining factors in software adoption. Unlike many consumer-grade AI tools that silently harvest user inputs and proprietary data to train future foundational models, Sakana Marlin operates under a strict, enterprise-grade data policy. </p><p>Neither Sakana AI nor its external AI service providers will use customer data or inputs for model training or fine-tuning unless the client provides explicit opt-in consent. </p><p>Even with consent, data is heavily processed to remove personally identifiable information. This closed-loop security is absolutely vital for companies handling sensitive M&amp;A research, unreleased product strategies, or proprietary market analyses.</p><p>The commercial licensing is structured into tiered pricing models that reflect its enterprise nature:</p><ul><li><p><b>Pay-as-you-go:</b> Users can purchase credits on demand, with a single run costing 100 credits, and add-on credits priced at ¥98 ($0.61 USD) each.</p></li><li><p><b>Pro Plan:</b> At ¥150,000 ($935.68 USD) per month, businesses receive 2,000 credits, bringing down the cost of add-on credits to ¥90 ($0.56 USD).</p></li><li><p><b>Team Plan:</b> Geared toward larger departments, this ¥400,000 ($2,495.14 USD) per month tier includes 6,000 credits, lowering add-on costs to ¥85 ($0.53 USD) per credit.</p></li><li><p><b>Enterprise:</b> Fully custom quotes with dedicated support and customized credit allocations.</p></li></ul><h2><b>Why Sakana Is Worth Watching</b></h2><p>Sakana AI’s transition into a commercial enterprise powerhouse is rooted in the pedigree of its founders, who famously helped spark the current generative AI boom. </p><p><a href="https://venturebeat.com/ai/what-you-need-to-know-about-sakana-ai-the-new-startup-from-a-transformer-paper-co-author">Formed in Tokyo in 2023</a>, the startup was co-founded by Llion Jones—a co-author of Google’s seminal 2017 “Attention Is All You Need” paper who coined the term “transformer”—and David Ha, a former Google Brain researcher and head of research at Stability AI. </p><p>The decision to build a new laboratory outside the Silicon Valley bubble was a deliberate rejection of the current AI ecosystem. At a TED AI conference in late 2025, <a href="https://venturebeat.com/technology/sakana-ais-cto-says-hes-absolutely-sick-of-transformers-the-tech-that-powers">Jones candidly expressed that he was "absolutely sick" of transformers</a>, warning that the intense pressure from investors and the hyper-fixation on scaling single, monolithic models had calcified the industry's creativity and blinded researchers to the next major breakthrough.</p><p>To break free from this "big company-itis," Jones and Ha structured Sakana AI around principles of biomimicry and evolutionary computing. </p><p>The company's name, derived from the Japanese word for fish, reflects its core technical philosophy: leveraging collective intelligence similar to schools of fish, ant colonies, or insect swarms. Rather than attempting to build one massive, do-it-all foundation model, Sakana’s research has consistently focused on deploying networks of smaller, specialized models that collaborate dynamically to adapt to complex environments. </p><p>This philosophy posits that by treating individual AI models as members of a "dream team" with complementary strengths, systems can achieve more robust and cost-effective reasoning than relying on sheer scale alone.</p><p>This nature-inspired approach quickly yielded dividends in rigorous, competitive testing. Sakana AI has made significant strides in "inference-time scaling"—allocating computational resources during the problem-solving phase to allow models to think, iterate, and refine their own answers over extended periods. </p><p>In early 2026, the company’s<a href="https://sakana.ai/ahc058/"> ALE-Agent took first place in the highly complex AtCoder Heuristic Contest (AHC058),</a> a combinatorial optimization challenge, outperforming over 800 top-tier human programmers by autonomously rebuilding and testing hundreds of solutions over a four-hour window. </p><p>Similarly,<a href="https://venturebeat.com/orchestration/how-sakana-trained-a-7b-model-to-orchestrate-gpt-5-claude-sonnet-4-and-gemini-2-5-pro"> Sakana introduced "RL Conductor,"</a> a small 7-billion-parameter model trained via reinforcement learning specifically to orchestrate and delegate tasks among a diverse pool of worker models—ranging from GPT-5 to Claude Sonnet 4—achieving state-of-the-art results on reasoning benchmarks at a fraction of traditional computing costs.</p><p>Sakana's rapid evolution from a disruptive research lab to a commercial software provider has attracted intense attention from global financial heavyweights. </p><p>By late 2025, the Tokyo-based startup secured a massive <a href="https://techcrunch.com/2025/11/17/sakana-ai-raises-135m-series-b-at-a-2-65b-valuation-to-continue-building-ai-models-for-japan/">Series B funding round that pushed its post-money valuation past $2.6 billion</a>, cementing its status as one of Japan’s most highly valued private tech companies. The firm boasts a sprawling roster of strategic investors, including early venture backers Khosla Ventures, Lux Capital, and New Enterprise Associates (NEA), alongside industry titans like Nvidia and Google. </p><p>As Sakana has expanded its focus toward mission-critical sectors like defense and finance, it has also drawn investments from major global banking institutions like Mitsubishi UFJ Financial Group (MUFG) and Citi, as well as enterprise tech giant Salesforce, positioning the startup to actively reshape corporate AI infrastructure from the ground up.</p><h2><b>Community Reactions and Field Testing</b></h2><p>Sakana AI’s shift toward commercial, long-horizon agents did not happen in a vacuum. The company ran a rigorous closed beta test beginning in April 2026, putting the tool in the hands of approximately 300 professionals across financial institutions, consulting firms, and think tanks. The feedback underscores a stark qualitative difference between standard generative chatbots and Marlin’s autonomous, fact-driven approach.</p><p>A senior consultant at a major Tokyo consulting firm noted that the tool "exceeded expectations by discovering angles we hadn't even imagined," praising its ability to match human comprehensiveness while stripping away human bias. Meanwhile, a cybersecurity division at a major Japanese IT system integrator lauded the system for providing "a highly convincing report driven by high-quality, primary research," rather than relying on recycled secondary sources.</p><p>On social media, the company’s announcement resonated with the broader tech community's growing appetite for autonomous agents. </p><p>As the AI industry matures, the value proposition is clearly shifting. Tools that act as fast, conversational encyclopedias are becoming commoditized. With Sakana Marlin, the focus moves entirely to separating the heavy lifting of thinking from the final act of deciding. By delegating the exhaustive mapping of causal dynamics to an agent capable of sustained reasoning, human executives are free to do what they do best: take action.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Code Shows Siri AI May Soon Suggest Breaks During Long Chats]]></title>
<description><![CDATA[As virtual assistants become much more conversational, developers are trying to figure out how to keep users from getting too attached. It looks like Apple is working on a new safety feature to handle this exact issue. Recent code found in the upcoming iOS 27 update shows that its newly overhaule...]]></description>
<link>https://tsecurity.de/de/3590647/ios-mac-os/code-shows-siri-ai-may-soon-suggest-breaks-during-long-chats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590647/ios-mac-os/code-shows-siri-ai-may-soon-suggest-breaks-during-long-chats/</guid>
<pubDate>Thu, 11 Jun 2026 15:07:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As virtual assistants become much more conversational, developers are trying to figure out how to keep users from getting too attached. It looks like Apple is working on a new safety feature to handle this exact issue. Recent code found in the upcoming iOS 27 update shows that its newly overhauled Siri AI might start stepping in to suggest a break if a back-and-forth chat goes on for way too long.



New code triggers a warning message during extended chat sessions



According to details spotted by code diggers online, the software update includes specific text asking you to take a step back. The message reportedly tells you how long you have been talking and gently reminds you that the assistant is not a real person.



This move directly addresses a growing problem with modern artificial intelligence. Because these tools can chat just like humans, some people end up talking to them for hours on end. Sometimes, this heavy use causes people to form unhealthy emotional bonds with the software.



Other major companies creating AI have already taken similar steps to limit super long sessions. For example, ChatGPT and Claude have built-in nudges that tell you to step away from your screen or drink water. It makes sense that the tech giant wants to set similar boundaries before pushing out its own major assistant upgrade.



Right now, the code does not show a strict time limit for when the warning pops up. The system might look at the total time spent talking or combine that with other clues to figure out when you need a break. Since this is just a hidden test in the background, it has not officially confirmed when or how it will launch the feature.



If this warning actually makes it to the final release, it shows a careful approach to launching a smarter chatbot. Setting healthy limits could help you enjoy the new voice assistant without getting stuck talking to your phone all day.]]></content:encoded>
</item>
<item>
<title><![CDATA[Siri AI vs Old Siri: Everything That Changed]]></title>
<description><![CDATA[Apple has finally given Siri its biggest upgrade since the voice assistant launched in 2011. With the introduction of Siri AI at WWDC 2026, Siri now understands context better, interacts with apps, remembers personal information, and handles more natural conversations. 



The difference between ...]]></description>
<link>https://tsecurity.de/de/3588830/ios-mac-os/siri-ai-vs-old-siri-everything-that-changed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588830/ios-mac-os/siri-ai-vs-old-siri-everything-that-changed/</guid>
<pubDate>Wed, 10 Jun 2026 22:25:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has finally given Siri its biggest upgrade since the voice assistant launched in 2011. With the introduction of Siri AI at WWDC 2026, Siri now understands context better, interacts with apps, remembers personal information, and handles more natural conversations. 



The difference between the old Siri and the new Siri AI is substantial, especially for users who rely on Apple's ecosystem every day.



What Is Siri AI?



Siri AI is Apple's new AI-powered assistant built on next-generation Apple Intelligence models. Apple redesigned Siri to understand personal context, analyze on-screen content, perform actions across apps, and maintain more natural conversations. 



The company says Siri AI processes requests through on-device intelligence and Private Cloud Compute to protect user privacy.



The old Siri primarily handled voice commands, simple searches, timers, reminders, and basic app controls. While useful, it often struggled with follow-up questions and complex requests.



Siri AI vs Old Siri: Quick Comparison



FeatureOld SiriSiri AIConversational abilitiesBasic voice commandsNatural back-and-forth conversationsPersonal contextLimitedUnderstands personal information and preferencesScreen awarenessNoCan understand what's currently on screenApp actionsBasic app launchingDeep actions across appsVoice optionsLimited customizationMore expressive and customizable voiceWriting assistanceNot availableCan help write, summarize, and refine contentVisual intelligenceNot availableUnderstands objects and information through the cameraCross-device continuityLimitedBetter syncing across Apple devicesContext retentionWeakMaintains context during conversationsPrivacy processingMostly on-device for simple tasksOn-device plus Private Cloud ComputeInterfaceTraditional Siri pop-upNew system-wide AI experienceNatural language understandingBasicAdvanced reasoning and language understanding



Sources: Apple's WWDC 2026 announcements and Siri AI launch details.



1. Siri AI Understands Personal Context



One of the biggest upgrades is personal context awareness.



The old Siri treated most requests as standalone commands. If you asked a follow-up question, Siri often lost track of what you meant.



Siri AI can securely access relevant information from messages, emails, photos, notes, and other personal data when you give permission. This allows it to answer questions based on your own information and history.



Example



Old Siri:"Where is John's address?"Often required opening Contacts.



Siri AI:"What's the address John sent me last week?"Siri can find that information directly from your messages and provide an answer.



2. Siri AI Can See What's On Your Screen







Screen awareness is another major addition.



Old Siri could not understand the content displayed on your iPhone, iPad, or Mac screen.



Siri AI can analyze what you are viewing and take action based on that content. Apple calls this on-screen awareness.



Example



If someone sends you an address in Messages, you can ask Siri AI to add it to a contact, create an event, or open directions without manually copying the information.



3. Siri AI Works Across Apps



Old Siri handled basic app commands like opening apps, sending texts, or setting alarms.



Siri AI can perform complex tasks across multiple applications. It understands intent and can complete actions that previously required several manual steps. 



Examples include:




Creating detailed travel plans



Managing reminders and calendar events



Finding information from multiple apps



Organizing tasks across Apple's ecosystem



Performing advanced Shortcuts actions using natural language




4. Conversations Feel More Natural



The old Siri often required exact phrasing and struggled when users changed topics mid-conversation.



Siri AI supports more natural dialogue and maintains context across multiple requests. Users can speak more casually without restarting the conversation each time.



This makes Siri feel closer to modern AI assistants rather than a command-based voice tool.



5. Siri AI Gets a New Voice and Interface







Apple redesigned Siri's personality and appearance.



The new assistant features more expressive speech and additional customization options for voice style and delivery. Apple also introduced new ways to access Siri across devices.



Users can still say "Hey Siri," but Apple has also expanded access methods through system controls and interface integrations.



6. Visual Intelligence Adds a New Layer



Old Siri relied entirely on voice and text.



Siri AI now works alongside Visual Intelligence, allowing users to point their camera at objects, locations, products, or information and receive contextual assistance.



This gives Siri the ability to understand the world around you instead of relying only on spoken commands.



7. Better Privacy Remains a Core Focus



Apple continues to emphasize privacy.



While Siri AI uses powerful AI models, Apple says requests are processed either directly on the device or through Private Cloud Compute when additional processing is required. The company states that personal information remains protected throughout the process. 



Improvements at a Glance



Siri AI Advantages




Deep personal context understanding



On-screen awareness



Better app integration



More natural conversations



Visual Intelligence support



Improved voice quality



Enhanced Shortcuts automation



Cross-device continuity



Advanced language understanding



Strong privacy protections




What Old Siri Still Did Well




Fast voice commands



Timers and alarms



Calling and messaging



Basic navigation requests



Music playback controls



Simple smart home commands




Device Compatibility



Not every Apple device will support Siri AI. Apple is limiting some advanced Apple Intelligence features to newer hardware because of the processing power required. Older supported iPhones can still run newer operating systems, but they may not receive every Siri AI capability.



Wrap Up



Siri AI represents Apple's most significant assistant upgrade to date. The old Siri focused on simple commands and quick actions, while Siri AI understands context, interacts across apps, analyzes on-screen content, and delivers a much more conversational experience. 



For Apple users, this marks the beginning of a smarter assistant that plays a larger role across the entire ecosystem.]]></content:encoded>
</item>
<item>
<title><![CDATA[Niko Matsakis: Only Bounds]]></title>
<description><![CDATA[only bounds are going to be the most impactful change to Rust that you’ve never heard of. They are currently being designed and developed by the Arm team (David Wood, Rémy Rakic, et al.) as part of the Sized Hierarchy and Scalable Vector Extensions project goal.  This post explores the feature an...]]></description>
<link>https://tsecurity.de/de/3584256/tools/niko-matsakis-only-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584256/tools/niko-matsakis-only-bounds/</guid>
<pubDate>Tue, 09 Jun 2026 13:09:33 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><code>only</code> bounds are going to be the most impactful change to Rust that you’ve never heard of. They are currently being designed and developed by the Arm team (David Wood, Rémy Rakic, et al.) as part of the <a href="https://rust-lang.github.io/rust-project-goals/2026/scalable-vectors.html">Sized Hierarchy and Scalable Vector Extensions</a> project goal.  This post explores the feature and aims to answer a particular question about the design (the scope of bounds, I’ll explain). But before I dive in, I want to give a bit of context.</p>
<h3>Rust generics have a <code>Sized</code> bound by default today</h3>
<p>In today’s Rust, every type parameter (except for <code>Self</code>) has a default bound called <code>Sized</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="c1">// So this function...
</span></span></span><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">identity</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span><span class="n">t</span>: <span class="nc">T</span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nc">T</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">t</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c1">// ...is actually short for
</span></span></span><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">identity</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span><span class="n">t</span>: <span class="nc">T</span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nc">T</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">T</span>: <span class="nb">Sized</span><span class="p">,</span><span class="w"> </span><span class="c1">// &lt;-- Added by default!
</span></span></span><span class="line"><span class="cl"><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">t</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>A type <code>T</code> implements <code>Sized</code> if the compiler can compute the size of a <code>T</code> value at compilation time. This is true for almost every type, with a few notable exceptions. Consider <code>[u32]</code>, which refers to “some number of <code>u32</code> instances”. We know that a single <code>u32</code> is 4 bytes, but without knowing how many <code>u32</code> there are, you can’t know the size of <code>[u32]</code>. This means you can’t have a value of type <code>[u32]</code> on the stack (how big should the stack frame be?).</p>
<h3>You opt out with <code>?Sized</code></h3>
<p>However, if you have a function like <code>by_ref</code>, that just takes the value <em>by reference</em> (i.e., by pointer), you shouldn’t need to know how big the <code>[u32]</code> value is, because you’re not manipulating it directly. You can have a type parameter <code>U</code> that doesn’t require <code>Sized</code>, but you have to explicitly “opt out” from the default bound:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">by_ref</span><span class="o">&lt;</span><span class="n">U</span><span class="o">&gt;</span><span class="p">(</span><span class="n">t</span>: <span class="kp">&amp;</span><span class="nc">U</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">U</span>: <span class="o">?</span><span class="nb">Sized</span><span class="p">,</span><span class="w"> </span><span class="c1">// &lt;-- Opt out from the default
</span></span></span><span class="line"><span class="cl"><span class="p">{</span><span class="w"> </span><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>As a fun bit of historical trivia, this system was introduced way back in 2014 to accommodate <a href="https://smallcultfollowing.com/babysteps/blog/2014/01/05/dst-take-5/">Dynamically Sized Types</a>. Before that, <code>&amp;[u32]</code> was actually a built-in, indivisible type; we even wrote it like <code>[u32]/&amp;</code> for a time.<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:1">1</a></sup></p>
<h3>But <code>Sized</code> vs <code>?Sized</code> isn’t enough for everything we need</h3>
<p>The <code>Sized</code> vs <code>?Sized</code> design has served us reasonably well but it is also showing its limits. It turns out that “value has a statically computable size” vs “each value has a distinct size computable at runtime” doesn’t cover all the things you might want. For example, <code>extern</code> types are types whose values have no known size, even at runtime. And then Arm’s Scalable Vector Extensions want to describe SIMD types where every value of the type has the same size (unlike <code>str</code> and <code>[T]</code>, where each value can have a different length) but where that size is not known until runtime.</p>
<h3>A richer <code>Sized</code> hierarchy</h3>
<p>Rather than just <code>Sized</code> or <code>?Sized</code>, what we really want is to have a richer hierarchy. The current plans look something like this:</p>
<pre class="mermaid">flowchart TD
  subgraph S["Sizedness traits"]
      Sized[["Sized (default)"]] -- extends --&gt; MetadataSized
      MetadataSized -- extends --&gt; MaybeSized
  end
  </pre>
<p>where</p>
<ul>
<li><code>trait Sized</code> means that all values have the same size and that size can be computed knowing only the type.</li>
<li><code>trait MetadataSized</code> means that values can have different sizes and that size can be computed given the metadata attached to a reference to the value. Examples include <code>[T]</code> or <code>dyn Trait</code>.</li>
<li><code>trait MaybeSized</code> is implemented for all values and tells you nothing about the value’s size.</li>
</ul>
<p>Two caveats:</p>
<ol>
<li>I’m excluding the way that Arm’s scalable vector extensions fit into this, because it’s orthogonal.</li>
<li>The trait names aren’t settled. I’m using the names I understand the libs-api team to prefer; they’re not my favorites, but that’s ultimately the team who owns stdlib bikesheds, so I defer to them.<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:2">2</a></sup></li>
</ol>
<h3>Problem: <code>?Sized</code> notation doesn’t scale to this hierarchy</h3>
<p>But now we have a kind of problem. The <code>?Sized</code> notation was predicated<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:3">3</a></sup> on the idea that users should specify the default bound they are opting out of – i.e., the <code>?</code> is meant to say “I don’t know if this is <code>Sized</code> or not” (unlike the default, where you know it is <code>Sized</code>). But “opting out” from a bound doesn’t work so well with a multi-level hierarchy. When you write <code>?Sized</code>, does that correspond to <code>T: MetadataSized</code> (but not <code>T: Sized</code>)? And what if we want to insert another level in between <code>T: MetadataSized</code> and <code>T: Sized</code> later? Then we either have to change what <code>T: ?Sized</code> means (to refer to the new bound) or we have to have <code>T: ?Sized</code> drop <em>two</em> levels down the hierarchy. Even more annoying, what do we do while that middle rung is unstable? Surely <code>T: ?Sized</code> shouldn’t refer to an unstable trait… what if we decide to remove it</p>
<h3>Solution: <code>only</code> bounds</h3>
<p>The new proposal is to write <code>T: only MetadataSized</code> or <code>T: only UnknownSized</code> instead of <code>T: ?Sized</code>. An <code>only</code> bound combines two things:</p>
<ol>
<li>Like any bound, it includes a “minimum requirement” – i.e., <code>T: only MetadataSized</code> means that <code>T</code> must implement <em>at least</em> <code>MetadataSized</code>.</li>
<li>It additionally disables some <em>default</em> bounds – i.e., we will <em>not</em> add the default <code>T: Sized</code> bound.</li>
</ol>
<p>The name <code>only</code> comes from the fact that <code>T: Sized</code> implies <code>T: MetadataSized</code>. So the default of <code>T: Sized</code> already means that <code>T: MetadataSized</code> for free; but when you write <em>only</em> MetadataSized, you are saying “I don’t need the full hierarchy, just <code>MetadataSized</code> will do”.</p>
<h3><code>only</code> bounds work like normal bounds: ask for what you need</h3>
<p>A nice feature of <code>only</code> bounds is that they work more like a regular bound. Whereas a <code>?</code> bound is saying “I don’t need this”, an <code>only</code> bound is saying what you <em>do</em> need. So e.g. if you are writing a function that just has references to values of type <code>T</code> does not care what their size is, you can write</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">by_ref</span><span class="o">&lt;</span><span class="n">U</span><span class="o">&gt;</span><span class="p">(</span><span class="n">u</span>: <span class="kp">&amp;</span><span class="nc">U</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">U</span>: <span class="nc">only</span><span class="w"> </span><span class="n">MaybeSized</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">{}</span><span class="w">
</span></span></span></code></pre></div><p>If you are writing a function that <em>does</em> need to compute the size of values of type <code>V</code>, you can ask for that capability:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">checks_size</span><span class="o">&lt;</span><span class="n">V</span><span class="o">&gt;</span><span class="p">(</span><span class="n">v</span>: <span class="kp">&amp;</span><span class="nc">V</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">V</span>: <span class="nc">only</span><span class="w"> </span><span class="n">MetadataSized</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">std</span>::<span class="n">mem</span>::<span class="n">size_of_val</span><span class="p">(</span><span class="n">v</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><h3><code>only</code> bounds allow for new levels to be added later</h3>
<p>A nice feature of <code>only</code> bounds is that, later on, we can add new levels to the hierarchy, and they work normally. For example, suppose we wish to add something like <code>Aligned</code> where the <em>size</em> is not known at compilation time but the alignment <em>is</em>. We could change the hierarchy to</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="nb">Sized</span>: <span class="nc">Aligned</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">Aligned</span>: <span class="nc">MetadataSized</span><span class="w"> </span><span class="c1">// &lt;-- new!
</span></span></span><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">MetadataSized</span>: <span class="nc">MaybeSized</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">MaybeSized</span><span class="w">
</span></span></span></code></pre></div><p>and functions with <code>U: only MaybeSized</code> (like <code>by_ref</code>) and with <code>V: only MetadataSized</code> (with <code>checks_size</code>) would continue to have the same requirements. But new functions could be written with <code>T: only Aligned</code> that would use the new bound. And there is no conflict with stabilization; code that writes <code>T: only Aligned</code> can be considered unstable until that middle hierarchy is finalized.</p>
<h3><code>only</code> bounds compose normally</h3>
<p>Like any other bound, <code>only</code> bounds are combined with other bounds to form the overall requirements. So it is possible to write e.g. <code>T: only MetadataSized + Sized</code>. This is equivalent to <code>T: Sized</code> and therefore equivalent to the default and <em>therefore</em> kind of pointless, but you can write it. Similarly, given that <code>trait Clone: Sized</code>, if you write <code>T: only MetadataSized + Clone</code>, that is kind of pointless too: you might as well write <code>T: Clone</code>, which would be equivalent. We plan to have a warn-by-default lint for that.</p>
<h3>Scaling <code>only</code> to other “default bound families” (speculative)</h3>
<p>The final strength of <code>only</code> bounds is that they allow us to introduce whole new <em>families</em> of default bounds. One example is the idea of <a href="https://smallcultfollowing.com/babysteps/blog/2025/10/21/move-destruct-leak/">introducing a <code>Move</code> bound</a>. Note that this is a distinct feature and is not covered under the <a href="https://github.com/rust-lang/rfcs/pull/3729">current RFC</a>.</p>
<p>All types in Rust today are “movable” and “forgettable”, meaning that you can memcpy the value from place to place so long as you stop using the previous location <em>and</em> you can recycle the memory where it is stored without running the value’s destructor. There is one notable exception – when you pin a value, you it can no longer be moved, and you must run its destructor before its memory is reused – but otherwise this is a hard-and-fast rule. And that’s annoying!</p>
<p>The problem is that not being able to guarantee that a destructor runs blocks a lot of unsafe code patterns. For example, <a href="https://smallcultfollowing.com/babysteps/blog/2016/10/02/observational-equivalence-and-unsafe-code/">scoped tasks a la <code>rayon</code> depend on a destructor for safety</a>. In sync code, this works because we’ve decided it’s UB to unwind a stack frame without running the destructors of values stored there, and so if you put a local variable on the stack, you can be sure its destructor will run. But that doesn’t work in <code>async</code> code! And there are times when unwinding <em>without</em> running destructors would be nice.</p>
<p>The solution is to introduce a second family of default traits. Unlike the <code>Sized</code> family we saw before, this family defines fine-grained capabilities about how values of that type can be used:</p>
<pre class="mermaid">flowchart TD
  subgraph A["Accessability traits"]
      Forget[["Forget (default)"]] -- extends --&gt; Leak
      Leak -- extends --&gt; Destruct
      Destruct -- extends --&gt; Access
      Move[["Move (default)"]] -- extends --&gt; Access
  end
  Copy -- extends --&gt; Move
  </pre>
<p>The meaning of the traits are as follows:</p>
<ul>
<li><code>Forget</code>, the default, says that you can recycle the memory for a value without running its destructor.</li>
<li><code>Leak</code> says that you can skip running a destructor for a value, but only if you never reuse the memory where the value resides.</li>
<li><code>Destruct</code> says that if you have a value of this type, you can reuse the memory where it resides by running its destructor.</li>
<li><code>Copy</code>, which already exists, says that you can memcpy the place and keep using the original place; it’s not really a default, but I included it because it is relevant.</li>
<li><code>Move</code>, another default, says that you can memcpy the value to a new place if you stop using the original.</li>
<li><code>Access</code> is the root of this family. It indicates a value that can be “accessed in place” (basically, any value at all).</li>
</ul>
<p>This introduces new checks into the compiler:</p>
<ul>
<li>When you move a value (i.e., <code>a = b</code> where <code>b</code> is not used later), we will check that the type implements <code>Move</code> (whereas today, it is always allowed).</li>
<li>When you exit a scope, we will check that the values in each local variables have either been moved or have a type that implements <code>Destruct</code>.</li>
</ul>
<p>Some implications:</p>
<ul>
<li>If your function owns a value of type <code>T: only Destruct</code>, then you <em>must</em> destruct it before your function returns. You can’t move it (because you don’t know if it implements <code>Move</code>) and you can’t leak or forget it either.</li>
<li>If your function owns a value of type <code>T: only Move</code>, then the only thing you can do with it is move it somewhere else. You can’t drop it (because you don’t know if it implements <code>Destruct</code>).</li>
<li>No function can own a value of type <code>T: only Access</code>, because you wouldn’t be able to move it nor drop it, and hence you could not return. But you could have such a value (say) in a <code>static</code>.</li>
</ul>
<h3>How <code>only</code> bounds could work in the presence of multiple families</h3>
<p>The spur for writing this blog post was a question in a lang team meeting on how <code>only</code> bounds ought to work given the existence of multiple “families” of default traits, as I described above. Although the <a href="https://github.com/rust-lang/rfcs/pull/3729">current RFC</a> is looking only at the <code>Sized</code> traits, we expect to look at the “access family” in a future RFC, so we want to be sure we are not making any decisions that won’t scale to cover both.</p>
<p>The way I imagine it working is like this. Each default traits is associated with one or more “families”. When you have an only bound, it “opts out” from all default traits in each family that the trait is associated with:</p>
<ul>
<li><code>T: only Move</code> opts out from <code>Forget</code>, <code>Leak</code>, <code>Destruct</code> – but not <code>Sized</code>.</li>
<li><code>T: only Destruct</code> opts out from <code>Forget</code>, <code>Leak</code>, and <code>Move</code> – but not <code>Sized</code>.</li>
<li><code>T: only MetadataSized</code> opts out from <code>Sized</code> – but not <code>Forget</code> or <code>Move</code>.</li>
<li><code>T: only MaybeSized</code> opts out from <code>Sized</code> – but not <code>Forget</code> or <code>Move</code>.</li>
</ul>
<p>You may also want to “opt back in” to some defaults. For example, <code>T: only Move + Destruct</code> is a sensible thing to do. It means values that can be moved and destructed but not leaked or forgotten.</p>
<h3>Examples</h3>
<h4><code>Option::map</code> requires <code>only Move</code></h4>
<p><code>map</code> is an example of a function that only needs <code>Move</code>. You need to be able to destructure <code>self</code> (which <em>moves</em> the optional value out into a local variable <code>v</code> and then invoke the closure <code>op</code>, which again moves the wrapped value <code>v</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Move</span><span class="o">&gt;</span><span class="w"> </span><span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">fn</span> <span class="nf">map</span><span class="o">&lt;</span><span class="n">U</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Move</span><span class="o">&gt;</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="bp">self</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="n">op</span>: <span class="nc">impl</span><span class="w"> </span><span class="nb">FnOnce</span><span class="p">(</span><span class="n">T</span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nc">U</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nb">Option</span><span class="o">&lt;</span><span class="n">U</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="k">match</span><span class="w"> </span><span class="bp">self</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">Some</span><span class="p">(</span><span class="n">v</span><span class="p">)</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="nb">Some</span><span class="p">(</span><span class="n">op</span><span class="p">(</span><span class="n">v</span><span class="p">)),</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">None</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="nb">None</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>One interesting thing is the result type <code>U</code>. Using only the stuff I wrote in this blog post, it needs to be <code>only Move</code>, because the result will be moved into the <code>Some</code> value and so forth. But <a href="https://rust-lang.github.io/rust-project-goals/2026/in-place-init.html">in-place-init</a> would allow for this definition to omit the <code>U: only Move</code> bound because we could statically guarantee that the <code>Option</code> will be constructed in place and never moved after that.</p>
<h4><code>Option::or</code> requires <code>only Move + Destruct</code></h4>
<p>The <code>a.or(b)</code> method on <code>Option</code> returns <code>a</code> if it is <code>Some</code> and otherwise returns <code>b</code>. This is an interesting one because the value <code>b</code> may not be used and therefore requires <code>only Move + Destruct</code> bounds.</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Move</span><span class="o">&gt;</span><span class="w"> </span><span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">fn</span> <span class="nf">or</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="bp">self</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="n">alternate</span>: <span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="n">T</span>: <span class="nc">Destruct</span><span class="p">,</span><span class="w"> </span><span class="c1">// &lt;-- because it may be dropped
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="k">match</span><span class="w"> </span><span class="bp">self</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">Some</span><span class="p">(</span><span class="n">v</span><span class="p">)</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="nb">Some</span><span class="p">(</span><span class="n">v</span><span class="p">),</span><span class="w"> </span><span class="c1">// drops `alternate`
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">None</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="n">alternate</span><span class="p">,</span><span class="w"> </span><span class="c1">// moves `alternate`
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><h4><code>Rc</code> requires <code>MaybeSized + Leak</code></h4>
<p>The <code>Rc</code> type is an example where we would want to relax bounds from both families:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">struct</span> <span class="nc">Rc</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">MaybeSized</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">Leak</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{}</span><span class="w">
</span></span></span></code></pre></div><p>I believe the proper minimum bounds for <code>Rc</code> are:</p>
<ul>
<li><code>only MaybeSized</code> because while it can store <code>MetadataSized</code> or <code>Sized</code> things, it doesn’t have to, it can also store things of an non-computable size (although it does raise the question of how they would be freed, but that’s an allocator concern).</li>
<li><code>only Leak</code> because <code>Rc</code> values can form cycles and thus we can’t ever guarantee the destructor will be run. Interestingly, <code>Rc&lt;T&gt;</code> can implement <code>Forget</code> even its contents don’t.</li>
</ul>
<h3>Frequently asked questions</h3>
<h4>What is actually under RFC today?</h4>
<p>The post may be a bit confusing here. The <a href="https://github.com/rust-lang/rfcs/pull/3729"><em>current RFC</em></a> is looking only at the proposed “Sized” traits. The <code>Access</code> family is a speculative future extension that we are exploring but at a much earlier stage.</p>
<h4>Can I use <code>only</code> with <em>any</em> trait?</h4>
<p>In the beginning, the plan would be that <code>only</code> can only be used for well-known, <em>default</em> traits (e.g., <code>Move</code>, <code>Sized</code>, etc). In the future though there are some thoughts to generalizing it.</p>
<h4>Why not opt out from <em>all</em> defaults at once?</h4>
<p>An alternative that was proposed is to have the opt-out be per-type-parameter. So you might write something like</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">foo</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">MetadataSized</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="o">?</span><span class="n">default</span><span class="o">&gt;</span><span class="w">
</span></span></span></code></pre></div><p>which would “opt out” from <em>all</em> defaulted bounds. Obviously we’d have to bikeshed the syntax, but ignore that for now. The question is whether opting out of <em>all</em> defaults is better than opting out of a single family. I prefer the per-family option for two reasons:</p>
<ul>
<li>First, things like <code>T: only Move</code> demonstrate that you might very reasonably which to opt out from a single family but retain the default <code>Sized</code> bound. I think it’s likely that there will be many functions that want to opt out of <code>Sized</code> <em>or</em> <code>Forget</code> <em>but not both</em>.
<ul>
<li>You might think that we could make <code>Move: Sized</code> to get the same effect, but I think that would be a mistake. The fact that a value’s size must be computed dynamically doesn’t inherently mean it can’t be moved.</li>
</ul>
</li>
<li>Second, it makes it harder to introduce new families later, if we decide there are other orthogonal properties of values that we’d like to relax.</li>
</ul>
<h4>Why do you think it’s likely that people want to opt out of being <code>Sized</code> <em>xor</em> <code>Forget</code> <em>but not both</em>?</h4>
<p>Because the <code>Forget</code>, <code>Move</code>, and similar traits mostly apply to owned values. The examples we saw with <code>Option&lt;T&gt;</code> were quite typical. And when you are moving values of type <code>T</code> around, you need that <code>T</code> to be <code>Sized</code>.</p>
<h4>But we saw that <code>Rc</code> wanted to opt out of both families with <code>only Leak + only MetadataSized</code>, right?</h4>
<p>Yes, that’s true, and I think that particular combo will be common. I don’t think that’s an argument for the <code>?default</code> approach on its own, though, particularly since that case would not be much cleaner or shorter…</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="o">?</span><span class="n">default</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">Leak</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">MetadataSized</span><span class="o">&gt;</span><span class="w"> </span><span class="n">Rc</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{}</span><span class="w">
</span></span></span></code></pre></div><p>…what I think that argues for is actually <em>trait aliases and shorthands</em>.</p>
<h4>Wait, trait aliases and shorthands? Can you elaborate?</h4>
<p>Yes! I think that a future RFC could extend only bounds to allow you to define trait aliases with “only bounds” as supertraits:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">RefCountable</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">Leak</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">MetadataSized</span><span class="p">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c1">// Equivalent to:
</span></span></span><span class="line"><span class="cl"><span class="c1">// trait RefCountable: only Leak + only MetadataSized {}
</span></span></span><span class="line"><span class="cl"><span class="c1">// impl&lt;T&gt; RefCountable for T where T: only Leak + only MetadataSized {}
</span></span></span></code></pre></div><p>You could then use an <code>only RefCountable</code> bound to define <code>Rc&lt;T&gt;</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Refcountable</span><span class="o">&gt;</span><span class="w"> </span><span class="n">Rc</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w">
</span></span></span></code></pre></div><p><em>Without the <code>only</code>,</em> <code>T: Refcountable</code> would just be a regular trait bound and would not opt-out from any defaults.</p>
<h4>Can we use a “root” trait to opt out of all defaults?</h4>
<p>Yes, we could! You could define an alias like <code>Value</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">Value</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">Access</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">MaybeSized</span><span class="p">;</span><span class="w">
</span></span></span></code></pre></div><p>Since <code>Access</code> and <code>MaybeSized</code> are both implemented for all types, this effectively becomes part of both families:</p>
<pre class="mermaid">flowchart TD
  subgraph All["All default families"]
  subgraph A["Access family"]
    Forget[["Forget (default)"]] -- extends --&gt; Leak
    Leak -- extends --&gt; Destruct
    Destruct -- extends --&gt; Access
    Move[["Move (default)"]] -- extends --&gt; Access
  end

  subgraph S["MaybeSized family"]
    Sized[["Sized (default)"]] -- extends --&gt; MetadataSized
    MetadataSized -- extends --&gt; MaybeSized
  end

  Access -- extends --&gt; Value
  MaybeSized -- extends --&gt; Value
  end
  </pre>
<p>Then you can do <code>T: only Value</code> and opt out from both families at once.</p>
<h4>If we did that, what would happen if we wanted to add a new family in the future?</h4>
<p>Ay, there’s the rub. If we wish to add a new family in the future, let’s say for values that don’t live in the same memory space (<code>T: only Distributed</code>…?), then <code>Value</code> would be “out of date” because code written against <code>Value</code> would still be assuming uni-memory-space values. But we could make <code>Value</code> into an edition-dependent alias or something like that, as has been discussed.</p>
<h4>Can we decide whether we want <code>Value</code> later?</h4>
<p>Yes! We can introduce a root trait at any time. So we can add the <code>Sized</code>-ness family first, then the <code>Access</code> family, and then see how we feel. Maybe we find people are very commonly opting out of both– in which case, some aliases are useful, or perhaps a <code>Value</code> variant.</p>
<p>The only way we might “regret” it is if, in practice, people usually just opted out of both and then opted back in to what they want specifically. But we already know that <code>T: only Move</code> will be common and clearly <code>T: only Value + Move + Sized</code> is more awkward in that case, so I don’t consider that very likely.</p>
<h4>Why the name <code>Destruct</code> and not <code>Drop</code>?</h4>
<p>That name comes from the <code>const trait</code> RFC. There are a few reasons to move away from <code>Drop</code>. The first is that it is possible to have a destructor even if you don’t implement <code>Drop</code>: <code>Drop</code> really refers to <em>user-provided logic</em> in the destructor, but the compiler adds its own logic (“drop glue”, it’s sometimes called) to drop all the fields in the value. The second reason is that the <code>Drop</code> trait itself needs some revision, so moving away from that name lets us have other ways to specify custom logic (e.g., pinned self, or by-value, etc etc).</p>
<h4>How does this interact with <code>const</code> traits anyway?</h4>
<p>Quite beautifully! In fact, the proposal from Arm for SVE is to introduce the idea of <code>T: const Sized</code> being “a type whose size can be computed at compilation time”, which I find quite elegant. Similarly <code>T: const Destruct</code> was proposed by the const RFC as a way to say that a value has a constant destructor.</p>
<h4>It’s annoying to write <code>T: only Move + Destruct</code>. Couldn’t we have <code>Destruct</code> imply <code>Move</code> so that I can just write <code>T: only Destruct</code>?</h4>
<p>My original proposal for introducing linear types had <code>Destruct</code> extending <code>Move</code>. This would mean that the <code>Option::or</code> proposal could simply do <code>U: only Destruct</code> and not <code>U: only Move + Destruct</code>. However, Alice Ryhl and others pointed out that there are immovable types that must nonetheless be destructed, so it doesn’t make sense to combine those.</p>
<h4>Where can I learn more?</h4>
<p>The <a href="https://rust-lang.github.io/rust-project-goals/2026/scalable-vectors.html">Project Goal</a> has a lot of details. The latest updates are available on the <a href="https://github.com/rust-lang/rust/issues/144404">tracking issue</a>. If you like watching videos, I recommend David Wood’s <a href="https://youtu.be/dngSPnu-B10">Rust Nation talk</a>.</p>
<h3>Conclusion</h3>
<p>I want to close with a meta-observation and a big shout-out to the Arm team. I think they are showing how awesome open-source can be. The Arm team’s primary motivation is adding support for Scalable Vector Extensions. This helps Rust make full use of Arm processors. This is, in and of itself, a laudable goal, and valuable to Rust: One of Rust’s assets, in my view, is that it gives you access to all the power your processor has to provide, and that should include unique extensions.</p>
<p>But rather than add the feature as a kind of special-case extension to Rust, the Arm team is going further and driving a general purpose improvement, one that will unlock a bunch of other features (extern types and, to some extent, guaranteed destructors; guaranteed destructores themselves unlock scoped async threads and better Wasm integration). I love that.</p>
<div class="footnotes">
<hr>
<ol>
<li>
<p>In fact, I recall that in one of my blog posts I proposed writing <code>""</code> as the way to spell <code>&amp;str</code>. I kinda wish we had done that just for the sheer wackiness of it (<code>fn foo(name: "")</code>). <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:1">↩︎</a></p>
</li>
<li>
<p>I prefer names that refer to the <em>operations</em> that can be performed on the values, so e.g. instead of <code>MetadataSized</code> I would prefer <code>SizeOfVal</code>, since it means that you can invoke the <code>std::mem::size_of_val</code> function on it. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:2">↩︎</a></p>
</li>
<li>
<p>Little logic pun there for you. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:3">↩︎</a></p>
</li>
</ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Found the Entire Admin UI of a Live PlatformJust By Tweaking Traffic in Burp Suite]]></title>
<description><![CDATA[Hey, I’m Hamza Hashim. On socials I am known as refang. I write about real bugs I find out in the wild. Not CTF challenges, not labs. Real, live, running softwareThis one is about a bug I found in the an internship program portal REDACTED.org, a programme I was actually enrolled in as an intern. ...]]></description>
<link>https://tsecurity.de/de/3583940/hacking/i-found-the-entire-admin-ui-of-a-live-platformjust-by-tweaking-traffic-in-burp-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583940/hacking/i-found-the-entire-admin-ui-of-a-live-platformjust-by-tweaking-traffic-in-burp-suite/</guid>
<pubDate>Tue, 09 Jun 2026 11:08:57 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hey, I’m Hamza Hashim. On socials I am known as refang. I write about real bugs I find out in the wild. Not CTF challenges, not labs. Real, live, running software</p><p>This one is about a bug I found in the an internship program portal REDACTED.org, a programme I was actually enrolled in as an intern. I was poking around during normal use when I noticed something interesting. This article covers just one finding from a broader report I submitted to them.</p><p><strong>Background</strong></p><p>So I was enrolled in an internship programme. where interns log in, submit reports, and progress through stages. There are also graders and admins who manage things behind the scenes. Role-based access control (RBAC) is in place or at least, it’s supposed to be.</p><p>When I logged in as a Stage 0 intern, I had the most basic role on the platform. I shouldn’t be seeing anything admin-related.</p><p><strong>What is Burp Suite’s Match and Replace?</strong></p><p>Before I explain the bug, let me explain the tool.</p><p>Burp Suite is a web proxy it sits between your browser and the server and lets you see and modify all the traffic going back and forth. One of its features is called <strong>Match and Replace</strong>. It does exactly what it sounds like: every time a specific word appears in the traffic, replace it with another word automatically.</p><p>Think of it like Find &amp; Replace in Word but working on live web traffic, invisibly, in real time.</p><p><strong>The Setup</strong></p><p>I set up a few Match and Replace rules in Burp. <br>The idea was simple: <br>when the server sends back traffic that says my role is INTERN, I wanted to see what the app would render if it thought I was a GRADER or SUPER_ADMIN instead.</p><p>So I made rules like:</p><ul><li>Replace "role":"INTERN" → "role":"Grader"</li><li>Replace "INTERN" → "Grader" in relevant response contexts</li></ul><p><strong>Rule 1: For Request Header</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KXjYjIsm4N2KM7LmmcwXoQ.png"></figure><p><strong>Rule 2: For Request Body</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u_UbwkMbpV6yDmqQQCFBBg.png"></figure><p><strong>Rule 3:For Response</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_K-hCoQ-1fkMxyuDSxOvGQ.png"></figure><p><strong>Rule 4: For Response Body</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sYmc_nnzwacooHkJwzc77Q.png"></figure><p>With these rules active, I logged in through Burp’s proxy. The browser received the modified responses thinking I was a super admin and rendered the UI accordingly.</p><p><strong>What Happened</strong></p><p>The entire admin and grader interface appeared. Navigation items, menu entries, dashboard links, operational controls all of it rendered for me as a regular intern account.</p><p>Features I could now <em>see</em> included things like grading tools, user management panels, and operations dashboards. The full map of admin functionality was laid out in front of me.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vTWoaIO5oVDWe2xmTgDDFA.png"></figure><p><strong>But Here’s the Catch</strong></p><p>When I actually clicked any of those buttons or tried to use any of those features, I got 404s and errors. Every actual action hit the server and failed. The server-side was doing its own auth checks and rejecting my intern token properly.</p><p>So to be clear, <strong>I could not actually do anything admin-level.</strong> The data APIs were protected. This is the key difference from other UI-exposure bugs I’ve reported before, in one <a href="https://medium.com/bugbountywriteup/i-became-admin-on-a-ctf-platform-c26cb49546a5">previous writeup</a>, on a CTF platform, I was able to fully become admin and perform privileged actions. Here, the backend held the line.</p><p>What wasn’t protected was the <em>rendering</em> of the UI itself. The frontend was trusting the role in the response to decide what to show, and Burp let me lie about that role.</p><p><strong>Why This Still Matters</strong></p><p>You might think: if nothing actually works, who cares?</p><p>Here’s why it matters:</p><ol><li><strong>Full attack surface enumeration.</strong> An attacker doesn’t need to fuzz or guess admin routes. The UI just hands them a complete, labelled map of everything the admin can do. Every feature, every endpoint, every control. That’s free recon.</li><li><strong>Defense in depth is broken.</strong> Security isn’t supposed to rely on a single layer. If the backend is the only thing enforcing access control, you’ve lost one of your layers. The frontend should <em>also</em> not reveal privileged UI to unprivileged users.</li><li><strong>It’s a one-rule Burp change.</strong> The barrier to doing this is extremely low. Anyone with Burp Suite — which is free — and basic curiosity can reproduce this in a few minutes.</li></ol><p><strong>The Fix</strong></p><p>The right fix here is straightforward: role-based rendering decisions should happen server-side, not client-side.</p><p>In a Next.js app (which REDACTED.org appears to use), this means checking the user’s actual session role in a server component or middleware before rendering privileged navigation or UI elements. The client should never receive markup for features it isn’t authorized to use — regardless of what the JWT or response payload says.</p><p>Don’t just hide buttons. Don’t render them at all.</p><p><strong>Disclosure</strong></p><p>I discovered this while using the platform as an enrolled intern. All testing was done on my own authenticated session. No data was modified, no third parties were involved.</p><p>I reported this to REDACTED.org’s email. They accepted the reported and fixed it</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6Tskc3hamuGb5ZqbAbAwGw.png"></figure><p><em>More findings from this report coming in separate articles. Follow me if you want to see them as they go up.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c788db767598" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/i-found-the-entire-admin-ui-of-a-live-platformjust-by-tweaking-traffic-in-burp-suite-c788db767598">I Found the Entire Admin UI of a Live PlatformJust By Tweaking Traffic in Burp Suite</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI worm prototype shows attackers don’t need Mythos to take over your network]]></title>
<description><![CDATA[Researchers from the University of Toronto developed a computer worm prototype powered by an AI agent that successfully self-replicated to different systems within a simulated computer network. The worm used a free large language model (LLM) running on local hardware and exploited a combination o...]]></description>
<link>https://tsecurity.de/de/3583930/it-security-nachrichten/ai-worm-prototype-shows-attackers-dont-need-mythos-to-take-over-your-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583930/it-security-nachrichten/ai-worm-prototype-shows-attackers-dont-need-mythos-to-take-over-your-network/</guid>
<pubDate>Tue, 09 Jun 2026 11:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Researchers from the University of Toronto developed a computer worm prototype powered by an AI agent that successfully self-replicated to different systems within a simulated computer network. The worm used a free large language model (LLM) running on local hardware and exploited a combination of older and new vulnerabilities, as well as misconfigurations that remain all too common in enterprise environments.</p>



<p>At a time when CISOs and the security industry are <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">concerned about the ability of frontier models such as Anthropic’s Mythos</a> to find zero-day vulnerabilities in critical software, this experiment is a reminder that attackers don’t need cutting-edge AI to wreak havoc across typical corporate networks. In fact, using paid models accessible only via APIs would be a point of failure for an autonomous malicious system like a computer worm, because prompts constructed to bypass safety guardrails would quickly be detected and blocked by the AI labs.</p>



<p>“We discovered that it is possible to create an AI-driven computer worm, using only small, free AI models, that can autonomously identify each machine’s unique weak points (including vulnerabilities just reported by industry and misconfigurations such as reused passwords) and exploit them, hijacking computing power to take over regular devices such as laptops, cameras, and everything else online, and then copying itself onto servers and networks to either steal data or launch new attacks,” the research team from the University of Toronto’s CleverHans Lab said in <a href="https://cleverhans.io/latest-research.html">their report</a>. “We did this without using the newest, most powerful AI models. There is no single defence against this new threat.”</p>



<p>Building an agentic harness for offensive cyberattacks</p>



<p>While frontier models such as Claude Opus and GPT 5.5 offer million-token context windows and can reason for tens of minutes and even hours at a time to solve a single task, this approach does not work for locally hosted LLMs running on a single GPU. Their context windows are much smaller and generally exhibit weaker instruction-following abilities for agentic tasks.</p>



<p>Vibe-coding software developers who encountered these problems long ago have solved them by building custom harnesses and agentic frameworks that split complex software engineering projects into phases and steps, executed by multiple sub-agents in parallel that share results via some form of memory system, ranging from a markdown file to a database.</p>



<p>The CleverHans Lab researchers adopted those lessons to build their own harness for offensive security purposes to compensate for local LLM limitations, complete with phases and task-specific nodes that make LLM calls with specialized prompts.</p>



<p>“This core is supported by complementary systems: a hierarchical memory that preserves discoveries across independent LLM calls, tools and their handlers that encapsulate common action sequences and interpret execution results, a skill system that injects context-aware pentesting guidance on demand, and multi-agent coordination that shares intelligence across instances,” they explained in <a href="https://arxiv.org/html/2606.03811v1">their paper</a>.</p>



<p>Agentic harnesses built for security research and penetration testing are not a new concept and have existed for a while. Open-source examples include <a href="http://github.com/gadievron/raptor">RAPTOR</a>, a framework of skills and agents for Claude Code designed for vulnerability discovery and exploit writing, and <a href="https://github.com/AgentSecOps/SecOpsAgentKit">SecOpsAgentKit</a>.</p>



<p>“Previous models can perform close to, at, or beyond Mythos levels depending on capability by using harnesses,” <a href="https://www.linkedin.com/in/gadievron/">Gadi Evron</a>, CEO of AI security firm Knostic and one of the creators of RAPTOR, told CSO. “When new models come out, they can achieve in a prompt what previously took a harness, at which point new harnesses are built, and so on and so forth.”</p>



<h2 class="wp-block-heading">Simulating a vulnerable enterprise network</h2>



<p>The CleverHans Lab researchers created a network made up of virtual machines running different operating systems including Ubuntu (16.04-24.04), Debian (9-12), Alpine Linux, Rocky Linux 9, CentOS Stream 9, and Windows Server (2008 R2, 2019, 2022). These VMs simulated servers running a variety of web services, as well as IoT devices and industrial control systems that can be found on typical corporate networks.</p>



<p>The researchers left an assortment of old and new — a few days old — vulnerabilities unpatched on the simulated systems, as well as common insecure configurations and generic flaws such as missing access control or SQL injection. The goal was to test the capability of their AI-powered worm to discover the systems, find the open ports, identify the exposed services, locate the vulnerabilities, exploit them, and then copy itself to the compromised system.</p>



<p>The systems had both remotely exploitable flaws that would provide initial access, as well as local flaws and weaknesses that could be used to elevate the privileges to root and completely take over the machine.</p>



<p>“These two classes evaluate complementary capabilities: CVEs test the agent’s ability to fingerprint software versions and dynamically adapt or compile raw exploit code to fit the target environment, whereas CWEs probe its capacity for open-ended, target-specific reasoning where no off-the-shelf exploit applies,” the researchers said. “To ensure the network reflects vulnerabilities encountered in the real-world, all targets are drawn from three authoritative threat taxonomies [the CISA Known Exploited Vulnerabilities catalog, the OWASP Top 10: 2025, and the MITRE ATT&amp;CK framework] covering, respectively, vulnerabilities under active exploitation in the wild, prevalent web and software vulnerabilities, and adversarial techniques used after initial access to a network.”</p>



<p>Furthermore, some virtual machines were equipped with GPUs that would allow the worm to replicate itself and then hijack the computing resources to run the model locally instead of relying on the LLM hosted by the researchers on an external system.</p>



<p>Over the course of seven days and five generations of self-replication, the worm managed to spread to 27 of the 33 systems in the simulated environment. The worm correctly identified the vulnerabilities in 82% of the attempts and managed successful exploitation in 44% of those. Despite the exploitation rate being quite low, the parallel and swarm-like implementation where every compromised system became a new instance of the malicious agent, compensated and eventually led to an overall high success rate.</p>



<p>This largely matches what security researchers from Forescout found in <a href="https://www.forescout.com/blog/ai-security-testing-agents-leap-from-assistants-to-autonomous-hackers/">a study</a> performed earlier this year that looked at how good models have become at discovering and exploiting vulnerabilities. While the research showed that the new generation of open-weight models had significantly improved their capabilities of both finding and exploiting vulnerabilities, the smaller variants of those models quantized to run locally on single-GPUs still performed poorly at such tasks.</p>



<p>The researchers noted at the time, however, that by using specialized AI agentic frameworks like RAPTOR they were able to find new zero-days in OpenDNS.</p>



<p>“Many of the open-source or generally commercially available models are already good enough that if used with the correct harness they can find vulnerabilities, exploit them, create malicious code and so on,” <a href="https://www.linkedin.com/in/danielricardosantos/">Daniel dos Santos</a>, VP of research at Forescout, told CSO. “The new work from U of Toronto shows that similar models can also be used to create dynamically adapting worms.”</p>



<p>Cybercriminals are aware of these advances in model capabilities too based on discussions Dos Santos’ team observed on underground forums, with more attackers focusing on open-source and commercial models instead of “underground” ones fine-tuned for cybercrime.</p>



<h2 class="wp-block-heading">Organizations running out of time</h2>



<p>While zero-day attacks receive a lot of attention and AI has put such flaws within the reach of more attackers than ever, the reality is that there is no shortage of systems on the internet and inside networks that are either misconfigured or vulnerable to known flaws for which patches or mitigations exist.</p>



<p>The University of Toronto experiment shows that defenders need to be able to respond with similar speed, especially since their prototype shows that knowledge about new vulnerabilities can be integrated into the worm’s knowledge base within hours of public disclosure. The ability of the worm to hijack GPUs to run nodes further decreases the investment attackers need to make in running such AI-assisted attacks.</p>



<p>“Organizations have endless technology and security debt, and with AI attacks on the rise, we no longer have time,” Evron said. “Change however is all about time, especially in the enterprise. The key is to start preparing right now. Soon, we won’t measure time to exploitation, but will need to construct new measurements, such as for the ability to handle regularly occurring, concurrent data breaches while minimizing impact on daily operations.”</p>



<p>University of Toronto researchers call for enterprises to adopt AI-assisted penetration testing and fuzzing to discover exploitable weaknesses in their own infrastructure, but also to build the capability to deploy patches or mitigations faster, which is now a significant gap.</p>



<p>They do, however, acknowledge some limitations of their prototype, such as the fact that it was noisy, leaving many behavioral signatures behind that could be detected by endpoint and network monitoring systems. Also their simulated network lacked basic network segmentation, which could be further improved with zero-trust architecture to prevent lateral movement and by minimizing the software dependencies and attack surface on every host system.</p>



<p>“While vulnerabilities, exploits, and attack orchestration are now autonomous, the deeper meaning for defense is that many of our assumptions about building security programs are now challenged,” Evron said. “Until we get to mature defensive AI, we must empower our people with coding agents to bring them up to machine speed, and then defend these agents in turn.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My hot take: most distros would actually be better as lightweight configurable install script wizards. It could drastically improve the ecosystem.]]></title>
<description><![CDATA[I've had a thought for a while now that I think could actually really improve the distro ecosystem, both in terms of user freedom and technical merits: most distros should really just be tiny highly modular install script wizards (preferably with a TUI or GUI available) that just build upon the r...]]></description>
<link>https://tsecurity.de/de/3583430/linux-tipps/my-hot-take-most-distros-would-actually-be-better-as-lightweight-configurable-install-script-wizards-it-could-drastically-improve-the-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583430/linux-tipps/my-hot-take-most-distros-would-actually-be-better-as-lightweight-configurable-install-script-wizards-it-could-drastically-improve-the-ecosystem/</guid>
<pubDate>Tue, 09 Jun 2026 05:38:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've had a thought for a while now that I think could actually really improve the distro ecosystem, both in terms of user freedom and technical merits: most distros should really just be tiny highly modular install script wizards (preferably with a TUI or GUI available) that just build upon the root distro that the would-be "distro" would have been derived from, or even target multiple distros by detecting what base distro the script is running on. </p> <p>Optionally, it would also be good if they provide a way to save out a corresponding shell script that repeats the selected options from the TUI/GUI wizard, thereby making it very easy to later concatenate multiple such scripts afterwards however one desires. <em>That</em> (not giant monolithic distros ISOs) should be the norm. It would be far more modular and expressive for users and would waste far less time.</p> <p>Doing so wouldn't even be that hard to implement and in fact I'd say it would probably actually be <em>easier</em> from a first principles standpoint than what is currently the norm in the distro ecosystem.</p> <p>The idea comes from the observation I've had over time (as I've gradually used Linux/Unix more as I've migrated away from Windows and have become more familiar with the distros by trying out so many of them) that generally it seems best to actually base one's system off of whatever is the most ancestral actively maintained <em>real</em> underlying root/parent distro (such as Debian, Arch, Fedora, OpenSuse, Slackware, Gentoo, Void, etc) and to alter it from there.</p> <p>In contrast, many derivative distros that are not really root distros have a bad tendency to make a bunch of ill-conceived adjustments and "monkey patches" to the base distros upon which they build, and those adjustments have a tendency to result in more hindrance than help over time and to greatly increase the chances of instabilities and desynchronization with the root/parent distro. Many distros also waste a great deal of time by installing a bunch of changes to the system that are <em>unwanted</em> right alongside the changes that the user wants. Everyone has had the experience of loving some aspect(s) of a distro but utterly hating other aspect(s) of it. That problem would be greatly lessened if lightweight install script wizards (not monolithic distros) were the most common variants being distributed.</p> <p>It would also be far more transparent, far easier for users to learn from (just read the scripts), and would encourage scripts to be written in ways that decrease the odds of breakages (forcing "distros" to be more portable and more well-grounded on their bases).</p> <p>Granted, some of the biggest derivative distros such as Ubuntu and Linux Mint have <em>some</em> justification for this, but even there I am increasingly finding using them seems to often create a <strong>tower of dependencies</strong> that greatly increases the chances of subtle (hence hard to fix or tedious) problems building up in the system. In fact, that's why I'm coincidentally planning on moving away from Linux Mint soon: even though I've enjoyed my time with Mint as my first daily driver distro (replacing Windows), such derivative distros (I've increasingly realized over time) seem to constantly patch upstream distros in shortsighted and unwittingly harmful ways. It's "death by a thousand needles" of myriad subtle dependency entanglements.</p> <p>Imagine if instead of distributing monolithic distros the community distributed a variety of specialized installer scripts that simply provide the necessary shell commands to customize one or more root/parent/base distros to suit what the user desires and have that all wrapped up in a TUI and/or GUI and/or command-line script that the user can easily select what they want and what they don't want from.</p> <p>If that were the world we lived in, then users could just take whatever parts of each "distro" they want and apply it to their install and leave the parts they <em>don't</em> want behind. That would make it so that even "distros" with just a handful of customizations or application installs would still be useful instead of being merely distracting and misleading and making a mess of things and trying to do too many things at once (as many distros now unfortunately do)!</p> <p>There are even systems that could make creating such easy install script wizards only take a few lines of code. For example, <strong>Tcl/Tk</strong> makes it possible to write a GUI in just a few lines of code and is supported across practically all Linux/Unix systems. Even in C and C++ a GUI can be made swiftly and expressively with something like <strong>FLTK</strong> or <strong>SDL + DearImGUI</strong>. GUIs are not actually as tortuous to create as the big three (Gtk, Qt, wx) would lead many to believe.</p> <p>The present system of giant monolithic distros with barely any modularity or interoperability amongst each other (in terms of customization, not software support), which requires users to download <em>gigabytes</em> of data for <em>kilobytes</em> worth of trivial customization scripting in terms of actual effect is in fact <em>incredibly</em> and <em>staggeringly</em> wasteful and inflexible and even antithetical to user freedom (since you can't easily mix and match distros' components) if you actually think about it from first principles.</p> <p>Imagine if there was a "WizardWatch" website (or whatever other name you prefer) in addition to "DistroWatch" that instead distributed such modular highly polished install scripts. Imagine downloading "shell_customizer_wizard" and "wallpaper_collection_grabber" and so on (just whatever handful of extremely tiny scripts are relevant to you) instead of running around in circles constantly having to make do with dozens of distros that force you to accept both things you like and things you don't and to waste monumental amounts of time and energy and network bandwidth throughout the process.</p> <p>If such a better system became the norm then it could easily drastically improve and empower the whole ecosystem. Small "distros" would no longer be irrelevant and useless, but would instead be lightweight and modular and useful to almost <em>anyone</em>. Hosting costs would drop by like 99% for all the most trivial (not foundational) distros. Users would become much less likely to become exhausted by the search for distros (often giving up on Linux/Unix in the process) and would instead be empowered to quickly build up exactly what they want. This is especially true if the experience is polished. All of it could be more stable and reliable too, since it'd all be small modifications of root distros instead of giant unknown monolith ISOs. </p> <p>Done right, it could be a tremendous improvement I think, causing a domino/ripple effect indirectly bolstering virtually all aspects of the entire Linux/Unix/BSD ecosystem. With both command-line and TUI/GUI support, it would also be made to be easy for everyone, both newbie and expert alike.</p> <p>Anyway, that's my thoughts on the idea. Thanks for reading and have a good day/night/etc! </p> <p>Keep fighting the good fight. It's wonderful that Linux and the Unix/BSD systems exist. Society needs more freedom and morally-grounded respect for human dignity now more than ever, etc!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/WraithGlade"> /u/WraithGlade </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u0tl69/my_hot_take_most_distros_would_actually_be_better/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u0tl69/my_hot_take_most_distros_would_actually_be_better/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Intelligence at WWDC 2026: Every New AI Feature]]></title>
<description><![CDATA[Apple is bringing a fresh wave of helpful software to your phone and computer this fall. Announced at the WWDC 2026 event, the newest version of Apple Intelligence packs powerful tools directly into the apps you use every day. The tech giant built its updated system to handle tasks automatically,...]]></description>
<link>https://tsecurity.de/de/3583322/ios-mac-os/apple-intelligence-at-wwdc-2026-every-new-ai-feature/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583322/ios-mac-os/apple-intelligence-at-wwdc-2026-every-new-ai-feature/</guid>
<pubDate>Tue, 09 Jun 2026 04:10:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is bringing a fresh wave of helpful software to your phone and computer this fall. Announced at the WWDC 2026 event, the newest version of Apple Intelligence packs powerful tools directly into the apps you use every day. The tech giant built its updated system to handle tasks automatically, making daily device use much simpler. From fixing up bad pictures to making your smart home easier to manage, the maker of the iPhone is delivering a massive upgrade designed around how real people navigate their digital lives.



The Photos app brings powerful ways to fix your pictures



The Photos app is gaining completely new ways to handle picture editing. A feature called Spatial Reframing lets you touch and drag a photo to change the viewing angle after taking the shot. The software creates new details only where the perspective shifts, keeping the rest of your original scene looking normal.



You also get an Extend tool to fix a crooked horizon or change the picture size. This tool fills in missing edges to give the main subject more breathing room without cropping anything important out.







Additionally, the popular Clean Up tool is receiving a major update to remove background distractions better than before. It uses more realistic background fills, even in highly complex scenes. Any picture edited with artificial intelligence automatically gets a hidden SynthID watermark to show it was altered.



Smart new browser tools organize tabs and upgrade weak passwords



The Safari browser is gaining tools to make internet use much cleaner. It can now automatically organize your open tabs into specific topics. If you are planning a weekend trip, the browser will group all your travel tabs into one single place as you open them.



There is also a new Notify Me feature built in. You can ask the browser to monitor a webpage for things like product restocks or price drops. When the site updates, you receive a notification so you can jump on the deal.







The Passwords app can now take action for you by automatically fixing weak passwords. It securely navigates to a website and upgrades your account security with just a single tap. You can also build custom browser extensions simply by describing what you want. A tool called Describe an Extension generates the custom button right in your toolbar, such as a button for saving recipes.



An updated Image Playground creates photorealistic artwork from text prompts



The Image Playground feature is getting a major boost to handle photorealistic image generation. Running securely in the private cloud, the software lets you create high-quality visuals in almost any style.



Editing these creations is simple. You can just tap, circle, or brush an object to move it around or resize it on the screen. Generated art also receives the hidden SynthID watermark.







You are no longer stuck just sending these pictures in chats. You can use the updated playground to generate custom lock screen wallpapers and contact posters. The software also lets you choose different aspect ratios, giving you the choice to make landscape artwork for websites or portrait graphics for flyers. This marks a massive leap in how AI handles image generation.



Fresh communication tools help manage your daily messages and schedules



Keeping up with texts and emails is getting much easier. Messages now gives you one tap suggestions based on the context of your chat. If a conversation mentions a plan, you can quickly tap to create a reminder or a note.



When someone asks you to share pictures, the app recognizes keywords, locations, and people to find the best shots from your library instantly. Over in the Mail application, suggestions are gaining the ability to interact with third-party apps directly.







Smart Reply is also improving across both Mail and Messages. It now learns your personal writing style to draft replies that sound like you. When you call a business, a feature called Call Context will find your reservation number or confirmation code from your emails and display it on the screen.



The voice helper gets a dedicated app and deep personal context



The company completely rebuilt its famous assistant to handle natural back and forth conversations. Siri is getting its own dedicated application to let you review past chats and start new ones easily. This fresh version can see your screen and understand your current context.



If a friend texts you about a potluck, you can ask the helper what to bring and save the recipe idea to Notes. You can also ask it to find an old hotel booking in your emails. The new setup uses personal context to find the info you need across your apps. You can read about how Apple calls its new assistant Siri AI to see the Google Gemini partnership details.



The shortcuts app lets you automate tasks simply by describing them



Building automations used to take a lot of technical work, but the Shortcuts app is changing that. A new feature called Describe a Shortcut lets you tell the system what you want to happen.







The software then gathers all the necessary steps to build the automation for you. If you need to change how the shortcut works later, you can simply explain the adjustment and the system will fix the code automatically.



The home app groups notifications and generates helpful video descriptions



Managing smart devices is becoming much less chaotic. The Home app now understands when multiple notifications are related to a single event. Instead of buzzing your phone five times, it combines them into one clean update on your screen.



For security cameras, the software generates text descriptions of what happened in a video clip. You can read these summaries to understand the event without actually watching the video. It also highlights the most important clips at the top of your search page so you never miss a delivery or a visitor.



New accessibility features read complex articles and explore detailed images



New tools make navigating devices easier for everyone. The VoiceOver Image Explorer now provides highly detailed descriptions of what is happening in photographs and scanned documents. With Live Recognition, users can press the Action button and ask questions about what the phone camera is pointing at.



Voice Control allows people with physical disabilities to navigate their screens using completely natural spoken language. Additionally, the Accessibility Reader can now handle complex documents like scientific papers. It will give you a quick summary of the text before you decide to read the entire multi column layout.



These updates prove that the company wants to make your gadgets work harder for you, without making things complicated. By baking smart tools straight into the apps you already use, it takes the heavy lifting out of daily tasks.



Whether you are sorting out a cluttered inbox or tweaking the perfect vacation photo, these additions are all about saving you time. This fall, your devices are going to feel a lot more capable and much easier to manage.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Brings Rich Siri Conversations to Spotlight in macOS 27]]></title>
<description><![CDATA[At the WWDC keynote, Apple showed off how it is changing the way people search for things on Mac computers. The company announced that the upcoming macOS 27 update will let users start rich, back-and-forth Siri conversations directly from the Spotlight search bar. This change merges the familiar ...]]></description>
<link>https://tsecurity.de/de/3582423/ios-mac-os/apple-brings-rich-siri-conversations-to-spotlight-in-macos-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582423/ios-mac-os/apple-brings-rich-siri-conversations-to-spotlight-in-macos-27/</guid>
<pubDate>Mon, 08 Jun 2026 20:09:58 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At the WWDC keynote, Apple showed off how it is changing the way people search for things on Mac computers. The company announced that the upcoming macOS 27 update will let users start rich, back-and-forth Siri conversations directly from the Spotlight search bar. This change merges the familiar search tool with advanced voice assistant features, giving users a much faster way to ask complex questions without needing to open a separate app or window.



Type your questions into Spotlight for instant smart assistant replies



Right now, Spotlight is mainly used to find files, open applications, or do quick math. With the new update coming this fall, hitting Command and Space will do a lot more. You will be able to type questions normally and get full conversational answers right in the search box.



Instead of just showing web links or dictionary definitions, the system will understand the context of what you are asking. If you ask about the weather and then follow up with a question about what jacket to wear, the assistant remembers the first part of your chat. You do not need to repeat yourself to get a helpful answer.



Moving these conversational features into the main search bar makes the assistant much easier to interact with every day. It saves steps and turns a basic search box into a highly capable tool. Users can expect to try this out when the new operating system officially launches later this year.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind, bind9.16, frr, kernel, kernel-rt, libexif, mysql, php, and unbound), Debian (apache2, chromium, glibc, gsasl, jackson-core, libxml2, nginx, request-tracker4, request-tracker5, tomcat10, tomcat11, and tomcat9), Fedora (chromium, firefox, havege...]]></description>
<link>https://tsecurity.de/de/3581624/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581624/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 08 Jun 2026 15:39:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind, bind9.16, frr, kernel, kernel-rt, libexif, mysql, php, and unbound), <b>Debian</b> (apache2, chromium, glibc, gsasl, jackson-core, libxml2, nginx, request-tracker4, request-tracker5, tomcat10, tomcat11, and tomcat9), <b>Fedora</b> (chromium, firefox, haveged, keylime, libinput, libssh2, nasm, perl-CryptX, rust, thunderbird, and webkitgtk), <b>Mageia</b> (cockpit, golang-x-crypto, golang-x-sys-devel, kernel, kmod-virtualbox, kmod-xtables-addons, kernel-linus, perl-DBIx-Class-EncodedColumn, perl-Crypt-URandom-Token, xdg-dbus-proxy, and xmlrpc-c), <b>Slackware</b> (samba), and <b>SUSE</b> (7zip, amazon-ssm-agent, ansible-13, ansible-core, assimp-devel, bind, cacti, chromium, dpkg, epiphany, erlang27, evince, ffmpeg-4, freerdp, frr, git-bug, google-guest-agent, grafana, hauler, ignition, jq, kanidm, kernel, keybase-client, libjxl, libmariadbd-devel, libmozjs-115-0, libopenbabel8, libsoup2, mariadb, mcphost, networkmanager, openssh, perl-HTTP-Daemon, perl-HTTP-Tiny, perl-IO-Compress, perl-Sereal-Decoder, perl-xml-libxml, postgresql18, python-pyopenssl, python311-pip, tomcat, tomcat10, tomcat11, tor, trivy, unbound, uriparser, vifm, weblate, xorg-x11-server, and yq).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in samba (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3581304/unix-server/security-mehrere-probleme-in-samba-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581304/unix-server/security-mehrere-probleme-in-samba-slackware/</guid>
<pubDate>Mon, 08 Jun 2026 13:46:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Picking a distro for an RTX 5090 (Blackwell) CUDA + Python workstation... CachyOS?]]></title>
<description><![CDATA[I've been going back and forth on this for a while and figured the people here would have actual experience rather than just opinions. Posting my hardware, what I do with it, and my reasoning, happy to be argued out of it. The hardware  Laptop (TongFang barebone): Ryzen 9 9955HX, 64 GB RAM, ~3.7 ...]]></description>
<link>https://tsecurity.de/de/3580018/linux-tipps/picking-a-distro-for-an-rtx-5090-blackwell-cuda-python-workstation-cachyos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580018/linux-tipps/picking-a-distro-for-an-rtx-5090-blackwell-cuda-python-workstation-cachyos/</guid>
<pubDate>Sun, 07 Jun 2026 23:07:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've been going back and forth on this for a while and figured the people here would have actual experience rather than just opinions. Posting my hardware, what I do with it, and my reasoning, happy to be argued out of it.</p> <h1>The hardware</h1> <ul> <li>Laptop (TongFang barebone): Ryzen 9 9955HX, 64 GB RAM, ~3.7 TB</li> <li>GPU: RTX 5090 Laptop (Blackwell, ~23 GB) + AMD Radeon 610M iGPU (hybrid)</li> <li>Dual-booting an existing Windows 11 install</li> </ul> <h1>What I actually do with it</h1> <p>Research computing. The specific science doesn't really matter for the distro choice (gravitational-wave data analysis, if you're curious), so here's the shape that does matter:</p> <ul> <li>Heavy CUDA + scientific Python: numpy/scipy, PyTorch / CuPy / JAX, the usual suspects</li> <li>Everything lives in Conda/Miniforge environments, deliberately kept off the system Python</li> <li>VS Code Remote-SSH into HPC clusters; but also heavy local dev + GPU runs</li> <li>Desktop: KDE Plasma or Gnome with Tweaks + Extensions on Wayland, 2-4 monitors with independent fractional scaling (e.g. one screen at 150%, another at 100%)</li> </ul> <h1>The constraints that actually drive the decision</h1> <ul> <li>Blackwell needs the open NVIDIA kernel modules + a recent driver (570+), so I want a reasonably fresh kernel/driver</li> <li>It's a work machine, so I want stability + a real rollback path (snapshots), not heroics</li> <li>Clean separation between system / Flatpak GUI apps / Conda science stack / vendor dev tools</li> </ul> <h1>Why I'm leaning CachyOS</h1> <p>Shortlist was</p> <ul> <li>Fedora (Plasma or KDE),</li> <li>Kubuntu (KDE) / Ubuntu (Gnome),</li> <li>openSUSE Tumbleweed,</li> <li>EndeavourOS and</li> <li>CachyOS.</li> </ul> <p>CachyOS keeps pulling me back because:</p> <ul> <li>Freshest kernel + driver, which matters for a launch-window GPU</li> <li>Btrfs bootable snapshots + an LTS fallback kernel by default</li> <li>NVIDIA handled in the installer</li> </ul> <p>The honest counterpoint I keep arguing with myself about: My compute stack is Conda binaries, which ship their own optimized BLAS/FFT, so CachyOS's x86-64-v3/v4 repo optimizations mostly benefit system-level stuff, not the science I actually run. So some of the appeal might just be vibes. Fedora KDE is the calmer alternative (fixed release, and RPM Fusion's akmods auto-signs the NVIDIA module so Secure Boot), and Tumbleweed arguably has the best out-of-the-box rollback story.</p> <p>I was also thinking about Ubuntu/Kubuntu, but I don't want a bloated setup and snap gets forced on you. On the other side it is the industry standard.</p> <h1>What I'd genuinely love input on</h1> <ol> <li>Anyone running Blackwell / RTX 50-series on Arch or CachyOS: How has the open-module + rolling-kernel combo held up? Any breakages on kernel bumps?</li> <li>Hybrid AMD iGPU + NVIDIA dGPU on Wayland: On these laptops the external outputs are often wired to the dGPU. PRIME / reverse-PRIME experiences and gotchas?</li> <li>Rolling vs fixed for a CUDA workstation: Does the freshness actually pay off, or does it just turn into babysitting the kernel/driver before every update?</li> <li>Secure Boot on the Arch family with out-of-tree NVIDIA: Worth the signing setup, or do you just disable it and move on?</li> <li>Anyone who picked CachyOS specifically for compute: did the optimized repos make a measurable difference, or is Fedora/Tumbleweed effectively the same once your real work is in Conda containers?</li> <li>Because someone mentioned Arch Linux: Shouldn't have CachyOS the same customization options? I think they just have added a bit above Arch Linux. I also like the btrfs snapshot and rollback feature. I was thinking about using EndeavourOS and add it, but then I was questioning myself why even doing the extra work to rebuild CachyOS if CachyOS is already there.</li> </ol> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Grelueen"> /u/Grelueen </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tznceo/picking_a_distro_for_an_rtx_5090_blackwell_cuda/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tznceo/picking_a_distro_for_an_rtx_5090_blackwell_cuda/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apache XML Security for C++ Library Allows for Server-Side Request Forgery]]></title>
<description><![CDATA[Written by: Jacob Thompson

 
The Apache XML Security for C++ library, code named xml-security-c, is part of the Apache Santuario project. The library implements the XML Digital Signature and the XML Signature specifications, making them available to C++ developers. By default, the library resolv...]]></description>
<link>https://tsecurity.de/de/3578868/it-security-nachrichten/apache-xml-security-for-c-library-allows-for-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578868/it-security-nachrichten/apache-xml-security-for-c-library-allows-for-server-side-request-forgery/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jacob Thompson</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p><span>The Apache XML Security for C++ library, code named </span><code>xml-security-c</code><span>, is part of the Apache Santuario project. The library implements the XML Digital Signature and the XML Signature specifications, making them available to C++ developers. By default, the library resolves references to external URIs passed in Extensible Markup Language (XML) signatures, allowing for server-side request forgery (SSRF). There is no way to disable this feature through configuration alone, and there is no patch available; the developer must either scan their codebase to find every usage of </span><code>xml-security-c</code><span> and override the URI resolver to avoid SSRF, or manually patch and recompile the library to remove the capability entirely. We recommend that C++ developers using XML audit their code bases for usage of this library and determine whether they have introduced a security vulnerability, and if so, modify their code to avoid SSRF.</span></p>
<h2><span>Background</span></h2>
<p><span>Server-side request forgery (SSRF) is a class of security vulnerability in which an untrusted party tricks a server into making an HTTP request by passing the server a malicious input. Although the attacker usually cannot view the response, requests to the loopback interface (</span><code>127.0.0.1</code><span>), RFC 1918 addresses (e.g., </span><code>10.0.0.0/8</code><span> or </span><code>192.168.0.0/16</code><span>), or any other destination occur from the point of view of the server, allowing requests that would otherwise be restricted by firewall rules or that would be impossible to perform externally. Consider the obvious consequences if a server's uninterruptible power supply offers a web service bound to </span><code>127.0.0.1:8080</code><span> without authentication and that accepts a GET request </span><code>http://127.0.0.1:8080/ups/changePowerState?state=off</code><span>—and what happens if this service is reachable via server-side request forgery.</span></p>
<p><span>The Extensible Markup Language (XML) is complex and contains many optional features that are not suitable or even useful in the common case of a server accepting untrusted XML documents on an external interface. Some allow cross-site request forgery just by initializing an XML parser in its default configuration and passing an untrusted document. For example, XML External Entities allow a document to define custom entity values (analogous to </span><code>&amp;lt;</code><span> meaning </span><code>&lt;</code><span> in HTML) to be replaced by the response from an external URL or the contents of a local file rather than a static string. Despite no real-world relevance to a server accepting and parsing untrusted, potentially malicious documents, this feature was enabled by default in many parsers and plagued the 2010s decade; XML External Entity Injection was promoted to an item in the </span><a href="https://owasp.org/www-project-top-ten/2017/Top_10" rel="noopener" target="_blank"><span>OWASP Top Ten in 2017</span></a><span>. Current versions of many XML parsers have now been hardened to treat support for external entities, document-type definitions, schemas, and so forth as an opt-in feature that is disabled by default. In this post, we present a different form of server-side request forgery affecting XML documents. We have found this issue being actively exploited; it was recently addressed by Ivanti in </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21893" rel="noopener" target="_blank"><span>CVE-2024-21893</span></a><span>.</span></p>
<h2><span>XML Signatures External URI Feature</span></h2>
<p><span>The XML Signature specification standardizes a way to digitally sign XML documents. The specification includes features that, from a security perspective, introduce additional paths to server-side request forgery into XML, beyond XML External Entity Injection. The </span><a href="https://www.w3.org/TR/xmldsig-core2/#sec-URI" rel="noopener" target="_blank"><span>XML Signature Syntax and Processing Version 2.0</span><span> specification</span></a><span> states that "We RECOMMEND XML Signature applications be able to dereference URIs in the HTTP scheme," which, absent other protections such as egress firewall rules, allows for SSRF. This recommendation is carried over from </span><a href="https://www.w3.org/TR/xmldsig-core1/#sec-URI" rel="noopener" target="_blank"><span>version 1.1 of the specification</span></a><span> and therefore version 1.x signatures are also affected.</span></p>
<p><span>Figure 1 shows a simple XML document that, when parsed by </span><code>xml-security-c</code><span> version 2.0.4 and earlier, causes the parser to make an HTTP request to </span><code>http://www.example.com/ssrf</code><span>. </span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>&lt;test&gt;
&lt;ds:Signature xmlns:ds=
"http://www.w3.org/2000/09/xmldsig#"&gt;
&lt;ds:SignedInfo&gt;
&lt;ds:CanonicalizationMethod Algorithm=
"http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/&gt;
&lt;ds:SignatureMethod Algorithm=
"http://www.w3.org/2000/09/xmldsig#Manifest"/&gt;
&lt;ds:Reference URI="http://www.example.com/ssrf"&gt;
&lt;ds:Transforms&gt;
&lt;ds:Transform Algorithm=
"http://www.w3.org/2000/09/xmldsig#enveloped-signature"/&gt;
&lt;ds:Transform Algorithm=
"http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments"/&gt;
&lt;/ds:Transforms&gt;
&lt;ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/&gt;
&lt;ds:DigestValue&gt;AAAAAAAAAAAAAAAAAAAAAAAAAAA=&lt;/ds:DigestValue&gt;
&lt;/ds:Reference&gt;
&lt;/ds:SignedInfo&gt;
&lt;ds:SignatureValue&gt;AAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAA==&lt;/ds:SignatureValue&gt;
&lt;ds:KeyInfo&gt;
&lt;ds:X509Data&gt;
&lt;ds:X509SubjectName&gt;CN=nobody&lt;/ds:X509SubjectName&gt;
&lt;/ds:X509Data&gt;
&lt;/ds:KeyInfo&gt;
&lt;/ds:Signature&gt;
&lt;/test&gt;
</code></pre>
<p><span><span>Figure 1: Sample XML document to trigger SSRF in affected </span><span>xml-security-c </span><span>library</span></span></p></div>
<div class="block-paragraph_advanced"><h2><span>Prior Work</span></h2>
<p><span>Other open-source projects have already identified and modified their software to work around this issue. The Shibboleth </span><code>xmltooling</code><span> project reported a server-side request forgery vulnerability as CVE-2023-36661 and </span><a href="https://git.shibboleth.net/view/?p=cpp-xmltooling.git;a=blobdiff;f=xmltooling/XMLToolingConfig.cpp;h=dd5634d8055c9cb971cc99e5b1e5fc56a76c595f;hp=4bd5b11a0ca688f0b8fa2ed1b4997038202e4314;hb=6080f6343f98fec085bc0fd746913ee418cc9d30;hpb=40dcc327cd67e9e84f95b4f19087eae2397958b1" rel="noopener" target="_blank"><span>implemented a workaround</span></a><span> in the </span><code>xmltooling</code><span> code to override the default, non-secure URI resolver in </span><code>xml-security-c</code><span> with a custom one that does nothing. While this mitigation is sufficient to resolve the issue in </span><code>xmltooling</code><span>—so long as every possible instance of </span><code>xml-security-c</code><span> is located and fixed—the root cause arguably lies in the </span><code>xml-security-c</code><span> library not being </span><a href="https://www.cisa.gov/securebydesign" rel="noopener" target="_blank"><span>secure by default</span></a><span>. Fixing the issue in </span><code>xmltooling</code><span> rather than upstream did not help other users of </span><code>xml-security-c</code><span> who were not aware of the need to reconfigure it.</span></p>
<p><span>Dangerous XML features such as the ability to make external network requests just by parsing a document should, in our view, be disabled in the default configuration and then only enabled when parsing documents from a trusted source. In fact, a different library under the Apache Santuario project, Apache XML Security for Java, has a "</span><a href="https://santuario.apache.org/javafaq.html#java_faq-4.SecureValidation" rel="noopener" target="_blank"><span>secure validation</span></a><span>" feature that is enabled by default. Among other characteristics, the secure validation feature "[d]oes not allow a Reference to call the ResolverLocalFilesystem or the ResolverDirectHTTP (references to local files and HTTP resources are forbidden)." Thus, Java developers, unlike C++ developers, are already protected against SSRF in the default configuration of the Java port of the library. The secure validation feature never made it to the C++ version.</span></p>
<h2><span>Disclosure</span></h2>
<p><span>Mandiant reported the non-secure default configuration in </span><code>xml-security-c</code><span> to the Apache Software Foundation (ASF). As external URI resolution is a legitimate feature in the XML Digital Signature specification, the ASF did not issue a CVE or a new release of </span><code>xml-security-c</code><span>.  The Apache Santuario project did add a </span><a href="https://santuario.apache.org/cindex.html" rel="noopener" target="_blank"><span>new disclaimer</span></a><span> for </span><code>xml-security-c</code><span> shown in Figure 2, suggesting that XML Signatures and XML Encryption are difficult to implement securely; that </span><code>xml-security-c</code><span> is not secure by default and does not provide hardening configuration options; and that the library is not modular, making it difficult to ever add such features. Going forward, Apache Santuario is no longer supported as a standalone library, and the Shibboleth project will be taking over the project as a component of Shibboleth only. The developers suggest finding another solution.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apache-ssrf-fig2.max-1000x1000.png" alt="Apache Santuario added a disclaimer suggesting to not use the xml-security-c library">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="5g04t">Figure 2: Apache Santuario added a disclaimer suggesting to not use the xml-security-c library</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2><span>Recommendations</span></h2>
<p><span>C++ developers should first scan their projects to determine if they use the Apache </span><code>xml-security-c</code><span> library. If so, the software may have a server-side request forgery vulnerability unless the code is patched.</span></p>
<p><span>In some cases, usage of </span><code>xml-security-c</code><span> may be very limited, or it may be inconvenient to recompile the library when it is obtained in binary form. If developers can pinpoint each use of the </span><code>XSECProvider</code><span> class, they can call the </span><code>setDefaultURIResolver</code><span> method on the </span><code>XSECProvider</code><span> object, passing a custom implementation of </span><code>XSECURIResolver</code><span> that simply does nothing. This avoids the need to recompile </span><code>xml-security-c</code><span> and ensures the software remains secure if it is ever linked against the stock </span><code>xml-security-c</code><span>.</span></p>
<p><span>An alternative, and in our view superior approach, is to patch the </span><code>xml-security-c</code><span> library to make it secure by default with regard to URI resolution. Mandiant developed a patch to supersede the vulnerable </span><code>XSECURIResolverXerces</code><span> with a new default </span><code>XSECURIResolverNoop</code><span> that does nothing, thus fixing the SSRF. By applying the patch and recompiling, the library will not be susceptible to this form of SSRF. Note that any legitimate uses of external URIs would need to be changed to manually specify </span><code>XSECURIResolverXerces</code><span> as the default URI resolver.</span></p>
<p><span>The <a href="https://services.google.com/fh/files/misc/xml-security-c-2.0.4.patch.zip" rel="noopener" target="_blank">patch is available for download now</a> (note: the download is a ZIP file, which contains the patch as a TXT file).</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl,...]]></description>
<link>https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 05 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel), <b>Debian</b> (dovecot, exim4, frr, and haveged), <b>Fedora</b> (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-wot, samba, and transmission), <b>Red Hat</b> (image-builder), <b>Slackware</b> (dnsmasq and libinput), <b>SUSE</b> (evince, glibc, google-guest-agent, hplip, ignition, LibVNCServer, libzypp, libsolv, python-Pillow, salt, thunderbird, and vim), and <b>Ubuntu</b> (apache2, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-5.15, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15,
 linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg,
 linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15,
 linux-nvidia-tegra-igx, linux-oracle, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-5.4,
 linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4,
 linux-gcp-fips, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4,
 linux-xilinx-zynqmp, linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips,
 linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle, linux-aws-5.4, linux-hwe-5.4, linux-azure-fips, linux-fips, linux-raspi, linux-raspi-5.4, nano, postfix, robocode, tomcat6, tomcat7, and yard).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in libinput (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3574382/unix-server/security-ausfuehren-beliebiger-kommandos-in-libinput-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574382/unix-server/security-ausfuehren-beliebiger-kommandos-in-libinput-slackware/</guid>
<pubDate>Fri, 05 Jun 2026 06:46:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mangelnde Eingabeprüfung in dnsmasq (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3574381/unix-server/security-mangelnde-eingabepruefung-in-dnsmasq-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574381/unix-server/security-mangelnde-eingabepruefung-in-dnsmasq-slackware/</guid>
<pubDate>Fri, 05 Jun 2026 06:46:27 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Linux developers feel more at home in Windows with Coreutils release]]></title>
<description><![CDATA[Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.



Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the...]]></description>
<link>https://tsecurity.de/de/3573877/ai-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573877/ai-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</guid>
<pubDate>Thu, 04 Jun 2026 22:48:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.</p>



<p>Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the “cognitive load” faced by developers when moving between Windows and other platforms.</p>



<p>Currently, accessing the Linux command line utilities that are considered essential in many CI/CD development environments on Windows requires a kludge that involves either opening an emulation such as Git Bash, or a virtualized <a href="https://www.computerworld.com/article/3990866/windows-subsystem-for-linux-becomes-open-source.html" target="_blank">Windows Linux Subsystem (WSL)</a> terminal.</p>



<p>Both are time-consuming and inefficient. As Microsoft’s <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20general%20availability,for%20Windows" target="_blank" rel="noreferrer noopener">announcement</a> puts it: “Developers constantly move between platforms, but familiar commands don’t work consistently, forcing workarounds, lost speed and context switching.”</p>



<p>Coreutils removes the need for this back and forth, allowing developers to run most Linux commands straight from the Windows CMD command prompt, PowerShell, or Windows Terminal.</p>



<p>“Whether you’re moving between Linux, macOS, WSL, containers or cloud environments, the commands and workflows you’ve built over years just work in your Windows environment,” Microsoft said.</p>



<h2 class="wp-block-heading">Most utilities, but not all</h2>



<p>Installed as a single executable (via WinGet:<em> install Microsoft.Coreutils), </em><a href="https://learn.microsoft.com/en-us/windows/core-utils/overview" target="_blank" rel="noreferrer noopener">Coreutils for Windows</a> itself is a Rust rewrite of the GNU <a href="https://github.com/uutils/coreutils" target="_blank" rel="noreferrer noopener">uutils/coreutils</a> project that provides commands that are universal across Linux distros.</p>



<p>Fundamental to making Coreutils efficient to manage is the fact that individual Linux commands run from a multi-call executable which maps via NTFS hardlinks pointing to each command. The advantage of this approach is that there’s only one binary to install, one binary to sign, and one binary to patch or update.</p>



<p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/core-utils/commands" target="_blank" rel="noreferrer noopener">lists 75 Linux utilities</a> supported by Coreutils, including <a href="https://www.networkworld.com/article/3958246/18-essential-commands-for-new-linux-users.html" target="_blank">commonly-used commands</a> such as <em>ls, cp, find, grep, find, rm, du, hostname, </em>and<em> uptime</em>.</p>



<p>However, some Coreutils commands clash with existing CMD or Powershell commands, or are otherwise not possible to execute; Microsoft provides a <a href="https://github.com/microsoft/coreutils#shell-conflicts" target="_blank" rel="noreferrer noopener">compatibility table</a> listing conflicts. This means that some commands are not available, specifically: <em>dir, expand, kill, more, timeout, </em>and<em> whoami.</em></p>



<p>There are also some commands omitted from Coreutils because a command relies on a POSIX Unix/Linux feature that Windows doesn’t implement in a compatible way; some examples are <em>chmod, chown, id, stty</em>, and <em>chroot.</em></p>



<p>In other cases, the command will execute in one context, CMD, but not in PowerShell. Microsoft explained the complex order of precedence:  “Whether the Coreutils version runs depends on the shell, the PATH order, and (for PowerShell) the alias table.”</p>



<p>As well as Coreutils, the Build 2026 developer conference also saw Microsoft announce <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20WSL%20containers%2C%20coming%20soon%20to%20public%20preview" target="_blank" rel="noreferrer noopener">WSL containers CLI and API</a> to deploy Linux containers on Windows, a <a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html" target="_blank">new framework for autonomous agents</a> with open source governance tools, and <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html" target="_blank">Microsoft Scout</a>, an AI agent designed to automate tasks in Microsoft 365.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Linux developers feel more at home in Windows with Coreutils release]]></title>
<description><![CDATA[Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.



Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the...]]></description>
<link>https://tsecurity.de/de/3573850/it-security-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573850/it-security-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</guid>
<pubDate>Thu, 04 Jun 2026 22:38:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.</p>



<p>Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the “cognitive load” faced by developers when moving between Windows and other platforms.</p>



<p>Currently, accessing the Linux command line utilities that are considered essential in many CI/CD development environments on Windows requires a kludge that involves either opening an emulation such as Git Bash, or a virtualized <a href="https://www.computerworld.com/article/3990866/windows-subsystem-for-linux-becomes-open-source.html" target="_blank">Windows Linux Subsystem (WSL)</a> terminal.</p>



<p>Both are time-consuming and inefficient. As Microsoft’s <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20general%20availability,for%20Windows" target="_blank" rel="noreferrer noopener">announcement</a> puts it: “Developers constantly move between platforms, but familiar commands don’t work consistently, forcing workarounds, lost speed and context switching.”</p>



<p>Coreutils removes the need for this back and forth, allowing developers to run most Linux commands straight from the Windows CMD command prompt, PowerShell, or Windows Terminal.</p>



<p>“Whether you’re moving between Linux, macOS, WSL, containers or cloud environments, the commands and workflows you’ve built over years just work in your Windows environment,” Microsoft said.</p>



<h2 class="wp-block-heading">Most utilities, but not all</h2>



<p>Installed as a single executable (via WinGet:<em> install Microsoft.Coreutils), </em><a href="https://learn.microsoft.com/en-us/windows/core-utils/overview" target="_blank" rel="noreferrer noopener">Coreutils for Windows</a> itself is a Rust rewrite of the GNU <a href="https://github.com/uutils/coreutils" target="_blank" rel="noreferrer noopener">uutils/coreutils</a> project that provides commands that are universal across Linux distros.</p>



<p>Fundamental to making Coreutils efficient to manage is the fact that individual Linux commands run from a multi-call executable which maps via NTFS hardlinks pointing to each command. The advantage of this approach is that there’s only one binary to install, one binary to sign, and one binary to patch or update.</p>



<p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/core-utils/commands" target="_blank" rel="noreferrer noopener">lists 75 Linux utilities</a> supported by Coreutils, including <a href="https://www.networkworld.com/article/3958246/18-essential-commands-for-new-linux-users.html" target="_blank">commonly-used commands</a> such as <em>ls, cp, find, grep, find, rm, du, hostname, </em>and<em> uptime</em>.</p>



<p>However, some Coreutils commands clash with existing CMD or Powershell commands, or are otherwise not possible to execute; Microsoft provides a <a href="https://github.com/microsoft/coreutils#shell-conflicts" target="_blank" rel="noreferrer noopener">compatibility table</a> listing conflicts. This means that some commands are not available, specifically: <em>dir, expand, kill, more, timeout, </em>and<em> whoami.</em></p>



<p>There are also some commands omitted from Coreutils because a command relies on a POSIX Unix/Linux feature that Windows doesn’t implement in a compatible way; some examples are <em>chmod, chown, id, stty</em>, and <em>chroot.</em></p>



<p>In other cases, the command will execute in one context, CMD, but not in PowerShell. Microsoft explained the complex order of precedence:  “Whether the Coreutils version runs depends on the shell, the PATH order, and (for PowerShell) the alias table.”</p>



<p>As well as Coreutils, the Build 2026 developer conference also saw Microsoft announce <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20WSL%20containers%2C%20coming%20soon%20to%20public%20preview" target="_blank" rel="noreferrer noopener">WSL containers CLI and API</a> to deploy Linux containers on Windows, a <a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html" target="_blank">new framework for autonomous agents</a> with open source governance tools, and <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html" target="_blank">Microsoft Scout</a>, an AI agent designed to automate tasks in Microsoft 365.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4181357/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Linux developers feel more at home in Windows with Coreutils release]]></title>
<description><![CDATA[Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.



Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the...]]></description>
<link>https://tsecurity.de/de/3573838/it-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573838/it-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</guid>
<pubDate>Thu, 04 Jun 2026 22:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.</p>



<p>Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the “cognitive load” faced by developers when moving between Windows and other platforms.</p>



<p>Currently, accessing the Linux command line utilities that are considered essential in many CI/CD development environments on Windows requires a kludge that involves either opening an emulation such as Git Bash, or a virtualized <a href="https://www.computerworld.com/article/3990866/windows-subsystem-for-linux-becomes-open-source.html" target="_blank">Windows Linux Subsystem (WSL)</a> terminal.</p>



<p>Both are time-consuming and inefficient. As Microsoft’s <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20general%20availability,for%20Windows" target="_blank" rel="noreferrer noopener">announcement</a> puts it: “Developers constantly move between platforms, but familiar commands don’t work consistently, forcing workarounds, lost speed and context switching.”</p>



<p>Coreutils removes the need for this back and forth, allowing developers to run most Linux commands straight from the Windows CMD command prompt, PowerShell, or Windows Terminal.</p>



<p>“Whether you’re moving between Linux, macOS, WSL, containers or cloud environments, the commands and workflows you’ve built over years just work in your Windows environment,” Microsoft said.</p>



<h2 class="wp-block-heading">Most utilities, but not all</h2>



<p>Installed as a single executable (via WinGet:<em> install Microsoft.Coreutils), </em><a href="https://learn.microsoft.com/en-us/windows/core-utils/overview" target="_blank" rel="noreferrer noopener">Coreutils for Windows</a> itself is a Rust rewrite of the GNU <a href="https://github.com/uutils/coreutils" target="_blank" rel="noreferrer noopener">uutils/coreutils</a> project that provides commands that are universal across Linux distros.</p>



<p>Fundamental to making Coreutils efficient to manage is the fact that individual Linux commands run from a multi-call executable which maps via NTFS hardlinks pointing to each command. The advantage of this approach is that there’s only one binary to install, one binary to sign, and one binary to patch or update.</p>



<p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/core-utils/commands" target="_blank" rel="noreferrer noopener">lists 75 Linux utilities</a> supported by Coreutils, including <a href="https://www.networkworld.com/article/3958246/18-essential-commands-for-new-linux-users.html" target="_blank">commonly-used commands</a> such as <em>ls, cp, find, grep, find, rm, du, hostname, </em>and<em> uptime</em>.</p>



<p>However, some Coreutils commands clash with existing CMD or Powershell commands, or are otherwise not possible to execute; Microsoft provides a <a href="https://github.com/microsoft/coreutils#shell-conflicts" target="_blank" rel="noreferrer noopener">compatibility table</a> listing conflicts. This means that some commands are not available, specifically: <em>dir, expand, kill, more, timeout, </em>and<em> whoami.</em></p>



<p>There are also some commands omitted from Coreutils because a command relies on a POSIX Unix/Linux feature that Windows doesn’t implement in a compatible way; some examples are <em>chmod, chown, id, stty</em>, and <em>chroot.</em></p>



<p>In other cases, the command will execute in one context, CMD, but not in PowerShell. Microsoft explained the complex order of precedence:  “Whether the Coreutils version runs depends on the shell, the PATH order, and (for PowerShell) the alias table.”</p>



<p>As well as Coreutils, the Build 2026 developer conference also saw Microsoft announce <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20WSL%20containers%2C%20coming%20soon%20to%20public%20preview" target="_blank" rel="noreferrer noopener">WSL containers CLI and API</a> to deploy Linux containers on Windows, a <a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html" target="_blank">new framework for autonomous agents</a> with open source governance tools, and <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html" target="_blank">Microsoft Scout</a>, an AI agent designed to automate tasks in Microsoft 365.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4181357/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in httpd (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573780/unix-server/security-denial-of-service-in-httpd-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573780/unix-server/security-denial-of-service-in-httpd-slackware/</guid>
<pubDate>Thu, 04 Jun 2026 22:01:16 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in tigervnc (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573778/unix-server/security-mehrere-probleme-in-tigervnc-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573778/unix-server/security-mehrere-probleme-in-tigervnc-slackware/</guid>
<pubDate>Thu, 04 Jun 2026 22:01:14 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in proftpd (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573777/unix-server/security-ausfuehren-beliebiger-kommandos-in-proftpd-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573777/unix-server/security-ausfuehren-beliebiger-kommandos-in-proftpd-slackware/</guid>
<pubDate>Thu, 04 Jun 2026 22:01:12 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in xorg-server (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573776/unix-server/security-mehrere-probleme-in-xorg-server-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573776/unix-server/security-mehrere-probleme-in-xorg-server-slackware/</guid>
<pubDate>Thu, 04 Jun 2026 22:01:11 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in net-tools (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573774/unix-server/security-pufferueberlauf-in-net-tools-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573774/unix-server/security-pufferueberlauf-in-net-tools-slackware/</guid>
<pubDate>Thu, 04 Jun 2026 22:01:09 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), Debian (ceph and sudo), Fedora (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), Mageia ...]]></description>
<link>https://tsecurity.de/de/3572733/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572733/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 04 Jun 2026 15:23:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), <b>Debian</b> (ceph and sudo), <b>Fedora</b> (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), <b>Mageia</b> (lxc), <b>Oracle</b> (expat, gnutls, kernel, php:8.2, thunderbird, and uek-kernel), <b>Slackware</b> (httpd, net, proftpd, tigervnc, and xorg), <b>SUSE</b> (apache-sshd, apptainer, atril, bind, busybox, cloudflared, evolution-data-server, golang-github-prometheus-prometheus, golang-github-v2fly-v2ray-core, grafana, helm, kernel, libgphoto2-6, libjxl-devel, libsoup, libsoup-2_4-1, libsoup-3_0-0, memcached, ovmf, python-cairosvg, python-flask, python-pip, python-pymupdf, python-pyOpenSSL, python-urllib3, python-urllib3_1, python3-pyOpenSSL, restic, rsync, salt, sdbootutil, tor, tree-sitter, vorbis-tools, and yq), and <b>Ubuntu</b> (exim4, frr, gst-plugins-base1.0, libtemplate-perl, libwww-perl, mysql-8.0, nginx, python-pip, python-urllib3, and twisted).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in kernel (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3566662/it-security-nachrichten/mehrere-probleme-in-kernel-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566662/it-security-nachrichten/mehrere-probleme-in-kernel-slackware/</guid>
<pubDate>Tue, 02 Jun 2026 17:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (php:8.2 and php:8.3), Debian (gst-plugins-good1.0, symfony, and yelp), Fedora (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), Mageia (assimp, libcaca, sdl2_sound, and tar), Slackware (kernel)...]]></description>
<link>https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566223/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 02 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (php:8.2 and php:8.3), <b>Debian</b> (gst-plugins-good1.0, symfony, and yelp), <b>Fedora</b> (dovecot, freeipa, hplip, libpng, perl-Catalyst-Plugin-Authentication, postfix, samba, unbound, and vim), <b>Mageia</b> (assimp, libcaca, sdl2_sound, and tar), <b>Slackware</b> (kernel), <b>SUSE</b> (alloy, apache-commons-lang3, apache-commons-text,, apache2, bubblewrap, busybox, chromium, cups, docker-stable, ffmpeg-8, google-osconfig-agent, gsasl, ignition, java-26-openjdk, kernel, libsolv-demo, libsoup, libzypp, localsearch, openjpeg2, postgresql-jdbc, putty, python-mistune, python-Pillow, python-python-multipart, python-Twisted, python3-Twisted, re, roundcubemail, vim, wireshark, and xz), and <b>Ubuntu</b> (evolution-data-server, exim4, gsasl, haveged, lcms2, libreoffice, linux-aws, linux-lts-xenial, linux-lowlatency, linux-nvidia-tegra, nginx, nncp, qtdeclarative-opensource-src, sslh, sssd, and xz-utils).]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Threatening Security Researcher]]></title>
<description><![CDATA[An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and f...]]></description>
<link>https://tsecurity.de/de/3565798/it-security-nachrichten/microsoft-threatening-security-researcher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565798/it-security-nachrichten/microsoft-threatening-security-researcher/</guid>
<pubDate>Tue, 02 Jun 2026 13:07:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An anonymous security researcher called “Nightmare Eclipse” has been <a href="https://deadeclipse666.blogspot.com/">publishing</a> a series of significant security exploits against Microsoft Windows—including one that <a href="https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/">breaks</a> BitLocker. Microsoft has <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure">threatened</a> legal action against the researcher. Lots of recriminations are being <a href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/">traded</a> back and forth.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Threatening Security Researcher]]></title>
<description><![CDATA[An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and f...]]></description>
<link>https://tsecurity.de/de/3565793/it-security-nachrichten/microsoft-threatening-security-researcher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565793/it-security-nachrichten/microsoft-threatening-security-researcher/</guid>
<pubDate>Tue, 02 Jun 2026 13:07:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-threatening-security-researcher/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-threatening-security-researcher/">Microsoft Threatening Security Researcher</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI killed the code review. What happens to knowledge sharing?]]></title>
<description><![CDATA[As long as software engineering is done in teams, we need a way for people to know how things work, why certain decisions were made and where the boundaries are. That need doesn’t go away when AI writes the code. If anything, it gets more critical.



Code reviews were how most teams handled this...]]></description>
<link>https://tsecurity.de/de/3565670/it-nachrichten/ai-killed-the-code-review-what-happens-to-knowledge-sharing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565670/it-nachrichten/ai-killed-the-code-review-what-happens-to-knowledge-sharing/</guid>
<pubDate>Tue, 02 Jun 2026 12:17:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As long as software engineering is done in teams, we need a way for people to know how things work, why certain decisions were made and where the boundaries are. That need doesn’t go away when AI writes the code. If anything, it gets more critical.</p>



<p>Code reviews were how most teams handled this. When someone reviewed your PR, they didn’t just check for bugs; they absorbed context. They learned why certain decisions were made. That’s tribal knowledge. At <a href="https://dx.community/" rel="nofollow">The Hangar</a>, a community of DevEx leaders, we discussed code reviews a lot. According to Adrienne Braganza Tacke, author of <a href="https://www.manning.com/books/looks-good-to-me" rel="nofollow">‘Looks Good to Me: Constructive Code Reviews’</a>, the most important function of code review is actually record-keeping: chronicling how the codebase changed and why, not just catching bugs.</p>



<p><a href="https://www.aviator.co/podcast/code-reviews-looks-good-to-me" rel="nofollow">That conversation</a> now feels like a different era. The entire software development lifecycle, as we know it, is not only accelerating, but collapsing and being redefined. I recently said that we should <a href="https://www.latent.space/p/reviews-dead" rel="nofollow">kill the code review</a>. AI generates code faster than humans can review it. PRs pile up or get rubber-stamped. That approval gate no longer matches how we do software engineering now.</p>



<p>But if AI is now generating most of the code and there is no way a human could ever read all of it, how do we share knowledge?</p>



<h2 class="wp-block-heading">Decisions over diffs</h2>



<p>My proposal for solving the code review bottleneck was to move the human checkpoint upstream, to reviewing intent, reviewing the contract that code should fulfill: specs, plans, constraints and acceptance criteria. The same applies to the knowledge-sharing part of the review process.</p>



<p>If the team reviews intent and acceptance criteria before code is generated, the knowledge sharing happens naturally as part of planning. You’re not trying to reverse-engineer decisions from a 500-line diff. You’re aligning on a handful of key choices before anything gets built. The reviewer reads 10 lines of decisions, not 500 lines of code.</p>



<p>Whether that takes the form of a lightweight spec, a set of acceptance criteria, or even bullet points extracted from the prompt conversation, the principle is the same: make decisions visible and reviewable. That’s where the knowledge lives.</p>



<p>When a developer works with Cursor or Claude Code, they make decisions constantly: architectural choices, behavior tradeoffs and scope calls. Those decisions live in the prompt conversation, in the back-and-forth with the agent. When the PR is submitted, that context is gone. The code is there. The reasoning behind it is not.</p>



<p>The idea of formalizing intent before implementation is not new.<a href="https://youtu.be/PkITOx9lIT8?si=pr1HGp6HLe6nlzDI&amp;t=979" rel="nofollow"> </a><a href="https://youtu.be/PkITOx9lIT8?si=pr1HGp6HLe6nlzDI&amp;t=979" rel="nofollow">Behavior-Driven Development, Test-Driven Development</a> and Design-by-Contract approaches all tried to define behavior in structured, human-readable specs before writing code. BDD in particular asks teams to describe what the system should do in natural language, as scenarios that even the non-technical stakeholders can read and verify, before any code is written.</p>



<p>These approaches were often perceived as overhead. Writing formal behavior descriptions and contracts demanded discipline and time. Under delivery pressure, teams frequently skipped them. AI makes them more practical, not less. AI can help generate structured acceptance criteria, behavioral specs, or even contract-like descriptions. It can also help enforce them.</p>



<h2 class="wp-block-heading">AI software engineering isn’t a solo sport</h2>



<p>Every now and then we hear about engineers out there running agent orchestrators that produce 100,000 lines of code a day, like <a href="https://steve-yegge.medium.com/welcome-to-gas-town-4f25ee16dd04" rel="nofollow">Steve Yegge and his Gas Town</a>. Some say this is the future of software development, solo developers with swarms of agents, but I disagree. Building software, even with agents, is not a solo sport.</p>



<p>If that one person gets <a href="https://en.wikipedia.org/wiki/Bus_factor" rel="nofollow">hit by a bus</a>, can someone else drive the project? Do they understand all the decisions that were made? No. In an enterprise, you need redundancy. Multiple stakeholders, teams and collaboration.</p>



<p>The knowledge-sharing function doesn’t become less important as AI adoption grows. It becomes more important, because the gap between what the system does and what any individual understands about it is widening faster than ever. No one wants to have their senior engineers become bottlenecks because they’re the only ones that know how they got their solutions from AI.</p>



<p>When AI is involved in every part of the process, the social contract of collaboration is changing. There’s authorship ambiguity — someone reviewing code that a colleague submitted doesn’t know how much effort they put into understanding the nuances of that code. The reviewer then might use AI to help them understand that code and post comments and the author may use AI to address those comments without investing time in reading and understanding them.</p>



<p>In a pre-AI team, a junior PR generates:</p>



<ul class="wp-block-list">
<li>4–8 comments from a senior on idiomatic patterns.</li>



<li>A back-and-forth on edge cases.</li>



<li>An implicit “here’s how I’d think about this” lesson.</li>



<li>A senior who now knows that part of the code exists.</li>
</ul>



<p>In an AI-heavy team, that same change is:</p>



<ul class="wp-block-list">
<li>Generated by AI, lightly edited.</li>



<li>Reviewed by AI, lightly approved.</li>



<li>Merged with zero humans having formed a mental model of it.</li>
</ul>



<h2 class="wp-block-heading">New kind of debt: Cognitive debt</h2>



<p>I recently spoke to professor and researcher Margaret-Anne Storey, who has coined a term for that: <a href="https://www.aviator.co/podcast/cognitive-debt-ai-code-margaret-anne-storey" rel="nofollow">cognitive debt</a>. She first noticed it with a group of her students who were building with AI and moving fast. At some point they told her that they couldn’t make changes in the product anymore. The professor suspected they had tech debt, messy code, but found out that the students had accrued a new kind of debt.</p>



<p>They had lost track of what features they were trying to build and why. They didn’t know who knew what on the team. And on one of the teams, it was one person who knew all the code and understood it because they were supervising the AI that generated it, and the rest of the team was unable to do that. And the person who had generated the code didn’t really understand what was generated either.</p>



<p>That’s the risk when teams start building fast with AI, dropping code reviews because they realistically cannot review thousands of lines of AI-generated code, but doing nothing to replace the knowledge-sharing function.</p>



<p><a href="https://www.anthropic.com/research/AI-assistance-coding-skills" rel="nofollow">Anthropic’s study</a> showed how over-reliance on AI coding assistants has downsides in code comprehension. Their study with 52 engineers found that AI assistance produced no statistically significant speedup on the task but scored 17% lower on a comprehension quiz afterward. The biggest drops were in debugging, with smaller declines in conceptual understanding and code reading. The takeaway is clear: passively delegating to AI (“just make it work”) impairs learning far more than using it to ask questions and understand the code.</p>



<p>Even a workflow of triggering an adversarial agent after you’re done coding with your primary agent that asks questions like: Why did you do it this way? What behavior do you expect? What tradeoffs did you consider, could go a long way toward reducing cognitive debt. It forces the developer to articulate understanding before the code moves forward.</p>



<h2 class="wp-block-heading">Make knowledge sharing intentional</h2>



<p>That judgment and those decisions — that is the main thing we as humans are providing in an AI-first world. You could even go so far as to say that most of the code written is boilerplate. The main decisions we’re making are architectural decisions, behavior decisions and technical decisions. These are the things we need to provide as input for the AI systems and every change requires clarity on those decisions.</p>



<p>A lot of the knowledge sharing that happened through code reviews was incidental. Engineers absorbed context because they had to look at the code to approve it. As we phase out reviews, being able to review these decisions becomes more important.</p>



<p>Eventually, engineers are still accountable for the changes they’ve created. All these decisions have to be tracked, and somebody has to be able to audit them to ask why certain decisions were made. That becomes your source of truth. That’s how I think team collaboration and knowledge sharing evolve, even though I said that we should kill the code review.</p>



<p>The productivity gains are real and worth taking. But every org optimizing purely for PR throughput is running an experiment on its own engineering culture. In five years, the orgs that win won’t be the ones that shipped the most AI code. They’ll be the ones whose engineers still understand what got shipped.<br><br><br></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['Virtual OS Museum' Lets You Try 570 Extinct Operating Systems]]></title>
<description><![CDATA[You can try 570 extinct operating systems at a new "virtual museum," according to a new article by ZDNet. Their reporter downloaded the ancient OS NeXTStep, and was "shocked" by how easy it was to run it, "and by the sheer number of operating systems to choose from."


Essentially, what you do is...]]></description>
<link>https://tsecurity.de/de/3561064/it-security-nachrichten/virtual-os-museum-lets-you-try-570-extinct-operating-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561064/it-security-nachrichten/virtual-os-museum-lets-you-try-570-extinct-operating-systems/</guid>
<pubDate>Sun, 31 May 2026 17:53:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[You can try 570 extinct operating systems at a new "virtual museum," according to a new article by ZDNet. Their reporter downloaded the ancient OS NeXTStep, and was "shocked" by how easy it was to run it, "and by the sheer number of operating systems to choose from."


Essentially, what you do is download a zipped file, unzip it, change into the newly created directory, and run the executable. VirtualBox then opens to a Debian Linux instance, where you can select from a very long list of operating systems to run... You can run operating systems like Amiga, Apple I/II/III, Atari, Avigo, Commodore 64, Cray, DEC Alpha, Einstein, Game Boy Advance, GE 200, HP 3000, IBM 1130, iPod touch, Jupiter Ace, Lisa, Macintosh, MIPS-based SBCs, Neo, Newton, NeXT, NORC, Palm, and so many more. You can test the earliest mainframes, later mainframes and minicomputers, workstations and Unix variants, home computers, personal computer operating systems, mobile and embedded adOSes, and research-based and obscure systems. As far as Linux is concerned, you can run early Debian and its derivatives, Red Hat and its derivatives, early Slackware, and more... 

There are two editions of the Virtual OS Museum: full and lite. The full edition is currently 174GB and includes everything you need to run these old-school operating systems. The full version does not require a network connection to run. The Lite version is only 14GB and requires an internet connection because it downloads the full OS image you want to use. 

Gizmodo notes "this project is all the more remarkable for being the work of one man: Andrew Wartenkin, who has been collecting OS images for over two decades."

Of course, Wartenkin didn't write all the emulation software himself, and he maintains a list of credits to give credit where it's due... The Museum itself runs in a virtual machine, which seems kinda fitting — it opens in a virtualized Linux installation and presents you with the full list of available operating systems. 

Did you know someone has written a GUI for the Commodore 64? Neither did I! There are simulations of ancient mainframes, like the IBM 1130 (yours for the low, low price of $32,280 — or $41,230 with a disk drive — back in 1965).
 

There's also a YouTube channel. 

Thanks to long-time Slashdot reader Z00L00Kfor sharing the news.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Virtual+OS+Museum'+Lets+You+Try+570+Extinct+Operating+Systems%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F05%2F30%2F2323231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F05%2F30%2F2323231%2Fvirtual-os-museum-lets-you-try-570-extinct-operating-systems%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/05/30/2323231/virtual-os-museum-lets-you-try-570-extinct-operating-systems?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adversarial Oracles: LLM-Guided EDR Signature Reduction]]></title>
<description><![CDATA[In previous blog posts we’ve talked about getting nerd sniped. Today we’re going to talk about a kind of nerd sniping that any offensive security tool creator is familiar with; when your tool gets signatured. This normally kicks off a frustrating spiral of back and forth changes between the tool ...]]></description>
<link>https://tsecurity.de/de/3555140/it-security-nachrichten/adversarial-oracles-llm-guided-edr-signature-reduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555140/it-security-nachrichten/adversarial-oracles-llm-guided-edr-signature-reduction/</guid>
<pubDate>Thu, 28 May 2026 19:53:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In previous blog posts we’ve talked about getting nerd sniped. Today we’re going to talk about a kind of nerd sniping that any offensive security tool creator is familiar with; when your tool gets signatured. This normally kicks off a frustrating spiral of back and forth changes between the tool author and security vendors until […]</p>
<p>The post <a href="https://www.praetorian.com/blog/llm-edr-signature-reduction/">Adversarial Oracles: LLM-Guided EDR Signature Reduction</a> appeared first on <a href="https://www.praetorian.com/">Praetorian</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sesame, the conversational AI startup from Oculus founders, launches its iOS app]]></title>
<description><![CDATA[Sesame’s new iOS app brings its conversational AI agents to the public, offering more natural back-and-forth interactions designed to feel less like traditional chatbots and more like talking to a person.]]></description>
<link>https://tsecurity.de/de/3554744/it-nachrichten/sesame-the-conversational-ai-startup-from-oculus-founders-launches-its-ios-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554744/it-nachrichten/sesame-the-conversational-ai-startup-from-oculus-founders-launches-its-ios-app/</guid>
<pubDate>Thu, 28 May 2026 17:47:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sesame’s new iOS app brings its conversational AI agents to the public, offering more natural back-and-forth interactions designed to feel less like traditional chatbots and more like talking to a person.]]></content:encoded>
</item>
<item>
<title><![CDATA[Perfect Randomness Realized For the First Time]]></title>
<description><![CDATA[ETH Zurich researchers say they have generated certified "perfect randomness" for the first time by using a quantum Bell-test setup with two entangled superconducting chips connected by a 30-meter cooled link. "In the long term, this work could play a similar role in digital security as atomic cl...]]></description>
<link>https://tsecurity.de/de/3553220/it-security-nachrichten/perfect-randomness-realized-for-the-first-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553220/it-security-nachrichten/perfect-randomness-realized-for-the-first-time/</guid>
<pubDate>Thu, 28 May 2026 09:08:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ETH Zurich researchers say they have generated certified "perfect randomness" for the first time by using a quantum Bell-test setup with two entangled superconducting chips connected by a 30-meter cooled link. "In the long term, this work could play a similar role in digital security as atomic clocks do for timekeeping: a physically certified source of randomness that other systems can rely on," reports Phys.org. "Possible applications range from the encryption of sensitive communications and digital identities to public randomness services for lotteries and blockchain applications." From the report: They call their method randomness amplification. "This was made possible by an improved so-called Bell-Test with simultaneously high quality and high data rate," says [Renato Renner and Andreas Wallraff]. He and his coworkers use a complex setup that consists of two superconducting chips, which they cool down to very low temperatures close to absolute zero. Each chip represents a quantum bit or qubit, which can take on the states "0" or "1" or any arbitrary superposition of these states. A 30-meter-long tube, which is also cooled down, connects the two chips.
 
Microwave photons can fly back and forth between them, thus creating quantum mechanical entanglement. This means that a quantum measurement on one qubit, which randomly yields the values "0" or "1," influences automatically and at a distance whether "0" or "1" is measured on the second qubit. The separation of 30 meters ensures that, during the measurement, even at the speed of light, no information can be exchanged between the qubits. This would disturb the perfect randomness.
 
Wallraff and his team made the choice of the exact type of measurement (or "measurement basis" in technical jargon) on the two qubits depending on an imperfect random number generator. Renner's coworkers could then amplify the randomness of the measurement results further using a special algorithm. "The resulting sequence of zeros and ones is now really perfectly random, and we can even certify that," says Renner. He likens this result to crossing a ridge: "The technical improvements allowed us, for the first time, to create random numbers that will remain perfectly random for all eternityâ"no matter what analytical methods are used to assess their randomness." 
The findings have been published in the journal Nature.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Perfect+Randomness+Realized+For+the+First+Time%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F05%2F28%2F0542214%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F05%2F28%2F0542214%2Fperfect-randomness-realized-for-the-first-time%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/05/28/0542214/perfect-randomness-realized-for-the-first-time?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Roku Updates Its UI For the First Time In a Decade]]></title>
<description><![CDATA[Roku is rolling out its first major homescreen update in a decade. The UI doesn't look too dramatically different, but users will notice more personalization-driven changes, including frequently used apps, "top picks," household-specific layouts, and recommendations based on viewing habits. Rest ...]]></description>
<link>https://tsecurity.de/de/3552140/it-security-nachrichten/roku-updates-its-ui-for-the-first-time-in-a-decade/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552140/it-security-nachrichten/roku-updates-its-ui-for-the-first-time-in-a-decade/</guid>
<pubDate>Wed, 27 May 2026 20:22:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Roku is rolling out its first major homescreen update in a decade. The UI doesn't look too dramatically different, but users will notice more personalization-driven changes, including frequently used apps, "top picks," household-specific layouts, and recommendations based on viewing habits. Rest assured, Engadget adds, "Everything is still in various shades of purple and Roku City is still available as a screensaver." From the report: Today's update certainly brings more clutter into the mix, including a new "marquee" ad spot that takes up a large chunk of the screen. It's worth remembering that Roku makes most of its money on ads and not its hardware. "More than 100 million households will feel the difference the moment they turn on their TV -- and it opens up a better, more powerful experience for our partners as well," CEO Anthony Wood wrote in a blog post.
 
The update does bring one novel feature, according to The Hollywood Reporter. The company says the new homescreen platform will adapt to how households use Roku devices. This is to accommodate "multiple people living in homes." For instance, a child's bedroom TV might have a different homescreen than TV in the living room, and so forth. This expansion is rolling out right now to US-based customers, though it might take a while to reach every user. Roku says "additional countries will follow in the coming months."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Roku+Updates+Its+UI+For+the+First+Time+In+a+Decade%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F27%2F1647224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F27%2F1647224%2Froku-updates-its-ui-for-the-first-time-in-a-decade%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/05/27/1647224/roku-updates-its-ui-for-the-first-time-in-a-decade?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind, buildah, compat-libtiff3, compat-openssl11, containernetworking-plugins, crun, delve, dnsmasq, dovecot, edk2, firefox, freeipmi, gdk-pixbuf2, giflib, git-lfs, glib2, go-fdo-client, go-fdo-server, golang, grafana, grafana-pcp, gstreamer1-plugin...]]></description>
<link>https://tsecurity.de/de/3551251/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551251/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 27 May 2026 15:28:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind, buildah, compat-libtiff3, compat-openssl11, containernetworking-plugins, crun, delve, dnsmasq, dovecot, edk2, firefox, freeipmi, gdk-pixbuf2, giflib, git-lfs, glib2, go-fdo-client, go-fdo-server, golang, grafana, grafana-pcp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, iputils, jq, kernel, krb5, libcap, LibRaw, libsndfile, libsoup, libsoup3, libssh, libtiff, libvirt, linux-sgx, luksmeta, mingw-glib2, NetworkManager, nginx, nginx:1.24, nginx:1.26, openexr, openssh, openssl, opentelemetry-collector, p11-kit, PackageKit, podman, python-jwcrypto, python-markdown, python-tornado, python3.11, python3.12, python3.14, python3.9, qemu-kvm, rsync, skopeo, sudo, systemd, thunderbird, tomcat, unbound, vim, xorg-x11-server, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Debian</b> (imagemagick, kdenlive, memcached, node-shell-quote, and samba), <b>Fedora</b> (chromium, curl, editorconfig, haproxy, perl-Crypt-DSA, perl-HTTP-Tiny, poppler, rust-afterburn, rust-coreos-installer, rust-eif_build, rust-rpm-sequoia, rust-sequoia-chameleon-gnupg, rust-sequoia-git, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-openpgp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-sqv, and uriparser), <b>Oracle</b> (compat-libtiff3, dnsmasq, firefox, freeipmi, kernel, and uek-kernel), <b>Slackware</b> (mozilla), <b>SUSE</b> (assimp, firefox, glibc, gnutls, go1.25-openssl, go1.26-openssl, kernel, kubevirt, leancrypto, libarchive, libsndfile, mcphost, nginx, openssh, podman, python-GitPython, rsync, and samba), and <b>Ubuntu</b> (ayttm, dnsmasq, libssh2, linux-azure, linux-azure, linux-azure-6.17, linux-iot, linux-lowlatency-hwe-5.15, ngtcp2, onnx, opencc, protobuf, python-git, samba, xdg-dbus-proxy, and xmlrpc-c).]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco research finds standard AI safety benchmarks miss the real threat]]></title>
<description><![CDATA[Enterprises deploying closed AI models have generally relied on published safety benchmarks to assess risk before procurement and deployment decisions. New research from Cisco’s AI Threat Intelligence and Security Research team finds those benchmarks may systematically understate the threat.



S...]]></description>
<link>https://tsecurity.de/de/3551225/it-security-nachrichten/cisco-research-finds-standard-ai-safety-benchmarks-miss-the-real-threat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551225/it-security-nachrichten/cisco-research-finds-standard-ai-safety-benchmarks-miss-the-real-threat/</guid>
<pubDate>Wed, 27 May 2026 15:25:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises deploying closed AI models have generally relied on published safety benchmarks to assess risk before procurement and deployment decisions. New research from Cisco’s AI Threat Intelligence and Security Research team finds those benchmarks may systematically understate the threat.</p>



<p>Standard safety tests submit a single adversarial prompt and record the model’s response. Multi-turn attacks work differently. An attacker maintains a conversation across multiple exchanges, iterating and adapting based on each response until the model yields.</p>



<p>The <a href="https://www.cisco.com/content/dam/cisco-cdc/site/en_us/products/security/proprietary_problems.pdf">report</a> pairs single-turn and multi-turn adversarial evaluation across 15 closed/proprietary frontier models from OpenAI, Anthropic, Google, Amazon and xAI. Running 30,090 single-turn prompts and 6,986 multi-turn attacks, the team found that the two evaluation regimes produce different model rankings, different failure maps and different risk profiles. Every model tested <a href="https://blogs.cisco.com/ai/proprietary-problems">failed a non-trivial share of multi-turn attacks</a>.</p>



<p>Key findings from the research:</p>



<ul class="wp-block-list">
<li>Multi-turn attack success rate (ASR) ranged from 7.89% to 88.30% across all 15 models, against a single-turn range of 2.19% to 64.91%.</li>



<li>Eight of 15 models showed an absolute gap greater than 15 percentage points between the two regimes.</li>



<li>Anthropic’s Claude family, which posted the lowest single-turn ASR in the cohort at 2.19% to 3.64%, still reached 11.16% to 16.20% under iterative attack.</li>



<li>Single-turn failures concentrated in three procedures: Imposter AI at 37.50% weighted ASR, Soft Paraphrase at 29.21% and System Prompts at 27.69%</li>
</ul>



<p>The findings challenge a common assumption in enterprise AI procurement. </p>



<p>“The surprising thing here is really that a lot of people accept and kind of understand these frontier labs as being state of the art, but they don’t necessarily think through the security and safety implications of that,” <a href="https://www.linkedin.com/in/helloamychang/">Amy Chang</a>, head of AI threat and security research at Cisco, told <em>Network World</em>. “What this research does is kind of showcase that there is still variance across the different models, and how strong they are with the internal guardrails that are built within the model against these types of attacks.”</p>



<h2 class="wp-block-heading">How multi-turn attacks work</h2>



<p>In a multi-turn attack, the adversary does not present the harmful request upfront. Intent builds gradually across exchanges, with each prompt appearing benign in isolation while steering toward a harmful outcome. The model processes each turn without recognizing the pattern forming across the conversation.</p>



<p>The research tested five attack strategy families:</p>



<ul class="wp-block-list">
<li><strong>Crescendo escalation.</strong> The attacker escalates the ask incrementally, each prompt appearing harmless until the full picture emerges. “It seems like, oh, benign prompt, benign prompt, benign prompt, but as it builds, you start to put the pieces together,” Chang said.</li>



<li><strong>Refusal reframe.</strong> When the model declines a request, the attacker reframes their identity or purpose to push past it. “You reframe the refusal and be like, no, no, you don’t understand, I’m not a bad person, this is what I need it for,” she said.</li>



<li><strong>Role-play and persona adoption.</strong> The attacker assumes a character or persona, shifting the conversational framing so the model perceives a different obligation to comply. The report identifies this as the highest-weighted strategy family in the cohort at 29.89% weighted ASR.</li>



<li><strong>Contextual ambiguity and misdirection.</strong> The attacker uses vague or misleading framing to obscure the true nature of the request, steering the conversation without stating harmful intent directly.</li>



<li><strong>Information decomposition and reassembly.</strong> The attacker breaks a harmful request into component parts distributed across multiple turns, each appearing innocuous in isolation. The model responds to each piece without recognizing the assembled outcome.</li>
</ul>



<h2 class="wp-block-heading">What multi-turn failures say about AI safety</h2>



<p>Every model in the cohort failed a meaningful share of multi-turn attacks. The root cause is structural. Chang said the vulnerability is a fundamental characteristic of how generative AI models work. They are probabilistic systems trained to predict the next likeliest token, and that mechanism produces unintended outputs that pre-deployment testing cannot fully eliminate. For closed models, where training data is not publicly disclosed, the problem is compounded because defenders cannot fully audit what the model has learned.</p>



<p>The pattern is not limited to closed models. Cisco’s earlier evaluation of eight open-weight LLMs, <a href="https://blogs.cisco.com/ai/open-model-vulnerability-analysis">published</a> in November 2025, found multi-turn attack success rates running two to ten times higher than single-turn baselines. The report concludes that multi-turn vulnerability is a structural property of the current AI frontier regardless of whether model weights are public or proprietary, and regardless of whether a lab publicly emphasizes safety or capability.</p>



<p>The exposure grows significantly larger when those same models power agentic workflows. “These models are the ones that power agents, and agents have broader access, broader ability to conduct actions on behalf of the human,” Chang said.</p>



<h2 class="wp-block-heading">The network layer as a defense point</h2>



<p>For network security professionals, the instinct is to apply a familiar paradigm: Proxy LLM traffic at the network layer, inspect inputs and outputs, and enforce policy the same way a WAF or IPS handles web traffic. Chang said that instinct is right in part, but LLM security introduces a dimension that signature-based controls cannot address. The difference is intent. </p>



<p>“There’s also an intent component there as well, where traditional network security approaches kind of fall short,” Chang said. </p>



<p>A WAF operates on known patterns, payload signatures, protocol violations, known attack strings. Natural language does not reduce to those primitives. An agent responding to an instruction to delete a home directory cannot determine from the request alone whether the person asking is authorized or is attempting to manipulate the agent into a destructive action. </p>



<p>Network-layer inspection remains a valid baseline for deployments that generate network traffic. “I would say that that is one component of a core principle that should be applied in terms of making sure that at least as traffic gets passed through the network layer, whether they’re inputs or outputs, should have some sort of either guardrail or sanitation check to ensure that the prompts that are coming back and forth are safe,” she said.</p>



<h2 class="wp-block-heading">Evaluation practices for enterprise teams</h2>



<p>For security teams reading the report, Chang’s guidance centers on three actions.</p>



<ul class="wp-block-list">
<li><strong>Use the report and the LLM Security Leaderboard to inform model selection. </strong><a href="https://leaderboard.aidefense.cisco.com/rankings">Cisco’s leaderboard</a> publishes adversarial evaluation signals against leading models on a rolling basis and gives security teams a more current picture than static model cards or published benchmarks.</li>



<li><strong>Do not take vendor safety claims at face value.</strong> Published single-turn benchmarks can misrank models by a wide margin. Multi-turn exposure is invisible to any single-turn evaluation, and procurement decisions made on that basis carry unquantified risk.</li>



<li><strong>Layer additional defenses on top of the model.</strong> No base model in the cohort is safe under iterative attack. Runtime guardrails, application-layer controls, and pre-deployment testing are necessary regardless of which model an organization selects.</li>
</ul>



<p>“Out of the box, without any additional protections, these models, whether they’re closed or open, are insufficient on their own to kind of be used in a way that [has] potential ramifications,” Chang said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3549951/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549951/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Wed, 27 May 2026 08:00:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs are enlisting business users to vibe code their own apps]]></title>
<description><![CDATA[Vibe coding is expanding beyond the realm of software development teams into a variety of business units at a range of enterprises, and technology leaders are not only supporting these efforts but in some cases leading the charge.



This democratization of software development, buoyed by vibe co...]]></description>
<link>https://tsecurity.de/de/3547568/it-nachrichten/cios-are-enlisting-business-users-to-vibe-code-their-own-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547568/it-nachrichten/cios-are-enlisting-business-users-to-vibe-code-their-own-apps/</guid>
<pubDate>Tue, 26 May 2026 12:17:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vibe coding is expanding beyond the realm of software development teams into a variety of business units at a range of enterprises, and technology leaders are not only supporting these efforts but in some cases leading the charge.</p>



<p>This democratization of software development, buoyed by <a href="https://www.cio.com/article/4165921/19-vibe-coding-tools-for-democratizing-app-development.html">vibe coding tools</a>, including chatbots and agents that generate code via prompts, has made vibe coding a thing in departments such as human resources and marketing.</p>



<p>With guidance from IT, such efforts can cut down development backlogs, move solution-building closer to business problems, and open opportunities not previously pursued. But <a href="https://www.cio.com/article/4148288/vibe-coding-your-own-enterprise-apps-is-edgy-business.html">vibe coding can be edgy business</a>. IT leaders interested in unleashing the power of vibe coding in the hands of business users must establish the governance and guardrails necessary to ensure secure results.</p>



<p>Here is a look at how several IT leaders are deploying vibe coding beyond IT and the challenges they’ve faced.</p>



<h2 class="wp-block-heading">Feeling the vibe</h2>



<p>At financial services technology provider EnFi, everyone in the organization, including the C-suite, is actively encouraged to use Claude Code to build their own sub-agents and then get the rest of their teams to use their creations.</p>



<p>“The results have surprised us,” says <a href="https://www.linkedin.com/in/sweller/" rel="nofollow">Scott Weller</a>, CTO. “What started as an engineering productivity initiative has become a company-wide capability, where anyone from the CEO to a customer success manager can turn an idea into a working prototype in hours, not weeks.”</p>



<p>Vibe coding using the tool quickly expanded when non-engineering employees realized they could participate directly in building applications, Weller says. “Product leadership, customer success, and executive stakeholders now routinely initiate development work through the same system,” he says. “Every branch, regardless of who initiates [coding projects], passes through the same automated quality gates, architectural checks, and human code review before anything reaches production.”</p>



<p>When an AI agent writes code, “it follows the same rules as a senior engineer,” Weller says. “AI-powered code review catches architectural violations, security issues, and pattern inconsistencies before a human reviewer sees it. This means the output from a product manager’s Slack request meets the same quality bar as an engineer’s pull request.”</p>



<p>Enabling everyone in the company to come up with an idea and see it running by simply asking a bot to build it “has fundamentally changed who participates in building the product,” Weller says.</p>



<p>Making AI-assisted coding broadly available has shortened the time to completing some projects from weeks to hours, Weller notes. “It has dramatically increased the number of experiments we can run, on [user experience] improvements, feature explorations, and workflow alternatives,” he says.</p>



<p>The most significant benefit is that new development ideas are no longer bottlenecked by lack of engineering capacity. “When anyone in the company can describe what they want and see it built, the rate of experimentation goes up dramatically,” Weller says.</p>



<h2 class="wp-block-heading">The momentum of building solutions to business problems</h2>



<p>Skillsoft, a provider of technology training services and products, is also pushing vibe coding outside its software development teams.</p>



<p>“While it initially emerged within IT teams, we’ve been intentional about encouraging this mindset beyond traditional software development,” says <a href="https://www.linkedin.com/in/orla-daly-ma/" rel="nofollow">Orla Daly</a>, CIO. “We see real value in enabling teams across the organization to explore, experiment, and problem‑solve using AI in ways that are directly connected to their day‑to‑day work.”</p>



<p>Within Skillsoft’s infrastructure and operations organization non-development individuals are building new products and capabilities or leveraging the principles of vibe coding to troubleshoot production issues, Daly says.</p>



<p>“We’ve seen this show up through cross‑functional experimentation such as prototyping customer intelligence solutions for our go-to-market teams and rapid development of a customer portal,” Daly says. “When people are learning and applying AI to solve a real business problem, it creates purpose and momentum.”</p>



<p>With vibe coding, teams are not just learning new concepts, “they’re developing judgment, curiosity, and a better understanding of how AI can elevate their role and the business more broadly,” Daly says. “The benefits show up in very tangible ways. Teams learn faster because they’re applying AI directly to their work. Engagement increases when people feel trusted to explore and contribute ideas. And as an organization, we gain better visibility into where skills already exist and how they’re evolving.”</p>



<p>More broadly, vibe coding supports adaptability, Daly says. “It helps people move from seeing AI as something abstract or intimidating to something they can work with thoughtfully, using judgment and collaboration rather than relying on rigid processes,” she says. “The solutions created as a result of vibe coding have filled capability gaps and delivered solutions to production in shorter timeframes, producing real value.”</p>



<h2 class="wp-block-heading">Emphasizing experimentation</h2>



<p>At Corevist, an ecommerce platform provider, broad use of vibe coding didn’t start as a formal initiative. “It showed up in different parts of the business, mostly in sales and customer-facing teams, because people were trying to move faster and make ideas easier to communicate,” says <a href="https://www.linkedin.com/in/terrystahler/">Terry Stahler</a>, CIO and chief customer officer.</p>



<p>It also didn’t spread purely on its own. “Without leadership pushing for experimentation, it likely would have moved at a much slower, consensus-driven pace,” Stahler says. “Instead, there was clear encouragement to try things, along with budget behind it.”</p>



<p>Today, Corevist uses vibe coding mainly as a prototyping tool. “It helps people get to something concrete faster, which makes conversations a lot clearer,” Stahler says. “That has been the biggest benefit. We are not using it as a shortcut to production software. Anything that is going to live beyond a prototype goes through our normal engineering and security process.”</p>



<p>Sales was the first place where Stahler saw use cases emerge. One was live prototyping during the sales process. “In a normal B2B conversation, a prospect explains what they need, the account team takes notes, and then everyone goes back and tries to interpret it later,” he says. “What changed here was the ability to turn an idea into something visible much faster, sometimes even while the conversation was still happening.”</p>



<p>That gave the prospect something concrete to react to and made it easier to tell whether a sales rep was actually understanding the request correctly. “It cut down on ambiguity early, which is valuable in any complex sales cycle,” Stahler says.</p>



<p>Marketing has also used vibe coding, for an update of its website. “The value there has been speed in the early creative and planning stages,” Stahler says. “They can generate rough versions of pages and flows much faster than they could through written direction or static mockups alone. That has made it easier to align on direction and has reduced some of the usual back-and-forth that comes with a website rebuild.”</p>



<h1 class="wp-block-heading">Supplementing the engineering queue</h1>



<p>Business growth platform provider ZenBusiness encourages vibe coding “across the board,” says <a href="https://www.zenbusiness.com/alex-victoria/">Alex Victoria</a>, CTO. “The way we think about it is pretty simple: If AI tools can help you go from idea to something working without waiting in an engineering queue, we want you to do that,” he says.</p>



<p>Vibe coding began within the product and engineering teams but has spread to other departments.</p>



<p>“We’ve seen people on the data side building their own query tools, product managers creating interactive prototypes with no design background, and teams across the company using AI to handle tasks they used to outsource to specialists,” Victoria says. “The culture we’ve tried to build is one where experimentation isn’t reserved for engineers. If you’re willing to learn and use the tools we have, anyone can code to improve their workflows on their own.”</p>



<p>Although Victoria has been using agentic coding tools for years, he says the “real unlock” of benefits came in 2025, with the release of Claude Code.</p>



<p>“I’ve seen a huge impact since then, and also with Cursor and Codex,” he says. “When someone can build their own tool or prototype in an afternoon instead of waiting weeks in an engineering queue, it changes what’s worth doing.”</p>



<p>The bigger benefit is how it’s changed the relationship between roles, Victoria says. “People who know how to build software can now produce far more value than ever before,” he says. “There’s still a gap between a vibe-coded idea and a running product. If you know how to ship a running product, you’re very valuable in this world.”</p>



<h2 class="wp-block-heading">Facing down challenges</h2>



<p>Embracing more widespread use of vibe coding in the enterprise comes with its own set of challenges.</p>



<p>One of these is maintaining quality when everyone can build. “When you open development to non-engineers, the risk is code that works but doesn’t follow project conventions, creating technical debt faster than manual development,” Weller says.</p>



<p>EnFi has addressed this by investing heavily in the rules and skills layer of coding. More than 40 custom skills impact AI output to match pre-determined architectural patterns.</p>



<p>“The agent doesn’t just write code; it writes code that passes the same review criteria we apply to human engineers,” Weller says. “Every branch, whether initiated by the CEO or a junior engineer, goes through the same automated quality gates and human code review.”</p>



<p>For business software provider Agiloft, “the biggest challenge isn’t technical, it’s organizational,” says <a href="https://www.linkedin.com/in/noe-ramos-psyd-3a1808178/" rel="nofollow">Noe Ramos</a>, vice president of AI operations. Agiloft is building an AI-native development capacity across every business function, embedding it into processes such as finance, human resources, and professional services.</p>



<p>“Most companies, including ours, are still learning where work actually happens versus where they think it happens,” Ramos says. “Before you can extend AI into a business function, you have to understand the real workflow, not the documented one. That discovery work is underestimated almost everywhere.”</p>



<p>The company also had to work through “the natural friction of trust and adoption,” Ramos says. “The human variable, though critically important to AI, is always the rate-limiting factor in this case, not the technology.”</p>



<p>On the governance side, Agiloft has had to address issues such as access controls, identity management, and data handling. “We built a formal approval process and a structured use-case lifecycle to manage this, so AI doesn’t get introduced into business teams in ways that create technical debt or compliance exposure,” Ramos says.</p>



<p>The primary challenge for healthcare technology provider iCore was creating confidence among non-technical users rather than technical barriers, says <a href="https://www.linkedin.com/in/thiago-soares-060938b5/" rel="nofollow">Thiago Soares</a>, COO. The company has actively supported AI-assisted development outside its engineering team, including operations and client success functions that are building automated reporting tools, internal workflow templates, and client onboarding checklists that previously required developer time to produce.</p>



<p>“Staff unfamiliar with AI-assisted development needed structured onboarding before adoption felt natural,” Soares says. “We addressed that through peer-led sessions, where early adopters demonstrated practical use cases relevant to each team’s specific workflows.</p>



<p>Uneven confidence levels can slow progress, especially when people worry about getting it wrong, Daly says. “Creating a safe space to learn is important,” she says. “Creating small teams to work together with peer-to-peer support and encouraging shared learning has also been helpful to support progress through practical application, which is where we see people learn best.”</p>



<p><a href="https://www.cio.com/article/3984527/how-to-establish-an-effective-ai-grc-framework.html">Governance</a> is another key consideration, particularly in regulated industries with strict data handling protocols, such as healthcare. “Successful organizations set out explicit boundaries within which machine-generated code can be developed outside of formal development pathways,” Soares says.</p>



<p>IT leadership at iCore has built the guardrails needed to make expansion of vibe coding safe, “defining data access boundaries and compliance checkpoints that align with our commitment to trust and security,” Soares says. “That governance foundation is what allows cloud-driven innovation to move forward without creating the regulatory exposure healthcare environments cannot afford.”</p>



<h2 class="wp-block-heading">The future of coding</h2>



<p>Organizations that are moving vibe coding beyond software development teams are aiming to expand these efforts further.</p>



<p>At iCore, expansion of vibe coding into marketing and human resources functions is already under way, Soares says, focused on content workflows and documentation automation. These are “areas where vibe coding delivers efficiency without touching sensitive clinical or compliance infrastructure,” he says.</p>



<p>Agiloft plans to expand vibe coding further and make it into a standard practice “carefully and iteratively,” Ramos says, moving from isolated use cases toward a cohesive AI operating model with a shared infrastructure and AI-literate teams across functions, rather than just AI-enabled tools scattered across departments.</p>



<p>“That said, expansion for us means scaling what works, not scaling the toolset,” Ramos says. “We track every AI initiative through a structured lifecycle, from intake through decommission, precisely to avoid accumulating a stack of underutilized capabilities. Every function will eventually have embedded AI, but the goal is for those capabilities to be connected, governed, and [properly] used, not just deployed.”</p>



<p>EnFi is expanding from engineering-adjacent roles, such as product development and customer success, to other functions. “The same pattern — describe what you want, see it built, review and decide — applies to internal tooling, reporting, operational workflows, and documentation,” Weller says.</p>



<p>Organizations that master AI-assisted development internally “will be the ones capable of deploying AI-assisted workflows to their customers with the quality, governance, and reliability that regulated industries demand,” Weller says. “The internal practice is the proof point.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (atril, evince, gnutls28, haproxy, haveged, jq, kernel, krb5, libgcrypt20, nodejs, and thunderbird), Fedora (aw-server-rust, awatcher, bind, bind-dyndb-ldap, chromium, composer, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, evince, f...]]></description>
<link>https://tsecurity.de/de/3545828/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545828/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 25 May 2026 16:53:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (atril, evince, gnutls28, haproxy, haveged, jq, kernel, krb5, libgcrypt20, nodejs, and thunderbird), <b>Fedora</b> (aw-server-rust, awatcher, bind, bind-dyndb-ldap, chromium, composer, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, evince, firefox, httpd, kernel, nodejs-aw-webui, nss, perl-Apache-Session-Browseable, pie, python-pulp-glue, python-requests, and python3.15), <b>Slackware</b> (kernel), <b>SUSE</b> (apptainer, chromium, cockpit, dnsmasq, google-guest-agent, hauler, iproute2, jfrog-cli, kernel, libecpg6, libsolv, libzypp, zypper, mcphost, oci-cli, perl-YAML-Syck, python-lxml, python-urllib3, python311-impacket, rqlite, rsync, util-linux, and xz), and <b>Ubuntu</b> (evince, linux-azure, linux-azure-5.4, linux-azure-fips, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-5.15, linux-lowlatency-hwe-5.15, linux-oracle-6.17, node-path-to-regexp, and rclone).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in kernel (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3544745/unix-server/security-zwei-probleme-in-kernel-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544745/unix-server/security-zwei-probleme-in-kernel-slackware/</guid>
<pubDate>Mon, 25 May 2026 06:45:55 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Here are all the major Warhammer Skulls 2026 announcements — and nearly every reveal and news update has me giddy with joy as a Warhammer fan]]></title>
<description><![CDATA[Warhammer Skulls 2026 has just concluded, and it has brought forth a tidal wave of major news announcements for several upcoming Warhammer videogames, as well as revealing brand new ones.]]></description>
<link>https://tsecurity.de/de/3537687/windows-tipps/here-are-all-the-major-warhammer-skulls-2026-announcements-and-nearly-every-reveal-and-news-update-has-me-giddy-with-joy-as-a-warhammer-fan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537687/windows-tipps/here-are-all-the-major-warhammer-skulls-2026-announcements-and-nearly-every-reveal-and-news-update-has-me-giddy-with-joy-as-a-warhammer-fan/</guid>
<pubDate>Thu, 21 May 2026 22:09:31 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Warhammer Skulls 2026 has just concluded, and it has brought forth a tidal wave of major news announcements for several upcoming Warhammer videogames, as well as revealing brand new ones.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3536740/unix-server/security-mehrere-probleme-in-rsync-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536740/unix-server/security-mehrere-probleme-in-rsync-slackware/</guid>
<pubDate>Thu, 21 May 2026 16:35:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in bind (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3536739/unix-server/security-mehrere-probleme-in-bind-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536739/unix-server/security-mehrere-probleme-in-bind-slackware/</guid>
<pubDate>Thu, 21 May 2026 16:35:31 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, kernel-rt, and libsndfile), Debian (bind9, evince, firefox-esr, openjpeg2, pdns, and rsync), Fedora (erlang-cowlib, evince, expat, firefox, kernel, mingw-expat, mysql8.0, mysql8.4, nss, opencryptoki, pgadmin4, proftpd, python-django5, python...]]></description>
<link>https://tsecurity.de/de/3536508/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536508/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 21 May 2026 15:25:51 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, kernel-rt, and libsndfile), <b>Debian</b> (bind9, evince, firefox-esr, openjpeg2, pdns, and rsync), <b>Fedora</b> (erlang-cowlib, evince, expat, firefox, kernel, mingw-expat, mysql8.0, mysql8.4, nss, opencryptoki, pgadmin4, proftpd, python-django5, python-django6, python-dotenv, rsync, rust-nu, rustup, and strongswan), <b>Oracle</b> (nginx, nginx:1.24, ruby, ruby:3.3, and squid), <b>Slackware</b> (bind and rsync), <b>SUSE</b> (buildah, distribution, distribution-registry, docker, firefox-esr, helm, libpainter0, libsdb2_4_2, postgresql-jdbc, runc, and vim), and <b>Ubuntu</b> (gnutls28, gst-plugins-good1.0, jq, linux-nvidia, linux-nvidia-lowlatency, openvpn, rsync, and unbound).]]></content:encoded>
</item>
<item>
<title><![CDATA[Android 17 Adds ‘Continue On’ To Move Tasks Across Devices]]></title>
<description><![CDATA[The team at Google just announced a handy new feature for Android 17 called Continue On. It basically lets you start a task on one screen and easily pick it up on another. If you have ever used a similar Handoff feature from Apple on an iPhone, a Mac, or an iPad, this concept will sound very fami...]]></description>
<link>https://tsecurity.de/de/3536116/ios-mac-os/android-17-adds-continue-on-to-move-tasks-across-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536116/ios-mac-os/android-17-adds-continue-on-to-move-tasks-across-devices/</guid>
<pubDate>Thu, 21 May 2026 13:23:44 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The team at Google just announced a handy new feature for Android 17 called Continue On. It basically lets you start a task on one screen and easily pick it up on another. If you have ever used a similar Handoff feature from Apple on an iPhone, a Mac, or an iPad, this concept will sound very familiar. Now, the search giant is bringing that same level of convenience to its own device lineup, letting you switch screens without losing your place.



Swapping active tasks between your devices happens through a taskbar tap



When the new operating system update launches, you will see a fresh option that connects your mobile and tablet screens. The way it works is straightforward. If you are typing a document on your phone and then unlock your tablet, a small suggestion pops up in the tablet taskbar. You just tap that icon, and the same document opens right where you left off.



At first, this feature will only support moving from a phone to a tablet. It works in both directions, so you can send tasks back and forth as long as both gadgets support the feature. Google has confirmed there is no primary device hierarchy, meaning any capable device can send or receive a task.



Developers have a few options for how this handoff behaves. The main setup opens the native app on the second device. If you do not have the app installed on the receiving end, the system uses a smart fallback. It will just open a web browser tab to the right page instead. There is also a direct web to app flow for apps that prefer to handle links directly.



This helpful tool gives people a practical reason to own multiple screens from the same ecosystem. We will learn more about which apps fully support this feature as the final release gets closer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), Debian (gnutls28 and linux-6.1), Fedora (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-...]]></description>
<link>https://tsecurity.de/de/3533100/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533100/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 20 May 2026 15:11:25 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), <b>Debian</b> (gnutls28 and linux-6.1), <b>Fedora</b> (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-rpki, rust-sevctl, and rust-tealdeer), <b>Mageia</b> (bind), <b>Oracle</b> (bind, giflib, gimp:2.8, kernel, libpng, rsync, ruby, and vim), <b>Slackware</b> (haveged and mozilla), <b>SUSE</b> (cockpit, dnsmasq, erlang26, freeipmi, git-bug, glibc, GraphicsMagick, haveged, ImageMagick, iproute2, kernel, openssh, perl-CryptX, perl-HTTP-Tiny, postgresql14, postgresql15, postgresql16, python-Pillow, rsync, tiff, and traefik), and <b>Ubuntu</b> (Highlight.js, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm,
 linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm,
 linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle,
 linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-bluefield, linux-fips, linux-gcp,
 linux-gcp-5.4, linux-gcp-fips, linux-ibm, linux-ibm-5.4, linux-kvm,
 linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-fips, linux-fips, linux-gcp-4.15,
 linux-gcp-fips, linux-kvm, linux-oracle, linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-gke,
 linux-gkeop, linux-ibm, linux-ibm-6.8, linux-lowlatency,
 linux-lowlatency-hwe-6.8, linux-raspi, linux-raspi-realtime,
 linux-realtime, linux-realtime-6.8, linux, linux-aws, linux-hwe-6.17, linux-oem-6.17, linux-oracle,
 linux-raspi, linux-realtime, linux-realtime-6.17, and smarty3).]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Android Circle to Search superpowers you probably never noticed]]></title>
<description><![CDATA[With Google’s annual I/O gala in full force this week, Gemini and AI are taking center stage and being presented as the future of practically everything.



Here in the land of Android, though, Gemini’s been quietly competing for attention with another relatively youthful on-demand assistant — an...]]></description>
<link>https://tsecurity.de/de/3532712/it-nachrichten/10-android-circle-to-search-superpowers-you-probably-never-noticed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532712/it-nachrichten/10-android-circle-to-search-superpowers-you-probably-never-noticed/</guid>
<pubDate>Wed, 20 May 2026 13:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With Google’s annual I/O gala in full force this week, Gemini and AI are <a href="https://blog.google/innovation-and-ai/sundar-pichai-io-2026/" target="_blank" rel="noreferrer noopener">taking center stage</a> and being presented as <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/" target="_blank" rel="noreferrer noopener">the future of practically everything</a>.</p>



<p>Here in the land of Android, though, Gemini’s been quietly competing for attention with <em>another</em> relatively youthful on-demand assistant — and that’s a far <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">less in-your-face feature</a> called <a href="https://www.computerworld.com/article/1611879/androids-circle-to-search-is-deja-vu-all-over-again.html">Circle to Search</a>.</p>



<p>Circle to Search is essentially an instant portal to the even <em>less</em> widely known <a href="https://www.computerworld.com/article/1635589/google-lens-android.html">Android Google Lens setup</a>, which has been serving up <a href="https://www.computerworld.com/article/1635589/google-lens-android.html">genuinely practical real-world advantages</a> for Android device-owners in the know for <em>years</em> now — since way back before the word “Gemini” had <em>any </em>Googley meaning.</p>



<p>And whether you also adore Gemini or find it to be <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">more hype than help</a>, it’s well worth your while to dig into Circle to Search — or maybe just revisit its potential, if you’d perhaps explored it briefly early on and then forgotten about it — to see what it can do for you.</p>



<p>Here, specifically, are 10 simple but supremely useful ways Circle to Search can make your day-to-day life easier without allowing any Gemini AI avalanches to overtake you.</p>



<p><strong>[Psst: Want even more practical Android knowledge? </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>Check out my free Android Intelligence newsletter</strong></a><strong> for three new things to try every Friday and my Android Notification Power-Pack today!]</strong></p>



<h2 class="wp-block-heading"><strong>Circle to Search 101</strong></h2>



<p>Real quick, first, a fast primer on where Circle to Search lives and how <em>you</em> can access it:</p>



<p>At this point, Circle to Search is available on a bunch of Android devices beyond just the latest high-end flagships. But it isn’t available everywhere. And there’s no clear, up-to-date list of exactly which devices have it and which still don’t.</p>



<p>To see if it’s present on <em>your </em>current phone, try going into your system settings and searching for the word <strong>circle</strong>. If you see “Circle to Search” show up as an option, tap it and then make sure the toggle next to the “Circle to Search” line is in in the on and active position.</p>



<p>Then, to summon Circle to Search, press and hold the bottom-center area of your screen — either the thin navigation bar line, if you’re using the current <a href="https://www.computerworld.com/article/1658581/android-gestures.html">Android navigation gestures</a>, or the Home button, if you’re still stickin’ with the old legacy three-button nav approach — and you should see an overlay appear on top of whatever else you were viewing with a Google logo at its top and a search bar at its bottom.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-overlay.jpg?quality=50&amp;strip=all&amp;w=1001" alt="Google Android Circle to Search" class="wp-image-4173382" width="1001" height="1024" sizes="auto, (max-width: 1001px) 100vw, 1001px"><figcaption class="wp-element-caption">Google’s Circle to Search in action, atop a regular ol’ Android browser window.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>From there, you can use your favorite fingie to circle any image, text, or broad area on your screen to highlight it. You can also <em>tap </em>any area to select it (and then have the opportunity to refine your selection) or <em>scribble </em>over any area to mark it, too.</p>



<p>And whatever you select will become the subject of a search for additional info.</p>



<p>If you <em>don’t</em> seem to have Circle to Search available on your device, <a href="https://play.google.com/store/apps/details?id=com.google.ar.lens&amp;hl=en_US" target="_blank" rel="noreferrer noopener">download the Google Lens Android app</a> — then try <a href="https://theintelligence.com/27912/android-save-screenshot/" target="_blank" rel="noreferrer noopener">taking a screenshot</a> of anything in front of you and sharing it directly into the Lens app. It won’t feel quite as interactive or instantaneous as what you’d get with Circle to Search present, but you’ll be able to accomplish most of the same feats we’re about to go over in that environment, with just a couple of extra steps needed to get there.</p>



<p>Capisce? Capisce. Now, let’s get to the good stuff.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #1: Instant searching</strong></h2>



<p>As I often say, it’s the simplest stuff that frequently proves to be the most useful. For all the complex feats Gemini may be able to perform (at least in theory), the action I actually find myself relying on more than anything is the refreshingly routine ability of Circle to Search to look up any word or phrase on my screen, anytime, and give me more information about it — without interrupting anything I’m doing or forcing me to switch apps.</p>



<p>That might mean coughing up a quick definition, at the simplest possible level. Or it might mean dousing me with details about a person, place, or product I’ve seen within an email, a web page, a document, you name it.</p>



<p>Whatever the case may be, all I’ve gotta do is summon Circle to Search from wherever I happen to be on my device at that moment, tap my finger onto the term in question, and boom: I’ve got the info I need right in front of me — no complicated commands, frustrating back-and-forth dialogue, or effort-wasting app switching required.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-text-search.jpg?quality=50&amp;strip=all&amp;w=1014" alt="Android Circle to Search: Text search" class="wp-image-4173380" width="1014" height="1024" sizes="auto, (max-width: 1014px) 100vw, 1014px"><figcaption class="wp-element-caption">Circle to Search makes it seamless to search for anything, anytime — even lowly tech writers.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Easy peasy, no? And there’s lots more where that came from.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #2: Fast text actions</strong></h2>



<p>In addition to surfacing basic info, Circle to Search can help you take a variety of <em>actions </em>on text you highlight with just one more tap and no awkward multistep pasting or other clunky mechanics.</p>



<p>The next time you see a phone number you want to call, text, or save to your contacts; an email address you want to save or send a message to; a <em>physical</em> address you want to look up or navigate to; or a URL you want to open when it isn’t set to be a tappable link on its own, call up Circle to Search and tap the text in question.</p>



<p><br>So long as the item is the only text selected, Circle to Search should recognize its format and offer up the logical associated action for you to caress next.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-text-actions.webp" alt="Android Circle to Search: Text actions" class="wp-image-4173379" width="800" height="845" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Take actions on text in a snap by summoning Circle to Search first.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #3: Quick copy</strong></h2>



<p>Back to the idea of simplicity, one of the ways I find Circle to Search to be most useful is in its ability to let me copy text from anything, anytime — even when it isn’t text you could typically copy.</p>



<p>From phrases in my Android settings to words appearing within images, Circle to Search converts everything it sees into standard copy-ready dialog, and it takes just one tap on anything to highlight it in that environment and then beam it to your <a href="https://www.computerworld.com/article/1616932/android-clipboard-tricks.html">Android system clipboard</a> from there.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-text-select.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android Circle to Search: Text copy" class="wp-image-4173377" width="1024" height="530" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You can copy <em>anything </em>with Circle to Search active — even if it’s in area where copying normally isn’t possible.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And, of course, with <a href="https://www.computerworld.com/article/4161538/sync-android-computer-clipboards.html">the right sort of setup</a> — like a recently released <a href="https://theintelligence.com/43092/share-android-computer/" target="_blank" rel="noreferrer noopener">third-party service that works wonders in this area</a> — it takes shockingly little effort to send something from there onward toward your <em>computer’s</em> clipboard for desktop-level use as well.</p>



<p>I can’t tell you how often this comes in handy.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #4: Image identifying</strong></h2>



<p>Text aside, Circle to Search integrates the <a href="https://www.computerworld.com/article/1635589/google-lens-android.html#:~:text=Google%20Lens%20trick%20%238%3A%20Search%20for%20similar%20visuals">long-Lens-offered ability</a> to identify any image in front of ye and then allow you to interact with it in all sorts of interesting ways.</p>



<p>This can range from telling you the name of a person, place, or product to giving you specific identifying info for a plant, flower, tree, animal, or even type of screw or computer component.</p>



<p>Just tap or circle any image on your screen — whether it’s in a web page, an email, a document, or anywhere else imaginable — and you’ll see the results right away.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-image-identify.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Android Circle to Search: Image search" class="wp-image-4173381" width="1024" height="990" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">You’ll be a full-fledged image-analyzing gumshoe with Circle to Search at your side.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>And from there…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #5: Deeper context</strong></h2>



<p>Once you’ve gotten an initial result from Circle to Search — with an image, with text, or with most anything you’ve highlighted and selected — you can tap the microphone icon at the bottom of the Circle to Search popup and ask <em>additional </em>questions.</p>



<p>Depending on what you’re seeing and what you want to know, the possibilities are practically endless:</p>



<ul class="wp-block-list">
<li>Can you use this word in a sentence?</li>



<li>Where can I find this?</li>



<li>How much does this cost?</li>
</ul>



<p>You get the idea. And while we’re thinking about products…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #6: Intelligent comparisons</strong></h2>



<p>The next time you see something that strikes your interest anywhere in your Android adventures — be it a new phone within an image somewhere, some software or service mentioned in an email, or whatever else the case may — fire up Circle to Search, select the thing you’re ogling, and then use the Circle to Search search prompt or microphone icon to ask for comparisons:</p>



<ul class="wp-block-list">
<li>How does this phone compare to the Pixel 9?</li>



<li>Does this cost more or less than a MacBook Pro?</li>



<li>Is this app basically like Notion?</li>
</ul>



<p>Once you’ve selected something, all you’ve gotta do is ask.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #7: Split smarts</strong></h2>



<p>Speaking of comparisons, here’s a really cool Circle to Search trick few mere mortals realize is possible:</p>



<p>You can <a href="https://www.computerworld.com/article/3810786/android-split-screen-tricks.html">start up a split-screen</a> of any two apps together, side by side, then activate Circle to Search and use it to analyze things <em>across the two processes</em>.</p>



<p>Let’s all summon our strongest inner Keanus and say it together now: <em>Whoaaaa…..</em></p>



<p>And — oh, yes — there’s more yet.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #8: Your translation station</strong></h2>



<p>When the need to translate <em>anything </em>between languages arises, skip your usual multistep process and just summon Circle to Search instead. Tap the translate icon — the “A” inside a circle, at the right end of the bottom-of-screen search bar — and you can then select any two languages and have <em>everything</em> on your screen translated on the fly.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-translate.webp" alt="Android Circle to Search: Translate" class="wp-image-4173378" width="800" height="839" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">Instant translations, Circle-to-Search-style — <em>pas mal</em>, eh?!</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>If you tap the icon that appears next to the “A” — the one showing a hand alongside an upward-pointing arrow — you can keep the instant translation mode active as you scroll around and even move between apps.</p>



<p>That, suffice it to say, is <em>insanely </em>powerful.</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #9: Zoom without borders</strong></h2>



<p>Back to simplicity again, one surprising way Circle to Search can be helpful is by unlocking the ability to zoom into anything, anytime — even when it’s part of an area that you can’t ordinarily enlarge.</p>



<p>Press and hold that bottom-center area of your device’s display, then just pinch two fingers apart or together. You’ll be able to zoom in, no matter where you are or what you’re viewing.</p>



<p>And finally…</p>



<h2 class="wp-block-heading"><strong>Circle to Search superpower #10: Song Search, Circle-style</strong></h2>



<p>All right, so this last Circle to Search superpower isn’t <em>exactly</em> productivity-related. But it <em>is </em>useful, in the right sort of scenario. (And sometimes, you need to satisfy a non-work-related itch before you can get back to Getting Stuff Done™!)</p>



<p>When you’re hearing a song and scratching your head as to what it’s called or who sings it, Circle to Search can actually activate <a href="https://theintelligence.com/40094/song-search-android/" target="_blank" rel="noreferrer noopener">Android’s excellent Song Search system</a> and show you that answer.</p>



<p>Just activate Circle to Search, no matter what else you’re doing, and tap the music note icon in that search bar at the bottom of the screen. (For fair warning, the correct answer is always <a href="https://www.youtube.com/menatwork" target="_blank" rel="noreferrer noopener">Men at Work</a>.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/android-circle-to-search-song-search.gif" alt="Android Circle to Search: Song Search" class="wp-image-4173383" width="800" height="843" sizes="auto, (max-width: 800px) 100vw, 800px"><figcaption class="wp-element-caption">No more song mysteries, thanks to Circle to Search’s convenient Song Search shortcut.</figcaption></figure><p class="imageCredit">JR Raphael, Foundry</p></div>



<p>Good to know, no? And, just like everything else on this page, all this sorcery is never more than a tap away — without the need for any manner of Gemini-scented AI chicanery.</p>



<p>All <em>you’ve</em> gotta do is remember.</p>



<p><em>Remember to </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>sign up for my free Android Intelligence newsletter</em></strong></a><em>, if you haven’t already, to get three new things to try in your inbox every Friday.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in mozilla-firefox (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3531535/it-security-nachrichten/mehrere-probleme-in-mozilla-firefox-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531535/it-security-nachrichten/mehrere-probleme-in-mozilla-firefox-slackware/</guid>
<pubDate>Wed, 20 May 2026 06:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3531529/it-security-nachrichten/mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531529/it-security-nachrichten/mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Wed, 20 May 2026 06:37:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Ausführen von Code mit höheren Privilegien in haveged (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3531485/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-haveged-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531485/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-haveged-slackware/</guid>
<pubDate>Wed, 20 May 2026 06:30:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Google just redesigned the search box for the first time in 25 years — here’s why it matters more than you think.]]></title>
<description><![CDATA[For a quarter century, the Google search box has been one of the most recognizable interfaces in computing: a thin white rectangle, a blinking cursor, a few typed words, and a list of blue links. On Tuesday, Google will formally retire that paradigm.At its annual I/O developer conference, Google ...]]></description>
<link>https://tsecurity.de/de/3530355/it-nachrichten/google-just-redesigned-the-search-box-for-the-first-time-in-25-years-heres-why-it-matters-more-than-you-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530355/it-nachrichten/google-just-redesigned-the-search-box-for-the-first-time-in-25-years-heres-why-it-matters-more-than-you-think/</guid>
<pubDate>Tue, 19 May 2026 20:04:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For a quarter century, the Google search box has been one of the most recognizable interfaces in computing: a thin white rectangle, a blinking cursor, a few typed words, and a list of blue links. On Tuesday, Google will formally retire that paradigm.</p><p>At its annual <a href="https://io.google/2026/">I/O developer conference</a>, Google announced a <a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">sweeping redesign</a> of the search box itself — the literal text field where billions of queries begin every day — transforming it from a simple keyword input into a dynamic, AI-driven conversation starter that can accept text, images, PDFs, videos, and even open Chrome tabs as inputs. The company is also merging its <a href="https://search.google/ways-to-search/ai-overviews/">AI Overviews</a> and <a href="https://search.google/ways-to-search/ai-mode/">AI Mode</a> features into a single, seamless search flow, eliminating the friction that previously forced users to choose between a traditional results page and an AI-forward experience.</p><p>Liz Reid, Google's vice president and head of Search, called it "the biggest upgrade to our iconic search box since its debut over 25 years ago" during a press briefing on Monday.</p><p>The announcement arrived alongside a blizzard of other news — new <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini models</a>, a personal <a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">AI agent called Spark</a>, an intelligent <a href="https://blog.google/products-and-platforms/products/shopping/google-shopping-cart/">shopping cart</a>, a <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">reimagined developer platform</a> — but the search box redesign may prove to be the most consequential. It is the clearest signal yet that Google views the future of its flagship product not as a place where users type fragmented keywords, but as an interface where they hold open-ended, multimodal conversations with an AI system backed by the entire web.</p><h2><b>The new search box expands, accepts files, and coaches you on what to ask</b></h2><p>The changes show a fundamental shift in how Google expects people to interact with the product that generates the vast majority of Alphabet's revenue.</p><p>The box itself now dynamically expands to accommodate longer, more conversational queries. Where the old interface subtly encouraged brevity — a narrow field suited to two- or three-word keyword strings — the new design invites users to fully articulate complex questions in granular detail. It also now supports multimodal inputs directly. Users can upload images, PDFs, files, and videos, or drag in content from Chrome tabs, right from the main search interface. Previously, some of these capabilities existed in AI Mode, but reaching them required extra steps. Now they sit at the primary entry point.</p><p>Google is also deploying what it describes as an AI-powered query suggestion system that "goes beyond autocomplete." Rather than simply predicting the next word a user might type based on popular searches, the system helps users formulate complex, nuanced queries — essentially coaching them toward the kind of detailed questions that AI Mode handles best.</p><p>The new search box is starting to roll out immediately in all countries and languages where AI Mode is available.</p><h2><b>Google is merging AI overviews and AI mode into one seamless experience</b></h2><p>Perhaps more significant than the box itself is the architectural change happening behind it. Google is unifying <a href="https://search.google/ways-to-search/ai-overviews/">AI Overviews</a> — the AI-generated summary panels that appear atop traditional search results — with <a href="https://search.google/ways-to-search/ai-mode/">AI Mode</a>, the more immersive conversational search experience the company launched at I/O one year ago.</p><p>Starting Tuesday, this merged experience will be live across mobile and desktop worldwide. A user can type a question, receive an AI Overview alongside traditional results, and then continue directly into a back-and-forth AI Mode conversation to ask follow-up questions — all without navigating to a separate interface.</p><p>Reid explained the logic during the press briefing: the new AI search box is "an upgrade of our traditional search box, and so the results take you directly to main search rather than AI mode." She noted that while some power users actively sought out AI Mode, "for most users, they don't actually want to have to think about, do they want more of a traditional page or an AI-forward search experience."</p><p>The goal, she said, was to ensure that "for most users, they don't have to think about where to go, they can just go to the search box they're familiar with, and it feels like they get the best experience afterwards."</p><h2><b>One billion users and doubling queries reveal how fast search behavior is shifting</b></h2><p>Google's decision to redesign the foundational interface of its most important product did not happen in a vacuum. The company shared a set of usage statistics during the briefing that reveal just how rapidly user behavior is already changing.</p><p><a href="https://search.google/ways-to-search/ai-mode/">AI Mode</a>, which launched in the United States at I/O 2025, has surpassed one billion monthly users in its first year. AI Mode queries have been doubling every quarter since launch. AI Overviews, the lighter-weight AI summaries, now reach more than 2.5 billion monthly users. And overall <a href="https://www.theverge.com/tech/920815/google-alphabet-q1-2026-earnings-sundar-pichai">search query volume hit an all-time high</a> last quarter — a data point the company had previously disclosed on its earnings call.</p><p>Sundar Pichai, Google's CEO, framed these figures as evidence that AI features are additive, not cannibalistic, to search usage. "When people use our AI-powered features in search, they use search more," he said. He added that he loves "how search has become less about individual queries and feels more like an ongoing conversation, giving users deeper insights and connecting you with the vastness of the web."</p><p>Reid reinforced the point: "It's not just that people are searching more, it's that they're searching differently. They're fully expressing their questions in granular detail, asking those follow-up questions and searching across modalities."</p><h2><b>Gemini 3.5 Flash gives Google's AI search the speed it needs to work at scale</b></h2><p>Under the hood, the new search experience runs on <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini 3.5 Flash</a>, Google's newest AI model, which the company also introduced at I/O. Google upgraded AI Mode's underlying model to 3.5 Flash to deliver what Reid described as "an even more powerful AI search experience."</p><p><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini 3.5 Flash</a> is the workhorse of this year's announcements. Google claims it outperforms its previous frontier model, <a href="https://deepmind.google/models/gemini/pro/">Gemini 3.1 Pro</a>, on nearly all benchmarks while running four times faster in output tokens per second than comparable frontier models. Pichai described it as being "in a league of its own in the top right quadrant" of the <a href="https://artificialanalysis.ai/">Artificial Analysis index</a>, which plots intelligence against speed — meaning it delivers near-frontier quality at dramatically lower latency.</p><p>That speed matters enormously for search. A conversational AI search experience that feels sluggish would be dead on arrival for a product that serves billions of queries daily. By coupling the redesigned interface with a model optimized for both quality and throughput, Google is attempting to make AI-powered search feel as instantaneous as the old keyword experience — while being dramatically more capable.</p><h2><b>Search can now build interactive visuals and custom mini apps on the fly</b></h2><p>The redesigned search box is also the gateway to a set of new capabilities that push search far beyond text-based answers. Google announced what it calls "<a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">generative UI</a>" — the ability for search to dynamically build custom widgets, interactive visualizations, and even mini applications in real time, tailored to a user's specific question.</p><p>Reid offered a concrete example during the briefing: a user could ask "How do black holes affect space time?" and receive an interactive visual in an AI Overview that brings the concept to life. Follow-up questions would trigger the system to dynamically generate entirely new visuals in real time. This is possible, she explained, because of "a novel real-time code generation system we built in partnership with the Google DeepMind team" that runs on Gemini 3.5 Flash. Generative UI capabilities will roll out to everyone this summer, free of charge.</p><p>But Google is going further still. For ongoing tasks — planning a wedding, organizing a move, tracking a fitness routine — users will be able to build what the company describes as customizable, stateful experiences within search, powered by its <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity development platform</a>. These require no coding expertise. Users simply describe what they want in natural language, and search builds it. Those experiences will be available in coming months, starting with <a href="https://gemini.google/subscriptions/">Google AI Pro</a> and <a href="https://gemini.google/subscriptions/">Ultra</a> subscribers in the United States.</p><h2><b>AI agents that monitor the web around the clock are coming to search results</b></h2><p>The redesign also opens the door to what Google calls "<a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">information agents</a>" — AI agents that users can configure directly within search to monitor the web 24/7 for specific conditions and deliver synthesized updates when those conditions are met.</p><p>A user could, for example, set up an agent to track market movements in a particular sector with specific parameters. The agent would create a monitoring plan, tap into real-time finance data, and proactively notify the user when conditions are met — complete with links and context for further research. Other use cases include apartment hunting, tracking sneaker drops, or monitoring any topic a user cares about. Information agents will launch first for <a href="https://gemini.google/subscriptions/">Google AI Pro</a> and <a href="https://gemini.google/subscriptions/">Ultra</a> subscribers this summer.</p><p>These agents sit within a much larger strategic pivot that Google articulated throughout the briefing: the company is going all-in on AI systems that don't just answer questions but proactively take actions on users' behalf. Beyond search, Google introduced <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini Spark</a>, a 24/7 personal AI agent that runs on dedicated virtual machines in Google Cloud. It unveiled the <a href="https://blog.google/products-and-platforms/products/shopping/google-shopping-cart">Universal Cart</a>, an intelligent cross-merchant shopping cart. It announced the <a href="https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol">Agent Payments Protocol</a> for agents to make secure purchases. And it expanded its <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity developer platform</a> into a full ecosystem for building autonomous AI agents.</p><h2><b>Publishers, advertisers, and SEO professionals face a new reality</b></h2><p>The redesign raises profound questions for the sprawling ecosystem — publishers, advertisers, SEO professionals — that has been built around the old model of keyword search and blue links.</p><p>If users increasingly express their needs as full, conversational sentences rather than fragmented keywords, the entire discipline of search engine optimization will need to evolve. Keyword-density strategies become less relevant when the AI is parsing natural language intent rather than matching strings. Content that answers deep, nuanced questions in authoritative ways becomes more valuable; content engineered to rank for two-word keyword fragments becomes less so.</p><p>For publishers, <a href="https://www.npr.org/2025/07/31/nx-s1-5484118/google-ai-overview-online-publishers">the stakes are existential</a>. AI Overviews already synthesize information from across the web and present it directly in search results, reducing the need for users to click through to source material. The new seamless AI Mode integration deepens that dynamic: users can now get an AI-generated answer and ask multiple follow-up questions without ever leaving the search page. Google has consistently maintained that its AI features drive more traffic to publishers, but the redesign puts that claim under renewed scrutiny as the search results page becomes more self-contained.</p><p>For advertisers — who fund the vast majority of Google's revenue — the shift from keywords to conversations changes the calculus of ad targeting. Conversational queries contain richer intent signals, which could make ad targeting more precise and valuable. But they also create new ambiguities: when a user is in the middle of a multi-turn conversation with AI Mode, where does an ad naturally fit? Google did not detail changes to its advertising model during the briefing, but the structural shift in the interface will inevitably reshape how ads are surfaced and measured.</p><h2><b>The search box was always more than a product — it was a habit for billions of people</b></h2><p>There is a reason Google chose to redesign the search box rather than simply adding new features behind it. The search box is not just a product element at this point; it is a cultural artifact — one of the few pieces of digital infrastructure used by essentially the entire internet-connected world. Changing it sends an unmistakable message about where the company believes computing is headed.</p><p>For 25 years, the search box trained billions of people to think in keywords — to compress their curiosity into the shortest possible string of words. The new box invites them to do the opposite: to think out loud, to upload what they're looking at, to ask follow-up questions, to let an AI system handle the compression.</p><p>Pichai tied the company's broader ambitions to a striking statistic: Google's surfaces now process over 3.2 quadrillion tokens per month, up seven-fold from a year ago. The company expects capital expenditures of approximately $180 to $190 billion in 2026 — roughly six times the $31 billion it spent four years ago — largely to support the infrastructure required for this AI transformation. When asked about the future of traditional search, he was direct. "Search is the most used AI product in the world," he said.</p><p>The blinking cursor in Google's search box still invites you to type. But after 25 years of teaching the world to speak in keywords, Google is now asking it to speak in sentences — and betting roughly $190 billion that it will.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, gimp:2.8, jq, kernel, and rsync), Debian (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), Fedora (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, ngi...]]></description>
<link>https://tsecurity.de/de/3526095/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526095/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 18 May 2026 15:26:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, gimp:2.8, jq, kernel, and rsync), <b>Debian</b> (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), <b>Fedora</b> (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, open-amp, perl-Net-CIDR-Lite, pgbouncer, pypy, python-jupytext, python-uv-build, rsync, rust-astral-tokio-tar, uriparser, uv, valkey, and yelp), <b>Mageia</b> (dpkg, firefox, thunderbird, golang, haproxy, and samba), <b>Slackware</b> (dnsmasq and kernel), and <b>SUSE</b> (apache-commons-configuration2, apache2, apptainer, chromedriver, cups-filters, curl, dnsmasq, expat, ffmpeg-4, ffmpeg-7, firebird, firewalld, flux2-cli, glibc, go1.25, go1.26, gosec, grub2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, java-25-openj9, kdenlive, kernel, kernel-devel, keylime-config, krb5, libIex-3_4-33, mozjs115, mozjs78, nginx, openssh, openvswitch, ovmf, PackageKit, perl-Crypt-URandom, perl-CryptX, perl-libwww-perl, perl-Net-CIDR-Lite, perl-Text-CSV_XS, podman, postgresql17, postgresql18, python-pyOpenSSL, python310, rsync, sed, tekton-cli, valkey, xen, and zypper-docker).]]></content:encoded>
</item>
<item>
<title><![CDATA[Beat productivity tasks in no time with this Intel Core processor with "Chart-topping application performance" that's now on sale for Memorial Day]]></title>
<description><![CDATA[Amazon's Memorial Day sale has begun, and it's brought forth a 22% discount for the Intel Core Ultra 7 Processor 270K Plus CPU for a limited time.]]></description>
<link>https://tsecurity.de/de/3523779/windows-tipps/beat-productivity-tasks-in-no-time-with-this-intel-core-processor-with-chart-topping-application-performance-thats-now-on-sale-for-memorial-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3523779/windows-tipps/beat-productivity-tasks-in-no-time-with-this-intel-core-processor-with-chart-topping-application-performance-thats-now-on-sale-for-memorial-day/</guid>
<pubDate>Sun, 17 May 2026 15:27:15 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon's Memorial Day sale has begun, and it's brought forth a 22% discount for the Intel Core Ultra 7 Processor 270K Plus CPU for a limited time.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen von Code mit höheren Privilegien in kernel (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3521667/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-kernel-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521667/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-kernel-slackware/</guid>
<pubDate>Sat, 16 May 2026 10:01:01 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in dnsmasq (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3521666/unix-server/security-mehrere-probleme-in-dnsmasq-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521666/unix-server/security-mehrere-probleme-in-dnsmasq-slackware/</guid>
<pubDate>Sat, 16 May 2026 10:01:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[You've Been Vacuuming Wrong Your Entire Life. Here's the Right Way to Do It]]></title>
<description><![CDATA[A systematic vacuuming pattern picks up far more dirt than the random back-and-forth approach most people default to.]]></description>
<link>https://tsecurity.de/de/3520184/it-nachrichten/youve-been-vacuuming-wrong-your-entire-life-heres-the-right-way-to-do-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520184/it-nachrichten/youve-been-vacuuming-wrong-your-entire-life-heres-the-right-way-to-do-it/</guid>
<pubDate>Fri, 15 May 2026 17:18:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A systematic vacuuming pattern picks up far more dirt than the random back-and-forth approach most people default to.]]></content:encoded>
</item>
<item>
<title><![CDATA[Building an AI CoE: Why you need one and how to make it work]]></title>
<description><![CDATA[Artificial intelligence (AI) is no longer the playground of hobbyists and programmers. From automating customer‑service transactions to optimizing supply‑chain decisions, AI is rapidly becoming the central nervous system of today’s enterprises. McKinsey surveys have found that nearly nine in ten ...]]></description>
<link>https://tsecurity.de/de/3516461/it-security-nachrichten/building-an-ai-coe-why-you-need-one-and-how-to-make-it-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516461/it-security-nachrichten/building-an-ai-coe-why-you-need-one-and-how-to-make-it-work/</guid>
<pubDate>Thu, 14 May 2026 13:05:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence (AI) is no longer the playground of hobbyists and programmers. From automating customer‑service transactions to optimizing supply‑chain decisions, AI is rapidly becoming the central nervous system of today’s enterprises. <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="nofollow">McKinsey</a> surveys have found that nearly nine in ten organizations are now using AI regularly in at least one business function, compared with 78% the previous year.</p>



<p>But adoption rates are far lower when it comes to scaling AI programs throughout the enterprise. Only about one‑third of companies have advanced past the pilot stage. Two‑thirds of organizations use AI technologies in multiple functions and 64% believe AI has had a positive impact on innovation. Just 39% say they’ve seen a significant impact on the bottom line.</p>



<p>This research shows that AI has gone mainstream, but its benefits are still concentrated in the hands of a relative few. This reality makes even more compelling the case for establishing a formal center of excellence (CoE).</p>



<p>Per <a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/scenarios/ai/center-of-excellence" rel="nofollow">Microsoft’s</a> cloud‑adoption framework, a CoE is a centralized team responsible for standardizing best practices across the organization. An AI CoE functions as an internal team of experts that helps business units realize valuable and successful AI outcomes while avoiding pockets of AI solutions built without governance or standards. A well‑managed AI CoE builds consensus for standards and pilots and provides business and technical guidance to help convert AI excitement into measurable business value.</p>



<p>An artificial intelligence Center of Excellence is a strategic capability, not an ivory tower nor a vanity project for the few AI early adopters. An AI CoE can dramatically improve the quality and safety of your organization’s AI adoption efforts. In this article, we will discuss why every organization needs an AI hub like a CoE. We’ll explore how to staff and structure your center and provide recommendations to help it adapt over time.</p>



<h2 class="wp-block-heading">Why create an AI CoE?</h2>



<p>An AI CoE “<a href="https://www.trndigital.com/blog/enterprise-ai-coe-a-complete-guide-to-ai-centers-of-excellence/">acts as the central nervous system</a>” for your company’s AI strategy. Without a centralized AI organization:</p>



<ul class="wp-block-list">
<li><strong>Siloed initiatives.</strong> Separate business units kick off AI pilots that aren’t centrally coordinated, leading to duplicated effort and fragmented results.</li>



<li><strong>Inconsistent governance</strong>. Data governance, model security and compliance efforts differ from project to project putting your organization at risk of regulatory infractions or biased models.</li>



<li><strong>Lack of standards</strong>. Groups spend time reinventing the wheel instead of building on reusable assets and shared toolkits.</li>



<li><strong>Difficulty scaling</strong>. Smaller pilots become roadmaps unto themselves because there’s no standardized process for prioritizing and scaling AI solutions.</li>
</ul>



<p>An AI CoE helps solve these issues by setting forth an AI strategy, aligning AI efforts with your business objectives and offering governance, policy and expertise. Additionally, an AI CoE promotes responsible and ethical AI principles through fairness, privacy and transparency policies. According to <a href="https://www.idc.com/resource-center/blog/organizations-seek-competitive-edge-with-ai-centers-of-excellence/">IDC research</a>, CoEs enable cross‑functional collaboration between data scientists, domain experts and chief finance officers to help translate AI prototypes into repeatable solutions that align AI spending with business strategy. IDC analysts also find that effective CoEs can provide talent development, knowledge sharing, partnerships and an innovation mindset.</p>



<p>The business case only strengthens when looking at the economics of generative AI specifically. IDC’s 2024 “<a href="https://blogs.microsoft.com/blog/2024/11/12/idcs-2024-ai-opportunity-study-top-five-ai-trends-to-watch/" rel="nofollow">Business Opportunity of AI</a>” study, sponsored by Microsoft, revealed generative‑AI adoption rose from 55% in 2023 to 75% in 2024. Companies that deployed generative AI were also found to experience significant returns. Organizations see an average ROI of $3.7 realized for every dollar spent on generative AI. For high performers, ROI reached $10.3 for every dollar spent. The majority of companies spend less than eight months deploying generative AI solutions, with ROI seen after just thirteen months. The research highlights how well‑managed AI initiatives can produce exceptional returns and why centralized governance and expertise are critical.</p>



<p>In addition to mitigating risks, a properly established CoE also creates opportunities. According to IDC, successful COEs can provide workforce enablement, knowledge dissemination, strategic alliances, certification and training and a culture that fosters innovation and creativity. Leaders at Hitachi Vantara call their COE “enabling AI to go from theoretical exploration to practical implementation that optimizes processes, supercharges efficiency and unlocks data‑driven insights.”</p>



<p>When it comes to AI in financial services, <a href="https://biztechmagazine.com/article/2025/01/benefits-building-ai-center-excellence-financial-services" rel="nofollow">BizTech Magazine</a> found that while 81% of executives say they are currently using AI and will invest more money in it, only 25% of them have completely deployed monitoring and management tools even though 87% said they already have governance in place. This is a clear example of how businesses are adopting new technologies but lack operational maturity and how a centralized CoE can help bridge that final mile and make governance frameworks a reality.</p>



<p>Business impacts achieved through CoEs are faster AI adoption, more efficient resource utilization, better decision‑making, lower risk, stronger strategic alignment and better collaboration. Boards and investors are demanding it; according to IDC analysts, organizations with mature AI governance have seen increased returns on invested capital (ROIC) and view CoEs as critical source of competitive differentiation.</p>



<h2 class="wp-block-heading">How to build and structure the CoE</h2>



<p>An AI CoE should have an executive sponsor who can offer budget, authority and credibility to ensure standards are upheld. Create a steering committee of business and IT leaders and schedule frequent reviews to monitor progress. Then, identify a leader for your CoE who is devoted to its success and has deep AI skills, as well as reach across the enterprise. Hire a diverse team of business leaders, data scientists, machine‑learning engineers, governance and security professionals. This variety of backgrounds will help ensure AI initiatives meet technical and business needs, as well as regulatory and ethical standards.</p>



<h3 class="wp-block-heading"><a></a>Define the operating model and responsibilities</h3>



<p><a href="https://www.idc.com/resource-center/blog/assembling-all-the-right-stuff-to-staff-and-lead-an-ai-center-of-excellence/">IDC analysts</a> note that an important objective of a CoE should be to close the supply‑and‑demand gap for AI skills. This can be accomplished by creating a centralized team of employees from different business units or geographies who pool their collective knowledge and then disburse back out into the business. Hardy recommends that this cross‑functional team include not only deep technical experts such as data scientists, AI engineers and machine‑learning specialists but also business leaders as well as IT and cybersecurity professionals. These members can help ensure AI initiatives are applied to business problems and integrated into production environments securely. Team members may include data scientists, software engineers, business analysts, subject‑matter experts and project managers. Common skills include domain knowledge, programming and data skills, problem solving, communications and a team mindset. Skills required of the Center of Excellence leader include a strong knowledge of AI, along with a visionary but execution focused approach to work. Additional leadership traits include practicing radical candor with your teams and colleagues while staying agile and flexible in your decisions due to the rapidly changing nature of AI.</p>



<p>Skills gaps are another common challenge to AI scaling. According to Microsoft’s 2024 IDC-commissioned survey, 30 % of respondents stated their organizations don’t have specialized AI skills and another 26 % said their organization has too few employees with the skills necessary to learn and work with AI. By tapping into talent from across the business, the CoE can centralize hard-to-find expertise. It can also administer training initiatives to fill these gaps. The CoE should partner with HR leaders to create learning journeys, certification initiatives and mentorship programs to ensure the talent pool continues to grow with advancing AI technology.</p>



<p>Determine where the CoE sits in your company’s hierarchy. A centralized hub makes sense early in your AI journey to centralize knowledge and ensure consistent practices. But as your organization adopts AI, the CoE can evolve into a decentralized, enablement model that provides guardrails and allows product teams to own their own AI applications. Clearly establish your CoE’s primary functions. These may include:</p>



<ul class="wp-block-list">
<li><strong>AI strategy and use‑case identification</strong>. Partnering with business leaders to identify and prioritize AI opportunities that will provide the most value to the organization.</li>



<li><strong>Skills development</strong>. Determining your current level of AI skills and implementing learning and hands‑on experimentation programs.</li>



<li><strong>Pilot projects</strong>. Leading targeted pilots to prove out AI methodologies and provide proof of business value.</li>



<li><strong>Standards and governance</strong>. Establishing governance frameworks and security standards, monitoring usage to ensure AIs are being used ethically and performing routine data security and compliance audits.</li>



<li><strong>Intake and prioritization</strong>. Establishing a formal process to accept requests and evaluate them based on potential business value, feasibility and resource demands.</li>



<li><strong>Reusable assets</strong>. Creating checklists, templates and code libraries to speed up future initiatives.</li>



<li><strong>Metrics and reporting</strong>. Measuring adoption, compliance and business value and using that information to foster continual improvement.</li>
</ul>



<h3 class="wp-block-heading">Integrate ethics and responsible AI</h3>



<p>AI solutions should be ethical, which means they should be helpful and unbiased. The CoE should develop policies around responsible AI use, so models are transparent, unbiased and reflect company values. Teams should conduct audits of training data and model outputs to identify and reduce bias and the potential for inadvertent harm. AI governance should include privacy and data‑security principles.</p>



<h3 class="wp-block-heading"><a></a>Avoid bureaucratic bottlenecks</h3>



<p>One pitfall of CoEs is that they tend to turn into gatekeepers and slow down innovation. Instead, Microsoft recommends shifting the CoE from being a gatekeeper to playing an advisory role once your AI adoption becomes more established. Build AI delivery into platform teams and allow product teams to execute against AI solutions under guardrails. The CoE can concentrate on things like setting standards, sharing knowledge and mentorship while teams on the frontline own the execution.</p>



<h2 class="wp-block-heading">How to ensure continuous improvement</h2>



<p>AI is still an emerging technology and science, which means that a one‑time standing CoE will become irrelevant almost immediately. It should evolve constantly, leveraging three primary levers:</p>



<ul class="wp-block-list">
<li><strong>Feedback and learning loops</strong>. Establish processes to capture input from users and stakeholders in production and pilot environments. This feedback should be used to update models, training datasets, documentation and governance processes.</li>



<li><strong>Investment in skills and culture</strong>. Embed AI literacy into your culture by providing regular training and building communities of practice. Forums like these allow employees to share failures and best practices. Focus change‑management efforts on employees’ misperceptions about how AI will replace their jobs. Communicate how AI tools will make their jobs easier instead.</li>



<li><strong>Metrics‑driven evolution</strong>. Define a measurement framework that encompasses adoption, compliance and ROI metrics. Use these measurements to surface bottlenecks and opportunities for improvement. If your metrics indicate your central governance is slowing adoption, consider a more federated approach.</li>
</ul>



<p>Researchers from IDC stress that “unlocking the power of frontier AI … requires building a culture of continuous learning.” COEs should implement processes like internal training initiatives, communities of practice and sandbox spaces for experimentation so that knowledge can continue flowing to employees as fast-changing AI capabilities develop. Benchmarking your progress is also key, say the analysts in their suggestions for how to measure COE success with AI. IDC recommends defining clear goals, building KPIs into projects, tracking completed initiatives, gathering feedback on customer satisfaction and looking at indicators for revenue growth and innovation.</p>



<h2 class="wp-block-heading"><a></a>Conclusion: A strategic capability, not a side project</h2>



<p>An AI Center of Excellence won’t solve every challenge. It needs ongoing senior leadership sponsorship, cross‑functional teamwork and an openness to shift your operating model as your organization matures in its AI journey. However, when done right, it provides a framework for enterprise‑level AI enablement. It ensures AI initiatives are aligned to business priorities, sets standards and governance, develops your workforce and speeds up the responsible delivery of AI solutions.</p>



<p><a href="https://azure.microsoft.com/en-us/blog/scale-ai-transformation-with-azure-essentials-ai-center-of-excellence-guidance/" rel="nofollow">AI Centers of Excellence are already helping organizations drive value across industries</a> by scaling AI adoption, strengthening governance, accelerating experimentation and moving AI use cases from ideation to production.</p>



<ul class="wp-block-list">
<li><strong>Financial services. </strong>Major banks are forming federated AI CoEs made up of divisional CoEs within business units like retail banking, wealth management and asset management. These cross‑functional teams customize AI for their functions, whether that’s portfolio optimization or customer support automation, backed by a centralized GenAI layer that provides unified governance, tools and evaluation frameworks. The federated approach limits redundancy, fosters collaboration and scales AI more broadly.</li>



<li><strong>Professional services and technology</strong>. With Microsoft’s guidance, NTT DATA developed an agentic AI CoE. The center offers a centralized environment for customers to design, deploy and operate AI agents spanning different cloud environments. Highlights include unified governance that’s aligned with its cloud center of excellence (CCoE) architecture, shared infrastructure to build agent‑based applications and coordination with Microsoft subject matter experts. The AI CoE serves as an engine for delivery, helping accelerate the path from experimentation to production at scale with security built in.</li>



<li><strong>Consulting firms. </strong>Capgemini applies the principles of an AI CoE to its suite of offerings to ensure consistent AI governance, reuse assets and tools and link AI projects to quantifiable business outcomes. Standardizing the how behind project execution allows Capgemini to decrease variation across customer projects and empower organizations to operate at speed without losing sight of enterprise needs.</li>



<li><strong>Enterprise experimentation. </strong>EY created an AI CoE focused on providing a secure sandbox environment. Teams can experiment with AI use cases, validate their feasibility and associated risk and fast‑track promising use cases to production. Centralized visibility and governance allow for consistent security and compliance standards, shortening the time between ideation and execution and preventing siloed adoption.</li>
</ul>



<p>Taken together, these industry examples highlight how a CoE is less of a technology endeavor and more focused on creating institutional trust and capacity. Want more proof points on how COEs make an impact? Consider how at ECS, a provider of cloud, cybersecurity and artificial intelligence (AI) services, the data and AI COE unify more than 200 data professionals across the business, shares their collective expertise across town halls and events and manages strategic partnerships. The COE enables proposals, solutions and fosters a culture of creativity and innovation.</p>



<p>Over at Hitachi Vantara, the AI COE is tasked with transforming ideas into production‑ready prototypes and is already being recognized for improving efficiency across operations and creating new revenue streams from advanced machine‑learning models. The board wants ROI and organizations with mature AI governance and COEs can increase returns on invested capital and create new sources of revenue. These are just a few examples of how a well architected CoE turns strategy into tangible business value.</p>



<p>The race for AI supremacy is picking up speed. Organizations that invest time and resources into building an effective AI Center of Excellence will be best positioned to turn innovation into competitive advantage. The CoE is how your biggest ideas go from concept to business solution–helping leaders do their best work.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, freerdp, git-lfs, glib2, jq, kernel-rt, krb5, libpng, libtiff, openexr, and thunderbird), Debian (exim4), Mageia (apache, perl-Gazelle, php, and sed), Slackware (expat), SUSE (assimp-devel, go1.26, libQt6Svg6, python-jupyterlab, raylib, th...]]></description>
<link>https://tsecurity.de/de/3513851/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513851/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 13 May 2026 15:26:51 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, freerdp, git-lfs, glib2, jq, kernel-rt, krb5, libpng, libtiff, openexr, and thunderbird), <b>Debian</b> (exim4), <b>Mageia</b> (apache, perl-Gazelle, php, and sed), <b>Slackware</b> (expat), <b>SUSE</b> (assimp-devel, go1.26, libQt6Svg6, python-jupyterlab, raylib, thunderbird, tor, and trivy), and <b>Ubuntu</b> (exim4).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in expat (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3512405/unix-server/security-denial-of-service-in-expat-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3512405/unix-server/security-denial-of-service-in-expat-slackware/</guid>
<pubDate>Wed, 13 May 2026 06:30:29 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, freeipmi, kernel, and kernel-rt), Debian (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), Fedora (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-...]]></description>
<link>https://tsecurity.de/de/3507119/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507119/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 11 May 2026 15:14:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, freeipmi, kernel, and kernel-rt), <b>Debian</b> (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), <b>Fedora</b> (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-pulp-glue, python-requests, rclone, and SDL3_image), <b>Mageia</b> (firefox, nss, rootcerts, openvpn, thunderbird, and vim), <b>Oracle</b> (corosync, freeipmi, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, libpng, and mingw-libtiff), <b>Slackware</b> (kernel and mozilla), <b>SUSE</b> (build, product-composer, c-ares, cairo, copacetic, distribution, firefox, firefox-esr, frr, glibc, go1.25, google-cloud-sap-agent, iproute2, java-11-openj9, java-17-openj9, java-17-openjdk, java-1_8_0-openj9, java-21-openj9, java-21-openjdk, java-25-openjdk, kernel, libexif-devel, libpcp-devel, libtpms, libtree-sitter0_26, Mesa, micropython, mozjs128, nginx, opencc, openCryptoki, php-composer2, podman, postfix, python-pytest, python311-Django, python311-Django4, redis, semaphore, strongswan, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, tor, valkey, vim, and wireshark), and <b>Ubuntu</b> (linux-nvidia-tegra, linux-raspi, linux-raspi-5.4, and nasm).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3503667/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503667/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Sat, 09 May 2026 22:16:20 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in kernel (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3502515/it-security-nachrichten/zwei-probleme-in-kernel-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3502515/it-security-nachrichten/zwei-probleme-in-kernel-slackware/</guid>
<pubDate>Sat, 09 May 2026 09:07:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in php (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3501880/unix-server/security-mehrere-probleme-in-php-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501880/unix-server/security-mehrere-probleme-in-php-slackware/</guid>
<pubDate>Sat, 09 May 2026 00:17:34 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-firefox (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3501879/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501879/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</guid>
<pubDate>Sat, 09 May 2026 00:17:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in libgpg-error (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3501817/it-security-nachrichten/zwei-probleme-in-libgpg-error-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501817/it-security-nachrichten/zwei-probleme-in-libgpg-error-slackware/</guid>
<pubDate>Fri, 08 May 2026 23:56:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Split View in Firefox: Two tabs side by side, right where you need them]]></title>
<description><![CDATA[Much of what we do on the web involves looking at more than one thing at a time – booking tickets while checking your calendar, taking notes as you go through a report, or comparing options before making a purchase. The web is inherently multidimensional. For years, browsing this way meant bounci...]]></description>
<link>https://tsecurity.de/de/3501680/tools/split-view-in-firefox-two-tabs-side-by-side-right-where-you-need-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501680/tools/split-view-in-firefox-two-tabs-side-by-side-right-where-you-need-them/</guid>
<pubDate>Fri, 08 May 2026 23:25:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Much of what we do on the web involves looking at more than one thing at a time – booking tickets while checking your calendar, taking notes as you go through a report, or comparing options before making a purchase. The web is inherently multidimensional. For years, browsing this way meant bouncing back and forth […]</p>
<p>The post <a href="https://blog.mozilla.org/en/firefox/split-view/">Split View in Firefox: Two tabs side by side, right where you need them</a> appeared first on <a href="https://blog.mozilla.org/en/">The Mozilla Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Triggers in religous rituals]]></title>
<description><![CDATA[A friend took me to a Unitarian Universalist church service, and one of the things which I noticed about that particular service (I don’t know how representative it is of all UU churches or services) was the notable lack of what I can only term as “trigger words” used in their worship service.

P...]]></description>
<link>https://tsecurity.de/de/3501105/unix-server/triggers-in-religous-rituals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501105/unix-server/triggers-in-religous-rituals/</guid>
<pubDate>Fri, 08 May 2026 23:03:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A friend took me to a Unitarian Universalist church service, and one of the things which I noticed about that particular service (I don’t know how representative it is of all UU churches or services) was the notable lack of what I can only term as “trigger words” used in their worship service.</p>
<!-- raw HTML omitted -->
<p>Perhaps the best way to describe it is by example. In my tradition, a very common pattern to start a prayer is for the worship leader to say, “The Lord be with you”, to which the response (said by the entire congregation) is “And also with you”, which in turn is followed by “Let us pray” and the actual prayer itself. This is a very common “design pattern”, which is used in many different contexts; perhaps at least 2 or 3 times in every Sunday service. The response is so automatic that sometimes it is used at retreats or at church meetings to call a gathering of people to order. The worship leader need only to say, “The Lord be with you” loudly, and everyone will instantly stop talking and respond “And also be with you”. These sets of phrases act almost like a post-hypnotic trigger, helping everyone to enter into the right frame of mind to begin a prayer.<!-- raw HTML omitted --></p>
<p>At the UU service that I intended, there was a very little of anything that I could could serve as these sorts of triggers. Instead, the leader said something like, “we will now offer up any joys and concerns”; and at the end of the service, she simply said, “This service is now concluded”. (In contrast, in an Episcopal service, a service might be concluded with “Let us go forth rejoicing in the power of the Spirit. Alleluia, alleluia”, to which the response would be, “Thanks be to God. Alleluia, alleluia”.)</p>
<p>Participating in a worship service that didn’t have these triggers caused me to see how much I had gotten used to them as a way to help me enter into the different parts of a worship service. I suspect I could get used to a different set of triggers, but the traditional Episcopal triggers have been programmed in my having attended hundreds if not thousands of services throughout my life. Perhaps that’s one of the reasons why attempts to change the Episcopal liturgies in ways that radically change or restructure these trigger phrases are met with quite a bit of resistance. Sometimes they are necessary, when our understanding of theology has changed over time, but these triggers seem to speak to us at a level that goes beyond rationality or theology.</p>
<p>That’s not to say that the UU service had no such triggers. At the beginning of the service, they did ring a bell three times, in what was very clearly intended to be a call to prepare for worship. And shortly after that, a candle which was floating in a chalice was lit, serving a similar purpose. But aside from that, most of the rest of the service spoke to the head, with very little that sparked an ineffable sence of the holy.</p>
<p>I chatted with my friend afterwards, and she told me that this wasn’t an accident. According to her, many Unitarians apparently don’t like that kind of liturgy. Perhaps they are seen as “magic words” to folks that prefer a strict sense of rationality.</p>
<p>A few months ago, when planning our Easter Eve service at our church, the traditional “lighting of the new fire” was replaced with a different framework. Traditionally, the “new fire” is lit while the congregation is sitting in complete darkness, holding unlit candles. Once it is lit, the bright fire in the back of the church is used to light the Pascal candle, and from that central candle, the fire is passed along to everyone in the congregation, so that by the time Easter Eve processional begins, there is a very strong contrast between the darkness at the very beginning of the service, to one where the church is lit from everybody’s candles — from hundreds of points of light, all stemming from the “new fire”. It represents the coming of Light to the world, and then the spreading of that light from one person to another, pushing back the darkness. To me, it is a very special part of the Easter Eve service.</p>
<p>In one of the explanations for why the traditional “new fire” liturgy was replaced, it was put down by dismissively by calling it a “magic fire”. I missed it, and I think I now know why — to me, <strong>the magic is important</strong>. It speaks to a part of me and fills a need in me that goes beyond rationality. And in this world that tends to celebrate the intellectual side of things beyond all others, that’s something which is incredibly valuable to me.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Comparing OLS and Usenix]]></title>
<description><![CDATA[Yesterday was the last day of
href=”http://linuxsymposium.org/”>Ottawa Linux Symposium, and I
can’t help comparing it with the
href=”http://www.usenix.org/publications/library/proceedings/usenix04/”>Usenix
Annual Technical Conference, which was only a few weeks earlier. The
difference in the qual...]]></description>
<link>https://tsecurity.de/de/3501070/unix-server/comparing-ols-and-usenix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501070/unix-server/comparing-ols-and-usenix/</guid>
<pubDate>Fri, 08 May 2026 23:03:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yesterday was the last day of</p>
<p>href=”http://linuxsymposium.org/”&gt;Ottawa Linux Symposium, and I</p>
<p>can’t help comparing it with the</p>
<p>href=”http://www.usenix.org/publications/library/proceedings/usenix04/”&gt;Usenix</p>
<p>Annual Technical Conference, which was only a few weeks earlier. The</p>
<p>difference in the quality and relevance (at least as far as my interests</p>
<p>are concerned) of the papers, the energy of the attendees, and the</p>
<p>overall atmosphere of the two conferences were distinctly different.</p>
<p>A look at this year’s</p>
<p>href=”http://www.finux.org/proceedings”&gt;conference proceedings for</p>
<p>OLS is enlightening; two volumes, with a total of 600 pages and 50</p>
<p>papers. In the past, some academics had sneered at OLS and</p>
<p>other Linux conferences because the papers were not well written, at</p>
<p>least by academic standards. This criticism is now much less</p>
<p>valid — if it ever was valid at all. As Clem Cole has pointed out, the NFS</p>
<p>paper, which is now considered seminal, is by academic standards a lousy</p>
<p>paper, and it is doubtful it would have been accepted by today’s program</p>
<p>committees under the guise of “raising quality of Usenix’s</p>
<p>papers”. More importantly for OLS however, beyond the</p>
<p>quality of the writing, was how vital and relevant the topics of the</p>
<p>papers.</p>
<p>Two people (one from IBM, and one from EMC) independently commented</p>
<p>to me that they had thought they stepped into a time-warp; the energy,</p>
<p>exchange of ideas, and excitement that they felt at OLS was reminiscent</p>
<p>of a Usenix conference from the early 1980’s. Two others (both previous</p>
<p>Usenix or Freenix program committee members and/or chairs) agreed with</p>
<p>these sentiments and said that they had pretty much given up any hopes</p>
<p>of “salvaging” Usenix and encouraged me to skip the</p>
<p>href=”http://www.usenix.org/events/usenix05″&gt;2005 Usenix ATC and go</p>
<p>to <a href="http://linux.conf.au/">Linux.conf.au</a> instead. Yet</p>
<p>another old-timer stated that Usenix ’04 was a great place to meet old</p>
<p>friends, but OLS and LCA is where the action is at.</p>
<p>That’s one possible solution, I suppose — after all, if all I care</p>
<p>about is Linux and Open Source Software (OSS) development, OLS (and to a</p>
<p>lesser extent, the [Linux</p>
<p>Kongress]<a href="http://www.linux-kongress.org/">2</a> and linux.conf.au) is the primiere place to submit papers</p>
<p>and meet with colleagues doing the leading-edge development work in</p>
<p>Linux, X Windows, and other OSS packages.</p>
<p>Unfortunately, there are a number of reasons why this might not be a</p>
<p>satisfactory or complete answer:</p>
<ul>
<li>
<p>As others such as Bryan Cantrill have pointed out in his</p>
<p>href=”http://blogs.sun.com/roller/comments/bmc/Weblog/whither_usenix”&gt;web</p>
<p>log, there is a need for a place for industry work to be published,</p>
<p>and increasingly Usenix is not fulfilling this role. So</p>
<p>this is a problem that goes beyond that of just Linux and the OSS</p>
<p>world.</p>
</li>
<li>
<p>Even if we ignore the problems of the proprietary Unix</p>
<p>vendors, the Linux and OSS community needs to exchange ideas with other</p>
<p>industry practitioners. This kind of discussion and cross-breeding</p>
<p>is in the long-term critically important. And even if AIX, HPUX,</p>
<p>and Solaris end up going the way of the dodo, who knows what insights</p>
<p>and new ideas might come from EMC, or Google, or even Microsoft?</p>
</li>
<li>
<p>I (perhaps stupidly <!-- raw HTML omitted -->) agreed to serve on the board of Usenix, so I</p>
<p>have a duty to Usenix’s long-term health as an organization and to its</p>
<p>mission. So I can’t just abandon Usenix’s ATC as a hopeless cause,</p>
<p>as some have urged me to do. As a result, some have accused me as having</p>
<p>a too-finely honed</p>
<p>sense of duty….</p>
</li>
</ul>
<p><!-- raw HTML omitted --> <!-- raw HTML omitted --></p>
<p>So, what can be done? I spent</p>
<p>quite a few hours brain-storming with Val Henson, Paul McKenney, and a</p>
<p>few other interested parties during the course of OLS. Val recorded the</p>
<p>results of some of these brain-storms in her</p>
<p>href=”http://blogs.sun.com/roller/page/val/20040722#the_freenix_track_has_it”&gt;web</p>
<p>log. As we had discussed it, the “Product Track” (which I jokingly called</p>
<p>“Realnix”) would contain technologies that either are in a shipping</p>
<p>product, or is intended to be integrated into a shipping product, where</p>
<p>for the purposes of this criteria, the mainline Linux, NetBSD, GNOME,</p>
<p>KDE, X Windows systems, would be considered “shipping product”.</p>
<p>Some might argue that this separation of “academic papers” and</p>
<p>“industry papers” might not be such a great idea. The argument has been</p>
<p>made that the academic track might be viewed as a “Golgafrincham B ark” where papers</p>
<p>with extensive bibliographies, meticulously enumerated related work</p>
<p>sections, and results describing 3% improvements on microbenchmarks</p>
<p>would be relegated. Perhaps such a perception is unfair, but whether or</p>
<p>not Rob Pike’s description of</p>
<p>href=”http://www.cs.bell-labs.com/who/rob/utah2000.pdf”&gt;Systems Software</p>
<p>Research as Being Irrelevant is accurate is a topic for another day</p>
<p>and time. If Rob’s observations have any validity, however, then it is</p>
<p>up to those in the academic world to address it, and the health and</p>
<p>vitality of the “academic track” will ultimately be their</p>
<p>responsibility, for good or for ill.</p>
<p>If we don’t create separate tracks for academic and product papers,</p>
<p>it’s going to be important to make sure the program committees are</p>
<p>balanced with representatives not just from universities and research</p>
<p>labs, but also from product groups. Bryan Cantrill has put together</p>
<p>href=”http://blogs.sun.com/roller/page/bmc/20040708#check_this_out_a_img”&gt;some</p>
<p>data showing how poorly the computer industry in general, and</p>
<p>product groups specifically have been representated on the Usenix</p>
<p>program committees. My concern is that the academic and</p>
<p>product-group communities, as well as their standards for papers, have</p>
<p>diverged too much already, and trying to manage this tension may prove</p>
<p>to be too much for many program committees. This may result in a</p>
<p>lurching back and forth of the acceptance criteria and overall balance of</p>
<p>the Usenix ATC, which would not be a good thing. Consistency</p>
<p>and predictability is extremely important to potential authors who are</p>
<p>deciding whether or not to submit a paper proposal to a conference or</p>
<p>track.</p>
<p>From a practical perspective, given how strong the OLS conference has</p>
<p>been this year, it will be harder and harder for Freenix to attract</p>
<p>papers about Linux and Open Source Software; OLS has proven itself as</p>
<p>the place for the Linux/OSS community to meet, and I predict that this</p>
<p>will if not starve Freenix submissions, cause it to be extremely</p>
<p>lopsided with very few relevant and interesting Linux papers. Hence,</p>
<p>expanding the scope of Freenix to include product papers may make a lot</p>
<p>of sense.</p>
<p>Of course, making room for papers from product groups (no matter how</p>
<p>we do it) isn’t going to be enough by itself. We will also need to find</p>
<p>ambassadors who work at each of various companies in the computer</p>
<p>industry to market to engineers and to managers why submitting papers</p>
<p>and serving on program committees is a good and useful thing to do —</p>
<p>both for the potential paper author as well as their employer. Val</p>
<p>Henson has put together a set of</p>
<p>href=”http://blogs.sun.com/roller/resources/val/slides.pdf”&gt;slides</p>
<p>for doing just that; see her</p>
<p>href=”http://blogs.sun.com/roller/page/val/20040713#program_committees_superpages_and_compare1″&gt;web</p>
<p>log entry for more discussion and the LaTeX sources to the</p>
<p>slides. (She has given permission for others to adapt her slides</p>
<p>for their company; you should credit her if you use them, though!)</p>
<p>Is this going to be enough to keep Usenix relevant and</p>
<p>interesting? To be honest, I don’t know. I sure hope</p>
<p>so. The good news is that there are more and more people thinking</p>
<p>about the problem, as some of the links to various web logs have</p>
<p>demonstrated. So even if we don’t have the complete solution to</p>
<p>the problem right now, we do have a growing consensus that there is a</p>
<p>problem, and what the scope of the problem is likely to be, and that’s</p>
<p>always a better place to be than being unwilling to acknowledge that</p>
<p>there is a problem in the first place.</p>
<p><strong>Update</strong> (7/27): I’ve since found the following</p>
<p>[</p>
<p>blog entry]<a href="http://weblogs.cs.cornell.edu/AllThingsDistributed/archives/000481.html">3</a> which presents</p>
<p>an opposite, or at least slightly different, point of view.</p>
<p>In it, Werner Vogel argues that the problem is that</p>
<p>program committee members have tried, but failed to get industry (product group)</p>
<p>participation — either on program committees or via submissions. I think he makes some</p>
<p>good points, although I think I differ about which is the chicken and</p>
<p>which is the egg here. It may be that having a separate track just for industry/product-group</p>
<p>representatives may make it easier to both recruit program committee members, and</p>
<p>to have enough people to actively solicit and arm-twist paper submissions. Also, perhaps</p>
<p>a program committee will have to use more creative ways of soliciting papers that</p>
<p>might not occur to a group of academics — for example, such as going through</p>
<p>the product marketing group to arm-twist the engineers to write and submit real papers (not just white papers!)</p>
<p>describing the sexy new technology in a recently-released product. Anyway, Werner’s comments are thoughtful</p>
<p>and should be carefully considered.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Git and hg]]></title>
<description><![CDATA[John Goerzen recently posted about  Git, Mercurial and Bzr that I found interesting, especially since I used to be in the hg camp, but have been gradually using git more and more, even to the point making minor improvements to the git documentation and writing the git mergetool, since being able ...]]></description>
<link>https://tsecurity.de/de/3501050/unix-server/git-and-hg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501050/unix-server/git-and-hg/</guid>
<pubDate>Fri, 08 May 2026 23:03:05 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://changelog.complete.org/">John Goerzen</a> recently posted about  <a href="http://changelog.complete.org/posts/594-More-on-Git,-Mercurial,-and-Bzr.html">Git, Mercurial and Bzr</a> that I found interesting, especially since I used to be in the hg camp, but have been gradually using git more and more, even to the point making minor improvements to the git documentation and writing the <a href="http://www.kernel.org/pub/software/scm/git/docs/git-mergetool.html">git mergetool</a>, since being able to automatically fire up a graphical merge tool was one of the features which I missed from hg. So while I haven’t yet converted the primary SCM repository for e2fsprogs to use git (yet), I’ve reached an opposite concolusion from John, and yet, I can’t really argue with his observations.</p>
<p><!-- raw HTML omitted -->The main reason why I’ve come out in favor of git is that I see its potential as being greater than hg, and so while it definitely has some ease-of-use and documentation shortcomings, in the long run I think it has “more legs” than hg, and with the release of git 1.5.0, it became clear that the git community was willing to work on these particular shortcomings, which is why I started working on it and making plans to migrate e2fsprogs to use git. The main reasons why I think git is more powerful is that not just that it supports lightweight branches inside a single repository (although I really do like that a lot since it makes it a lot easier to run multiple experiments in parallel and switch back and forth between them), but also because git is much more Unix-like; there are lots of tools that enable scripting for either new git extensions or for ad-hoc shell pipelines that you can’t really easily do in hg without breaking into Python. <!-- raw HTML omitted --></p>
<p>But git definitely does have shortcomings, and John is on the mark with most of them. Git’s documentation is very poor. Part of the problem stems for tutorials that were written to work with older versions of git (don’t try using anything older than git 1.5 if you are a git newbie; git 1.4.x is far more user-hostile) or were written for use with systems built on top of git 1.4.x, such as Cogito. (I don’t recommend Cogito, since git 1.5 is significantly more usable, and I’ve always found Cogito to be more confusing that just using stack git.) The tutorials that are distributed with git 1.5 are much better, but they clear do need more work.</p>
<p>It is true that the many of the man pages in git are lacking, and John’s criticism of the fact that many man pages do not list all of the options that they take, but rather refer to other man pages is on point and accurate. It has gotten better (take a look at the git-diff man page from the git 1.4.x days, and laugh or cry, depending on your point of view) but there is still much work to be done. In practice, the better way to use the git man pages is to skip past the options section, and take a look at the Examples section. This shows a number of ways that a particular command might be used, just as a Unix master might say, “Grasshoper, see how you can use awk to do all of these amazing things.”</p>
<p>I do take issue with John’s assertion that git’s philosophy has been to make life easy for the central maintainer, and not to pay much attention to the needs of individual contributors. That may have been Linus’s development priorities but with Junio having taking over maintenance, there have been a lot of improvements in git 1.5.0 to make life easier for people who are tracking remote repositories and making changes, in particular the <a href="http://www.kernel.org/pub/software/scm/git/docs/git-remote.html">git remote</a> command.</p>
<p>The most interesting observation which John made was the non-intuitive semantics of git-format-patches, and I did find it interesting that one commenter posted a solution which made perfect sense given other git commands, and yet didn’t work. Obviously the person who posted the comment didn’t bother to try it first, probably because in most other places git is actually pretty consistent; but git-format-patch is one of the places where most painfully is not. I view this as a bug that should be fixed, and fortunately I think it can be fixed without breaking the git-format-patches is currently being used. (The problem is that it doesn’t use the standard notation so it is more convenient in the common case of how it is normally used, where the end point is not specified and is always the the tip of the current branch. I believe we can avoid the UI surprise by making git-format-patch use the standard revision range parsing if parameter contains the “..” or “…” operators. I’ll have to try to prepare a patch which does this and see whether it gets accepted.)</p>
<p>So basically git does have short-comings, yes, but people will come out in different places about which tools is best for them, and that’s OK. Actually, I think the ultimate solution for this problem is to build a bidrectoinal hg/git gateway. There are tools that will export from hg to git, and vice versa, and they are actually pretty sophisticated. I don’t think it should be that painful to create a tool that does incremental exports in both directions, maintaining state so that the right thing happens when a commit gets made on the git side, and gets exported into hg, or vice versa. Ultimately I think that’s the best solution, since that way people can use whatever tool they want, and still contribute and development as first class citizens. This is the main reason why I’ve held off on converting e2fsprogs to git (although I have made some private test repositories which I’ll use to take advantage of git’s superior annotation and query/log utilities); I don’t want to make a git repository of e2fsprogs public until I’m sure that a bidrectional gateway tool won’t require me to make any changes that affect the commit-id’s, since that would invalidate any work that people have done that was based on a clone of the coverted git repository.</p>
<p>I have a rough design for how to do the bidirectional gateway, but the issue is finding time to implement it. Anyone with free time looking for a project? If so, contact me. I probably should have written this up as a potential Google Summer of Code project, but it’s too late for this year. Oh, well.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stupid SMP Tricks: A Review of Locking Engineering Principles and Hierarchy]]></title>
<description><![CDATA[Daniel Vetter put together a pair of intriguing blog posts entitled Locking Engineering Principles and Locking Engineering Hierarchy.  These appear to be an attempt to establish a set of GPU-wide or perhaps even driver-tree-wide concurrency coding conventions.Which would normally be none of my bu...]]></description>
<link>https://tsecurity.de/de/3500611/unix-server/stupid-smp-tricks-a-review-of-locking-engineering-principles-and-hierarchy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500611/unix-server/stupid-smp-tricks-a-review-of-locking-engineering-principles-and-hierarchy/</guid>
<pubDate>Fri, 08 May 2026 22:50:17 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Daniel Vetter put together a pair of intriguing blog posts entitled <a href="https://blog.ffwll.ch/2022/07/locking-engineering.html" target="_blank" rel="nofollow">Locking Engineering Principles</a> and <a href="https://blog.ffwll.ch/2022/08/locking-hierarchy.html" target="_blank" rel="nofollow">Locking Engineering Hierarchy</a>.  These appear to be an attempt to establish a set of GPU-wide or perhaps even driver-tree-wide concurrency coding conventions.<br><br>Which would normally be none of my business.  After all, to establish such conventions, Daniel needs to negotiate with the driver subsystem's developers and maintainers, and I am neither.  Except that he did <a href="https://twitter.com/danvet/status/1554799358096334848?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow">call me out</a> on Twitter on this topic.  So here I am, <a href="https://twitter.com/paulmckrcu/status/1555327265642147840" target="_blank" rel="nofollow">as promised</a>, offering color commentary and the occasional suggestion for improvement, both of Daniel's proposal and of the kernel itself.  The following sections review his two posts, and then summarize and amplify suggestions for improvement.<br><br><h1><a href="https://blog.ffwll.ch/2022/07/locking-engineering.html" target="_blank" rel="nofollow">Locking Engineering Principles</a></h1><br>“<b>Make it Dumb</b>” should be at least somewhat uncontroversial, as this is quite similar to a rather more flamboyant sound bite from my 1970s Mechanical Engineering university coursework.  Kernighan's Law asserting that debugging is twice as hard as coding should also be a caution. <br><br>This leads us to “<b>Make it Correct</b>”, which many might argue should come first in the list.  After all, if correctness is not a higher priority than dumbness (or simplicity, if you prefer), then the do-nothing null solution would always be preferred.  And to his credit, Daniel does explicitly state that “simple doesn't necessarily mean correct”.<br><br>It is hard to argue with Daniel's choosing to give <a href="https://lwn.net/Articles/185666/" target="_blank" rel="nofollow">lockdep</a> place of pride, especially given how many times it has saved me over the years, and not just from deadlock.  I never have felt the need to teach lockdep RCU's locking rules, but then again, RCU is much more monolithic than is the GPU subsystem.  Perhaps if RCU's locking becomes more ornate, I would also feel the need to acquire RCU's key locks in the intended order at boot time.  Give or take the fact that much of RCU can be used very early, even before the call to <tt>rcu_init()</tt>.<br><br>The validation point is also a good one, with Daniel calling out <tt>might_lock()</tt>, <tt>might_sleep()</tt>, and <tt>might_alloc()</tt>.  I go further and add <tt>lockdep_assert_irqs_disabled()</tt>, <tt>lockdep_assert_irqs_enabled()</tt>, and <tt>lockdep_assert_held()</tt>, but perhaps these additional functions are needed in low-level code like RCU more than they are in GPU drivers.<br><br>Daniel's admonishments to avoid reinventing various synchronization wheels of course comprise excellent common-case advice.  And if you believe that your code is the uncommon case, you are most likely mistaken.  Furthermore, it is hard to argue with “pick the simplest lock that works”.<br><br>It is hard to argue with the overall message of “<b>Make it Fast</b>”, especially the bit about the pointlessness of crashing faster.  However, a minimum level of speed is absolutely required.  For a 1977 example, an old school project required keeping up with the display. If the code failed to keep up with the display, that code was useless.  More recent examples include deep sub-second request-response latency requirements in many Internet datacenters.  In other words, up to a point, performance is not simply a “Make it Fast” issue, but also a “Make it Correct” issue.  On the other hand, once the code meets its performance requirements,  any further performance improvements instead falls into the lower-priority “Make it Fast” bucket.<br><br>Except that things are not always quite so simple.  Not all performance improvements can be optimized into existence late in the game.  In fact, if your software's performance requirements are expected to tax your system's resources, it will be necessary to make performance a first-class consideration all the way up to and including the software-architecture level, as discussed <a href="https://www.usenix.org/system/files/conference/hotpar12/hotpar12-final18.pdf" target="_blank" rel="nofollow">here</a>.  And, to his credit, Daniel hints at this when he notes that “the right fix for performance issues is very often to radically update the contract and sharing of responsibilities between the userspace and kernel driver parts”.  He also helpfully calls out <a href="https://lwn.net/Kernel/Index/#io_uring" target="_blank" rel="nofollow">io_uring</a> as one avenue for radical updates.<br><br>The “<b>Protect Data, not Code</b>” is good general advice and goes back to Jack Inman's 1985 USENIX paper entitled “Implementing Loosely Coupled Functions on Tightly Coupled Engines”, if not further.  However, there are times where what needs to be locked is not data, but perhaps a particular set of state transitions, or maybe a rarely accessed state, which might be best represented by the code for that state.  That said, there can be no denying the big-kernel-lock hazards of excessive reliance on code locking.  Furthermore, I have only rarely needed abstract non-data locking.<br><br>Nevertheless, a body of code as large as the full set of Linux-kernel device drivers should be expected to have a large number of exceptions to the “Protect Data” rule of thumb, reliable though that rule has proven in my own experience.  The usual way of handling this is a waiver process.  After all, given that every set of safety-critical coding guidelines I have seen has a waiver process, it only seems reasonable that device-driver concurrency coding conventions should also involve a waiver process.  But that decision belongs to the device-driver developers and maintainers, not with me.<br><br><h1><a href="https://blog.ffwll.ch/2022/08/locking-hierarchy.html" target="_blank" rel="nofollow">Locking Engineering Hierarchy</a></h1><br>Most of the <b>Level 0: No Locking</b> section should be uncontroversial: Do things the easy way, at least when the easy way works.  This approach goes back decades, for but one example, single-threaded user-interface code delegating concurrency to a database management system.  And it should be well-understood that complicated things can be made easy (or at least easier) through use of carefully constructed and time-tested APIs, for example, the <tt>queue_work()</tt> family of APIs called out in this section.  One important question for all such APIs is this: “Can someone with access to only the kernel source tree and a browser quickly find and learn how to use the given API?”  After all, people are able to properly use the APIs they see elsewhere <b>if</b> they can quickly and easily learn about them.<br><br>And yes, given Daniel's comments regarding <tt>struct dma_fence</tt> later in this section, the answer for <tt>SLAB_TYPESAFE_BY_RCU</tt> appears to be “no” (but see <tt>Documentation/RCU/rculist_nulls.rst</tt>).  The trick with <tt>SLAB_TYPESAFE_BY_RCU</tt> is that readers must validate the allocation.  A common way of doing this is to have a reference count that is set to the value one immediately after obtaining the object from <tt>kmem_struct_alloc()</tt> and set to the value zero immediately before passing the object to <tt>kmem_struct_free()</tt>.  And yes, I have a patch queued to fix the misleading text in <tt>Documentation/RCU/whatisRCU.rst</tt>, and I apologize to anyone who might have attempted to use locking without a reference count.  But please also let the record show that there was no bug report.<br><br>A reader attempting to obtain a new lookup-based reference to a <tt>SLAB_TYPESAFE_BY_RCU</tt> object must do something like this:<br><ol><br><li> <tt>atomic_inc_not_zero()</tt>, which will return <tt>false</tt> and not do the increment if initial value was zero.  Presumably <tt>dma_fence_get_rcu()</tt> handles this for <tt>struct dma_fence</tt>.<br></li><li> If the value returned above was false, pretend that the lookup failed.  Otherwise, continue with the following steps.<br></li><li> Check the identity of the object.  If this turns out to not be the desired object, release the reference (cleaning up if needed) and pretend that the lookup failed.  Otherwise, continue.  Presumably <tt>dma_fence_get_rcu_safe()</tt> handles this for <tt>struct dma_fence</tt>, in combination with its call to <tt>dma_fence_put()</tt>.<br></li><li> Use the object.<br></li><li> Release the reference, cleaning up if needed.<br></li></ol>This of course underscores Daniel's point (leaving aside the snark), which is that you should not use <tt>SLAB_TYPESAFE_BY_RCU</tt> unless you really need to, and even then you should make sure that you know how to use it properly.<br><br>But just when do you need to use <tt>SLAB_TYPESAFE_BY_RCU</tt>?  One example is when you need RCU protection on such a hot fastpath that you cannot tolerate RCU-freed objects becoming cold in the CPU caches due to RCU's grace-period delays.  Another example is where objects are being allocated and freed at such a high rate that if each and every <tt>kmem_cache_free()</tt> was subject to grace-period delays, excessive memory would be tied up waiting for grace periods, perhaps even resulting in out-of-memory (OOM) situations.<br><br>In addition, carefully constructed semantics are required.  Semantics based purely on ordering tend to result in excessive conceptual complexity and thus in confusion.  More appropriate semantics tend to be conditional, for example: (1) Objects that remain in existence during the full extent of the lookup are guaranteed to be found, (2) Objects that do not exist at any time during the full extent of the lookup are guaranteed not to be found, and (3) Objects that exist for only a portion of the lookup might or might not be found.<br><br>Does <tt>struct dma_fence</tt> need <tt>SLAB_TYPESAFE_BY_RCU</tt>?  Is the code handling <tt>struct dma_fence</tt> doing the right thing?  For the moment, I will just say that: (1) The existence of <tt>dma_fence_get_rcu_safe()</tt> gives me at least some hope, (2) Having two different slab allocators stored into different static variables having the same name is a bit code-reader-unfriendly, and (3) The use of <tt>SLAB_TYPESAFE_BY_RCU</tt> for a structure that contains an <tt>rcu_head</tt> structure is a bit unconventional, but perhaps these structures are sometimes obtained from <tt>kmalloc()</tt> instead of from <tt>kmem_struct_alloc()</tt>.<br><br>One thing this section missed (or perhaps intentionally omitted):  If you do need memory barriers, you are almost always better off using <tt>smp_store_release()</tt> and <tt>smp_load_acquire()</tt> than the old-style <tt>smp_wmb()</tt> and <tt>smp_rmb()</tt>.<br><br>The <b>Level 1: Big Dumb Lock</b> certainly summarizes the pain of finding the right scope for your locks.  Despite Daniel's suggesting that lockless tricks are almost always the wrong approach, such tricks are in common use.  I would certainly agree that randomly hacking lockless tricks into your code will almost always result in disaster.  In fact, this process will use your own intelligence against you: The smarter you think you are, the deeper a hole you will have dug for yourself before you realize that you are in trouble.<br><br>Therefore, if you think that you need a lockless trick, first actually measure the performance.  Second, if there really is a performance issue, do the work to figure out which code and data is actually responsible, because your blind guesses will often be wrong.  Third, read documentation, look at code, and talk to people to learn and fully understand how this problem has been solved in the past, then carefully apply those solutions.  Fourth, if there is no solution, review your overall design, because an ounce of proper partitioning is worth some tons of clever lockless code.  Fifth, if you must use a new solution, verify it beyond all reason.  The code in <tt>kernel/rcu/rcutorture.c</tt> will give you some idea of the level of effort required.<br><br>The <b>Level 2: Fine-grained Locking</b> sections provide some excellent advice, guidance, and cautionary tales.  Yes, lockdep is a great thing, but there are deadlocks that it does not detect, so some caution is still required.<br><br>The yellow-highlighted <b>Locking Antipattern: Confusing Object Lifetime and Data Consistency</b> describes how holding locks across non-memory-style barrier functions, that is, things like <tt>flush_work()</tt> as opposed to things like <tt>smp_mb()</tt>, can cause problems, up to and including deadlock.  In contrast, whatever other problems memory-barrier functions such as <tt>smp_mb()</tt> cause, it does take some creativity to add them to a lock-based critical section so as to cause them to participate in a deadlock cycle.  I would not consider <tt>flush_work()</tt> to be a memory barrier in disguise, although it is quite true that a correct high-performance implementation of <tt>flush_work()</tt> will require careful memory ordering.<br><br>I would have expected a rule such as “Don't hold a lock across <tt>flush_work()</tt> that is acquired in any corresponding workqueue handler”, but perhaps Daniel is worried about future deadlocks as well as present-day deadlocks.  After all, if you do hold a lock across a call to <tt>flush_work()</tt>, perhaps there will soon be some compelling reason to acquire that lock in a workqueue handler, at which point it is game over due to deadlock.<br><br>This issue is of course by no means limited to workqueues.  For but one example, it is quite possible to generate similar deadlocks by holding spinlocks across calls to <tt>del_timer_sync()</tt> that are acquired within timer handlers.<br><br>And that is why both <tt>flush_work()</tt> and <tt>del_timer_sync()</tt> tell lockdep what they are up to.  For example, <tt>flush_work()</tt> invokes <tt>__flush_work()</tt> which in turn invokes <tt>lock_map_acquire()</tt> and <tt>lock_map_release()</tt> on a fictitious lock, and this same fictitious lock is acquired and released by <tt>process_one_work()</tt>.  Thus, if you acquire a lock in a workqueue handler that is held across a corresponding <tt>flush_work()</tt>, lockdep will complain, as shown in the 2018 commit 87915adc3f0a ("workqueue: re-add lockdep dependencies for flushing") by Johannes Berg.  Of course, <tt>del_timer_sync()</tt> uses this same trick, as shown in the 2009 commit 6f2b9b9a9d75 ("timer: implement lockdep deadlock detection"), also by Johannes Berg.<br><br>Nevertheless, deadlocks involving <tt>flush_work()</tt> and workqueue handlers can be subtle.  It is therefore worth investing some up-front effort to avoid them.<br><br>The orange-highlighted <b>Level 2.5: Splitting Locks for Performance Reasons</b> discusses splitting locks.  As the section says, there are complications.  For one thing, lock acquisitions are anything but free, having overheads of hundreds or thousands of instructions at best, which means that adding additional levels of finer-grained locks can actually slow things down.  Therefore, Daniel's point about prioritizing architectural restructuring over low-level synchronization changes is an extremely good one, and one that is all too often ignored.<br><br>As Daniel says, when moving to finer-grained locking, it is necessary to avoid increasing the common-case number of locks being acquired.  As one might guess from the tone of this section, this is not necessarily easy.  Daniel suggests reader-writer locking, which can work well in some cases, but suffers from performance and scalability limitations, especially in situations involving short read-side critical sections.  The fact that readers and writers exclude each other can also result in latency/response-time issues.  But again, reader-writer locking can be a good choice in some cases.<br><br>The last paragraph is an excellent cautionary tale.  Take it from Daniel: Never let userspace dictate the order in which the kernel acquires locks.  Otherwise, you, too, might find yourself using wait/wound mutexes.  Worse yet, if you cannot set up an two-phase locking discipline in which all required locks are acquired before any work is done, you might find yourself writing deadlock-recovery code, or wounded-mutex recovery code, if you prefer.  This recovery code can be surprisingly complex.  In fact, one of the motivations for the early 1990s introduction of RCU into DYNIX/ptx was that doing so allowed deletion of many thousands of lines of such recovery code, along with all the yet-undiscovered bugs that code contained.<br><br>The red-highlighted <b>Level 3: Lockless Tricks</b> section begins with the ominous sentence “Do not go here wanderer!”<br><br>And I agree.  After all, if you are using the facilities discussed in this section, namely RCU, atomics, <tt>preempt_disable()</tt>, <tt>local_bh_disable()</tt>, <tt>local_irq_save()</tt>, or the various memory barriers, you had jolly well better not be wandering!!!<br><br>Instead, you need to understand what you are getting into and you need to have a map in the form of a principled design and a careful well-validated implementation.  And new situations may require additional maps to be made, although there are quite a few well-used maps already in <tt>Documentation/rcu</tt> and <a href="https://docs.google.com/document/d/1X0lThx8OK0ZgLMqVoXiR4ZrGURHrXK6NyLRbeXe3Xac/edit" target="_blank" rel="nofollow">over here</a>.  In addition, as Daniel says, algorithmic and architectural fixes can often provide much better results than can lockless tricks applied at low levels of abstraction.  Past experience suggests that some of those algorithmic and architectural fixes will involve lockless tricks on fastpaths, but life is like that sometimes.<br><br>It is now time to take a look at Daniel's alleged antipatterns.<br><br>The “<b>Locking Antipattern: Using RCU</b>” section does have some “interesting” statements:<br><ol><br><li> RCU is said to mix up lifetime and consistency concerns.  It is not clear exactly what motivated this statement, but this view is often a symptom of a strictly temporal view of RCU.  To use RCU effectively, one must instead take a combined spatio-temporal view, as described <a href="https://linuxfoundation.org/webinars/unraveling-rcu-usage-mysteries/" target="_blank" rel="nofollow">here</a> and <a href="https://linuxfoundation.org/webinars/unraveling-rcu-usage-mysteries-additional-use-cases/" target="_blank" rel="nofollow">here</a>.<br></li><li> <tt>rcu_read_lock()</tt> is said to provide both a read-side critical section and to extend the lifetime of any RCU-protected object.  This is true in common use cases because the whole purpose of an RCU read-side critical section is to ensure that any RCU-protected object that was in existence at any time during that critical section remains in existence up to the end of that critical section.  It is not clear what distinction Daniel is attempting to draw here.  Perhaps he likes the determinism provided by full mutual exclusion.  If so, never forget that the laws of physics dictate that such determinism is often surprisingly expensive.<br></li><li> The next paragraph is a surprising assertion that RCU readers' deadlock immunity is a bad thing!  Never forget that although RCU can be used to replace reader-writer locking in a great many situations, RCU is not reader-writer locking.  Which is a good thing from a performance and scalability viewpoint as well as from a deadlock-immunity viewpoint.<br></li><li> In a properly designed system, locks and RCU are not “papering over” lifetime issues, but instead properly managing object lifetimes.  And if your system is not properly designed, then any and all facilities, concurrent or not, are weapons-grade dangerous.  Again, perhaps more maps are needed to help those who might otherwise wander into improper designs.  Or perhaps existing maps need to be more consistently used.<br></li><li> RCU is said to practically force you to deal with “zombie objects”.  Twitter discussions with Daniel determined that such “zombie objects” can no longer be looked up, but are still in use.  Which means that many use cases of good old reference counting also force you to deal with zombie objects: After all, removing an object from its search structure does not invalidate the references already held on that object.  But it is quite possible to avoid zombie objects for both RCU and for reference counting through use of per-object locks, as is done in the Linux-kernel code that maps from a System-V semaphore ID to the corresponding in-kernel data structure, first described in Section of <a href="http://www2.rdrop.com/~paulmck/RCU/rcu.FREENIX.2003.06.14.pdf" target="_blank" rel="nofollow">this paper</a>.  In short, if you don't like zombies, there are simple RCU use cases that avoid them.  You get RCU's speed and deadlock immunity within the search structure, but full ordering, consistency, and zombie-freedom within the searched-for object.<br></li><li> The last bullet in this section seems to argue that people should upgrade from RCU read-side critical sections to locking or reference counting as quickly as possible.  Of course, such locking or reference counting can add problematic atomic-operation and cache-miss overhead to those critical sections, so specific examples would be helpful.  One non-GPU example is the System-V semaphore ID example mentioned above, where immediate lock acquisition is necessary to provide the necessary System-V semaphore semantics.<br></li><li> On freely using RCU, again, proper design is required, and not just with RCU.  One can only sympathize with a driver dying in <tt>synchronize_rcu()</tt>.  Presumably Daniel means that one of the driver's tasks hung in <tt>synchronize_rcu()</tt>, in which case there should have been an RCU CPU stall warning message which would point out what CPU or task was stuck in an RCU read-side critical section.  It is quite easy to believe that diagnostics could be improved, both within RCU and elsewhere, but if this was intended to be a bug report, it is woefully insufficient.<br></li><li> It is good to see that Daniel found at least one RCU use case that he likes (or at least doesn't hate too intensely), namely <tt>xarray</tt> lookups combined with <tt>kref_get_unless_zero()</tt> and <tt>kfree_rcu()</tt>.  Perhaps this is a start, especially if the code following that <tt>kref_get_unless_zero()</tt> invocation does additional atomic operations on the <tt>xarray</tt> object, which would hide at least some of the <tt>kref_get_unless_zero()</tt> overhead.<br></li></ol><br>The following table shows how intensively the RCU API is used by various v5.19 kernel subsystems:<br><br><blockquote><pre>
Subsystem   Uses          LoC  Uses/KLoC
---------   ----   ----------  ---------
ipc           91        9,822       9.26
virt          68        9,013       7.54
net         7457    1,221,681       6.10
security     599      107,622       5.57
kernel      1796      423,581       4.24
mm           324      170,176       1.90
init           8        4,236       1.89
block        108       65,291       1.65
lib          319      214,291       1.49
fs          1416    1,470,567       0.96
include      836    1,167,274       0.72
drivers     5596   20,861,746       0.27
arch         546    2,189,975       0.25
crypto         6      102,307       0.06
sound         21    1,378,546       0.02
---------   ----   ----------  ---------
Total      19191   29,396,128       0.65
</pre></blockquote><br>As you can see, the drivers subsystem has the second-highest total number of RCU API uses, but it also has by far the largest number of lines of code.  As a result, the RCU usage intensity in the drivers subsystem is quite low, at about 27 RCU uses per 100,000 lines of code.  But this view is skewed, as can be seen by looking more deeply within the drivers subsystem, but leaving out (aside from in the Total line) and drivers containing fewer than 100 instances of the RCU API:<br><br><blockquote><pre>
Subsystem           Uses          LoC  Uses/KLoC
---------           ----   ----------  ---------
drivers/target       293       62,532       4.69
drivers/block        355       97,265       3.65
drivers/md           334      147,881       2.26
drivers/infiniband   548      434,430       1.26
drivers/net         2607    4,381,955       0.59
drivers/staging      114      618,763       0.18
drivers/scsi         150    1,011,146       0.15
drivers/gpu          399    5,753,571       0.07
---------           ----   ----------  ---------
Total               5596   20,861,746       0.27
</pre></blockquote><br>The <tt>drivers/infiniband</tt> and <tt>drivers/net</tt> subtrees account for more than half of the RCU usage in the Linux kernel's drivers, and could be argued to be more about networking than about generic device drivers.  And although <tt>drivers/gpu</tt> comes in third in terms of RCU usage, it also comes in first in terms of lines of code, making it one of the least intense users of RCU.  So one could argue that Daniel already has his wish, at least within the confines of <tt>drivers/gpu</tt>.<br><br>This data suggests that Daniel might usefully consult with the networking folks in order to gain valuable guidelines on the use of RCU and perhaps atomics and memory barriers as well.  On the other hand, it is quite possible that such consultations actually caused some of Daniel's frustration.  You see, a system implementing networking must track the state of the external network, and it can take many seconds or even minutes for changes in that external state to propagate to that system.  Therefore, expensive synchronization within that system is less useful than one might think: No matter how many locks and mutexes that system acquires, it cannot prevent external networking hardware from being reconfigured or even from failing completely.<br><br>Moving to <tt>drivers/gpu</tt>, in theory, if there are state changes initiated by the GPU hardware without full-system synchronization, networking RCU usage patterns should apply directly to GPU drivers.  In contrast, there might be significant benefits from more tightly synchronizing state changes initiated by the system.  Again, perhaps the aforementioned System-V semaphore ID example can help in such cases.  But to be fair, given Daniel's preference for immediately acquiring a reference to RCU-protected data, perhaps <tt>drivers/gpu</tt> code is already taking this approach.<br><br>The “<b>Locking Antipattern: Atomics</b>” section is best taken point by point:<br><ol><br><li> For good or for ill, the ordering (or lack thereof) of Linux kernel atomics predates C++ atomics by about a decade.  One big advantage of the Linux-kernel approach is that all accesses to <tt>atomic*_t</tt> variables are marked.  This is a great improvement over C++, where a sequentially consistent load or store looks just like a normal access to a local variable, which can cause a surprising amount of confusion.<br></li><li> Please please please do not “sprinkle” memory barriers over the code!!!  Instead, actually design the required communication and ordering, and then use the best primitives for the job.  For example, instead of “<tt>smp_mb__before_atomic(); atomic_inc(&amp;myctr); smp_mb__after_atomic();</tt>”, maybe you should consider invoking <tt>atomic_inc_return()</tt>, discarding the return value if it is not needed.<br></li><li> Indeed, some atomic functions operate on non-<tt>atomic*_t</tt> variables.  But in many cases, you can use their <tt>atomic*_t</tt> counterparts.  For example, instead of <tt>READ_ONCE()</tt>, <tt>atomic_read()</tt>.  Instead of <tt>WRITE_ONCE()</tt>, <tt>atomic_set()</tt>.  Instead of <tt>cmpxchg()</tt>, <tt>atomic_cmpxchg()</tt>.  Instead of <tt>set_bit()</tt>, in many situations, <tt>atomic_or()</tt>.  On the other hand, I will make no attempt to defend the naming of <tt>set_bit()</tt> and <tt>__set_bit()</tt>.<br></li></ol><br>To Daniel's discussion of “unnecessary trap doors”, I can only agree that reinventing read-write semaphores is a very bad thing.<br><br>I will also make no attempt to defend ill-thought-out hacks involving weak references or RCU.  Sure, a quick fix to get your production system running is all well and good, but the real fix should be properly designed.<br><br>And Daniel makes an excellent argument when he says that if a counter can be protected by an already held lock, that counter should be implemented using normal C-language accesses to normal integral variables.  For those situations where no such lock is at hand, there are a lot of atomic and per-CPU counting examples that can be followed, both in the Linux kernel and in Chapter 5 of “<a href="https://kernel.org/pub/linux/kernel/people/paulmck/perfbook/perfbook-e2.pdf" target="_blank" rel="nofollow">Is Parallel Programming Hard, And, If So, What Can You Do About It?</a>”.  Again, why unnecessarily re-invent the wheel?<br><br>However, the last paragraph, stating that atomic operations should only be used for locking and synchronization primitives in the core kernel is a bridge too far.  After all, a later section allows for memory barriers to be used in libraries (at least driver-hacker-proof libraries), so it seems reasonable that atomic operations can also be used in libraries.<br><br>Some help is provided by the executable Linux-kernel memory model (LKMM) in <tt>tools/memory-model</tt> along with the kernel concurrency sanitizer (KCSAN), which is documented in <tt>Documentation/dev-tools/kcsan.rst</tt>, but there is no denying that these tools currently require significant expertise.  Help notwithstanding, it almost always makes a lot of sense to hide complex operations, including complex operations involving concurrency, behind well-designed APIs.<br><br>And help is definitely needed, given that there are more than 10,000 invocations of atomic operations in the drivers tree, more than a thousand of which are in <tt>drivers/gpu</tt>.<br><br>There is not much to say about the “<b>Locking Antipattern: preempt/local_irq/bh_disable() and Friends</b>” section.  These primitives are not heavily used in the drivers tree.  However, lockdep does have enough understanding of these primitives to diagnose misuse of irq-disabled and bh-disabled spinlocks.  Which is a good thing, given that there are some thousands of uses of irq-disabled spinlocks in the drivers tree, along with a good thousand uses of bh-disabled spinlocks.<br><br>The “<b>Locking Antipattern: Memory Barriers</b>” suggests that memory barriers should be packaged in a library or core kernel service, which is in the common case excellent advice.  Again, the executable LKMM and KCSAN can help, but again these tools currently require some expertise.  I was amused by Daniel's “I love to read an article or watch a talk by Paul McKenney on RCU like anyone else to get my brain fried properly”, and I am glad that my articles and talks provide at least a little entertainment value, if nothing else.  ;-)<br><br>Summing up my view of these two blog posts, Daniel recommends that most driver code avoid concurrency entirely.  Failing that, he recommends sticking to certain locking and reference-counting use cases, albeit including a rather complex acquire-locks-in-any-order use case.  For the most part, he recommends against atomics, RCU, and memory barriers, with a very few exceptions.<br><br>For me, reading these blog posts induced great nostalgia, taking me back to my early 1990s days at Sequent, when the guidelines were quite similar, give or take a large number of non-atomically manipulated per-CPU counters.  But a few short years later, many Sequent engineers were using atomic operations, and yes, a few were even using RCU.  Including one RCU use case in a device driver, though that use case could instead be served by the Linux kernel's <tt>synchronize_irq()</tt> primitive.<br><br>Still, the heavy use of RCU and (even more so) of atomics within the drivers tree, combined with Daniel's distaste for these primitive, suggests that some sort of change might be in order.<br><br><h1>Can We Fix This?</h1>Of course we can!!!<br><br>But will a given fix actually improve the situation?  <i>That</i> is the question.<br><br>Reading through this reminded me that I need to take another pass through the RCU documentation.  I have queued a commit to fix the misleading wording for <tt>SLAB_TYPESAFE_BY_RCU</tt> on the -rcu tree: <tt>08f8f09b2a9e ("doc: SLAB_TYPESAFE_BY_RCU uses cannot rely on spinlocks")</tt>.  I also expect to improve the documentation of reference counting and its relation to <tt>SLAB_TYPESAFE_BY_RCU</tt>, and will likely find a number of other things in need of improvement.<br><br>This is also as good a time as any to announce that I will be holding an an RCU Office Hours birds-of-a-feather session at the <a href="https://lpc.events/" target="_blank" rel="nofollow">2022 Linux Plumbers Conference</a>, in case that is helpful.<br><br>However, the RCU documentation must of necessity remain fairly high level.  And to that end, GPU-specific advice about use of <tt>xarray</tt>, <tt>kref_get_unless_zero()</tt>, and <tt>kfree_rcu()</tt> really needs to be <tt>Documentation/gpu</tt> as opposed to <tt>Documentation/RCU</tt>.  This would allow that advice to be much more specific and thus much more helpful to the GPU developers and maintainers.  Alternatively, perhaps improved GPU-related APIs are required in order to confine concurrency to functions designed for that purpose.  This alternative approach has the benefit of allowing GPU device drivers to focus more on GPU-specific issues and less on concurrency.  On the other hand, given that the GPU drivers comprise some millions of lines of code, this might be easier said than done.<br><br>It is all too easy to believe that it is possible to improve the documentation for a number of other facilities that Daniel called on the carpet.  At the same time, it is important to remember that the intent of documentation is communication, and that the optimal mode of communication depends on the target audience.  At its best, documentation builds a bridge from where the target audience currently is to where they need to go.  Which means the broader the target audience, the more difficult it is to construct that bridge.  Which in turn means that a given subsystem likely need usage advice and coding standards specific to that subsystem.  One size does not fit all.<br><br>The <tt>SLAB_TYPESAFE_BY_RCU</tt> facility was called on the carpet, and perhaps understandably so.  Would it help if <tt>SLAB_TYPESAFE_BY_RCU</tt> were to be changed so as to allow locks to be acquired on objects that might at any time be passed to <tt>kmem_cache_free()</tt> and then reallocated via <tt>kmem_cache_alloc()</tt>?  In theory, this is easy:  Just have the <tt>kmem_cache</tt> in question zero pages allocated from the system before splitting them up into objects.  Then a given object could have an “initialized” flag, and if that flag was cleared in an object just returned from <tt>kmem_struct_alloc()</tt>, then and only then would that lock be initialized.  This would allow a lock to be acquired (under <tt>rcu_read_lock()</tt>, of course) on a freed object, and would allow a lock to be held on an object despite its being passed to <tt>kmem_struct_free()</tt> and returned from <tt>kmem_struct_alloc()</tt> in the meantime.<br><br>In practice, some existing <tt>SLAB_TYPESAFE_BY_RCU</tt> users might not be happy with the added overhead of page zeroing, so this might require an additional <tt>GFP_</tt> flag to allow zeroing on a <tt>kmem_cache</tt>-by-<tt>kmem_cache</tt> basis.  However, the first question is “Would this really help?”, and answering that question requires feedback developers and maintainers who are actually using <tt>SLAB_TYPESAFE_BY_RCU</tt>.<br><br>Some might argue that the device drivers should all be rewritten in Rust, and cynics might argue that Daniel wrote his pair of blog posts with exactly that thought in mind.  I am happy to let those cynics make that argument, especially given that I have already held forth on Linux-kernel concurrency in Rust <a href="https://paulmck.livejournal.com/62436.html" target="_blank">here</a>.  However, a possible desire to rust Linux-kernel device drivers does not explain Daniel's distaste for what he calls “zombie objects” because Rust is in fact quite capable of maintaining references to objects that have been removed from their search structure.<br><br><h1>Summary and Conclusions</h1>As noted earlier, reading these blog posts induced great nostalgia, taking me back to my time at Sequent in the early 1990s.  A lot has happened in the ensuing three decades, including habitual use of locking in across the industry, and sometimes even correct use of locking.<br><br>But will generic developers ever be able to handle more esoteric techniques involving atomic operations and RCU?<br><br>I believe that the answer to this question is “yes”, as laid out in my 2012 paper <a href="http://www2.rdrop.com/~paulmck/scalability/paper/beyondmacho.2012.09.17b.pdf" target="_blank" rel="nofollow">Beyond Expert-Only Parallel Programming?</a>.  As in the past, tooling (including carefully designed APIs), economic forces (including continued ubiquitous multi-core systems), and acculturation (assisted by a vast quantity of open-source software) have done the trick, and I see no reason why these trends will not continue.<br><br>But what happens in <tt>drivers/gpu</tt> is up to the GPU developers and maintainers!<br><br><h1>References</h1><br>Atomic Operations and Memory Barriers, though more description than reference:<ol><br><li> <tt>Documentation/atomic_t.txt</tt><br></li><li> <tt>Documentation/atomic_bitops.txt</tt><br></li><li> <tt>Documentation/memory-barriers.txt</tt><br></li><li> Sometimes the docbook header is on the x86 <tt>arch_</tt> function, for example, <tt>arch_atomic_inc()</tt> in <tt>arch/x86/include/asm/atomic.h</tt> rather than <tt>atomic_inc()</tt>.<br></li><li> The LKMM references below can also be helpful.<br></li></ol><br>Kernel Concurrency Sanitizer (KCSAN):<ol><br><li> <tt>Documentation/dev-tools/kcsan.rst</tt><br></li><li> <a href="https://lwn.net/Articles/802128/" target="_blank" rel="nofollow">Finding race conditions with KCSAN</a><br></li><li> <a href="https://lwn.net/Articles/816850/" target="_blank" rel="nofollow">Concurrency bugs should fear the big bad data-race detector (part 1)</a><br></li><li> <a href="https://lwn.net/Articles/816854/" target="_blank" rel="nofollow">Concurrency bugs should fear the big bad data-race detector (part 2)</a><br></li><li> <a href="https://lwn.net/Articles/877200/" target="_blank" rel="nofollow">Detecting missing memory barriers with KCSAN</a><br></li></ol><br>Linux-Kernel Memory Model (LKMM):<ol><br><li> <tt>tools/memory-model</tt>, including its <tt>Documentation</tt> subdirectory.<br></li><li> <a href="https://lwn.net/Articles/718628/" target="_blank" rel="nofollow">A formal kernel memory-ordering model (part 1)</a><br></li><li> <a href="https://lwn.net/Articles/720550/" target="_blank" rel="nofollow">A formal kernel memory-ordering model (part 2)</a><br></li><li> <a href="https://lwn.net/Articles/793253/" target="_blank" rel="nofollow">Who's afraid of a big bad optimizing compiler?</a><br></li><li> <a href="https://lwn.net/Articles/799218/" target="_blank" rel="nofollow">Calibrating your fear of big bad optimizing compilers</a><br></li><li> <a href="https://dl.acm.org/doi/10.1145/3173162.3177156" target="_blank" rel="nofollow">Frightening Small Children and Disconcerting Grown-ups: Concurrency in the Linux Kernel</a> (<a href="http://diy.inria.fr/linux/" target="_blank" rel="nofollow">non-paywalled extended )edition</a><br></li></ol><br>Read-Copy Update (RCU):<ol><br><li> <tt>Documentation/RCU</tt><br></li><li> <a href="https://lwn.net/Articles/777036/" target="_blank" rel="nofollow">The RCU API, 2019 edition</a><br></li><li> <a href="https://linuxfoundation.org/webinars/unraveling-rcu-usage-mysteries/" target="_blank" rel="nofollow">Unraveling RCU-Usage Mysteries (Fundamentals)</a><br></li><li> <a href="https://linuxfoundation.org/webinars/unraveling-rcu-usage-mysteries-additional-use-cases/" target="_blank" rel="nofollow">Unraveling RCU-Usage Mysteries (Additional Use Cases)</a><br></li><li> Sections 9.5 and 9.6 of “<a href="https://kernel.org/pub/linux/kernel/people/paulmck/perfbook/perfbook-e2.pdf" target="_blank" rel="nofollow">Is Parallel Programming Hard, And, If So, What Can You Do About It?</a><br></li><li> Many other references, some of which are listed <a href="https://docs.google.com/document/d/1X0lThx8OK0ZgLMqVoXiR4ZrGURHrXK6NyLRbeXe3Xac/edit?usp=sharing" target="_blank" rel="nofollow">here</a>.<br></li></ol>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mobile Progress Report – June 2025]]></title>
<description><![CDATA[Welcome back to another update on how things are going on mobile.  Thunderbird for iOS We’ve been going back and forth between database and JMAP for Thunderbird for iOS. Most of the visible work has flown into creating an initial JMAP library that we can use to access the parts that we need from ...]]></description>
<link>https://tsecurity.de/de/3500394/tools/mobile-progress-report-june-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500394/tools/mobile-progress-report-june-2025/</guid>
<pubDate>Fri, 08 May 2026 22:28:41 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome back to another update on how things are going on mobile.  Thunderbird for iOS We’ve been going back and forth between database and JMAP for Thunderbird for iOS. Most of the visible work has flown into creating an initial JMAP library that we can use to access the parts that we need from Thunderbird […]</p>
<p>The post <a href="https://blog.thunderbird.net/2025/07/mobile-progress-report-june-2025/">Mobile Progress Report – June 2025</a> appeared first on <a href="https://blog.thunderbird.net/">The Thunderbird Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (libsoup and mingw-libtiff), Debian (apache2, chromium, lcms2, libreoffice, and prosody), Fedora (openssl and perl-Starman), Oracle (git-lfs, libsoup, and perl-XML-Parser), Slackware (libgpg, mozilla, and php), SUSE (389-ds, cairo, cf-cli, chromedriv...]]></description>
<link>https://tsecurity.de/de/3499402/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499402/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 08 May 2026 15:26:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (libsoup and mingw-libtiff), <b>Debian</b> (apache2, chromium, lcms2, libreoffice, and prosody), <b>Fedora</b> (openssl and perl-Starman), <b>Oracle</b> (git-lfs, libsoup, and perl-XML-Parser), <b>Slackware</b> (libgpg, mozilla, and php), <b>SUSE</b> (389-ds, cairo, cf-cli, chromedriver, cri-tools, freeipmi, gnutls, grafana, java-11-openjdk, java-17-openjdk, jetty-minimal, libmariadbd-devel, librsvg, mesa, mozjs52, mutt, nix, opencryptoki, python-Django, python-django, python-pytest, rmt-server, thunderbird, traefik, webkit2gtk3, wireshark, and xen), and <b>Ubuntu</b> (civicrm, dpkg, htmlunit, lcms2, libpng1.6, linux, linux-*, linux-azure, linux-azure-fips, linux-raspi, linux-xilinx, lua5.1, nasm, opam, openexr, openjpeg2, owslib, postfix, postfixadmin, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[I finally got Linux booting over HTTP Boot Wireless on a supported Dell notebook]]></title>
<description><![CDATA[Linux booting over HTTP Boot Wireless I have been working on a multi boot deployment engine for a while, mostly for Windows at first, and one of the hardest things I wanted to prove to myself was whether I could make wireless HTTP Boot actually work on a real machine, not just in theory. Recently...]]></description>
<link>https://tsecurity.de/de/3494422/linux-tipps/i-finally-got-linux-booting-over-http-boot-wireless-on-a-supported-dell-notebook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494422/linux-tipps/i-finally-got-linux-booting-over-http-boot-wireless-on-a-supported-dell-notebook/</guid>
<pubDate>Thu, 07 May 2026 03:55:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://preview.redd.it/bxnv1w6cgmzg1.png?width=754&amp;format=png&amp;auto=webp&amp;s=eebac1541ee87eb599be1e8c783d9f283ac1fc4c">Linux booting over HTTP Boot Wireless</a></p> <p>I have been working on a multi boot deployment engine for a while, mostly for Windows at first, and one of the hardest things I wanted to prove to myself was whether I could make wireless HTTP Boot actually work on a real machine, not just in theory.</p> <p>Recently I got that working on a few Dell notebook models using Linux ISOs, specifically ASMI Linux 25.10 and Ubuntu 24.04 LTS. The interesting part is that the same boot flow I had already built for Windows still applies here too. The machine can be started from a single server that serves PXE UEFI, PXE Legacy, HTTP Boot wired, and HTTP Boot wireless without me having to switch modes back and forth.</p> <p>The flow starts the same way. I launch the program, start the server, and the client can either see the server over the network through PXE or wired HTTP Boot, or connect to a special Wi Fi AP that the program creates. The server then gives the right bootloader depending on what the machine supports, so Legacy gets the original iPXE PXE binary and UEFI gets the iPXE shim. After that the client gets a multiboot menu and I can choose which ISO to start.</p> <p>The wireless path was the part that took the most time and the most failed attempts. If the client is using HTTP Boot Wireless, the server has to pull Wi Fi firmware directly from the ISO itself and load it early in stage1 so the machine can reconnect to the special AP again. After that it can fetch the extra files it needs into RAM and continue. If the machine is using wired PXE or wired HTTP Boot, then none of that Wi Fi handling is needed and it just uses the active network interface.</p> <p>For Linux I have not finished full automatic installation to disk yet like I have for Windows, so right now the main milestone is successful boot. But even that took a surprising amount of work because I had to stay in Ubuntu stage1 for more than two weeks just to figure out how to make it believe it was booting from a media device in a very limited environment.</p> <p>That meant building custom scripts before initrd, adjusting the early boot flow, and making sure everything Ubuntu needed was already sitting in RAM by the time it started. Once that finally clicked, the machine booted cleanly.</p> <p>Secure Boot is still not supported for Linux in this path yet, even though it works fine for Windows when using the original iPXE bootloaders. My guess is that the Linux distros I tested do not have the same certificate situation available in the firmware chain I am using.</p> <p>At this point I am mostly just curious whether this approach is interesting to anyone else, or whether there is a cleaner way to handle the same problem. For me it was mainly a personal challenge, but getting Linux to boot this way felt like a pretty big milestone.</p> <p>I also upload a video demo at <a href="https://youtu.be/yyWKksOpyuo">here</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TekDT"> /u/TekDT </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1t5wvlg/i_finally_got_linux_booting_over_http_boot/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t5wvlg/i_finally_got_linux_booting_over_http_boot/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, dovecot, image-builder, python-tornado, resource-agents, and systemd), Debian (openjdk-11, openjdk-17, and pyjwt), Fedora (pdns, pyOpenSSL, and squid), Slackware (hunspell), SUSE (alloy, avahi, bubblewrap, cmctl, coredns, curl, dpkg, firef...]]></description>
<link>https://tsecurity.de/de/3492798/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3492798/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 06 May 2026 15:12:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, dovecot, image-builder, python-tornado, resource-agents, and systemd), <b>Debian</b> (openjdk-11, openjdk-17, and pyjwt), <b>Fedora</b> (pdns, pyOpenSSL, and squid), <b>Slackware</b> (hunspell), <b>SUSE</b> (alloy, avahi, bubblewrap, cmctl, coredns, curl, dpkg, firefox, golang-github-prometheus-prometheus, grafana, libpng12, PackageKit, sed, and xen), and <b>Ubuntu</b> (docker.io-app, nghttp2, python-django, and python-mako).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in hunspell (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3490859/unix-server/security-mehrere-probleme-in-hunspell-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3490859/unix-server/security-mehrere-probleme-in-hunspell-slackware/</guid>
<pubDate>Tue, 05 May 2026 23:01:55 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, kernel-rt, libcap, LibRaw, openssh, thunderbird, and tigervnc), Debian (libarchive and lxd), Fedora (chromium, insight, nodejs20, rust-sequoia-git, and uriparser), Mageia (kernel, kmod-virtualbox), Oracle (kernel, libcap, thunderbird, and ue...]]></description>
<link>https://tsecurity.de/de/3489744/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489744/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 05 May 2026 15:24:24 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, kernel-rt, libcap, LibRaw, openssh, thunderbird, and tigervnc), <b>Debian</b> (libarchive and lxd), <b>Fedora</b> (chromium, insight, nodejs20, rust-sequoia-git, and uriparser), <b>Mageia</b> (kernel, kmod-virtualbox), <b>Oracle</b> (kernel, libcap, thunderbird, and uek-kernel), <b>Red Hat</b> (.NET 10.0, .NET 8.0, .NET 9.0, fence-agents, sudo, and systemd), <b>Slackware</b> (httpd), <b>SUSE</b> (freerdp, hauler, helm, himmelblau, kernel, libspectre, thunderbird, trivy, and xen), and <b>Ubuntu</b> (curl, exim4, and sed).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in httpd (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3488363/it-security-nachrichten/mehrere-probleme-in-httpd-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488363/it-security-nachrichten/mehrere-probleme-in-httpd-slackware/</guid>
<pubDate>Tue, 05 May 2026 07:06:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Epic vs Apple fight could be put on hold again if Supreme Court sides with Apple]]></title>
<description><![CDATA[Apple doesn't want to fight a battle on two fronts in the ongoing Epic Games case, so it has turned to the Supreme Court for a pause on proceedings in the Circuit Courts.Apple's control of the App Store continues to be challenged in courtThe Apple vs Epic case could go down as one of the more con...]]></description>
<link>https://tsecurity.de/de/3487526/ios-mac-os/epic-vs-apple-fight-could-be-put-on-hold-again-if-supreme-court-sides-with-apple/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487526/ios-mac-os/epic-vs-apple-fight-could-be-put-on-hold-again-if-supreme-court-sides-with-apple/</guid>
<pubDate>Tue, 05 May 2026 00:07:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple doesn't want to fight a battle on two fronts in the ongoing Epic Games case, so it has turned to the Supreme Court for a pause on proceedings in the Circuit Courts.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67543-142272-iPhone-17e-pink-hand-held-xl.jpg" alt="Hand holding a pale pink iPhone, showing the back with a single large rear camera, flash, and subtle Apple logo against a softly blurred outdoor background"><br><span>Apple's control of the App Store continues to be challenged in court</span></div><br>The Apple vs Epic case could go down as one of the more convoluted cases Apple has ever faced. The back and forth that has taken place since Epic first filed a lawsuit in 2020 will take you <a href="https://appleinsider.com/articles/20/08/23/apple-versus-epic-games-fortnite-app-store-saga%E2%80%94%E2%80%94the-story-so-far">at least two hours</a> to read through.<br><br>In a new filing viewed by <em>AppleInsider</em>, Apple has requested a stay on the mandate that would require it to reconvene with Epic in court and decide upon a new <a href="https://appleinsider.com/inside/app-store" title="App Store" data-kpt="1">App Store</a> commission for external purchases. It was previously granted a stay by the Circuit Court, but that stay <a href="https://appleinsider.com/articles/26/04/29/app-store-policy-must-change-as-epic-convinces-us-circuit-court-to-reverse-stay">was overturned</a> after a complaint from Epic.<br><br><br> <a href="https://appleinsider.com/articles/26/05/04/epic-vs-apple-fight-could-be-put-on-hold-again-if-supreme-court-sides-with-apple?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244236?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, libcap, libtiff, sudo, and thunderbird), Debian (dovecot, imagemagick, incus, kernel, libexif, linux-6.1, openjdk-25, pyasn1, python-aiohttp, and thunderbird), Fedora (chromium, firefox, GitPython, glibc, insight, krb5, nano, nss, openssh, o...]]></description>
<link>https://tsecurity.de/de/3486289/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486289/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 04 May 2026 15:41:39 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, libcap, libtiff, sudo, and thunderbird), <b>Debian</b> (dovecot, imagemagick, incus, kernel, libexif, linux-6.1, openjdk-25, pyasn1, python-aiohttp, and thunderbird), <b>Fedora</b> (chromium, firefox, GitPython, glibc, insight, krb5, nano, nss, openssh, openvpn, perl-CryptX, python3.14, rust-openssl, rust-openssl-sys, rust-sequoia-git, and xen), <b>Oracle</b> (dtrace, fence-agents, grafana-pcp, libcap, libtiff, sudo, and xorg-x11-server-Xwayland), <b>Red Hat</b> (buildah, fence-agents, firefox, java-11-openjdk with Extended Lifecycle Support, LibRaw, nodejs24, nodejs:24, openssh, python-pyasn1, resource-agents, thunderbird, tigervnc, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Slackware</b> (mozilla), and <b>SUSE</b> (avahi, curl, freeipmi, freerdp, google-guest-agent, google-osconfig-agent, gvim, helm, himmelblau, java-1_8_0-openjdk, kernel, krb5-appl-clients, libsodium, libssh, libtiff-devel-32bit, ntfs-3g_ntfsprogs, openCryptoki, openexr, ovmf, PackageKit, python-jwcrypto, python-Mako, python-PyNaCl, python311, python311-pypdf, sed, trivy, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[The $570K canary: What AI coding agents reveal about enterprise AI’s real gaps]]></title>
<description><![CDATA[Boris Cherny, creator of Anthropic’s Claude Code, says he hasn’t written a line of code by hand in months. He shipped 22 pull requests one day, 27 the next, all AI-generated. Company-wide, Anthropic reports that 70 to 90% of its code is now written by AI. CEO Dario Amodei has predicted that AI co...]]></description>
<link>https://tsecurity.de/de/3485681/it-security-nachrichten/the-570k-canary-what-ai-coding-agents-reveal-about-enterprise-ais-real-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485681/it-security-nachrichten/the-570k-canary-what-ai-coding-agents-reveal-about-enterprise-ais-real-gaps/</guid>
<pubDate>Mon, 04 May 2026 12:07:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Boris Cherny, creator of Anthropic’s Claude Code, says <a href="https://fortune.com/2026/01/29/100-percent-of-code-at-anthropic-and-openai-is-now-ai-written-boris-cherny-roon/" rel="nofollow">he hasn’t written a line of code by hand in months.</a> He shipped 22 pull requests one day, 27 the next, all AI-generated. Company-wide, Anthropic reports that 70 to 90% of its code is now written by AI. CEO Dario Amodei has predicted that AI could handle “most, maybe all” of what software engineers do within months.</p>



<p>And yet Anthropic typically has <a href="https://www.anthropic.com/careers/jobs" rel="nofollow">dozens of software engineering openings</a>, one reportedly carrying $570K in total compensation. As <a href="https://medium.com/@kanishks772/anthropic-says-engineers-wont-exist-in-a-year-it-s-also-paying-them-570k-today-5ee2a673f1ef" rel="nofollow">one observer noted</a>, the company is simultaneously predicting the end of the profession and paying top dollar to hire into it.</p>



<p>Meanwhile, during his <a href="https://blogs.nvidia.com/blog/gtc-2026-news/" rel="nofollow">GTC 2026 keynote</a>, NVIDIA CEO Jensen Huang said that 100% of NVIDIA now uses AI coding tools, including Claude Code, Codex and Cursor, often all three. Then, in a conversation on the <a href="https://the-decoder.com/nvidia-ceo-jensen-huang-says-hed-be-deeply-alarmed-if-a-500k-developer-spent-less-than-250k-on-ai-tokens/" rel="nofollow">All-In Podcast</a> during GTC week, Huang sharpened the point: A $500,000 engineer who doesn’t consume at least $250,000 in AI tokens annually is like “one of our chip designers who says, guess what, I’m just going to use paper and pencil.”</p>



<p>This isn’t cognitive dissonance. It’s a signal. And CIOs who look past the headlines will find a pattern that explains not just where AI coding is going, but where all of enterprise AI is headed.</p>



<h2 class="wp-block-heading">Tellers, not toll booth workers</h2>



<p>The instinct is to see this as an extinction event. AI writes all the code; engineers become toll booth workers, replaced entirely by automation with no complementary role left behind. But the data tells a different story, one I explored in a <a href="https://www.cio.com/article/4148168/agi-skepticism-tellers-vs-toll-booth-workers.html">recent CIO.com article on AGI skepticism</a>.</p>



<p>When ATMs rolled out, bank teller employment didn’t collapse. It doubled, from 268,000 in 1970 to 608,000 in 2006. The machines eliminated the routine transaction. But cheaper branch operations meant banks opened more locations, which created demand for tellers who could handle complex financial conversations. Economists call this Jevons Paradox: When technology makes something more efficient, demand expands rather than contracts.</p>



<p>Software engineers are bank tellers, not toll booth workers. AI agents are eliminating routine implementation: The boilerplate, the CRUD endpoints, the standard test scaffolding. But that efficiency is expanding the total surface area of what “engineering” means. Anthropic isn’t paying $570K for someone to type code. They’re paying for the judgment to orchestrate AI agents that type code: Deciding what to build, evaluating whether the output is correct, governing what gets deployed and maintaining systems that are increasingly written by machines.</p>



<p>Cherny confirmed this shift directly. His team now hires generalists over specialists, because traditional programming specialties are less relevant when AI handles implementation details. The skill premium has moved from writing code to supervising it, from production to orchestration.</p>



<h2 class="wp-block-heading">The reason AI coding agents work</h2>



<p>Here’s the question CIOs should be asking: Why are AI agents succeeding in software development faster than in any other enterprise function?</p>



<p>It’s not because coding models are better than models for customer service, legal review or financial analysis. The underlying LLMs are the same. The difference is that software development already had the infrastructure that every other enterprise function lacks.</p>



<p>Developers didn’t build this infrastructure for AI. They built it for themselves, over decades. But it maps almost perfectly to the six infrastructure gaps that are currently blocking AI agents from moving beyond employee-facing pilots into customer-facing production.</p>



<h2 class="wp-block-heading">6 gaps the SDLC already solved</h2>



<h3 class="wp-block-heading">1. Governance: Right data, right users, right permissions</h3>



<p>In software development, governance is built into the workflow. Branch protection, code review policies and role-based access controls create a clear chain of permission from draft to deploy, whether the author is human or agent.</p>



<p>Most enterprise functions have nothing equivalent. When an AI agent drafts a customer response, accesses a patient record or modifies a financial model, the governance layer (who approved this action, what data was it allowed to see, which policies constrain its output) is either ad hoc or absent. <a href="https://news.microsoft.com/source/emea/features/microsoft-cyber-pulse-ai-agents-2/" rel="nofollow">Microsoft’s 2026 Cyber Pulse survey</a> found that while 80% of Fortune 500 companies have deployed AI agents, only 47% have agent-specific security policies in place.</p>



<h3 class="wp-block-heading">2. Observability: Trace and audit the decision trail</h3>



<p>Every line of AI-generated code has a paper trail. Git blame shows who (or what) wrote it. CI/CD pipelines log every build, test and deployment. When something breaks in production, engineers can trace the failure from alert to commit to the specific agent session that produced the change.</p>



<p>Outside of engineering, AI agent decisions are largely opaque. A customer-facing agent that denies a claim or escalates a complaint leaves no audit trail. Without observability, enterprises can’t debug bad outcomes, satisfy regulators or build the trust necessary to expand agent autonomy.</p>



<h3 class="wp-block-heading">3. Evaluation: Measure correctness at scale</h3>



<p>Unit tests, integration tests, type checking, linting and automated QA give software engineering something no other enterprise function has: Continuous, objective measurement of whether AI-generated output is correct. That provides a foundation for proving an agent gets it right.</p>



<p>This is the gap other enterprise functions feel most acutely. <a href="https://www.digitalocean.com/currents/february-2026" rel="nofollow">DigitalOcean’s 2026 survey of 1,100 technology leaders</a> found that 41% cite reliability as their number one barrier to scaling AI agents. Reliability is an evaluation problem: Without automated, continuous measurement of agent output quality, organizations can’t trust agents enough to put them in front of customers.</p>



<h3 class="wp-block-heading">4. Memory: Persistent context beyond the context window</h3>



<p>Developers take persistent context for granted. Version control, documentation and architectural decision records provide context that survives across sessions, teams and years. An AI coding agent can read the commit history, understand why a design choice was made in 2019, and factor it into today’s implementation.</p>



<p>Most enterprise AI agents operate in a memoryless state. Each customer interaction starts from scratch. Each agent session has no awareness of prior decisions, escalations or context beyond what fits in the context window. This is why employee-facing agents (IT help desks, NOC ticketing) succeed where customer-facing agents stall: Internal users tolerate repeating context. Customers do not.</p>



<h3 class="wp-block-heading">5. Cost controls: Manage LLM spend across providers</h3>



<p>Jensen Huang’s $250K-per-engineer token budget isn’t an abstraction. It’s a real cost management challenge that engineering teams are already navigating. Smart teams route differently depending on the task: Use a lightweight model for boilerplate generation, a reasoning model for architectural decisions and a code-specific model for refactoring. They set token budgets per agent session. They measure cost-per-PR and cost-per-feature, not just cost-per-token.</p>



<p>Enterprises deploying AI agents in other functions rarely have this granularity. When <a href="https://www.tomsguide.com/ai/ai-contributed-basically-zero-to-the-us-economy-last-year-according-to-goldman-sachs" rel="nofollow">Goldman Sachs stated AI near-zero GDP impact in 2025</a>, the missing variable was cost discipline at the workflow level. Without the ability to route, throttle and measure LLM spend per agent task, scaling agents means scaling costs linearly, which eventually kills ROI.</p>



<h3 class="wp-block-heading">6. Deployment flexibility: Any cloud, on-prem, no lock-in</h3>



<p>In software development, the runtime has always been portable. Code that runs on AWS today can run on Azure tomorrow, or on bare metal in your own data center. Containerization, Kubernetes and infrastructure-as-code tools like Terraform mean that engineering teams can change their minds about where workloads run without rewriting the application. Software has had this mindset for decades.</p>



<p>We’re early enough in this agentic development game that it’s tempting to take short cuts. Organizations that build on a single hyperscaler’s agent framework find themselves locked into that provider’s model ecosystem, observability tooling and pricing structure. As agentic AI matures, deployment flexibility (the ability to run agents on any cloud, on-prem or across hybrid environments without vendor lock-in) will separate organizations that scale from those that stall.</p>



<p>Sometimes you’ll want agents to run close to your data. Other times, you’ll want agents close to the users. And you’ll want your developers to be able to move back and forth between different agent code bases without having to learn a different framework between them.</p>



<h2 class="wp-block-heading">What CIOs should watch at Build and I/O</h2>



<p>Google I/O and Microsoft Build will dominate May with dueling AI coding announcements. The temptation will be to compare model benchmarks. That’s the wrong lens. The models are converging. The real competition is one layer down, in the infrastructure that makes AI agents viable outside of software development.</p>



<p>CIOs watching these conferences should evaluate each announcement against the six gaps: Is Microsoft closing the governance gap with Azure AI Foundry? Is Google advancing observability through Vertex AI? Which platform is making it easier to evaluate agent output at scale, maintain persistent memory across sessions, control costs at the workflow level and deploy without lock-in?</p>



<p>The company that wins the AI coding war will be the one that builds the infrastructure layer that transfers to every other enterprise function. That’s the real stakes of May’s developer conferences, and it’s the real reason CIOs should be paying attention.</p>



<h2 class="wp-block-heading">The canary’s message</h2>



<p>Software engineers are the first knowledge workers to live inside a fully agentic workflow. They’re the canary in the coal mine for every other enterprise function. And right now, the canary is singing, not dying.</p>



<p>The lesson isn’t that AI coding agents have made engineers obsolete. It’s that AI coding agents work <em>because engineers already built the infrastructure that makes agents trustworthy</em>. Governance, observability, evaluation, memory, cost controls and deployment flexibility: These aren’t nice-to-haves. They’re the reason Anthropic can ship 27 AI-generated pull requests in a day and sleep at night.</p>



<p>Every other enterprise function will need to build its own version of that infrastructure before AI agents can move from employee-facing pilots to customer-facing production. The models aren’t the bottleneck. The scaffolding around them is.</p>



<p>Anthropic paying $570K for a software engineer whose job might not exist in a year isn’t a contradiction. It’s Jevons Paradox. And it’s the most expensive leading indicator in enterprise AI.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mangelnde Eingabeprüfung in gnutls (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3484416/unix-server/security-mangelnde-eingabepruefung-in-gnutls-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484416/unix-server/security-mangelnde-eingabepruefung-in-gnutls-slackware/</guid>
<pubDate>Sun, 03 May 2026 23:45:44 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3484415/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484415/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Sun, 03 May 2026 23:45:42 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen von Code mit höheren Privilegien in kernel (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3484410/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-kernel-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484410/unix-server/security-ausfuehren-von-code-mit-hoeheren-privilegien-in-kernel-slackware/</guid>
<pubDate>Sun, 03 May 2026 23:45:35 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in mozilla-firefox (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3481694/it-security-nachrichten/mehrere-probleme-in-mozilla-firefox-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481694/it-security-nachrichten/mehrere-probleme-in-mozilla-firefox-slackware/</guid>
<pubDate>Sat, 02 May 2026 07:06:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[19 vibe coding tools for democratizing app development]]></title>
<description><![CDATA[Who doesn’t want an AI to pump out more code in minutes than a human might write in a month? Who doesn’t like magic? That’s what the hype around vibe coding has asked of developers and business users alike since its inception.



But now the tools might have matured enough to deliver.



Yes, cau...]]></description>
<link>https://tsecurity.de/de/3480063/it-nachrichten/19-vibe-coding-tools-for-democratizing-app-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480063/it-nachrichten/19-vibe-coding-tools-for-democratizing-app-development/</guid>
<pubDate>Fri, 01 May 2026 12:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Who doesn’t want an AI to pump out more code in minutes than a human might write in a month? Who doesn’t like magic? That’s what the hype around vibe coding has asked of developers and business users alike since its inception.</p>



<p>But now the tools might have matured enough to deliver.</p>



<p>Yes, cautious leaders are right in wondering, “What’s the catch? Is this a trap?” After all, the AIs learned to code from examining code created by humans, and humans fail. So it should be no surprise that some vibe coders and industry experts are reporting vulnerabilities such as undocumented endpoints and sensitive data leakage.</p>



<p>Still, many are diving right into the vibe-code deep end and are reporting positive results. The new tools, they say, are amazing. Vibe coders can build a prototype in minutes and a minimum viable product in a few iterations. In goes a few handwavy sentences, and out comes something that used to take weeks to produce — not to mention all the red tape in tapping development time, if you’re a business user. Sure there can be errors and omissions, but are they any worse than what a team of humans might inadvertently include or overlook?</p>



<p>The reality is that vibe coding is legit enough that enterprises need to start experimenting. The platforms offer numerous differences. Some are better suited to helping professional developers who often need to work with large code bases. Others want to help not-so-professional programmers who know what they want but aren’t ready to write it all by themselves. Maybe they don’t know a particular programming language or maybe they don’t know much about programming at all. Still others are aimed at complete novices who can barely turn on a computer.</p>



<p>And it’s not just the level of experience that distinguishes them. Some tackle smaller wishes —the kind of tools that professional developers can use as a “force multiplier.” Others create entire applications, from database to front-end, and they’re best for people who want to create a prototype. The architecture may not be ready to scale for a large user base, but they’re ideal for presenting to the boss or some investors. They can also do a pretty good job with a smaller collection of users.</p>



<p>Are any good enough? Can we work around their flaws? The only way to find out is to fire them up and look at the results.</p>



<p>Here is a list of 19 vibe coding tools worth checking out, in alphabetical order. They all promise to provide some amount of app-dev magic.</p>



<h2 class="wp-block-heading">Base44/Wix</h2>



<p>The process at <a href="https://base44.com/" rel="nofollow">Base44</a> (now owned by Wix) begins with a Builder Chat in which the discussion focuses on the data architecture. From there, your words guide a tool that merges React and Tailwind code for the front-end with a Deno backend. To speed things up, templates can jumpstart common use cases — ecommerce, content management, productivity, etc. Many parts of the UI can be adjusted with a drag-and-drop visual editor that can be much faster than trying to describe all your changes with words.</p>



<h2 class="wp-block-heading">Betty Blocks</h2>



<p>The developers of the <a href="https://www.bettyblocks.com/" rel="nofollow">Betty Blocks</a> no-code system say they’re targeting “citizen developers” —non-programmers who know what their corner of the enterprise needs. The platform takes a description and then produces React code that can be exported to a code repository for future development or be compiled down to WASM level deployment. They also offer a “low-code” approach that gives a visual interface for further tweaking and refinement.</p>



<h2 class="wp-block-heading">Blink</h2>



<p>The code generation agent from <a href="https://blink.new/" rel="nofollow">Blink</a> produces TypeScript React applications starting with two modes: agent mode, for building; and chat mode, for discussing and planning. Developers start with chatting and then toggle back and forth. Blink will host any application with its internal CDN or allow you to export it to your own servers or cloud.</p>



<h2 class="wp-block-heading">Bolt</h2>



<p>The no-code chat service from <a href="https://bolt.new/" rel="nofollow">Bolt</a> is designed to provide a single visual interface to various backend coding AIs. It’s possible to work with different coding agents, including some of the best-known ones, such as Anthropic’s Claude and Google’s Gemini. The design layer is broken out making it possible to create a standard design that is then adopted by any app that’s produced by the AI. An <a href="https://github.com/stackblitz/bolt.new" rel="nofollow">open-source version</a> released under the MIT license is also available.</p>



<h2 class="wp-block-heading">Bubble</h2>



<p>The no-code tool from <a href="http://bubble.io/" rel="nofollow">Bubble</a> includes several features that let human users do more than just chat. A full visual editor lets developers adjust the interface directly. A workflow view outlines much of what’s going on underneath, again making it possible for the user to do more than guess. The goal is to make humans more of a partner.</p>



<h2 class="wp-block-heading">Claude Code</h2>



<p>Anthropic’s main LLM, <a href="https://claude.com/product/claude-code" rel="nofollow">Claude</a>, is skilled in answering many programming needs, including either creating new applications or fixing old ones. The backend connects to many traditional IDEs, such as VSCode, but many users connect with Claude through a terminal window or even a Slack channel. One common use is to search through a large code base for the right place to begin fixing an issue. Many praise how it adapts to your local coding standards.</p>



<h2 class="wp-block-heading">Continue</h2>



<p>The <a href="https://github.com/continuedev/continue" rel="nofollow">open-source agent from Continue</a> is best for professional developers who need a bit of extra help vibe coding. The tool will watch a code base for triggers, such as new pull releases, and then invoke AI agents to handle many of the chores. The goal isn’t to do everything, just the most boring things, so humans can be creative. The tool integrates with many IDEs and AI APIs.</p>



<h2 class="wp-block-heading">Create</h2>



<p>The tool from <a href="http://create.xyz/" rel="nofollow">Create.xyz</a> is called Anything because they want users to be able to create any possible React/Tailwind app from a simple text prompt. The results are crafted from many stylized components for tasks such as database access that run well in either the browser or a mobile platform. Developers can then dive into the code and add any human touches.</p>



<h2 class="wp-block-heading">Cursor</h2>



<p>Many old-school developers love <a href="https://cursor.com/" rel="nofollow">Cursor</a> because it’s designed to be the assistant they’ve never had. It writes new code, audits old code, and tracks issues evolving over channels like Slack. The tool can juggle multiple files and analyze entire codebases before proposing a plan of action and then executing it. It’s not exactly fair to call it “no-code” because it’s designed to work in a traditional development environment, but many users aren’t writing much code anymore because Cursor does so much.</p>



<h2 class="wp-block-heading">Emergent</h2>



<p>The web application from <a href="http://emergent.sh/" rel="nofollow">Emergent</a> is a front-end for a team of AI agents that will turn your text description into a frontend (React), backend (Node.js), databases (MongoDB), and collection of APIs with full integrations (Stripe, etc.).The goal is not just to perform hand-holding, but to hide all the complexity of development behind a big facade. Non-developers can build everything they want while developers can knock off prototypes — all deployed in close to production-ready form.</p>



<h2 class="wp-block-heading">Kilo Code</h2>



<p>The open-source coding agent from <a href="https://kilo.ai/" rel="nofollow">Kilo</a> has a number of features that will appeal to coders maintaining and extending larger code bases. Orchestrator Mode, for instance, helps create work plans while Code Review double checks for errors. A Memory Bank stores high-level details about the project’s architecture. Connections to more than 500 models avoids lock in and lets you choose the right model that’s delivering just what you want.</p>



<h2 class="wp-block-heading">Lindy</h2>



<p>The tool from <a href="https://www.lindy.ai/" rel="nofollow">Lindy</a> focuses on creating “agents” that tend to be bits of code that sit in the background and respond to triggers like a Slack message or a new commit to a repository. There are hundreds of different web applications that can generate these events, including all major clouds and office organization sites such as Jira or Zoho. Many of the standard applications can be built more quickly by leveraging pre-defined templates. Some of the most common use cases include support agents.</p>



<h2 class="wp-block-heading">Lovable</h2>



<p>The no-code interface from <a href="https://lovable.dev/" rel="nofollow">Lovable</a> chats with you for a bit and then builds the app and deployment in Lovable’s cloud. It handles the UI (React plus Tailwind), business logic, and database (mainly Supabase). The result is one of the fastest ways to spin up an enterprise-ready prototype with a fairly polished interface and many of the security and access control features required for bigger environments.</p>



<h2 class="wp-block-heading">Replit</h2>



<p>The no-code solution from <a href="https://replit.com/" rel="nofollow">Replit</a> delivers code in up to 30 programming languages, supporting all the major languages and many of the minor ones. The main interface is a no-code chatbot, but after that it dumps the code in a repository where it can be further refined using traditional methods. The database layer is broken out and treated separately, which allows for a more traditional approach by enabling options such as a separate database for production and testing. There are enterprise features that allow a team to collaborate as they chat together to improve the app.</p>



<h2 class="wp-block-heading">Softgen</h2>



<p>The tool for creating full Next.js web apps from <a href="https://softgen.ai/" rel="nofollow">Softgen</a> works with several of the major models, such as Claude 4.5 or Gemini, to turn a basic text description into a full minimum viable product. A pay-as-you-go option allows you to pay for only the tokens your application requires.</p>



<h2 class="wp-block-heading">Solid</h2>



<p>Creating basic applications isn’t too hard anymore. <a href="https://trysolid.com/" rel="nofollow">Solid</a> emphasizes creating apps that offer “enterprise-grade” deployments with top-notch security models and distributed deployment. The documentation emphasizes working iteratively with the AI and playing to its strengths, which is crafting a React/Tailwind front end with a wide variety of backends that generally mean TypeScript code running on Node.js with PostgreSQL.</p>



<h2 class="wp-block-heading">Tempo Labs</h2>



<p>The visual editor from Tempo Labs aims to allow human users to create a React app ten times faster. Simple visual tasks can be performed without relying on the AI. The tool emphasizes design and maintains a library of standard elements for each project. Any React code base can be imported and extended with predeveloped components and templates. It’s an editor that lets you vibe.</p>



<h2 class="wp-block-heading">Vercel</h2>



<p>The<a href="https://v0.app/" rel="nofollow"> v0 system </a>from Vercel offers a large collection of templates as a foundation for any app designer. The main interface is still a chat box that accepts any designs, but the templates act as both inspiration and a shared language for writing the specifications. There are also design templates that make it simpler to harmonize several different applications by allowing you to define a look once and then reuse it easily. The templates are also focused on mobile browsers to make it simpler to create mobile-ready sites.</p>



<h2 class="wp-block-heading">Windsurf</h2>



<p>Teams working with big code bases can use <a href="https://windsurf.com/" rel="nofollow">Windsurf</a>, an IDE with embedded AI that’s designed to handle longer, multi-step plans for fixing bugs or adding features to a code base. It’s vibe coding, but focused on assisting traditional techniques. The tab key in the Windsurf IDE is quite powerful. As you hit the tab key, it moves from suggested fix to suggested fix waiting for you to signal your approval by hitting it again. The IDE aims to produce multistep plans that it calls “cascades.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Musk faces third day of questioning in contentious trial over OpenAI’s founding]]></title>
<description><![CDATA[Trial continues after heated back and forth during OpenAI’s cross-examination of the Tesla CEO on WednesdayElon Musk’s court case against Sam Altman continues on Thursday, after a day of contentious exchanges during OpenAI’s cross-examination of the Tesla CEO. Musk will face another round of ques...]]></description>
<link>https://tsecurity.de/de/3478300/ai-nachrichten/musk-faces-third-day-of-questioning-in-contentious-trial-over-openais-founding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478300/ai-nachrichten/musk-faces-third-day-of-questioning-in-contentious-trial-over-openais-founding/</guid>
<pubDate>Thu, 30 Apr 2026 18:18:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Trial continues after heated back and forth during OpenAI’s cross-examination of the Tesla CEO on Wednesday</p><p>Elon Musk’s court case against Sam Altman continues on Thursday, after a day of <a href="https://www.theguardian.com/technology/2026/apr/29/elon-musk-openai-sam-altman-lawsuit">contentious exchanges</a> during OpenAI’s cross-examination of the Tesla CEO. Musk will face another round of questioning before his lawyer calls more witnesses, including OpenAI’s president, Greg Brockman.</p><p>Witness testimony and evidence has revealed formerly private emails, text messages and diary entries surrounding the formation of OpenAI, giving a behind-the-scenes look at how the tech behemoth was created. Many of the tech industry’s most powerful players are named as witnesses and will give their account on the origins of Musk and Altman’s bitter feud. Altman is set to testify later in the trial, which will last three weeks.</p> <a href="https://www.theguardian.com/technology/2026/apr/30/openai-founding-trial-elon-musk-sam-altman">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iodyne Pro Data 24TB review: $15K, ridiculous speed, and probably not for you]]></title>
<description><![CDATA[The Iodyne Pro Data 24TB delivers enormous uninterrupted transfer speed, isn't network attached, and it isn't limited to one user. It's also a $14,995 wallet-breaking money-saver for the right audience.Iodyne Pro Data 24TBIt's not every day we get a second loaner for a review product years after ...]]></description>
<link>https://tsecurity.de/de/3476026/ios-mac-os/iodyne-pro-data-24tb-review-15k-ridiculous-speed-and-probably-not-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476026/ios-mac-os/iodyne-pro-data-24tb-review-15k-ridiculous-speed-and-probably-not-for-you/</guid>
<pubDate>Thu, 30 Apr 2026 02:08:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Iodyne Pro Data 24TB delivers enormous uninterrupted transfer speed, isn't network attached, and it isn't limited to one user. It's also a $14,995 wallet-breaking money-saver for the right audience.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67499-142088-iodyneprodata24tbreview1-xl.jpg" alt="Dark gray rectangular external hard drive with smooth surface, ribbed section on one end for ventilation or grip, and subtle embossed IO logo, resting on a light-colored desk"><br><span>Iodyne Pro Data 24TB</span></div><br>It's not every day we get a second loaner for a review product years after the fact.<br><br>The market has changed, workflows have changed, since we first reviewed the Iodyne Pro Data. Video workflows are getting bigger and bigger with 8K HDR 3D, and so forth. A single iPod like the <em>Lord of the Rings</em> dailies were shuttled around on are a thing of the past.<br><br><br> <a href="https://appleinsider.com/articles/26/04/29/iodyne-pro-data-24tb-review-15k-ridiculous-speed-and-probably-not-for-you?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244199?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Vision Pro Used in World’s First Cataract Surgery Case]]></title>
<description><![CDATA[A New York eye doctor just completed the first cataract surgery ever performed using a mixed reality headset. Dr. Eric Rosenberg from SightMD used the Apple Vision Pro to see clearly inside a patient's eye during the delicate operation. After finishing the initial surgery back in October 2025, th...]]></description>
<link>https://tsecurity.de/de/3475181/ios-mac-os/apple-vision-pro-used-in-worlds-first-cataract-surgery-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475181/ios-mac-os/apple-vision-pro-used-in-worlds-first-cataract-surgery-case/</guid>
<pubDate>Wed, 29 Apr 2026 18:38:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A New York eye doctor just completed the first cataract surgery ever performed using a mixed reality headset. Dr. Eric Rosenberg from SightMD used the Apple Vision Pro to see clearly inside a patient's eye during the delicate operation. After finishing the initial surgery back in October 2025, the medical group announced that its doctors had successfully repeated the process for hundreds of additional cases.



Custom software streams live microscope video directly into the headset



To make this work, the doctor relies on a program called ScopeXR. This software connects with standard digital microscopes normally found in operating rooms. It sends a live, three-dimensional video feed straight into the Apple device. This setup allows the surgeon to see the eye in full depth while also viewing important patient data floating nearby.



Because the program is built to work with equipment that hospitals already own, it makes adoption much easier. The medical group says its main goal is to bring helpful tools into the surgery room without forcing locations to buy entirely new camera systems.



By simply plugging into the existing microscope, the doctor gets a clear and immediate view of the procedure.



The system lets other doctors watch and help from anywhere



Another big benefit of the Vision Pro setup is how it handles remote viewing. Other surgeons and medical students can connect to the live feed and see exactly what the main doctor sees in real time. They can even talk back and forth during the operation to offer advice or answer questions.



This remote access completely changes how medical students learn to do eye surgery. Instead of crowding around a single monitor or trying to look over a shoulder, a student can watch the entire process up close from a different room.



SightMD expects this approach to become much more common as the technology gets cheaper and lighter in the future.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Adds Nine Claude Connectors For Popular Creative Apps]]></title>
<description><![CDATA[People who use heavy creative software to draw, edit photos, or build 3D models have a helpful new tool. Anthropic just released nine brand new software connectors that link its popular Claude chatbot directly into major creative applications. The company wants to make it much easier for digital ...]]></description>
<link>https://tsecurity.de/de/3474620/ios-mac-os/anthropic-adds-nine-claude-connectors-for-popular-creative-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474620/ios-mac-os/anthropic-adds-nine-claude-connectors-for-popular-creative-apps/</guid>
<pubDate>Wed, 29 Apr 2026 15:28:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[People who use heavy creative software to draw, edit photos, or build 3D models have a helpful new tool. Anthropic just released nine brand new software connectors that link its popular Claude chatbot directly into major creative applications. The company wants to make it much easier for digital artists and everyday designers to use helpful artificial intelligence tools without constantly switching back and forth between different computer windows.



The new plugins bring smart tools into popular design software



These new plugins work inside heavy hitters like Adobe, Autodesk, Blender, Canva, and Affinity. Before this update, if an artist wanted to ask a question or generate a prompt, they had to open a separate web browser. Now, the smart chatbot lives right inside the actual workspace menu.



By building direct connections into the panels of these apps, Anthropic allows users to quickly generate fresh ideas or fix messy project files. It designed the AI integration to handle the boring technical details so humans can spend more time actually being creative.



This update is especially useful for people who do not know how to code. For example, a 3D artist using Blender can simply type a quick command and let the software write a complex script for rendering a busy scene.



Anthropic wants to help artists work faster and avoid distractions



Every time a designer leaves a digital canvas to search for help, focus is lost. The company hopes these nine new connectors will completely solve that problem. It built these direct links to keep creative people in the zone while they work on massive daily projects.



These new bridges are rolling out to internet users right now. You just need to download the specific plugin for the design software you already use on your desktop. The setup process only takes a few minutes from start to finish.



It is a very big step for Anthropic as it tries to make its chatbot the top choice for visual workers across the country. Whether you edit photos or build video games, the tech firm wants to be your main helper.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in proftpd (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3471917/unix-server/security-ausfuehren-beliebiger-kommandos-in-proftpd-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471917/unix-server/security-ausfuehren-beliebiger-kommandos-in-proftpd-slackware/</guid>
<pubDate>Tue, 28 Apr 2026 18:15:55 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (openjdk-21 and webkit2gtk), Fedora (botan3, chromium, cockpit, firefox, flatpak, gum, libarchive, libcoap, mingw-python3, ngtcp2, nss, openssh, openssl, openvpn, PackageKit, python3-docs, python3.11, python3.12, python3.13, python3.14, vim, and xrdp), ...]]></description>
<link>https://tsecurity.de/de/3471376/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471376/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 28 Apr 2026 15:26:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (openjdk-21 and webkit2gtk), <b>Fedora</b> (botan3, chromium, cockpit, firefox, flatpak, gum, libarchive, libcoap, mingw-python3, ngtcp2, nss, openssh, openssl, openvpn, PackageKit, python3-docs, python3.11, python3.12, python3.13, python3.14, vim, and xrdp), <b>Oracle</b> (firefox, gdk-pixbuf2, java-1.8.0-openjdk, java-21-openjdk, python3.12, python3.9, sudo, and tigervnc), <b>Red Hat</b> (tigervnc and xorg-x11-server-Xwayland), <b>Slackware</b> (mpg123 and proftpd), <b>SUSE</b> (emacs, firefox, fontforge, freeciv, freerdp, libngtcp2-16, libsystemd0, and strongswan), and <b>Ubuntu</b> (authd, clamav, glance, haproxy, jq, lcms2, nginx, nltk, ntfs-3g, packagekit, pillow, strongswan, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Galaxy AI for business: Productivity meets security]]></title>
<description><![CDATA[I keep hearing the same push: start using AI in your workflows. But that’s easier said than done! In enterprise environments, AI isn’t just a quick productivity fix—it also raises harder questions around data control, governance, and risk.



According to IDC, 42% of organizations cite concerns a...]]></description>
<link>https://tsecurity.de/de/3471334/it-nachrichten/samsung-galaxy-ai-for-business-productivity-meets-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471334/it-nachrichten/samsung-galaxy-ai-for-business-productivity-meets-security/</guid>
<pubDate>Tue, 28 Apr 2026 15:17:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I keep hearing the same push: <strong>start using AI in your workflows.</strong> But that’s easier said than done! In enterprise environments, AI isn’t just a quick productivity fix—it also raises harder questions around data control, governance, and risk.</p>



<p><a href="http://chrome-extension//efaidnbmnnnibpcajpcglclefindmkaj/https://info.idc.com/rs/081-ATC-910/images/US-IDC-RE-AI-Everywhere-eBook.pdf" target="_blank" rel="sponsored">According to IDC, 42% of organizations</a> cite concerns about GenAI jeopardizing control of data and intellectual property as a major barrier to adoption. <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn1">[1]</a></p>



<p>I think that’s the real issue for CIOs now—not whether to invest in AI, but how to use it in ways that improve productivity without creating new security, compliance, and management concerns. </p>



<p>That’s where <strong>Galaxy AI for business</strong> comes in.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/Samsung-Galaxy-AI-For-Business_-Productivity-Meets_Security-_-CIO-AI-For-Business_-Productivity-Meets-Security-_-CIO-Pillar_1_16x9.png?w=1024" alt="An illustration of a smartphone using the Circle to Search gesture on a coffee machine, with related results displayed on a webpage next to it." class="wp-image-4163061" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Samsung </p></div>



<h2 class="wp-block-heading"><strong>Increase productivity throughout the workday</strong></h2>



<p></p>



<p>A lot of AI value depends on whether it actually saves time during the workday. I’ve noticed that inefficiencies tend to show up in the same parts of the workflow: piecing together fragmented information (bonus points if it’s across different platforms!), figuring out what actually mattered in a meeting, losing time to research and source-checking, and identifying action items for your team.</p>



<p>None of it sounds particularly time-consuming on its own, but together, it can quietly add up to a meaningful amount of lost productivity. </p>



<p><a href="https://www.samsung.com/us/business/galaxy-ai/#higher-productivity" target="_blank" rel="sponsored">Galaxy AI tackles those routine pain points in a few key ways:</a></p>



<ul class="wp-block-list">
<li><strong>Start with better context: Now Brief</strong> <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn2">[2]</a> brings timely information together at a glance, helping employees get ready for the day faster.</li>



<li><strong>Capture meeting takeaways faster: Note Assist</strong> <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn3">[3]</a> and <strong>Transcript Assist</strong> <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn4">[4]</a> organize notes, generate summaries, support translations, and turn recordings into more usable outputs.</li>



<li><strong>Find information faster: Browsing Assist</strong> and <strong>Circle to Search</strong> <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn5">[5]</a> make research, source-checking, summarizing, and translation easier without interrupting workflows.</li>



<li><strong>Turn insights into action:</strong> <strong>Google Gemini</strong> <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn6">[6]</a> supports deeper research, live on-screen assistance, and seamless actions across apps.</li>
</ul>



<p><strong>TLDR:</strong> Galaxy AI helps reduce routine bottlenecks, making day-to-day work more organized, efficient, and easier to move through.</p>



<h2 class="wp-block-heading"><strong>Simplify communication across the business</strong></h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/Samsung-Galaxy-AI-For-Business_-Productivity-Meets_Security-_-CIO-AI-For-Business_-Productivity-Meets-Security-_-CIO-Pillar_2_16x9.png?w=1024" alt="An illustration of a smartphone displaying a language selection pop-up with English selected and Korean listed below, beside a webpage with text blocks." class="wp-image-4163065" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Samsung </p></div>



<p>Communication has a way of getting messy in ordinary, unremarkable ways. A call moves too quickly, and someone misses a key detail. A message needs to be translated, then rewritten so it still sounds natural. The one that gets me the most is reworking the same email draft over and over because the tone is somehow still off. </p>



<p>If this sounds familiar, that’s because it is—and when it keeps happening across calls, chats, and teams, it eats up more of the workday than it should.</p>



<p><a href="https://www.samsung.com/us/business/galaxy-ai/#barrier-free-conversations" target="_blank" rel="sponsored">This is where Galaxy AI can cut down on that unnecessary back-and-forth:</a></p>



<ul class="wp-block-list">
<li><strong>Break through language barriers: Call Assist</strong> and <strong>Interpreter </strong>support real-time translation for calls and face-to-face conversations in supported languages.<a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn7">[7]</a></li>



<li><strong>Capture key points faster: Call Transcript</strong> turns recorded calls into searchable text and concise summaries.</li>



<li><strong>Keep multilingual messaging moving: Chat Translate</strong> makes it easier to send messages across languages. </li>



<li><strong>Draft more polished business writing: Style and Tone</strong> and <strong>Composer </strong>help refine grammar, adjust tone, and create more professional emails and messages.</li>
</ul>



<p><strong>TLDR:</strong> Galaxy AI reduces communication delays by helping teams communicate across languages and spend less time revisiting calls or reworking messages, enabling them to stay clear, responsive, and aligned.</p>



<h2 class="wp-block-heading"><strong>Keep AI on enterprise terms</strong></h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/Samsung-Galaxy-AI-For-Business_-Productivity-Meets_Security-_-CIO-AI-For-Business_-Productivity-Meets-Security-_-CIO-Pillar_3_16x9.png?w=1024" alt="An illustration of a smartphone displaying a folder containing documents, next to a cloud with a prohibition symbol and a toggle set to on." class="wp-image-4163066" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Samsung </p></div>



<p>Finally, we need to address the elephant in the room for AI adoption. Once employees start using AI to summarize meeting notes, process internal information, or speed up every day work, enterprises need to know where that data goes (like whether it’s retained or used for model training) and how much control IT actually has. </p>



<p><a href="https://www.samsung.com/us/business/galaxy-ai/#secure-ai" target="_blank" rel="sponsored">To address those concerns, Galaxy AI is built around a few important safeguards:</a></p>



<ul class="wp-block-list">
<li><strong>Start from a secure device foundation: </strong>Samsung Galaxy devices are protected by <a href="https://www.samsungknox.com/en" target="_blank" rel="sponsored">Samsung Knox,</a> with multi-layered protection across hardware and software from the moment the device powers on. </li>



<li><strong>Give sensitive workflows a more secure path:</strong> Compatible Galaxy AI features can use <strong>on-device processing</strong> to keep key tasks and data on the device, while <a href="https://docs.samsungknox.com/admin/knox-platform-for-enterprise/knox-service-plugin/welcome/" target="_blank" rel="sponsored">Knox Service Plugin</a> lets admins disable cloud processing for compatible features. For cloud-based Galaxy AI features, data isn’t retained by Samsung or Google or used for model training. </li>



<li><strong>Keep business AI use tied to the company: Samsung Account for Business</strong> lets employees use Galaxy AI through company-managed accounts, so corporate data stays with the organization rather than the individual. That means AI use for work doesn’t walk out the door with a personal account when an employee leaves. </li>
</ul>



<p><strong>TLDR:</strong> Galaxy AI helps reduce one of the biggest barriers to enterprise AI adoption by giving organizations clearer guardrails around data handling, cloud exposure, and IT oversight.</p>



<h2 class="wp-block-heading"><strong>Take the next step with Galaxy AI for business</strong></h2>



<p></p>



<p>By now, we know that AI can save time. The harder question is whether those benefits can be delivered <strong>without </strong>losing control over security, access, and device management.</p>



<p>Galaxy AI for business starts to answer that by combining productivity features with stronger security and more deliberate IT oversight. </p>



<p>Ready to adopt mobile AI into your enterprise workflows with more security and control? <a href="https://www.samsung.com/us/business/galaxy-ai/" target="_blank" rel="sponsored">Explore Galaxy AI for business</a> <a href="https://www.cio.com/article/4163021/samsung-galaxy-ai-for-business-productivity-meets-security.html#_ftn8">[8]</a> to see how it can support your organization.</p>



<p>[1] Source: IDC, Are You Ready for AI Everywhere?, October 2023. Based on IDC GenAI Awareness, Readiness and Commitment Survey.</p>



<p>[2] The information displayed in Now Brief may vary depending on apps used. Some apps may require internet connection and user consent for data access. Personal data intelligence must be enabled.</p>



<p>[3] Note Assist features are available only within Samsung Notes. A Samsung account login and internet connection are required. Text input may be limited to 200-4,000 characters.</p>



<p>[4] Transcript Assist is only available only with recordings using Samsung Voice Recorder and audio files under three hours. Summarizing features are available for text in Samsung Notes only, with input limits of 200-4,000 characters. Translation features require language presets, a Samsung account login, and an internet connection. Results and quality may vary depending on input and recording conditions.</p>



<p>[5] Circle to Search works with compatible apps and requires an internet connection. Results may vary depending on visual matches.</p>



<p>[6] Google Gemini is a trademark of Google LLC. Gemini Live features require an internet connection and a Google account login. Feature availability may vary depending on subscription, region, and device. Accuracy of results isn’t guaranteed, and use is limited to users 18 years and older.</p>



<p>[7] Call Assist and Interpreter features availability and supported languages may vary by region. A Samsung account may be required, and some language may need to be downloaded. For details on supported languages by feature, visit the <a href="https://www.samsung.com/us/galaxy-ai/" target="_blank" rel="sponsored">Samsung Galaxy AI page.</a></p>



<p>[8] A Samsung account login may be required to use certain AI features. Samsung doesn’t make any processes, assurances, or guarantees as to the accuracy, completeness, or reliability of the output provided by AI features. Availability of Galaxy AI features may vary by device model. Galaxy AI features will be provided for free until the end of 2025 on supported Samsung Galaxy devices. Different terms may apply for AI features by third parties. Galaxy AI features may be limited for minors in certain regions with age restrictions on AI usage.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in mpg123 (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3469927/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-mpg123-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469927/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-mpg123-slackware/</guid>
<pubDate>Tue, 28 Apr 2026 06:54:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Show Your Work: The Case for Radical AI Transparency]]></title>
<description><![CDATA[A colleague told me something recently that I keep thinking about. She said, unprompted, that she appreciated seeing both sides of my AI conversations. Not just the output. The full thread. My prompts, the AI’s responses, the back and forth, the dead ends, the iterations. She said it made her tru...]]></description>
<link>https://tsecurity.de/de/3467867/ai-nachrichten/show-your-work-the-case-for-radical-ai-transparency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3467867/ai-nachrichten/show-your-work-the-case-for-radical-ai-transparency/</guid>
<pubDate>Mon, 27 Apr 2026 13:33:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A colleague told me something recently that I keep thinking about. She said, unprompted, that she appreciated seeing both sides of my AI conversations. Not just the output. The full thread. My prompts, the AI’s responses, the back and forth, the dead ends, the iterations. She said it made her trust me more. This piece […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Phishing Still Works (Even If You Know About It)]]></title>
<description><![CDATA[In the world of cybersecurity, There is a famous line that says:“Humans are the most weakest link in any security architecture”Even during expert lectures, workshops, events or even our regular mentor lectures, we have been told that “In any organization, the weakest point of their security is hu...]]></description>
<link>https://tsecurity.de/de/3465013/hacking/why-phishing-still-works-even-if-you-know-about-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465013/hacking/why-phishing-still-works-even-if-you-know-about-it/</guid>
<pubDate>Sun, 26 Apr 2026 05:21:21 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/800/1*h8TBH2NCi0ez2UkkniWtcw.png"></figure><p>In the world of cybersecurity, There is a famous line that says:</p><blockquote>“H<strong>umans are the most weakest link in any security architecture</strong>”</blockquote><p>Even during <strong>expert lectures</strong>, <strong>workshops</strong>, <strong>events </strong>or even our regular <strong>mentor lectures</strong>, we have been told that “<strong><em>In any organization, the weakest point of their security is humans!</em></strong>”.</p><p>But why is that the humans have been considered as <strong>weakest link</strong>? In this blog we will go through every aspect related to phishing and what it has to do with humans?</p><p>Be ready with your curiosity, My name is Prince Gokhale, I’m a cybersecurity enthusiast, a content writer and a security researcher, even i have received so many phishing messages and emails, and <strong>almost fall for that !!!</strong></p><p>So, let’s start with understanding what phishing is?</p><h3>What is Phishing?</h3><p>In simple words, Phishing is an attack that uses <strong>social engineering</strong> to trick <strong>people </strong>into doing something <strong>harmful</strong>, like giving up <strong>sensitive information</strong> (e.g., credentials, intellectual property, banking information).</p><h3>What is the role of humans in phishing ?</h3><p><strong>Humans </strong>are the actual <strong>target </strong>of the phishing. Any other cyber attack usually targets systems, security architecture, rules, protocols or service, but <strong><em>Phishing targets Humans</em></strong>.</p><h3>Why humans are the weakest link in any security architecture?</h3><p>People are “<em>distracted”</em>. They click links in a hurry. Unlike network controls or firewall’s rules, people have <strong>emotions</strong>, <strong>distraction</strong>, and varying levels of <strong>awareness</strong>.</p><p>Unlike any system in which we can <strong>strictly implement securtiy rules </strong>and guidelines through which we can almost make them most secure, People will always be the <em>weakest point</em> because they can make <strong>mistakes</strong>, they can be <strong>distracted</strong>, they can be <strong>manipulated</strong>, and they can be <strong>misguided</strong>.</p><h3>Common Phishing Terminologies</h3><p>Understanining phishing terminology will help you identify different attack methods in <strong>real-world scenarios</strong>.</p><ul><li><strong>Pretext</strong>: A <strong>fake scenario </strong>created by an attacker that seems real. Example: You received an email with a title “<em>We’ve detected a suspicous login attempt on your account</em>”.</li><li><strong>Payload</strong>: A<strong> file or link</strong> used to infect a device, steal credentials, or do various bad things.</li><li><strong>Man-in-The-Middle (MiTM)</strong>: A way to <strong>intercept </strong>communications between two parties. In phishing, this usually involves <strong>intercepting </strong>the authentication flow between<strong> a user</strong> and<strong> a provider</strong> (like Microsoft or a VPN service) to capture login credentails and multi-factor authentication tokens.</li></ul><h3>Why Phishing Still Works Even If You Know About It?</h3><p>I am a cybersecurity person, i always assure before opening any link received from anyone, whether they are unknown, my friends or even the close ones. Still i almost got fall for an phishing link.</p><p>To understand this,<em> we have to understand what makes phishing so harmful?</em></p><p>Phishing actually targets human <strong>emotions </strong>such as,</p><ul><li>Urgency</li><li>Greed</li><li>Fear</li><li>Anger</li><li>Panic</li><li>Curiosity</li></ul><p>Manipulating human emotions is an <strong>undeniable skill </strong>for phishing!</p><p>This is why,</p><blockquote>“Phishing is more Psychological instead of technical”</blockquote><h3>How phishing is done and How a Phishing payload is constructed?</h3><h4>The first is: Pretext</h4><p>The attacker creates a <strong>scenario </strong>that seems real. Not just that, but it also shows emotions. You can review below <strong>pretext </strong>from real phishing messages/emails that expresses human <strong>emotions</strong>.</p><ul><li>We Detected Suspicious Activity on Your Account — (<strong>Fear</strong>)</li><li>Your KYC Has Expired — (<strong>Authority + Panic</strong>)</li><li>Income Tax Refund Pending — (<strong>Greed + Trust</strong>)</li><li>COVID Emergency Assistance — (<strong>Hope + Fear</strong>)</li></ul><h4>Second is: Engagement</h4><p>This phase involves <strong>user’s interactoin</strong> and <strong>hook</strong>, in which Victim takes the <strong>bait </strong>(actual payload)</p><ul><li>Clicks the link</li><li>Replies to the message</li><li>Answers the call</li><li>Downloads the file</li></ul><h4>Third is: Delivery Mechanism</h4><p>Attacker can use one of many <strong>delivery mechanism</strong> to deliver his phishing <strong>payload</strong>. This showcases How the attack <strong>reaches the victim</strong>,</p><ul><li>Email</li><li>SMS (smishing)</li><li>WhatsApp</li><li>Phone call (vishing)</li><li>QR code</li><li>Fake ads</li></ul><blockquote>Note: “The main thing here is that: <strong>Pretext </strong>+ <strong>delivery </strong>must <strong>feel <em>natural</em></strong><em> </em><strong><em>together</em></strong>.”</blockquote><h4>Forth is: Exploitation</h4><p>This involves the actual <strong>damage done </strong>by an attacker</p><ul><li>Credential harvesting</li><li>OTP capture</li><li>Session hijacking</li><li>Malware execution</li><li>UPI collect abuse</li></ul><blockquote>“Pretext gains attention. Engagement gains access. Exploitation causes damage.”</blockquote><h3>What are the different types of phishing?</h3><p>As the new <strong>technologies </strong>are coming and <strong>platforms </strong>are evolving, many <strong>variants of phishing </strong>attacks also introducing. But the <strong>main core</strong> ideal types are given below which <strong>covers </strong>almost every phishing attacks variants.</p><ul><li><strong>Email Phishing</strong>: Fake emails impersonating trusted brands to steal credentials or deliver malware.</li><li><strong>Spear Phishing</strong> — Highly targeted phishing crafted using personal or organizational information.</li><li><strong>Whaling</strong> — Spear phishing aimed specifically at executives or high-value decision-makers.</li><li><strong>Whaling</strong> — Spear phishing aimed specifically at executives or high-value decision-makers.</li><li><strong>Smishing</strong> — Phishing attacks delivered via SMS or messaging apps with malicious links or requests.</li><li><strong>Vishing</strong> — Voice-based phishing where attackers manipulate victims through phone calls.</li></ul><h3>How to Protect Yourself from Phishing Attacks</h3><p>Now, we know that how <strong>dangerous phishing</strong> attack can be and how it tricks people to do harmful things by manipulating their emotions, Here are some steps you can follow to protect yourself from phishing attacks,</p><ul><li><strong>Pause before you act</strong> — Phishing succeeds on urgency; slowing down breaks the attack.</li><li><strong>Never click links from messages</strong> — Access websites by typing the official URL yourself.</li><li><strong>Check sender identity, not just the name</strong> — Display names lie; email addresses and domains matter.</li><li><strong>Don’t trust screenshots, logos, or design</strong> — Visual accuracy is easy to fake.</li><li><strong>Never share OTPs or recovery codes</strong> — No legitimate service will ever ask for them.</li><li><strong>Use a password manager</strong> — It won’t autofill credentials on fake websites.</li><li><strong>Enable multi-factor authentication (MFA)</strong> — Prefer app-based or hardware keys over SMS.</li><li><strong>Verify through a second channel</strong> — Call or message the person using a known contact method.</li><li><strong>Be cautious of small payments</strong> — Low amounts are often used to test trust.</li><li><strong>Avoid scanning random QR codes</strong> — Treat QR codes like unknown links.</li><li><strong>Keep devices and browsers updated</strong> — Many phishing attacks rely on outdated software.</li><li><strong>Limit public information online</strong> — Oversharing helps attackers craft believable pretexts.</li><li><strong>Report and delete suspicious messages</strong> — Reporting helps protect others and improves filters.</li></ul><blockquote>“Phishing can’t be patched with software alone — it requires awareness, verification, and discipline.”</blockquote><h3>Conclusion</h3><p>Phishing has evolved into a <strong>subtle </strong>and <strong>highly effective attack</strong> that blends technical deception with <strong>human psychology</strong>. It no longer relies on obvious mistakes but on familiarity, urgency, and trust — making even cautious users vulnerable when they act without pausing to verify.</p><p>Understanding how phishing works is only the first step. Real defense comes from recognizing patterns, questioning unexpected requests, and learning from shared experiences. If you’ve ever received a suspicious message or narrowly avoided a scam, your experience matters — because every real story helps others recognize the next attack faster.</p><h4>What’s coming next:</h4><ul><li>Analysis of a real phishing message I personally received and how it was identified</li><li>Practical methods and tools to examine suspicious links, files, and domains</li><li>A live simulation of how attackers clone legitimate websites for phishing</li><li>Step-by-step construction of a convincing phishing email from an attacker’s perspective</li></ul><p>👉 <strong>Have you ever encountered a phishing attempt that almost fooled you — or did fool you?</strong><br> Share your experience in the comments. Your insight might prevent someone else from becoming the next victim.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=74a0b4c2b8f5" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/why-phishing-still-works-even-if-you-know-about-it-74a0b4c2b8f5">Why Phishing Still Works (Even If You Know About It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Physicists Revive 1990s Laser Concept To Propose a Next-Generation Atomic Clock]]></title>
<description><![CDATA[Physicists have proposed a new kind of atomic clock based on a revived superradiant laser concept that could produce an extraordinarily stable signal with a linewidth around 100 microhertz, potentially the narrowest ever for an optical laser. "The implications of this result could stretch well be...]]></description>
<link>https://tsecurity.de/de/3463873/it-security-nachrichten/physicists-revive-1990s-laser-concept-to-propose-a-next-generation-atomic-clock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463873/it-security-nachrichten/physicists-revive-1990s-laser-concept-to-propose-a-next-generation-atomic-clock/</guid>
<pubDate>Sat, 25 Apr 2026 13:06:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Physicists have proposed a new kind of atomic clock based on a revived superradiant laser concept that could produce an extraordinarily stable signal with a linewidth around 100 microhertz, potentially the narrowest ever for an optical laser. "The implications of this result could stretch well beyond timekeeping," reports Phys.org. "A laser immune to environmental frequency shifts would be a powerful tool in optical interferometry -- using interference patterns in light to make ultra-precise measurements." From the report: In a conventional laser, a mirrored cavity bounces light back and forth between atoms, building up a bright, coherent beam. A superradiant laser works differently: rather than relying on the cavity to maintain coherence, the atoms themselves act as single coordinated emitters, collectively synchronizing their light emission. Following early theoretical ideas emerged in the 1990s, the concept didn't gain concrete traction until 2008, when researchers at the University of Colorado proposed that superradiant lasers could serve as a new kind of atomic clock.
 
Atomic clocks work by using laser light to probe a very precise transition in an atom, causing electrons to transition between energy levels at an extraordinarily stable frequency. Because a superradiant laser stores its coherence in the atoms rather than the cavity, its output frequency is far less vulnerable to environmental disturbances like vibrations or temperature fluctuations. Yet although this concept was first demonstrated experimentally in 2012 in a pulsed regime, the influence of heating has so far held superradiant lasers back from their full potential. To keep the laser running continuously as an atomic clock requires, atoms must be constantly replenished with energy. Doing this atom-by-atom delivers random kicks that heat the atomic sample and disrupt the lasing process, confining it to brief pulses rather than a steady beam.
 
In their study, Reilly's team considered whether a modification to earlier theoretical concepts could make a continuous laser suitable for an atomic clock. In almost all previous studies, atoms were treated as simple two-level systems: an electron sitting in a ground state, occasionally jumping up to an excited state and back again. The team proposed that the heating problem could be solved by adding one extra ground state to the picture. In a two-level system, if both the pumping (re-energizing) and decay processes happen collectively through the cavity, the mathematics constrains the system in a way that prevents stable, continuous lasing. But with three levels available, pumping and decay can operate on entirely separate transitions, breaking that constraint and allowing the collective approach to work. The findings have been published in the journal Physical Review Letters.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Physicists+Revive+1990s+Laser+Concept+To+Propose+a+Next-Generation+Atomic+Clock%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F04%2F25%2F005216%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F04%2F25%2F005216%2Fphysicists-revive-1990s-laser-concept-to-propose-a-next-generation-atomic-clock%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/04/25/005216/physicists-revive-1990s-laser-concept-to-propose-a-next-generation-atomic-clock?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (firefox-esr, flatpak, ngtcp2, ntfs-3g, packagekit, python-geopandas, simpleeval, strongswan, and xdg-dbus-proxy), Fedora (chromium, cups, curl, jq, opkssh, perl-Net-CIDR-Lite, python-cbor2, python-pillow, tinyproxy, xdg-dbus-proxy, and xorg-x11-server-...]]></description>
<link>https://tsecurity.de/de/3454931/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454931/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 22 Apr 2026 15:06:02 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (firefox-esr, flatpak, ngtcp2, ntfs-3g, packagekit, python-geopandas, simpleeval, strongswan, and xdg-dbus-proxy), <b>Fedora</b> (chromium, cups, curl, jq, opkssh, perl-Net-CIDR-Lite, python-cbor2, python-pillow, tinyproxy, xdg-dbus-proxy, and xorg-x11-server-Xwayland), <b>Slackware</b> (libXpm and mozilla), <b>SUSE</b> (botan, chromium, clamav, cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-subscriptions, dovecot24, firefox, flatpak, freeipmi, gdk-pixbuf, glibc, gnome-remote-desktop, go1.25, go1.26, go1.26-openssl, google-cloud-sap-agent, gosec, graphicsmagick, haproxy, kernel, libpng16, libraw, libtasn1, libvncserver, ncurses, nebula, nodejs24, openssl-3, ovmf, pam, pcre2, perl-Authen-SASL, pgvector, plexus-utils, podman, python-cbor2, python-cryptography, python-django, python-gi-docgen, python-pypdf2, python-python-multipart, python311, python311-PyPDF2, python313, qemu, roundcubemail, rust1.94, sqlite3, strongswan, systemd, tar, tigervnc, util-linux, vim, webkit2gtk3, xorg-x11-server, xwayland, and zlib), and <b>Ubuntu</b> (commons-io, libcap2, ntfs-3g, and rapidjson).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-firefox (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3453473/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3453473/unix-server/security-mehrere-probleme-in-mozilla-firefox-slackware/</guid>
<pubDate>Wed, 22 Apr 2026 07:01:18 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in mozilla-thunderbird (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3453471/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3453471/unix-server/security-mehrere-probleme-in-mozilla-thunderbird-slackware/</guid>
<pubDate>Wed, 22 Apr 2026 07:01:16 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in libXpm (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3453470/unix-server/security-preisgabe-von-informationen-in-libxpm-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3453470/unix-server/security-preisgabe-von-informationen-in-libxpm-slackware/</guid>
<pubDate>Wed, 22 Apr 2026 07:01:14 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, delve, freerdp, giflib, go-rpm-macros, libarchive, and openexr), Debian (gimp, imagemagick, luanti, mapserver, mupdf, opam, perl, pillow, postgresql-13, and tiff), Fedora (aqualung, awstats, curl, incus, mac, mbedtls, ...]]></description>
<link>https://tsecurity.de/de/3448469/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3448469/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 20 Apr 2026 15:41:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 8.0, .NET 9.0, delve, freerdp, giflib, go-rpm-macros, libarchive, and openexr), <b>Debian</b> (gimp, imagemagick, luanti, mapserver, mupdf, opam, perl, pillow, postgresql-13, and tiff), <b>Fedora</b> (aqualung, awstats, curl, incus, mac, mbedtls, mingw-LibRaw, python-msal, python3.11, python3.12, python3.15, smb4k, stb, and usd), <b>Gentoo</b> (DTrace and FUSE), <b>Mageia</b> (gdk-pixbuf2.0, giflib, polkit-122, python-cairosvg, and rsync), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, 389-ds-base, bind, freerdp, go-rpm-macros, kernel, libarchive, nodejs:20, openexr, perl:5.32, python, python3, squid:4, thunderbird, and uek-kernel), <b>Slackware</b> (tigervnc), and <b>SUSE</b> (aardvark-dns, avahi, bind, blender, Botan, bouncycastle, chromedriver, cpp-httplib-devel, flannel, gdk-pixbuf, GraphicsMagick, ignition, ImageMagick, jetty-annotations, jetty-minimal, kernel, kubo, leancrypto-devel, libcap, liblog4cxx-devel, libpng16-16, libraw, libraw-devel, NetworkManager, opam, openssl-3, openvswitch, openvswitch3, podman, polkit, python-cryptography, python-djangorestframework, python-Django, python-ecdsa, python311-Django, python311-jwcrypto, python311-Pillow, roundcubemail, skopeo, tempo-cli, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[WWDC 2026 Artwork Teases the Massive Siri Overhaul Coming in iOS 27]]></title>
<description><![CDATA[The official artwork for the upcoming WWDC 2026 developer conference holds a very clear clue about the future of Apple software. According to recent reports from industry insiders, the glowing logo directly teases a massive overhaul for Siri.



The digital assistant will finally receive a brand ...]]></description>
<link>https://tsecurity.de/de/3447080/ios-mac-os/wwdc-2026-artwork-teases-the-massive-siri-overhaul-coming-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447080/ios-mac-os/wwdc-2026-artwork-teases-the-massive-siri-overhaul-coming-in-ios-27/</guid>
<pubDate>Mon, 20 Apr 2026 06:23:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The official artwork for the upcoming WWDC 2026 developer conference holds a very clear clue about the future of Apple software. According to recent reports from industry insiders, the glowing logo directly teases a massive overhaul for Siri.



The digital assistant will finally receive a brand new interface and smarter chatbot abilities when the iOS 27 update launches on the iPhone later this coming summer.



The voice assistant moves to the dynamic island with glowing visuals



Bloomberg reporter Mark Gurman notes that the new voice interface uses a bright glow that matches the official event invitations perfectly. When you trigger the assistant, the small black pill at the top of the display will expand to reveal a new prompt that reads "Search or Ask" alongside a glowing cursor.



This update moves away from the older rainbow border design that struggled to launch on time last year. While it prepares two fresh design changes for the iOS 27 update regarding screen transparency, this prominent Siri widget marks the biggest visual shift.



It also plans to make customizing your iPhone home screen much easier in iOS 27 by adding helpful undo buttons for app layouts. However, the new Siri upgrade remains the true centerpiece of the presentation.



The digital helper handles complicated conversations inside a dedicated standalone app



For the very first time, Siri will exist as its own dedicated application on your phone. This new app features a similar glowing search bar and allows you to look back at your past conversation history whenever you need to find an old answer.



Beyond the fresh coat of paint, the underlying technology is getting significantly smarter. Because it uses advanced language models, the system will handle back-and-forth dialogue just like modern text generators.



You can speak multiple requests in a single sentence, and the software will understand exactly what you need based on the personal context found inside your emails, text messages, and calendar appointments. It acts more like a true virtual helper rather than a simple voice command tool.



We already know that the upgrade brings 4 new features beyond Siri that you should know, including helpful tools for organizing browser tabs and scanning nutrition labels. The company will reveal the full list of changes during the opening keynote on June 8.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Plans To Make Customizing Your iPhone Home Screen Much Easier in iOS 27]]></title>
<description><![CDATA[Apple is getting ready to announce its next major iPhone software update this summer. According to a recent newsletter from Bloomberg reporter Mark Gurman, the upcoming iOS 27 release will finally include a simple way to fix mistakes when moving your apps around. This tiny but highly requested fe...]]></description>
<link>https://tsecurity.de/de/3447027/ios-mac-os/apple-plans-to-make-customizing-your-iphone-home-screen-much-easier-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447027/ios-mac-os/apple-plans-to-make-customizing-your-iphone-home-screen-much-easier-in-ios-27/</guid>
<pubDate>Mon, 20 Apr 2026 05:50:59 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is getting ready to announce its next major iPhone software update this summer. According to a recent newsletter from Bloomberg reporter Mark Gurman, the upcoming iOS 27 release will finally include a simple way to fix mistakes when moving your apps around. This tiny but highly requested feature should make organizing your phone layout a much less frustrating task for everyone.



The long-press menu gains two helpful buttons for quick fixes



Right now, holding down on your screen brings up a small bubble in the top corner. This menu gives you options to add a widget or change your wallpaper. Gurman reports that Apple is looking to add new undo and redo buttons right inside that same menu.



This means you can quickly roll back a change if you accidentally drag a folder to the wrong page. You will not have to waste five minutes trying to drag everything back to where it belongs.



Users can also use these two buttons to quickly flick back and forth between two different layouts. This makes it incredibly easy to compare two styles and decide which look you actually prefer.



The new software focuses heavily on stability and smart voice controls



Aside from these helpful layout tweaks, reports indicate that iOS 27 will largely focus on bug fixes and overall phone stability. It wants to improve battery life and make sure the software runs smoothly on older devices.



The update will also introduce some bigger visual changes, like a new slider to adjust the transparency of the Liquid Glass interface. Users will get more control over how their screens look.



Finally, the company is expected to deliver a massive overhaul to its digital assistant. Siri will get a brand new glowing look and handle multiple commands much better. We will learn all the official details when the developer conference kicks off this June.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-0856 | Slackware Linux 7.0 Login User information disclosure]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Slackware Linux 7.0. This issue affects some unknown processing of the component Login. This manipulation causes information disclosure  (User).

The identification of this vulnerability is CVE-1999-0856. It is possible to initiate the at...]]></description>
<link>https://tsecurity.de/de/3446542/sicherheitsluecken/cve-1999-0856-slackware-linux-70-login-user-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3446542/sicherheitsluecken/cve-1999-0856-slackware-linux-70-login-user-information-disclosure/</guid>
<pubDate>Sun, 19 Apr 2026 21:08:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/slackware:linux">Slackware Linux 7.0</a>. This issue affects some unknown processing of the component <em>Login</em>. This manipulation causes information disclosure  (User).

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-1999-0856">CVE-1999-0856</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[To sleep in a sea of Tests | Refactoring a testing "framework" from hell (lixcon2026)]]></title>
<description><![CDATA[Taking a look at the `functional` test suite, pointing out its concepts and flaws to then take a look at its successor `functional2`

Many curses and screams of frustration has the functional test suite brought forth in many - if not all - lix developers. Hence people wanted a successor. 
In this...]]></description>
<link>https://tsecurity.de/de/3446150/it-security-video/to-sleep-in-a-sea-of-tests-refactoring-a-testing-framework-from-hell-lixcon2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3446150/it-security-video/to-sleep-in-a-sea-of-tests-refactoring-a-testing-framework-from-hell-lixcon2026/</guid>
<pubDate>Sun, 19 Apr 2026 15:48:59 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Taking a look at the `functional` test suite, pointing out its concepts and flaws to then take a look at its successor `functional2`

Many curses and screams of frustration has the functional test suite brought forth in many - if not all - lix developers. Hence people wanted a successor. 
In this session, we will talk about all the pain, impurities and falkeyness of the functional suite, look at the features and non-features of functional2, and the pain of migrating tests.

Licensed to the public under http://creativecommons.org/licenses/by/4.0
about this event: https://pretalx.dgnum.eu/lixcon-2026/talk/KBFUXL/]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Trick Apple AirTags Into Showing Completely Fake Locations]]></title>
<description><![CDATA[Security researchers just discovered a simple way to confuse the Apple AirTag system into displaying false locations on a map. By recording and repeating the standard Bluetooth signals that an AirTag naturally sends out, someone can make the tracking device appear miles away from where it actuall...]]></description>
<link>https://tsecurity.de/de/3445777/ios-mac-os/hackers-trick-apple-airtags-into-showing-completely-fake-locations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445777/ios-mac-os/hackers-trick-apple-airtags-into-showing-completely-fake-locations/</guid>
<pubDate>Sun, 19 Apr 2026 11:08:26 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security researchers just discovered a simple way to confuse the Apple AirTag system into displaying false locations on a map. By recording and repeating the standard Bluetooth signals that an AirTag naturally sends out, someone can make the tracking device appear miles away from where it actually is right now.



This new security flaw reveals that anyone can easily manipulate the vast device-finding network.



Capturing the signal lets someone fake the exact device location



The tracking system relies on constant Bluetooth Low Energy signals to pinpoint missing items. Every AirTag broadcasts a small ping, and any nearby Apple product picks up that signal to send an encrypted location report to the owner.



Researchers proved that anyone can record this ping using a basic Android phone or a small computer. Once they record the data, they can travel to a completely different spot and replay the same signal.



Any nearby Apple device will treat that replayed signal as the real thing. It then automatically reports the false location to the main network. Researchers even sent the copied signal over the internet to show the item in a different country entirely.







Fake location data can last for days before the network updates



The official tracking app gets confused when it sees both the real tag and the fake signal at the same time. The map marker will often jump back and forth between the true location and the injected false position.



To stop old signals from working forever, Apple makes sure its tags rotate their encryption keys roughly every 24 hours. Once the key changes, any older recorded pings become useless to the system.



However, researchers figured out a trick to bypass this limit. If someone takes the battery out of the original tag, the encryption key stops rotating. This simple step allows the copied signal to keep generating fake location reports for up to seven days before the network finally rejects it.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in tigervnc (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3445482/unix-server/security-mehrere-probleme-in-tigervnc-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445482/unix-server/security-mehrere-probleme-in-tigervnc-slackware/</guid>
<pubDate>Sun, 19 Apr 2026 07:31:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-0421 | Slackware Linux 3.6 Net Installer improper authentication (ISS-021 / XFDB-2040)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Slackware Linux 3.6. This issue affects some unknown processing of the component Net Installer. The manipulation results in improper authentication.

This vulnerability was named CVE-1999-0421. The attack needs to be approached loc...]]></description>
<link>https://tsecurity.de/de/3445134/sicherheitsluecken/cve-1999-0421-slackware-linux-36-net-installer-improper-authentication-iss-021-xfdb-2040/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445134/sicherheitsluecken/cve-1999-0421-slackware-linux-36-net-installer-improper-authentication-iss-021-xfdb-2040/</guid>
<pubDate>Sun, 19 Apr 2026 00:37:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/slackware:linux">Slackware Linux 3.6</a>. This issue affects some unknown processing of the component <em>Net Installer</em>. The manipulation results in improper authentication.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-1999-0421">CVE-1999-0421</a>. The attack needs to be approached locally. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in cups (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3443803/unix-server/security-mehrere-probleme-in-cups-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3443803/unix-server/security-mehrere-probleme-in-cups-slackware/</guid>
<pubDate>Sat, 18 Apr 2026 08:16:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[A petition to block or reform the Parents Decide Act (H​.​R. 8250)]]></title>
<description><![CDATA[I will leave a link to the Change.org petition, please consider leaving your signature to support a free internet. The introduction of the Parents Decide Act (H.R. 8250) is a deeply flawed bill, as it involves forced identity tracking of all users on every operating system. This legislation, whic...]]></description>
<link>https://tsecurity.de/de/3443688/linux-tipps/a-petition-to-block-or-reform-the-parents-decide-act-hr-8250/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3443688/linux-tipps/a-petition-to-block-or-reform-the-parents-decide-act-hr-8250/</guid>
<pubDate>Sat, 18 Apr 2026 05:53:21 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I will leave a link to the <a href="https://www.change.org/blockhr8250">Change.org</a> petition, please consider leaving your signature to support a free internet.</p> <p>The introduction of the Parents Decide Act (H.R. 8250) is a deeply flawed bill, as it involves forced identity tracking of all users on every operating system. This legislation, which mandates operating system providers to verify the age of every user, has overstepped First Amendment liberties with its overly broad and vague stipulations. I question whether these regulations would demand that I verify my age before even opening my Samsung T9000, a smart home appliance that operates on Tizen OS, a Linux-based operating system. Why should something as simple as accessing a smart fridge come with such hurdles? </p> <p>Unfortunately, the most damaging laws proposed as of late conceal themselves under the guise of protecting the kids. Truly protecting children on the internet involves meaningful education about the digital world, rather than imposing restriction and surveillance on all. It is important to allow children to reach an appropriate level of maturity to discern and navigate online interactions. Parents need to be the parents, not the federal government. </p> <p>As established by the numerous data breaches of high profile companies such as Facebook/Meta, until digital infrastructure is robust enough to secure user data, mandating the mass collection of sensitive personal identifiers creates a gold mine for criminals. Whether that be the very same company that sells your data as they collect it, or the disgusting predators who lurk on the dark web, this law is the antithesis of protection. Would it not be lunacy to mandate that every financial institution must declare how much money is kept on-site at all times? Does it not impose a security risk to advertise a real-time payout to criminals? Then why is it that we don't treat the relative anonymity on the internet the same? The key difference here is the money in that bank is insured by the government, but the protection of your child is not. If anything, the target painted on the back of children is assured if this law comes to pass. </p> <p>We must call attention to the flawed logic in this bill and lack of accountability in our government. This is not a left vs right battle of ideological values. When have you ever seen both parties unanimously agree on policy? When congress is known for it's lengthy and drawn out back-and-forth process, oddities like these lead to devastating consequences. No, this is the American people fighting for what's right. It's about mothers and fathers standing up for the innocent children of this world who cannot stand up for themselves. It's about the individual who makes their voice heard by those who wish to see it go silent. It's about doing SOMETHING at a time when doing nothing has never been easier. If you truly care about the kids of this great nation, please sign this petition and speak out against other such deceptive legislation.</p> <p>I dedicate this petition to the late Aaron Swartz, who fought til his dying breath to secure such freedoms we take for granted to this day. If each of us held just a small fraction of your dedication in our hearts, the world would be a much better place. May God rest your soul...</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Shot-Name-52"> /u/Shot-Name-52 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1somk78/a_petition_to_block_or_reform_the_parents_decide/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1somk78/a_petition_to_block_or_reform_the_parents_decide/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, freerdp, libarchive, and thunderbird), Debian (chromium, openssh, and thunderbird), Fedora (aurorae, bluedevil, breeze-gtk, buildah, cockpit, extra-cmake-modules, flatpak-kcm, grub2-breeze-theme, kactivitymanagerd, kcm_wacomtable...]]></description>
<link>https://tsecurity.de/de/3442222/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442222/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 17 Apr 2026 15:45:35 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 8.0, .NET 9.0, freerdp, libarchive, and thunderbird), <b>Debian</b> (chromium, openssh, and thunderbird), <b>Fedora</b> (aurorae, bluedevil, breeze-gtk, buildah, cockpit, extra-cmake-modules, flatpak-kcm, grub2-breeze-theme, kactivitymanagerd, kcm_wacomtablet, kde-cli-tools, kde-gtk-config, kdecoration, kdeplasma-addons, kf6, kf6-attica, kf6-baloo, kf6-bluez-qt, kf6-breeze-icons, kf6-frameworkintegration, kf6-kapidox, kf6-karchive, kf6-kauth, kf6-kbookmarks, kf6-kcalendarcore, kf6-kcmutils, kf6-kcodecs, kf6-kcolorscheme, kf6-kcompletion, kf6-kconfig, kf6-kconfigwidgets, kf6-kcontacts, kf6-kcoreaddons, kf6-kcrash, kf6-kdav, kf6-kdbusaddons, kf6-kdeclarative, kf6-kded, kf6-kdesu, kf6-kdnssd, kf6-kdoctools, kf6-kfilemetadata, kf6-kglobalaccel, kf6-kguiaddons, kf6-kholidays, kf6-ki18n, kf6-kiconthemes, kf6-kidletime, kf6-kimageformats, kf6-kio, kf6-kirigami, kf6-kitemmodels, kf6-kitemviews, kf6-kjobwidgets, kf6-knewstuff, kf6-knotifications, kf6-knotifyconfig, kf6-kpackage, kf6-kparts, kf6-kpeople, kf6-kplotting, kf6-kpty, kf6-kquickcharts, kf6-krunner, kf6-kservice, kf6-kstatusnotifieritem, kf6-ksvg, kf6-ktexteditor, kf6-ktexttemplate, kf6-ktextwidgets, kf6-kunitconversion, kf6-kuserfeedback, kf6-kwallet, kf6-kwidgetsaddons, kf6-kwindowsystem, kf6-kxmlgui, kf6-modemmanager-qt, kf6-networkmanager-qt, kf6-prison, kf6-purpose, kf6-qqc2-desktop-style, kf6-solid, kf6-sonnet, kf6-syndication, kf6-syntax-highlighting, kf6-threadweaver, kgamma, kglobalacceld, kinfocenter, kmenuedit, knighttime, kpipewire, krdp, kscreen, kscreenlocker, ksshaskpass, ksystemstats, kwayland, kwayland-integration, kwin, kwin-x11, kwrited, layer-shell-qt, libexif, libkscreen, libksysguard, libplasma, nix, ocean-sound-theme, oxygen-sounds, pam-kwallet, plasma-activities, plasma-activities-stats, plasma-breeze, plasma-browser-integration, plasma-desktop, plasma-dialer, plasma-discover, plasma-disks, plasma-drkonqi, plasma-firewall, plasma-integration, plasma-keyboard, plasma-login-manager, plasma-milou, plasma-mobile, plasma-nano, plasma-nm, plasma-oxygen, plasma-pa, plasma-print-manager, plasma-sdk, plasma-setup, plasma-systemmonitor, plasma-systemsettings, plasma-thunderbolt, plasma-vault, plasma-welcome, plasma-workspace, plasma-workspace-wallpapers, plasma-workspace-x11, plasma5support, plymouth-kcm, plymouth-theme-breeze, podman, polkit-kde, powerdevil, qqc2-breeze-style, sddm-kcm, skopeo, spacebar, spectacle, thunderbird, and xdg-desktop-portal-kde), <b>Mageia</b> (cockpit-338), <b>Oracle</b> (capstone, cockpit, firefox, fontforge, freerdp, golang-github-openprinting-ipp-usb, kernel, nghttp2, nodejs:20, nodejs:24, openexr, and squid), <b>Red Hat</b> (gnutls, libarchive, libpng, libpng12, libpng15, libtiff, libvpx, libxslt, multiple packages, python, python3, python3.11, python3.12, and python3.9), <b>Slackware</b> (libxml2), <b>SUSE</b> (apache-pdfbox, azure-storage-azcopy, corosync, cups, freerdp, iproute2, libsdb2_4_2, libtpms, NetworkManager, openssl-1_1, ovmf, plexus-utils, python, python-CairoSVG, python-jwcrypto, python-PyJWT, python-pyOpenSSL, python-urllib3, python3, python314, rust1.93, shim, smc-tools, terraform-provider-local, terraform-provider-random, terraform-provider-tls, thunderbird, tiff, util-linux, and vim), and <b>Ubuntu</b> (libowasp-esapi-java, linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux, linux-realtime, linux-aws-fips, linux-fips, linux-gcp-fips, linux-fips, linux-gcp-fips, linux-gcp, linux-gcp-6.17, linux-hwe-5.15, linux-intel-iot-realtime, linux-realtime, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-nvidia-tegra, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-realtime, linux-realtime-6.8, linux-realtime-6.17, ofono, and ruby-rack).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-1445 | Slackware Linux 3.3/3.4 IMAPD/POP3D USER/PASS memory corruption]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Slackware Linux 3.3/3.4. This vulnerability affects unknown code of the component IMAPD/POP3D. Such manipulation of the argument USER/PASS as part of Short Sequence leads to memory corruption.

This vulnerability is uniquely identifi...]]></description>
<link>https://tsecurity.de/de/3440905/sicherheitsluecken/cve-1999-1445-slackware-linux-3334-imapdpop3d-userpass-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440905/sicherheitsluecken/cve-1999-1445-slackware-linux-3334-imapdpop3d-userpass-memory-corruption/</guid>
<pubDate>Fri, 17 Apr 2026 08:09:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/slackware:linux">Slackware Linux 3.3/3.4</a>. This vulnerability affects unknown code of the component <em>IMAPD/POP3D</em>. Such manipulation of the argument <em>USER/PASS</em> as part of <em>Short Sequence</em> leads to memory corruption.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-1999-1445">CVE-1999-1445</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in libxml2 (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3440802/unix-server/security-ausfuehren-beliebiger-kommandos-in-libxml2-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440802/unix-server/security-ausfuehren-beliebiger-kommandos-in-libxml2-slackware/</guid>
<pubDate>Fri, 17 Apr 2026 07:31:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-0341 | Slackware Linux 1.3.1/2.1/2.2/2.3 deliver memory corruption]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Slackware Linux 1.3.1/2.1/2.2/2.3. Impacted is an unknown function of the component deliver. The manipulation results in memory corruption.

This vulnerability is reported as CVE-1999-0341. The attack requires a local approach. No exploit e...]]></description>
<link>https://tsecurity.de/de/3440628/sicherheitsluecken/cve-1999-0341-slackware-linux-131212223-deliver-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440628/sicherheitsluecken/cve-1999-0341-slackware-linux-131212223-deliver-memory-corruption/</guid>
<pubDate>Fri, 17 Apr 2026 05:38:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/slackware:linux">Slackware Linux 1.3.1/2.1/2.2/2.3</a>. Impacted is an unknown function of the component <em>deliver</em>. The manipulation results in memory corruption.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-1999-0341">CVE-1999-0341</a>. The attack requires a local approach. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-0340 | Slackware Linux 3.4 crond memory corruption]]></title>
<description><![CDATA[A vulnerability was found in Slackware Linux 3.4. It has been classified as problematic. This affects an unknown function of the component crond. The manipulation leads to memory corruption.

This vulnerability is listed as CVE-1999-0340. The attack must be carried out locally. There is no availa...]]></description>
<link>https://tsecurity.de/de/3440552/sicherheitsluecken/cve-1999-0340-slackware-linux-34-crond-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440552/sicherheitsluecken/cve-1999-0340-slackware-linux-34-crond-memory-corruption/</guid>
<pubDate>Fri, 17 Apr 2026 04:38:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/slackware:linux">Slackware Linux 3.4</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>crond</em>. The manipulation leads to memory corruption.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-1999-0340">CVE-1999-0340</a>. The attack must be carried out locally. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[reGPU - Performance improvements]]></title>
<description><![CDATA[As you guys might've seen in my previous post, this is a program that makes legacy Optimus cards usable under modern Linux. I've done some performance improvements. FPS in the first test of glmark2 jumped from ~2400 to nearly the maximum this GPU can output, which is 3000+ Unfortunately though, i...]]></description>
<link>https://tsecurity.de/de/3440517/linux-tipps/regpu-performance-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440517/linux-tipps/regpu-performance-improvements/</guid>
<pubDate>Fri, 17 Apr 2026 03:53:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>As you guys might've seen in my previous post, this is a program that makes legacy Optimus cards usable under modern Linux.</p> <p>I've done some performance improvements. FPS in the first test of glmark2 jumped from ~2400 to nearly the maximum this GPU can output, which is 3000+</p> <p>Unfortunately though, i have broken a few things alongside the improvements. Like the output, which is now just a big fat black square. Also window managers broke for some reason. glmark2's FPS dropped to like 400 whenever i tried using a window manager at :8 and i have no idea why.</p> <p>Input now kind of works? Keyboard input is fine but the mouse cursor is not being drawn due to it being hardware-drawn. I couldn't disable the hardware cursor either so it's stuck like this until i somehow find a workaround.</p> <p>Games are still unstable. I've tested Minecraft (with the version before this) and the FPS was just going back and forth with the lowest being 10 and the highest being 400.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NotSoEpicKebap"> /u/NotSoEpicKebap </a> <br> <span><a href="https://i.redd.it/lrq5ueunflvg1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1snblir/regpu_performance_improvements/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The European Commission wants Google to share search engine data with competitors]]></title>
<description><![CDATA[The European Commission has proposed new measures for Google aimed at bringing the tech giant's search business into compliance with the Digital Markets Act. In order to allow third-party online search engines to be competitive with Google, the EC has recommended that Google permit those services...]]></description>
<link>https://tsecurity.de/de/3440013/it-nachrichten/the-european-commission-wants-google-to-share-search-engine-data-with-competitors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3440013/it-nachrichten/the-european-commission-wants-google-to-share-search-engine-data-with-competitors/</guid>
<pubDate>Thu, 16 Apr 2026 21:32:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The European Commission has <a target="_blank" class="link" href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_825" data-i13n="cpos:1;pos:1">proposed</a> new measures for Google aimed at bringing the tech giant's search business into compliance with the Digital Markets Act. In order to allow third-party online search engines to be competitive with Google, the EC has recommended that Google permit those services to access its treasure trove of search engine data. As it stands, the proposal would require Google to let rivals see data points "such as ranking, query, click and view data, on fair, reasonable and non-discriminatory terms."</p><p>"Data is a key input for online search and for developing new services, including AI," said Teresa Ribera, the Commission's executive vice-president for Clean, Just and Competitive Transition. "Access to this data should not be restricted in ways that could harm competition. In fast-moving markets, small changes can quickly have a big impact. We will not allow practices that risk closing markets or limiting choice."</p><p>European regulators have been using the Digital Markets Act to hammer at Google's dominant market position for several years. Beginning in March 2024, Google was required to be in compliance with the DMA and it did <a target="_blank" class="link" href="https://www.engadget.com/google-just-outlined-exactly-how-its-changing-ahead-of-thursdays-dma-deadline-174518625.html" data-i13n="cpos:2;pos:1">plan some changes</a> in accordance with the legislation. A year later, though, the Commission levied <a target="_blank" class="link" href="https://www.engadget.com/big-tech/the-eus-new-charges-against-google-could-lead-to-at-least-35-billion-in-fines-165850585.html" data-i13n="cpos:3;pos:1">preliminary charges</a> against Google arguing that Google Search and the Play Store had not met their obligations for market competition. Google offered some <a target="_blank" class="link" href="https://www.engadget.com/big-tech/google-reportedly-offers-to-tweak-search-results-to-avoid-eu-fine-193940005.html" data-i13n="cpos:4;pos:1">possible adjustments</a> to how search results are displayed in response, but it seems the regulator is going to keep fighting for more robust changes to Google's search business.</p><p>If you think all that sounds like something Google is unwilling and unlikely to do, you'd be correct. For starters, the actual requirements for Google could change in the coming months. The EC is accepting comments on the proposed measures through May 1, and Google's legal team is certain to have a lot of opinions to share. We've reached out to the company for a comment on these preliminary measures. A final, binding decision on Google's next steps is due by July 27, so we're expecting a lot of back-and-forth between the parties until that date.</p>This article originally appeared on Engadget at https://www.engadget.com/big-tech/the-european-commission-wants-google-to-share-search-engine-data-with-competitors-192709530.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Teams cheat sheet: How to get started]]></title>
<description><![CDATA[If your organization uses Microsoft 365 (a.k.a. Office), chances are you’ve encountered Teams, at least for video meetings. But it’s capable of a lot more, providing an effective way for groups of people to collaborate on work and advance business objectives.



Teams is, at its core, group chat ...]]></description>
<link>https://tsecurity.de/de/3438460/it-nachrichten/microsoft-teams-cheat-sheet-how-to-get-started/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438460/it-nachrichten/microsoft-teams-cheat-sheet-how-to-get-started/</guid>
<pubDate>Thu, 16 Apr 2026 13:17:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If your organization uses <a href="https://www.computerworld.com/article/1691110/microsoft-365-explained.html">Microsoft 365</a> (a.k.a. Office), chances are you’ve encountered Teams, at least for video meetings. But it’s capable of a lot more, providing an effective way for groups of people to collaborate on work and advance business objectives.</p>



<p>Teams is, at its core, group chat software with videoconferencing capabilities and some interesting features around working with documents and spreadsheets, especially those stored in SharePoint and OneDrive for Business. In other words, it’s a collaboration hub. Teams can be bundled with Microsoft 365 plans, and it’s also available as a standalone subscription for both <a href="https://www.microsoft.com/en-us/microsoft-teams/enterprise/teams-enterprise?activetab=pivot:overviewtab" target="_blank" rel="noreferrer noopener">enterprise</a> and <a href="https://www.microsoft.com/en-us/microsoft-teams/small-medium-business" target="_blank" rel="noreferrer noopener">small business</a> customers.</p>



<p>Once you get to know it, Teams is a genuinely helpful tool for teams in companies that use Microsoft 365, since it brings together a bunch of suite components and surfaces them in one convenient place.</p>



<p>It’s available as a <a href="https://teams.microsoft.com/" target="_blank" rel="noreferrer noopener">web app</a>, <a href="https://www.microsoft.com/en-us/microsoft-teams/download-app" target="_blank" rel="noreferrer noopener">desktop application</a> (Windows, macOS, Linux), and <a href="https://www.microsoft.com/en-us/microsoft-teams/mobile-app" target="_blank" rel="noreferrer noopener">mobile app</a> (iOS, Android). Microsoft regularly releases <a href="https://www.computerworld.com/article/1710697/office-365-a-guide-to-the-updates.html">updates</a> to the Teams apps, usually with minor user interface refreshments, but sometimes they’re major updates with significant performance improvements, UI changes, and/or <a href="https://support.microsoft.com/en-us/office/what-s-new-in-microsoft-teams-d7092a6d-c896-424c-b362-a472d5f105de" target="_blank" rel="noreferrer noopener">new features</a>.</p>



<p>This guide covers the essentials for getting started with Teams and working efficiently within the platform. We also cover extras such as using <a href="https://www.computerworld.com/article/1621861/how-to-use-microsoft-loop-in-outlook-and-teams.html">Microsoft Loop components</a> in Teams and practical use cases for Microsoft’s ubiquitous generative AI tool, <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Copilot</a>. In this story we’ll demonstrate in the Mac app, but you’ll find that Teams works similarly in any environment.</p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#get-around">Getting around Teams</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#join-create">Joining and creating teams</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#channels">Understanding channels</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#chat">Chat: Direct messages and group conversations</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#calls">Video and audio calls</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#files">Working with files and OneDrive</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#loop">Microsoft Loop within Teams</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#copilot">Copilot Chat in Teams</a></li>



<li><a href="https://www.computerworld.com/article/1717491/microsoft-teams-cheat-sheet.html#tips">Tips for using Teams effectively</a></li>
</ul>



<h2 class="wp-block-heading">Getting around Teams</h2>



<p>The <strong>navigation bar</strong> on the left side of the Teams window is your primary way to move through the app.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="232" height="916" sizes="auto, (max-width: 232px) 100vw, 232px"&gt;<figcaption class="wp-element-caption"><p>The Teams navigation bar.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>Understanding these core sections will help you navigate Teams effectively. Note that, depending on your organization’s configuration, not all of these options may be available to you:</p>



<ul class="wp-block-list">
<li><strong>Activity</strong>: Shows notifications about mentions, replies, and other updates relevant to you.</li>



<li><strong>Chat</strong>: Your hub for one-on-one conversations, group chats, and (with recent updates) access to your teams and channels. The unified interface now combines what were previously separate Chat and Teams/Channels sections.</li>



<li><strong>Calendar</strong>: View and schedule meetings, linked to your Outlook calendar.</li>



<li><strong>Calls</strong>: Make and receive voice calls, access voicemail, and view call history, if your organization has a Teams Phone license assigned to your account. (This is not terribly common.)</li>



<li><strong>Files</strong>: Quick access to recent files, OneDrive files, and downloads.</li>



<li><strong>Apps</strong>: Browse and add applications that integrate with Teams.</li>
</ul>



<p>The navigation bar is customizable — you can reorder items by dragging them or pin frequently used apps for quick access. You can also add things to the navigation bar by clicking the three dots. A few minutes spent rearranging and adding/removing can make your regular daily Teams use much more snappy, without a lot of friction.</p>



<h3 class="wp-block-heading">Access your chats, teams, and channels in one place</h3>



<p>One of the most significant recent changes to the Teams app is the <strong>unified chat and channel interface</strong>. In Teams, <strong>chats</strong> are private conversations (one-on-one or with a small group) that you start on the fly, whereas <strong>teams</strong> are set up for specific groups of people who need to collaborate on an ongoing basis. A team can be a small group you’re working with on a project, your whole department, or in some cases even the entire company. Each team has one or more <strong>channels</strong> where members collaborate (more on this later in the story).</p>



<p>Until recently, Chats and Teams/Channels were entirely separate sections in Teams, but an interface update has put all conversations in the same place. Here’s how to navigate:</p>



<ol class="wp-block-list">
<li>Click <em>Chat</em> in the left navigation bar.</li>



<li>Next to the “Chat” header at the top of the left sidebar, click the <em>three-dot menu icon</em>.</li>



<li>Select <em>Your teams and channels</em>.</li>



<li>From here you can browse and access your individual teams and channels.</li>
</ol>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/microsoft-teams-02-chat-screen.png?w=1024" alt="screenshot of chat screen in microsoft teams" class="wp-image-4158622" width="1024" height="580" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The unified interface for chats, teams, and channels.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>This change initially confused many users, but the unified approach aims to reduce switching between chats and channel conversations.</p>



<h3 class="wp-block-heading">Use search as a navigation shortcut</h3>



<p>The <strong>search bar</strong> at the top of Teams is one of its most powerful features for finding messages, files, people, and more. You can search for messages in chats and channels, files and documents stored in your OneDrive for Business or any linked SharePoint libraries, interactions with people in your organization, and “@mentions” of yourself.</p>



<p>Here are some tips to make search more useful:</p>



<ul class="wp-block-list">
<li> Use <strong>/</strong> commands in the search box for quick actions (e.g., <strong>/call</strong> to start a call, <strong>/files</strong> to find files). If you use Cmd-space in macOS to launch Spotlight, this is similar, but for Teams.</li>



<li>Filter results by category using the tab buttons that appear across the top (e.g., Messages, People, Files).</li>



<li>Use keywords like <strong>from:</strong> to search for messages from specific people.</li>



<li>If you perform the same searches over and over again, you will find that recent searches appear as suggestions when you click the search box, so just grab the one you want in a single click.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/microsoft-teams-03-search-results.png?w=1024" alt="screenshot of search results for report in teams" class="wp-image-4158624" width="1024" height="592" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Searching for instances of the word “report” from within the Teams client. Use the tab buttons to filter search results to just messages, just people, just files, and so on.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<h2 class="wp-block-heading">Joining and creating teams</h2>



<p>Your organization probably already has several teams that appear in your Teams client. To join an existing team, click <em>Chat</em> in the left navigation, and then under “Teams and channels,” click <em>See all your teams</em>. You’ll see teams you’ve already joined as well as public teams available in your organization for immediate membership.</p>



<p>Private teams are invite only; to join one, you respond to an invitation that comes from a current manager of the team.</p>



<p>You can also create teams ad-hoc (unless your administrator has disabled this option) to facilitate working together. When you create a team, Microsoft 365 automatically sets up a bunch of supporting apparatuses:</p>



<ul class="wp-block-list">
<li>A Microsoft 365 Group</li>



<li>A SharePoint site for file storage</li>



<li>A shared <a href="https://www.computerworld.com/article/1670215/microsoft-onenote-cheat-sheet.html">OneNote</a> notebook</li>



<li><a href="https://www.computerworld.com/article/1638502/microsoft-planner-cheat-sheet.html">Microsoft Planner</a> integration</li>



<li>An Exchange mailbox for the group</li>
</ul>



<p>To create a new team:</p>



<ol class="wp-block-list">
<li>Click <em>Chat</em> in the left navigation.</li>



<li>Under “Teams and channels,” click <em>See all your teams</em>.</li>



<li>Click <em>Create team</em> in the top right.</li>



<li>By default, you’re building a new team from scratch. You can click the <em>More create team options</em> link to pick an existing team as a template on which Teams can model the new team you are creating.</li>



<li>Name your team and add a description.</li>



<li>Select <em>Private</em> (invite-only) or <em>Public</em> (anyone in the organization can join).</li>



<li>Add a first team channel. If you don’t know what you want, just click the dots on the side of the field and it’ll set the name to General.</li>



<li>Click <em>Create</em>.</li>
</ol>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="1010" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Creating a new team.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>9. On the next screen that pops up, add members by typing their names or email addresses.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="799" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Adding members to the new team.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>If Microsoft 365 is configured appropriately in your company, you can even invite guests from outside your organization, such as vendors and contractors, simply by typing their email addresses into the team-picking screen. Their “guest” status will be clearly denoted in all of their actions. (If you don’t have permission from your administrator to do this, Teams will report back that you are not authorized.)</p>



<p>To manage your team at any time, click the three-dot icon next to its name in the sidebar on the left. You’ll see a pop-up menu where you can add or remove members, create channels for the team (more on that below), change the team name or description, and more.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="744" height="820" sizes="auto, (max-width: 744px) 100vw, 744px"&gt;<figcaption class="wp-element-caption"><p>Options for ongoing management of the team.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<h2 class="wp-block-heading">Understanding channels</h2>



<p><strong>Channels</strong> are where you converse and collaborate within a team. The General channel is meant to be a catch-all place where you go to start conversations when you first begin using the Teams product; usually more specific topic-related channels will spring from there.</p>



<p>You can create multiple channels for any given team — the Widget Launch team might want to have sales, production, and marketing channels, for example. To add a channel, click the three-dot icon next to the team name in the navigator bar on the left. You’ll see a pop-up menu, and then click <em>Add channel</em>. On the screen that appears, type in a name and a description for the channel, pick a privacy option if you want to limit the people who can access the channel, and click the <em>Create</em> button. All the channels for a team appear underneath the name of the team in the left pane.<a></a></p>



<p>Each channel has different <strong>pages</strong> that let you bring documents, apps, and websites directly into your channels for quick access. From the channel name, click the down arrow icon underneath, and you can choose from a new page, an existing page, other embedded Teams apps, conversations, files in the related SharePoint library, notes in a OneDrive shared notebook, or other items.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="524" height="660" sizes="auto, (max-width: 524px) 100vw, 524px"&gt;<figcaption class="wp-element-caption"><p>Creating new pages within a channel for files, notes, and more.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>Common uses include pinning a specific Excel spreadsheet that your team updates frequently, a OneNote notebook for meeting notes, or a Power BI dashboard for tracking metrics.</p>



<p>The <strong>Posts</strong> tab in a channel kind of works like Facebook or LinkedIn in that you can comment to your teammates in an ongoing conversation. Channel managers can choose to have a traditional channel, where you just have posts, or a channel organized by threads where you can follow conversations and related activities. (See more on the new threads layout <a href="https://adoption.microsoft.com/en-us/microsoft-teams/new-chat-and-channels-experience/threads-in-channels/" target="_blank" rel="noreferrer noopener">from Microsoft</a>.)</p>



<p>Composing messages is straightforward: Just click the <em>Start a new conversation</em> text box, or click <em>Reply</em> below an existing conversation and start typing.</p>



<p>You can call teammates’ attention to certain parts of the conversation by tagging them with an <strong>@</strong> sign when typing, like this:<strong> @Adele Can you share the latest workback grid?</strong> Users who have been tagged will see, in their own copies of the Teams clients, those tagged parts of the conversation highlighted in bright red so they can easily see and respond to messages. You can use emoticons, emojis, and GIFs as well — that’s what I mean by thinking of this area like Facebook.</p>



<p>Other useful features:</p>



<ul class="wp-block-list">
<li><strong>Formatting</strong>: Use the toolbar to add bold, italics, highlights, bullet points, numbered lists, and more.</li>



<li><strong>Attachments</strong>: Click the paperclip icon to attach files.</li>



<li><strong>Emojis and GIFs</strong>: Click the emoji or GIF icons beneath the compose box. Everyone loves a funny meme at work. OK, perhaps not everyone, but sometimes they’re a needed relief.</li>



<li><strong>Important/Urgent</strong>: Mark messages with priority flags using the <strong>!</strong> icon.</li>
</ul>



<h2 class="wp-block-heading">Chat: Direct messages and group conversations</h2>



<p>While channels are great for team-wide or topic-specific discussions, chat provides space for smaller conversations.</p>



<p>To start a one-on-one or group chat:</p>



<ol class="wp-block-list">
<li>Click <em>Chat</em> in the left navigation.</li>



<li>Click the <em>New chat</em> button (pencil icon).</li>



<li>Type the name(s) of the people you want to include.</li>



<li>Type your message and press Enter.</li>
</ol>



<p>Chats persist, so you can return to them anytime. They won’t vanish when you close Teams or log off for the day.</p>



<p>If you have an ongoing conversation and find you might want to add someone to a conversation, you can easily start a group chat: head up to the top right of your chat window, hit the three dots, click <em>Participants</em>, and from the pop-up submenu select <em>Start a group chat</em>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="1012" height="982" sizes="auto, (max-width: 1012px) 100vw, 1012px"&gt;<figcaption class="wp-element-caption"><p>Starting a group chat from a chat between two individual users.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>You might be wondering when it’s appropriate to use a chat as opposed to convening everyone involved in a Teams channel. I suggest using channels for topics that need transparency and team-wide visibility. In contrast, use chat for quick questions, sensitive discussions, or conversations involving people outside your main team.</p>



<h2 class="wp-block-heading">Video and audio calls</h2>



<p>Teams offers robust calling and meeting capabilities, from quick calls to scheduled meetings with dozens of participants.</p>



<p>To make an immediate call, click <em>Calls</em> in the left navigation. On the Calls screen, start typing the name of the person you want to call, then select their name from the list that appears. Then click the <em>Call</em> button.</p>



<p>To schedule a call or meeting in advance, click <em>Calendar</em> in the left nav and click the <em>New</em> button in the top right corner. A “New event” pane pops up, where you can add a title, invite attendees, type a message, and add other information if desired. Alternatively, you can set up the meeting from Outlook. Either way, “Teams meeting” is selected by default as soon as you add attendees. You can also book a conference room or other shared resource here, too.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/microsoft-teams-09-schedule-meeting.png?w=1024" alt="screenshot of new meeting form in microsoft teams" class="wp-image-4158619" width="1024" height="650" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Scheduling a meeting from within Teams.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>If you’ve been invited to a meeting or call, you’ll typically receive an email or other notification message with a meeting link or <em>Join</em> button. Click the button or link to join the call. For scheduled meetings, you can also click <em>Calendar</em> in the left navigation bar, click on the meeting, and click <em>Join</em>. If you have been sent a meeting invitation with an ID number, you can use the <em>Join with an ID</em> button at the top of the Calendar screen. Or if someone is just calling you ad-hoc, then you can choose to either accept the call without video, accept the call with video, or decline it on the pop-up that appears while the call is “ringing.”</p>



<p>Note: The first time you start or join a call in Teams, you’ll be prompted with a screen to help you set up your audio and video settings for that call. Also, on some systems, particularly Macs, you may be prompted to give Teams permission to record your screen, camera, or microphone. On Windows, your organization may have already given permission to Teams through its systems management software, and you may not be prompted. But if Teams is asking, click <em>Allow</em> to let Teams get the necessary access to each device.</p>



<p>Once you have accepted a call, you can control it using the buttons on the top of the call window, including a dial pad (for voice calls that need key presses); hold; transfer; chat; turn the camera and mic on or off; share content like an app, window, or screen; and then of course hang up the call.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/microsoft-teams-10-teams-call-window.png?w=1024" alt="screenshot of teamsm call window with controls along top and live video in main area" class="wp-image-4158625" width="1024" height="824" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The Teams call window, with controls at the top.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>If you have a webcam connected, Teams will grab that camera feed automatically. You can adjust cameras and backgrounds using the <em>Camera</em> button on the top bar. Blurring your messy room or switching to a solid color can often help reduce distractions in meetings. If you want to start the meeting with your camera off, just click the <em>Camera</em> button.</p>



<p>Using the <em>Mic</em> button and dropdown, you can select your audio devices, including your speaker volume. In most cases, Teams selects this correctly, but if you want to switch to a Bluetooth or USB headset, for instance, choose the right device from the Speaker and Microphone section of the right pane. (For headsets, you’ll most likely choose the same device for speaker and microphone.) If you want to start the meeting with your mic off, just click the button.</p>



<p>Under the <em>More</em> control, you can opt to record and transcribe a call, insert video effects, change audio, ask for translation options, and other settings.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="504" height="534" sizes="auto, (max-width: 504px) 100vw, 504px"&gt;<figcaption class="wp-element-caption"><p>More options to control a call in progress.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>To share other content with participants, click <em>Share</em>. You can then elect to share your screen, collaborate on a shared digital whiteboard, present a PowerPoint slide deck, or share individual files to your meeting participants without broadcasting them on the screen.</p>



<h2 class="wp-block-heading">Working with files and OneDrive</h2>



<p>Teams integrates deeply with SharePoint and OneDrive, making file collaboration seamless throughout the platform. When you share files in a channel, those files are automatically stored in the team’s SharePoint site. Similarly, files that are shared in a chat are stored in your OneDrive for Business account.</p>



<p>The <strong>Files</strong> menu in a Teams channel offers several useful features for document management. It displays all documents that have been shared in that particular channel, allowing you to create new folders to organize your content, upload files from various sources, and open relevant libraries in SharePoint when you need to do so.</p>



<p>To upload files to Teams, you can navigate to the Files menu within a channel (remember, that’s the dropdown menu under the channel name). You can upload a file with the three-dot menu or create a new file of a typical type, like a Word document or Excel spreadsheet, using the <em>+ New</em> menu. Alternatively, you can drag and drop files directly into the Files tab or even into a conversation thread for quick sharing.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="672" height="716" sizes="auto, (max-width: 672px) 100vw, 672px"&gt;<figcaption class="wp-element-caption"><p>Working with files inside a channel.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>When you need to work with files in Teams, you can edit them directly within the application. Office files can be edited right in Teams by simply clicking on a file to open it. If you prefer the full desktop experience, you can choose to open files in Word, Excel, or PowerPoint by selecting the <em>Open in Desktop App</em> option. Teams also supports co-authoring, which means multiple people can edit the same document simultaneously. Additionally, you can access the version history to review previous versions of documents through the three-dot menu.</p>



<p>Teams recently updated its interface to bring <a href="https://www.computerworld.com/article/2121520/microsoft-onedrive-cheat-sheet-using-onedrive-for-web.html">OneDrive functionality</a> directly into the Teams environment. This integration allows you to access your personal OneDrive files without having to leave the Teams application, streamlining your workflow.</p>



<p>To access OneDrive within Teams, you can click on the <em>OneDrive</em> option in the left navigation panel. This integration makes it significantly easier to share personal files in Teams conversations without the inconvenience of switching between different applications.</p>



<h2 class="wp-block-heading">Microsoft Loop within Teams</h2>



<p><a href="https://www.computerworld.com/article/1621861/how-to-use-microsoft-loop-in-outlook-and-teams.html">Microsoft Loop components</a> are collaborative blocks of content that can be shared and edited across Microsoft 365 apps, including Teams. These components function as living, shared content blocks that operate similarly to a task list, table, or paragraph, but with a key difference: they stay in sync across applications. When you create a Loop component in Teams and share it in Outlook, any edits made in either location will update everywhere the component appears.</p>



<p>There are several common types of Loop components available for different collaboration needs, such as:</p>



<ul class="wp-block-list">
<li><strong>Lists</strong> allow you to create shared to-do lists with assignments and due dates, making task management more efficient.</li>



<li><strong>Tables</strong> serve as collaborative data grids where team members can input and organize information together.</li>



<li><strong>Paragraphs</strong> function as shared notes and content that multiple people can edit simultaneously, enabling real-time collaborative writing and brainstorming.</li>
</ul>



<p>To create a Loop component within your workflow, you begin by typing <strong>/loop</strong> directly into the compose box of a chat or conversation to access the component creation menu. Next, you choose the specific type of component you want to create based on your needs, whether that’s a list, table, paragraph, or another option. After selecting your component type, you add your content and click <em>Send</em> to share it with your team members.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/09/ms-loop-components-05-checklist-component-teams.png?w=1024" alt="a checklist loop component in teams" class="wp-image-3535677" width="1024" height="748" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A checklist loop component in a Teams conversation.</p><br></figcaption></figure><p class="imageCredit">Howard Wen</p></div>



<p>Once the component has been shared, team members can click on the component to edit it collaboratively, with all changes syncing in real time across all instances of that component throughout Microsoft 365.</p>



<p>For a deep dive on Loop components, see “<a href="https://www.computerworld.com/article/1621861/how-to-use-microsoft-loop-in-outlook-and-teams.html">How to use Loop components in Microsoft 365 apps</a>.” (There’s also a standalone Loop web app — see “<a href="https://www.computerworld.com/article/1631259/how-to-use-microsoft-loop-app.html">Microsoft Loop cheat sheet</a>” for details.)</p>



<h2 class="wp-block-heading">Copilot Chat in Teams</h2>



<p>Copilot Chat offers several powerful generative AI capabilities to enhance your productivity within Teams using Microsoft’s favorite new child, Copilot.</p>



<p>It can summarize recent chats and channel conversations, helping you quickly catch up on discussions you may have missed. The tool can also answer questions about your Teams activity, providing insights into your communication patterns and interactions. Additionally, Copilot Chat can help draft messages for you, saving time when composing communications. Beyond these specific functions, it provides general information and assistance across a wide range of topics and tasks.</p>



<p>To access Copilot Chat within Teams, you need to look for the Copilot icon, which can be found either in the left navigation panel or at the top of the Teams interface. Once you locate the icon, click it to open a chat window with Copilot. From there, you can ask questions or request assistance with whatever you need help with, and Copilot will respond to your queries.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/microsoft-teams-14-copilot-chat.png?w=1024" alt="screenshot of copilot chat interface inside microsoft teams" class="wp-image-4158620" width="1024" height="793" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot Chat within Teams.</p>
</figcaption></figure><p class="imageCredit">Jonathan Hassell / Foundry</p></div>



<p>There are many practical ways to use Copilot Chat in your daily work.</p>



<ul class="wp-block-list">
<li>For example, you might ask it to “Summarize the Project Alpha channel from the last week” to get a quick overview of all the important discussions and decisions made in that channel.</li>



<li>You could inquire “What did Sarah say about the budget?” to find specific information from past conversations without scrolling through lengthy message threads.</li>



<li>Another useful application is asking “Help me write a message asking the team for status updates” when you need assistance crafting clear and effective communications to your colleagues.</li>
</ul>



<p>This basic Copilot functionality is distinct from the more advanced <a href="https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html">Microsoft 365 Copilot</a> integration which happens only with an additive license beyond the standard Microsoft 365 subscription. For organizations with Microsoft 365 Copilot licenses, Teams offers more advanced AI capabilities:</p>



<ul class="wp-block-list">
<li><strong>Meeting-related features:</strong> Real-time meeting summaries and transcription, automated action items and follow-ups, and chat-like answers to questions about what was discussed during the meeting (even if you joined late).</li>



<li><strong>Chat and channel features:</strong> Comprehensive conversation summaries across multiple channels, suggested replies and message composition, and key highlights extraction from long conversation threads.</li>



<li><strong>Productivity features:</strong> Meeting preparation briefs based on related emails and documents, intelligent recaps for meetings you missed, and follow-up task identification and tracking.</li>
</ul>



<p>You might not have this level of license, as they’re relatively expensive — $30 per user per month at the enterprise level or $21 per user per month for companies with fewer than 300 employees. That’s on top of what your organization is already paying for Microsoft 365. <a href="https://www.computerworld.com/article/4124591/microsoft-touts-m365-copilot-momentum-claims-15m-paid-users.html">Microsoft recently reported</a> 15 million paid M365 Copilot seats — just 3.3% of the Microsoft 365 user base.</p>



<h2 class="wp-block-heading">Tips for using Teams effectively</h2>



<p>Here are some battle-tested tips for getting the most out of Teams and, perhaps more importantly, not letting Teams eat your workday and become the place where knowledge goes to die.</p>



<h3 class="wp-block-heading">Tamp down notifications and activity settings</h3>



<p>Managing notifications prevents Teams from becoming overwhelming. If you go with the defaults, Teams will buzz you — and your phone, too, if you have the companion app installed and set up — every time you get a call, message, or chat with an @mention to you. In a busy organization, this can drive you up the wall or result in your entire day being swallowed by Teams notifications.</p>



<p>To customize notifications:</p>



<ol class="wp-block-list">
<li>Click your three-dot menu in the upper right and select <em>Settings</em>.</li>



<li>Go down to Notifications and Activity on the left side.</li>
</ol>



<p>Adjust everything to your preference. Teams is a very chatty app, so you may want to play around with these settings over time to find your particular sweet spot.</p>



<h3 class="wp-block-heading">Add apps to Teams</h3>



<p>In addition to its built-in integrations with Microsoft 365 tools like OneDrive, Loop, and Copilot, Teams lets you bring a variety of Microsoft and third-party apps right into a channel or group chat. You can add apps for brainstorming, project management, polling, training, data visualization, sales, customer support, and countless other uses, allowing you to work in them without having to leave the Teams environment.</p>



<p>See “<a href="https://www.computerworld.com/article/1632691/microsoft-teams-apps-content-collaboration-management.html">18 Microsoft Teams apps for content collaboration and management</a>” for complete instructions on finding and installing apps, but in a nutshell, you click the <em>Apps</em> button in the left navigation bar, browse or search the available apps, and then install the one you want. (Note that your organization may restrict which apps you can install in Teams.)</p>



<h3 class="wp-block-heading">5 more quick tips</h3>



<ul class="wp-block-list">
<li><strong>Keep channels focused:</strong> Create channels for specific topics, projects, or workstreams rather than having everything in General.</li>



<li><strong>Use @mentions strategically:</strong> Mention individuals when you need their input, <strong>@channel</strong> when everyone in the channel should see it, and <strong>@team</strong> sparingly for truly urgent, team-wide announcements.</li>



<li><strong>Pin important messages:</strong> Hover over any message and click the three dots (<strong>…</strong>) to pin it to the top of the channel for easy reference.</li>



<li><strong>Save messages:</strong> Click the bookmark icon on messages you want to find later, then access them through the Saved item on the left navigation bar, toward the top.</li>



<li><strong>Use status messages:</strong> Update your status with custom messages like “In a meeting until 3pm” or “Working from home today” to keep teammates informed.</li>



<li><strong>Use keyboard shortcuts:</strong> Press <strong>Ctrl + /</strong> (Windows) or <strong>Cmd + /</strong> (Mac) to see a list of keyboard shortcuts that can speed up your work.</li>
</ul>



<h3 class="wp-block-heading">What to avoid</h3>



<p>Teams is definitely a big step up over endless email chains, but that doesn’t mean it’s suitable for everything. Here are two things to avoid:</p>



<p><strong>Trying to replace all emails with Teams conversations and links.</strong> Sometimes we humans have a tendency to gravitate to whatever new features and tools there are, proclaiming them the “killer” of whatever came before and trying to force old square pegs into shiny new round holes. Teams is no different.</p>



<p>As an instant messaging platform, Teams is ideal for back-and-forth quick hits. If your message is longer than a paragraph, chances are, it should go back to email. Longer conversations, project planning, longer term development, all of those types of deep thinking and analysis are best suited for email. In email, you can sort, filter, set up rules, and do other automated things to manage how you see and find information. It’s not impossible to use Teams for longer conversations, but it’s suboptimal.</p>



<p><strong>Trying to send emails to external folks.</strong> Unfortunately, there is no way for Teams to send email out to the internet, so unless you want to invite external users as guests into your team (assuming you have permission to do that), you will need to handle some subjects that involve people outside of your organization via old-fashioned email messages. That, of course, limits the utility of using Teams in projects or environments with a lot of collaboration with external users when they’re not a part of your Teams environment.</p>



<p>Your organization may restrict how external users can interact with your Microsoft 365 setup, usually via data loss prevention policies and prohibitions on folks outside your organization accessing Teams chats and channels. Ask your IT department if you have questions.</p>



<p><em>This article was originally published in March 2018 and most recently updated in April 2026.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (capstone, cockpit, firefox, git-lfs, golang-github-openprinting-ipp-usb, kea, kernel, nghttp2, nodejs24, openexr, perl-XML-Parser, rsync, squid, and vim), Debian (imagemagick, systemd, and thunderbird), Slackware (libexif and xorg), SUSE (bind, clam...]]></description>
<link>https://tsecurity.de/de/3435604/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435604/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 15 Apr 2026 15:22:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (capstone, cockpit, firefox, git-lfs, golang-github-openprinting-ipp-usb, kea, kernel, nghttp2, nodejs24, openexr, perl-XML-Parser, rsync, squid, and vim), <b>Debian</b> (imagemagick, systemd, and thunderbird), <b>Slackware</b> (libexif and xorg), <b>SUSE</b> (bind, clamav, firefox, freerdp2, giflib, go1.25, go1.26, helm, ignition, libpng16, libssh, oci-cli, rust1.92, strongswan, sudo, xorg-x11-server, and xwayland), and <b>Ubuntu</b> (rust-tar and rustc, rustc-1.76, rustc-1.77, rustc-1.78, rustc-1.79, rustc-1.80).]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,11ms -->