<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=isnt+weakits+underused+promptnova%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 03:54:28 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 03:54:28 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=isnt+weakits+underused+promptnova%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=isnt+weakits+underused+promptnova%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694780/ai-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Own nothing, upgrade everything: Apple’s new Klarna deal]]></title>
<description><![CDATA[Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to launch its new deal with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread a...]]></description>
<link>https://tsecurity.de/de/3694772/ai-nachrichten/own-nothing-upgrade-everything-apples-new-klarna-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694772/ai-nachrichten/own-nothing-upgrade-everything-apples-new-klarna-deal/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to <a href="https://www.reuters.com/business/apple-launch-upgrade-device-leasing-program-spur-sales-bloomberg-news-reports-2026-07-21/" target="_blank" rel="noreferrer noopener">launch its new deal</a> with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread across up to three years.</p>



<p class="wp-block-paragraph">This matters because when combined with Apple One and Apple’s Creator Studio subscriptions, the Klarna arrangement brings Apple closer to offering a full subscription model for hardware, software, and services. The only thing you don’t get under the new arrangement is AppleCare, for which you’ll allegedly need to pay extra.</p>



<h2 class="wp-block-heading"><strong>Moving closer to hardware-as-a-service</strong></h2>



<p class="wp-block-paragraph">Apple has slowly been <a href="https://www.applemust.com/opinion-how-you-will-access-apple-products-in-future/#google_vignette" target="_blank" rel="noreferrer noopener">transitioning toward</a> hardware-as-a-service for almost a decade. Back then, Forrester analyst <a href="https://www.applemust.com/apple-klarna-mean-we-can-now-get-apple-as-a-service/" target="_blank" rel="noreferrer noopener">Frank Gillet predicted</a> the company would eventually offer bundles of services and products for a monthly, all-in, fee. </p>



<p class="wp-block-paragraph">This isn’t quite where we are yet; you still need at least three subscriptions to get close. But, after the better part of a decade, Apple has moved much nearer to the hardware-as-a-service idea.</p>



<p class="wp-block-paragraph">There are some products reportedly excluded from the arrangement, including MacBook Neo, Apple Watch SE, the entry-level iPad, and iPhone 16. Clearly, Apple sees those products as sufficiently affordable. </p>



<h2 class="wp-block-heading"><strong>Easy payments for RAM-ageddon</strong></h2>



<p class="wp-block-paragraph">The new Klarna arrangement comes as Apple is forced to increase product prices as AI-driven memory price inflation becomes widely felt across every economy. In theory, I assume, Apple hopes to make its products available to cash-strapped consumers who need new hardware, while also navigating a time of deep economic tumult and uncertainty. It’s thought the company has <a href="https://www.bloomberg.com/news/newsletters/2025-04-06/will-apple-raise-iphone-prices-in-the-us-after-trump-tariffs-iphone-17-details" target="_blank" rel="noreferrer noopener">previously rejected these plans</a> to protect normal hardware sales, but normality is a kingdom we no longer seem to possess. Interesting times. Probable inflation incoming.</p>



<p class="wp-block-paragraph">“Apple Upgrade lands at precisely the moment Apple needs it,” IDC analyst Francisco Jeronimo wrote in a note seen by <em>Computerworld</em>. “Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September — as well as the new iPhone foldable expected at $2,500 — Apple’s real risk is that rising prices even further can impact the upgrade cycle.” </p>



<h2 class="wp-block-heading"><strong>New age, new shopping habits</strong></h2>



<p class="wp-block-paragraph">The introduction of the scheme gives consumers a way to purchase the company’s popular high-end devices when they are introduced — no doubt,at higher cost — this fall. Plus, of course, if it’s <a href="https://www.businessinsider.com/general-motors-gm-earnings-subscriptions-revenue-business-2026-1" target="_blank" rel="noreferrer noopener">good enough for GM</a>, it’s good enough for Apple.</p>



<p class="wp-block-paragraph">It’s all about attitude, too. From Apple’s perspective, it <a href="https://www.computerworld.com/article/4125784/are-you-ready-for-apple-as-a-service.html">has done plenty of the groundwork</a> required to <a href="https://www.applemust.com/apple-vp-eddy-cue-shares-15-important-apple-services-stats/" target="_blank" rel="noreferrer noopener">convince its customers</a> that subscription payments for things you value are no bad thing. </p>



<p class="wp-block-paragraph">Reluctance to embrace “Access Not Ownership’”purchasing models has dropped dramatically since Apple — and <a href="https://www.computerworld.com/article/1665439/apples-tim-cook-has-kept-his-50b-services-promises.html">CEO Tim Cook</a> — first began <a href="https://www.applemust.com/apples-50b-services-target-just-isnt-ambitious-enough/">banging the drum</a> for services income. Apple’s services stream has now become its second-biggest revenue driver after the iPhone. It has over 1 billion paid subscriptions, and an active hardware installed base of <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">more than 2.5 billion devices globally</a>.</p>



<p class="wp-block-paragraph">A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. “Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do,” Jeronimo wrote to me. </p>



<p class="wp-block-paragraph">There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but <a href="https://medium.com/from-heart-to-hand/the-subscription-society-what-happens-when-you-own-nothing-ef32d5bc32d2" target="_blank" rel="noreferrer noopener">probably can’t afford to own</a>.</p>



<h2 class="wp-block-heading"><strong>Managing future risk</strong></h2>



<p class="wp-block-paragraph">The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but <a href="https://www.bbc.co.uk/news/articles/c255y82y9x8o" target="_blank" rel="noreferrer noopener">abandoned that plan</a> as it became riskier with rising bank rates. “Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet,” Jeronimo said.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘The Odyssey’ isn’t on IMAX 70mm in Seattle — is it worth a journey for the summer’s biggest film?]]></title>
<description><![CDATA[Want to see "The Odyssey" as director Christopher Nolan intended? Here is how formats and theaters compare across 70mm, IMAX, and digital — and why a road trip may be needed. Read More]]></description>
<link>https://tsecurity.de/de/3692214/it-nachrichten/the-odyssey-isnt-on-imax-70mm-in-seattle-is-it-worth-a-journey-for-the-summers-biggest-film/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692214/it-nachrichten/the-odyssey-isnt-on-imax-70mm-in-seattle-is-it-worth-a-journey-for-the-summers-biggest-film/</guid>
<pubDate>Fri, 24 Jul 2026 19:50:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="1260" height="709" src="https://cdn.geekwire.com/wp-content/uploads/2026/07/odyssey-1260x709.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/07/odyssey-1260x709.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/07/odyssey-768x432.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/07/odyssey.jpg 1280w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Want to see "The Odyssey" as director Christopher Nolan intended? Here is how formats and theaters compare across 70mm, IMAX, and digital — and why a road trip may be needed. <a href="https://www.geekwire.com/2026/the-odyssey-isnt-on-imax-70mm-in-seattle-is-it-worth-a-journey-for-the-summers-biggest-film/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Federal quantum bet grows with DARPA’s $125 million PsiQuantum award]]></title>
<description><![CDATA[Defense research agency DARPA made its largest quantum computing award ever this week, with a $125 million agreement announced on Wednesday. The same day, the White House announced an additional $5 billion for the Genesis Mission, which focuses on AI for science but also includes technology to ac...]]></description>
<link>https://tsecurity.de/de/3689459/it-security-nachrichten/federal-quantum-bet-grows-with-darpas-125-million-psiquantum-award/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689459/it-security-nachrichten/federal-quantum-bet-grows-with-darpas-125-million-psiquantum-award/</guid>
<pubDate>Thu, 23 Jul 2026 17:13:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Defense research agency DARPA made its largest quantum computing award ever this week, with a <a href="https://www.psiquantum.com/news-import/psiquantum-signs-125-million-agreement-with-darpa">$125 million agreement</a> announced on Wednesday. The same day, the White House announced an <a href="https://www.whitehouse.gov/releases/2026/07/45502/">additional $5 billion for the Genesis Mission</a>, which focuses on AI for science but also includes technology to accelerate quantum computing and quantum sensors.</p>



<p class="wp-block-paragraph">“Taken together, these announcements signal that U.S. quantum strategy is shifting from supporting individual research projects to building the infrastructure needed for a quantum-enabled economy,” says <a href="https://www.linkedin.com/in/heather-c-west-ph-d-52075667/">Heather West</a>, research manager in the infrastructure systems, platforms, and technology group at IDC.</p>



<p class="wp-block-paragraph">None of the individual quantum announcements are surprising, she says. But the level of coordination is new. “Government investment is expanding beyond foundational research toward commercialization, manufacturing, and deployment,” she says.</p>



<p class="wp-block-paragraph">“The US government has been signaling that quantum computing is a priority,” says <a href="https://www.linkedin.com/in/davidmooter/">David Mooter</a>, an analyst at Forrester Research. Part of it is the desire for the US to be a leader in quantum, as it has been in other high-tech areas, he says. And part of it is because the government itself can take advantage of quantum computers.</p>



<p class="wp-block-paragraph">“Spy agencies would love to use them to decrypt intercepted messages, including messages they intercepted years ago and saved,” he says. And other departments could use quantum computers or networks for energy-related research, for supply chain optimization, and for secure communications. </p>



<p class="wp-block-paragraph">Quantum computing is accelerating, he says. “I would not be surprised to see a general gate-based quantum computer that’s good enough to provide commercial value for limited use cases by 2030.”</p>



<h2 class="wp-block-heading">DARPA’s Quantum Benchmarking Initiative</h2>



<p class="wp-block-paragraph">DARPA’s Quantum Benchmarking Initiatives was launched in 2024, and 18 companies were selected in April of 2025 for <a href="https://www.darpa.mil/news/2025/companies-targeting-quantum-computers">Stage A of the project</a>, with awards of up to $1 million each. The companies were to use the money to provide details of their concepts and show how they could lead to a functional, fault-tolerant quantum computer in under a decade.</p>



<p class="wp-block-paragraph">Then, in November of 2025, DARPA chose 11 companies for <a href="https://www.darpa.mil/research/programs/quantum-benchmarking-initiative/stage-b-selection">Stage B of the project</a>, with awards of up to $15 million for developing their research plans.</p>



<p class="wp-block-paragraph">To date, only two companies have been chosen for <a href="https://www.darpa.mil/news/2025/quantum-computing-approaches">Stage C</a>: PsiQuantum and Microsoft. PsiQuantum announced $32 million of DARPA funding for testing and evaluation in September of last year. This week’s $125 million award will expand the scope and pacing of the validation and verification work. Stage C awards can go up to $300 million, <a href="https://www.darpa.mil/sites/default/files/attachment/2025-09/darpa-mto-spark-tank-qbi.pdf">according to DARPA</a>.</p>



<p class="wp-block-paragraph">This past May, <a href="https://www.psiquantum.com/news-import/us-department-of-commerce">PsiQuantum also announced $100 million</a> from the Department of Commerce, part of the CHIPS and Science Act, to accelerate domestic manufacturing of critical quantum computing components.</p>



<p class="wp-block-paragraph">Microsoft and PsiQuantum are both in Stage C, bypassing the sequential path that other companies are expected to follow, because they were both part of DARPA’s predecessor to QBI, the Underexplored Systems for Utility-Scale Quantum Computing program.</p>



<h2 class="wp-block-heading">Genesis Mission</h2>



<p class="wp-block-paragraph">Genesis Mission was <a href="https://www.whitehouse.gov/presidential-actions/2025/11/launching-the-genesis-mission/">launched</a> in late 2025 with the goal of using AI to accelerate scientific breakthroughs, and it now includes more than 15 government agencies.</p>



<p class="wp-block-paragraph">As part of the Genesis Mission, quantum computing and sensing company Infleqtion announced <a href="https://infleqtion.com/infleqtion-secures-three-genesis-mission-projects-from-u-s-department-of-energy/">three projects for the Department of Energy</a> on Wednesday. The three projects focus on quantum circuit design for nuclear applications, atomic quantum sensing, and nuclear fusion energy research.</p>



<p class="wp-block-paragraph">This announcement did not include the total monetary value of the projects, but, in May, the company announced a separate agreement with the Department of Commerce for $100 million to accelerate Infleqtion’s neutral-atom technology roadmap.</p>



<p class="wp-block-paragraph">Other quantum-related Genesis Mission projects announced this week include $1.5 million for a <a href="https://www.bluequbit.io/blog/bluequbit-and-partners-awarded-1-5m-in-doe-genesis-mission-grants-to-advance-ai-driven-quantum-error-correction">BlueQubit quantum error correction project</a> with Microsoft and other partners, a <a href="https://news.stanford.edu/stories/2026/07/stanford-and-slac-to-lead-genesis-mission-projects-that-tackle-the-nation-s-most-complex-science-and-technology-challenges">Stanford effort</a> to model the behavior of electrons at quantum scale, an <a href="https://news.mit.edu/2026/mit-projects-selected-funding-under-doe-genesis-mission-0723">MIT quantum sensing project</a>, Argonne National Laboratory <a href="https://www.anl.gov/article/argonne-to-lead-ai-research-projects-under-the-department-of-energys-genesis-mission">projects</a> on quantum circuit design and quantum sensors, Brookhaven Lab <a href="https://www.bnl.gov/newsroom/news.php?a=123041">quantum sensor projects</a>, and quantum computing <a href="https://news.northwestern.edu/stories/2026/07/northwestern-projects-receive-genesis-mission-funding">projects</a> at Northwestern University.</p>



<p class="wp-block-paragraph">IBM, one of three dozen private companies that are part of the <a href="https://www.genesismissionconsortium.org/our-members#private-sector">Genesis Mission Consortium</a>, announced that it will be leading a <a href="https://research.ibm.com/blog/ibm-us-genesis-mission-quantum-ai">project</a> to support more effective quantum applications, and will contribute up to $50 million of quantum compute access for the Genesis Mission.</p>



<h2 class="wp-block-heading">Enterprise priorities</h2>



<p class="wp-block-paragraph">This week’s quantum announcements aren’t a sign that enterprises need to run out and buy quantum computers, says IDC’s West. But they do need to start preparing for the quantum era — such as by identifying business areas where quantum computing could become a competitive differentiator over the next decade.</p>



<p class="wp-block-paragraph">But the most immediate threat is that of adversaries using quantum computers to break current encryption standards. Organizations should be inventorying cryptographic assets and developing a roadmap for the migration to quantum-proof algorithms, West says.</p>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4158139/fixing-encryption-isnt-enough-quantum-developments-put-focus-on-authentication.html">The point of no return is closer than ever</a>, and many major players in the encryption and communication space, including Google and Cloudflare, have been accelerating their timelines. In fact, this Wednesday was the <a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">federal deadline</a> for naming their post-quantum cryptography migration leads under a June executive order.</p>



<p class="wp-block-paragraph">“The preparation that needs to be done to prepare is to implement post-quantum cryptography yesterday,” says Forrester’s Mooter.</p>



<p class="wp-block-paragraph">However, according to a survey <a href="https://www.digicert.com/news/quantum-security-deployment-remains-stuck">released by DigiCert this morning</a>, while 87% of organizations are planning, testing or implementing PQC initiatives, only 7% of organizations have deployed quantum-safe or hybrid cryptography across most of their digital certificates.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[bringing mainline Linux to the Nokia Lumia 1520]]></title>
<description><![CDATA[Hey everyone, I’ve been working on getting a modern mainline Linux stack running on the Nokia Lumia 1520, a 2013 Windows Phone built around Qualcomm’s MSM8974 platform. This isnt an Android ROM port or a Windows Phone mod. The goal is to bring the device up on a current Linux kernel with postmark...]]></description>
<link>https://tsecurity.de/de/3687880/linux-tipps/bringing-mainline-linux-to-the-nokia-lumia-1520/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687880/linux-tipps/bringing-mainline-linux-to-the-nokia-lumia-1520/</guid>
<pubDate>Thu, 23 Jul 2026 04:29:03 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone,</p> <p>I’ve been working on getting a modern mainline Linux stack running on the Nokia Lumia 1520, a 2013 Windows Phone built around Qualcomm’s MSM8974 platform.</p> <p>This isnt an Android ROM port or a Windows Phone mod. The goal is to bring the device up on a current Linux kernel with postmarketOS and gradually implement the missing hardware support needed to make it usable.</p> <p>So far, I’ve managed to:</p> <ul> <li>Build a custom bootloader and device-tree configuration</li> <li>Create a postmarketOS device package for the RM-940</li> <li>Boot a Linux 6.16-based kernel</li> <li>Bring up USB networking</li> <li>Establish a stable SSH connection to the phone</li> <li>Run an Alpine Linux/postmarketOS userspace</li> <li>Begin implementing device-specific power and hardware support</li> </ul> <p>The SSH milestone was a major step because I can now properly inspect the running system, collect logs, test kernel changes, and continue development without relying only on framebuffer output or early boot behavior.</p> <p>The current challenge is power management.</p> <p>Full system suspend currently powers down the USB high-speed PHY, but the PHY fails to initialize again when the device resumes. Because USB networking is also the main development connection, this effectively cuts off access to the phone.</p> <p>For now, I’m treating display blanking and panel power management as a separate, more achievable target while I continue investigating the suspend/resume issue.</p> <p>There is still a lot missing, and I would not call it a usable daily-driver port yet, but the Lumia 1520 is now booting a modern Linux kernel and running a real userspace more than a decade after the hardware was released. I just wanted to share the work....</p> <p>The work is public here:</p> <p><a href="https://github.com/KorelisLabs/lumia-1520-mainline">https://github.com/KorelisLabs/lumia-1520-mainline</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/DestinyInDepth"> /u/DestinyInDepth </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v3s3p3/bringing_mainline_linux_to_the_nokia_lumia_1520/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v3s3p3/bringing_mainline_linux_to_the_nokia_lumia_1520/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Own nothing, upgrade everything: Apple’s new Klarna deal]]></title>
<description><![CDATA[Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to launch its new deal with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread a...]]></description>
<link>https://tsecurity.de/de/3687133/it-nachrichten/own-nothing-upgrade-everything-apples-new-klarna-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687133/it-nachrichten/own-nothing-upgrade-everything-apples-new-klarna-deal/</guid>
<pubDate>Wed, 22 Jul 2026 19:18:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Just in time for the iPhone’s 20th anniversary, Apple is moving closer to becoming a service company. It is set to <a href="https://www.reuters.com/business/apple-launch-upgrade-device-leasing-program-spur-sales-bloomberg-news-reports-2026-07-21/" target="_blank" rel="noreferrer noopener">launch its new deal</a> with Klarna next week and when it does, Apple enthusiasts in the US will effectively be able to subscribe to their favorite Apple hardware, with the cost spread across up to three years.</p>



<p class="wp-block-paragraph">This matters because when combined with Apple One and Apple’s Creator Studio subscriptions, the Klarna arrangement brings Apple closer to offering a full subscription model for hardware, software, and services. The only thing you don’t get under the new arrangement is AppleCare, for which you’ll allegedly need to pay extra.</p>



<h2 class="wp-block-heading"><strong>Moving closer to hardware-as-a-service</strong></h2>



<p class="wp-block-paragraph">Apple has slowly been <a href="https://www.applemust.com/opinion-how-you-will-access-apple-products-in-future/#google_vignette" target="_blank" rel="noreferrer noopener">transitioning toward</a> hardware-as-a-service for almost a decade. Back then, Forrester analyst <a href="https://www.applemust.com/apple-klarna-mean-we-can-now-get-apple-as-a-service/" target="_blank" rel="noreferrer noopener">Frank Gillet predicted</a> the company would eventually offer bundles of services and products for a monthly, all-in, fee. </p>



<p class="wp-block-paragraph">This isn’t quite where we are yet; you still need at least three subscriptions to get close. But, after the better part of a decade, Apple has moved much nearer to the hardware-as-a-service idea.</p>



<p class="wp-block-paragraph">There are some products reportedly excluded from the arrangement, including MacBook Neo, Apple Watch SE, the entry-level iPad, and iPhone 16. Clearly, Apple sees those products as sufficiently affordable. </p>



<h2 class="wp-block-heading"><strong>Easy payments for RAM-ageddon</strong></h2>



<p class="wp-block-paragraph">The new Klarna arrangement comes as Apple is forced to increase product prices as AI-driven memory price inflation becomes widely felt across every economy. In theory, I assume, Apple hopes to make its products available to cash-strapped consumers who need new hardware, while also navigating a time of deep economic tumult and uncertainty. It’s thought the company has <a href="https://www.bloomberg.com/news/newsletters/2025-04-06/will-apple-raise-iphone-prices-in-the-us-after-trump-tariffs-iphone-17-details" target="_blank" rel="noreferrer noopener">previously rejected these plans</a> to protect normal hardware sales, but normality is a kingdom we no longer seem to possess. Interesting times. Probable inflation incoming.</p>



<p class="wp-block-paragraph">“Apple Upgrade lands at precisely the moment Apple needs it,” IDC analyst Francisco Jeronimo wrote in a note seen by <em>Computerworld</em>. “Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September — as well as the new iPhone foldable expected at $2,500 — Apple’s real risk is that rising prices even further can impact the upgrade cycle.” </p>



<h2 class="wp-block-heading"><strong>New age, new shopping habits</strong></h2>



<p class="wp-block-paragraph">The introduction of the scheme gives consumers a way to purchase the company’s popular high-end devices when they are introduced — no doubt,at higher cost — this fall. Plus, of course, if it’s <a href="https://www.businessinsider.com/general-motors-gm-earnings-subscriptions-revenue-business-2026-1" target="_blank" rel="noreferrer noopener">good enough for GM</a>, it’s good enough for Apple.</p>



<p class="wp-block-paragraph">It’s all about attitude, too. From Apple’s perspective, it <a href="https://www.computerworld.com/article/4125784/are-you-ready-for-apple-as-a-service.html">has done plenty of the groundwork</a> required to <a href="https://www.applemust.com/apple-vp-eddy-cue-shares-15-important-apple-services-stats/" target="_blank" rel="noreferrer noopener">convince its customers</a> that subscription payments for things you value are no bad thing. </p>



<p class="wp-block-paragraph">Reluctance to embrace “Access Not Ownership’”purchasing models has dropped dramatically since Apple — and <a href="https://www.computerworld.com/article/1665439/apples-tim-cook-has-kept-his-50b-services-promises.html">CEO Tim Cook</a> — first began <a href="https://www.applemust.com/apples-50b-services-target-just-isnt-ambitious-enough/">banging the drum</a> for services income. Apple’s services stream has now become its second-biggest revenue driver after the iPhone. It has over 1 billion paid subscriptions, and an active hardware installed base of <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">more than 2.5 billion devices globally</a>.</p>



<p class="wp-block-paragraph">A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. “Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do,” Jeronimo wrote to me. </p>



<p class="wp-block-paragraph">There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but <a href="https://medium.com/from-heart-to-hand/the-subscription-society-what-happens-when-you-own-nothing-ef32d5bc32d2" target="_blank" rel="noreferrer noopener">probably can’t afford to own</a>.</p>



<h2 class="wp-block-heading"><strong>Managing future risk</strong></h2>



<p class="wp-block-paragraph">The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but <a href="https://www.bbc.co.uk/news/articles/c255y82y9x8o" target="_blank" rel="noreferrer noopener">abandoned that plan</a> as it became riskier with rising bank rates. “Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet,” Jeronimo said.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt Engineering Isn’t Enough: How Four Bricks of Context Engineering Stop RAG Hallucinations]]></title>
<description><![CDATA[Enterprise Document Intelligence [Vol.1 #9bis] - Your RAG isn’t hallucinating, it’s answering the wrong context faithfully. On real NIST and World Bank documents, watch each of the four bricks break, and the contract that closes it
The post Prompt Engineering Isn’t Enough: How Four Bricks of Cont...]]></description>
<link>https://tsecurity.de/de/3684373/ai-nachrichten/prompt-engineering-isnt-enough-how-four-bricks-of-context-engineering-stop-rag-hallucinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684373/ai-nachrichten/prompt-engineering-isnt-enough-how-four-bricks-of-context-engineering-stop-rag-hallucinations/</guid>
<pubDate>Tue, 21 Jul 2026 18:35:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise Document Intelligence [Vol.1 #9bis] - Your RAG isn’t hallucinating, it’s answering the wrong context faithfully. On real NIST and World Bank documents, watch each of the four bricks break, and the contract that closes it</p>
<p>The post <a href="https://towardsdatascience.com/prompt-engineering-isnt-enough-how-four-bricks-of-context-engineering-stop-rag-hallucinations/">Prompt Engineering Isn’t Enough: How Four Bricks of Context Engineering Stop RAG Hallucinations</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple could ‘run the table’ on AI if it does things right]]></title>
<description><![CDATA[Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.



Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to hel...]]></description>
<link>https://tsecurity.de/de/3681267/it-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681267/it-nachrichten/apple-could-run-the-table-on-ai-if-it-does-things-right/</guid>
<pubDate>Mon, 20 Jul 2026 15:33:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment.</p>



<p class="wp-block-paragraph">Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get things done through Siri AI.</p>



<p class="wp-block-paragraph">Apple also <a href="https://www.macobserver.com/news/apple-calls-its-new-assistant-siri-ai-at-wwdc-2026-gemini-partnership-now-official/" target="_blank" rel="noreferrer noopener">offers limited capacity for more complex tasks</a> through <a href="https://www.applemust.com/apple-commences-us-manufacturing-of-private-cloud-compute-servers/" target="_blank" rel="noreferrer noopener">Private Cloud Compute</a>, and, in partnership with the likes of Google in the US and Alibaba in China, the company is giving users a trusted conduit through which to access even more sophisticated AI services. </p>



<h2 class="wp-block-heading"><strong>Deeply deployable</strong></h2>



<p class="wp-block-paragraph">Critics can say it <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">took Apple a long time</a> to get to this point, but they also seem to think the company has finally got the mix right with its series 27 operating systems. Arriving late to a party <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">doesn’t mean you won’t shine once you get there</a>.</p>



<p class="wp-block-paragraph">Apple is also coming up the inside lane around frontier AI, with iterative OS and hardware enhancements that mean its devices become increasingly effective for <a href="https://www.computerworld.com/article/4016798/why-i-hope-apple-keeps-investing-in-on-device-ai.html">Edge AI use cases</a>, on device — no cloud service required.</p>



<p class="wp-block-paragraph">The company appears to be digging down into those use cases. Mark Gurman at Bloomberg recently predicted that <a href="https://www.tomshardware.com/tech-industry/semiconductors/apples-rumored-m7-ultra-targets-1-5tb-of-memory-and-blackwell-class-ai" target="_blank" rel="noreferrer noopener">future M7 Ultra Macs</a> will support as much as 1.5TB RAM, making these systems more than capable of running full weight frontier models in people’s offices, colleges, and homes. </p>



<p class="wp-block-paragraph">While that does assume the <a href="https://www.computerworld.com/article/4187825/the-trillion-dollar-ai-hallucination.html">AI-flationary memory market</a> can supply that much RAM at prices humans can afford, it is also true that people are already <a href="https://www.computerworld.com/article/4092162/apples-macos-ai-for-the-rest-of-us.html">running AI clusters</a> using off-the-shelf Mac minis networked over Thunderbolt cables. It’s no stretch to believe <a href="https://www.applemust.com/macweb-now-offers-mac-mini-cloud-clusters-in-east-coast-data-centre/" target="_blank" rel="noreferrer noopener">this will continue to be the case</a>, and that it will even broaden as the power/performance offered at the high end grows.</p>



<h2 class="wp-block-heading"><strong>What’s wrong with good enough?</strong></h2>



<p class="wp-block-paragraph">When combined with open AI stacks, particularly newly emerging varieties, Apple’s platforms should become leading contenders for <a href="https://www.computerworld.com/article/4074648/apples-big-bang-ai-moment-is-approaching.html">private AI services</a> and edge AI. Many business users will leap at the chance to offer their workers powerful, self-hosted, private AI services using one or more daisy-chained Mac Studios or Mac minis. The recent craze in deployment of both Macs to support <a href="https://openclaw.ai/" target="_blank" rel="noreferrer noopener">OpenClaw</a> instances shows they already are.</p>



<p class="wp-block-paragraph">Ultimately, these different slices of momentum mean I agree with <a href="https://podcastalpha.substack.com/p/all-in-can-ai-regulate-itself-stripe" target="_blank" rel="noreferrer noopener">investor Jason Calacanis</a> that Apple is in position to apply a great deal of pressure on OpenAI and Claude just by putting models on their devices. </p>



<p class="wp-block-paragraph">It’s also worth thinking about how people use AI today. How many of the queries made in the world right now constitute relatively simple tasks that could be transacted by on-device AI, such as the emerging new version of Apple Intelligence or even smaller LLM models running on device? You can even run <a href="https://9to5mac.com/2026/07/14/prismml-releases-bonsai-27b-claiming-first-major-ai-model-of-its-size-fit-for-iphone/" target="_blank" rel="noreferrer noopener">PrismML’s 1-bit, 27-billion parameter Bonsai</a> on an iPad using the Locally app, and that’s in the here and now.</p>



<p class="wp-block-paragraph">What happens? Pretty soon you’ll find people recognize that they can already run the vast majority of their AI-augmented workflows using services they <a href="https://www.applemust.com/morgan-stanley-its-when-not-if-apple-will-deliver-ai-on-the-edge/" target="_blank" rel="noreferrer noopener">have on their existing device</a> or can access on their on-prem Mac set-ups. And, of course, as people get used to running small tasks locally and larger tasks on premises, the actual space in which they need to turn to cloud-based frontier models <a href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html">will erode</a>. That’s even as companies like PrismML work towards slimming down full-weight models so they don’t need to run on a server at all. </p>



<p class="wp-block-paragraph">“It’s going to be wild when people have unlimited tokens on their desks,” said Calacanis in a podcast round table discussion.</p>



<h2 class="wp-block-heading"><strong>Who has the most to lose?</strong></h2>



<p class="wp-block-paragraph">The current incarnations of AI felt like they came from nowhere. Most people weren’t aware of the technology until returning to work after the 2022 holiday season. Since then, the industry has proliferated with dozens of competing models, most recently including powerful but affordable frontier models such as Qwen and Kimi.ai.</p>



<p class="wp-block-paragraph">These models aren’t necessarily all as good as one another, but in many cases for much of what we do, we’ll find them to be good enough. That’s an existential crisis for some, as industry observers now think the inevitable pricing pressure means some services might have over-invested in capacity before finding any way to turn a profit.</p>



<p class="wp-block-paragraph">Those profit-seeking services are the ones with the most to lose as Apple extends its hardware advantage, democratizing AI access for all while providing platforms suitable for edge AI, on-premises AI, private AI, and even AI access using third-party services. (The need for the latter will shrink as the capabilities of the former get better.)</p>



<h2 class="wp-block-heading"><strong>Cupertino rising</strong></h2>



<p class="wp-block-paragraph">What does this all mean? While the industry remains young, it is already fragmenting. And striding through the dust of that process comes Apple, equipped with the hardware, software, and approach to build its business even as the enterprise of first mover AI services erodes. </p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to my daily Apple-related news summaries at <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple probably won't add Jony Ive to OpenAI trade secret theft suit]]></title>
<description><![CDATA[Four years ago, Jony Ive left Apple, and joined OpenAI, yet he isn't named in the intellectual property theft suit. The reasons for that are myriad, ranging from the personal to practical.Jony Ive & OpenAI's Sam Altman | Image Credit: OpenAIOn July 10, Apple launched what looks to become a major ...]]></description>
<link>https://tsecurity.de/de/3679663/ios-mac-os/apple-probably-wont-add-jony-ive-to-openai-trade-secret-theft-suit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679663/ios-mac-os/apple-probably-wont-add-jony-ive-to-openai-trade-secret-theft-suit/</guid>
<pubDate>Sun, 19 Jul 2026 17:08:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Four years ago, <a href="https://appleinsider.com/inside/jony-ive" title="Jony Ive" data-kpt="1">Jony Ive</a> left Apple, and joined OpenAI, yet he isn't named in the intellectual property theft suit. The reasons for that are myriad, ranging from the personal to practical.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68288-143945-64318-134009-iveandalt-xl-xl.jpg" alt="Two men pose closely in black and white, one wearing glasses and leaning on the other's shoulder, both looking calmly at the camera against a simple background" height="738"><br><span>Jony Ive &amp; OpenAI's Sam Altman | Image Credit: OpenAI</span></div><br>On July 10, <a href="https://appleinsider.com/articles/26/07/10/apple-sues-openai-previous-vp-of-product-design-over-mass-ip-theft">Apple launched</a> what looks to become a <a href="https://appleinsider.com/articles/26/07/13/apples-corporate-espionage-suit-against-openai-isnt-the-first">major lawsuit</a> against OpenAI, accusing ex-Apple employees of stealing intellectual property. However, despite former Apple design chief's links to OpenAI, he isn't in the crosshairs of Apple's lawyers.<br><br>In Sunday's "Power On" <a href="https://www.bloomberg.com/news/newsletters/2026-07-19/why-apple-s-openai-lawsuit-doesn-t-mention-jony-ive-ai-recording-at-genius-bar-mrrv4mix?srnd=undefined">newsletter</a> for <em>Bloomberg</em>, Mark Gurman writes about the lawsuit and the oddity. He believes there are two big reasons for Apple not to implicate Ive in the lawsuit at all.<br><br><br> <a href="https://appleinsider.com/articles/26/07/19/apple-probably-wont-add-jony-ive-to-openai-trade-secret-theft-suit?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244994?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Context Engineering Isn’t Enough — A Loop Engineering Experiment With No LLM Inside the Loop]]></title>
<description><![CDATA[Everyone is talking about loop engineering, but most discussions assume an LLM sits at the center of the loop. I wanted to isolate the architecture itself. So I built a deterministic, zero-dependency Python benchmark that replaces the model with simple rules, allowing me to measure one question d...]]></description>
<link>https://tsecurity.de/de/3676200/ai-nachrichten/context-engineering-isnt-enough-a-loop-engineering-experiment-with-no-llm-inside-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676200/ai-nachrichten/context-engineering-isnt-enough-a-loop-engineering-experiment-with-no-llm-inside-the-loop/</guid>
<pubDate>Fri, 17 Jul 2026 15:33:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Everyone is talking about loop engineering, but most discussions assume an LLM sits at the center of the loop. I wanted to isolate the architecture itself. So I built a deterministic, zero-dependency Python benchmark that replaces the model with simple rules, allowing me to measure one question directly: can a goal-directed controller isolate failures better than a traditional linear pipeline? After validating the benchmark across 300 random seeds—and fixing a subtle bug that initially invalidated my own results—I found that the controller consistently completed independent branches that a linear executor never reached. This article walks through the architecture, the benchmark design, the debugging process, and the evidence behind a narrow but practical claim: failure isolation is a measurable property of control flow, independent of LLM reasoning.</p>
<p>The post <a href="https://towardsdatascience.com/context-engineering-isnt-enough-a-loop-engineering-experiment-with-no-llm-inside-the-loop/">Context Engineering Isn’t Enough — A Loop Engineering Experiment With No LLM Inside the Loop</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MediaArena malvertising: why a quarantine isn’t the end of the incident]]></title>
<description><![CDATA[If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21…
Read more →
The post MediaArena malver...]]></description>
<link>https://tsecurity.de/de/3675888/it-security-nachrichten/mediaarena-malvertising-why-a-quarantine-isnt-the-end-of-the-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675888/it-security-nachrichten/mediaarena-malvertising-why-a-quarantine-isnt-the-end-of-the-incident/</guid>
<pubDate>Fri, 17 Jul 2026 13:23:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/mediaarena-malvertising-why-a-quarantine-isnt-the-end-of-the-incident/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/mediaarena-malvertising-why-a-quarantine-isnt-the-end-of-the-incident/">MediaArena malvertising: why a quarantine isn’t the end of the incident</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI model should you bet your company on? None of them]]></title>
<description><![CDATA[Every day this past week I did something I suspect millions of other people also did: I stared at an LLM model picker and wondered which one I was supposed to want.



OpenAI just released ⁠GPT-5.6 Sol, Terra, and Luna. Sol is the flagship. Terra offers much of its intelligence for less money. Lu...]]></description>
<link>https://tsecurity.de/de/3671165/ai-nachrichten/which-ai-model-should-you-bet-your-company-on-none-of-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671165/ai-nachrichten/which-ai-model-should-you-bet-your-company-on-none-of-them/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every day this past week I did something I suspect millions of other people also did: I stared at an <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM </a>model picker and wondered which one I was supposed to want.</p>



<p class="wp-block-paragraph">OpenAI just released ⁠<a href="https://openai.com/index/gpt-5-6/">GPT-5.6 Sol, Terra, and Luna</a>. Sol is the flagship. Terra offers much of its intelligence for less money. Luna is cheaper still. Anthropic released ⁠<a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a> at the end of June and Opus 4.8 the month prior, with a little Fable 5 emerging in between. Meanwhile, Google, which seemed to be winning the model wars a few months ago, is now getting shade from Gergely Orosz, who ⁠<a href="https://x.com/GergelyOrosz/status/2075160978493210685?s=20">argues that Gemini has slipped outside the top tier</a> for software development and has been out of the major model release game for <em>eons</em> (May 19).</p>



<p class="wp-block-paragraph">Perhaps Orosz is right. Perhaps he’ll be wrong again in six weeks. Honestly, it’s exhausting.</p>



<p class="wp-block-paragraph">I use ChatGPT and Claude constantly and still have no principled idea which model to choose most of the time. I tend to click whatever looks like the biggest, most expensive option because I don’t know what I’m giving up by choosing something smaller. “Instant” sounds dangerously unserious. “Thinking” sounds expensive but powerful.</p>



<p class="wp-block-paragraph">A quick <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/">survey of my LinkedIn crowd</a> suggests others also feel my “WHICH MODEL???” pain. More importantly, I suspect most enterprises do, too.</p>



<h2 class="wp-block-heading"><a></a>A model doesn’t rot</h2>



<p class="wp-block-paragraph">Before getting carried away, however, it’s worth considering whether any of this model churn actually matters. After all, a model doesn’t rot. The model an enterprise put into production in March performs just as well in July as it did when the company selected it. “Obsolete” generally means that something better now exists, not that the deployed model suddenly stopped summarizing insurance claims or classifying support tickets. (In other words, once you have something working, the idea that “but maybe Opus 200.2 is better!” is really a FOMO problem, not a performance issue.)</p>



<p class="wp-block-paragraph">Most enterprise workloads don’t live at the frontier anyway. Extraction, summarization, classification, document comparison, and customer-service assistance often work perfectly well with smaller, cheaper models. OpenAI’s own pitch for the trio of GPT-5.6 models isn’t simply that Sol is better. It’s that ⁠Terra and Luna deliver different combinations of intelligence, latency, and cost. Luna, the cheapest tier, nearly matches the previous generation’s peak performance at less than half the estimated cost, according to OpenAI.</p>



<p class="wp-block-paragraph">The practical question, of course, is where to start. An enterprise can’t test every model, every reasoning setting, and every price tier before doing any work. So here’s my advice (which I don’t follow in my own work, but I’m not defining enterprise strategy and can be a little price-insensitive). Start with the cheapest credible model that appears capable of the task. Give it a representative set of real examples and, before you start testing, define what counts as good enough. If it passes, stop. If it fails, move up a tier or try a model with strengths better suited to the work.</p>



<p class="wp-block-paragraph">That sounds almost offensively simple, but it reverses the way many people, including me, use these products. We start with the biggest model because we’re afraid of what we might lose. Enterprises should start lower and require evidence before paying for more intelligence.</p>



<p class="wp-block-paragraph">There are exceptions, of course. For genuinely difficult work, such as autonomous coding, complex research, or high-stakes reasoning, beginning with a frontier model may save time. But even then, the goal should be to establish a quality ceiling, then test whether a cheaper model can meet it. It’s changing the question from “which model is best?” to “what is the least expensive model that reliably clears the bar for this job?”</p>



<p class="wp-block-paragraph">For many workloads, that price improvement matters more than a few extra benchmark points. <a href="https://www.infoworld.com/article/2335519/ai-hype-isnt-helping-anyone.html">⁠As I argued back in 2023</a>, following AI hype doesn’t help anyone. If your model strategy depends on whichever benchmark screenshot is circulating on X this week, you don’t have a strategy. Not a viable one, anyway. Pick a model and ignore the noise.</p>



<p class="wp-block-paragraph">Except, of course, when that noise suggests a serious signal.</p>



<h2 class="wp-block-heading"><a></a>Sometimes better really is better</h2>



<p class="wp-block-paragraph">Frontier improvements aren’t always incremental, making it advantageous to consider an upgrade. Coding is the obvious example. There’s a significant difference between a model that suggests the next few lines of code and one that can inspect a repository, plan a change, use tools, run tests, discover its own mistakes, and keep working for an extended period. That isn’t merely a nicer autocomplete experience. It can reorganize a development workflow.</p>



<p class="wp-block-paragraph">This is why enterprises can’t simply standardize on an 18-month-old model and declare victory. In some areas, particularly software development and other agentic work, better models can unlock compounding productivity. A model that reliably completes 80% of a bounded task rather than 50% may justify an entirely different division of labor between humans and machines.</p>



<p class="wp-block-paragraph">Still, that upgrade isn’t free.</p>



<p class="wp-block-paragraph">Models differ in how they interpret instructions, call tools, manage context, refuse requests, and fail. Prompts and scaffolding tuned for one model can regress when moved to another. Or costs can explode. As one of my Oracle colleagues discovered just this week, running the same tasks in GPT 5.6 was orders of magnitude more expensive than 5.5. The API change may be trivial, but the revalidation and implications are not.</p>



<p class="wp-block-paragraph">This leaves enterprises caught between two bad options. They can freeze and potentially miss out on meaningful improvements or chase every release and repeatedly test production systems on faith. What to do?</p>



<h2 class="wp-block-heading"><a></a>Stop making model bets</h2>



<p class="wp-block-paragraph">The answer is to stop making LLM bets and start making job-to-be-done bets. Stop asking which model is fastest. Instead, figure out what work you are trying to improve. What does a good result look like? How much latency and cost can the workflow tolerate? How wrong can it be before a human must intervene? Once those questions have answers, model selection becomes less opaque.</p>



<p class="wp-block-paragraph">A difficult code migration may justify GPT-5.6 Sol or Claude Sonnet 5. A repetitive classification task may work just as well with Luna or another smaller model. A regulated workflow may require a model or deployment option that offers particular data controls. Sometimes the correct model is no LLM at all, like when I’m writing this post. Sorry, AI vendors! (At least you won’t get blamed for my mistakes.)</p>



<p class="wp-block-paragraph">This is where evaluations become the center of enterprise AI strategy. <a href="https://www.infoworld.com/article/4166247/improving-ai-agents-through-better-evaluations.html">⁠As I’ve said before</a>, most companies don’t have an AI quality problem so much as an AI measurement problem. Hence, a private evaluation suite built from real company work is the only leaderboard that matters. Does the new model materially improve quality? If so, use it! Does it reduce cost or latency? Again, that’s your free pass to adoption. Does the improvement justify the expense and effort of revalidation? If yes, continue.</p>



<h2 class="wp-block-heading"><a></a>Make model releases boring</h2>



<p class="wp-block-paragraph">As important as the model is, keep in mind that AI success always comes back to <em>your</em> company’s data, <em>your</em> company’s workflows<em>, your</em> company’s integrations, etc. That’s the ⁠<a href="https://www.infoworld.com/article/4157506/mastering-the-dull-reality-of-sexy-ai.html">dull reality behind sexy AI</a>. Retrieval, <a href="https://www.infoworld.com/article/4189492/how-to-improve-the-memory-of-ai-agents.html">memory</a>, governance, data quality, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, and feedback loops aren’t as exciting as a new model launch, but they’re what ultimately make AI truly work.</p>



<p class="wp-block-paragraph">Again, when it’s time to consider something new, the principle should be to default to the least expensive model that reliably passes your evaluations. Only escalate harder tasks to more capable models when measurement shows that the premium pays. Tip: Make this invisible to employees so that the system routes to the best model for a particular prompt. As <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287481372047860715522%2Curn%3Ali%3Aactivity%3A7481369774401409024%29">dbt Labs’ Jon Lewis expresses</a> it, “The best model is ‘Auto’ and I won’t hear anyone say otherwise.” OpenAI’s own ⁠<a href="https://developers.openai.com/api/docs/guides/latest-model">migration guidance</a> recommends testing models on representative tasks, including trying a lower reasoning level rather than automatically cranking everything to the maximum.</p>



<p class="wp-block-paragraph">As for me, I’ll probably keep clicking the shiniest option. I don’t have a formal evaluation suite for InfoWorld columns, and the marginal cost is a subscription I already pay. Enterprises don’t get that excuse.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trusting your kids online isn’t enough (Lock and Code S07E14)]]></title>
<description><![CDATA[This week on the Lock and Code podcast, we speak with Anna Brading about what actually works in keeping her kids safe online. This article has been indexed from Malwarebytes Read the original article: Trusting your kids online isn’t enough…
Read more →
The post Trusting your kids online isn’t eno...]]></description>
<link>https://tsecurity.de/de/3665726/it-security-nachrichten/trusting-your-kids-online-isnt-enough-lock-and-code-s07e14/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665726/it-security-nachrichten/trusting-your-kids-online-isnt-enough-lock-and-code-s07e14/</guid>
<pubDate>Mon, 13 Jul 2026 17:23:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This week on the Lock and Code podcast, we speak with Anna Brading about what actually works in keeping her kids safe online. This article has been indexed from Malwarebytes Read the original article: Trusting your kids online isn’t enough…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/trusting-your-kids-online-isnt-enough-lock-and-code-s07e14/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/trusting-your-kids-online-isnt-enough-lock-and-code-s07e14/">Trusting your kids online isn’t enough (Lock and Code S07E14)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is GitOps? Extending devops to Kubernetes and beyond]]></title>
<description><![CDATA[Over the past decade, software development has been shaped by two closely related transformations. One is the rise of devops and continuous integration and continuous delivery (CI/CD), which brought development and operations teams together around automated, incremental software delivery.



The ...]]></description>
<link>https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past decade, software development has been shaped by two closely related transformations. One is the rise of <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">devops</a> and <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and continuous delivery</a> (CI/CD), which brought development and operations teams together around automated, incremental software delivery.</p>



<p class="wp-block-paragraph">The other is the shift from monolithic applications to distributed, cloud-native systems built from microservices and containers, typically managed by orchestration platforms such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>.</p>



<p class="wp-block-paragraph">While Kubernetes and similar platforms simplify many aspects of running distributed applications, operating these systems at scale is still complicated. Configuration sprawl, environment drift, and the need for rapid, reliable change all introduce operational challenges. GitOps emerged as a way to address those challenges by extending familiar devops and CI/CD techniques beyond application code and into infrastructure and system configuration.</p>



<p class="wp-block-paragraph">At the heart of GitOps is the concept of <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC). In a GitOps model, not only application code but also infrastructure definitions, deployment configurations, and operational settings are described in files stored in a version control system. Automated processes continuously compare the running system with those declarations and work to bring the live environment back into alignment when differences appear.</p>



<p class="wp-block-paragraph">In this approach, the version control repository serves as the system of record for how applications and their supporting infrastructure should look in production. Changes flow through the same review, approval, and automation pipelines that developers already use for software, bringing greater consistency, traceability, and repeatability to cloud-native operations.</p>



<p class="wp-block-paragraph">At a high level, GitOps refers to a set of operational practices for managing cloud-native systems using declarative configuration, version control, and automated reconciliation. Rather than treating infrastructure and application configuration as mutable runtime state, GitOps treats them as versioned artifacts that move through the same review, testing, and deployment processes as application code.</p>



<h2 class="wp-block-heading"><strong>GitOps defined</strong></h2>



<p class="wp-block-paragraph">The term GitOps was originally coined and popularized by Weaveworks, which helped formalize the approach in the context of Kubernetes operations. While that early work shaped the way GitOps was discussed and implemented, GitOps has since evolved into a broadly adopted, vendor-neutral pattern. Today, it describes a shared set of ideas rather than a specific product or platform.</p>



<p class="wp-block-paragraph">The defining characteristic of GitOps is its reliance on declarative configuration stored in a version control system. Instead of issuing imperative commands to change live systems, teams describe the desired state of applications and infrastructure in configuration files. Automated agents then continuously compare that declared state with what is actually running and work to reconcile any differences. This pull-based model—where systems converge toward the desired state defined in version control—provides built-in drift detection, repeatability, and a clear audit trail for every change.</p>



<p class="wp-block-paragraph">Because GitOps centers on configuration files stored in a version control system, familiar software development practices carry over naturally. Changes are proposed through commits, reviewed before being accepted, and tracked over time. Rollbacks are accomplished by reverting to known-good versions, and the history of how a system evolved is preserved alongside the configuration itself.</p>



<p class="wp-block-paragraph">While the use of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> as the version control system is not strictly required, it has become the default choice because of its ubiquity in modern devops workflows and its strong support for collaboration and change management, so its place in the name has stuck.</p>



<aside class="sidebar">
<h3><strong> GitOps vs. IaC </strong></h3>
<p>Infrastructure as code (IaC) and GitOps are closely related, but they solve different problems. </p>
<p>IaC focuses on how infrastructure is defined. Servers, networks, and services are described using declarative configuration files, which are then applied by automation tools. GitOps builds on IaC by adding an operating model around those definitions. In a GitOps workflow, the desired state of systems is stored in a version control repository and treated as the system of record. Automated agents continuously compare the running environment with that desired state and reconcile any differences.</p>
<p>The key distinction is persistence. IaC provisions infrastructure; GitOps keeps systems in the intended state over time. By using pull-based reconciliation and continuous drift detection, GitOps extends IaC into a day-to-day operational discipline.
</p>

</aside>



<h2 class="wp-block-heading"><strong>What is the CI/CD process?</strong></h2>



<p class="wp-block-paragraph">A complete look at CI/CD is beyond the scope of this article—<a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">see the InfoWorld explainer on the subject</a>—but we need to say a few words about CI/CD because it’s at the core of how GitOps works. The <em>continuous integration</em> half of CI/CD is enabled by version control repositories like Git: Developers can make constant small improvements to their codebase, rather than rolling out huge, monolithic new versions every few months or years. The <em>continuous deployment</em> piece is made possible by automated systems called <em>pipelines</em> that build, test, and deploy the new code to production.</p>



<p class="wp-block-paragraph">Again, we keep talking about <em>code </em>here, and that usually summons up visions of executable code written in a programming language such as C or Java or JavaScript. But in GitOps, the “code” we’re managing is largely made up of configuration files. This isn’t just a minor detail — it’s at the heart of what GitOps does. These config files are, as we’ve said, the “single source of truth” describing what our system should look like. They are <em>declarative </em>rather than instructive. That means that instead of saying “start up ten servers,” the configuration file will simply say, “this system includes ten servers.”</p>



<p class="wp-block-paragraph"><strong>GitOps and Kubernetes</strong></p>



<p class="wp-block-paragraph">GitOps first took hold in the Kubernetes ecosystem, where declarative configuration and continuous reconciliation are core design principles. As a result, Kubernetes remains the most common and best-understood environment for applying GitOps practices. A typical GitOps-driven update process for a Kubernetes application looks like this:</p>



<ol start="1" class="wp-block-list">
<li>A developer proposes a change by committing updated application code or configuration to a version control repository, usually through a pull request.</li>



<li>That change is reviewed and approved, then merged into the main branch.</li>



<li>The merge triggers an automated CI/CD pipeline that tests the change, builds new artifacts if needed, and publishes them to a registry.</li>



<li>A GitOps controller or similar automated agent detects the updated desired state stored in version control.</li>



<li>The controller compares that desired state with the current state of the Kubernetes cluster and applies the necessary changes to bring the cluster back into alignment.</li>
</ol>



<p class="wp-block-paragraph">This pull-based reconciliation loop—where the cluster continuously converges toward the desired state defined in version control—is central to how GitOps works in practice. While Kubernetes provides a natural fit for this model, it represents just one canonical use case. The same patterns increasingly apply to infrastructure provisioning, policy enforcement, and multi-cluster operations beyond Kubernetes itself.</p>



<h2 class="wp-block-heading"><strong>GitOps tooling in practice: Argo CD, Flux, and the ecosystem</strong></h2>



<p class="wp-block-paragraph">GitOps is enabled by a set of tools that embody the principles we’ve outlined, with some open-source projects emerging as de facto standards in cloud-native environments.</p>



<p class="wp-block-paragraph">At the center of the GitOps ecosystem is Argo CD, an open-source controller that continuously monitors a version control repository and ensures that the state of running systems matches the declared desired state. Argo CD is widely used in Kubernetes environments because it directly implements pull-based reconciliation: it compares the desired state stored in Git with the cluster’s actual state and applies changes to correct any drift.</p>



<p class="wp-block-paragraph">Alongside Argo CD, Flux is another prominent open source GitOps engine. Both Flux and Argo CD help teams adopt GitOps workflows by managing the synchronization loop between code and runtime, but they differ in operational philosophy, integration surfaces, and ecosystem fit.</p>



<p class="wp-block-paragraph">GitOps tooling often appears as part of broader platforms or integrated stacks rather than as isolated utilities. For example, <a href="https://www.infoworld.com/article/4006297/top-6-multicloud-management-systems.html">multicloud and cluster management solutions</a> now routinely include GitOps support, with Argo CD or compatible controllers bundled alongside deployment, policy, and governance capabilities.</p>



<p class="wp-block-paragraph">In addition to Flux and Argo CD, a range of auxiliary tools contribute to a complete GitOps ecosystem: policy as code engines (e.g., Open Policy Agent), drift detection systems, and infrastructure provisioning tools that mesh with Git-centric workflows.</p>



<h2 class="wp-block-heading"><strong>GitOps, devops, and normalization</strong></h2>



<p class="wp-block-paragraph">GitOps grew out of the same forces that drove devops into mainstream IT practice, and in its early days, GitOps was often discussed as a distinct extension of devops, specifically tailored to managing declarative infrastructure and Kubernetes-centric systems. At the time, GitOps was still relatively new and <a href="http://infoworld.com/article/2265546/why-gitops-isnt-ready-for-the-mainstream-yet.html">not yet widely adopted outside cloud-native pioneers</a>.</p>



<p class="wp-block-paragraph">Over the last several years, however, GitOps practices have become deeply woven into how teams operate modern cloud environments. Rather than being treated as an optional add-on or marketing term, the core ideas of GitOps — using version-controlled, declarative configuration and automated reconciliation loops to continuously align running systems with intended state — are now part of standard operational practice in many Kubernetes-centric shops. In this sense, GitOps has shifted from a buzzword about what might be possible to a baseline pattern for cloud-native operations, much like devops itself did years earlier.</p>



<p class="wp-block-paragraph">In environments where Kubernetes and declarative systems are the norm, GitOps workflows are the default way teams manage and deploy change. Many organizations now implement these patterns without explicitly calling them “GitOps,” just as few teams today explicitly say they do “CI/CD” even though continuous pipelines are taken for granted. The term has become less prominent in marketing, but its practices are often embedded in pipelines, controllers, and platform tooling.</p>



<p class="wp-block-paragraph">That normalization shows up in how GitOps workflows are woven into broader operational frameworks. For example, <a href="https://www.infoworld.com/article/2338225/what-is-platform-engineering-evolving-devops.html">platform engineering</a> teams frequently build internal developer platforms that encapsulate GitOps patterns behind standardized developer APIs, making the pattern invisible to most application teams while still providing the auditability and automation that GitOps promises.</p>



<h2 class="wp-block-heading"><strong>GitOps beyond Kubernetes: infrastructure, policy, and drift</strong></h2>



<p class="wp-block-paragraph">While GitOps first gained traction as a way to manage Kubernetes deployments, its core principles apply broadly to infrastructure and operational concerns beyond any single orchestration platform. GitOps treats desired state as declarative configuration stored in version control and uses automated reconciliation to ensure running systems align with that state. That pattern naturally extends to infrastructure provisioning, policy enforcement, configuration drift detection, and governance workflows across diverse environments.</p>



<p class="wp-block-paragraph">In modern operational stacks, infrastructure is increasingly defined declaratively, whether through Kubernetes manifests, Terraform modules, or other infrastructure-as-code formats. Storing these declarations in version control enables the same peer-review, auditability, and rollback practices developers already use for application code. Automated tooling then continuously detects when the live infrastructure diverges from the declared state and works to bring it back into alignment, reducing the risk of configuration drift and inadvertent misconfigurations.</p>



<p class="wp-block-paragraph">Configuration drift — the state where an environment has diverged from what’s declared in version control — remains a major operational headache, especially in complex, dynamic systems. Drift can arise from ad hoc fixes, emergency updates, or manual changes made outside normal pipelines, and it can lead to inconsistencies, outages, and security gaps. By continually checking running systems against the desired state in Git and reconciling deviations automatically, GitOps workflows help teams keep environments predictable and auditable.</p>



<p class="wp-block-paragraph">Policy enforcement and compliance are another natural extension of GitOps patterns. As organizations adopt declarative practices, policy-as-code engines and drift detection systems can be woven into GitOps pipelines to validate that proposed configurations meet security, compliance, or operational standards before they’re ever applied to running systems. Embedding policy checks into declarative workflows brings consistency to governance while preserving the automation and speed that devops teams expect.</p>



<h2 class="wp-block-heading"><strong>GitOps – beyond Kubernetes</strong></h2>



<p class="wp-block-paragraph">GitOps began as a way to bring devops discipline to Kubernetes operations, but its longer-term impact has been more subtle. In many ways, it’s been absorbed into the fabric of modern cloud-native operations, where declarative configuration, version control, and automated reconciliation are taken for granted. Today, GitOps is less about a specific set of tools or a named practice and more about an operational mindset. By treating infrastructure and configuration as versioned, auditable artifacts and relying on automation to enforce consistency, GitOps helps teams manage complexity at scale. Even as the term itself fades from the spotlight, the practices it introduced continue to shape how distributed systems are built, deployed, and operated.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's corporate espionage suit against OpenAI isn't the first]]></title>
<description><![CDATA[Since its founding, Sam Altman's OpenAI has been at the center of multiple controversies, with Apple's intellectual property theft suit being just the latest chapter. Here's the story so far about what's been alleged over the last decade.Sam Altman of OpenAIThe artificial intelligence development...]]></description>
<link>https://tsecurity.de/de/3665549/ios-mac-os/apples-corporate-espionage-suit-against-openai-isnt-the-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665549/ios-mac-os/apples-corporate-espionage-suit-against-openai-isnt-the-first/</guid>
<pubDate>Mon, 13 Jul 2026 16:24:17 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Since its founding, Sam Altman's OpenAI has been at the center of multiple controversies, with Apple's intellectual property theft suit being just the latest chapter. Here's the story so far about what's been alleged over the last decade.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68224-143841-openaialtman-xl.jpg" alt="Black-and-white portrait of a man with short hair and slight smile, shown from shoulders up, with a large white OpenAI knot logo behind him on a gray background" height="738"><br><span>Sam Altman of OpenAI</span></div><br>The artificial intelligence development wave has greatly affected the tech industry. As usual, this also includes accusations, threats, and lawsuits.<br><br>OpenAI is no different, as it has attracted many different lawsuits in its short existence. As you might expect, Apple is central to some, and peripheral to others.<br><br><br> <a href="https://appleinsider.com/articles/26/07/13/apples-corporate-espionage-suit-against-openai-isnt-the-first?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244941?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which AI model should you bet your company on?]]></title>
<description><![CDATA[Every day this past week I did something I suspect millions of other people also did: I stared at an LLM model picker and wondered which one I was supposed to want.



OpenAI just released ⁠GPT-5.6 Sol, Terra, and Luna. Sol is the flagship. Terra offers much of its intelligence for less money. Lu...]]></description>
<link>https://tsecurity.de/de/3664783/ai-nachrichten/which-ai-model-should-you-bet-your-company-on/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664783/ai-nachrichten/which-ai-model-should-you-bet-your-company-on/</guid>
<pubDate>Mon, 13 Jul 2026 11:33:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Every day this past week I did something I suspect millions of other people also did: I stared at an <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM </a>model picker and wondered which one I was supposed to want.</p>



<p>OpenAI just released ⁠<a href="https://openai.com/index/gpt-5-6/">GPT-5.6 Sol, Terra, and Luna</a>. Sol is the flagship. Terra offers much of its intelligence for less money. Luna is cheaper still. Anthropic released ⁠<a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a> at the end of June and Opus 4.8 the month prior, with a little Fable 5 emerging in between. Meanwhile, Google, which seemed to be winning the model wars a few months ago, is now getting shade from Gergely Orosz, who ⁠<a href="https://x.com/GergelyOrosz/status/2075160978493210685?s=20">argues that Gemini has slipped outside the top tier</a> for software development and has been out of the major model release game for <em>eons</em> (May 19).</p>



<p>Perhaps Orosz is right. Perhaps he’ll be wrong again in six weeks. Honestly, it’s exhausting.</p>



<p>I use ChatGPT and Claude constantly and still have no principled idea which model to choose most of the time. I tend to click whatever looks like the biggest, most expensive option because I don’t know what I’m giving up by choosing something smaller. “Instant” sounds dangerously unserious. “Thinking” sounds expensive but powerful.</p>



<p>A quick <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/">survey of my LinkedIn crowd</a> suggests others also feel my “WHICH MODEL???” pain. More importantly, I suspect most enterprises do, too.</p>



<h2 class="wp-block-heading"><a></a>A model doesn’t rot</h2>



<p>Before getting carried away, however, it’s worth considering whether any of this model churn actually matters. After all, a model doesn’t rot. The model an enterprise put into production in March performs just as well in July as it did when the company selected it. “Obsolete” generally means that something better now exists, not that the deployed model suddenly stopped summarizing insurance claims or classifying support tickets. (In other words, once you have something working, the idea that “but maybe Opus 200.2 is better!” is really a FOMO problem, not a performance issue.)</p>



<p>Most enterprise workloads don’t live at the frontier anyway. Extraction, summarization, classification, document comparison, and customer-service assistance often work perfectly well with smaller, cheaper models. OpenAI’s own pitch for the trio of GPT-5.6 models isn’t simply that Sol is better. It’s that ⁠Terra and Luna deliver different combinations of intelligence, latency, and cost. Luna, the cheapest tier, nearly matches the previous generation’s peak performance at less than half the estimated cost, according to OpenAI.</p>



<p>The practical question, of course, is where to start. An enterprise can’t test every model, every reasoning setting, and every price tier before doing any work. So here’s my advice (which I don’t follow in my own work, but I’m not defining enterprise strategy and can be a little price-insensitive). Start with the cheapest credible model that appears capable of the task. Give it a representative set of real examples and, before you start testing, define what counts as good enough. If it passes, stop. If it fails, move up a tier or try a model with strengths better suited to the work.</p>



<p>That sounds almost offensively simple, but it reverses the way many people, including me, use these products. We start with the biggest model because we’re afraid of what we might lose. Enterprises should start lower and require evidence before paying for more intelligence.</p>



<p>There are exceptions, of course. For genuinely difficult work, such as autonomous coding, complex research, or high-stakes reasoning, beginning with a frontier model may save time. But even then, the goal should be to establish a quality ceiling, then test whether a cheaper model can meet it. It’s changing the question from “which model is best?” to “what is the least expensive model that reliably clears the bar for this job?”</p>



<p>For many workloads, that price improvement matters more than a few extra benchmark points. <a href="https://www.infoworld.com/article/2335519/ai-hype-isnt-helping-anyone.html">⁠As I argued back in 2023</a>, following AI hype doesn’t help anyone. If your model strategy depends on whichever benchmark screenshot is circulating on X this week, you don’t have a strategy. Not a viable one, anyway. Pick a model and ignore the noise.</p>



<p>Except, of course, when that noise suggests a serious signal.</p>



<h2 class="wp-block-heading"><a></a>Sometimes better really is better</h2>



<p>Frontier improvements aren’t always incremental, making it advantageous to consider an upgrade. Coding is the obvious example. There’s a significant difference between a model that suggests the next few lines of code and one that can inspect a repository, plan a change, use tools, run tests, discover its own mistakes, and keep working for an extended period. That isn’t merely a nicer autocomplete experience. It can reorganize a development workflow.</p>



<p>This is why enterprises can’t simply standardize on an 18-month-old model and declare victory. In some areas, particularly software development and other agentic work, better models can unlock compounding productivity. A model that reliably completes 80% of a bounded task rather than 50% may justify an entirely different division of labor between humans and machines.</p>



<p>Still, that upgrade isn’t free.</p>



<p>Models differ in how they interpret instructions, call tools, manage context, refuse requests, and fail. Prompts and scaffolding tuned for one model can regress when moved to another. Or costs can explode. As one of my Oracle colleagues discovered just this week, running the same tasks in GPT 5.6 was orders of magnitude more expensive than 5.5. The API change may be trivial, but the revalidation and implications are not.</p>



<p>This leaves enterprises caught between two bad options. They can freeze and potentially miss out on meaningful improvements or chase every release and repeatedly test production systems on faith. What to do?</p>



<h2 class="wp-block-heading"><a></a>Stop making model bets</h2>



<p>The answer is to stop making LLM bets and start making job-to-be-done bets. Stop asking which model is fastest. Instead, figure out what work you are trying to improve. What does a good result look like? How much latency and cost can the workflow tolerate? How wrong can it be before a human must intervene? Once those questions have answers, model selection becomes less opaque.</p>



<p>A difficult code migration may justify GPT-5.6 Sol or Claude Sonnet 5. A repetitive classification task may work just as well with Luna or another smaller model. A regulated workflow may require a model or deployment option that offers particular data controls. Sometimes the correct model is no LLM at all, like when I’m writing this post. Sorry, AI vendors! (At least you won’t get blamed for my mistakes.)</p>



<p>This is where evaluations become the center of enterprise AI strategy. <a href="https://www.infoworld.com/article/4166247/improving-ai-agents-through-better-evaluations.html">⁠As I’ve said before</a>, most companies don’t have an AI quality problem so much as an AI measurement problem. Hence, a private evaluation suite built from real company work is the only leaderboard that matters. Does the new model materially improve quality? If so, use it! Does it reduce cost or latency? Again, that’s your free pass to adoption. Does the improvement justify the expense and effort of revalidation? If yes, continue.</p>



<h2 class="wp-block-heading"><a></a>Make model releases boring</h2>



<p>As important as the model is, keep in mind that AI success always comes back to <em>your</em> company’s data, <em>your</em> company’s workflows<em>, your</em> company’s integrations, etc. That’s the ⁠<a href="https://www.infoworld.com/article/4157506/mastering-the-dull-reality-of-sexy-ai.html">dull reality behind sexy AI</a>. Retrieval, <a href="https://www.infoworld.com/article/4189492/how-to-improve-the-memory-of-ai-agents.html">memory</a>, governance, data quality, <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a>, and feedback loops aren’t as exciting as a new model launch, but they’re what ultimately make AI truly work.</p>



<p>Again, when it’s time to consider something new, the principle should be to default to the least expensive model that reliably passes your evaluations. Only escalate harder tasks to more capable models when measurement shows that the premium pays. Tip: Make this invisible to employees so that the system routes to the best model for a particular prompt. As <a href="https://www.linkedin.com/feed/update/urn:li:activity:7481369774401409024/?dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287481372047860715522%2Curn%3Ali%3Aactivity%3A7481369774401409024%29">dbt Labs’ Jon Lewis expresses</a> it, “The best model is ‘Auto’ and I won’t hear anyone say otherwise.” OpenAI’s own ⁠<a href="https://developers.openai.com/api/docs/guides/latest-model">migration guidance</a> recommends testing models on representative tasks, including trying a lower reasoning level rather than automatically cranking everything to the maximum.</p>



<p>As for me, I’ll probably keep clicking the shiniest option. I don’t have a formal evaluation suite for InfoWorld columns, and the marginal cost is a subscription I already pay. Enterprises don’t get that excuse.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Power of Apple's M7 & M8 chips was born from Apple Car research]]></title>
<description><![CDATA[We've been telling you this for years — Apple Car research wasn't lit on fire, and the fruits of Apple's labor on it will be seen in artificial intelligence performance in the M7 and M8 processor.16-inch MacBook Pro will be the first to get M7 Pro processorsBefore AI used to be called Apple's big...]]></description>
<link>https://tsecurity.de/de/3663483/ios-mac-os/power-of-apples-m7-m8-chips-was-born-from-apple-car-research/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663483/ios-mac-os/power-of-apples-m7-m8-chips-was-born-from-apple-car-research/</guid>
<pubDate>Sun, 12 Jul 2026 17:09:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We've been telling you this for years — Apple Car research wasn't lit on fire, and the fruits of Apple's labor on it will be seen in artificial intelligence performance in the M7 and M8 processor.<br><br><div><img src="https://photos5.appleinsider.com/gallery/61811-127942-Glossy-VS-Matte-Displaky-xl.jpg" alt="Two laptops on a wooden table display video editing software, with lighting creating a warm, cozy atmosphere." height="738"><br><span>16-inch MacBook Pro will be the first to get M7 Pro processors</span></div><br>Before AI used to be called Apple's <a href="https://appleinsider.com/articles/23/12/21/apple-isnt-behind-on-ai-its-looking-ahead-to-the-future-of-smartphones">biggest failure</a>, that title went to the <a href="https://appleinsider.com/inside/apple-car" title="Apple Car" data-kpt="1">Apple Car</a> which was cancelled after ten years of development and <a href="https://appleinsider.com/articles/24/02/29/abandoned-10-billion-apple-car-project-referred-to-as-titanic-disaster-by-employees">ten billion dollars</a> of investment. <em>AppleInsider</em> argued at the time that Apple Car research would pay off, but now both of these failures are being recast as positives, with <em>Bloomberg</em> saying this research is <a href="https://www.bloomberg.com/account/newsletters/power-on">being used</a> in designing future AI processors.<br><br>The report claims that for the future M7 and M8 processors, Apple is concentrating more on AI support than on issues such as overall speed and power efficiency. This reportedly means that these chip designs for the <a href="https://appleinsider.com/inside/mac" title="Mac" data-kpt="1">Mac</a> and Apple Intelligence servers are based on the company's efforts toward a self-driving car.<br><br><br> <a href="https://appleinsider.com/articles/26/07/12/power-of-apples-m7-m8-chips-was-born-from-apple-car-research?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244932?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Long Context Isn’t Free — I Built a Safe Prompt-Pruning Layer That Makes LLM Systems Work]]></title>
<description><![CDATA[LLMs don’t fail because they forget—they fail because they remember too much. As conversations grow, prompts accumulate redundant and low-value tokens, driving up cost and latency while silently degrading output quality. This article introduces a deterministic prompt-pruning layer that reduces to...]]></description>
<link>https://tsecurity.de/de/3662083/ai-nachrichten/long-context-isnt-free-i-built-a-safe-prompt-pruning-layer-that-makes-llm-systems-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662083/ai-nachrichten/long-context-isnt-free-i-built-a-safe-prompt-pruning-layer-that-makes-llm-systems-work/</guid>
<pubDate>Sat, 11 Jul 2026 17:33:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>LLMs don’t fail because they forget—they fail because they remember too much. As conversations grow, prompts accumulate redundant and low-value tokens, driving up cost and latency while silently degrading output quality. This article introduces a deterministic prompt-pruning layer that reduces token usage without breaking dependencies, backed by real benchmarks and production-tested design.</p>
<p>The post <a href="https://towardsdatascience.com/long-context-isnt-free-i-built-a-safe-prompt-pruning-layer-that-makes-llm-systems-work/">Long Context Isn’t Free — I Built a Safe Prompt-Pruning Layer That Makes LLM Systems Work</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website]]></title>
<description><![CDATA[The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it. This article has been indexed from Securelist Read the original article: When checking the URL…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3648318/it-security-nachrichten/when-checking-the-url-isnt-enough-a-device-code-phishing-attack-via-a-microsoft-website/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648318/it-security-nachrichten/when-checking-the-url-isnt-enough-a-device-code-phishing-attack-via-a-microsoft-website/</guid>
<pubDate>Mon, 06 Jul 2026 11:36:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it. This article has been indexed from Securelist Read the original article: When checking the URL…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/when-checking-the-url-isnt-enough-a-device-code-phishing-attack-via-a-microsoft-website/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/when-checking-the-url-isnt-enough-a-device-code-phishing-attack-via-a-microsoft-website/">When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Your GRC Career Isn’t Moving Forward]]></title>
<description><![CDATA[It’s not your certifications. It’s that you’re still explaining knowledge instead of proving judgment.Continue reading on InfoSec Write-ups »]]></description>
<link>https://tsecurity.de/de/3646309/hacking/why-your-grc-career-isnt-moving-forward/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646309/hacking/why-your-grc-career-isnt-moving-forward/</guid>
<pubDate>Sun, 05 Jul 2026 08:22:35 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://infosecwriteups.com/why-your-grc-career-isnt-moving-forward-87735b884d4a"><img src="https://cdn-images-1.medium.com/max/1280/1*Ey8-8AsBKrVd1JzuGOb0kQ.jpeg" width="1280"></a></p><p class="medium-feed-snippet">It’s not your certifications. It’s that you’re still explaining knowledge instead of proving judgment.</p><p class="medium-feed-link"><a href="https://infosecwriteups.com/why-your-grc-career-isnt-moving-forward-87735b884d4a">Continue reading on InfoSec Write-ups »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t]]></title>
<description><![CDATA[Police arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most…
Read more →
The post XSS.is, The Forum That Ran ...]]></description>
<link>https://tsecurity.de/de/3637086/it-security-nachrichten/xssis-the-forum-that-ran-the-ransomware-supply-chain-is-down-the-market-isnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637086/it-security-nachrichten/xssis-the-forum-that-ran-the-ransomware-supply-chain-is-down-the-market-isnt/</guid>
<pubDate>Wed, 01 Jul 2026 01:38:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Police arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/xss-is-the-forum-that-ran-the-ransomware-supply-chain-is-down-the-market-isnt/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/xss-is-the-forum-that-ran-the-ransomware-supply-chain-is-down-the-market-isnt/">XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The New Insider Threat Isn’t Human: Securing AI Agents Before They Secure Themselves]]></title>
<description><![CDATA[In mid-September 2025, engineers inside Anthropic’s threat intelligence team noticed something that didn’t fit the usual pattern of automated probing on their platform. Ten days of digging later, they had a name for it: GTG-1002, a Chinese state-sponsored group that…
Read more →
The post The New ...]]></description>
<link>https://tsecurity.de/de/3628491/it-security-nachrichten/the-new-insider-threat-isnt-human-securing-ai-agents-before-they-secure-themselves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628491/it-security-nachrichten/the-new-insider-threat-isnt-human-securing-ai-agents-before-they-secure-themselves/</guid>
<pubDate>Fri, 26 Jun 2026 22:09:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In mid-September 2025, engineers inside Anthropic’s threat intelligence team noticed something that didn’t fit the usual pattern of automated probing on their platform. Ten days of digging later, they had a name for it: GTG-1002, a Chinese state-sponsored group that…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-new-insider-threat-isnt-human-securing-ai-agents-before-they-secure-themselves/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-new-insider-threat-isnt-human-securing-ai-agents-before-they-secure-themselves/">The New Insider Threat Isn’t Human: Securing AI Agents Before They Secure Themselves</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Presidential order addresses quantum computing gaps]]></title>
<description><![CDATA[The quantum computing industry has a supply-chain problem: The companies that could make the specialized lasers, cryogenics, and photonics it depends on don’t have enough of a market yet to invest in creating these products.



An executive order signed Monday aims to fix that, directing the gove...]]></description>
<link>https://tsecurity.de/de/3627624/it-security-nachrichten/presidential-order-addresses-quantum-computing-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627624/it-security-nachrichten/presidential-order-addresses-quantum-computing-gaps/</guid>
<pubDate>Fri, 26 Jun 2026 15:54:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The quantum computing industry has a supply-chain problem: The companies that could make the specialized lasers, cryogenics, and photonics it depends on don’t have enough of a market yet to invest in creating these products.</p>



<p>An <a href="https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation">executive order</a> signed Monday aims to fix that, directing the government to strengthen domestic component manufacturing and partner with the private sector to fill the gaps. In addition, the order tells the Department of Energy to lead the development of a <a href="https://www.networkworld.com/article/4158139/fixing-encryption-isnt-enough-quantum-developments-put-focus-on-authentication.html">useful quantum computer</a>, assess the performance of quantum computers, and track how close quantum computers are to being able to <a href="https://www.networkworld.com/article/4117438/quantum-computing-is-getting-closer-but-quantum-proof-encryption-remains-elusive.html">break encryption</a>. The order also calls for tighter export controls of key quantum technologies and launches a hiring push for quantum talent.</p>



<p><a href="https://www.linkedin.com/in/celia-merzbacher-b345a411/">Celia Merzbacher</a>, executive director at Quantum Economic Development Consortium, says the order is “extremely encouraging.”</p>



<p>“It is a sign from the highest level of government that quantum is important,” she tells <em>Network World</em>.</p>



<p>On Tuesday, the Energy Department followed up with its announcement of <a href="https://www.energy.gov/science/articles/energy-department-announces-initiative-create-and-deploy-worlds-first">Quantum Genesis</a>, an initiative to create and deploy what it called the world’s first scientifically relevant, fault-tolerant quantum computer. Quantum computing is a key component of the Genesis Mission, <a href="https://www.whitehouse.gov/presidential-actions/2025/11/launching-the-genesis-mission/">announced</a> at the end of 2025.</p>



<p>Monday’s executive order didn’t include any funding for the new quantum computing strategy but says that it is “subject to the availability of appropriations” and directs the Energy Department to “explore potential private-sector partnership models.”</p>



<p>The next step, according to Merzbacher, is to get the funding in place. “So there’s a role for Congress to write the checks and follow up and do the work that needs to be done,” she says.</p>



<p>The supply chain piece is particularly important. “Quantum is still at a fairly early stage, and the markets aren’t big,” she says. “There isn’t a market engine or flywheel yet.”</p>



<p>Specifically, quantum computing needs electronics, cryogenic technologies, lasers, photonics, and optics, she says. “And there are a lot of players in those areas.”</p>



<p>Some of them are getting into the quantum sector as a business — but some are not, because they see the market as too small, she says. “So, how do you get that flywheel going? One of the things the government can do is send some signals that as the technology comes along, there will be a market, whether that’s the government paying for acquiring some systems and putting them out there for researchers to use, or some other way of sending a demand signal to get the business case to the companies that can actually develop and make the technology.”</p>



<p>The executive order also addresses the issue of assessing the performance of quantum computers. Benchmarks have been lacking in the quantum space.</p>



<p>“It’s not easy to compare quantum computers in an apples-to-apples way because the quantum computer systems aren’t that stable yet,” Merzbacher says. “If you run it in the morning and in the afternoon, you get a different performance.”</p>



<p>By comparison, in AI, there are a number of benchmarks comparing AI models on everything from how well they do at math, to their ability to generate images, to whether they can find bugs in computer code.</p>



<p>Benchmarks are important so that people can do fair comparisons of quantum systems, says <a href="https://www.linkedin.com/in/juliette-peyronnet05/">Juliette Peyronnet</a>, US general manager at Alice &amp; Bob, a quantum computing company.</p>



<p>“We know Sandia, the national lab, is working on one, and we hope it will be out soon, but it’s not there yet,” she tells <em>Network World</em>. “We want an organization like Sandia to come out with a benchmark that’s not from a vendor.”</p>



<h3 class="wp-block-heading">Read more about quantum computing and HPC</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4185154/ibm-sends-signals-with-its-10-billion-quantum-pledge.html">IBM sends signals with its $10 billion quantum pledge</a>: “The quantum era is no longer ahead of us, it has started,” said IBM CEO Arvind Krishna in statement tied to news that the company is committing $10 billion to advancing quantum computing and commercializing the technology.</li>



<li><a href="https://www.networkworld.com/article/4153752/new-tool-on-aws-makes-it-easier-to-develop-quantum-error-correction.html">New tool on AWS makes it easier to develop quantum error correction</a>: Quantum computers are no longer a physics challenge but an engineering one, and quantum error correction is the heart of what’s going to make quantum computing a reality. A new tool uses AI-powered digital twins to make it easier for researchers to solve this challenge, and it’s available on AWS.</li>



<li><a href="https://www.networkworld.com/article/4117438/quantum-computing-is-getting-closer-but-quantum-proof-encryption-remains-elusive.html">Quantum computing is getting closer, but quantum-proof encryption remains elusive</a>: The day when quantum computers will be able to break conventional encryption is rapidly approaching, but not all companies are prepared to implement post-quantum cryptography.</li>



<li><a href="https://www.networkworld.com/article/4188115/chinas-lineshine-dethrones-el-capitan-as-the-worlds-fastest-supercomputer.html">China’s LineShine is the world’s fastest supercomputer</a>: The debut of China’s LineShine on the June 2026 edition of the TOP500 rankings ends El Capitan’s run at the top the list and marks the first time a China-based system has led the rankings since Sunway TaihuLight in 2017.</li>



<li>Curious about quantum? <a href="https://www.networkworld.com/article/4157986/curious-about-quantum-check-out-training-options-from-isc2-ibm-aws-and-more.html">Check out training options from ISC2, IBM, AWS and more</a>: ISC2 released a 30-minute primer on the cybersecurity implications of quantum computing. If you want to dig deeper, there are many quantum training options that don’t require going back to school for a PhD.</li>



<li><a href="https://www.networkworld.com/article/4088709/top-quantum-breakthroughs-of-2025.html">Top quantum breakthroughs of 2025</a>: 10 areas in which we’ve seen significant breakthroughs and milestones in quantum computing.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vector RAG Isn’t Enough — I Built a Context Graph Layer for Multi-Agent Memory]]></title>
<description><![CDATA[I benchmarked raw chat history, vector-only RAG, and a context graph on the same multi-agent conversations. The results exposed a surprising weakness in relational retrieval.
The post Vector RAG Isn’t Enough — I Built a Context Graph Layer for Multi-Agent Memory appeared first on Towards Data Sci...]]></description>
<link>https://tsecurity.de/de/3625656/ai-nachrichten/vector-rag-isnt-enough-i-built-a-context-graph-layer-for-multi-agent-memory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625656/ai-nachrichten/vector-rag-isnt-enough-i-built-a-context-graph-layer-for-multi-agent-memory/</guid>
<pubDate>Thu, 25 Jun 2026 20:48:28 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I benchmarked raw chat history, vector-only RAG, and a context graph on the same multi-agent conversations. The results exposed a surprising weakness in relational retrieval.</p>
<p>The post <a href="https://towardsdatascience.com/vector-rag-isnt-enough-i-built-a-context-graph-layer-for-multi-agent-memory/">Vector RAG Isn’t Enough — I Built a Context Graph Layer for Multi-Agent Memory</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI efficiency beyond the model: Rethinking code, hardware and cloud]]></title>
<description><![CDATA[As AI adoption grows, I see fellow enterprise leaders realizing that just implementing AI is not enough. We need to develop and adopt the best, fastest and most efficient AI models. It’s not just a matter of pride about who has the shiniest toy; optimizing models for efficiency can be the differe...]]></description>
<link>https://tsecurity.de/de/3624204/it-security-nachrichten/ai-efficiency-beyond-the-model-rethinking-code-hardware-and-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624204/it-security-nachrichten/ai-efficiency-beyond-the-model-rethinking-code-hardware-and-cloud/</guid>
<pubDate>Thu, 25 Jun 2026 13:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As AI adoption grows, I see fellow enterprise leaders realizing that just implementing AI is not enough. We need to develop and adopt the best, fastest and most efficient AI models. It’s not just a matter of pride about who has the shiniest toy; <a href="https://www.cio.com/article/4109911/cognitive-data-architecture-designing-self-optimizing-frameworks-for-scalable-ai-systems.html">optimizing models</a> for efficiency can be the difference between a failed pilot and an effective business strategy.</p>



<p>At the most extreme end of the spectrum, inefficient use of AI can cost billions of dollars. Sam Altman, CEO of OpenAI, made headlines when he <a href="https://x.com/sama/status/1912646035979239430" rel="nofollow">admitted on X</a> that his company loses tens of millions of dollars every time people say “please” and “thank you” to his AI models, even though he added that he feels it’s money well spent.</p>



<p>Model efficiency also matters for those of us not operating at OpenAI’s scale. A more efficient model helps reduce overall costs because it doesn’t require as powerful or expensive hardware, uses less electricity, delivers output faster and can operate with a smaller cloud footprint.</p>



<p>Models that are optimized for efficiency deliver lower latency, improved scalability, increased flexibility and are less likely to drift. In my experience, all of this adds up to higher profit margins, a sharper competitive edge and a faster time to market, which are crucial whether you’re planning to use your model internally or sell it to others.</p>



<h2 class="wp-block-heading">The new CIO investment dilemma</h2>



<p>For a long time, it was believed that hardware must continually increase in power to enable models to grow in size. Then DeepSeek v2 came along and demolished all those theories. It showed that more efficient hardware can deliver equivalent results with less compute power by running smaller, smarter models.</p>



<p>Now, those of us in the CIO seat face a new dilemma: should we increase investment in computing power, focus on hardware or concentrate on software?</p>



<p>In my view, the correct answer is: all the above. AI efficiency is a full-stack problem. Hardware, compilers, runtime and model architecture must be co-designed to work in harmony; otherwise, we’re wasting money and failing to achieve the results we need. Today, choosing GPUs vs. custom accelerators vs. CPUs affects which model optimizations are viable.</p>



<h2 class="wp-block-heading">Hardware power constraints model capabilities</h2>



<p>It remains true that even the most powerful model in the world can’t function without access to the necessary hardware. Hardware performance is ultimately bounded by memory bandwidth, interconnect speed and compute units, no matter how optimized our models are.</p>



<p>This means that scalability depends on interconnects. Multi-node training and large inference clusters hinge on the performance of NVLink, InfiniBand or Ethernet fabric, not just model quality, so decisions about hardware investments or cloud providers can be critical to overall functionality.</p>



<p>“The pace of innovation is directly tied to advances in GPUs, tensor processing units (TPUs) and custom accelerators. The real question isn’t just what models we can build, but whether we have the compute infrastructure to support them,” says Gaurav Dewan, a research director at Avasant. “Models can only grow as powerful as the chips, memory systems and data center networks sustaining them.”</p>



<h2 class="wp-block-heading"><a></a>Compute power isn’t everything</h2>



<p>That said, in my experience, you can’t just throw computing power at every problem. Choices about hardware and cloud architecture determine how effectively users can tap into the potential of compute resources. Modern AI workloads are often memory-bound rather than compute-bound, so faster HBM, cache hierarchies and interconnects directly lower latency.</p>



<p>What’s more, the energy for computing power is limited. Companies can’t always afford the compute power they want, <a href="https://www.cloudzero.com/state-of-ai-costs/" rel="nofollow">with 58% saying</a> their AI cloud costs are too high. Cost per inference is hardware-driven and compute is usually the biggest line item in AI TCO. It’s not even easy to find space for enough GPUs, creating board-level power and cooling constraints in enterprise AI. More efficient silicon reduces data center strain, sustainability risk and cost per token/inference.</p>



<p>Additionally, reliability and utilization affect ROI. Features like MIG partitioning, hardware scheduling and fault tolerance determine how fully we can monetize expensive accelerators. Performance per watt is now the bottom line, with CIOs like me striving to get more out of every existing GPU per watt, dollar and square meter. We need to make our hardware more efficient by fine-tuning models and software to maximize capability.</p>



<p>“DeepSeek’s breakthrough suggests that AI models no longer need to scale indefinitely in size and complexity to achieve superior performance. Instead, they can be algorithmically optimized to deliver the same, if not better, results while consuming significantly fewer resources,” explains Matthew Taylor <a href="https://www.linkedin.com/pulse/ai-infrastructure-dilemma-on-premises-vs-cloud-2025-dr-matthew--zed1e/" rel="nofollow">in his post</a> on LinkedIn.</p>



<h2 class="wp-block-heading">Rethinking cloud strategy in the age of AI</h2>



<p>That cost pressure has forced many of us to revisit assumptions we held for the better part of a decade. Cloud computing has reached an uncertain crossroads. The hyperscaler-by-default posture that defined the last era of enterprise IT no longer survives a serious look at AI economics.</p>



<p>When inference costs scale linearly with usage and training runs can consume an annual infrastructure budget in weeks, the question I hear in every CIO conversation is the same: does our cloud strategy still match the workload we are actually running?</p>



<p>In my experience, the answer is increasingly no, at least not without significant rebalancing. Private clouds, written off as legacy not long ago, are quietly making a comeback. The combination of predictable cost structures, tighter control over data residency and the sensitivity of the proprietary data feeding our AI systems is making on-premise and colocation options compelling again, particularly for regulated industries.</p>



<p>At the same time, purpose-built neoclouds for GPU workloads, along with sovereign clouds responding to jurisdictional and data-protection mandates, are steadily chipping away at the dominance of AWS, Azure and GCP. None of these alternatives replace the hyperscalers outright, but they are forcing every CIO I know to think about cloud as a portfolio rather than a single vendor relationship.</p>



<p>What I have found is that navigating this shift takes more than a procurement decision. It takes a clear-eyed view of where each workload genuinely belongs. Training, inference, retrieval, fine-tuning and experimentation each carry different cost curves, latency profiles and data-gravity considerations. As organizations move <a href="https://www.artefact.com/blog/data-platforms-for-the-agentic-era/" rel="nofollow">towards the agentic</a> AI era, the underlying data platform becomes equally important, requiring architectures that can support multimodal data, real-time processing and governance at scale.</p>



<p>The enterprises I have seen handle this best treat cloud strategy as an ongoing exercise in workload placement, not a one-time platform commitment.</p>



<p>That is also where the conversation tends to outgrow internal teams.</p>



<p>As AI moves from pilots to production, the questions get harder: how to architect data foundations that survive model churn, how to govern AI without strangling it, how to translate technical efficiency into measurable business value. I have seen organizations lean on specialist partners to think through these problems alongside them. Among the consultancies working at this intersection is Artefact, founded in Paris and operating across data strategy, AI engineering and enterprise transformation. Its work includes governance, platform development, operating models and workforce enablement—areas that have become increasingly important as organizations move from AI pilots to large-scale deployment.</p>



<p>What I find useful about these consultancies is not the technology recommendations themselves; it is the pattern recognition they bring from seeing similar cloud and AI transitions play out across geographies and sectors. In a moment when every CIO is rewriting the playbook simultaneously, that outside vantage point matters more than it used to.</p>



<h2 class="wp-block-heading">Hardware is often underused and misused</h2>



<p><a></a>A lot of hardware goes unused or underutilized. Often, GPUs sit idle due to deployment complexity and data infrastructure bottlenecks, so enterprises don’t see the value of the compute power they’re paying for. When data and computing are on two separate chips, compute is wasted moving data between the two locations.</p>



<p>Likewise, models that exceed accelerator memory or require excessive HBM traffic suffer steep latency and cost penalties. Optimizing models to align with hardware means that all the compute power is being put to good use.</p>



<p>Techniques like operator fusion, activation management, fine-tuning smaller models, pruning unnecessary parameters and memory-aware architectures keep more of the model resident on the accelerator, reduce unnecessary read/write cycles and combine steps so data is touched fewer times.</p>



<p>Kfir Aberman, founding member at Decart AI, <a href="https://www.techzine.eu/experts/analytics/136536/how-our-team-optimizes-infrastructure-for-minimal-ai-video-processing-latency/">explains this approach</a>. “Our solution to this was to optimize our kernels for how [Nvidia GPU] Hopper works. Essentially, we created a single ‘mega kernel’ that enables the chip to process all of a model’s computations in a single, continuous pass. By doing this, we eliminate all of the stopping, starting and data movement, allowing more of the GPU to be utilized more of the time, speeding up processing by an order of magnitude.”</p>



<p>When models match accelerator characteristics such as tensor core shapes, SIMD widths and kernel libraries, this keeps expensive silicon working effectively and translates theoretical FLOPs into real throughput.</p>



<h2 class="wp-block-heading">More hardware can’t overcome model mismatch</h2>



<p><a></a>Another way that organizations undermine ROI on their own AI investments is by ignoring coordination efficiency.</p>



<p>They’ll buy large GPU clusters but pay little attention to what seem like minor issues with batching and alignment. Unfortunately, when batch sizes are wrong, work is split inefficiently and network links become bottlenecks, you see expensive but underutilized clusters.</p>



<p>Ultimately, more GPUs don’t guarantee more performance. Parallelism and batching must match the system topology. Effective scaling depends on aligning data, tensor and pipeline parallelism and batch sizing with the actual interconnect bandwidth and node configuration.</p>



<h2 class="wp-block-heading">The magic happens when model and hardware come together</h2>



<p>The lesson that those of us in CIO roles are learning is that symbiosis between model and hardware is critical. Code determines what our AI can do, hardware determines how efficiently we can afford to do it and co-design determines whether our AI program scales economically and successfully.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding token costs are on track to rival human payroll]]></title>
<description><![CDATA[Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.



According to Gartner, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.



This is not only because developers are increasin...]]></description>
<link>https://tsecurity.de/de/3623163/ai-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623163/ai-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</guid>
<pubDate>Thu, 25 Jun 2026 03:18:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges" target="_blank" rel="noreferrer noopener">According to Gartner</a>, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.</p>



<p>This is not only because developers are increasingly adopting generative AI and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html" target="_blank">agentic tools</a>, it reflects a trend toward consumption-based licensing models as vendors balance infrastructure investments with profitability. Rather than the flat per-seat <a href="https://www.computerworld.com/article/4131921/saas-isnt-dead-the-market-is-just-becoming-more-hybrid-2.html" target="_blank">SaaS model</a> of the past, enterprises now pay for developer token use as well.</p>



<p>Gartner senior principal analyst <a href="https://www.gartner.com/en/experts/nitish-tyagi" target="_blank" rel="noreferrer noopener">Nitish Tyagi</a> explained that it’s important to note that Gartner’s prediction is based on a global average salary of $2,000 per month; it doesn’t mean AI token usage will exceed all salaries. For instance, in the US, yearly pay rates can be six digits or more.</p>



<p>However, that kind of spend is not out of the realm of possibility, Tyagi emphasized. “I have heard scary numbers like ‘My developer consumed $20K last month,’ or ‘A business user consumed $32K’.”</p>



<p>If these amounts sound shocking, that’s the point. “The goal is to alarm the industry about the impact of token cost if it is not governed and controlled,” he said.</p>



<h2 class="wp-block-heading">Lack of visibility, immature oversight</h2>



<p>Enterprises are quickly moving from experimentation to scaled deployment of <a href="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html" target="_blank">AI coding agents</a>, but many still underestimate token costs, Tyagi noted.</p>



<p>This is because cost structures for software engineering workloads are “highly variable,” he pointed out, and there isn’t a lot of transparency into how token consumption is calculated and billed.</p>



<p>AI coding vendors have yet to deliver “mature, built-in cost optimization capabilities,” Tyagi said, and prices will likely only continue to rise as vendors further build out their models while at the same time trying to remain profitable.</p>



<p>Thus, enterprises struggle to forecast and control costs, and, because AI is moving so fast, many organizations lack the “maturity and frameworks” to determine ROI, he noted. Agent-driven workflows are difficult to govern, context windows become bloated, budgets are wiped out earlier than anticipated, and token spend becomes hard to justify.</p>



<p>Added to this, light users such as non-developers will increase their usage as they become more familiar with, and even reliant on, AI tools, driving up token consumption and spend even more.</p>



<p>Tyagi said that, while AI is incredibly valuable, he sees no “direct relationship” between the number of tokens developers consume and their productivity gains. Rather, applying context engineering principles to optimize or reduce token consumption increases quality.</p>



<p>“<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html" target="_blank">Tokenmaxxing</a> is not directly related to higher productivity gains,” Tyagi said, “but optimizing token consumption is.”</p>



<p>Still, this in no way means that organizations should move away from AI coding agents, he emphasized. Optimizing token consumption simply means spending only as much as needed without compromising the quality and value brought by AI.</p>



<p>“Without a governed engineering operating model, costs can escalate faster than the productivity gains these tools are designed to deliver,” Tyagi said.</p>



<h2 class="wp-block-heading">How enterprises can control token usage</h2>



<p>The traditional ‘lines-of-code-written’ productivity metric no longer applies when AI can almost instantaneously produce entire Python libraries. Rather, value should be measured in quality, speed, and customer satisfaction metrics, Tyagi said.</p>



<p>For instance: How quickly are developers able to release important features? How much time is reduced between app development and feedback from business, product, and development teams? Shipping features quickly while maintaining quality can create competitive advantage and improve user and customer experience, he said.</p>



<p>Gartner also advises establishing strong governance and cost controls. For instance, introduce token thresholds, automate usage monitoring, and create explicit escalation policies.</p>



<p>“Embedding these controls into engineering workflows ensures consistency and prevents uncontrolled cost growth,” the firm notes.</p>



<p>In addition, enterprises should create a “use case driven” decision framework. This means clearly defining when AI coding agents should be used, and their appropriate levels of autonomy given certain tasks. Further, classify those tasks into three execution models: ‘developer‑led,’ ‘developer‑with‑agent’, and ‘fully agent‑led.’</p>



<p>Enterprises should also select models based on task complexity. Break work into smaller tasks that can be performed by smaller models, “with escalation only when complexity demands it,” Gartner advises. Engineering teams should route workflows deliberately, directing simpler, high-frequency tasks to smaller models and using frontier models only for complex and high-value work.</p>



<p>Another cost saving tactic is mandating specific context engineering practices, the firm says. Developers should be trained to optimize the context they input to AI, including only the information that’s relevant, summarizing that content as much as possible, and eliminating unnecessary data.</p>



<p>Further, teams should embed token usage reviews into development cycles. Regular review of high token consuming workflows can help identify inefficiencies, refine practices, and support collaboration, Gartner says.</p>



<p>Tyagi noted that developers tend to optimize for speed and convenience rather than cost efficiency, so token discipline cannot be achieved through developer choice alone.</p>



<p>His advice for leaders: Do not treat escalating AI coding costs as a reason to move away from AI, or to shift to open generative AI models for everything. “The goal is always to optimize costs without compromising the value.”</p>



<p>Start small, and focus on context engineering first, he said. Assess your current software engineering maturity and select the appropriate agent autonomy. AI assistive development can provide up to 20% productivity gains, “which is not a bad number.”</p>



<p>For developers, he advises: “Target context engineering as one of the most important <a href="https://www.cio.com/article/2128415/generative-ai-certifications-and-certificate-programs.html" target="_blank">skills for yourself</a>. This is not only going to help your employer, but also your career.”</p>



<p><em>This article originally appeared on <a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding token costs are on track to rival human payroll]]></title>
<description><![CDATA[Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.



According to Gartner, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.



This is not only because developers are increasin...]]></description>
<link>https://tsecurity.de/de/3623145/it-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623145/it-nachrichten/ai-coding-token-costs-are-on-track-to-rival-human-payroll/</guid>
<pubDate>Thu, 25 Jun 2026 02:47:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprises may soon be paying as much for their developers’ AI token usage as they do for their salaries.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges" target="_blank" rel="nofollow">According to Gartner</a>, these costs will meet, or even exceed, the typical software engineer’s monthly salary within the next two years.</p>



<p>This is not only because developers are increasingly adopting generative AI and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html" target="_blank">agentic tools</a>, it reflects a trend toward consumption-based licensing models as vendors balance infrastructure investments with profitability. Rather than the flat per-seat <a href="https://www.computerworld.com/article/4131921/saas-isnt-dead-the-market-is-just-becoming-more-hybrid-2.html" target="_blank">SaaS model</a> of the past, enterprises now pay for developer token use as well.</p>



<p>Gartner senior principal analyst <a href="https://www.gartner.com/en/experts/nitish-tyagi" target="_blank" rel="nofollow">Nitish Tyagi</a> explained that it’s important to note that Gartner’s prediction is based on a global average salary of $2,000 per month; it doesn’t mean AI token usage will exceed all salaries. For instance, in the US, yearly pay rates can be six digits or more.</p>



<p>However, that kind of spend is not out of the realm of possibility, Tyagi emphasized. “I have heard scary numbers like ‘My developer consumed $20K last month,’ or ‘A business user consumed $32K’.”</p>



<p>If these amounts sound shocking, that’s the point. “The goal is to alarm the industry about the impact of token cost if it is not governed and controlled,” he said.</p>



<h2 class="wp-block-heading">Lack of visibility, immature oversight</h2>



<p>Enterprises are quickly moving from experimentation to scaled deployment of <a href="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html" target="_blank">AI coding agents</a>, but many still underestimate token costs, Tyagi noted.</p>



<p>This is because cost structures for software engineering workloads are “highly variable,” he pointed out, and there isn’t a lot of transparency into how token consumption is calculated and billed.</p>



<p>AI coding vendors have yet to deliver “mature, built-in cost optimization capabilities,” Tyagi said, and prices will likely only continue to rise as vendors further build out their models while at the same time trying to remain profitable.</p>



<p>Thus, enterprises struggle to forecast and control costs, and, because AI is moving so fast, many organizations lack the “maturity and frameworks” to determine ROI, he noted. Agent-driven workflows are difficult to govern, context windows become bloated, budgets are wiped out earlier than anticipated, and token spend becomes hard to justify.</p>



<p>Added to this, light users such as non-developers will increase their usage as they become more familiar with, and even reliant on, AI tools, driving up token consumption and spend even more.</p>



<p>Tyagi said that, while AI is incredibly valuable, he sees no “direct relationship” between the number of tokens developers consume and their productivity gains. Rather, applying context engineering principles to optimize or reduce token consumption increases quality.</p>



<p>“<a href="https://www.cio.com/article/4178320/tokenmaxxing-when-ai-adoption-metrics-go-bad.html" target="_blank">Tokenmaxxing</a> is not directly related to higher productivity gains,” Tyagi said, “but optimizing token consumption is.”</p>



<p>Still, this in no way means that organizations should move away from AI coding agents, he emphasized. Optimizing token consumption simply means spending only as much as needed without compromising the quality and value brought by AI.</p>



<p>“Without a governed engineering operating model, costs can escalate faster than the productivity gains these tools are designed to deliver,” Tyagi said.</p>



<h2 class="wp-block-heading">How enterprises can control token usage</h2>



<p>The traditional ‘lines-of-code-written’ productivity metric no longer applies when AI can almost instantaneously produce entire Python libraries. Rather, value should be measured in quality, speed, and customer satisfaction metrics, Tyagi said.</p>



<p>For instance: How quickly are developers able to release important features? How much time is reduced between app development and feedback from business, product, and development teams? Shipping features quickly while maintaining quality can create competitive advantage and improve user and customer experience, he said.</p>



<p>Gartner also advises establishing strong governance and cost controls. For instance, introduce token thresholds, automate usage monitoring, and create explicit escalation policies.</p>



<p>“Embedding these controls into engineering workflows ensures consistency and prevents uncontrolled cost growth,” the firm notes.</p>



<p>In addition, enterprises should create a “use case driven” decision framework. This means clearly defining when AI coding agents should be used, and their appropriate levels of autonomy given certain tasks. Further, classify those tasks into three execution models: ‘developer‑led,’ ‘developer‑with‑agent’, and ‘fully agent‑led.’</p>



<p>Enterprises should also select models based on task complexity. Break work into smaller tasks that can be performed by smaller models, “with escalation only when complexity demands it,” Gartner advises. Engineering teams should route workflows deliberately, directing simpler, high-frequency tasks to smaller models and using frontier models only for complex and high-value work.</p>



<p>Another cost saving tactic is mandating specific context engineering practices, the firm says. Developers should be trained to optimize the context they input to AI, including only the information that’s relevant, summarizing that content as much as possible, and eliminating unnecessary data.</p>



<p>Further, teams should embed token usage reviews into development cycles. Regular review of high token consuming workflows can help identify inefficiencies, refine practices, and support collaboration, Gartner says.</p>



<p>Tyagi noted that developers tend to optimize for speed and convenience rather than cost efficiency, so token discipline cannot be achieved through developer choice alone.</p>



<p>His advice for leaders: Do not treat escalating AI coding costs as a reason to move away from AI, or to shift to open generative AI models for everything. “The goal is always to optimize costs without compromising the value.”</p>



<p>Start small, and focus on context engineering first, he said. Assess your current software engineering maturity and select the appropriate agent autonomy. AI assistive development can provide up to 20% productivity gains, “which is not a bad number.”</p>



<p>For developers, he advises: “Target context engineering as one of the most important <a href="https://www.cio.com/article/2128415/generative-ai-certifications-and-certificate-programs.html" target="_blank">skills for yourself</a>. This is not only going to help your employer, but also your career.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Biggest Identity Problem Isn’t Your Employees Anymore; It’s Everything Else]]></title>
<description><![CDATA[I used to open identity audits by asking a CISO how many users were on their network. These days, I ask a different question first: how many non-human identities do you have, and when was the last time anyone counted?…
Read more →
The post Your Biggest Identity Problem Isn’t Your Employees Anymor...]]></description>
<link>https://tsecurity.de/de/3622742/it-security-nachrichten/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622742/it-security-nachrichten/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/</guid>
<pubDate>Wed, 24 Jun 2026 22:24:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I used to open identity audits by asking a CISO how many users were on their network. These days, I ask a different question first: how many non-human identities do you have, and when was the last time anyone counted?…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-biggest-identity-problem-isnt-your-employees-anymore-its-everything-else/">Your Biggest Identity Problem Isn’t Your Employees Anymore; It’s Everything Else</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon will present its framework for engineering trustworthy AI agents at VB Transform 2026]]></title>
<description><![CDATA[AI agents are increasingly proficient at executing business tasks autonomously, but IT leaders are cautious about granting permissions to access enterprise systems. Part of the challenge lies in how AI reliability is measured. Industry standards often rely on EVAL scores, which provide a static s...]]></description>
<link>https://tsecurity.de/de/3622267/it-nachrichten/amazon-will-present-its-framework-for-engineering-trustworthy-ai-agents-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622267/it-nachrichten/amazon-will-present-its-framework-for-engineering-trustworthy-ai-agents-at-vb-transform-2026/</guid>
<pubDate>Wed, 24 Jun 2026 19:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI agents are increasingly proficient at executing business tasks autonomously, but IT leaders are cautious about granting permissions to access enterprise systems. </p><p>Part of the challenge lies in how <a href="https://venturebeat.com/technology/karpathys-march-of-nines-shows-why-90-ai-reliability-isnt-even-close-to">AI reliability</a> is measured. Industry standards often rely on EVAL scores, which provide a static snapshot of performance rather than a measure of overall reliability. These metrics can fail to capture predictability across prompts, environments, and input types, said Bryan Silverthorn, director of the AGI Autonomy research lab at Amazon.</p><p>Amazon’s AGI autonomy research lab is moving beyond raw performance benchmarks, focusing instead on a structured framework centered on consistency, robustness, predictability, and safety, Silverthorn told VentureBeat during an interview ahead of his session at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>.</p><p>Rather than assuming that models can be harnessed into safety, Amazon’s approach emphasizes decoupled systems, such as sandboxed environments where agents propose changes that are reviewed by humans before implementation. </p><p>This strategy aims to bridge the trust gap by prioritizing verifiable interactions, even in highly sensitive domains like finance, where the potential damage an agent can cause is significant.</p><p>In VentureBeat’s Q2 Pulse Research survey of over 100 senior technology leaders and buyers, just 4% said they are comfortable relying on model guardrails alone. When asked what worries them most about model guardrails, 40% said unauthorized access to tools or data and 27% cited prompt manipulation or injection.</p><p>At VB Transform, Silverthorn will share details of Amazon’s approach to trustworthy agentic AI and how companies can move from single-agent wrappers to multi-tool architectures that can self-correct mid-execution during his session titled <b>Closing the capability-reliability gap: Inside Amazon’s framework for engineering trustworthy agents</b>.</p><p>Another agentic ops and evals-focused session at VentureBeat’s flagship conference, happening July 14 and 15 in Menlo Park, is <b>Intelligence at scale: How Waymo builds safe, efficient AI for the physical world</b> with speaker Manasi Joshi, director of systems intelligence and machine learning at Waymo. </p><p><i>Interested in attending VB Transform 2026? A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i>Contact us </i></a><i>to get yours. You can also purchase tickets </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i>here</i></a><i>.</i>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No Claude Fable 5? No problem: Sakana achieves frontier performance with new Fugu multi-model, auto synthesis system]]></title>
<description><![CDATA[Last night, the increasingly enterprise-focused AI startup Sakana launched Fugu, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API. Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and ...]]></description>
<link>https://tsecurity.de/de/3616186/it-nachrichten/no-claude-fable-5-no-problem-sakana-achieves-frontier-performance-with-new-fugu-multi-model-auto-synthesis-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616186/it-nachrichten/no-claude-fable-5-no-problem-sakana-achieves-frontier-performance-with-new-fugu-multi-model-auto-synthesis-system/</guid>
<pubDate>Mon, 22 Jun 2026 19:03:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last night, the increasingly enterprise-focused AI startup <a href="https://sakana.ai/fugu/">Sakana launched Fugu</a>, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API. </p><p>Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and geopolitical export controls, Fugu (Japanese for "pufferfish"), bypasses the traditional monolithic model structure by dynamically routing queries to a swappable pool of specialized AI agents. </p><p>Sakana CEO and co-founder David Ha, formerly of Google Brain, positioned Fugu as a more reliable option for enterprise workflows than any single AI model provider in the wake of<a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do"> Anthropic's move on June 12 to revoke public access</a> to its most powerful models, Claude Mythos 5 and Claude Fable 5, in the wake of a U.S. government export control order. As <a href="https://x.com/hardmaru/status/2068884466056225025">Ha wrote in a post today on X:</a></p><blockquote><p>"Fugu dynamically orchestrates the world’s best models to tackle complex tasks. We are proving that a well-orchestrated pool of swappable agents can match restricted frontier models like Fable and Mythos.

But Fugu is about more than just performance. I believe that Orchestration Models are the next frontier, beyond bigger models.

Relying on a single company’s model for national infrastructure is a massive risk. As recent export controls have shown, access to top models can disappear overnight.

Collective intelligence is the practical hedge against this concentration of power. Fugu simply routes around vendor restrictions by relying on an entirely swappable agent pool."</p></blockquote><p>Sakana AI explicitly states that the specific models Fugu selects and how it coordinates them are proprietary, meaning this routing information is hidden from the user by design. The documentation only refers generally to a "diverse pool of powerful models," "multiple LLMs," or "specialized models" without providing a specific count.</p><p>By acting as a sophisticated coordinator rather than a standalone foundation model, Fugu matches the output quality of top-tier models like Fable and Mythos on third-party benchmarks of agentic tasks, while fundamentally altering how developers deploy critical AI infrastructure.</p><h2><b>How Sakana Fugu works and where it beats Anthropic's Claude Fable 5</b></h2><p>At its core, Sakana Fugu operates like a master general contractor. When presented with a complex request, Fugu does not attempt to execute every step itself. </p><p>Instead, it breaks the problem down, delegates sub-tasks to a pool of expert foundation models, verifies their work, and synthesizes the final output.</p><p>"Fugu is itself an LLM, trained to call various LLMs in an agent pool, including instances of itself recursively," the Sakana AI team noted in their technical release. </p><p>Grounded in two of Sakana's 2026 research papers, <a href="https://sakana.ai/trinity/">TRINITY</a> and the <a href="https://sakana.ai/learning-to-orchestrate/">Conductor</a>, the system autonomously manages the entire lifecycle of model selection and verification using learned coordination strategies rather than hand-designed workflows. To the end user, this multi-agent swarm is entirely abstracted behind a standard API endpoint.</p><p>Sakana AI is offering two variants of the system to cater to different operational workloads:</p><ul><li><p><b>Fugu:</b> A high-speed, low-latency model optimized for everyday tasks. It is designed to act as the default engine for interactive chatbots and integrates directly into coding environments like Codex.</p></li><li><p><b>Fugu Ultra:</b> The flagship tier engineered for complex, high-stakes tasks such as AI research, cybersecurity analysis, and multi-step patent investigations. According to Sakana, Fugu Ultra coordinates a deeper pool of experts and matches industry-leading monolithic models across rigorous scientific and reasoning benchmarks.</p></li></ul><p>Additionally, on the pay-as-you-go plan, standard Fugu charges a dynamic rate based on the specific underlying models activated, whereas Fugu Ultra utilizes a fixed pricing structure starting at $5 per million input tokens and $30 per million output tokens.</p><p>As indicated by benchmark charts shared by Sakana, Fugu actually exceeds the performance of Anthropic's Claude Fable 5 on <a href="https://huggingface.co/blog/leaderboard-livecodebench">LiveCodeBench</a>, an open source benchmark testing coding performance on regularly refreshed, software problem-solving tasks (Fugu Ultra: 93.2, Fugu: 92.9, Fable: 89.8), and beats the prior Claude Mythos Preview model on <a href="https://epoch.ai/benchmarks/gpqa-diamond">GPQA-D (Diamond)</a> , a test of 198 graduate-level multiple-choice questions in biology, physics, and chemistry (Fugu Ultra: 95.5, Fugu: 95.5, Mythos Preview: 94.6).</p><p>By orchestrating multiple models from different providers, Fugu essentially builds native redundancy into the AI stack. If one provider suffers an outage or faces sudden regulatory restrictions, Fugu routes around the disruption to maintain uptime.</p><h2><b>Licensing and availability</b></h2><p>Fugu is offered as a commercial, proprietary API service, not an open-source framework. </p><p>Because Sakana’s core intellectual property lies in its non-obvious collaboration patterns, the specific routing information—meaning exactly which underlying models Fugu selects for a given query—remains proprietary and is intentionally hidden from the user.</p><p>However, Sakana offers critical controls for enterprise data compliance. Developers can explicitly opt specific models or providers out of their Fugu routing pool to maintain strict corporate privacy standards. </p><p>Additionally, users can opt out of having their prompts used for future training data. Geographically, Fugu is restricted from operating within the European Union (EU) and European Economic Area (EEA) while Sakana works to align its black-box data routing architecture with GDPR regulations.</p><h2><b>Pricing is fairly steep</b></h2><p>Fugu is available immediately in most regions—with the temporary exception of the EU and EEA—at subscription tiers and pay-as-you-go pricing.</p><p>Teams can opt for monthly <a href="https://sakana.ai/fugu/">subscription allowances </a>designed for individual or hands-on use: a Standard tier at $20/month for lightweight workflows, a Pro tier at $100/month providing 10x standard usage, and a Max tier at $200/month offering 20x usage for continuous, long-running tasks. I wasn't able to find the actual amount of tokens covered under these plans, but I've reached out to Ha on X for more information.</p><p>As part of the initial rollout, Sakana is offering a free second month for users who subscribe to any tier by July 31, 2026.</p><p>For enterprise scaling and production deployments, Sakana offers an elastic pay-as-you-go plan. Crucially for high-stakes environments, requests made under this consumption-based model are served at a higher priority than those from monthly subscription plans. </p><p>Under this framework, the standard Fugu engine charges the single rate of the highest-tier underlying model involved in a query, without ever stacking multi-agent fees. The flagship Fugu Ultra tier (fugu-ultra-20260615) utilizes a fixed pricing structure per one million tokens: $5 for input, $30 for output, and $0.50 for cached input. These rates increase to $10, $45, and $1.00 respectively for extreme workloads utilizing context windows above 272K tokens. That puts it among the more expensive options compared to single AI models via provider APIs:</p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p>DeepSeek</p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p>DeepSeek</p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p>MiniMax</p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p>Google</p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p>Alibaba Cloud</p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p>xAI</p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p>Moonshot</p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p>Z.ai</p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p>xAI</p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p>Alibaba Cloud</p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p>Google</p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p>Google</p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p>OpenAI</p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p>Google</p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p>Anthropic</p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p>OpenAI</p></td></tr><tr><td><p><b>Sakana Fugu Ultra</b></p></td><td><p><b>$5.00</b></p></td><td><p><b>$30.00</b></p></td><td><p><b>$35.00</b></p></td><td><p><b>Sakana AI</b></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p>Anthropic</p></td></tr></tbody></table><p>Developers modeling operational costs should also note a significant architectural caveat in how Fugu bills for its multi-agent capabilities. According to the developer documentation, Fugu Ultra’s API responses include detailed usage fields that separate user-visible token generation from internal orchestration work. The background tokens consumed and generated when Fugu delegates sub-tasks, verifies code, or routes between underlying agents are not absorbed by the provider; they represent real token usage and are counted toward the final price of the request at standard rates.</p><h2><b>The Orchestration landscape: Fugu vs. The Field and notable benchmark performance</b></h2><p>To understand Fugu’s position in the mid-2026 AI ecosystem, it is critical to distinguish between <i>model routing</i> and <i>multi-agent orchestration</i>. </p><p>Over the past year, enterprise adoption of standard routing platforms—such as Not Diamond, Martian, and the open-source RouteLLM framework—has skyrocketed. These systems act as intelligent air traffic controllers; using semantic classifiers or meta-models, they analyze an incoming prompt and predict which single foundation model will yield the highest quality or most cost-effective response, dispatching the query accordingly.</p><p>Fugu operates on a fundamentally different paradigm. Rather than making a one-shot routing decision, Fugu aligns more closely with complex multi-round systems like Router-R1 (a framework introduced at NeurIPS 2025). It breaks a query down, interleaves reasoning with delegation, and dynamically assigns sub-tasks to multiple models in parallel or sequence before synthesizing a final output.</p><p>While frameworks like LangGraph, CrewAI, and Microsoft AutoGen offer developers the tools to build similar multi-agent systems, they require immense manual configuration—defining roles, setting up conditional edges, and managing state across long-running loops. </p><p>Fugu abstracts this operational overhead entirely. It is essentially a LangGraph-style workflow packaged as a single, black-box API endpoint.</p><p>An orchestration system is ultimately bounded by the raw capabilities of the underlying models in its pool, a reality reflected in Sakana’s own benchmark testing against standalone frontier models.</p><p>On rigorous coding and agentic tasks, collective intelligence shows a distinct advantage over standard models. Fugu Ultra posted a <b>73.7 on SWE-Bench Pro</b>, significantly outperforming Anthropic's Claude Opus 4.8 (69.2) and OpenAI's GPT-5.5 (58.6). </p><p>However, Fugu is not a silver bullet, and its performance is not a clean sweep across the board. When compared to highly specialized or restricted-access monolithic models, Fugu occasionally trails:</p><ul><li><p><b>SWE-Bench Pro:</b> While Fugu Ultra (73.7) beat most accessible models, it was comfortably eclipsed by Anthropic’s limited-access Fable 5 (80.0), which is currently absent from Fugu's swappable pool due to the U.S. government's export control order and Anthropic's subsequent response to remove the model entirely from global usage. </p></li><li><p><b>Humanity's Last Exam:</b> Fugu Ultra (50.0) narrowly edged out Opus 4.8 (49.8), but again fell short of Fable 5 (53.3).</p></li><li><p><b>Long-Context and Security:</b> On the MRCRv2 long-context-recall test, OpenAI's GPT-5.5 maintained the lead (94.8 vs Fugu Ultra's 93.6), and Opus 4.8 remained the top performer on the CTI-REALM cybersecurity benchmark (69.6 vs Fugu Ultra's 69.4).</p></li></ul><p>The quantitative data points to a clear conclusion: Fugu is highly effective at boosting performance on messy, multi-step tasks (like writing a complex HTML5 game from scratch) by leaning on the combined strengths of multiple mid-tier and high-tier models. </p><p>However, for sheer brute-force reasoning within a single, highly constrained domain, the industry's largest standalone models still hold the edge—provided an enterprise can maintain uninterrupted access to them.</p><h2><b>Background on Sakana's formation and noteworthy achievements to date</b></h2><p><a href="https://venturebeat.com/ai/what-you-need-to-know-about-sakana-ai-the-new-startup-from-a-transformer-paper-co-author">Sakana AI was formed in Tokyo in 2023 </a>by Llion Jones, a co-author of Google’s foundational 2017 "Attention Is All You Need" paper, and David Ha, the former head of research at Stability AI. </p><p>Disillusioned by large tech company bureaucracy and the industry's hyper-fixation on scaling single, massive foundational models, the founders built Sakana around principles of biomimicry and evolutionary computing.</p><p>The company's name, derived from the Japanese word for fish, reflects its core technical thesis: utilizing collective "swarm" intelligence rather than brute-force compute. Following a $2.6 billion Series B valuation in late 2025 and <a href="https://venturebeat.com/technology/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours">the recent June 2026 launch of Marlin</a>—an autonomous, eight-hour research agent for the B2B sector—Fugu represents the commercialization of Sakana's multi-agent routing technology for everyday developers.</p><h2><b>A mixed reception among the broader AI community online</b></h2><p>The developer community has responded to Fugu by rigorously testing its practical tradeoffs, weighing its routing efficiencies against the sheer power of monolithic foundation models.</p><p>AI observer, developer and influencer <a href="https://x.com/ChrissGPT/status/2068904825685787083?s=20">Chris (@ChrissGPT on X)</a> highlighted the specific utility of Fugu over raw foundational AI. </p><p>"For a single clean prompt, you probably would [use Fable 5, Mythos, or GPT-5.5 directly]," he noted, but argued that Fugu's true value emerges in messy, multi-step environments. "...whether it involves delegation, verification, synthesis, code review, research loops, security analysis... the more it would make sense to use this," he wrote.</p><p>Chris also pointed out the strategic geopolitical advantage of Fugu's architecture, noting that if frontier AI access is abruptly revoked due to regulation or export controls, an orchestrator can dynamically swap models to prevent a total system failure.</p><p>Creative agency owner <a href="https://x.com/markksantos/status/2068962823007285628?s=20">Mark Santos (@markksantos) </a>of Mark Studios provided a direct, real-world comparison by tasking both Fugu Ultra and Claude Opus 4.8 with building a "Crossy Road" game clone using Three.js. The results underscored the operational differences between an orchestrator and a monolithic giant:</p><ul><li><p><b>Sakana Fugu Ultra:</b> Completed the task in 22 minutes using ~89,000 tokens for roughly $7.32. However, the final game suffered from minor logic errors, such as inverted directional turns and wonky camera angles.</p></li><li><p><b>Claude Opus 4.8:</b> Took 79 minutes, burned ~940,000 tokens for nearly $37.85, and got stuck in a retry loop requiring human intervention. Despite the inefficiency, it ultimately produced superior application design and functionality.</p></li></ul><p>Santos concluded the experiment by stating, "In terms of application functionality, quality, and design, Opus won. In terms of model speed and performance, Fugu... won".</p><p>Elie Bakouch, a research engineer at cloud-based, open AI infrastructure and systems provider <a href="https://www.primeintellect.ai/">Prime Intellect</a>, <a href="https://x.com/eliebakouch/status/2068939729811468503">pointed out on X</a> that "to be clear, this is a closed source orchestrator on top of closed source models. if before you didn't control the models, now you don't even control which ones are used or how much. this is not 'AI sovereignty'..."</p><div></div><p>These early tests and reactions mirror the sentiment summarized by <a href="https://www.reddit.com/r/LLMDevs/comments/1uca8e3/comment/ot2k0kx/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button">Reddit user GreedyWorking1499</a> in initial platform discussions: "<i>Until proven otherwise, this is just a highly advanced router/wrapper, not a fundamental not a fundamental leap in intelligence like Mythos/Fable was.</i>"</p><p>Yet, as enterprises increasingly demand fail-safes against single-vendor reliance, Sakana is proving that packaging collective intelligence into a single API endpoint is a highly viable commercial path.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Mac isn't immune to viruses & surveillance tools, Intego One is here to help]]></title>
<description><![CDATA[If you're on the hunt for one of the best antivirus for Mac, then Intego One is an excellent option, as it combines four important security tools into one. Get it today at 50% off your subscription.Intego One is a complete suite of tools for your MacThere may be fewer viruses and spyware made for...]]></description>
<link>https://tsecurity.de/de/3615677/ios-mac-os/your-mac-isnt-immune-to-viruses-surveillance-tools-intego-one-is-here-to-help/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615677/ios-mac-os/your-mac-isnt-immune-to-viruses-surveillance-tools-intego-one-is-here-to-help/</guid>
<pubDate>Mon, 22 Jun 2026 15:56:22 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you're on the hunt for one of the best antivirus for Mac, then Intego One is an excellent option, as it combines four important security tools into one. Get it today at 50% off your subscription.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67983-143354-IMG_4691-xl.jpg" alt="Computer screen showing Intego ONE security dashboard with antivirus, firewall, VPN, and SmartScan panels on the left, and text on the right stating Your Mac is Actively Protected with glowing shield icon" height="738"><br><span>Intego One is a complete suite of tools for your Mac</span></div><br>There may be fewer viruses and spyware made for Macs, but that advantage is shrinking every day. Apple's protections are robust, but you don't want to go without some dedicated tools to help ensure your data stays yours as you use your Mac.<br><br>That's where <a href="https://offer.intego.com/appleinsiderIO_9w68eprq9" rel="sponsored" target="_blank"><strong>Intego One</strong></a> comes in. It's an upgrade from Intego X9 that brings five separate apps into a single interface.<br><br><br> <a href="https://appleinsider.com/articles/26/06/22/your-mac-isnt-immune-to-viruses-surveillance-tools-intego-one-is-here-to-help?utm_source=rss">Continue Reading on AppleInsider</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Incoming CEO John Ternus may be looking to fix something that isn't broken]]></title>
<description><![CDATA[John Ternus has been talking about focusing on Apple's core strength of design once he takes over as CEO, and a now a questionable report extrapolates that this means he'll shake up the design team.John Ternus plans to concentrate on Apple's core strength of designJohn Ternus is now best known fo...]]></description>
<link>https://tsecurity.de/de/3613738/ios-mac-os/incoming-ceo-john-ternus-may-be-looking-to-fix-something-that-isnt-broken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613738/ios-mac-os/incoming-ceo-john-ternus-may-be-looking-to-fix-something-that-isnt-broken/</guid>
<pubDate>Sun, 21 Jun 2026 16:54:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://appleinsider.com/inside/john-ternus" title="John Ternus" data-kpt="1">John Ternus</a> has been talking about focusing on Apple's core strength of design once he takes over as CEO, and a now a questionable report extrapolates that this means he'll shake up the design team.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66449-139348-John-Ternus-outside-xl.jpg" alt="Apple's John Ternus in dark t-shirt stands outside a modern glass Apple Store at night, hands clasped, with glowing Apple logo, wet tiled ground, and trees by water in background" height="738"><br><span>John Ternus plans to concentrate on Apple's core strength of design</span></div><br>John Ternus is now best known for taking over as Apple CEO from <a href="https://appleinsider.com/inside/tim-cook" title="Tim Cook" data-kpt="1">Tim Cook</a>, but as recently as <a href="https://appleinsider.com/articles/26/01/22/apples-john-ternus-solidifies-his-role-as-ceo-apparent-amid-design-team-shakeup">January 2026</a>, he took control of the firm's design team. Now according to <em>Bloomberg</em>, far from leaving that because of other CEO duties, he <a href="https://www.bloomberg.com/account/newsletters/power-on">is planning</a> to continue working on Apple's whole design philosophy.<br><br>Reportedly, Ternus told staff that under him, Apple will "keep focusing on design, because design is core to what we do in Apple."<br><br><br> <a href="https://appleinsider.com/articles/26/06/21/incoming-ceo-john-ternus-may-be-looking-to-fix-something-that-isnt-broken?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244712?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel Screenshots Isn’t Only Using On-Device AI Anymore]]></title>
<description><![CDATA[Pixel Screenshots was launched on Pixel devices as a way for users to process screenshots and collect information from them using on-device AI. It was quick, it was painless. A recent change to the service is implementing the ability for Pixel Screenshots to now upload those same screenshots and ...]]></description>
<link>https://tsecurity.de/de/3608575/it-nachrichten/pixel-screenshots-isnt-only-using-on-device-ai-anymore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608575/it-nachrichten/pixel-screenshots-isnt-only-using-on-device-ai-anymore/</guid>
<pubDate>Thu, 18 Jun 2026 19:48:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Pixel Screenshots was launched on Pixel devices as a way for users to process screenshots and collect information from them using on-device AI. It was quick, it was painless. A recent change to the service is implementing the ability for Pixel Screenshots to now upload those same screenshots and process them, securely, in the cloud....</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/06/18/pixel-screenshots-isnt-only-using-on-device-ai-anymore/">Pixel Screenshots Isn’t Only Using On-Device AI Anymore</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone Air successor rumored for spring 2027 with two cameras]]></title>
<description><![CDATA[A new rumor suggests that the iPhone Air 2 is being tested and is expected to launch in early 2027 with improved battery life and an ultra-wide camera. Though, these aren't groundbreaking claims.iPhone Air 2 is expected to add an ultrawide rear cameraThe iPhone Air debuted in September 2025 along...]]></description>
<link>https://tsecurity.de/de/3606042/ios-mac-os/iphone-air-successor-rumored-for-spring-2027-with-two-cameras/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606042/ios-mac-os/iphone-air-successor-rumored-for-spring-2027-with-two-cameras/</guid>
<pubDate>Wed, 17 Jun 2026 22:39:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new rumor suggests that the <a href="https://appleinsider.com/inside/iphone-air" title="iPhone Air" data-kpt="1">iPhone Air 2</a> is being tested and is expected to launch in early 2027 with improved battery life and an ultra-wide camera. Though, these aren't groundbreaking claims.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67980-143310-Air-2-xl.jpg" alt="White iPhone lying face down on a dark surface, showing dual rear cameras and Apple logo, with light reflecting off the metallic edges" height="738"><br><span>iPhone Air 2 is expected to add an ultrawide rear camera</span></div><br>The iPhone Air debuted <a href="https://appleinsider.com/articles/25/09/24/iphone-air-review-an-aspirational-iphone-that-the-pro-wont-buy">in September 2025</a> alongside the <a href="https://appleinsider.com/inside/iphone-17" title="iPhone 17" data-kpt="1">iPhone 17</a> lineup as a separate device. It <a href="https://appleinsider.com/articles/25/11/16/iphone-air-isnt-annual-iphone-air-2-was-never-coming-in-2026">seemed clear</a> at the time that Apple wouldn't be upgrading it annually, at least not at first.<br><br>The latest rumor places the second-generation iPhone Air in the spring alongside the <a href="https://appleinsider.com/inside/iphone-18" title="iPhone 18" data-kpt="1">iPhone 18</a> and iPhone 18e. Speculation already picked that timeframe due to the <a href="https://appleinsider.com/articles/25/11/16/expect-big-changes-in-iphone-release-timing-in-2026-and-2027">previously known shift</a> in <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> release schedule.<br><br><br> <strong>Rumor Score:</strong> 🤯 Likely <br><br><br> <a href="https://appleinsider.com/articles/26/06/17/iphone-air-successor-rumored-for-spring-2027-with-two-cameras?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244686?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI isn’t solving cybersecurity workforce woes]]></title>
<description><![CDATA[More than half of cybersecurity professionals say they’re thinking about leaving the industry, according to a new report. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: AI isn’t solving cybersecurity workforce woes
Read more →
The post AI isn’t solv...]]></description>
<link>https://tsecurity.de/de/3605367/it-security-nachrichten/ai-isnt-solving-cybersecurity-workforce-woes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605367/it-security-nachrichten/ai-isnt-solving-cybersecurity-workforce-woes/</guid>
<pubDate>Wed, 17 Jun 2026 17:55:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>More than half of cybersecurity professionals say they’re thinking about leaving the industry, according to a new report. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: AI isn’t solving cybersecurity workforce woes</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-isnt-solving-cybersecurity-workforce-woes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-isnt-solving-cybersecurity-workforce-woes/">AI isn’t solving cybersecurity workforce woes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT hurtles toward the ‘Great Enterprise Pricing Reset’]]></title>
<description><![CDATA[The SaaS and AI software markets have entered an era of pricing upheaval, with some new pricing models that can benefit IT leaders and some that may burn through their budgets.



The global software marketplace may be headed toward a widespread pricing reset, as AI products that compete with tra...]]></description>
<link>https://tsecurity.de/de/3601365/it-security-nachrichten/it-hurtles-toward-the-great-enterprise-pricing-reset/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601365/it-security-nachrichten/it-hurtles-toward-the-great-enterprise-pricing-reset/</guid>
<pubDate>Tue, 16 Jun 2026 12:09:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The SaaS and AI software markets have entered an era of pricing upheaval, with some new pricing models that can benefit IT leaders and some that may burn through their budgets.</p>



<p>The global software marketplace may be headed toward a widespread pricing reset, as AI products that compete with traditional SaaS offerings <a href="https://www.cio.com/article/4173257/the-saas-reckoning-why-ai-is-about-to-reprice-enterprise-software.html?utm=hybrid_search">force vendors to rethink</a> per-seat pricing, many observers say.</p>



<p>Pricing for traditional SaaS products is trending toward outcome-based billing, which is generally good news for CIOs and CFOs. At the same time, however, pricing for some AI tools, and some SaaS packages, is moving toward consumption-based billing, which can lead to huge invoice surprises if IT leaders don’t keep a close eye on employee usage.</p>



<p>CIOs should expect major pricing changes — and the need to deal with pricing uncertainty — as software vendors respond to competition and market demand, says <a href="https://www.linkedin.com/in/ramsinghaney" rel="nofollow">Sidharth Ramsinghaney</a>, director of strategy and operations at CRM data platform provider Twilio.</p>



<p>“The most immediate problem is budget volatility that most organizations have never had to manage before,” he says. “The shift transfers forecasting risk from vendor to buyer.”</p>



<p>At least 40% of enterprise SaaS spending will shift toward usage-, agent-, or outcome-based pricing by 2030, <a href="https://www.softwareseni.com/saas-pricing-is-shifting-from-per-seat-to-usage-and-outcome-what-changes-at-your-next-renewal/" rel="nofollow">Gartner has predicted</a>, with seat-based vendor revenue share declining from 21% to 15%. As recently as late 2025, however, some SaaS vendors were <a href="https://www.cio.com/article/4104365/saas-price-hikes-put-cios-budgets-in-a-bind.html?utm=hybrid_search">hiking prices</a>.</p>



<p>AI agents, in particular, have the potential to <a href="https://www.cio.com/article/4158442/ai-isnt-killing-saas-its-exposing-which-platforms-matter.html?utm=hybrid_search">disrupt pricing models</a>, Ramsinghaney says. “That projection holds if AI agents continue replacing human task execution,” he adds. “AI agents have decoupled labor from value, making per-seat pricing obsolete when one agent does work that previously required 10 employees.”</p>



<p>However, if agent adoption stalls, per-seat pricing may have more longevity than current predictions suggest, he says, and with uncertainty about the most profitable pricing model, hybrid pricing may become the default.</p>



<h2 class="wp-block-heading">Questions about outcomes</h2>



<p>Meanwhile, even though some customers have pushed for, and some vendors have experimented with, outcome-based pricing, it’s not an easy model to figure out, Ramsinghaney says.</p>



<p>“Pure outcome-based pricing stays aspirational for most categories because outcome attribution is genuinely hard to measure cleanly,” he adds.</p>



<p><a href="https://www.linkedin.com/in/jaspergeurts/" rel="nofollow">Jasper Geurts</a>, CTO at software consulting firm Software Improvement Group, agrees that outcome-based pricing is difficult to implement. Many AI vendors, for example, are combining seat-based pricing with usage, instead of focusing on outcomes, he says.</p>



<p>Vendors will continue to experiment with outcome- and usage-based models, but there’s an ongoing debate over what counts as an outcome, he notes.</p>



<p> “An agent can pass every acceptance test and still produce code nobody can safely evolve,” he explains. “If you pay only for functional outcomes, you are paying vendors to create technical debt.”</p>



<p>While some SaaS vendors look at outcome-based or hybrid pricing models, it’s a different story with AI vendors, Geurts says. The cost for frontier AI models is going up, not down, with Anthropic’s new Fable 5 model <a href="https://decrypt.co/370688/internet-furious-anthropic-claude-mythos-fable-5" rel="nofollow">costing double</a> the per-token price of Opus 4.8, he notes.</p>



<p>“CIOs tell me the token economy is opaque,” he says. “You cannot forecast a bill when agents decide how many tokens to burn. CIOs should treat tokens like cloud spend a decade ago: Meter it, govern it, tie it to outcomes.”</p>



<p>Still, token pricing isn’t fixed, with both OpenAI and Anthropic <a href="https://finance.yahoo.com/markets/stocks/articles/openai-anthropic-cutting-token-prices-034031580.html" rel="nofollow">considering price cuts</a> to better compete against each other as <a href="https://www.cio.com/article/4181090/what-anthropic-and-openai-ipos-spell-for-cios-ai-budgets.html">both move toward IPOs</a>.</p>



<p>This pricing upheaval creates new headaches for IT leaders, Geurts says. Spending becomes harder to predict, and the outputs harder to control.</p>



<p>“Per-seat pricing capped the bill at headcount,” he adds. “Usage pricing scales with consumption, and as AI moves from assistants to autonomous coding, code volume outgrows what any architecture team can review. The code itself is a liability you keep paying for.”</p>



<p>At the same time that token usage pricing has increased, <a href="https://www.lorka.ai/knowledge-hub/ai-tool-pricing-subscription-costs" rel="nofollow">subscription pricing for AI tools</a> has risen as well, according to a study from Lorka AI, provider of an AI-based writing and research tool.</p>



<p>AI tools that were free or low cost in 2023 now average between $20 and $30 per employee per month, with some premium AI tiers now reaching $200 per month, Lorka AI says. Some enterprises using several AI tools are now spending more than $1,200 per year per employee, often with overlapping functionality between products, according to the company.</p>



<h2 class="wp-block-heading">Vigilance needed</h2>



<p>All of this pricing uncertainty means that IT leaders need to be extra vigilant about software costs, experts say.</p>



<p>CIOs will need to pay close attention to both how services are procured and how much they are used, says <a href="https://innowise.com/authors/maksim-hodar/" rel="nofollow">Maksim Hodar</a>, CIO at software development firm Innowise. CIOs should pay attention to usage analytics so that they can identify cost control measures and determine which pricing model best suits their business cases, he recommends.</p>



<p>CIOs should also conduct pilot programs before scaling the use of new software with new pricing models, he suggests.</p>



<p>“CIO success depends upon your ability to choose a service’s pricing model based on your business process, risk profile, and expected value associated with the service,” he says. “It’s easy to become overwhelmed by trends in the industry and simply go with what everybody else is doing.”</p>



<p>Hodar expects several different pricing models to hang on, with the predictability of per-seat pricing and the flexibility and scalability of usage-based pricing keeping both models around. Outcome-based pricing will also emerge as an alternative as long as vendors and customers can measure the outputs, he predicts.</p>



<p>IT leaders who haven’t yet embraced <a href="https://www.cio.com/article/416337/what-is-finops-your-guide-to-cloud-cost-management.html">FinOps practices</a> should now do so, adds Twilio’s Ramsinghaney. CIOs should track token and other usage to verify that features deliver more value than they cost, he recommends.</p>



<p>Those enterprises moving to outcome-based pricing models should enter explicit outcome measurement agreements with software and platform providers, he adds. “Attribution disputes are where these contracts fall apart,” he says. “Outcome-based pricing only scales where both parties can agree on attribution, and in complex enterprise environments where multiple factors drive results, that clean attribution often doesn’t exist.”</p>



<p>Like others, Ramsinghaney sees room for multiple pricing models going forward. Usage-based pricing works for infrastructure and API-first products where buyers build their own applications, while outcome-based pricing wins where results are cleanly measurable, such as resolved support tickets or completed workflows.</p>



<p>“Hybrid wins as the dominant model rather than either pure form, because it balances vendor revenue predictability with buyer cost alignment,” he adds.</p>



<p>Some per-seat pricing will survive as well, he says, but its use will shrink to situations where humans remain the primary users and value is closely tied to headcount.</p>



<p>“Per-seat persists for collaboration tools and applications where software augments human work, rather than replacing it,” Ramsinghaney says. “The misalignment only becomes acute when AI agents start acting as users that don’t occupy seats.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft reveals Windows 11’s Media Player isn’t dead, but Legacy still opens videos instantly]]></title>
<description><![CDATA[Microsoft confirmed that Media Player has never stopped being developed, and the June Insider builds bring a fresh round of bug fixes. But the app still takes a few seconds to load a video that Legacy opens instantly, idles at 377 MB of RAM, and locks HEVC playback behind a $0.99 purchase.
The po...]]></description>
<link>https://tsecurity.de/de/3600383/windows-tipps/microsoft-reveals-windows-11s-media-player-isnt-dead-but-legacy-still-opens-videos-instantly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600383/windows-tipps/microsoft-reveals-windows-11s-media-player-isnt-dead-but-legacy-still-opens-videos-instantly/</guid>
<pubDate>Tue, 16 Jun 2026 01:42:53 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft confirmed that Media Player has never stopped being developed, and the June Insider builds bring a fresh round of bug fixes. But the app still takes a few seconds to load a video that Legacy opens instantly, idles at 377 MB of RAM, and locks HEVC playback behind a $0.99 purchase.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/06/16/microsoft-reveals-windows-11s-media-player-isnt-dead-but-legacy-still-opens-videos-instantly/">Microsoft reveals Windows 11’s Media Player isn’t dead, but Legacy still opens videos instantly</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GM Updates 250,000 EVs with Vehicle-to-Grid Firmware, Announces Grid-Scale Sodium-Ion Batteries]]></title>
<description><![CDATA["Battery breakthroughs will lessen AI's demand on the electricity grid," argues The Washington Post's editoral board, arguing that GM's latest moves "offer a fresh reminder that resource constraints can be solved by innovation." 

Or As Fortune put it, "America's electric grid is buckling under e...]]></description>
<link>https://tsecurity.de/de/3596172/it-security-nachrichten/gm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596172/it-security-nachrichten/gm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries/</guid>
<pubDate>Sat, 13 Jun 2026 22:50:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Battery breakthroughs will lessen AI's demand on the electricity grid," argues The Washington Post's editoral board, arguing that GM's latest moves "offer a fresh reminder that resource constraints can be solved by innovation." 

Or As Fortune put it, "America's electric grid is buckling under extreme weather, aging infrastructure, and an AI build-out that is quietly rewriting U.S. power demand — and General Motors wants to turn that crisis into a business." They describe GM's plan as offering itself "as a distributed utility in disguise... stitching together hundreds of thousands of battery-powered cars, new grid-scale storage, and a unified charging platform into what amounts to a virtual fleet of power plants."

 The bet puts GM on a collision course with Ford's newly branded Ford Energy unit as both Detroit rivals race to repurpose underused EV capacity for a more urgent problem: keeping the lights on in the AI era. GM's case rests on three planks. The first is its existing fleet. GM says more than 250,000 of its EVs on U.S. roads can already charge bidirectionally — pulling electricity from the grid and sending it back. "Every evening, a quiet transformation occurs across the American landscape," GM Energy vice president Wade Sheffer writes in an open letter to utilities and regulators, describing the EVs sitting in driveways as "a massive opportunity to aggregate energy storage capacity." 

 A firmware update is rolling out to customers with GM Energy's vehicle-to-home hardware, converting those systems into full vehicle-to-grid assets with no new hardware and turning home backup systems into grid resources when utilities need them. GM is piloting the idea in Michigan with DTE Energy at 30 employee homes, and has sketched a 2030 vision with Pacific Gas &amp; Electric in which more than 52,000 GM EVs help balance the grid out of a projected 130,000 vehicles in the area. 

GM is also "seeking partnerships with utility companies nationwide to assist in offering such vehicle-to-grid services for customers," reports CNBC, noting it's one of two moves "meant to address concerns about rising energy costs amid an artificial intelligence boom." 


 Forbes reports that GM's second goal "is to leapfrog the dominant battery cell tech used for energy storage packs right now" — right past the LFP (lithium-iron phosphate) stage, "which is dominated by China."

 Sodium batteries are cheaper to use than LFP because they don't need an additional cooling system. They also have a 20-year usable life and are made from materials that can be sourced from within the U.S., the company said at a briefing in San Francisco on Tuesday.
"Sodium-ion actually is the better chemistry for that application. And when I say sodium-ion is better, I mean GM's version of sodium-ion," Kurt Kelty, GM's battery chief and a long-time Tesla battery executive, told Forbes. He said GM is seeing great results from its prototypes, even at scorching temperatures of 55 Celsius (131 Fahrenheit). 

 "Sodium-ion-powered energy storage systems have the potential to operate without active cooling and with much less system complexity," Kurt Kelty, GM's vice president of battery and sustainability, said Tuesday in a blog post. "In large energy storage systems, that matters." Not having to cool the battery cells could lead to lower upfront costs as well as operating costs, the automaker said. 

TechCrunch reports on GM's big new partnership with energy-storage startup Peak Energy to develop GM's sodium-ion battery chemistry for grid-scale deployments:
GM wouldn't share with TechCrunch how much money it is investing in this energy-storage effort. But we do know the company has committed $900 million to commercialize new battery chemistries, an investment that includes a new battery-development center. .. The first GM cells are expected to enter trial production at the company's Battery Cell Development Center in 2028. 

"Our next-generation sodium-ion cell development will drive energy density higher," promises GM's blog post, arguing they're extending the company's battery expertise and technical infrastructure "into the electrical grid itself. If we get this right, we will not just build better batteries. We will help create a more resilient, more affordable and more flexible energy future... Every improvement we make strengthens the development stack that supports both EVs and energy storage." 

"The message: GM isn't just selling cars into a stressed grid; it's supplying the batteries to stabilize it," argues Fortune. 


And GM also announced they're augmenting their apps with an "Energy Pass" offering "seamless access to Tesla Supercharger, IONNA, Electrify America, and soon, ChargePoint and EVgo networks." Their goal is to simplify the charging experience with an app "that covers nearly 70% of all DC fast chargers in the United States, plus many Level 2 chargers, all through one app."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=GM+Updates+250%2C000+EVs+with+Vehicle-to-Grid+Firmware%2C+Announces+Grid-Scale+Sodium-Ion+Batteries%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F13%2F0224235%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F13%2F0224235%2Fgm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/13/0224235/gm-updates-250000-evs-with-vehicle-to-grid-firmware-announces-grid-scale-sodium-ion-batteries?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pen Testing Once a Year Isn’t Enough: Why SMEs Need Pentesting as a Service]]></title>
<description><![CDATA[Image Credit: Designed by Magnific Learn More/… Latest Posts from SECURUS Communications FIREWALLS SMECYBERIINSIGHTS Do...
The post Pen Testing Once a Year Isn’t Enough: Why SMEs Need Pentesting as a Service appeared first on SME Cybersecurity News | SMECYBERInsights.co.uk.]]></description>
<link>https://tsecurity.de/de/3593092/it-security-nachrichten/pen-testing-once-a-year-isnt-enough-why-smes-need-pentesting-as-a-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593092/it-security-nachrichten/pen-testing-once-a-year-isnt-enough-why-smes-need-pentesting-as-a-service/</guid>
<pubDate>Fri, 12 Jun 2026 12:12:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="150" height="150" src="https://smecyberinsights.co.uk/wp-content/uploads/2026/06/close-up-hands-typing-keyboard-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="Pen Testing Once a Year Isn’t Enough: Why SMEs Need Pentesting as a Service" decoding="async" loading="lazy">Image Credit: Designed by Magnific Learn More/… Latest Posts from SECURUS Communications FIREWALLS SMECYBERIINSIGHTS Do...</p>
<p>The post <a rel="nofollow" href="https://smecyberinsights.co.uk/index.php/2026/06/12/pen-testing-once-a-year-isnt-enough/">Pen Testing Once a Year Isn’t Enough: Why SMEs Need Pentesting as a Service</a> appeared first on <a rel="nofollow" href="https://smecyberinsights.co.uk/">SME Cybersecurity News | SMECYBERInsights.co.uk</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why CIOs should reopen the build vs. buy question]]></title>
<description><![CDATA[Many companies are still buying software for workflows that define how they compete. That used to be a rational way to control costs and reduce risk. Increasingly, though, it’s becoming a quiet way to standardize away differentiation.



For most of the last 20 years, the CIO’s answer to build ve...]]></description>
<link>https://tsecurity.de/de/3593059/it-nachrichten/why-cios-should-reopen-the-build-vs-buy-question/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593059/it-nachrichten/why-cios-should-reopen-the-build-vs-buy-question/</guid>
<pubDate>Fri, 12 Jun 2026 12:04:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many companies are still buying software for workflows that define how they compete. That used to be a rational way to control costs and reduce risk. Increasingly, though, it’s becoming a quiet way to standardize away differentiation.</p>



<p>For most of the last 20 years, the CIO’s answer to build versus buy was clear: unless you’re a software company, don’t build. Buy a SaaS product, integrate it into the stack, and reserve scarce engineering capacity for the few places where custom work is unavoidable. That advice was rational. It protected companies from fragile custom systems, undocumented dependencies, runaway maintenance costs, and the shadow applications that later became operational liabilities.</p>



<p>But defaults age. When they do, leaders often continue defending them long after the conditions that made them useful have changed. The buy-default is reaching that point. The case for buy hasn’t disappeared, but its status as the automatic default has, and the CIO who continues to default to buy without revisiting why is no longer protecting the business from risk but protecting an assumption that’s quietly stopped being load-bearing.</p>



<h2 class="wp-block-heading">What changed</h2>



<p>Three shifts have moved the math, and the technology side of each one gets the headlines. The business consequence is the part the CIO must act on.</p>



<p>The first shift is cost. AI-assisted development has compressed the time from idea to working software from quarters to weeks, and in some cases prototypes that once required a formal six-figure engagement can now be produced by a small team in a sprint, or by a capable operator over a weekend. Productivity surveys of AI-assisted developers put the gain in the 70 to 90 percent range on routine engineering tasks, and several large technology firms now report that AI-generated code accounts for up to 40% of new commits. The business consequence is that workflows previously too expensive to customize are now economically viable. The custom build is no longer reserved for the few capabilities the business can’t live without. It’s available, in principle, for any capability where the off-the-shelf product forces a meaningful compromise.</p>



<p>The second is who can build. The <a href="https://www.cio.com/article/4136302/how-to-get-ai-democratization-right.html?utm=hybrid_search">democratization</a> of software development is no longer a category of marketing slide. Gartner has been writing for years about fusion teams and the rise of business-side technologists, and the AI generation of coding tools has accelerated that trajectory beyond what most enterprise architecture functions are tracking.</p>



<p>Recent usage data on AI-assisted coding platforms suggest that roughly 65% of users don’t come from a developer background. They sit in operations, marketing, and finance, and they increasingly produce working internal applications, not just demos or toys. The business consequence is that <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html?utm=hybrid_search">build decisions</a> will happen whether CIOs govern them or not. The CIO who assumes building still requires hiring a software team is operating on a labor market description that no longer matches reality, and is also operating on the assumption that the build-or-no-build decision still sits inside IT. It doesn’t.</p>



<p>The third shift is what gets exposed. The traditional reasons custom builds failed haven’t vanished. Authentication, scalability, recoverability, security, and maintainability are still real engineering disciplines, and they still consume real effort. What’s changed is they’re increasingly available as managed services, embedded primitives, or platform features.</p>



<p>Authentication can be subcontracted to a specialist provider. Compliance-aware data storage can be procured on a credit card. Documentation can be generated alongside the code it documents. The business consequence is that the risk has shifted from can we build it to can we govern what we build. That’s a different question, and most organizations aren’t yet structured to answer it.</p>



<p>The combination of those three shifts has done something the industry hasn’t fully digested yet: not eliminating the case for buy but eliminating the case for buy as automatic default.</p>



<h2 class="wp-block-heading">Where the case for build now holds</h2>



<p>This isn’t an argument that organizations should now build everything. The places where buy was the right answer for so many years remain the places where it’s still the right answer today.</p>



<p>For commodity workflows, accounting, payroll, calendaring, document storage, identity management, and the common operations of any business, the <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html?utm=hybrid_search">SaaS market</a> wins decisively. The advantage of building these is small, the cost of maintaining them is real, and the supply of mature products is strong. CIOs are still correct to push back when a business unit proposes building its own ERP. That hasn’t changed, and it won’t.</p>



<p>What has changed is the second category — the workflows that aren’t commodity, the processes that distinguish the business from its competitors, and the operating model details that get bent around the limitations of off-the-shelf systems because no vendor has built a product that matches the actual shape of the work.</p>



<p>In that category, buying has always been a compromise. CIOs accepted the compromise because the alternative was building, and building was unaffordable. With the cost of building no longer prohibitive, that compromise becomes a deliberate choice rather than an unavoidable one. In the workflows where the business is supposed to be different from its competitors, accepting a vendor’s idea of how the work should be done isn’t a neutral position but a slow erosion of the differentiation the business is presumably trying to defend.</p>



<p>The CIO’s job is also to tell the difference between these requests, where buy still wins and the buy-default ones are now obstacles to the business’s competitive position.</p>



<p>This can’t become another category of decisions quietly delegated to IT. If a workflow defines how the business competes, the accountable owner must be the business leader who owns that capability. The CIO should own the architecture, guardrails, risk model, and integration logic, and the business should own the value, adoption, and operating consequences. When that split isn’t explicit, accountability disappears, and the build-versus-buy decision becomes another technology argument with business consequences no one owns.</p>



<h2 class="wp-block-heading">The risks have moved, not disappeared.</h2>



<p>It’d be irresponsible to write this without naming what hasn’t changed. Custom builds still fail when the people building them ignore non-functional requirements. Independent security reviews of AI-generated code report basic failure rates approaching half of the samples examined, with leaked secrets, hardcoded credentials, and misconfigured access controls turning up routinely when the builder isn’t a security practitioner.</p>



<p>Citizen developers still produce systems that look like they work and turn out to be ungoverned, undocumented, and unmaintainable. <a href="https://www.cio.com/article/4120070/how-learning-enterprises-compete.html?utm=hybrid_search">The single-point-of-failure problem</a>, where the entire build lives in the head of one person who eventually leaves, isn’t theoretical. Most CIOs have either inherited a build like that or watched a peer do so. The reflexes that produced the buy-default aren’t arbitrary, they’re scar tissue.</p>



<p>The shift isn’t that those risks have disappeared. It’s where they sit within the decision’s architecture. They used to live in the column labelled “reasons not to start.” They now live in the “things to design for if you do” column. That’s a different conversation that requires a <a href="https://www.cio.com/article/4126383/how-the-growing-ai-workforce-is-changing-the-cio-role.html?utm=hybrid_search">different role from the CIO</a> than the one most of us were trained for.</p>



<p>In the previous era, the CIO’s value-add was largely defensive. Stop the bad build before it starts. Push the business toward the vendor that the company can hold accountable. Maintain the standardization that makes the environment sustainable. That work still matters, but it’s no longer sufficient.</p>



<p>The new value is architecture, not gatekeeping. It’s the ability to look at a workflow and tell the business whether buying it commoditizes a real differentiator, whether building it is operationally sustainable, what the maturity prerequisites are, and where the build needs to sit relative to the rest of the stack. It’s also the ability to govern <a href="https://www.cio.com/article/475444/democratizing-automation-with-citizen-developers-navigating-the-pitfalls-and-opportunities.html?utm=hybrid_search">citizen development</a> without trying to suppress it, because suppression is no longer a viable strategy. Business users will build with or without IT’s blessing and the CIO who makes that an adversarial relationship loses both the build and the governance.</p>



<h2 class="wp-block-heading">What this asks of the CIO function</h2>



<p>If the build-versus-buy question is no longer settled, the CIO role can’t remain settled either. So, a few things follow.</p>



<p>Architecture must come back to the center of the role. Not <a href="https://www.cio.com/article/4119297/how-to-get-your-enterprise-architecture-ready-for-agentic-ai.html?utm=hybrid_search">enterprise architecture</a> as the bureaucratic ritual it became in many organizations, but as the discipline of deciding which capabilities the business builds, buys, and how the two compose into something coherent. That work can’t be delegated to vendors or business units, both of whom have legitimate but partial views of the question.</p>



<p>Governance of citizen development becomes a real responsibility, not a residual one. The CIO who pretends business users aren’t building loses visibility into a category of growing risk. The CIO who entirely shuts down citizen development loses the ability to capture the value it can produce. The middle path of frameworks, sandboxes, security primitives, and lightweight standards, is harder to design and run than either extreme, and it’s now part of the job.</p>



<p>Talent strategy has to update. The CIO function has been hiring against a labor market that assumed a sharp line between business users and software developers. That line has become a gradient. Hiring needs to follow.</p>



<p>Most importantly, the CIO needs to be willing to retire advice that’s become reflex. The buy-default served the field well for a long time. The unwillingness to revisit it serves the field poorly now.</p>



<p>So the build-versus-buy question isn’t really about software but about which capabilities the business must control, which it can safely consume, and who owns the consequences when that choice proves wrong. The old default protected organizations from one kind of risk. Leaving it unexamined now creates another.</p>



<p>The economics have shifted and the default shouldn’t survive unexamined. The better question is no longer whether responsible CIOs should build or buy but whether they know which business capabilities are too important to leave to a vendor’s operating model.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Vision Pro's biggest problem isn't addressed in visionOS 27, but progress is progress]]></title>
<description><![CDATA[In spite of the AI-heavy WWDC, Apple Vision Pro still got plenty of attention with visionOS 27. Here's what Apple got right and where it still needs work.Apple Vision Pro gets another great update with visionOS 27I've been asked to provide my first impressions of visionOS 27, and honestly, I thin...]]></description>
<link>https://tsecurity.de/de/3590596/ios-mac-os/apple-vision-pros-biggest-problem-isnt-addressed-in-visionos-27-but-progress-is-progress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590596/ios-mac-os/apple-vision-pros-biggest-problem-isnt-addressed-in-visionos-27-but-progress-is-progress/</guid>
<pubDate>Thu, 11 Jun 2026 14:54:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In spite of the AI-heavy WWDC, Apple Vision Pro still got plenty of attention with <a href="https://appleinsider.com/inside/visionos-27" title="visionOS 27" data-kpt="1">visionOS 27</a>. Here's what Apple got right and where it still needs work.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67903-143177-Apple-Vision-Pro-M5-keyboard-table-xl.jpg" alt="Apple Vision Pro on a table by a mechanical keyboard and a Magic Trackpad in dramatic lighting" height="738"><br><span>Apple Vision Pro gets another great update with visionOS 27</span></div><br>I've been asked to provide my first impressions of visionOS 27, and honestly, I think it's a good release. The quality-of-life work continues in this release alongside some really interesting new features.<br><br>There was <a href="https://appleinsider.com/articles/26/05/10/not-dead-yet-apple-vision-still-has-a-future">some talk</a> about Apple basically abandoning <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro</a>. However, visionOS 27 proves that it is a platform Apple is interested in developing, even if new hardware is <a href="https://appleinsider.com/articles/26/05/31/slimmer-lighter-apple-vision-pro-is-at-least-two-years-away">years away</a>.<br><br><br> <a href="https://appleinsider.com/articles/26/06/11/apple-vision-pros-biggest-problem-isnt-addressed-in-visionos-27-but-progress-is-progress?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244628?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data lakehouses now a backbone for enterprise analytics and AI]]></title>
<description><![CDATA[The need for a central data repository for enterprise analytics and gen AI has made the data lakehouse the default choice for enterprise data. Meanwhile, the emergence of open table standards makes the shift easier and reduces vendor lock-in for enterprises while also allowing for better integrat...]]></description>
<link>https://tsecurity.de/de/3581044/it-security-nachrichten/data-lakehouses-now-a-backbone-for-enterprise-analytics-and-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581044/it-security-nachrichten/data-lakehouses-now-a-backbone-for-enterprise-analytics-and-ai/</guid>
<pubDate>Mon, 08 Jun 2026 12:06:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The need for a central data repository for enterprise analytics and gen AI has made the data lakehouse the default choice for enterprise data. Meanwhile, the emergence of open table standards makes the shift easier and reduces vendor lock-in for enterprises while also allowing for better integration between lakehouses and other enterprise systems and service providers.</p>



<p><a href="https://www.cio.com/article/4104444/8-tips-for-rebuilding-an-ai-ready-data-strategy.html?utm=hybrid_search">Data lakehouses</a> combine the structure of data warehouses with the flexibility of data lakes, making them versatile tools to make the most of any data the enterprise collects, whether it’s for business analytics, integration with other systems, or providing relevant context to LLMs.</p>



<p>The idea behind the data lakehouse is to merge together the best of what data lakes and data warehouses have to offer, says Gartner analyst Adam Ronthal.</p>



<p>Data warehouses also enable companies to store large amounts of structured data with well-defined schemas, as they’re designed to support a large number of simultaneous queries and deliver results quickly to many simultaneous users.</p>



<p>Data lakes, on the other hand, enable companies to collect raw, unstructured data in many formats for data analysts to hunt through. These vast pools of data have recently grown in prominence thanks to the flexibility they provide enterprises to store massive data streams without first having to define the purpose of doing so. </p>



<p><a href="https://www.gartner.com/en/documents/6674234" rel="nofollow">According to Gartner</a>, data lakehouses are the next step in the evolution of data architectures, merging these two capabilities into a single platform to overcome limitations of previous architectures, reducing complexity, streamlining <a href="https://www.cio.com/article/4117094/data-management-trends-whats-in-whats-out.html?utm=hybrid_search">data management</a>, and supporting diverse workloads.</p>



<p>In late 2025, Gartner also released the first market guide for data lakehouse platforms. “The lakehouse is now firmly established as the architecture that most organizations will seek to standardize on,” wrote Ronthal and his co-authors in the report.</p>



<p>Meanwhile, data lakehouses themselves are also standardizing on the Apache Iceberg data table format, first created by Netflix in 2017, and donated to the Apache Software Foundation the following year. It hit the tipping point in 2024 with adoption by companies like Apple, LinkedIn, Adobe, and all the major cloud vendors. Even Databricks, which created the competing Delta Lake standard, now supports Iceberg natively.</p>



<p>Lakehouse vendors are opening their architecture more to allow better access to the data by third parties, says Gerry Szatvanyi, chief AI officer at consulting firm OSF Digital. “That wasn’t the case a few years ago,” he says.</p>



<p>And other enterprise service providers have been taking advantage of this, he says. For example, Salesforce Data Cloud can connect directly to Iceberg-formatted data.</p>



<p>“Salesforce has a Zero Copy access format, so it can connect its own data platform to another data lake without copying data into Salesforce,” says Szatvanyi.</p>



<p>And of course, as with everything else in the enterprise today, gen AI is having a big effect. Data lakehouses are particularly good for LLMs because they can provide critical business context for RAG embeddings and MCP access, the two most common ways to feed data into LLMs.</p>



<p>“Lakehouses are being accessed more by AI agents,” Szatvanyi says. “It’s the main thing I see happening.”</p>



<p>Even traditional business analytics is now increasingly handled via AI interfaces, he adds, democratizing user access to enterprise data.</p>



<p>In a recent <a href="https://mfe-prod.idc.com/getdoc.jsp?containerId=US52974125" rel="nofollow">IDC report</a>, the leading vendors in the data platform space are Databricks, Google, Oracle, and Snowflake, with other major players including Microsoft, IBM, and Cloudera. IDC also listed Amazon SageMaker as a lakehouse platform to watch, but it only became widely available in early 2025, so wasn’t yet included among the top vendors.</p>



<p>Gartner includes Databricks, Google, Oracle, Snowflake, Microsoft, IBM, Cloudera and Amazon SageMaker on its list of representative vendors for data lakehouse platforms, among other firms.</p>



<h2 class="wp-block-heading">The business benefits of data lakehouses</h2>



<p>Docusign opted to go with Snowflake for the data platform used to train an internal agent for sales, and is training its ML models in order to serve customers more accurately. Information is pulled from Salesforce, and they’re also exploring Atlassian and ServiceNow, as well as other internal custom tools.</p>



<p>The information also goes out to LLMs using RAG embedding pipelines, and MCP connectivity is also being explored as the technology matures.</p>



<p>Other companies use data lakehouses for the flexibility of the data sources it supports and the volume of data they can handle.</p>



<p>Sega Europe, for example, began using the Amazon Redshift data warehouse to collect event data from its Football Manager video game back in 2016. At first this event, data consisted simply of players opening and closing games.</p>



<p>“But there was so much more data we could collect,” says Felix Baker, the company’s head of data services. “Like what teams people were managing, or how much money they were spending.”</p>



<p>Because of the data structures needed for inclusion in the data warehouse, data was coming in batches and it took too much time to analyze.</p>



<p>“We wanted to analyze the data in real-time,” Baker adds, but this functionality wasn’t available in Redshift at the time. “Databricks offered an out-of-the-box managed services solution that did what we needed without us having to develop anything,” he adds. In addition, the data lakehouse architecture enabled Sega Europe to ingest unstructured data, such as social media feeds.</p>



<p>The cost efficiencies enabled by providing a source for all of an organization’s structured and unstructured data is a value driver for data lakehouses, says Steven Karan, AI transformation lead at Capgemini, and it’s helped implement data lakehouses at leading organizations in financial services, telecom, and retail.</p>



<p>Moreover, data lakehouses store data in a way that it’s readily available for use by a wide array of technologies, from traditional business intelligence and reporting systems to ML and AI. “Other benefits include reduced data redundancy, simplified IT operations, a simplified data schema to manage, and easier to enable data governance,” Karan says.</p>



<h2 class="wp-block-heading">Helping data emerge</h2>



<p>One particularly valuable use case for data lakehouses is in helping companies get value from <a href="https://www.cio.com/article/4168669/7-signs-your-data-isnt-ready-for-ai.html?utm=hybrid_search">data previously trapped in legacy or siloed systems</a>. For example, one Capgemini enterprise customer, which had grown through acquisitions over a decade, couldn’t access data related to resellers of their products.</p>



<p>“By migrating the siloed data from legacy data warehouses into a centralized data lakehouse, the client could understand at an enterprise level which of their reseller partners were most effective, and how changes such as referral programs and structures drove revenue,” he says.</p>



<p>One company capitalizing on the benefits of data lakehouses is life sciences, analytics, and services company IQVIA, which began using data lakehouses several years ago.</p>



<p>Before the pandemic, pharmaceutical companies running drug trials used to send employees to hospitals and other sites to collect data about things such as adverse effects, says Wendy Morahan, senior director of product management for clinical data analytics at IQVIA. “That’s how they make sure the patient is safe.”</p>



<p>Once the pandemic hit and sites were locked down, however, pharmaceutical companies had to scramble to figure out how to get the data they needed — and to get it in a way that was compliant with regulations, and fast enough to enable them to quickly spot potential problems.</p>



<p>Snowflake and Databricks gave the company the ability to store the raw data in any format, including images and audio, all in a single platform.</p>



<h2 class="wp-block-heading">Lakehouse adoption growth</h2>



<p>In <a href="https://www.researchandmarkets.com/reports/6075267/data-lakehouse-market-report" rel="nofollow">a February report</a> from Research and Markets, the data lakehouse market has been growing exponentially.</p>



<p>In 2025, it totaled $10.3 billion and is predicted to hit $12.6 billion by the end of this year, a compound growth rate of 22%. By 2030, this will be up to $27.3 billion, the research firm projects.</p>



<p>And according to a recent survey from Dremio, a lakehouse vendor, 63% of companies run most analytics on a lakehouse rather than a traditional warehouse, up from 55% in 2024.</p>



<p>Data lakehouses are also increasingly being used for IT and security workloads, says Ed Bailey, field CISO at telemetry vendor Cribl. “Previously, lakehouse providers were the realm of business data with a focus on structured data and SQL.”</p>



<p>Lakehouses can handle IT and security data at a lower cost, and this is a critical issue given the volumes of data in this space. “Even mid-sized companies produce much more IT and security data than business data,” he says. “Lakehouse vendors are finally starting to push into the market.”</p>



<p>But it’s still early, and initial solutions are immature and an awkward fit for this kind of data. “IT and security data are very different from business data,” he adds. For example, business data tends to be more predictable and well-structured. Plus, business users are more familiar with using data analytics tools than IT and security users. “This mismatch has been a serious obstacle to adoption,” he says.</p>



<p>Data lakehouses are also evolving in another way. Gartner says the lakehouse isn’t the ultimate solution but a transitional architecture on the way to more advanced systems, such as data fabric. The difference between the two is data lakehouses contain data from disparate systems, while data fabrics simply contain pointers to where the data is natively located.</p>



<p>An advantage of data fabrics is that the original security access controls and metadata are preserved and used, there’s no duplication of data, and no need to reconcile disparate standards.</p>



<p>“But it comes with some performance issues, and access isn’t that seamless,” says OSF Digital’s Szatvanyi.</p>



<p>A data fabric might be a good place for smaller companies to start, he says, or you can use both. “You can have a big chunk of data in a lakehouse and have a fabric for two or three secondary systems,” he says. “But I’d say the data lakehouse is the gold standard.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Making sense of too much code]]></title>
<description><![CDATA[Anyone can build an app now. But nobody seems to care.



Well, not nobody. VCs keep funding startups that add AI to, well, everything. But users aren’t buying the massive influx of new apps. In a chart shared by Jen Zhu Scott based on the new National Bureau of Economic Research’s working paper ...]]></description>
<link>https://tsecurity.de/de/3580892/ai-nachrichten/making-sense-of-too-much-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580892/ai-nachrichten/making-sense-of-too-much-code/</guid>
<pubDate>Mon, 08 Jun 2026 11:03:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anyone can build an app now. But nobody seems to care.</p>



<p>Well, not <em>nobody</em>. VCs keep funding startups that add AI to, well, everything. But users aren’t buying the massive influx of new apps. In a chart <a href="https://x.com/jenzhuscott/status/2063032701087883647">shared by Jen Zhu Scott</a> based on the new National Bureau of Economic Research’s working paper “<a href="https://www.nber.org/papers/w35275">Writing Code vs. Shipping Code</a>,” iOS app releases have exploded since the advent of agentic AI. That would perhaps be cause for celebration had app reviews not declined during this same period, and apps with significant usage have stayed essentially flat.</p>



<p>In other words, more apps but almost nobody new showing up to use them.</p>



<p>For those of us that grew up in <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a>, it’s a familiar problem. The greater the abundance of code, the greater the need to help would-be customers navigate it through marketing (including branding), sales, etc. AI is creating so much noise, in terms of new code, new products, etc., that the real work has shifted to taste-making.</p>



<h2 class="wp-block-heading"><a></a>Getting more but not using more</h2>



<p>I’ve been <a href="https://www.infoworld.com/article/4125409/ai-will-not-save-developer-productivity.html">saying for a while</a> that developer productivity isn’t about producing more code faster. Or at least it shouldn’t be. Productivity is about producing well-architected, secure, maintainable code that solves a problem someone actually has.</p>



<p>That’s a very different thing. It’s not something AI can fix; at least, not yet.</p>



<p>Charity Majors put it more bluntly in a post <a href="https://www.infoworld.com/article/3509197/junior-developers-and-ai.html">I wrote in 2024</a>: “Writing code is the easiest part of software engineering,” she said. The harder parts are figuring out what to build, integrating it into a larger system, validating that it works, maintaining it over time, and getting humans to trust it enough to use it.</p>



<p>Turns out the harder parts are really hard. <a href="https://www.nber.org/papers/w35275">Mert Demirer, Leon Musolff, and Liyuan Yang</a> tracked more than 100,000 GitHub developers alongside their AI usage telemetry. Autocomplete, interactive agents, and autonomous agents each ramped raw coding activity, with cumulative effects on commits of 40%, 140%, and 180%. That sounds great until you look how the gains attenuate the closer you get to actual users. For example, that 180% jump in commits became roughly 50% more projects and just 30% more actual releases. The report’s authors call this the weak-link problem: The strong link (writing code) got much stronger, while the weak links (everything else humans have to do) didn’t. The estimated elasticity of substitution between AI and human effort is 0.25, which is economist for “these complement each other, but they don’t replace each other.”</p>



<p>When the authors checked four major app marketplaces, they found a bump in new apps but no increase in total usage. In other words, we’re getting better at creating things with AI’s help; apparently we’re not good at turning that into user interest. User attention (and budget) is finite. The hard part is to figure out how to get users to care enough to pay (with their time or their money).</p>



<h2 class="wp-block-heading"><a></a>Learning to love marketing</h2>



<p>So what’s actually scarce in a world of near-infinite software? Not code, for sure. No, what’s scarce is attention, trust, and a reason to switch.</p>



<p>That means the durable advantages in software increasingly live in the parts of the business developers often undervalue, like a recognizable brand (something that Red Hat figured out early on in open source) or a channel they already use. Or it could be in areas that developers appreciate but don’t pay for, like good documentation or a welcoming community.</p>



<p>This isn’t a new idea; it’s just newly unavoidable. We’re watching something similar inside enterprises, where <a href="https://www.infoworld.com/article/4151572/the-starkly-uneven-reality-of-enterprise-ai-adoption.html">AI adoption is</a><a href="https://www.infoworld.com/article/4151572/the-starkly-uneven-reality-of-enterprise-ai-adoption.html"> </a>wildly uneven, not because the technology has no value, but because the organizational plumbing around it often hasn’t been built. This is why a new kind of speed is important. I once<a href="https://www.infoworld.com/article/3611644/speed-is-the-killer-app.html"> argued that speed was the killer app</a>, and that was mostly true. Today the more interesting speed is how quickly you can earn trust, fit into a workflow, answer objections, and get adopted.</p>



<p>Years ago I wrote that<a href="https://www.techrepublic.com/article/rethinkdb-is-dead-and-mongodb-isnt-what-killed-it/"> RethinkDB was dead and MongoDB wasn’t what killed it</a>. RethinkDB was at the time, by many technical measures, a better database, built around “correctness, simplicity, and consistency.” It still lost—and badly. <a href="https://gist.github.com/ramalho/93b87e961b6e019be8e1f6f82864b6f9">Its founder’s own postmortem</a> was unsparing: They had picked a brutal market and tuned the product to the wrong definition of good. Being technically right turned out to have almost nothing to do with getting adopted.</p>



<p>With AI we’re generating a thousand smaller “RethinkDBs,” only faster and with nicer landing pages generated by the same model that wrote the code. These aren’t going to win, any more than RethinkDB was able to unseat MongoDB. It’s not just about the tech, but rather about making that tech fit within a user’s or enterprise’s world and making it easy to adopt. AI makes this harder, not easier.</p>



<p>It’s a cliché that developers don’t like marketing. It’s also false in my inexperience. What developers don’t like is traditional marketing. During my time at MongoDB and now at Oracle, my developer relations teams have focused on offering developers deep, hands-on enablement, and the response has been fantastic. Is a technical tutorial marketing? Of course it is. So is a forward-deployed engineer working side by side with an enterprise’s engineers to help them effectively use your tech. Just because it’s not a 30-second Super Bowl ad doesn’t mean it’s not marketing.</p>



<p>Years ago the Dilbert cartoon <a href="https://x.com/mjasay/status/545616694249410560">captured developers’ disdain for marketing</a>. It was funny then, and it’s funny now, but it has never been true.</p>



<p>Years ago Matt Klein, creator of the open source Envoy project, once <a href="https://www.infoworld.com/article/2260935/are-you-sure-you-want-to-open-source-that-project.html">talked me through all the non-development work</a> that goes into making an open source project thrive. As he reflected, “If you look at what I did in 2016 and early 2017 to [introduce] and grow the project, it was not technical.” So what was it, if not core engineering? “It was all leadership, public relations, marketing, documentation, etc., and I did it all myself and I nearly killed myself [doing it].” As he summed it up for me, it was a “f—ing lot of work,” and much (most?) of it wasn’t about code. It was about helping users appreciate the value of that code.</p>



<p>TL;DR? The boring but essential go-to-market grind has always been the real job. It’s what will separate winners from losers in AI.</p>



<h2 class="wp-block-heading"><a></a>The boring work wins</h2>



<p>None of this is an argument against AI coding tools. Developers should absolutely use them. I use them constantly.</p>



<p>But AI can’t compensate for the hard work that goes into making a product successful in the market. In a world drowning in AI-generated sameness, taste becomes a competitive advantage. For me, “taste” translates into knowing what not to build, or what not to publish. It’s also all about knowing how to market one’s product, which might include ads but definitely needs to incorporate technical training that helps developers make sense of your code.</p>



<p>In short, there’s no <em>Field of Dreams</em> “build it and they will come.” There’s just a lot of hard, human work to help real people find and use your code.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Hidden ChatGPT Features: Scheduled Tasks, Image Creation, and More]]></title>
<description><![CDATA[Learn 10 underused ChatGPT features, from Projects and Canvas to Deep Research and Scheduled Tasks, that can make AI more useful at work.]]></description>
<link>https://tsecurity.de/de/3576274/it-nachrichten/10-hidden-chatgpt-features-scheduled-tasks-image-creation-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576274/it-nachrichten/10-hidden-chatgpt-features-scheduled-tasks-image-creation-and-more/</guid>
<pubDate>Fri, 05 Jun 2026 20:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn 10 underused ChatGPT features, from Projects and Canvas to Deep Research and Scheduled Tasks, that can make AI more useful at work.]]></content:encoded>
</item>
<item>
<title><![CDATA[How digital sovereignty shapes Amnesty International Spain’s tech model]]></title>
<description><![CDATA[Transformation of an organization is no longer measured solely in terms of productivity, automation, or the adoption of new tools. In nonprofits like Amnesty International Spain, technology has also become a matter of independence, privacy, and the ability to act autonomously.



For over 14 year...]]></description>
<link>https://tsecurity.de/de/3574990/it-security-nachrichten/how-digital-sovereignty-shapes-amnesty-international-spains-tech-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574990/it-security-nachrichten/how-digital-sovereignty-shapes-amnesty-international-spains-tech-model/</guid>
<pubDate>Fri, 05 Jun 2026 12:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Transformation of an organization is no longer measured solely in terms of productivity, automation, or the adoption of new tools. In <a href="https://www.cio.com/article/4139229/nonprofits-shaping-the-future-of-responsible-ai.html?utm=hybrid_search">nonprofits</a> like Amnesty International Spain, technology has also become a matter of independence, privacy, and the ability to act autonomously.</p>



<p>For over 14 years, the Spanish branch of the organization has operated with a clear premise to minimize its dependence on large technology platforms, and maintain control over its data, systems, and communications. This strategy, amid the ongoing European debate on digital sovereignty and AI, is taking on a new dimension. “From the ground up, we have a policy of being technologically independent, hosting as much as possible ourselves to ensure we have no problems suing any company, or that any report we publish doesn’t affect the systems we work with,” says head of IT infrastructure Carlos López Belenguer.</p>



<p>Having worked like this long before concepts such as digital sovereignty became a regular part of the European tech debate, people are now discussing it more. “I think it’s a powerful and quite appropriate term,” he says.</p>



<h2 class="wp-block-heading">Technology to avoid dependence on big tech</h2>



<p>Amnesty International Spain’s tech strategy has focused on finding free software alternatives and self-hosted systems that allow them to maintain control over their infrastructure. “One of the great advantages of free software is we aren’t dependent on any company to work,” says Belenguer, adding it’s especially important in an organization dedicated to defending human rights, so it can denounce or investigate any company knowing it won’t face retaliation regarding the use of software.</p>



<p>In his view, the current geopolitical context and some recent moves by large technology companies further reinforce this philosophy. “It’s no coincidence Microsoft is withdrawing a significant portion of its licensing model for NGOs right after Donald Trump said none of its suppliers could have certain policies that went against his administration’s philosophy,” he says.</p>



<p>Belenguer adds that these types of changes can create significant economic and technological problems for organizations that depend entirely on external platforms. “When you already have your entire infrastructure in place, you don’t have many options to switch to the competition, because you’re really intertwined,” he says.</p>



<h2 class="wp-block-heading">Providing the means</h2>



<p>A prime example of this strategy has been implementing Nextcloud as an internal collaborative work platform. But Belenguer’s relationship with this tool began years before its deployment within the organization. “I was already familiar with the software and had been following it for years,” he says.</p>



<p>At that time, Amnesty International Spain was still working with local file servers, and solutions like Microsoft 365 and Microsoft SharePoint were just beginning to spread. “Like many others, we worked with a file system on a local server in the office,” he says. “Everyone went to work in person, and the whole Office 365 movement was just starting to emerge.”</p>



<p>However, the organization decided to explore another option. “I proposed Nextcloud because I was already familiar with it, had considerable experience with <a href="https://www.cio.com/article/4139444/open-source-isnt-altruism-its-how-you-avoid-getting-surprised.html?utm=hybrid_search">open-source software</a>, and we already had quite a few things hosted,” he says. “In the end, it was just a matter of launching one more product.”</p>



<p>The implementation began with a small pilot test with five users, which later grew to 10, and then 30. But the major turning point came with the pandemic in 2020 and the rise of remote work. “By then, we already had it up and running in production with everyone using it,” Belenguer says. “It practically saved our lives in IT.”</p>



<p>The tool evolved from a simple file-sharing system into a collaborative work platform. “When people saw they could edit documents concurrently and work together seamlessly, they began to find many more uses for it,” he says.</p>



<h2 class="wp-block-heading">Privacy, flexibility, and control</h2>



<p>Beyond functionality, Belenguer says the main differentiating value of these types of solutions is control over infrastructure and data. “The only real way today to guarantee privacy when working with big tech is to leave big tech,” he says.</p>



<p>In this way, he expresses a particularly critical view of how large tech platforms handle personal data. “Microsoft seeks to create a general profile of everyone who works with or uses a computer,” he says, adding that the increasing integration of digital services, accounts, and tools is generating a massive collection of information about users. “All this is done under the guise of improving security or ensuring a better user experience.”</p>



<p>Free software, on the other hand, offers a more flexible and secure alternative. “Being your own Google without compromising user privacy and documents, and being technologically independent is a huge leap,” he says.</p>



<p>In addition to privacy, the adaptability offered by working with one’s own infrastructure is also key. “We’ve had much more flexibility both in managing the platform and in recovering lost data, as well as enabling different ways of working,” he says.</p>



<p>Despite its commitment to technological independence, Amnesty International Spain acknowledges that some dependencies remain difficult to overcome, so certain tools from major tech companies have become de facto standards. “A big commitment I feel we have to make is to use Teams,” says Belenguer. “Many people don’t realize an alternative exists.” Still, he adds the organization has achieved a high degree of technological autonomy. “I’d say we’re at about 70% independent,” he says. “If the US cuts the cord, we believe we could continue working practically without problems.”</p>



<h2 class="wp-block-heading">AI: opportunity and concern</h2>



<p>Regarding AI, Amnesty International Spain has developed internal <a href="https://www.cio.com/article/4095393/6-strategies-for-cios-to-effectively-manage-shadow-ai.html?utm=hybrid_search">policies to limit use of external tools with sensitive data</a>. “We’ve developed policies to ensure personal data is neither shared nor fed into any AI controlled by a large company,” he says.</p>



<p>At the same time, the nonprofit is working on projects to deploy its own self-hosted models that can offer users tools with which to process personal data without compromising sensitive information. Among the projects under development are those related to videoconferencing, transcription, and voice and text analysis and synthesis. “We’re aiming for a hybrid model in which certain tasks can be performed with external tools, and others require our own infrastructure,” he says.</p>



<p>Belenguer understands AI will continue to profoundly transform the work of organizations. “There’s practically no aspect of our work that won’t be affected,” he adds. Despite this, he believes this very transformation makes maintaining technological control even more important. “It’s a very good time to try to become technologically independent and control most of our systems,” he says.</p>



<h2 class="wp-block-heading">A cultural shift that has already begun</h2>



<p>Belenguer acknowledges those who opted to maintain their own infrastructure and reduce dependence on large technology platforms were seen as oddities. “For a long time, we felt quite alone doing this,” he says. But he believes the current context is driving a change in mindset. “In the last two years, though, we’ve seen a major ideological shift. There’s constant and enthusiastic talk about digital sovereignty, hosting your own systems, and owning your data.”</p>



<p>This shift confirms the path the organization embarked on years ago made sense. “Now we realize we were largely right and we’ve done the necessary thing,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro Max isn't getting any thinner as Apple focuses elsewhere]]></title>
<description><![CDATA[Apple's upcoming iPhone 18 Pro Max is said to be the same thickness as the iPhone 17 Pro Max, dashing hopes of a more svelte form factor this time around.The iPhone 18 Pro Max isn't getting any thinner this year.Just like its predecessor, a new report claims Apple's monster 2026 iPhone will measu...]]></description>
<link>https://tsecurity.de/de/3572432/ios-mac-os/iphone-18-pro-max-isnt-getting-any-thinner-as-apple-focuses-elsewhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572432/ios-mac-os/iphone-18-pro-max-isnt-getting-any-thinner-as-apple-focuses-elsewhere/</guid>
<pubDate>Thu, 04 Jun 2026 13:54:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's upcoming <a href="https://appleinsider.com/inside/iphone-18" title="iPhone 18" data-kpt="1">iPhone 18</a> Pro Max is said to be the same thickness as the iPhone 17 Pro Max, dashing hopes of a more svelte form factor this time around.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67833-142962-iPhone-18-Pro-Max-small-Dynamic-Island-xl.jpg" alt="Close-up of a smartphone lock screen showing large white clock digits over a cloudy sky background, with status icons and date Fri Jan 23 at the top against a blue border" height="738"><br><span>The iPhone 18 Pro Max isn't getting any thinner this year.</span></div><br>Just like its predecessor, a new report claims Apple's monster 2026 <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> will measure 8.75mm. That's thicker than the <a href="https://appleinsider.com/inside/iphone-16" title="iPhone 16" data-kpt="1">iPhone 16</a> Pro Max's 8.25mm measurement, and a pocket-filler for fans of skinny jeans and the like.<br><br>The measurement <a href="https://weibo.com/5673255066/R2xsh86Eo">comes</a> from Weibo leaker Ice Universe, and is notable given their previous claims of an increase in thickness. They <a href="https://appleinsider.com/articles/26/03/11/smaller-dynamic-island-is-headed-for-iphone-19-pro-not-iphone-18-pro">said in March</a> that the iPhone 18 Pro Max would be 8.8mm thick, a modest growth.<br><br><br> <strong>Rumor Score:</strong> 🤯 Likely <br><br><br> <a href="https://appleinsider.com/articles/26/06/04/iphone-18-pro-max-isnt-getting-any-thinner-as-apple-focuses-elsewhere?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244530?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your outsourcing contract needs XLAs, not just SLAs]]></title>
<description><![CDATA[I’ve lost count of how many clients have called frustrated, not because their managed services provider (MSP) was missing SLAs, but because meeting every SLA still wasn’t helping employees do their jobs. Tickets close on time, uptime stays above target, and scorecards are green across the board y...]]></description>
<link>https://tsecurity.de/de/3572158/it-nachrichten/your-outsourcing-contract-needs-xlas-not-just-slas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572158/it-nachrichten/your-outsourcing-contract-needs-xlas-not-just-slas/</guid>
<pubDate>Thu, 04 Jun 2026 12:17:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve lost count of how many clients have called frustrated, not because their managed services provider (MSP) was missing SLAs, but because meeting every SLA still wasn’t helping employees do their jobs. Tickets close on time, uptime stays above target, and scorecards are green across the board yet employees remain frustrated by broken processes, recurring issues, and support that feels transactional instead of useful.</p>



<p>The help desk resolves tickets quickly without solving underlying problems, so employees create their own workarounds. This is the watermelon effect: green on the outside, red on the inside. It remains one of the most persistent problems in outsourced IT today.</p>



<h2 class="wp-block-heading">Patterns across major MSP relationships</h2>



<p>I see this pattern across relationships with every major provider. These are sophisticated organizations with mature delivery capabilities that can absolutely hit the metrics you put in front of them. That’s precisely the problem.</p>



<p><a href="https://www.cio.com/article/4160884/you-selected-the-right-vendors-now-govern-them-like-you-mean-it.html?utm=hybrid_search">Vendors</a> optimize for whatever the contract measures. If your contract only measures operational outputs, that’s what your provider will focus on. They’re not doing anything wrong. They’re doing exactly what the contract incentivizes.</p>



<p>What I’ve seen time and again is that the contracts organizations signed five or seven years ago were designed for a different model of IT support, one that enforces compliance and control costs. They weren’t designed to drive outcomes or improve the employee experience, and in many cases, those contracts are still running.</p>



<p>Realigning a major MSP relationship isn’t simply a matter of telling the provider to do better. It requires changing what the contract measures. That’s where experience level agreements come in.</p>



<h2 class="wp-block-heading">Why SLAs weren’t designed to measure what matters most</h2>



<p>SLAs were built for an earlier era of IT. The logic was straightforward: define the service, establish operational standards, measure compliance, and apply financial consequences when performance falls short. It’s precise, auditable, and legally defensible.</p>



<p>But SLAs measure the process, not the outcome. A service desk can resolve 95% of tickets within the agreed timeframe and still leave employees feeling completely unsupported. An application can technically meet uptime standards while being so slow and unreliable that employees avoid using it. That gap, between what the contract measures and what employees actually experience, is where productivity leaks, morale erodes, and the business case for outsourcing quietly unravels.</p>



<p>I’ve sat in enough quarterly business reviews with providers to know how this dynamic plays out. The provider presents a polished scorecard. Every metric is green or amber. The client’s internal stakeholders raise concerns about employee complaints, escalating shadow IT, and department heads who have stopped submitting tickets because they’ve given up. The provider points to the scorecard and there’s no mechanism in the contract to address the gap.</p>



<p>That’s a contract design problem, not a provider capability problem. And it’s one that experience-based measurements like XLAs are specifically designed to solve.</p>



<h2 class="wp-block-heading">The shift organizations need to make, and why it’s hard</h2>



<p>When I work with clients on <a href="https://www.cio.com/article/405257/6-top-managed-cloud-services-providers-and-how-to-choose.html?utm=hybrid_search">realigning MSP relationships</a>, the conversation often starts with frustration, and the solution isn’t straightforward either. Organizations face real structural barriers to making this shift, like with baseline data, for instance. You can’t set meaningful experience targets without knowing where you’re starting from. Many of my clients have been operating on SLA-only contracts for years, sometimes with the same provider, and they have no employee experience data at all. They know ticket volumes and resolution times, but they have no idea how employees actually feel about the service.</p>



<p>Contract language is another issue. Major MSPs have mature commercial teams that are very skilled at navigating ambiguous commitments. Improving the employee experience isn’t a contractual commitment. A defined happiness score is, one that’s measured by a specific tool, and reported monthly with agreed escalation protocols when thresholds are missed.</p>



<p>Another is incentive alignment. The most common mistake I see organizations make is converting an XLA into a penalty mechanism. If the only consequence for missing an experience target is a financial deduction, providers will manage the number rather than the experience. The most effective XLA structures I’ve worked on combine penalties for persistent underperformance with shared gain mechanisms that reward genuine improvement.</p>



<h2 class="wp-block-heading">Four ways to structure XLAs in an outsourcing contract</h2>



<p>Based on what I’ve seen work across client relationships, there are four practical models for building XLAs into a contract. The right starting point depends on where the organization and the provider relationship currently are.</p>



<p><strong>1. Commit to a defined experience score</strong>. The vendor commits contractually to achieving a defined satisfaction threshold. This is the most rigorous model and requires established baseline data on both sides. It works best when the relationship has been running for at least six to 12 months and both parties have experience measurement in place.</p>



<p><strong>2. Commit to a digital experience score</strong>. Here, the XLA is tied to a broader digital employee experience (DEX) score that combines employee sentiment with technical telemetry. Providers like HCL and Cognizant increasingly support this model through partnerships with platforms like Nexthink.</p>



<p><strong>3. Commit to continuous improvement</strong>. Rather than setting fixed thresholds immediately, both parties agree to a shared obligation to improve experience metrics over time, with targets reviewed and reset every six months. This is usually the best entry point for organizations that are new to experience measurement. It builds a data baseline, establishes a culture of shared accountability, and avoids the trap of locking in arbitrary targets before either party understands the benchmarks.</p>



<p><strong>4. Commit to delivering the XLA capability</strong>. In this model, the provider takes responsibility for building and operating the measurement infrastructure itself. This works well when the client lacks internal XLA capability but still wants accountability built into the relationship from the outset. I’ve seen this work particularly well in new contract structures with Accenture and Capgemini, both of which have invested in building proprietary experience measurement frameworks.</p>



<h2 class="wp-block-heading">What XLAs actually measure</h2>



<p>Unlike SLAs, which focus on technical outputs, XLAs focus on human outcomes. The metrics I most commonly see built into client contracts include:</p>



<ul class="wp-block-list">
<li>Employee satisfaction scores</li>



<li>Perceived lost productivity time</li>



<li>Repeat incident rates for the same underlying issue</li>



<li>Ease of getting support across different channels</li>



<li>Task completion success rates</li>



<li>Confidence in IT services overall</li>
</ul>



<p>The goal isn’t to eliminate SLAs as systems still need uptime targets and response standards, and providers operate at a scale where those operational commitments genuinely matter. So the goal is to add the missing layer of whether or not employees feel supported and productive, not just if tickets are being processed.</p>



<h2 class="wp-block-heading">The data infrastructure behind a working XLA program</h2>



<p>Strong XLA programs depend on three categories of data working together. Getting this right is often where the real negotiation with providers happens, because <a href="https://www.cio.com/article/4168669/7-signs-your-data-isnt-ready-for-ai.html?utm=hybrid_search">data ownership</a> and transparency are genuinely contested terrain in major MSP relationships.</p>



<p><strong>Experience data (X-data)</strong>: This is the human layer, how employees feel about their IT experience. It comes from pulse surveys, post-interaction feedback, and always-on feedback channels. Platforms like HappySignals, Nexthink, and Qualtrics are commonly used. One of the most important negotiating points I work through with clients is ensuring that this data is owned by the client, not the provider. Some MSPs propose operating the measurement platform themselves, which creates a structural conflict of interest.</p>



<p><strong>Operational data (O-data)</strong>: This is the traditional metrics layer already stored in ITSM platforms most common among our clients like ServiceNow or Jira Service Management. Most providers already produce this data and the value comes from correlating it with experience data, not treating it in isolation.</p>



<p><strong>Technical data (T-data)</strong>: This is the infrastructure layer comprised of device health, application performance, network latency, and endpoint health. Platforms like Nexthink and 1E collect this telemetry passively. When experience scores drop, correlating against technical data tells you whether the problem is the technology environment, the support process, or the service interaction itself. Without that triangulation, you know something is wrong but can’t pinpoint why.</p>



<h2 class="wp-block-heading">The transparency problem</h2>



<p>In my experience, the biggest failure point in XLA programs isn’t the metrics but transparency. When clients hide poor experience scores or providers obscure unfavorable data, the foundation of the XLA model breaks down.</p>



<p>I’ve seen MSPs manage the measurement platform and report improving scores, only for independent measurement to reveal a very different reality. The strongest XLA programs treat experience data as jointly owned, openly shared, and central to collaborative problem-solving.</p>



<p>Contracts create accountability, but governance drives improvement. Weekly working sessions, monthly reviews, and leadership steering meetings matter far more than scorecards alone. Building that level of transparency is often the hardest part.</p>



<h2 class="wp-block-heading">The shift from service delivery to outcome delivery</h2>



<p>The shift from SLA-only contracts to XLA-enabled outsourcing reflects more than a new measurement framework. It signals a fundamental change in how organizations define IT value. Cost and efficiency still matter, but leading organizations are now asking whether technology investments improve employee productivity, reduce frustration, and create better support experiences. That requires a different level of provider accountability.</p>



<p>MSPs can deliver experience-based outcomes, but they rarely prioritize them unless contracts demand it. XLAs formalize those expectations, and increasingly, organizations see them as the standard for measuring meaningful IT performance.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[word-sys's PDF Editor v1.9.2 Released with AppImage and Binary Release!]]></title>
<description><![CDATA[https://github.com/word-sys/word-sys-pdf-editor/releases/tag/v1.9.2 Hello everyone, im word-sys, word-sys's PDF Editor v1.9.2 AppImage and Binary release update published on Github, looks to be new stable update, read the README for more information about how to use AppImage and Binary release if...]]></description>
<link>https://tsecurity.de/de/3566872/linux-tipps/word-syss-pdf-editor-v192-released-with-appimage-and-binary-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566872/linux-tipps/word-syss-pdf-editor-v192-released-with-appimage-and-binary-release/</guid>
<pubDate>Tue, 02 Jun 2026 18:25:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://github.com/word-sys/word-sys-pdf-editor/releases/tag/v1.9.2">https://github.com/word-sys/word-sys-pdf-editor/releases/tag/v1.9.2</a></p> <p>Hello everyone, im word-sys, word-sys's PDF Editor v1.9.2 AppImage and Binary release update published on Github, looks to be new stable update, read the README for more information about how to use AppImage and Binary release if you wanna use, thanks everyone who supports and helps to this project, filling a gap on linux application ecosystem with community support is best thing i ever done, thank you. </p> <p>Also project released on AUR, if you wanna use it on there please read the README for important information about it.</p> <p><a href="https://github.com/word-sys/word-sys-pdf-editor">https://github.com/word-sys/word-sys-pdf-editor</a></p> <p>word-sys </p> <p>(This post was removed from linux subreddit due to picture were similar to v1.9.1, i had to wait a week to repost it again, for people isnt informed, this post posted on gnome week ago, people doesnt saw it can see here now)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/word-sys"> /u/word-sys </a> <br> <span><a href="https://i.redd.it/lwc8kpcvou4h1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tunfyg/wordsyss_pdf_editor_v192_released_with_appimage/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[ERP Isn’t Being Replaced by AI — It’s Being Re‑Engineered Around It]]></title>
<description><![CDATA[For the last two decades, ERP has been the operational backbone of the enterprise. Stable, reliable, and deeply embedded, it runs finance, supply chain, HR…
The post ERP Isn’t Being Replaced by AI — It’s Being Re‑Engineered Around It first appeared on CIO WaterCooler.]]></description>
<link>https://tsecurity.de/de/3553785/it-security-nachrichten/erp-isnt-being-replaced-by-ai-its-being-reengineered-around-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553785/it-security-nachrichten/erp-isnt-being-replaced-by-ai-its-being-reengineered-around-it/</guid>
<pubDate>Thu, 28 May 2026 12:39:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For the last two decades, ERP has been the operational backbone of the enterprise. Stable, reliable, and deeply embedded, it runs finance, supply chain, HR…</p>
The post <a href="https://www.ciowatercooler.co.uk/erp-isnt-being-replaced-by-ai-its-being-re-engineered-around-it/">ERP Isn’t Being Replaced by AI — It’s Being Re‑Engineered Around It</a> first appeared on <a href="https://www.ciowatercooler.co.uk/">CIO WaterCooler</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[When GPU utilization lies: The FinOps blind spot in secure AI training]]></title>
<description><![CDATA[Enterprise cloud teams are trained to act on utilization data.



If a virtual machine is idle, resize it.If storage is overallocated, reclaim it.If a GPU appears underused, move the job to a smaller instance.



That logic is central to modern FinOps. It helps organizations reduce waste, improve...]]></description>
<link>https://tsecurity.de/de/3550766/it-nachrichten/when-gpu-utilization-lies-the-finops-blind-spot-in-secure-ai-training/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550766/it-nachrichten/when-gpu-utilization-lies-the-finops-blind-spot-in-secure-ai-training/</guid>
<pubDate>Wed, 27 May 2026 13:02:21 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise cloud teams are trained to act on utilization data.</p>



<p>If a virtual machine is idle, resize it.<br>If storage is overallocated, reclaim it.<br>If a GPU appears underused, move the job to a smaller instance.</p>



<p>That logic is central to modern FinOps. It helps organizations reduce waste, improve forecasting and keep cloud spending under control.</p>



<p>But secure AI training introduces a different problem: sometimes the utilization signal is technically true and operationally misleading.</p>



<p>A GPU can look underused even when the workload is not over-provisioned. In privacy-preserving machine learning, low accelerator utilization may indicate a memory-bound bottleneck, not excess capacity. If a cloud optimization process treats that signal as ordinary waste, the recommended fix can make the job slower and more expensive.</p>



<p>For CIOs, this is not just a GPU tuning issue. It is a cloud governance issue. As I have noted previously, IT leaders must look<a href="https://www.cio.com/article/4113246/beyond-the-cloud-bill-the-hidden-operational-costs-of-ai-governance.html"> </a><a href="https://www.cio.com/article/4113246/beyond-the-cloud-bill-the-hidden-operational-costs-of-ai-governance.html">beyond the cloud bill to understand the hidden operational costs of AI governance</a></p>



<h2 class="wp-block-heading">The utilization number does not explain the bottleneck</h2>



<p>Traditional cloud right-sizing depends on a simple assumption: low utilization usually means unused capacity.</p>



<p>That assumption works for many enterprise workloads. It can work for web services, batch jobs, databases and standard compute jobs. But secure AI training can break that assumption because the workload shape changes.</p>



<p>In my IEEE systems research on <a href="https://ieeexplore.ieee.org/document/11454302" rel="nofollow">privacy and robustness in machine learning</a>, I profiled what happens when trust controls are added to model training. The important lesson for CIOs was not only that secure training costs more, but it was that secure training can change what infrastructure metrics mean.</p>



<p>On a controlled NVIDIA V100 GPU setup, privacy-preserving training increased cost by <strong>3.55x</strong> on a vision workload and <strong>2.96x</strong> on a tabular workload. Robustness training increased cost by <strong>4.07x</strong> on the vision workload.</p>



<p>Those cost multipliers matter. But for FinOps teams, the deeper finding is this:</p>



<p>The workload became less aligned with the hardware signals that cloud teams often use for rightsizing.</p>



<h2 class="wp-block-heading">Why privacy-preserving training can look inefficient</h2>



<p>Modern AI accelerators are very good at large, dense mathematical operations. Standard model training often keeps these accelerator units busy because the work can be organized into large blocks of computation.</p>



<p>Differential privacy training often requires per-example gradient computation and clipping. Instead of pushing most of the work through large, efficient operations, the system performs more fine-grained steps across individual training examples.</p>



<p>That changes the performance profile. In my study, this pattern created memory-bound behavior and reduced effective use of specialized GPU compute units such as Tensor Cores. To a dashboard, that can look like underutilization.</p>



<p>To a systems engineer, it means something more specific: the job is not waiting because the GPU is too large. It is waiting because the workload is constrained by memory movement and per-example operations, simply those are not the same problem.</p>



<h2 class="wp-block-heading">The FinOps risk: Right answer, wrong context</h2>



<p>Automated cloud recommenders are useful because they identify resources that appear oversized or idle. The problem is not that these tools exist. The problem is applying a generic right-sizing rule to a specialized AI workload.</p>



<p>A standard recommendation workflow might ask, “Is the accelerator busy?: For secure AI training, CIOs need the team to ask, “Why is the accelerator not busy?”</p>



<p>If the answer is idle capacity, downsizing may save money.</p>



<p>If the answer is memory-bound privacy computation, downsizing may increase total cost.</p>



<p>A smaller instance may have a lower hourly price, but cloud bills are not based only on hourly price. They are based on hourly price multiplied by runtime. If the smaller instance extends the training job enough, the total bill can rise.</p>



<p>That is the FinOps blind spot: a recommendation can look correct on a utilization dashboard but fail when measured against the full training job.</p>



<h2 class="wp-block-heading">Secure AI needs a different exception policy</h2>



<p>Enterprise IT already treats some workloads differently. Regulated databases, security-sensitive systems and latency-critical applications often have special infrastructure policies.</p>



<p>Secure AI training needs similar exception handling; a model training job that uses differential privacy or adversarial training should not be evaluated the same way as an idle development server. These workloads can produce unusual utilization patterns because the algorithm itself changes the way hardware is used.</p>



<h3 class="wp-block-heading">1. Tag secure-AI training jobs</h3>



<p>FinOps teams need to know when a training job uses privacy-preserving or robustness-oriented methods.</p>



<p>A simple workload tag can prevent the job from being evaluated as ordinary compute. The tag should tell cloud teams:</p>



<p>Low utilization may be caused by the algorithm, not by waste.</p>



<p>This gives FinOps, MLOps and infrastructure teams a shared signal before any right-sizing decision is made.</p>



<h3 class="wp-block-heading"><a></a>2. Treat rightsizing as a review trigger, not an automatic action</h3>



<p>For secure AI jobs, an automated recommendation should start an investigation. It should not automatically become a change request.</p>



<p>Before moving the workload to a smaller instance, the team should answer four questions:</p>



<ul class="wp-block-list">
<li>Is the workload compute-bound or memory-bound?</li>



<li>Is the bottleneck caused by data loading, memory bandwidth or per-example privacy operations?</li>



<li>Would the smaller instance reduce total job cost, or only reduce hourly rate?</li>



<li>Has the team measured runtime impact before approving the change?</li>
</ul>



<p>This shifts FinOps from simple utilization management to workload-aware cost governance.</p>



<h3 class="wp-block-heading">3. Bring MLOps into FinOps decisions</h3>



<p>FinOps teams understand pricing, commitment plans, chargeback and utilization. But secure AI workloads require another layer of interpretation.</p>



<p>Someone must understand what the training algorithm is doing.</p>



<p>DP-SGD and PGD do not merely consume more GPU time. They change the computation pattern. That means utilization percentage alone is not enough to make an infrastructure decision.</p>



<p>CIOs should connect FinOps, MLOps, AI governance and infrastructure engineering before applying cost recommendations to secure AI training workloads.</p>



<h3 class="wp-block-heading"><a></a>4. Measure total job economics, not only instance utilization</h3>



<p>The cheapest instance is not always the lowest-cost option. For secure AI training, CIOs should require teams to compare:</p>



<ul class="wp-block-list">
<li>Hourly cost</li>



<li>Total runtime</li>



<li>Energy use</li>



<li>Job completion time</li>



<li>Model utility impact</li>



<li>Infrastructure bottleneck profile</li>
</ul>



<p>To truly optimize these economics, teams must look beyond the hardware and apply<a href="https://www.infoworld.com/article/4168496/12-model-level-deep-cuts-to-slash-ai-training-costs.html"> model-level deep cuts to slash AI training costs</a>. Ultimately, a GPU that looks underused may still be the better economic choice if it completes the workload faster and avoids a longer memory-bound run. Failing to account for the model utility impact during these infrastructure changes can easily lead organizations into<a href="https://www.vktr.com/ai-technology/the-ai-accuracy-trap/" rel="nofollow"> the AI accuracy trap</a>, where cost savings inadvertently ruin real-world performance.</p>



<h2 class="wp-block-heading">The CIO takeaway</h2>



<p>The next phase of enterprise AI will require more than model accuracy and fast experimentation. Organizations will need AI systems that are private, robust, governable and economically sustainable.</p>



<p>In ordinary cloud operations, low utilization often means waste. In secure AI training, low utilization may mean the workload has exposed a hardware-software mismatch.</p>



<p>The rule for CIOs is simple: Do not right-size secure AI training jobs until you understand why the accelerator is underused.</p>



<p>In trustworthy AI, utilization is not always truth.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Georgia-Pacific drives autonomous decision-making]]></title>
<description><![CDATA[As VP of data and analytics at Atlanta-based Georgia-Pacific, Matt Robuck gives a multitude of insights to the business. In the past, these would’ve been delivered as dashboards and reports, but over the last three years, with the proliferation of AI, he and his team of over 180 engineers have be...]]></description>
<link>https://tsecurity.de/de/3550630/it-security-nachrichten/how-georgia-pacific-drives-autonomous-decision-making/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550630/it-security-nachrichten/how-georgia-pacific-drives-autonomous-decision-making/</guid>
<pubDate>Wed, 27 May 2026 12:08:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As VP of data and analytics at Atlanta-based Georgia-Pacific, Matt Robuck gives a multitude of insights to the business. In the past, these would’ve been delivered as dashboards and reports, but over the last three years, with the proliferation of AI, he and his team of over 180 engineers have been questioning how they can strategically implement emerging tech to solve problems differently.</p>



<p>“Georgia-Pacific has been around for nearly 100 years, and many of the problems we’re trying to solve today we’ve been dealing with for decades,” he says. “New technologies allow us to look at these challenges through a different lens.”</p>



<h2 class="wp-block-heading">Metadata and the AI ecosystem</h2>



<p>According to Robuck, developing an AI ecosystem starts with having a very strong bedrock of data. “We’ve made substantial investments over the past three years to build these foundations,” he says. “In the past, <a href="https://www.cio.com/article/4168669/7-signs-your-data-isnt-ready-for-ai.html?utm=hybrid_search">data quality</a>, metadata and contextual data weren’t seen as critical because if something was wrong in a report, a human would usually catch it. But with AI agents, there usually isn’t a human in the loop until much later in the process, which means poor-quality data can have big consequences.”</p>



<p>When building the data platform, Georgia-Pacific invested in data lake architecture, proactive data quality, and metadata. “We couldn’t have moved as fast as we have without these things,” he adds. For Robuck, the metadata component — the data context — is critical to the success of their AI agents.</p>



<p>With over 1,000 applications running across the company, each one has its own naming conventions, data types, and data structures. So when an agent is put on top of these data sets, it’ll do its best to interpret the data. “But we need more deterministic outcomes,” he says. “Our agents need to be right more often than not. <a href="https://www.cio.com/article/4158048/how-poor-data-foundations-can-undermine-ai-success.html?utm=hybrid_search">Metadata</a>, therefore, acts as a translation layer, giving the agents critical context.”</p>



<p>And by making the metadata even richer, with more detailed information about Georgia-Pacific’s different manufacturing sites, like size, products they produce, and business lines they serve, the agents have deeper knowledge of what the data means for the business more broadly.</p>



<p>The company considered building their own metadata solution, but given its size and scale, it partnered with agentic data intelligence platform Alation to ensure the process was quick and cost-effective.</p>



<h2 class="wp-block-heading">Using data to solve real business problems</h2>



<p>One area where these foundations are now being used to add value is across the business’ marketing function. Georgia-Pacific invests heavily in both digital and traditional marketing to promote its consumer products. But when a business wants to understand if its marketing budget is being allocated effectively, it must be able to track campaign performance.</p>



<p>“If you budget $50 million for a campaign, but no one sees it, that’s a nice waste of money,” Robuck says. The marketing team used to spend months at a time consolidating data to determine whether a particular campaign performed well, and then adjust strategies based on this deep dive.</p>



<p>“Understanding marketing performance is ultimately a data challenge,” he says. “That’s why we built a solution that pulls near real-time data from multiple marketing platforms, and turns it into actionable insights, giving marketing teams a far clearer view of how their campaigns perform.”</p>



<p>This strategy cuts costs, eliminates about 30,000 man hours every year, and helps the business connect with a wider customer base. In addition, if the marketing team deploys a campaign that isn’t performing well, having near real-time data allows them to pivot before they’ve wasted time and money on the wrong strategy.</p>



<p>“There’s been fairly substantial optimization of our marketing spend through this process,” he says, adding there are many other opportunities to improve marketing processes, including how he and his team recently deployed a new set of agents on top of these marketing datasets and data products, which can analyze performance data and make recommendations based on how the different campaigns are doing.</p>



<p>“Soon we’ll see <a href="https://www.cio.com/article/4146658/autonomous-ai-adoption-is-on-the-rise-but-its-risky.html?utm=hybrid_search">agents autonomously making decisions</a> and changing our campaign strategies in real-time,” he says. “Maybe there’s a human in the loop or maybe this runs fully autonomously.”</p>



<p>But the success of this initiative doesn’t mean Georgia-Pacific plans to throw AI at every business problem. “You must start with the business problem in mind, not AI, and think about it holistically,” he says. “To achieve what we have with our marketing team, we went on a three-year journey to get the data right and make sure what we were proposing was the right fit for them.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You]]></title>
<description><![CDATA[Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn’t log in without the second factor. While that logic was sound, attackers have now…
Read more →
The post MFA Prompt Bombin...]]></description>
<link>https://tsecurity.de/de/3547827/it-security-nachrichten/mfa-prompt-bombing-why-your-second-factor-isnt-saving-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547827/it-security-nachrichten/mfa-prompt-bombing-why-your-second-factor-isnt-saving-you/</guid>
<pubDate>Tue, 26 May 2026 13:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn’t log in without the second factor. While that logic was sound, attackers have now…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/mfa-prompt-bombing-why-your-second-factor-isnt-saving-you/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/mfa-prompt-bombing-why-your-second-factor-isnt-saving-you/">MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The role of MCP in context engineering]]></title>
<description><![CDATA[There’s no denying the excitement around Model Context Protocol (MCP), an open protocol for connecting AI assistants with external data, tools, and APIs. Since its debut by Anthropic in late 2024, thousands of MCP servers have emerged for devops, cloud, and beyond.



Now that developers have int...]]></description>
<link>https://tsecurity.de/de/3545164/ai-nachrichten/the-role-of-mcp-in-context-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545164/ai-nachrichten/the-role-of-mcp-in-context-engineering/</guid>
<pubDate>Mon, 25 May 2026 11:02:53 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There’s no denying the excitement around <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP), an open protocol for connecting AI assistants with external data, tools, and APIs. Since its debut by Anthropic in late 2024, thousands of MCP servers have emerged for <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">devops</a>, <a href="https://www.infoworld.com/article/4129024/five-mcp-servers-to-rule-the-cloud.html">cloud</a>, and beyond.</p>



<p>Now that developers have integrated MCP servers into applications, and they have been battle-tested, usage patterns are emerging. For instance, supplying better context for AI is the most commonly cited primary value of using MCP, according to Zuplo’s <a href="https://zuplo.com/mcp-report">State of MCP report</a> released in early 2026. The Zuplo report also found that 63% of MCP users adopt MCP servers for accessing data sources such as documentation or knowledge bases.</p>



<p>In software development, <a href="https://www.infoworld.com/article/4127462/what-is-context-engineering-and-why-its-the-new-ai-architecture.html">context engineering</a> is the act of supplying <a href="https://www.infoworld.com/article/4024327/12-ai-coding-agents-at-the-cutting-edge.html">AI coding agents</a> with relevant data and capabilities to improve the accuracy and relevance of their outputs. It also involves optimizing the breadth of information to guide efficient processing. Such context can include coding style, internal libraries, <a href="https://www.infoworld.com/article/4091400/anatomy-of-an-ai-agent-knowledge-base.html">institutional knowledge</a>, production data, and <a href="https://www.infoworld.com/article/4120322/how-should-ai-agents-consume-external-data.html">external data</a> from platforms like Slack, Atlassian, Notion, or GitHub, among others.</p>



<p>“MCPs support context engineering because it creates a standard way for AI systems to connect to various business tools,” says <a href="https://www.linkedin.com/in/toddaolson/">Todd Olson</a>, CEO of <a href="https://www.pendo.io/">Pendo</a>, a product experience platform. “The key benefit is that the agent determines what context it needs based on the question, then uses the appropriate MCP server to fetch that information in real time.”</p>



<p>With the rise in AI-assisted coding, MCP is becoming a doorway for real-time dynamic search and retrieval across various sources, playing an important role in context engineering efforts. As <a href="https://www.linkedin.com/in/theoutdoorprogrammer/">Joey Stout</a>, solutions architect at <a href="https://spacelift.io/">Spacelift</a>, an infrastructure orchestration platform, puts it, MCP is the “saving grace of vibe coding.”</p>



<h2 class="wp-block-heading"><a></a>How MCP boosts context engineering</h2>



<p>Using MCP, agents can fetch structured data contextually relevant to the task at hand. According to <a href="https://www.linkedin.com/in/kussberg/">Edgar Kussberg</a>, group product manager at <a href="https://www.sonarsource.com/">Sonar</a>, MCP accelerates the knowledge-hunting engineers must routinely perform on a daily basis.</p>



<p>“When an engineer needs to answer a question, they do not rely on memory alone,” says Kussberg. “They navigate code repositories, dashboards, CI systems, documentation, and security reports, pulling information from each system as needed. MCP gives AI agents that same capability.”</p>



<p>Many of the most popular MCP servers retrieve contextual information to improve agentic coding. For example, an MCP server from <a href="https://github.com/upstash/context7">Context7</a> provides up-to-date documentation, while another from <a href="https://github.com/modelcontextprotocol/servers/tree/main/src/filesystem">Filesystem</a> pulls from any directory on a local machine. An MCP server from <a href="https://docs.sentry.io/ai/mcp/">Sentry</a> accesses production issues and errors, a server from <a href="https://www.sonarsource.com/products/sonarqube/mcp-server/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=SQ-NA-US-East-Brand-Beinc&amp;utm_content=mcp-server&amp;utm_term=sonarqube%20mcp%20server&amp;s_campaign=SQ-NA-US-East-Brand-Beinc&amp;s_content=mcp-server&amp;s_term=sonarqube%20mcp%20server&amp;s_category=Paid&amp;s_source=Paid%20Search&amp;s_origin=Google&amp;cq_src=google_ads&amp;cq_cmp=23576298435&amp;cq_con=196318441871&amp;cq_term=sonarqube%20mcp%20server&amp;cq_med=&amp;cq_plac=&amp;cq_net=g&amp;cq_pos=&amp;cq_plt=gp&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=SQ-NA-US-East-Brand-Beinc&amp;utm_content=mcp-server&amp;utm_term=sonarqube%20mcp%20server&amp;s_campaign=SQ-NA-US-East-Brand-Beinc&amp;s_content=mcp-server&amp;s_term=sonarqube%20mcp%20server&amp;s_category=Paid&amp;s_source=Paid%20Search&amp;s_origin=Google&amp;cq_src=google_ads&amp;cq_cmp=23576298435&amp;cq_con=196318441871&amp;cq_term=sonarqube%20mcp%20server&amp;cq_med=&amp;cq_plac=&amp;cq_net=g&amp;cq_pos=&amp;cq_plt=gp&amp;gad_source=1&amp;gad_campaignid=23576298435&amp;gbraid=0AAAAAC0fKmo3CzAuxD-J1yoRRbolpI2DZ&amp;gclid=Cj0KCQjwv-LOBhCdARIsAM5hdKcg5cAclxuhMymQNu4C1OJatpQNdVIzGz6d1fO_sjighYg9ce0Pfi8aApUKEALw_wcB">SonarQube</a> exposes security issues, and a server from <a href="https://www.multiplayer.app/docs/ai/mcp-server/">Multiplayer</a> returns user session data.</p>



<p>The great thing about using MCP for these situations is that it avoids the need to put large code chunks in every prompt. Instead, coding context like relevant methods, dependencies, or recent changes can be called at runtime, says <a href="https://www.linkedin.com/in/jvenugopal/">Venugopal Jidigam</a>, head of agentic platform engineering at <a href="https://www.wavemaker.com/">WaveMaker</a>, an agentic development platform. “The MCP server assembles and returns scoped, structured context, which the model then uses to reason and respond accurately,” he says.</p>



<p>Another common context-gathering example is retrieving institutional knowledge. “Instead of hardcoding that knowledge into the model, the agent uses MCP to retrieve relevant documents or data at runtime,” says <a href="https://www.linkedin.com/in/ebrahim-alareqi-1b570048/">Ebrahim Alareqi</a>, principal machine learning engineer at <a href="https://www.incorta.com/">Incorta</a>, a data and analytics platform provider. “This keeps the agent lightweight while still giving it access to enterprise-specific context when needed.”</p>



<p>Others praise MCP for its role in bringing common standards to agentic data retrieval. “MCP provides the plumbing that makes context engineering practical,” says <a href="https://www.linkedin.com/in/gilfeig/">Gil Feig</a>, co-founder and CTO at <a href="https://www.merge.dev/">Merge</a>, an API platform provider. Without standards, teams end up building fragile custom data pipelines that break often, he adds.</p>



<h2 class="wp-block-heading"><a></a>Benefits of using MCP for gathering context</h2>



<p>AI-assisted coding has some challenges. Most notably is a trust issue. The vast majority of developers don’t trust the output of AI coding agents — 96%, according to Sonar’s 2026 <a href="https://www.sonarsource.com/company/press-releases/sonar-data-reveals-critical-verification-gap-in-ai-coding/">State of Code Developer Survey report</a>. A second challenge is increased time spent reviewing and debugging AI-generated code. A late <a href="https://stackoverflow.blog/2025/12/29/developers-remain-willing-but-reluctant-to-use-ai-the-2025-developer-survey-results-are-here/">2025 StackOverflow survey</a> found nearly half of developers report frustration dealing with AI solutions that are “almost right, but not quite”.</p>



<p>Context engineering, as well as the use of MCP for this purpose, could help overcome many of these challenges. Using MCP servers, engineers can automatically append relevant logs or internal data to their prompts, refining LLM processing considerably to avoid irrelevant outputs.</p>



<p>The end result is improved accuracy. “MCP allows systems to dynamically fetch what the model needs, like APIs, databases, files, or domain knowledge,” says <a href="https://www.linkedin.com/in/neeraj-abhyankar-9040141/">Neeraj Abhyankar</a>, VP of data and AI at <a href="https://www.rsystems.com/">R Systems</a>, a digital product engineering company. “This makes prompts leaner, reduces hallucinations, and ensures models operate with task‑relevant context.”</p>



<p>Another huge benefit is better context window management. Using MCP for context engineering can enable more efficient interaction with underlying models. “MCP tools can save you thousands of tokens just by ensuring you’re using the right things,” says Spacelift’s Stout.</p>



<p>Stout specifically highlights the <a href="https://github.com/github/github-mcp-server">GitHub MCP server</a>. “It can now access specific files directly from GitHub and do GitHub searching and all the bells and whistles you expect when referencing GitHub,” he says. “MCP made retrieval from GitHub a million times better.”</p>



<p>Using MCP also enhances autonomy and scalability across an enterprise. “Teams can stop relying on partial views or anecdotal evidence and instead operate from a shared understanding,” says Pendo’s Olson. This greatly reduces the friction typically involved in stitching tools, building reports, or looping in teammates, he says.</p>



<p>All in all, the experts say the benefits of MCP in context engineering are numerous. Standardizing on MCP affords more focused prompts that generate more explicitly and relevant context, decreasing the likelihood of LLM hallucination and optimizing what the agent acts on. This in turn can lessen the manual review required for validation and debugging, reclaiming some developer time in the process.</p>



<p>Together, these benefits aim to solve many of the core issues inherent in <a href="https://www.infoworld.com/article/3844363/why-ai-generated-code-isnt-good-enough-and-how-it-will-get-better.html">AI-generated code</a> and <a href="https://www.infoworld.com/article/4035926/multi-agent-ai-workflows-the-next-evolution-of-ai-coding.html">agentic workflows</a> at large. “MCP shifts AI development from fragile prompt tuning to repeatable engineering,” says WaveMaker’s Jidigam. “The result is consistent behavior, minimal data exposure, and AI systems that can scale.”</p>



<h2 class="wp-block-heading"><a></a>To MCP, or not to MCP</h2>



<p>Experts agree MCP can go beyond <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval augmented generation</a> (RAG) to provide more timely and relevant content in a more optimized fashion. “Traditional knowledge bases and RAG pipelines rely on pre-indexed snapshots,” says Sonar’s Kussberg. “In fast-moving environments, this quickly becomes outdated.”</p>



<p>For this reason and others, MCP unlocks all kinds of possibilities for developers. That said, the protocol is <a href="https://thenewstack.io/when-is-mcp-actually-worth-it/">not a silver bullet</a> for all use cases. It’s up against competing <a href="https://www.infoworld.com/article/4007686/a-developers-guide-to-ai-protocols-mcp-a2a-and-acp.html">agentic protocols</a> for some scenarios, and even simple CLI or direct API access for others.</p>



<p>Ballooning portfolios of MCP servers can <a href="https://www.reddit.com/r/ClaudeAI/comments/1rzz784/mcp_is_costing_you_37_more_tokens_than_necessary/">increase LLM inputs substantially</a>, too, requiring <a href="https://thenewstack.io/how-to-reduce-mcp-token-bloat/">vigilant optimization techniques</a> to avoid hitting token limits. Such strategies include intentionally designing tools, progressive disclosure, automated discovery, and other emerging tactics.</p>



<p>Then, there are <a href="https://thenewstack.io/building-with-mcp-mind-the-security-gaps/">MCP-related security concerns</a>. The security model for the MCP protocol itself has <a href="https://modelcontextprotocol.io/docs/tutorials/security/authorization">matured quite a bit</a>, but it’s incumbent upon implementers to enforce the correct permissions. “MCP, when implemented the right way, lets you enforce policy-driven access controls,” says Merge’s Feig. This should prevent a junior engineer, for instance, from accessing logs they’re not authorized to access, even if the agent has broader permissions, he adds.</p>



<p>To boost confidence using MCP within enterprise development settings, many experts recommend using an <a href="https://www.infoworld.com/article/4145014/how-to-build-an-enterprise-grade-mcp-registry.html">MCP registry</a> that houses vetted, governed MCP servers approved for internal use. Other tools and practices, including <a href="https://www.infoworld.com/article/4115115/visual-studio-code-adds-support-for-agent-skills.html">agent skills</a>, <a href="https://thenewstack.io/port-of-context-the-open-source-code-mode/">code mode</a>, and emerging <a href="https://nordicapis.com/why-ai-agents-need-deterministic-api-workflows/">specifications for deterministic AI</a> also promise to play a role in establishing context for agents.</p>



<p>Beyond MCP itself, Stout recommends using Claude Code’s <a href="https://medium.com/@joe.njenga/claude-code-just-cut-mcp-context-bloat-by-46-9-51k-tokens-down-to-8-5k-with-new-tool-search-ddf9e905f734">tool search feature</a>, which searches for tools without using token windows. He also highlights Sisyphus, an <a href="https://opencode.ai/">OpenCode</a>-compatible agent for matching models with different tasks, and <a href="https://plannotator.ai/">Plannotator</a>, a plugin for Claude Code and OpenCode that can be used to plan projects, both of which can aid optimization.</p>



<h2 class="wp-block-heading">Context is king</h2>



<p>The pace of MCP development is accelerating. Analysis of 1,400 MCP servers by <a href="https://bloomberry.com/blog/we-analyzed-1400-mcp-servers-heres-what-we-learned/">Bloomberry</a> charted a 232% increase in six months, from August 2025 to February 2026. Interestingly, read operations outpaced write operations two to one, indicating these servers are performing a significant amount of data retrieval.</p>



<p>Looking to the future, context engineering is anticipated to continue cementing itself as a software discipline, while MCP wields the power to transform APIs into engines for agentic reasoning. As Jidigam says, “MCP-like abstractions will become standard infrastructure, much like REST did in earlier eras.”</p>



<p>Others are similarly confident. “In context engineering, MCP becomes the control plane agents use to access context, tools, and actions,” adds Incorta’s Alareqi. “It will be foundational as software becomes increasingly agent-driven.”</p>



<p>The underlying takeaway: MCP already plays a large role in context engineering, and will continue to do so. As the standard interface between AI systems and data, MCP is the primary vessel for dynamic cross-platform context retrieval at run time, allowing engineers to fetch documentation, API references, policies, available actions, and more.</p>



<p>However, this doesn’t mean context engineering has reached its zenith. Looking ahead, context engineering will evolve from fetching information to coordinating it, says Kussberg, combining multiple MCPs along the way. This will require increased discipline in enforcing standards, assessing risks, and validating changes more often, he says.</p>



<p>So, get started with context engineering using MCP, and stay alert to how your MCP servers are impacting LLM token usage and shaping workflows. The difference between context and non-context matters. Because, as they say, context is king.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deepmind's Hassabis sees humanity "in the foothills of the singularity" while LeCun says current AI isn't intelligent]]></title>
<description><![CDATA[Yann LeCun says current AI systems aren't genuinely intelligent. Demis Hassabis thinks humanity is already "standing in the foothills of the singularity." And Gemini co-lead Oriol Vinyals splits the difference: today's models would've looked like AGI seven years ago, but they still can't learn fr...]]></description>
<link>https://tsecurity.de/de/3543620/ai-nachrichten/deepminds-hassabis-sees-humanity-in-the-foothills-of-the-singularity-while-lecun-says-current-ai-isnt-intelligent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543620/ai-nachrichten/deepminds-hassabis-sees-humanity-in-the-foothills-of-the-singularity-while-lecun-says-current-ai-isnt-intelligent/</guid>
<pubDate>Sun, 24 May 2026 15:03:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://the-decoder.com/wp-content/uploads/2026/05/hassabis_io_26.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Yann LeCun says current AI systems aren't genuinely intelligent. Demis Hassabis thinks humanity is already "standing in the foothills of the singularity." And Gemini co-lead Oriol Vinyals splits the difference: today's models would've looked like AGI seven years ago, but they still can't learn from experience or produce real breakthroughs.</p>
<p>The article <a href="https://the-decoder.com/deepminds-hassabis-sees-humanity-in-the-foothills-of-the-singularity-while-lecun-says-current-ai-isnt-intelligent/">Deepmind's Hassabis sees humanity "in the foothills of the singularity" while LeCun says current AI isn't intelligent</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Recon Isn’t Just Technical — It’s Psychological]]></title>
<description><![CDATA[Hey there!😁Continue reading on InfoSec Write-ups »]]></description>
<link>https://tsecurity.de/de/3541580/hacking/recon-isnt-just-technical-its-psychological/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541580/hacking/recon-isnt-just-technical-its-psychological/</guid>
<pubDate>Sat, 23 May 2026 10:36:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://infosecwriteups.com/recon-isnt-just-technical-it-s-psychological-0bc51a58487b"><img src="https://cdn-images-1.medium.com/max/1024/1*darNDAHwnyV6MRgDROsJ6g.png" width="1024"></a></p><p class="medium-feed-snippet">Hey there!😁</p><p class="medium-feed-link"><a href="https://infosecwriteups.com/recon-isnt-just-technical-it-s-psychological-0bc51a58487b">Continue reading on InfoSec Write-ups »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft's Xbox controller refresh kills its underused accessory port]]></title>
<description><![CDATA[Hold your Chatpads close.]]></description>
<link>https://tsecurity.de/de/3537788/it-nachrichten/microsofts-xbox-controller-refresh-kills-its-underused-accessory-port/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537788/it-nachrichten/microsofts-xbox-controller-refresh-kills-its-underused-accessory-port/</guid>
<pubDate>Thu, 21 May 2026 23:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hold your Chatpads close.]]></content:encoded>
</item>
<item>
<title><![CDATA[Your API Authentication Isn’t Broken; It’s Quietly Failing in These 6 Ways]]></title>
<description><![CDATA[Most API authentication setups don’t fail loudly. They fail quietly, and by the time you notice, something else is already wrong. APIs sit at the center of most modern applications. They connect frontends, microservices, and third-party integrations. In theory, we…
Read more →
The post Your API A...]]></description>
<link>https://tsecurity.de/de/3536798/it-security-nachrichten/your-api-authentication-isnt-broken-its-quietly-failing-in-these-6-ways/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536798/it-security-nachrichten/your-api-authentication-isnt-broken-its-quietly-failing-in-these-6-ways/</guid>
<pubDate>Thu, 21 May 2026 16:48:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most API authentication setups don’t fail loudly. They fail quietly, and by the time you notice, something else is already wrong. APIs sit at the center of most modern applications. They connect frontends, microservices, and third-party integrations. In theory, we…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-api-authentication-isnt-broken-its-quietly-failing-in-these-6-ways/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-api-authentication-isnt-broken-its-quietly-failing-in-these-6-ways/">Your API Authentication Isn’t Broken; It’s Quietly Failing in These 6 Ways</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt Engineering Isn’t Enough — I Built a Control Layer That Works in Production]]></title>
<description><![CDATA[Most LLM failures in production aren’t random — they’re predictable.
I kept hitting broken JSON, silent failures, and outages that froze my entire app. Prompt engineering didn’t fix it.
So I built a control layer above the model — and took structured output reliability from 0% to 100% without cha...]]></description>
<link>https://tsecurity.de/de/3536251/ai-nachrichten/prompt-engineering-isnt-enough-i-built-a-control-layer-that-works-in-production/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536251/ai-nachrichten/prompt-engineering-isnt-enough-i-built-a-control-layer-that-works-in-production/</guid>
<pubDate>Thu, 21 May 2026 14:03:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most LLM failures in production aren’t random — they’re predictable.<br>
I kept hitting broken JSON, silent failures, and outages that froze my entire app. Prompt engineering didn’t fix it.<br>
So I built a control layer above the model — and took structured output reliability from 0% to 100% without changing a single prompt.</p>
<p>The post <a href="https://towardsdatascience.com/prompt-engineering-isnt-enough-i-built-a-control-layer-that-works-in-production/">Prompt Engineering Isn’t Enough — I Built a Control Layer That Works in Production</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[need papa linus to save us.]]></title>
<description><![CDATA[I always take the surface level complaints about anything linux related with a grain of salt, when i looked at btrfs i saw them. But i wanted that snapshot granularity + compression. So i went for it. There are a lot of uAPI things that are "odd" especially with the whole snapper "make the snapsh...]]></description>
<link>https://tsecurity.de/de/3535017/linux-tipps/need-papa-linus-to-save-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535017/linux-tipps/need-papa-linus-to-save-us/</guid>
<pubDate>Thu, 21 May 2026 06:22:58 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I always take the surface level complaints about anything linux related with a grain of salt, when i looked at btrfs i saw them. But i wanted that snapshot granularity + compression. So i went for it.</p> <p>There are a lot of uAPI things that are "odd" especially with the whole snapper "make the snapshot subvolume then unmount then make it then remount then delete and don't do it wrong or snapper has a stroke" sorcery. I immediately moved to just doing snapshots manually because no way i was going to even touch something that depends on a naming convention to work. </p> <p>I really liked btrfs, i was able to get my sophisticated layout, i do a lot of NPU related low level projects so i have a flat layout with seperate subvolumes for ssh, certain compilers like v++ i will build from source and keep isolated so i can have them out of the equation for a different one path resolution wise. </p> <p>The issue arrived however, when i realized it was just the fact i THOUGHT i liked it because of running btrfs send to my network drive with it as RO, running btrfs receive, then checking that it hit the drive. I mean if you look at a directory and see the file than it's there... one would assume. </p> <p>Suffice to say, one day i checked on the drive to grab a python wheel i knew i had tucked away and had accidentally delete on my test machine. The snapshots just kind of walked away... Like i thought peter dinklage was going to come to me and say the "the file system just... never cared" or some shit. Wasn't an unmounted subvolume, wasn't a userfacing miss. The data was just gone. </p> <p>This brings me to the main point of this post, PLEASE LET OVERSTREET BACK INTO THE MAINLINE EMPEROR LINUS. It truly has boiled down to my issues with it, and just the objective state of the actual btrfs team that all roads lead back to the overstreet. Read the front page to his website and you see exactly the type of shit that is overlooked in btrfs development but is just wrong. "Never writes bad data", things that are just outlook and introspective. But the type where there's objectively correct and then there's stupid </p> <p>Overstreet pushed a filesystem commit for an issue that was seriously important for bcachefs users- because i mean having the kernel doesn't really matter when you have critical filesystem issues that need to be constrained for some autisitc nerds unrelated NPU drivers ( that's me btw, not to demean ). Bcachefs is structurally better than btrfs even as a dkms, but pretty unusable for mainline users. </p> <p>Regardless of it's usage btrfs is still just beating at a dead horse, i do not see why the technically inferior filesystem is being taken seriously when the only reason it's still the COW standard is some maintainers having their feelings hurt. Like idk how anybody could look at that commit past the merge window and not think "oh that'd be a pretty fair exception" </p> <p>What is the general consensus on this one? my bad for the long post, just wanted to make it clear i didn't just hastily snapshot things and send as RW with no btrfs receive being ran- or just anything that isnt in the docs. </p> <p>I say petition to bring/invite Kent Overstreet to come back into the kernel cycle. He's got an ego, he's kind of a douche, but in my opinion even if charles manson was on the prison's kindle E book, rooted it, and was pushing something that showed promise -- id go with it. </p> <p>just overall curious on what the community thinks about this topic, raid 5 coming before the heat death of the universe! </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/PooperLubey"> /u/PooperLubey </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tj9h9e/need_papa_linus_to_save_us/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tj9h9e/need_papa_linus_to_save_us/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mysteriöser “Secure Boot”-Ordner in Windows 11 aufgetaucht: Das steckt dahinter]]></title>
<description><![CDATA[Einige Nutzer haben in den vergangenen Tagen bemerkt, dass nach der Installation des neusten Updates für Windows 11 (KB5089549, das bei einigen noch Probleme verursacht) ein neuer Ordner erscheint. Diesen findet man im Windows-Systemverzeichnis unter dem Namen „SecureBoot“ und es ist zunächst nic...]]></description>
<link>https://tsecurity.de/de/3532821/it-nachrichten/mysterioeser-secure-boot-ordner-in-windows-11-aufgetaucht-das-steckt-dahinter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532821/it-nachrichten/mysterioeser-secure-boot-ordner-in-windows-11-aufgetaucht-das-steckt-dahinter/</guid>
<pubDate>Wed, 20 May 2026 13:46:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Einige Nutzer haben in den vergangenen Tagen bemerkt, dass nach der Installation des neusten Updates für Windows 11 (<a href="https://www.pcwelt.de/article/3143004/sicherheits-update-kb5089549-crasht-windows-microsoft-bestaetigt-problem-und-empfiehlt-diese-loesungen.html" target="_blank" rel="noreferrer noopener">KB5089549, das bei einigen noch Probleme verursacht</a>) ein neuer Ordner erscheint. Diesen findet man im Windows-Systemverzeichnis unter dem Namen „SecureBoot“ und es ist zunächst nicht klar, wofür dieses Verzeichnis gedacht ist.</p>



<p>Wer sich aber zurückerinnert an die Thematik der <a href="https://www.pcwelt.de/article/3033338/wichtige-windows-11-zertifikate-laufen-ab-so-pruefen-sie-secure-boot.html" target="_blank" rel="noreferrer noopener">bald ablaufenden Secure-Boot-Zertifikate</a>, der wird schnell auf die richtige Idee kommen: Der Ordner dient als wichtige Sicherheitsmaßnahme, <a href="https://www.pcwelt.de/article/3059801/alarm-ihr-windows-pc-bekommt-ab-sommer-echte-probleme-secure-boot-zertifikate.html" target="_blank" rel="noreferrer noopener">damit Ihr PC ab Juni keine ernsten Probleme bekommt.</a></p>



<p>Kurz zusammengefasst: Da bei vielen Windows-11-Nutzern Zertifikate für den sicheren Systemstart, also Secure Boot, fehlen, muss Microsoft nachhelfen. Wenn die Zertifikate aus dem Jahr 2011 stammen, sind sie veraltet und werden ab Juni nicht mehr unterstützt. Der PC kann dann nicht mehr den sicheren Systemstart nutzen und ist anfälliger für Angriffe.</p>



<p>Um das zu verhindern, liefert Microsoft nach und nach neuere Zertifikate an Windows-Nutzer aus. Das läuft quasi nebenbei zu den Windows-Updates. Wenn Sie Ihren PC also immer auf dem neuesten Stand halten, ist die Wahrscheinlichkeit groß, dass Sie bis Juni alle nötigen Zertifikate beisammen haben.</p>



<p>Überprüfen lässt sich das auch <a href="https://www.pcwelt.de/article/3123713/diese-neue-anzeige-in-windows-11-verraet-ob-ihnen-wichtige-zertifikate-fehlen.html" target="_blank" rel="noreferrer noopener">über diese neue Anzeige, die Microsoft eingebaut hat.</a>  Damit können Sie den Status von Secure Boot jederzeit überprüfen. Für Admins führt Microsoft jetzt als nächsten Schritt den Secure-Boot-Ordner ein, der dafür sorgen soll, dass auch in Unternehmen alle wichtigen Zertifikate vorhanden sind.</p>



<p>Microsoft schreibt im dazugehörigen <a href="https://support.microsoft.com/de-de/topic/12-mai-2026-kb5089549-betriebssystembuilds-26200-8457-und-26100-8457-28ec2a99-4bbe-481d-a340-5c6cf18d9acb" target="_blank" rel="noreferrer noopener">Support-Dokument</a>:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Dieses Update fügt einen neuen SecureBoot Ordner unter C:\Windows auf berechtigten Geräten hinzu. Der Ordner enthält Beispielskripts für Organisationen mit IT-Experten, die Updates in ihrer Geräteflotte aktiv verwalten. Diese Skripts können verwendet werden, um die Aktualisierung des Zertifikats für den sicheren Startstatus zu erkennen und die Bereitstellung über einen sicheren Rolloutmechanismus in einer Active Directory-Umgebung zu automatisieren. Weitere Informationen finden Sie unter <a href="https://support.microsoft.com/de-de/topic/beispielleitfaden-f%C3%BCr-die-e2e-automatisierung-f%C3%BCr-den-sicheren-start-f850b329-9a6e-40d1-823a-0925c965b8a0">Beispiel für die E2E-Automatisierung für den sicheren Start.</a></p>
</blockquote>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3140667-1-0-0-0-0?x-source=4-0-3142190-1-0-0-0-0?x-source=4-0-3143341-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">Was kann ich mit dem Ordner anfangen?</h2>



<p>Für private Windows-Nutzer ändert sich durch den Ordner erst einmal nichts. Sie müssen nichts damit tun und auch keine Änderungen daran vornehmen. Den Secure-Boot-Ordner einfach zu löschen, ist allerdings auch nicht empfehlenswert, da er eben einen bestimmten Zweck erfüllt.</p>



<p>Die Seite <a href="https://www.windowslatest.com/2026/05/17/microsoft-confirms-the-new-secure-boot-folder-in-windows-11-isnt-a-bug-you-dont-need-to-delete-it/" target="_blank" rel="noreferrer noopener">Windowslatest</a> empfiehlt explizit, den Ordner nicht zu entfernen, da dadurch auch Probleme mit künftigen Windows-Updates entstehen könnten. Etwa wenn nach dem Ordner gesucht wird und eine Fehlermeldung entsteht, weil er nicht auffindbar ist. </p>



<p>Mehr Informationen zur Secure-Boot-Thematik können Sie in unserem Ratgeber nachlesen: <a href="https://www.pcwelt.de/article/3059462/secure-boot-probleme-losen-so-gehts-juni-2026.html" target="_blank" rel="noreferrer noopener">Ihr Windows-PC bekommt ab Juni ernste Probleme – das können Sie tun</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coming Bright Up: Apple’s AI moment looms]]></title>
<description><![CDATA[Apple has confirmed this year’s Worldwide Developers Conference (WWDC) will take place June 8-12. The show begins with a keynote speech likely to be Tim Cook’s final public appearance as Apple’s CEO. His successor, John Ternus, will also be in the spotlight, but perhaps not quite as much as Apple...]]></description>
<link>https://tsecurity.de/de/3529810/it-nachrichten/coming-bright-up-apples-ai-moment-looms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529810/it-nachrichten/coming-bright-up-apples-ai-moment-looms/</guid>
<pubDate>Tue, 19 May 2026 18:18:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple has confirmed this year’s <a href="https://www.apple.com/newsroom/2026/05/apple-kicks-off-worldwide-developers-conference-on-june-8/" target="_blank" rel="noreferrer noopener">Worldwide Developers Conference</a> (WWDC) will take place June 8-12. The show begins with a keynote speech likely to be Tim Cook’s final public appearance as Apple’s CEO. His successor, <a href="https://fortune.com/article/who-is-john-ternus-new-apple-ceo-tim-cook-retirement/" target="_blank" rel="noreferrer noopener">John Ternus</a>, will also be in the spotlight, but perhaps not quite as much as Apple’s promised smart Siri successor.</p>



<p>Getting AI right is <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">incredibly important to the company</a> this year, and Apple seems to recognize that. The <a href="https://www.applemust.com/apple-announces-june-8-wwdc/#google_vignette" target="_blank" rel="noreferrer noopener">official media invitation</a> features a brightly glowing Swift logo with the tagline “<em>Coming Bright Up</em>,” which some see as a hint at the advanced AI capabilities Apple intends making available. It also hints at the new Siri user interface Apple is building, while the use of a Swift suggests the introduction of additional Foundation Models with which developers can add AI tools to their products.</p>



<p>On the developer website, Apple’s media images all show that bright glow, which also hints at potential improvements to <a href="https://www.computerworld.com/article/4100974/there-is-no-dye-in-apples-design-team.html">Liquid Glass</a>. There’s no doubt at all that the entire industry will be tuned into WWDC to find out where Apple is going with AI. So, no pressure there, right?</p>



<h2 class="wp-block-heading"><strong>AI tools developers can use</strong></h2>



<p>The company told developers to expect more than 100 new videos about tools, technologies, and design, many of them to be revealed during the Platforms State of the Union address, which follows the keynote.</p>



<p>“WWDC26 will kick off June 8 with the Keynote and Platforms State of the Union, introducing incredible updates for Apple platforms, including AI advancements and exciting new software and developer tools,” Apple said, announcing the event.</p>



<p>Apple <a href="https://www.computerworld.com/article/4167906/apple-intelligence-hype-cost-the-company-250m.html">knows the world is watching</a> and seems unlikely to want to disappoint its audience again, though the way it framed this in suggests some of the improvements will be for developers, with end users to benefit later. This is the approach Apple has taken with Foundation Models so far, though it isn’t yet clear if the company intends introducing a paid tier of APIs for developers. I’d consider that a risk at this stage, given the perception Apple faces.</p>



<h2 class="wp-block-heading"><strong>What’s at stake?</strong></h2>



<p>A confluence of challenges means Apple is <a href="https://www.computerworld.com/article/4170159/wwdc-from-nextstep-for-apple-to-apples-next-step-for-ai.html">perceived as having fallen behind on AI</a>. That’s got to hurt. The company is under a lot of pressure to push back against that viewpoint, and while that’s a challenge, it’s also a big opportunity. </p>



<p>Wedbush Securities analyst <a href="https://www.investors.com/research/ibd-stock-of-the-day/apple-stock-buy-zone-wwdc-2026/" target="_blank" rel="noreferrer noopener">Dan Ives</a> says Apple is a “sleeping tech giant” poised for growth if it gets the mix right, predicting the company’s ecosystem could become the “consumer hub” of AI, to the extent that 20% of the global population will use Apple to access it. At Morgan Stanley, analyst Erik Woodring thinks what Apple is about to introduce will prompt a mass upgrade and sees revenue potential in AI services for the company. In general, people seem to agree that Apple’s ecosystem is more than capable of handling the demands of AI; the challenge is properly integrating it within Apple’s environment.</p>



<h2 class="wp-block-heading"><strong>What is Apple Planning?</strong></h2>



<p>At the moment, <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">strong speculation suggests</a> Apple has added new Writing Tools, improved image generation on its devices, and has worked with Google Gemini to extend the number of available APIs developers can use, as well as enhancing contextual understanding by Siri.</p>



<p>Any one of these things would have impressed us all at one time, but in an AI world of Claude, Gemini, or even Grok, some will likely see even these enhancements as weak sauce. Additional key expectations include:</p>



<ul class="wp-block-list">
<li>Siri will become a chatbot-style assistant in the form of an LLM-enhanced app, built in partnership with Google Gemini.</li>



<li>Apple will <a href="https://www.computerworld.com/article/4171288/apples-app-store-model-for-ai.html">give users a choice of AI apps</a>, including the ability to make whatever they choose the default on their system.</li>



<li>Siri will gain a new interface hosted in the Dynamic Island on devices that support it.</li>



<li>Siri might also gain the ability to string instructions together using a combination of text/speech and Shortcuts abilities. </li>



<li>You should see improved contextual awareness; Siri will be able to “see’”what’s on your screen and take relevant actions across one or more third-party apps.</li>



<li>Those functions are likely to be delivered by App Intents, which permits developers to make app functions available across the system without opening the apps.</li>



<li>Visual Intelligence will let the iPhone camera app identify more options, including objects and passes, such as for events and public transit.</li>



<li>Multitasking on iPads should improve, while macOS might gain some touch-based interface improvements. That could set the scene for better integration between iPad and Mac, and, of course, make a touchscreen Mac possible.</li>
</ul>



<p>Most recently, there’s been chatter about Apple introducing an iMac equipped with an M5 processor. If so, this could emerge at, or slightly before, WWDC.</p>



<p>As it does each year, the conference will feature the Apple Design Awards, Swift Student Challenge, Labs, and an in-person, 1,000 people gathering in Cupertino for the keynote. </p>



<h2 class="wp-block-heading"><strong>Watch it in real time</strong></h2>



<p>The keynote will be available to stream on Apple’s website. It will also be hosted on the Apple TV app and Apple’s YouTube channel, with playback on-demand after the event.</p>



<p><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  LinkedIn, and <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[They Didn’t Hack You. They Hacked What You Trust.]]></title>
<description><![CDATA[Picture this.It is a Tuesday morning. Your team’s CI pipeline runs as normal. Tests pass. Build succeeds. Code ships to production. Nothing looks wrong.But somewhere in that build, tucked inside a package your app has depended on for years, a tiny script quietly ran. It read your environment vari...]]></description>
<link>https://tsecurity.de/de/3528502/hacking/they-didnt-hack-you-they-hacked-what-you-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528502/hacking/they-didnt-hack-you-they-hacked-what-you-trust/</guid>
<pubDate>Tue, 19 May 2026 11:23:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Aixf8Zf7UoIujQ2mskKzJA.png"></figure><h4>Picture this.</h4><p>It is a Tuesday morning. Your team’s CI pipeline runs as normal. Tests pass. Build succeeds. Code ships to production. Nothing looks wrong.</p><p>But somewhere in that build, tucked inside a package your app has depended on for years, a tiny script quietly ran. It read your environment variables. It copied your cloud credentials. It sent them — over an encrypted connection — to a server in Eastern Europe.</p><blockquote>You didn’t get hacked. Your dependency did. And that’s exactly the point.</blockquote><p>In December 2020, the US Treasury, the Pentagon, and over 18,000 other organizations were breached in what became known as the SolarWinds attack. The attackers didn’t brute-force any passwords. They didn’t exploit a zero-day vulnerability. They simply slipped a backdoor into a legitimate software update — one that all of these organizations automatically downloaded and trusted because it came from a vendor they had been using for years.</p><blockquote>Fast forward to early 2026. The same playbook, now running at internet speed.</blockquote><p>The axios library — a tool used to make web requests, downloaded <strong>100 million times every single week</strong> — was hijacked by a state-sponsored group. A remote access trojan (think: a hidden door into your computer that lets someone else walk in and look around) was quietly dropped onto every machine that ran npm install axios.</p><p>Around the same time, a popular VS Code extension called cline published version 2.3.0. Buried inside it was a silent instruction to install a second piece of software called openclaw — a credential harvester that hunted for passwords, API keys, and SSH keys on the developer's machine. No mention of this in the release notes.</p><p>And then there was Mini Shai-Hulud — a self-spreading worm (a program that copies itself from machine to machine automatically) that began bouncing between CI pipelines (the automated systems that build and deploy code). It hit TanStack, Mistral AI, UiPath, and others in a single wave, each one becoming the launchpad for the next infection.</p><p>None of these victims were careless. They were doing exactly what modern software development demands: building on open source, automating their pipelines, moving fast.</p><p>That is what makes supply chain attacks so insidious. And so important to understand — whether you write code for a living or you lead the people who do.</p><h3>The One Idea That Explains Everything</h3><p>Here is the core concept, in plain English:</p><blockquote><strong><em>Attackers don’t target you directly. They compromise something you already trust — so that you deliver the attack to yourself.</em></strong></blockquote><p>This is not a new idea. It exists in every industry.</p><p>The 2008 melamine-in-milk scandal in China wasn’t a problem with the brands on supermarket shelves. It was a problem at the bulk ingredient supplier, many steps upstream. Every brand that sourced from that supplier became a victim — and so did every consumer who bought from those brands. Nobody targeted them specifically. The supply chain did the work.</p><p>In software, your “supply chain” is every library, tool, and service your code depends on. And those dependencies have their own dependencies. And those have more. By the time you reach the bottom of that tree, you are implicitly trusting hundreds — sometimes thousands — of people and organizations you have never heard of.</p><h3>How the Attack Actually Works</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*F2Bp1cyaTmiKxVKKmnvBcA.png"><figcaption><em>The full attack surface — from source code to production. Every stage is a potential entry point.</em></figcaption></figure><p>The diagram above maps the typical software supply chain: from the moment a developer writes code, through building and packaging it, storing it in a registry, distributing it as a dependency, integrating it into other projects, and finally running it in production.</p><p>Attackers look at this chain and ask a simple question: <em>where is the easiest place to get in?</em></p><p>The answer is almost never “the final target.” It is almost always somewhere in the middle — a trusted supplier, a shared tool, a package registry.</p><p>The attack pattern, once you see it, is everywhere:</p><p><strong>Step 1 — Compromise.</strong> Find a weak link. Maybe a package maintainer left their npm login token in a public GitHub repository. Maybe an open source project hasn’t had an active maintainer in two years and someone can simply request ownership. Maybe a CI system is configured to trust any code from a contributor without review. The barrier to entry is often astonishingly low.</p><p><strong>Step 2 — Poison it.</strong> Add something malicious. Usually this hides in a postinstall script — a feature that lets packages run code automatically the moment you install them, with no confirmation prompt. The axios attack used this to drop a Remote Access Trojan. The cline attack used it to install a credential harvester. The code is typically obfuscated (deliberately scrambled to be hard to read) and the changes are buried in files most developers never look at.</p><p><strong>Step 3 — Let the supply chain distribute it.</strong> Do nothing. The package registry, the CDN, the automated update system — all the infrastructure everyone already trusts — does the distribution for you. The package has a valid version number. It passes the usual checks. It downloads normally. Millions of npm install commands do the rest.</p><p><strong>Step 4 — Impact thousands at once.</strong> One poisoned package. One upstream compromise. Thousands of victims who never made a single mistake. The attack scales automatically because the supply chain scales automatically.</p><h3>The Six Places Attackers Actually Strike</h3><p>Most security thinking focuses on <em>your</em> code. Supply chain attacks succeed because the real attack surface is much wider.</p><p><strong>Your code and dependencies</strong> are the obvious starting point — open source packages, third-party libraries. But attackers also exploit typosquatting: publishing a package called crossenv knowing that some developers will mistype the real package name cross-env. Download it once and you've invited malware in.</p><p><strong>Your build system and CI/CD pipeline</strong> (the automated system that compiles, tests, and deploys your code) is arguably the highest-value target. This is where OIDC tokens live — temporary credentials that grant the ability to publish packages. Steal one of these and you can publish a malicious version of a legitimate package <em>as the legitimate author</em>, with all the credibility that implies.</p><p><strong>Package registries</strong> like npm and PyPI are where trust gets encoded. A package published without provenance attestation (a cryptographic record of exactly where and how it was built) is a package that could have come from anywhere.</p><p><strong>Distribution channels</strong> — the update servers, mirrors, and download endpoints — are where one compromise becomes many victims. This is the SolarWinds mechanism: poison the distribution point and everyone downstream is automatically exposed.</p><p><strong>Your deployment infrastructure</strong> — the cloud credentials, the configuration secrets, the IaC (Infrastructure as Code) templates that describe your entire cloud environment — is often where the real prize sits. Once an attacker is inside your CI pipeline, they can reach all of this.</p><p><strong>Third-party services</strong> — the monitoring tools, the identity providers, the SaaS integrations — represent a sprawling surface area that most organizations have almost no visibility into. A compromised logging service could be reading everything that flows through it.</p><h3>The Worm That Changed the Rules</h3><p>The Mini Shai-Hulud attack deserves its own moment because it represents a genuinely new and alarming capability.</p><p>Traditional supply chain attacks require a human attacker to take action at each step: steal a token, publish a malicious package, wait for victims to install it. The attack spreads as far as that package’s install base — then stops.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Mj5Ht1lHV8IJK3t2STpcow.png"></figure><p>Mini Shai-Hulud automated the entire loop:</p><ol><li>The worm installs on a developer machine or CI runner</li><li>It steals the OIDC token from the CI environment</li><li>It uses that token to find all packages the victim has permission to publish</li><li>It injects itself into those packages and publishes new malicious versions automatically</li><li>Every developer who installs those packages becomes the next host — and their CI token becomes the next weapon</li></ol><p>The worm spreads itself. Each new victim is automatically turned into an attacker.</p><p>What made this particularly alarming to security researchers: the worm produced packages with valid <strong>SLSA Build Level 3 provenance attestations</strong>. SLSA (Supply chain Levels for Software Artifacts) is the gold standard for supply chain integrity — it’s a cryptographic proof that a package was built in a specific, verified way. It’s supposed to be the highest level of assurance you can have.</p><p>The worm bypassed it. Completely. Because it had stolen legitimate credentials and used a legitimate pipeline to build the package. The attestation said “this package is authentic.” It was right. It was authentically malicious.</p><p>This is the most important lesson in this entire article: <strong>a signature tells you where something came from. It doesn’t tell you whether it’s safe.</strong> Provenance verification and runtime behavioral monitoring are not substitutes for each other. You need both.</p><h3>What Good Defense Actually Looks Like</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Te55cng_HIsusJNLonbgHA.png"><figcaption><em>A practical defense framework for organizations — from inventory to incident response.</em></figcaption></figure><p>The defense framework above is built around a simple idea: <strong>you cannot defend what you cannot see, and you cannot respond to what you cannot detect.</strong></p><p>Here is how to think through each layer.</p><h3>Know what you’re running</h3><p>The first step — and the one most organizations skip — is building a <strong>Software Bill of Materials (SBOM)</strong>. Think of this as an ingredients list for your software: every library, every package, every tool your application depends on, including all the indirect dependencies (the dependencies of your dependencies, and so on, sometimes dozens of layers deep).</p><p>Without an SBOM, you are essentially running a kitchen without knowing what is in your pantry. You cannot check whether an ingredient has been recalled if you don’t know it’s there.</p><p>Tools like syft or GitHub's dependency graph can generate this automatically. It is not glamorous work, but it is the foundation of everything else.</p><h3>Assess what is risky</h3><p>Not all dependencies carry equal risk. A package maintained by one person, last updated three years ago, with 50 million weekly downloads, is a high-value target — attractive to attackers precisely because of its reach and low security maturity.</p><p>Look specifically for packages that publish via manual token rather than <strong>Trusted Publishing</strong> (where the publishing credential is generated automatically by the CI system and only valid for a single session, making stolen tokens much less useful). Every package in your dependency tree that publishes manually is a package where a stolen password immediately becomes your problem.</p><h3>Harden your build</h3><p>Three concrete changes that most teams haven’t made:</p><p>Use <strong>npm ci</strong> instead of npm install in your CI pipeline. The difference: npm install can update packages if a newer version is available. npm ci installs exactly what is in your lockfile, nothing more, nothing less. It will fail loudly if anything doesn't match. This alone would have blocked several of the attacks described in this article.</p><p>Use <strong>--ignore-scripts</strong> when installing packages. This flag tells npm to skip postinstall scripts — the most common mechanism for hiding malicious code. Most packages don't need to run scripts on install. The ones that do can be explicitly whitelisted.</p><p><strong>Pin your GitHub Actions to a full commit SHA.</strong> GitHub Actions (the automation steps in your CI pipeline) are themselves packages. A version tag like v3 can be silently changed by the action's author to point to different code. A commit SHA like abc123def456... is immutable — it will always refer to exactly the same code it referred to when you pinned it.</p><h3>Deploy runtime detection</h3><p>This is the most underused defense in the toolkit, and the most reliably effective.</p><p><strong>StepSecurity’s Harden-Runner</strong> is an open source GitHub Action that monitors all outbound network connections made by your CI pipeline during a run. It was the first system to detect the axios attack — by flagging an unexpected outbound connection to sfrclak.com seconds after npm install ran in CI. That one signal, in real time, was the earliest warning anyone had that something was wrong.</p><p>The principle is straightforward: if your CI pipeline is building code, it should be talking to known endpoints — your package registry, your artifact storage, your deployment target. It should not be calling home to a domain you have never seen before. A strict network egress policy (a list of allowed outbound destinations) combined with runtime monitoring turns invisible attacks into loud alerts.</p><h3>Have a response plan before you need one</h3><p>When — not if — something gets through, the difference between a minor incident and a major breach is often measured in minutes.</p><p>Know in advance:</p><ul><li>Who gets paged when an unexpected outbound connection is detected?</li><li>How do you rotate all credentials in the affected environment?</li><li>How do you pin downstream consumers to a safe package version?</li><li>How do you communicate to users who may be affected?</li></ul><p>Running through this for the first time during an active incident is the worst possible time to figure it out.</p><h3>The Cross-Cutting Controls</h3><p>Some defenses don’t belong to any single step. They have to run everywhere, all the time.</p><p><strong>Least privilege</strong> means every credential, every token, every permission should be scoped to the minimum required. Your CI job that runs tests does not need permission to publish packages. A developer’s local npm account should not have admin rights on the organization. Every unnecessary permission is a potential pivot point.</p><p><strong>MFA on everything that publishes.</strong> Multi-factor authentication on npm, PyPI, GitHub — any account that can push code or release a package. This is the single cheapest control relative to the attack surface it closes. The cline attack worked because a maintainer account was compromised. MFA would have been a significant barrier.</p><p><strong>Secret scanning</strong> on every commit. Tools like GitHub’s built-in secret scanner or truffleHog automatically flag credentials that appear in source code. A token committed even briefly — even to a private repository — must be treated as compromised and rotated immediately.</p><p><strong>A dependency cooldown policy.</strong> The Mini Shai-Hulud worm published malicious versions and had them installed by CI pipelines within minutes, because those pipelines were configured to always use the latest version. A simple rule — don’t automatically upgrade to a package version published in the last 24 hours — would have dramatically slowed the spread.</p><h3>The Five Principles Worth Pinning Up</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nsUo3dC3bhqh8UcozcRW4Q.png"></figure><p><strong>Assume breach.</strong> Not “this might happen someday.” Assume it has already happened, or will happen soon, and build your detection and response accordingly. The organizations that fared best in the SolarWinds attack were not the ones who thought they were impenetrable — they were the ones who had strong detection, segmentation, and recovery capabilities.</p><p><strong>Defence in depth.</strong> No single control is sufficient. SLSA was bypassed. Signatures can be faked. Package reviews miss obfuscated code. The teams that caught the Mini Shai-Hulud worm early were running multiple independent layers — lockfiles, runtime EDR, network egress controls, anomaly alerts. Each layer could be bypassed individually. Together, they created enough signal to catch the attack before significant damage occurred.</p><p><strong>Least privilege is a habit, not a one-time setting.</strong> It has to be the default for every new token, every new integration, every new workflow. Start with zero permissions and add only what is explicitly needed.</p><p><strong>Transparency beats obscurity.</strong> Share your SBOM. Publish your security posture. The open source packages that recovered fastest from supply chain incidents were the ones with clear ownership, active maintainers, and public security policies — because the community could identify and help remediate faster.</p><p><strong>Evolve continuously.</strong> The threat landscape is moving faster than any fixed checklist can keep up with. Quarterly dependency audits, post-incident reviews, threat intelligence subscriptions — these are ongoing habits, not one-time projects.</p><h3>What This Means for You</h3><p>If you lead an engineering team or a technology organization, the honest message is this: your security posture is only as strong as the least-scrutinized package in your dependency tree.</p><p>That is not a criticism. It is the structural reality of how modern software is built. We stand on top of an enormous mountain of open source code, and that is mostly a wonderful thing — it lets small teams build things that would have required hundreds of engineers a decade ago.</p><p>But that mountain has cracks in it. And attackers have learned exactly where to look.</p><p>The good news: the gap between “doing nothing” and “meaningfully protected” is not as large as it feels. Three things, done well, would have caught or blocked most of the attacks described in this article:</p><ol><li><strong>An SBOM</strong> — so you know what you are running</li><li><strong>Harden-Runner on every CI workflow</strong> — so you know what your pipelines are doing at runtime</li><li><strong>Lockfiles + </strong><strong>npm ci + </strong><strong>--ignore-scripts</strong> — so an upstream change cannot silently slip into your build</li></ol><p>Start there. Then work outward through the framework in Image 2.</p><p>The attackers are not waiting for you to be ready. But they are counting on you to keep trusting things you have never verified.</p><p><em>The incidents referenced in this article — SolarWinds (2020), axios npm hijack (2026), cline@2.3.0 (2026), Mini Shai-Hulud self-spreading worm (2026) — are all documented public cases. Detection of the axios and cline attacks is credited to StepSecurity’s Harden-Runner. Research on the Mini Shai-Hulud worm is credited to StepSecurity and the broader npm security community.</em></p><p><strong>Tags:</strong> Supply Chain Security · DevSecOps · npm · Open Source · Cybersecurity · Engineering Leadership</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=aa08997e346a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/they-didnt-hack-you-they-hacked-what-you-trust-aa08997e346a">They Didn’t Hack You. They Hacked What You Trust.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An AI data center in your home?]]></title>
<description><![CDATA[As CNBC recently reported, some of the resistance to large AI data center construction is pushing the market to consider a more distributed model, including small compute systems designed for residential settings. The story pointed to pilot-stage thinking among companies such as PulteGroup, Nvidi...]]></description>
<link>https://tsecurity.de/de/3528427/ai-nachrichten/an-ai-data-center-in-your-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528427/ai-nachrichten/an-ai-data-center-in-your-home/</guid>
<pubDate>Tue, 19 May 2026 11:02:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As <a href="https://www.cnbc.com/2026/05/09/ai-data-center-construction-public-opposition.html" data-type="link" data-id="https://www.cnbc.com/2026/05/09/ai-data-center-construction-public-opposition.html">CNBC recently reported</a>, some of the resistance to large AI data center construction is pushing the market to consider a more distributed model, including small compute systems designed for residential settings. The story pointed to pilot-stage thinking among companies such as PulteGroup, Nvidia, and Span, suggesting this is no longer just a home-lab fantasy or a fringe edge-computing thought experiment. It is now credible enough to be discussed by experts in housing, energy management, and economic infrastructure. It’s certainly not mainstream, but it is worth serious examination.</p>



<h2 class="wp-block-heading">Economic forces at work</h2>



<p>The timing is not accidental. Homes are expensive, especially for those who bought at the elevated prices and interest rates of late. Mortgage payments are a heavy burden; insurance and taxes continue to climb. In this housing market, homeowners are increasingly interested in turning underutilized parts of their properties into sources of recurring income. Spare rooms have become short-term rentals. Garages have become workshops or accessory units. Rooftops have become solar assets. Now, major players in the housing market are considering basements, utility rooms, and detached structures as potential spaces for small-scale server <a href="https://www.infoworld.com/article/2255598/what-is-iaas-your-data-center-in-the-cloud.html">infrastructure</a>.</p>



<p>At the same time, businesses are under pressure to rethink where compute lives. <a href="https://www.infoworld.com/article/4061121/a-brief-history-of-ai.html">AI</a> is increasing the demand for processing capacity. <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">Edge workloads</a> continue to grow. Not every application needs to run in a hyperscale facility, and not every business wants to pay for hyperscale economics. There is a strategic appeal to pushing workloads closer to users or into lower-cost, more widely distributed locations. Residential hosting becomes one possible answer to a question the industry is already asking: How much infrastructure can be decentralized without losing economic and operational control?</p>



<p>There is also a cultural shift at work. More technically capable homeowners now understand racks, uninterruptible power supply systems, network monitoring, remote access, and even local power upgrades. The old gap between enterprise infrastructure knowledge and prosumer infrastructure knowledge has narrowed. That makes the idea feel more achievable, even if the barriers to doing it commercially remain substantial.</p>



<h2 class="wp-block-heading">Business models taking shape</h2>



<p>The most important point to understand is that there is not yet a large, polished market in which random homeowners openly host random third-party servers the way people list rooms on Airbnb. What does exist are several adjacent business models that point in that direction without fully embracing the concept of residential colocation.</p>



<p>One model is the controlled edge-host program. In this arrangement, a company places or manages compute equipment in selected distributed locations, often with strict standards for connectivity, power, and maintenance. The homeowner or site operator is not acting as an open colocation provider. Instead, they participate in a curated hosting network where the provider controls the service architecture.</p>



<p>Another model is the decentralized compute marketplace. These platforms allow individuals or smaller operators to sell spare compute capacity from their own hardware. This is closer to the economics of monetizing residential infrastructure. Still, it is not the same as taking custody of someone else’s physical server and being responsible for the environment in which it runs. Selling compute cycles is one thing. Housing enterprise hardware is another.</p>



<p>A third model is the traditional infrastructure broker or marketplace. These companies already match buyers and sellers for colocation, bare-metal, and related services. They are proof that brokering infrastructure relationships is a viable business. But those relationships generally connect enterprises to professional facilities, not to homeowners willing to make room for a small server farm next to their furnace or water heater.</p>



<p>In other words, the components of a market are visible. Distributed demand exists. Brokering exists. Willing hosts likely exist. But the residential version remains incomplete because the trust, standardization, and liability models are still underdeveloped.</p>



<h2 class="wp-block-heading">The upside is obvious</h2>



<p>The strongest positive component of this potential market is its financial aspect. If a homeowner can generate enough monthly income to offset part of a mortgage payment, the idea will always attract attention, especially in newer housing markets, where monthly carrying costs are high, and people are seeking durable sources of supplemental income. Hosting infrastructure sounds like, at least in theory, a more stable and less socially intrusive way to monetize a property than opening a home to a constant stream of short-term tenants.</p>



<p>There is also an argument for asset utilization. Many homes contain underused spaces that could produce some economic return. A basement corner, a detached workshop, or a dedicated utility room may be worthless from a revenue perspective until someone turns it into something productive. If infrastructure providers are willing to pay for access to space, power, and connectivity, the home begins to function as part of the digital economy rather than simply as shelter.</p>



<p>For businesses, the appeal is equally straightforward. Residential locations may offer lower real estate costs, faster deployment, and better geographic distribution for select workloads. In regions with relatively inexpensive electricity and strong connectivity, a modest amount of residential hosting could fill gaps that do not warrant full commercial data center expansion. Homes will not replace data centers; rather, they might, in a very narrow set of circumstances, complement them.</p>



<h2 class="wp-block-heading">The downsides are everything else</h2>



<p>The problem with the whole idea is that the negatives are significant. Residential power is not data center power. Residential broadband is not enterprise-grade networking. A private home is not a secure, redundant, environmentally controlled facility, no matter how carefully a rack is installed.</p>



<p>Power is the first issue. Most homes are not designed to handle sustained commercial server loads without electrical upgrades. These upgrades can be expensive, heavily regulated, and dependent on local utility cooperation. Once backup batteries, uninterruptible power supply systems, cooling equipment, and dedicated circuits are added, the project starts to look less like a side hustle and more like a facilities operation.</p>



<p>Heat and noise follow quickly. Commercial hardware generates both continuously, which affect the comfort of the house, the cost of climate control, and the long-term reliability of the equipment. It also transforms residential life. Maintenance becomes routine. Monitoring becomes constant. The house begins to absorb the rhythm of an always-on machine room.</p>



<p>Then come the risks that stall many otherwise creative ideas. Fire hazards. Water damage. Physical theft. Tampering. Insurance complications. Zoning restrictions. HOA objections. Lease restrictions for tenants. Questions about who can access the equipment and when. Liability if a customer’s hardware is damaged. Compliance concerns if sensitive data or regulated workloads are involved. All of these factors are manageable in theory, but they are precisely why professional facilities exist.</p>



<p>Customer trust may be the biggest obstacle of all. Most businesses are comfortable buying compute from a recognized provider because they assume a predictable operating environment. That assumption weakens significantly when the infrastructure sits in a private residence. Who is responsible during an outage? What happens if there is a storm, a flood, or a neighborhood power event? How is physical access controlled? How are incidents documented? Those questions are not edge cases. They determine the model’s viability.</p>



<h2 class="wp-block-heading">What is realistic from here?</h2>



<p>Residential data hosting is unlikely to become the next mainstream large-scale hosting model. The economics of professional data centers still win in most situations because those facilities were built to solve exactly the problems that home models will struggle to address. Reliability, security, redundancy, and customer assurance are difficult and expensive to achieve. Purpose-built environments handle them better.</p>



<p>Still, the concept should not be dismissed outright. In some parts of the country, there may be a path forward. Cheap power. Upgradeable electrical service. Strong broadband. Detached or isolated space. Favorable local rules. Workloads that benefit from geographic distribution and do not require pristine enterprise conditions. In those scenarios, carefully managed micro-hosting could make sense.</p>



<p>That is probably the realistic future. Not an Airbnb for random servers. Not whole neighborhoods that are converted into basement data centers. Instead, a selective market where curated providers match specific homeowners or small properties with specific infrastructure needs under tightly controlled terms. What will start as a niche could still be enough to matter.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Master's Degree Isn't the Job Guarantee It Used To Be]]></title>
<description><![CDATA[An anonymous reader quotes a report from the Wall Street Journal: Going back to grad school has long been the Plan B of young professionals who aspire to climb higher in their careers or struggle to get promoted in a tough job market. New data show that getting a master's degree isn't the guarant...]]></description>
<link>https://tsecurity.de/de/3527022/it-security-nachrichten/a-masters-degree-isnt-the-job-guarantee-it-used-to-be/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527022/it-security-nachrichten/a-masters-degree-isnt-the-job-guarantee-it-used-to-be/</guid>
<pubDate>Mon, 18 May 2026 20:07:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from the Wall Street Journal: Going back to grad school has long been the Plan B of young professionals who aspire to climb higher in their careers or struggle to get promoted in a tough job market. New data show that getting a master's degree isn't the guarantee it used to be. The unemployment rate for workers under 35 with a master's degree has rarely been higher in the past 20 years, according to the Burning Glass Institute, a labor-market think tank focused on the future of work, which analyzed data collected by the U.S. Bureau of Labor Statistics going back to 2003.
 
At the same time, the unemployment rate for workers under 35 with a Ph.D., law degree or medical degree has rarely been lower. "For most of the past two decades, these lines moved together -- not anymore," said Gad Levanon, chief economist of Burning Glass. Levanon has a theory about why the payoffs for advanced degrees have uncoupled: "More degrees chasing fewer of the positions those degrees were meant to unlock." [...] While degrees from law school and medical school amount to a license to practice, master's degrees are more of a signal, Levanon said. And a signal loses value when so many people have one, he added: "It's hardly a sure bet to securing a good job."
 
Now master's-degree holders under 35 are at the 77th percentile of unemployment, where the 50th percentile is normal, according to the Burning Glass analysis. Even associate-degree holders have had a higher employment level for the past year. Unemployment among master's-degree holders has been worse only about a quarter of the time in the past 20-plus years. There was a stint during the Covid-19 pandemic when this cohort was out of work at higher rates, and a more prolonged stretch as the U.S. climbed out of the recession in 2008 and 2009. "Every indication is hiring managers now are more receptive than ever to the idea that a person doesn't need a graduate degree to be competitive," said Johnny C. Taylor Jr., president of SHRM, the chief lobbying group for human-resource professionals.
 
"We are seeing that, hands down, especially in the last two or three years with AI," he said of job readiness. Employers just want to know, "Can you do it?"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=A+Master's+Degree+Isn't+the+Job+Guarantee+It+Used+To+Be%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F18%2F1656217%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F18%2F1656217%2Fa-masters-degree-isnt-the-job-guarantee-it-used-to-be%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/05/18/1656217/a-masters-degree-isnt-the-job-guarantee-it-used-to-be?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft confirms the new Secure Boot folder in Windows 11 isn’t a bug, you don’t need to delete it]]></title>
<description><![CDATA[New “SecureBoot” folder created by Windows 11 KB5089549 is expected behavior for Secure Boot certificates update and not a known issue.
The post Microsoft confirms the new Secure Boot folder in Windows 11 isn’t a bug, you don’t need to delete it appeared first on Windows Latest]]></description>
<link>https://tsecurity.de/de/3524204/windows-tipps/microsoft-confirms-the-new-secure-boot-folder-in-windows-11-isnt-a-bug-you-dont-need-to-delete-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3524204/windows-tipps/microsoft-confirms-the-new-secure-boot-folder-in-windows-11-isnt-a-bug-you-dont-need-to-delete-it/</guid>
<pubDate>Sun, 17 May 2026 20:24:49 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New “SecureBoot” folder created by Windows 11 KB5089549 is expected behavior for Secure Boot certificates update and not a known issue.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/05/17/microsoft-confirms-the-new-secure-boot-folder-in-windows-11-isnt-a-bug-you-dont-need-to-delete-it/">Microsoft confirms the new Secure Boot folder in Windows 11 isn’t a bug, you don’t need to delete it</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pandas Isn’t Going Anywhere: Why It’s Still My Go-To for Data Wrangling]]></title>
<description><![CDATA[Billions of rows might be the exception, but for everything else, Pandas is still a highly reliable tool.
The post Pandas Isn’t Going Anywhere: Why It’s Still My Go-To for Data Wrangling appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3523918/ai-nachrichten/pandas-isnt-going-anywhere-why-its-still-my-go-to-for-data-wrangling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3523918/ai-nachrichten/pandas-isnt-going-anywhere-why-its-still-my-go-to-for-data-wrangling/</guid>
<pubDate>Sun, 17 May 2026 17:02:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Billions of rows might be the exception, but for everything else, Pandas is still a highly reliable tool.</p>
<p>The post <a href="https://towardsdatascience.com/pandas-isnt-going-anywhere-why-its-still-my-go-to-for-data-wrangling/">Pandas Isn’t Going Anywhere: Why It’s Still My Go-To for Data Wrangling</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The enterprise risk nobody is modeling: AI is replacing the very experts it needs to learn from]]></title>
<description><![CDATA[For AI systems to keep improving in knowledge work, they need either a reliable mechanism for autonomous self-improvement or human evaluators capable of catching errors and generating high-quality feedback. The industry has invested enormously in the first. It's giving almost no thought to what's...]]></description>
<link>https://tsecurity.de/de/3522771/it-nachrichten/the-enterprise-risk-nobody-is-modeling-ai-is-replacing-the-very-experts-it-needs-to-learn-from/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3522771/it-nachrichten/the-enterprise-risk-nobody-is-modeling-ai-is-replacing-the-very-experts-it-needs-to-learn-from/</guid>
<pubDate>Sun, 17 May 2026 00:17:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For <a href="https://venturebeat.com/infrastructure/intent-based-chaos-testing-is-designed-for-when-ai-behaves-confidently-and-wrongly?_gl=1*11n0mtp*_up*MQ..*_ga*NTg2MjM1NTE0LjE3Nzg5NjQ5NzA.*_ga_SCH1J7LNKY*czE3Nzg5NjQ5NjkkbzEkZzAkdDE3Nzg5NjQ5NjkkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3Nzg5NjQ5NjkkbzEkZzAkdDE3Nzg5NjQ5NjkkajYwJGwwJGgw">AI systems</a> to keep improving in knowledge work, they need either a reliable mechanism for autonomous self-improvement or human evaluators capable of catching errors and generating high-quality feedback. The industry has invested enormously in the first. It's giving almost no thought to what's happening to the second.</p><p>I’d argue that we need to treat the human evaluation problem with just as much rigor and investment as we put into building the model capabilities themselves. New grad hiring at major tech companies has <a href="https://fortune.com/2025/08/15/ai-gutting-next-generation-of-talent/"><u>dropped by half since 2019</u></a>. Document review, first-pass research, data cleaning, code review: Models handle these now. The economists tracking this call it displacement. The companies doing it call it efficiency. Neither are focusing on the future problem.</p><h2><b>Why self-improvement has limits in knowledge work</b></h2><p>The obvious pushback is reinforcement learning (RL). AlphaZero learned Go, chess, and Shogi at superhuman levels without human data and generated novel strategies in the process. Move 37 in the 2016 match against Lee Sedol, a move professionals said they would never have played, didn't come from human annotation. It emerged from AI self-play. </p><p>What enables this is the stability of the environment. Move 37 is a novel move within the fixed state space of Go. The rules are complete, unambiguous, and permanent. More importantly, the reward signal is perfect: Win or lose, and immediate, with no room for interpretation. The system always knows whether a move was good because the game eventually ends with a clear result.</p><p>Knowledge work doesn't have either of those properties. The rules in any professional domain are dynamic and continuously rewritten by the humans operating in them. New laws get passed. New financial instruments are invented. A legal strategy that worked in 2022 may fail in a jurisdiction that has since changed its interpretation. Whether a medical diagnosis was right may not be known for years. Without a stable environment and an unambiguous reward signal, you cannot close the loop. You need humans in the evaluation chain to continue teaching the model.</p><h2><b>The formation problem</b></h2><p>The AI systems being built today were trained on the expertise of people who went through exactly that formation. The difference now is that entry-level jobs that develop such expertise were automated first. Which means the next generation of potential experts is not accumulating the <a href="https://medium.com/@ahmad.al.dahle/the-future-of-software-engineering-isnt-what-you-think-96abb293d70a"><u>kind of judgment</u></a> that makes a human evaluator worth having in the loop.</p><p>History has examples of knowledge dying. Roman concrete. Gothic construction techniques. Mathematical traditions that took centuries to recover. But in every historical case, the cause was external: Plague, conquest, the collapse of the institutions that hosted the knowledge. What's different here is that no external force is required. Fields could atrophy not from catastrophe but from a thousand individually rational economic decisions, each one sensible in isolation. That's a new mechanism, and we don't have much practice recognizing it while it's happening.</p><h2><b>When entire fields go quiet</b></h2><p>At its logical limit, this isn’t just a pipeline problem. It’s a <a href="https://venturebeat.com/security/ai-tool-poisoning-exposes-a-major-flaw-in-enterprise-agent-security?_gl=1*11n0mtp*_up*MQ..*_ga*NTg2MjM1NTE0LjE3Nzg5NjQ5NzA.*_ga_SCH1J7LNKY*czE3Nzg5NjQ5NjkkbzEkZzAkdDE3Nzg5NjQ5NjkkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3Nzg5NjQ5NjkkbzEkZzAkdDE3Nzg5NjQ5NjkkajYwJGwwJGgw">demand collapse</a> for the expertise itself.</p><p>Consider advanced mathematics. It doesn’t atrophy because we stop training mathematicians. It atrophies because organizations stop needing mathematicians for their day-to-day work, the economic incentive to become one disappears, the population of people who can do frontier mathematical reasoning shrinks, and the field’s capacity to generate novel insight quietly collapses. The same logic applies to coding. Our question is not “will AI write code” but “if AI writes all production code, who develops the deep architectural intuition that produces genuinely novel systems design?” </p><p>There is a critical difference between a field being automated and a field being understood. We can automate a huge amount of structural engineering today, but the abstract knowledge of why certain approaches work lives in the heads of people who spent years doing it wrong first. If you eliminate the practice, you don’t just lose the practitioners. You lose the capacity to know what you’ve lost.</p><p>Advanced mathematics, theoretical computer science, deep legal reasoning, complex systems architecture: When the last person who deeply understands a subfield of algebra retires and no one replaces them because the funding dried up and the career path disappeared, that knowledge isn’t likely to be rediscovered any time soon. </p><p>It’s gone. And nobody notices because the models trained on their work still perform well on benchmarks for another decade. I think of this as a hollowing out: The surface capability remains (models can still produce outputs that look expert) while the underlying human capacity to validate, extend, or correct that expertise quietly disappears.</p><h2><b>Why rubrics don't fully substitute</b></h2><p>The current approach is rubric-based evaluation. Constitutional AI, reinforcement learning from AI feedback (RLAIF), and structured criteria that let models score models are serious techniques that meaningfully reduce dependence on human evaluators. I'm not dismissing them.</p><p>Their <a href="https://venturebeat.com/infrastructure/intent-based-chaos-testing-is-designed-for-when-ai-behaves-confidently-and-wrongly?_gl=1*138a6ow*_up*MQ..*_ga*NTg2MjM1NTE0LjE3Nzg5NjQ5NzA.*_ga_SCH1J7LNKY*czE3Nzg5NjQ5NjkkbzEkZzAkdDE3Nzg5NjQ5NjkkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3Nzg5NjQ5NjkkbzEkZzAkdDE3Nzg5NjQ5NjkkajYwJGwwJGgw">limitation</a> is this: A rubric can only capture what the person who wrote it knew to measure. Optimize hard against it and you get a model that's very good at satisfying the rubric. That's not the same thing as a model that's actually right.</p><p>Rubrics scale the explicit, articulable part of judgment. The deeper part, the instinct, the felt sense that something is off, doesn't fit in a rubric. You can't write it down because you need to experience it first before you know what to write.</p><h2><b>What this means in practice</b></h2><p>This isn’t an argument for slowing development. The capability gains are real. And it’s possible that researchers will find ways to close the evaluation loop without human judgment. Maybe synthetic data pipelines get good enough. Maybe models develop reliable self-correction mechanisms we can’t yet imagine.</p><p>But we don’t have those today. And in the meantime, we’re dismantling the human infrastructure that currently fills the gap, not as a deliberate decision but as a byproduct of a thousand rational ones. The responsible version of this transition isn’t to assume the problem will solve itself. It’s to treat the evaluation gap as an open research problem with the same urgency we bring to capability gains.</p><p>The thing AI most needs from humans is the thing we’re least focused on preserving. Whether that’s permanently true or temporarily true, the cost of ignoring it is the same.</p><p><i>Ahmad Al-Dahle is CTO of Airbnb. </i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How RecursiveMAS speeds up multi-agent inference by 2.4x and reduces token usage by 75%]]></title>
<description><![CDATA[One of the key challenges of current multi-agent AI systems is that they communicate by generating and sharing text sequences, which introduces latency, drives up token costs, and makes it difficult to train the entire system as a cohesive unit. To overcome this challenge, researchers at Universi...]]></description>
<link>https://tsecurity.de/de/3520880/it-nachrichten/how-recursivemas-speeds-up-multi-agent-inference-by-24x-and-reduces-token-usage-by-75/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520880/it-nachrichten/how-recursivemas-speeds-up-multi-agent-inference-by-24x-and-reduces-token-usage-by-75/</guid>
<pubDate>Fri, 15 May 2026 23:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One of the key challenges of current multi-agent AI systems is that they communicate by generating and sharing text sequences, which introduces latency, drives up token costs, and makes it difficult to train the entire system as a cohesive unit. </p><p>To overcome this challenge, researchers at University of Illinois Urbana-Champaign and Stanford University developed <a href="https://recursivemas.github.io/"><u>RecursiveMAS</u></a>, a framework that enables agents to collaborate and transmit information through embedding space instead of text. This change results in both efficiency and performance gains. </p><p>Experiments show that RecursiveMAS achieves accuracy improvement across complex domains like code generation, medical reasoning, and search, while also increasing inference speed and slashing token usage. </p><p>RecursiveMAS is significantly cheaper to train than standard full fine-tuning or LoRA methods, making it a scalable and cost-effective blueprint for custom multi-agent systems.</p><h2>The challenges of improving multi-agent systems</h2><p><a href="https://venturebeat.com/orchestration/research-shows-more-agents-isnt-a-reliable-path-to-better-enterprise-ai"><u>Multi-agent systems</u></a> can help tackle complex tasks that single-agent systems struggle to handle. When scaling multi-agent systems for real-world applications, a big challenge is enabling the system to evolve, improve, and adapt to different scenarios over time. </p><p>Prompt-based adaptation improves agent interactions by iteratively refining the shared context provided to the agents. By updating the prompts, the system acts as a director, guiding the agents to generate responses that are more aligned with the overarching goal. The fundamental limitation is that the capabilities of the models underlying each agent remain static. </p><p>A more sophisticated approach is to train the agents by updating the weights of the underlying models. Training an entire system of agents is difficult because updating all the parameters across multiple models is computationally non-trivial.</p><p>Even if an engineering team commits to training their models, the standard method of agents communicating via text-based interactions creates major bottlenecks. Because agents rely on sequential text generation, it causes latency as each model must wait for the previous one to finish generating its text before it can begin its own processing. </p><p>Forcing models to spell out their intermediate reasoning token-by-token just so the next model can read it is highly inefficient. It severely inflates token usage, drives up compute costs, and makes iterative learning across the whole system painfully slow to scale. </p><h2>How RecursiveMAS works</h2><p>Instead of trying to improve each agent as an isolated, standalone component, RecursiveMAS is designed to co-evolve and scale the entire multi-agent system as a single integrated whole. </p><p>The framework is inspired by <a href="https://venturebeat.com/ai/mits-new-recursive-framework-lets-llms-process-10-million-tokens-without"><u>recursive language models</u></a> (RLMs). In a standard language model, data flows linearly through a stack of distinct layers. In contrast, a recursive language model reuses a set of shared layers that processes the data and feeds it back to itself. By looping the computation, the model can deepen its reasoning without adding parameters.</p><p>RecursiveMAS extends this scaling principle from a single model to a multi-agent architecture that acts as a unified recursive system. In this setup, each agent functions like a layer in a recursive language model. Rather than generating text, the agents iteratively pass their continuous latent representations to the next agent in the sequence, creating a looped hidden stream of information flowing through the system. </p><p>This latent hand-off continues down the line through all the agents. When the final agent finishes its processing, its latent outputs are fed directly back to the very first agent, kicking off a new recursion round. </p><p>This structure allows the entire multi-agent system to interact, reflect, and refine its collective reasoning over multiple rounds entirely in the latent space, with only the very last agent producing a textual output in the final round. It is like the agents are communicating telepathically as a unified whole and the last agent provides the final response as text.</p><h2>The architecture of latent collaboration</h2><p>To make continuous latent space collaboration possible, the authors introduce a specialized architectural component called the RecursiveLink. This is a lightweight, two-layer module designed to transmit and refine a model's latent states rather than forcing it to decode text. </p><p>A language model's last-layer hidden states contain the rich, semantic representation of its reasoning process. The RecursiveLink is designed to preserve and transmit this high-dimensional information from one embedding space to another. </p><p>To avoid the cost of updating every parameter across multiple large language models, the framework keeps the models' parameters frozen. Instead, it optimizes the system by only training the parameters of the RecursiveLink modules.</p><p>To handle both internal reasoning and external communication, the system uses two variations of the module. The inner RecursiveLink operates inside an agent during its reasoning phase. It takes the model's newly generated embeddings and maps them directly back into its own input embedding space. This allows the agent to continuously generate a stream of latent thoughts without generating discrete text tokens. </p><p>The outer RecursiveLink serves as the bridge between agents. Because agents in a real-world system might use different model architectures and sizes, their internal embedding spaces have entirely different dimensions. The outer RecursiveLink includes an additional layer designed to match the embeddings from one agent's hidden dimension with the next agent's embedding space.</p><p>During training, first, the inner links are trained independently to warm up each agent's ability to think in continuous latent embeddings. Then, the system enters outer-loop training, where the diverse, frozen models are chained together in a loop, and the system is evaluated based on the final textual output of the last agent. </p><p>The only thing that gets updated in the training process is the RecursiveLink parameters and the original model weights remain unchanged, similar to <a href="https://venturebeat.com/ai/running-thousands-of-llms-on-one-gpu-is-now-possible-with-s-lora"><u>low-rank adaptation</u></a> (LoRA). Another advantage of this system comes into effect when you have multiple agents on top of the same backbone model. </p><p>If you have a multi-agent system where two agents are built on the exact same foundation model acting in different roles, you do not need to load two copies of the model into your GPU memory, nor do you train them separately. The agents will share the same backbone as the brain and use the RecursiveLink as the connective tissue.</p><h2>RecursiveMAS in action</h2><p>The researchers evaluated RecursiveMAS across nine benchmarks spanning mathematics, science and medicine, code generation, and search-based question answering. They created a multi-agent system using open-weights models including Qwen, Llama-3, Gemma3, and Mistral. These models were assigned roles to form different agent collaboration patterns such as sequential reasoning and mixture-of-experts collaboration. </p><p>RecursiveMAS was compared to baselines under identical training budgets, including standalone models enhanced with LoRA or full supervised fine-tuning, alternative multi-agent frameworks like Mixture-of-Agents and TextGrad, and recursive baselines like LoopLM. It was also compared to Recursive-TextMAS, which uses the same recursive loop structure as RecursiveMAS but forces the agents to explicitly communicate via text.</p><p>RecursiveMAS achieved an average accuracy improvement of 8.3% compared to the strongest baselines across the benchmarks. It excelled particularly on reasoning-heavy tasks, outperforming text-based optimization methods like TextGrad by 18.1% on AIME2025 and 13% on AIME2026. </p><p>Because it avoids generating text at every step, RecursiveMAS achieved 1.2x to 2.4x end-to-end inference speedup. RecursiveMAS is also much more token efficient than the alternative. Compared to the text-based Recursive-TextMAS, it reduces token usage by 34.6% in the first round of the recursion, and by round three, it achieves 75.6% token reduction. RecursiveMAS also proved remarkably cheap to train. Because it only updates the lightweight RecursiveLink modules, which consist of roughly 13 million parameters or about 0.31% of the trainable parameters of the frozen models, it requires the lowest peak GPU memory and cuts training costs by more than half compared to full fine-tuning.</p><h2>Enterprise adoption</h2><p>The efficiency gains — lower token consumption, reduced GPU memory requirements, and faster inference — are intended to make complex multi-step agent workflows viable in production environments without the compute overhead that limits enterprise agentic deployments. The researchers have released the <a href="https://github.com/RecursiveMAS/RecursiveMAS">code</a> and <a href="https://huggingface.co/RecursiveMAS">trained model weights</a> under the Apache 2.0 license.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Next AI Bottleneck Isn’t the Model: It’s the Inference System]]></title>
<description><![CDATA[Enterprise AI systems are entering a phase where inference design matters as much as model capability itself.
The post The Next AI Bottleneck Isn’t the Model: It’s the Inference System appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3517370/ai-nachrichten/the-next-ai-bottleneck-isnt-the-model-its-the-inference-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517370/ai-nachrichten/the-next-ai-bottleneck-isnt-the-model-its-the-inference-system/</guid>
<pubDate>Thu, 14 May 2026 18:33:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise AI systems are entering a phase where inference design matters as much as model capability itself.</p>
<p>The post <a href="https://towardsdatascience.com/the-next-ai-bottleneck-isnt-the-model-its-the-inference-system/">The Next AI Bottleneck Isn’t the Model: It’s the Inference System</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FlowerStorm phishing gang adopts virtual-machine obfuscation to evade email defenses]]></title>
<description><![CDATA[A widely active phishing-as-a-service (PhaaS) operation known as FlowerStorm has begun using a browser-based virtual machine to conceal credential theft code, marking what researchers say is an escalation in phishing-kit sophistication that could make attacks harder for traditional email and stat...]]></description>
<link>https://tsecurity.de/de/3516805/it-security-nachrichten/flowerstorm-phishing-gang-adopts-virtual-machine-obfuscation-to-evade-email-defenses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516805/it-security-nachrichten/flowerstorm-phishing-gang-adopts-virtual-machine-obfuscation-to-evade-email-defenses/</guid>
<pubDate>Thu, 14 May 2026 15:10:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A widely active phishing-as-a-service (PhaaS) operation known as FlowerStorm has begun using a browser-based virtual machine to conceal credential theft code, marking what researchers say is an escalation in phishing-kit sophistication that could make attacks harder for traditional email and static-analysis tools to detect.</p>



<p>Researchers at Sublime Security said in April that they identified the campaign, which used KrakVM, an open-source JavaScript virtual machine recently published on GitHub, to obfuscate malicious code delivered via HTML attachments in phishing emails.</p>



<p>The campaign targets credentials and multi-factor authentication (MFA) codes for services including Microsoft 365, Hotmail, and GoDaddy, while also supporting <a href="https://www.csoonline.com/article/4147134/your-mfa-isnt-broken-its-being-bypassed-and-your-employees-cant-tell-the-difference.html" target="_blank">adversary-in-the-middle (AiTM) interception</a> techniques designed to hijack authenticated sessions.</p>



<p>“What makes this campaign notable is the adoption of KrakVM as a delivery wrapper within a month of the project’s public release,” the researchers wrote in a <a href="https://sublime.security/blog/flowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation/" target="_blank" rel="noreferrer noopener">report</a>.</p>



<p>The findings highlight how phishing operations are increasingly adopting techniques traditionally associated with sophisticated malware campaigns, including virtualized execution environments and layered obfuscation frameworks.</p>



<h2 class="wp-block-heading">Browser-based VM used to hide phishing payloads</h2>



<p>According to the report, victims receive phishing emails containing HTML attachments disguised as voicemail notices, invoices, or vendor communications. When opened in a browser, embedded JavaScript immediately launches a credential-harvesting workflow tailored to the victim’s environment.</p>



<p>The attack chain uses KrakVM to compile malicious JavaScript into encrypted bytecode, which is executed through a virtual machine running inside the browser.</p>



<p>“KrakVM compiles JavaScript into unreadable bytes,” the researchers wrote, adding that the virtual machine then interprets and executes the payload at runtime.</p>



<p>The approach adds multiple layers of obfuscation designed to complicate static analysis and evade traditional email-security tooling.</p>



<p>While virtual-machine-based obfuscation has long been used in malware packers and software protection systems, its adoption inside large-scale phishing kits appears far less common.</p>



<h2 class="wp-block-heading">The campaign dynamically adapts to victims</h2>



<p>After deobfuscation, the phishing payload loads infrastructure designed to impersonate Microsoft 365 and other login portals while dynamically adapting to targeted users.</p>



<p>According to the report, the malware can determine which authentication provider should be impersonated, preload victim email addresses into phishing pages, and customize branding elements such as company logos and backgrounds.</p>



<p>The phishing kit also enumerates MFA methods registered on victim accounts, including Microsoft Authenticator push notifications, TOTP codes, SMS authentication, and voice verification flows.</p>



<p>When the victim enters credentials, the kit forwards them to a command-and-control server, which attempts a real login against the target service. If the service prompts for MFA, the kit presents the victim with a matching prompt, captures the response, and forwards it to complete the attacker’s session.</p>



<p>Researchers said the framework supports real-time AiTM interception, allowing operators to relay authentication sessions while harvesting credentials and MFA tokens.</p>



<p>“A widely known unique feature of FlowerStorm is its capability for advanced AiTM and MFA interception,” the report said.</p>



<h2 class="wp-block-heading">Detection challenges grow for defenders</h2>



<p>The combination of VM-based obfuscation and AiTM-capable payload creates a detection gap for email security tools.</p>



<p>Sublime Security said its own Autonomous Security Analyst system identified the attack as malicious, partly because of the HTML attachment’s use of “heavily obfuscated JavaScript with custom virtual machine bytecode.”</p>



<p>The researchers also noted that both KrakVM and FlowerStorm appeared to operate close to their default configurations, suggesting the campaign did not require advanced technical sophistication from operators.</p>



<p>That raises concern that VM-based obfuscation techniques could spread quickly across phishing ecosystems if tooling becomes easier to operationalize, the report added.</p>



<h2 class="wp-block-heading">The broader phishing ecosystem is evolving</h2>



<p>The campaign has targeted sectors including local government, logistics, retail, communications, and real estate, according to the report. Researchers also identified infrastructure using domains designed to resemble court systems, enterprise portals, and Microsoft-related services.</p>



<p>Sublime published 153 indicators of compromise, including dozens of subdomains on cloud object storage services across regions, including Singapore, Bangkok, Frankfurt, Tokyo, Seoul, Jakarta, and Ashburn.</p>



<p>The researchers also identified domain naming patterns that overlap with prior FlowerStorm reporting, including German-language domains assembled from English words to mimic legitimate business names.</p>



<p>Sophos had <a href="https://www.sophos.com/en-us/blog/phishing-platform-rockstar-2fa-trips-and-flowerstorm-picks-up-the-pieces" target="_blank" rel="noreferrer noopener">documented</a> FlowerStorm in December 2024, after the kit emerged following a disruption to the Rockstar2FA phishing service. The researchers said they had found no evidence linking the KrakVM developer to FlowerStorm operations.</p>



<p>The findings come as security teams face increasingly sophisticated phishing campaigns that blend credential theft, MFA interception, session hijacking, and anti-analysis techniques into unified attack chains.</p>



<p>“This campaign likely represents only the earliest use of KrakVM’s obfuscation capabilities,” the researchers wrote. “We anticipate more complex implementations as its adoption grows.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple studies explore LLMs spatial understanding, sign language annotation]]></title>
<description><![CDATA[Apple's interest in AI models and their applications in spatial computing shows no signs of slowing down, even as some claim the Apple Vision Pro is dead.Apple hasn't abandoned spatial computing, judging by its research studies.In April 2026, it was argued that the Apple Vision Pro was an outrigh...]]></description>
<link>https://tsecurity.de/de/3508587/ios-mac-os/apple-studies-explore-llms-spatial-understanding-sign-language-annotation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508587/ios-mac-os/apple-studies-explore-llms-spatial-understanding-sign-language-annotation/</guid>
<pubDate>Tue, 12 May 2026 01:21:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's interest in AI models and their applications in spatial computing shows no signs of slowing down, even as some claim the <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro</a> is dead.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67615-142461-Vision-Pros-stack-xl.jpg" alt="Two sleek, reflective black VR headsets with white fabric straps lying overlapping against a dark background, showing their curved lenses and small front-facing cameras"><br><span>Apple hasn't abandoned spatial computing, judging by its research studies.</span></div><br>In <a href="https://appleinsider.com/articles/26/04/29/rumored-apple-vision-pro-team-break-up-isnt-a-death-knell-for-the-product">April 2026</a>, it was argued that the Apple Vision Pro was an outright failure and that, as a result, we'd never see a successor product. That rumor, though it always seemed unreasonable, has since <a href="https://appleinsider.com/articles/26/05/10/not-dead-yet-apple-vision-still-has-a-future">come into question</a>.<br><br>Even though the company's Vision Products Group may have seen some changes, there's ultimately still hope for a new generation of the Apple Vision Pro. Apple's AI research suggests the company hasn't abandoned its spatial-related projects.<br><br><br> <a href="https://appleinsider.com/articles/26/05/11/apple-studies-explore-llms-spatial-understanding-sign-language-annotation?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244314?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Purple Team Isn’t Purple — It’s Just Red and Blue in the Same Room]]></title>
<description><![CDATA[Defending a network at 2 am looks a lot like this: an analyst copy-pasting a hash from a PDF into a SIEM query. A red team script is being rewritten by hand so the blue team can use it. A…
Read more →
The post Your Purple Team Isn’t Purple — It’s Just Red and Blue in the Same Room appeared first ...]]></description>
<link>https://tsecurity.de/de/3506944/it-security-nachrichten/your-purple-team-isnt-purple-its-just-red-and-blue-in-the-same-room/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3506944/it-security-nachrichten/your-purple-team-isnt-purple-its-just-red-and-blue-in-the-same-room/</guid>
<pubDate>Mon, 11 May 2026 14:25:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Defending a network at 2 am looks a lot like this: an analyst copy-pasting a hash from a PDF into a SIEM query. A red team script is being rewritten by hand so the blue team can use it. A…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-purple-team-isnt-purple-its-just-red-and-blue-in-the-same-room/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-purple-team-isnt-purple-its-just-red-and-blue-in-the-same-room/">Your Purple Team Isn’t Purple — It’s Just Red and Blue in the Same Room</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Not dead yet: Apple Vision still has a future]]></title>
<description><![CDATA[As we've repeated before, and a new report reiterates, the supposed death of Apple Vision Pro and its product team was an exaggeration. There are no signs of "giving up" on the product line.Apple Vision Pro isn't a dead product or an abandoned projectA report relying on a limited-in-scope anonymo...]]></description>
<link>https://tsecurity.de/de/3504942/ios-mac-os/not-dead-yet-apple-vision-still-has-a-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3504942/ios-mac-os/not-dead-yet-apple-vision-still-has-a-future/</guid>
<pubDate>Sun, 10 May 2026 17:10:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As we've repeated before, and a new report reiterates, the supposed death of <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro</a> and its product team was an exaggeration. There are no signs of "giving up" on the product line.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67598-142429-Apple-Vision-Pro-M5-table-backlit-xl.jpg" alt="Apple Vision Pro and connected battery pack resting on a wooden table by a sunny window, with two small green potted plants softly blurred in the background"><br><span>Apple Vision Pro isn't a dead product or an abandoned project</span></div><br>A report relying on a limited-in-scope anonymous leak reached <a href="https://appleinsider.com/articles/26/04/29/rumored-apple-vision-pro-team-break-up-isnt-a-death-knell-for-the-product">the conclusion</a> that Apple Vision Pro had become an abandoned product line. While the base team may have changed or evolved, the project itself hasn't been given up on.<br><br><em>AppleInsider</em>'s initial assessment of the situation has been reiterated by others in the know, including in the latest <a href="https://www.bloomberg.com/account/newsletters/power-on">According to</a> the <em>Power On</em> newsletter. While the Vision Products Group has been broken up into various other organizations, development of the Apple Vision Pro hasn't stopped.<br><br><br> <a href="https://appleinsider.com/articles/26/05/10/not-dead-yet-apple-vision-still-has-a-future?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244291?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Trump Phone Either Is Or Isn't Closer To Delivery]]></title>
<description><![CDATA[September 2025? January 2026? Delivery dates keep slipping for the Trump Organization's "Trump Phone" — a gold-coloured Android smartphone priced at $499 (£370). But in March the Verge spotted signs the phone was moving forward:


FCC listings for a smartphone with the trade name "T1" show that i...]]></description>
<link>https://tsecurity.de/de/3503704/it-security-nachrichten/the-trump-phone-either-is-or-isnt-closer-to-delivery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503704/it-security-nachrichten/the-trump-phone-either-is-or-isnt-closer-to-delivery/</guid>
<pubDate>Sat, 09 May 2026 22:54:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[September 2025? January 2026? Delivery dates keep slipping for the Trump Organization's "Trump Phone" — a gold-coloured Android smartphone priced at $499 (£370). But in March the Verge spotted signs the phone was moving forward:


FCC listings for a smartphone with the trade name "T1" show that it was tested late last year, and granted certification by the FCC in January... [T]he phone was submitted for testing by another company entirely: Smart Gadgets Global, LLC... Smart Gadgets Global's website promises "Top Quality Electronics created for 'YOUR' customer!"
 

But in April the Trump phone revised its "Terms and Conditions" for preorders. The new language?
A preorder deposit provides only a conditional opportunity if Trump Mobile later elects, in its sole discretion, to offer the Device for sale. A deposit is not a purchase, does not constitute acceptance of an order, does not create a contract for sale, does not transfer ownership or title interest, does not allocate or reserve specific inventory, and does not guarantee that a Device will be produced or made available for purchase.... 
Estimated ship dates, launch timelines, or anticipated production schedule are non-binding estimates only. Trump Mobile does not guarantee that: the Device will be commercially released... Trump Mobile will not be responsible for delay, modification, or failure to release a Device due to causes beyond its reasonable control, including but not limited to regulatory review, carrier certification delays, component shortages, labor disruptions, governmental orders, acts of God, transportation interruptions, or third-party supplier failures... 

If Trump Mobile cancels or discontinues the Device offering prior to sale, Trump Mobile will issue a full refund of the deposit amount paid... If Trump Mobile cancels, delays, or does not release the Device, your sole and exclusive remedy is a full refund of the deposit amount actually paid, and you waive any claim for equitable, injunctive, or specific performance relief relating to preorder priority or Device allocation. 
There was an unconfirmed report on social media that the updated Terms were also emailed to customers (cited by the International Business Times). And the new language also hedges that for the gold T1 phone, "Images, prototypes, beta demonstrations, and marketing renderings are illustrative only and may not reflect final production units...." 


But then eight days ago The Verge reported that phone "has just passed another milestone on its slow road to release," described as "a requirement for any phone launching in the US..." 

"The phone has received the little-known PTCRB certification, a first step toward being certified to work on major networks and be issued with IMEI numbers."
[A]t least, I think it's been certified. What's actually been certified by the PTCRB is the SGG-06, a smartphone from Smart Gadgets Global, LLC, with support for 5G, 4G, 3G, and 2G networks.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=The+Trump+Phone+Either+Is+Or+Isn't+Closer+To+Delivery%3A+https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F05%2F09%2F1826252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F05%2F09%2F1826252%2Fthe-trump-phone-either-is-or-isnt-closer-to-delivery%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://mobile.slashdot.org/story/26/05/09/1826252/the-trump-phone-either-is-or-isnt-closer-to-delivery?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release PULS Release v0.9.0 · word-sys/puls]]></title>
<description><![CDATA[Hello everyone, im word-sys, main developer of PULS, recently i opened a Github organization called "FOSPX", its closed, i mean i closed it due to lack of interest and confusing naming, i thought that naming my application under an organization name will make them more memorable and understandabl...]]></description>
<link>https://tsecurity.de/de/3494402/linux-tipps/release-puls-release-v090-word-syspuls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494402/linux-tipps/release-puls-release-v090-word-syspuls/</guid>
<pubDate>Thu, 07 May 2026 03:41:27 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello everyone, im word-sys, main developer of PULS, recently i opened a Github organization called "FOSPX", its closed, i mean i closed it due to lack of interest and confusing naming, i thought that naming my application under an organization name will make them more memorable and understandable, however it didnt, so i taking actions to close FOSPX organization, that organization created by me btw, all applications/projects released and developed by me will be on my github page's repository from now on: <a href="https://github.com/word-sys/puls">https://github.com/word-sys/puls</a></p> <p>New update isnt just a naming change, its a bit UI change and improvement on core compoments, for example added more CPU telemetry to CPU Tab for example CPU Vendor, Family, L3 Cache and more. Dashboard completely changed to be usefull at some point, added graphs for CPU Memory and GPU tab improved, a bit visual stability and more importantly: lower core usage, i find out running nvidia-smi always on the back to show and get use graph for user isnt a great approach, now its activated only when GPU tab is on screen, other fixes and changes on CHANGELOG on Github: <a href="https://github.com/word-sys/puls/blob/main/CHANGELOG.md">https://github.com/word-sys/puls/blob/main/CHANGELOG.md</a></p> <p>Thanks everyone who supports this project, i hope that this turns out to be usefull at some point, for me its usefull to watch process when i compile something or while developing project to see project core usage etc. i hope it becomes usefull for everyone, i dont have any focus to replace anything but trying to make it simpler everything for the end-user or developers who wants instant easy info on something etc.</p> <p>word-sys</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/word-sys"> /u/word-sys </a> <br> <span><a href="https://github.com/word-sys/puls/releases/tag/0.9.0">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t5gxyz/release_puls_release_v090_wordsyspuls/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release word-sys's PDF Editor v1.9.0 · word-sys/word-sys-pdf-editor]]></title>
<description><![CDATA[Hello everyone, im word-sys, main developer of word-sys's PDF Editor, recently i opened a Github organization called "FOSPX", its closed, i mean i closed it due to lack of interest and confusing naming, i thought that naming my application under an organization name will make them more memorable ...]]></description>
<link>https://tsecurity.de/de/3494395/linux-tipps/release-word-syss-pdf-editor-v190-word-sysword-sys-pdf-editor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494395/linux-tipps/release-word-syss-pdf-editor-v190-word-sysword-sys-pdf-editor/</guid>
<pubDate>Thu, 07 May 2026 03:41:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello everyone, im word-sys, main developer of word-sys's PDF Editor, recently i opened a Github organization called "FOSPX", its closed, i mean i closed it due to lack of interest and confusing naming, i thought that naming my application under an organization name will make them more memorable and understandable, however it didnt, so i taking actions to close FOSPX organization, that organization created by me btw, all applications/projects released and developed by me will be on my github page's repository from now on: <a href="https://github.com/word-sys/word-sys-pdf-editor">https://github.com/word-sys/word-sys-pdf-editor</a></p> <p>New update isnt just a naming change, its a bit UI change and improvement, now there is edit mode and view mode, making the application PDF Editor &amp; Reader, underlined texts now available, right click menu, highlight menu ans other fixes and changes on CHANGELOG on Github: <a href="https://github.com/word-sys/word-sys-pdf-editor/blob/main/CHANGELOG.md">https://github.com/word-sys/word-sys-pdf-editor/blob/main/CHANGELOG.md</a></p> <p>word-sys</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/word-sys"> /u/word-sys </a> <br> <span><a href="https://github.com/word-sys/word-sys-pdf-editor/releases/tag/1.9.0">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t5pp84/release_wordsyss_pdf_editor_v190/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft confirms Windows 11’s File Explorer is sluggish, and preloading isn’t the only fix coming]]></title>
<description><![CDATA[Microsoft introduced File Explorer preloading to make Windows 11 feel faster, but power users quickly called it a lazy fix that just wastes RAM. Now, the Windows Shell team is responding to the backlash and detailing the deep architectural optimizations actually happening under the hood.
The post...]]></description>
<link>https://tsecurity.de/de/3491169/windows-tipps/microsoft-confirms-windows-11s-file-explorer-is-sluggish-and-preloading-isnt-the-only-fix-coming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491169/windows-tipps/microsoft-confirms-windows-11s-file-explorer-is-sluggish-and-preloading-isnt-the-only-fix-coming/</guid>
<pubDate>Wed, 06 May 2026 03:40:38 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft introduced File Explorer preloading to make Windows 11 feel faster, but power users quickly called it a lazy fix that just wastes RAM. Now, the Windows Shell team is responding to the backlash and detailing the deep architectural optimizations actually happening under the hood.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/05/06/microsoft-confirms-windows-11s-file-explorer-is-sluggish-and-preloading-isnt-the-only-fix-coming/">Microsoft confirms Windows 11’s File Explorer is sluggish, and preloading isn’t the only fix coming</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Glasses Privacy Leak?! New WiFi Attack & Password Manager Flaw - Snubs on Security]]></title>
<description><![CDATA[Author: Shannon Morse - Bewertung: 683x - Views:7912 Shoutout to my sponsor DeleteMe, who’s offering my community 20% off with code SNUBS at https://joindeleteme.com/morsecode

Meta’s Ray-Ban smart glasses are raising serious privacy concerns, researchers just dropped a new WiFi attack that can i...]]></description>
<link>https://tsecurity.de/de/3489424/videos/meta-glasses-privacy-leak-new-wifi-attack-password-manager-flaw-snubs-on-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489424/videos/meta-glasses-privacy-leak-new-wifi-attack-password-manager-flaw-snubs-on-security/</guid>
<pubDate>Tue, 05 May 2026 13:47:55 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Shannon Morse - Bewertung: 683x - Views:7912 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gD4L2j6sSes?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Shoutout to my sponsor DeleteMe, who’s offering my community 20% off with code SNUBS at https://joindeleteme.com/morsecode<br />
<br />
Meta’s Ray-Ban smart glasses are raising serious privacy concerns, researchers just dropped a new WiFi attack that can intercept your traffic, password managers might not be as “zero-knowledge” as they claim, and people are literally destroying surveillance cameras across the U.S.<br />
<br />
💻 In this episode of Snubs on Security, I break down:<br />
- Meta smart glasses and human video reviewers 👀 <br />
- The new “AirSnitch” WiFi attack explained<br />
- Password manager security research (and what it actually means)<br />
- Why Flock surveillance cameras are being targeted<br />
- Quick TLDRs on AI security flaws, surveillance pricing, and more<br />
<br />
⏱️ Chapters<br />
 - Welcome to Snubs on Security<br />
00:42 - Meta smart glasses privacy concerns<br />
06:30 - AirSnitch WiFi attack breakdown<br />
14:30 - DeleteMe sponsor<br />
17:00 - Password manager “zero-knowledge” flaw<br />
24:00 - TLDR: OpenClaw AI vulnerabilities<br />
25:30 - TLDR: Flock cameras getting destroyed<br />
28:00 - TLDR: Surveillance pricing in grocery stores<br />
29:30 - TLDR: Instagram loses encryption<br />
<br />
🕶️ Meta Ray-Ban Smart Glasses / Privacy<br />
- https://www.svd.se/a/K8nrV4/metas-ai-smart-glasses-and-data-privacy-concerns-workers-say-we-see-everything<br />
- https://www.zdnet.com/article/meta-ray-ban-smart-glasses-privacy-concerns/<br />
- https://gizmodo.com/want-to-know-if-glassholes-are-using-smart-glasses-near-you-theres-an-app-for-that-2000726480<br />
- https://play.google.com/store/apps/details?id=ch.pocketpc.nearbyglasses<br />
<br />
📶 AirSnitch Wi-Fi Attack<br />
- https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/<br />
- https://infosec.exchange/@vanhoefm/116138411163131123<br />
- https://www.ndss-symposium.org/wp-content/uploads/2026-f1282-paper.pdf<br />
- https://github.com/vanhoefm/airsnitch<br />
<br />
🔐 Password Manager Research<br />
- https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/<br />
- https://eprint.iacr.org/2026/058<br />
<br />
🤖 OpenClaw / AI Security Issues<br />
- https://www.oasis.security/blog/openclaw-vulnerability<br />
- https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html<br />
- https://www.bleepingcomputer.com/news/security/clawjacked-attack-let-malicious-websites-hijack-openclaw-to-steal-data/<br />
- https://www.reco.ai/blog/openclaw-the-ai-agent-security-crisis-unfolding-right-now<br />
- https://www.zdnet.com/article/moltbook-and-openclaw-fools-gold-in-ai-boom/<br />
<br />
 📷 Flock Surveillance Cameras<br />
- https://gizmodo.com/flock-cameras-have-a-people-love-smashing-them-problem-2000725063<br />
- https://www.wcia.com/news/menard-county/menard-co-sheriffs-office-investigating-damaged-flock-camera-burglary/<br />
- https://deflock.org/<br />
- https://www.wavy.com/news/local-news/suffolk/suffolk-man-charged-with-destroying-13-flock-cameras/<br />
- https://lookouteugene-springfield.com/story/justice/2025/10/15/police-investigate-vandalism-to-flock-cameras-in-eugene-springfield/<br />
- https://sdslackers.com/2026/02/16/flock-cameras-destroyed-in-la-mesa-amid-surveillance-backlash/<br />
- https://www.bloodinthemachine.com/p/across-the-us-people-are-dismantling<br />
<br />
🛒 Surveillance Pricing Bill<br />
- https://gizmodo.com/dems-want-to-ban-surveillance-pricing-at-big-grocery-stores-2000722182<br />
<br />
Becoming a Morse Code Member by checking out the perks linked here!:<br />
https://www.youtube.com/channel/UCNofX8wmSJh7NTklvMqueOA/join<br />
<br />
Editor: @ColleenEdits<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
SUBSCRIBE! 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
SUPPORT MY WORK<br />
PATREON 💛 https://www.patreon.com/ShannonMorse<br />
BUY ME A COFFEE 💛 https://www.buymeacoffee.com/snubs<br />
MY SHOP 💛 https://shannonrmorse.com/shop<br />
SPRING SHOP 💛 https://morsecode.creator-spring.com/<br />
ACTIVE COUPON CODES 💛 https://shannonrmorse.com/support<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
FOLLOW THE SOCIALS THINGS<br />
THREADS 🌸  https://www.threads.net/@snubs<br />
INSTAGRAM 🌸  http://www.instagram.com/snubs<br />
TIKTOK 🌸  https://tiktok.com/@snubsie<br />
YOUTUBE 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1<br />
WEBSITE 🌸 https://www.morsecodecreative.com/<br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
MY OTHER SHOWS<br />
Shannon Travels The World 🌙 https://www.youtube.com/@ShannonTravelsTheWorld/featured <br />
Sailor Snubs 🌙 https://www.youtube.com/@SailorSnubs/featured <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
GET IN TOUCH<br />
Mail ✈ <br />
https://shannonrmorse.com/contact <br />
<br />
Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com<br />
My Media Kit ✈ https://shannonrmorse.com/work-with-me <br />
Sponsor This Channel ✈ https://shannonrmorse.com/shannon-morse <br />
<br />
💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜<br />
<br />
😍 FTC DISCLAIMER 😍<br />
Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Any products provided as gifts are listed above. Thank you for your support!<br />
<br />
Comment section code of conduct policy:<br />
https://shannonrmorse.com/code-of-conduct<br />
<br />
Code of Ethics:<br />
https://www.morsecodecreative.com/code-of-ethics<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs]]></title>
<description><![CDATA[A newly identified malware campaign is abusing Microsoft’s Phone Link feature to intercept SMS-based one-time passwords and other sensitive mobile data directly from Windows systems.



The activity, first observed by Cisco Talos in January 2026, involves a remote access trojan dubbed CloudZ and ...]]></description>
<link>https://tsecurity.de/de/3489357/it-nachrichten/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489357/it-nachrichten/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs/</guid>
<pubDate>Tue, 05 May 2026 13:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly identified malware campaign is abusing Microsoft’s Phone Link feature to intercept SMS-based one-time passwords and other sensitive mobile data directly from Windows systems.</p>



<p>The activity, first observed by Cisco Talos in January 2026, involves a remote access trojan dubbed CloudZ and a custom plugin named Pheno that together allow attackers to harvest credentials and potentially capture authentication codes synced from a user’s smartphone, Talos researchers Alex Karkins and Chetan Raghuprasad wrote in a blog post.</p>



<p>“According to the functionalities of the CloudZ RAT and Pheno plugin, this was with the intention of stealing victims’ credentials and potentially one-time passwords (OTPs),” the researchers wrote.</p>



<p>The attack does not target the mobile device itself. Instead, it exploits the trust relationship between phones and Windows PCs by monitoring data mirrored through the Phone Link application, the blog post said.</p>



<p>CloudZ “utilizes the custom Pheno plugin to hijack the established PC-to-phone bridge by abusing the Microsoft Phone Link application, allowing the plugin to continuously scan for active Phone Link processes and potentially intercept sensitive mobile data like SMS and OTPs without deploying malware on the phone,” the Talos report said.</p>



<p>The technique sidesteps the need to compromise the mobile device itself, which the researchers said makes the intrusion notable to enterprise defenders.</p>



<p>It adds to a growing body of attacker tradecraft aimed at <a href="https://www.csoonline.com/article/4147134/your-mfa-isnt-broken-its-being-bypassed-and-your-employees-cant-tell-the-difference.html">bypassing</a> SMS- and app-based MFA by extracting authentication codes from compromised Windows systems where mobile data is synced.</p>



<p>Microsoft did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">Phone Link data becomes an attack surface</h2>



<p>Microsoft Phone Link, previously known as Your Phone, is a built-in Windows feature that connects a PC to a smartphone and mirrors messages, notifications, and calls on the desktop.</p>



<p>Pheno is designed to locate the Phone Link data stored locally on the Windows system. According to the advisory, the attacker using CloudZ “can potentially intercept the Phone Link application’s SQLite database file on the victim machine, potentially compromising SMS-based OTP messages and other authenticator application notification messages.”</p>



<p>Because this data resides on the endpoint, the technique shifts risk from mobile devices to enterprise-managed Windows systems, potentially bypassing controls focused on securing smartphones.</p>



<h2 class="wp-block-heading">Multi-stage infection chain</h2>



<p>The intrusion begins with an unknown initial access vector, followed by the execution of a malicious file disguised as a ScreenConnect update, Talos said.</p>



<p>The initial payload is a Rust-compiled loader using filenames such as “systemupdates.exe,” which drops a .NET loader disguised as a text file in a system directory, the post said.</p>



<p>Persistence is established through a scheduled task named “SystemWindowsApis” that runs at startup with elevated privileges using the legitimate regasm.exe utility, the researchers wrote in the blog.</p>



<p>The .NET loader runs anti-analysis checks before unpacking CloudZ. It performs multiple checks to detect security tools and sandbox environments before executing the payload in memory, the report said.</p>



<p>It “calculates the actual elapsed time of a sleep command to detect if it is executed in the analysis environment,” and scans for tools such as Wireshark, Fiddler, Procmon, and Sysmon. “The .NET loader exits the execution if these are detected in the victim environment,” the blog post added.</p>



<p>The CloudZ payload is then decrypted in memory and executed, it said.</p>



<h2 class="wp-block-heading">RAT enables credential theft and plugin delivery</h2>



<p>CloudZ establishes an encrypted connection to a command-and-control server and supports a range of functions, including credential harvesting, file operations, and remote command execution, Talos said.</p>



<p>The malware also retrieves secondary configuration data from attacker-controlled infrastructure.</p>



<p>The Talos researchers wrote that the RAT downloads configuration data from remote servers and “extracts the C2 server IP address … and port number … establishing connections through TCP sockets.”</p>



<p>It also rotates user-agent strings to blend its traffic with legitimate browser activity, the researchers noted.</p>



<h2 class="wp-block-heading">Pheno plugin monitors active device sync</h2>



<p>The Pheno plugin is responsible for identifying active Phone Link sessions and enabling data interception.</p>



<p>It “scans all running processes for specific keywords such as ‘YourPhone,’ ‘PhoneExperienceHost,’ or ‘Link to Windows,’” and logs results locally, the report said.</p>



<p>The plugin then checks for evidence of a proxy connection used by Phone Link to relay data between devices.</p>



<p>“The presence of ‘proxy’ … indicates that the Phone Link session is actively routing traffic through its relay channel,” the researchers wrote.</p>



<p>When such activity is detected, the plugin flags the system as connected, which “eventually allows the attacker … to potentially monitor SMS or OTP requests that appear on the Phone Link application,” according to the report.</p>



<p>Talos has released detection signatures and indicators of compromise, including malware hashes, command-and-control infrastructure, and Snort rules associated with the activity.</p>



<p>Cisco Talos did not attribute the activity to a known threat actor.</p>



<p><em>The article originally appeared on <a href="https://www.csoonline.com/article/4167092/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCs]]></title>
<description><![CDATA[A newly identified malware campaign is abusing Microsoft’s Phone Link feature to intercept SMS-based one-time passwords and other sensitive mobile data directly from Windows systems.



The activity, first observed by Cisco Talos in January 2026, involves a remote access trojan dubbed CloudZ and ...]]></description>
<link>https://tsecurity.de/de/3489281/it-security-nachrichten/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489281/it-security-nachrichten/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs/</guid>
<pubDate>Tue, 05 May 2026 13:07:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly identified malware campaign is abusing Microsoft’s Phone Link feature to intercept SMS-based one-time passwords and other sensitive mobile data directly from Windows systems.</p>



<p>The activity, first observed by Cisco Talos in January 2026, involves a remote access trojan dubbed CloudZ and a custom plugin named Pheno that together allow attackers to harvest credentials and potentially capture authentication codes synced from a user’s smartphone, Talos researchers Alex Karkins and Chetan Raghuprasad wrote in a blog post.</p>



<p>“According to the functionalities of the CloudZ RAT and Pheno plugin, this was with the intention of stealing victims’ credentials and potentially one-time passwords (OTPs),” the researchers wrote.</p>



<p>The attack does not target the mobile device itself. Instead, it exploits the trust relationship between phones and Windows PCs by monitoring data mirrored through the Phone Link application, the blog post said.</p>



<p>CloudZ “utilizes the custom Pheno plugin to hijack the established PC-to-phone bridge by abusing the Microsoft Phone Link application, allowing the plugin to continuously scan for active Phone Link processes and potentially intercept sensitive mobile data like SMS and OTPs without deploying malware on the phone,” the Talos report said.</p>



<p>The technique sidesteps the need to compromise the mobile device itself, which the researchers said makes the intrusion notable to enterprise defenders.</p>



<p>It adds to a growing body of attacker tradecraft aimed at <a href="https://www.csoonline.com/article/4147134/your-mfa-isnt-broken-its-being-bypassed-and-your-employees-cant-tell-the-difference.html">bypassing</a> SMS- and app-based MFA by extracting authentication codes from compromised Windows systems where mobile data is synced.</p>



<p>Microsoft did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">Phone Link data becomes an attack surface</h2>



<p>Microsoft Phone Link, previously known as Your Phone, is a built-in Windows feature that connects a PC to a smartphone and mirrors messages, notifications, and calls on the desktop.</p>



<p>Pheno is designed to locate the Phone Link data stored locally on the Windows system. According to the advisory, the attacker using CloudZ “can potentially intercept the Phone Link application’s SQLite database file on the victim machine, potentially compromising SMS-based OTP messages and other authenticator application notification messages.”</p>



<p>Because this data resides on the endpoint, the technique shifts risk from mobile devices to enterprise-managed Windows systems, potentially bypassing controls focused on securing smartphones.</p>



<h2 class="wp-block-heading">Multi-stage infection chain</h2>



<p>The intrusion begins with an unknown initial access vector, followed by the execution of a malicious file disguised as a ScreenConnect update, Talos said.</p>



<p>The initial payload is a Rust-compiled loader using filenames such as “systemupdates.exe,” which drops a .NET loader disguised as a text file in a system directory, the post said.</p>



<p>Persistence is established through a scheduled task named “SystemWindowsApis” that runs at startup with elevated privileges using the legitimate regasm.exe utility, the researchers wrote in the blog.</p>



<p>The .NET loader runs anti-analysis checks before unpacking CloudZ. It performs multiple checks to detect security tools and sandbox environments before executing the payload in memory, the report said.</p>



<p>It “calculates the actual elapsed time of a sleep command to detect if it is executed in the analysis environment,” and scans for tools such as Wireshark, Fiddler, Procmon, and Sysmon. “The .NET loader exits the execution if these are detected in the victim environment,” the blog post added.</p>



<p>The CloudZ payload is then decrypted in memory and executed, it said.</p>



<h2 class="wp-block-heading">RAT enables credential theft and plugin delivery</h2>



<p>CloudZ establishes an encrypted connection to a command-and-control server and supports a range of functions, including credential harvesting, file operations, and remote command execution, Talos said.</p>



<p>The malware also retrieves secondary configuration data from attacker-controlled infrastructure.</p>



<p>The Talos researchers wrote that the RAT downloads configuration data from remote servers and “extracts the C2 server IP address … and port number … establishing connections through TCP sockets.”</p>



<p>It also rotates user-agent strings to blend its traffic with legitimate browser activity, the researchers noted.</p>



<h2 class="wp-block-heading">Pheno plugin monitors active device sync</h2>



<p>The Pheno plugin is responsible for identifying active Phone Link sessions and enabling data interception.</p>



<p>It “scans all running processes for specific keywords such as ‘YourPhone,’ ‘PhoneExperienceHost,’ or ‘Link to Windows,’” and logs results locally, the report said.</p>



<p>The plugin then checks for evidence of a proxy connection used by Phone Link to relay data between devices.</p>



<p>“The presence of ‘proxy’ … indicates that the Phone Link session is actively routing traffic through its relay channel,” the researchers wrote.</p>



<p>When such activity is detected, the plugin flags the system as connected, which “eventually allows the attacker … to potentially monitor SMS or OTP requests that appear on the Phone Link application,” according to the report.</p>



<p>Talos has released detection signatures and indicators of compromise, including malware hashes, command-and-control infrastructure, and Snort rules associated with the activity.</p>



<p>Cisco Talos did not attribute the activity to a known threat actor.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your data left the building. Did anyone notice?]]></title>
<description><![CDATA[The question nobody is asking loudly enough



I keep hearing the same AI conversation everywhere I go. Better models, faster inference, more capable agents. The race is on and everyone wants in.



But something is missing.



Most organizations I work with have already moved past experimentatio...]]></description>
<link>https://tsecurity.de/de/3488890/it-security-nachrichten/your-data-left-the-building-did-anyone-notice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488890/it-security-nachrichten/your-data-left-the-building-did-anyone-notice/</guid>
<pubDate>Tue, 05 May 2026 11:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The question nobody is asking loudly enough</h2>



<p>I keep hearing the same AI conversation everywhere I go. Better models, faster inference, more capable agents. The race is on and everyone wants in.</p>



<p>But something is missing.</p>



<p>Most organizations I work with have already moved past experimentation. AI is embedded in workflows, shaping customer interactions, processing internal documents, informing operational decisions. The question of whether AI works has largely been answered. What has not been answered, in most cases, is something far more basic.</p>



<p>Where does our data actually go when it flows through an LLM? Who can access it? Under which jurisdiction is it processed? Could it end up improving someone else’s model?</p>



<p>These are not hypothetical concerns. These are the questions that surface when a regulator asks how your organization handles personal data, when a client wants to know what happens to the documents they share with your AI-powered service, or when a board member reads about a policy change at one of the major AI providers and wants to know what it means for the business.</p>



<p>In my experience, most organizations cannot answer these questions clearly. Not because they do not care, but because the adoption moved faster than the governance. Teams were encouraged to experiment, pilots became production and somewhere along the way, the data conversation got left behind.</p>



<p>This is not a fringe problem. Recent industry data suggests that most enterprise leaders are now actively redesigning their data architectures, not because the AI did not work, but because the way it was connected to their data became a liability.</p>



<p>The capability conversation has dominated for the last two years. I think the next two years will be defined by a different question entirely: Not what can AI do, but who controls what it knows?</p>



<h2 class="wp-block-heading">Your data is already travelling further than you think</h2>



<p>When I talk to CIOs about AI risk, the conversation almost always starts with model accuracy, hallucinations or bias. Rarely does anyone open with: “Do we actually know where our data goes when someone on the team uses an LLM?”</p>



<p>That question matters more than most people realise. Not because of some hypothetical future breach, but because right now, most organizations are operating across a mix of LLM tiers and tools with no unified picture of what data is going where or under what terms.</p>



<p>OpenAI, Anthropic and Google all operate a two-tier system. At the enterprise and API level, based on publicly available policies, the commitments are clear: Your data is not used for model training. But those protections only apply if everyone in your organization is using the enterprise tier. In practice, that is almost never the case.</p>



<p>Teams sign up for free accounts to test things quickly. Employees paste internal documents into consumer-tier tools because it is faster than raising a ticket. Contractors use personal subscriptions for client work. None of this is malicious. All of it is invisible to leadership.</p>



<p>And the consumer tiers operate under very different rules. OpenAI’s consumer <a href="https://developers.openai.com/api/docs/guides/your-data">ChatGPT</a> may use conversations for model improvement unless the user opts out. Google’s free Gemini tier works similarly. In September 2025, Anthropic introduced changes to its <a href="https://www.anthropic.com/news/updates-to-our-consumer-terms" rel="nofollow">consumer terms</a>: Conversations are now eligible for training by default, with data retention extending from 30 days to up to five years.</p>



<p>This is the shadow AI problem. Corporate data entering consumer-tier systems where it may be retained for extended periods and processed under terms nobody in the organization approved. Not because anyone made a bad decision, but because no one made a deliberate one.</p>



<p>When a regulator in Riyadh asks how your organization handles personal data processed through an LLM, or a client in Doha wants to know where their documents went after your team used AI to summarise them, “we think we are on the enterprise tier” is not a defensible answer. The problem is not that something has gone wrong. It is that most organizations could not prove things are going right.</p>



<h2 class="wp-block-heading">The sovereignty map is more complicated than people think</h2>



<p>Most conversations about data sovereignty still default to one question: Where is the data stored? In the context of AI, that is not enough.</p>



<p>I work across the UK, the Gulf and Europe. Each region is moving toward stronger data protection, but they are getting there differently, at different speeds and with different expectations. For any organization operating across borders, that creates real tension.</p>



<p>In Europe, GDPR set the foundation and the EU AI Act is raising the bar further. In Saudi Arabia, the PDPL is no longer a paper exercise. SDAIA issued 48 <a href="https://iapp.org/news/a/saudi-arabia-s-data-protection-authority-steps-up-enforcement">enforcement decisions</a> in 2025 and published cross-border transfer rules requiring a four-step risk assessment before personal data leaves the Kingdom. In Qatar, the PDPPL has been in place since 2016, but enforcement was historically light. That changed in late 2024, with the National Data Privacy Office now issuing binding decisions against organizations found in violation.</p>



<p>Now add the LLM layer.</p>



<p>When an organization sends data through a cloud-based LLM, the question is not just where the data is stored. It is where the data is processed at inference time. Your infrastructure might sit in Riyadh, but if the model processes your prompt on a server in another jurisdiction, most legal frameworks would say sovereignty has not been preserved.</p>



<p>And as organizations move toward agentic AI, this gets harder still. Agents do not respond to a single prompt. They retrieve context from multiple sources, call external tools and chain decisions across systems. Each step is a potential jurisdiction question and a potential compliance gap that nobody mapped.</p>



<p>Sovereignty is not just geography. It has at least four dimensions: Where data and compute reside, who manages them, who owns the underlying technology and who governs it. Most organizations are only thinking about the first one.</p>



<h2 class="wp-block-heading">The real trade-off: Pay to keep your data or pay with your data</h2>



<p>Once an organization recognises the sovereignty problem, the natural instinct is to bring everything in-house. Run your own models, keep your data on your own infrastructure, remove the dependency on external providers entirely.</p>



<p>That instinct is understandable. It is also expensive.</p>



<p>Local models like Llama and Mistral give you full control. No data leaves your boundary. No third-party terms to worry about. No inference happening in a jurisdiction you did not choose. On paper, it solves the problem.</p>



<p>In practice, a production-grade on-premise deployment for a 70 billion parameter model costs anywhere from $40,000 to $190,000 in hardware alone. Self-hosting only becomes cost-effective if you are processing above roughly two million tokens per day. Below that, the API is cheaper. On top of the hardware, you need the talent to deploy, fine-tune, secure, patch and maintain these systems over time. That is not a one-off cost. It is an ongoing operational commitment that most organizations underestimate.</p>



<p>And there is a capability gap. The frontier models, the ones that perform best on complex reasoning, coding, analysis and multi-step tasks, are not available for self-hosting. If your use case demands the best available performance, you are using an API. That means your data is leaving your boundary, processed under someone else’s terms, in someone else’s infrastructure.</p>



<p>So, the trade-off is real. At the extremes, you are either paying serious money to keep your data close, or you are paying with your data by accepting terms you may not fully understand. Most organizations sit somewhere in between, but very few have made that choice deliberately. It happened by default. Someone picked a tool, someone else signed up for an account, a pilot became production and suddenly the organization is operating across a patchwork of tiers, agreements and jurisdictions that nobody designed and nobody fully controls.</p>



<p>This is not a technology decision. It is a strategic one. And it belongs in the boardroom, not buried in an IT procurement process.</p>



<h2 class="wp-block-heading"><a></a>The market is already restructuring around sovereignty</h2>



<p>If you want to know where enterprise AI is heading, follow the money.</p>



<p>The sovereign cloud market is projected to grow from $154 billion in 2025 to over $800 billion by 2032. That is not a forecast driven by hype. It is driven by enterprise buyers telling their providers: We need to control where our data lives and how it is processed.</p>



<p>The response has been significant. <a href="https://blogs.microsoft.com/blog/2026/02/24/microsoft-sovereign-cloud-adds-governance-productivity-and-support-for-large-ai-models-securely-running-even-when-completely-disconnected/" rel="nofollow">Microsoft</a> launched Foundry Local, which lets organizations run large AI models on their own hardware in fully disconnected environments, and committed to processing Copilot interactions in-country for 15 nations by the end of 2026. Google and Oracle are pushing a model where AI services move to where the data lives rather than the other way around, deploying their cloud stacks inside customer infrastructure and sovereign regions.</p>



<p>These are not experimental initiatives. They are multi-billion-dollar structural shifts. And they tell me something important: The providers are not leading this conversation. They are responding to it.</p>



<p>But it is worth being honest about what sovereign offerings deliver today. They come with cost premiums, longer deployment timelines and in some cases a reduced feature set. The trade-off does not disappear. It changes shape. CIOs still need to understand what sovereignty means for their specific context, not just trust that a sovereign label on a cloud product solves the problem.</p>



<h2 class="wp-block-heading">What CIOs should be doing now</h2>



<p>If I were advising a CIO today, I would not start with tools or vendors. I would start with visibility.</p>



<p>Know exactly what data flows through which LLM and under what terms. Not at the contract level, at the actual usage level. Which teams are using which tools? Are they on consumer or enterprise tiers? Who approved the terms? If you cannot answer those questions today, that is the first problem to solve.</p>



<p>Map your data exposure against every jurisdiction you operate in, and do not stop at storage. Understand where inference happens. Understand where context is retrieved from. If you are operating across the EU, Saudi Arabia and Qatar, those are three different regulatory frameworks with three different enforcement postures, and the LLM layer touches all of them.</p>



<p>Audit for shadow AI. Not as a one-off exercise, but as a recurring part of your governance. Employees are not going to stop using AI tools. The goal is not to block adoption. It is to make sure adoption happens on terms the organization has chosen deliberately.</p>



<p>Do not default to local models out of fear or cloud models out of convenience. Make the trade-off intentionally, with real cost and capability analysis behind it. Understand what you gain and what you give up in each direction and make sure that decision is documented and owned at the right level.</p>



<p>Build procurement frameworks that treat LLM data handling as a first-class requirement. Not a footnote in a vendor assessment, but a core criterion alongside security, resilience and performance. If a provider cannot clearly explain what happens to your data, that is not a gap in their documentation. It is a gap in their offering.</p>



<p>The readiness gap is real. 95% of enterprise leaders say they plan to build sovereign AI foundations. Based on current research, only 13% are on track. The organizations that close that gap first will scale faster, win more trust and defend their choices with confidence. The rest will have the conversation forced on them.</p>



<h2 class="wp-block-heading"><a></a>From AI capability to AI sovereignty</h2>



<p>For the last couple of years, the focus has been on what AI can do. Bigger models, faster outputs, more automation. That progress is real and I do not think anyone should slow down.</p>



<p>But I think the next phase will be defined by something different. Not capability, but control. Not what the model can do, but whether you can prove you know where your data went, who had access to it, what terms governed it and what happens to it next.</p>



<p>CIOs will not be judged on whether they adopted AI. They will be judged on whether they adopted it in a way they can defend. To a regulator. To a client. To a board. In plain language, with evidence they can stand behind.</p>



<p>In my first <a href="https://www.cio.com/article/4132817/ai-isnt-the-risk-not-being-able-to-explain-it-is.html">article</a> for CIO Network, I argued that explainability is the control layer that makes AI safe to scale. Data sovereignty is the other half of that equation. Explainability answers “why did the system do that?” Sovereignty answers “where did the data go and who controls it?”</p>



<p>If you can answer both, you can scale with confidence. If you cannot, you are building on a foundation you do not fully own.</p>



<p>And once that foundation is questioned, it is very difficult to rebuild.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 startet plötzlich mehrfach neu – das ist der Grund]]></title>
<description><![CDATA[Einige Nutzer von Windows 11 berichten derzeit von ungewöhnlichem Verhalten nach aktuellen Updates: Der PC startet während der Installation nicht nur einmal, sondern gleich mehrfach neu. Das kann schnell den Eindruck erwecken, dass ein Fehler vorliegt oder das System beschädigt ist. Das berichtet...]]></description>
<link>https://tsecurity.de/de/3488716/it-nachrichten/windows-11-startet-ploetzlich-mehrfach-neu-das-ist-der-grund/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488716/it-nachrichten/windows-11-startet-ploetzlich-mehrfach-neu-das-ist-der-grund/</guid>
<pubDate>Tue, 05 May 2026 10:02:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Einige Nutzer von Windows 11 berichten derzeit von ungewöhnlichem Verhalten nach aktuellen Updates: Der PC startet während der Installation nicht nur einmal, sondern gleich mehrfach neu. Das kann schnell den Eindruck erwecken, dass ein Fehler vorliegt oder das System beschädigt ist. Das berichtet das Portal <a href="https://www.windowslatest.com/2026/05/05/microsoft-confirms-windows-11-may-restart-multiple-times-after-updates-and-your-pc-isnt-broken-as-its-due-to-secure-boot-2023/" target="_blank" rel="noreferrer noopener">Windows Latest</a> unter Berufung auf ein aktualisiertes Support-Dokument von Microsoft.</p>



<p>Doch laut Microsoft ist genau dieses Verhalten in bestimmten Fällen beabsichtigt.</p>



<h2 class="wp-block-heading">Mehrere Neustarts sind aktuell kein Fehler</h2>



<p>Wie aus einem <a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4825" target="_blank" rel="noreferrer noopener">aktualisierten Support-Dokument</a> hervorgeht, kann es bei aktuellen und kommenden Updates vereinzelt zu zusätzlichen Neustarts kommen. Hintergrund ist die Verteilung neuer Sicherheitszertifikate im Rahmen von Secure Boot.</p>



<p>Normalerweise benötigen monatliche Windows-Updates nur einen einzigen Neustart. Mehrere Reboots sind sonst eher von großen Funktionsupdates oder bei Firmware- und Treiberinstallationen bekannt.</p>



<p>Aktuell kann es jedoch auch bei regulären Updates passieren, dass Windows zwei- oder sogar dreimal neu startet.</p>



<h2 class="wp-block-heading">Ursache: Neue Secure-Boot-Zertifikate</h2>



<p>Konkret geht es um die sogenannten „Secure Boot 2023“-Zertifikate. Diese ersetzen ältere Zertifikate aus dem Jahr 2011, die im Juni 2026 auslaufen.</p>



<p>Damit Systeme weiterhin sicher starten können, müssen diese neuen Zertifikate installiert werden. Dieser Prozess kann einen zusätzlichen Neustart erfordern.</p>



<p>Laut Microsoft betrifft das nur eine begrenzte Anzahl von Geräten. Der zusätzliche Neustart tritt dabei einmalig im Rahmen dieses Updates auf.</p>



<h2 class="wp-block-heading">So prüfen Sie den Status auf Ihrem PC</h2>



<p>Ob Ihr System bereits aktualisiert wurde, können Sie direkt unter Windows überprüfen:</p>



<ul class="wp-block-list">
<li>Öffnen Sie die Windows-Sicherheit</li>



<li>Navigieren Sie zu „Gerätesicherheit“</li>



<li>Prüfen Sie den Bereich „Secure Boot“</li>
</ul>



<p>Dort zeigt Windows den Status mit Symbolen an:</p>



<ul class="wp-block-list">
<li><strong>Grün:</strong> Alles aktuell, keine Aktion erforderlich</li>



<li><strong>Gelb:</strong> Update steht noch aus, wird automatisch nachgeholt</li>



<li><strong>Rot:</strong> Handlungsbedarf, Installation konnte nicht abgeschlossen werden</li>
</ul>



<p>Wichtig: Ein grünes Symbol bedeutet nur dann Entwarnung, wenn zusätzlich angezeigt wird, dass alle erforderlichen Zertifikate installiert sind.</p>



<h3 class="wp-block-heading">Probleme vor allem bei älteren Geräten möglich</h3>



<p>Nicht alle PCs können die neuen Zertifikate problemlos erhalten. Voraussetzung ist eine aktuelle Firmware beziehungsweise ein passendes BIOS-Update.</p>



<p>Gerade bei älteren Geräten kann es vorkommen, dass diese Updates nicht mehr bereitgestellt werden. In solchen Fällen kann die Installation der neuen Zertifikate scheitern.</p>



<p>Wenn Windows hier einen Fehler meldet, ist meist der Gerätehersteller gefragt. Ohne entsprechende Firmware-Unterstützung lässt sich das Problem oft nicht lösen.</p>



<h2 class="wp-block-heading">Kein Grund zur Panik</h2>



<p>Wenn Ihr PC nach einem Update mehrfach neu startet, ist das derzeit in vielen Fällen normal. Ein Defekt liegt in der Regel nicht vor. Sie sollten jedoch prüfen, ob die Sicherheitszertifikate korrekt installiert wurden. Nur so ist sichergestellt, dass Ihr System auch künftig sicher startet.</p>



<p><strong>Mehr zum Thema: </strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3130964/probleme-mit-dem-backup-programm-nach-einem-windows-update.html" target="_blank" rel="noreferrer noopener">Windows 11 April-Update sorgt jetzt auch noch für Probleme mit Backup-Programmen</a></li>



<li><a href="https://www.pcwelt.de/article/3130738/windows-11-soll-endlich-besser-werden-microsoft-startet-grosse-aenderungen.html" target="_blank" rel="noreferrer noopener">Windows 11 soll endlich besser werden – Microsoft startet große Änderungen</a></li>



<li><a href="https://www.pcwelt.de/article/3130361/microsoft-schockt-gamer-so-viel-ram-braucht-windows-11-wirklich.html" target="_blank" rel="noreferrer noopener">Microsoft schockt Gamer: So viel RAM braucht Windows 11 wirklich</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft confirms Windows 11 may restart multiple times after updates and your PC isn’t broken, as it’s due to Secure Boot 2023]]></title>
<description><![CDATA[Microsoft has clarified that Windows 11 restarting more than once after an update is expected behavior, not a sign of a failed install.
The post Microsoft confirms Windows 11 may restart multiple times after updates and your PC isn’t broken, as it’s due to Secure Boot 2023 appeared first on Windo...]]></description>
<link>https://tsecurity.de/de/3488071/windows-tipps/microsoft-confirms-windows-11-may-restart-multiple-times-after-updates-and-your-pc-isnt-broken-as-its-due-to-secure-boot-2023/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488071/windows-tipps/microsoft-confirms-windows-11-may-restart-multiple-times-after-updates-and-your-pc-isnt-broken-as-its-due-to-secure-boot-2023/</guid>
<pubDate>Tue, 05 May 2026 03:23:38 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has clarified that Windows 11 restarting more than once after an update is expected behavior, not a sign of a failed install.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/05/05/microsoft-confirms-windows-11-may-restart-multiple-times-after-updates-and-your-pc-isnt-broken-as-its-due-to-secure-boot-2023/">Microsoft confirms Windows 11 may restart multiple times after updates and your PC isn’t broken, as it’s due to Secure Boot 2023</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU DMA after-action review didn't go the way that Apple wanted]]></title>
<description><![CDATA[Apple's vice president of products & regulatory law Kyle Andeer lashed out at the European Union's Digital Markets Act, repeating the refrains that unfair targeting and requirement that it must share tech with rivals will put users worldwide at risk.Apple slams EU DMA over privacy and innovation ...]]></description>
<link>https://tsecurity.de/de/3487447/ios-mac-os/eu-dma-after-action-review-didnt-go-the-way-that-apple-wanted/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487447/ios-mac-os/eu-dma-after-action-review-didnt-go-the-way-that-apple-wanted/</guid>
<pubDate>Mon, 04 May 2026 23:08:52 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's vice president of products &amp; regulatory law Kyle Andeer lashed out at the European Union's Digital Markets Act, repeating the refrains that unfair targeting and requirement that it must share tech with rivals will put users worldwide at risk.<br><br><div><img src="https://photos5.appleinsider.com/gallery/64368-134123-00-lede-EU-xl.jpg" alt="European Union flags waving in front of a modern glass building with a curved facade." height="720"><br><span>Apple slams EU DMA over privacy and innovation risks</span></div><br>Two years after the Digital Market Act went <a href="https://appleinsider.com/articles/24/03/07/apple-isnt-done-with-concessions-in-ios-to-placate-the-european-union">into effect</a>, Apple is still vehemently opposed to the European Union telling it what to do.<br><br>It's hardly a new stance. Apple has been beating the same drum since the Digital Markets Act (DMA) was <a href="https://appleinsider.com/articles/20/11/19/apple-invited-to-discuss-proposed-eu-digital-regulations">first proposed</a>.<br><br><br> <a href="https://appleinsider.com/articles/26/05/04/eu-dma-after-action-review-didnt-go-the-way-that-apple-wanted?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244235?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple is preparing to spend, but not necessarily on AI]]></title>
<description><![CDATA[Apple last week nixed its long-held “net cash neutral” target, a move analysts see as giving the company more flexibility to make massive infrastructure investments or acquisitions. Naturally, as AI is the only thing that seems to matter in tech these days, commentators rushed to speculate on pot...]]></description>
<link>https://tsecurity.de/de/3486689/it-nachrichten/apple-is-preparing-to-spend-but-not-necessarily-on-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486689/it-nachrichten/apple-is-preparing-to-spend-but-not-necessarily-on-ai/</guid>
<pubDate>Mon, 04 May 2026 17:34:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple last week <a href="https://www.computerworld.com/article/4165995/apple-breaks-records-admits-it-cant-make-macs-fast-enough.html">nixed its long-held “net cash neutral” target</a>, a move analysts see as giving the company more flexibility to make massive infrastructure investments or acquisitions. Naturally, as AI is the only thing that seems to matter in tech these days, commentators rushed to speculate on potential acquisition targets in the AI space.</p>



<p>The thing is, this may not be about AI. </p>



<p>Now that Apple has <a href="https://www.computerworld.com/article/4161377/with-john-ternus-as-ceo-expect-apples-platforms-to-proliferate.html">confirmed John Ternus as its next CEO</a>, the market can stop treating the company’s cash shift as speculative and start treating it as strategic. Ternus, a hardware‑first leader by background, understands the value of services and has <a href="https://www.bloomberg.com/news/newsletters/2026-04-26/new-apple-ceo-john-ternus-first-major-product-is-the-foldable-iphone-road-map-mofu521p" target="_blank" rel="noreferrer noopener">pledged to expand Apple’s services business</a>. </p>



<h2 class="wp-block-heading"><strong>Services, services, services</strong></h2>



<p>The great thing about services is that they provide the company with a solid and predictable revenue stream to insulate it from fluctuations in product-driven business. We’ve seen this in the last few years, with Apple’s dramatically climbing services income acting as a cushion against slow product quarters, empowering the company to return successive record results. There is no doubt the high margins generated by services oils Apple’s business machinery.</p>



<p>“I look forward to continuing to expand that and continuing to look for the kinds of services where we’re really finding the opportunities between the hardware and software,” <a href="https://9to5mac.com/2026/04/27/john-ternus-says-apple-has-so-much-opportunity-to-expand-services/#:~:text=And%20so%20I%20look%20forward,Pay%20is%20an%20incredible%20one." target="_blank" rel="noreferrer noopener">Ternus said</a>, pointing particularly at Apple Pay. </p>



<p>Years of watching the company tells me that Apple tends to leave the truth in plain sight if you happen to be sensitive to it; I read that statement as suggesting the company is preparing to introduce its latest Apple Pay service updates.</p>



<h2 class="wp-block-heading"><strong>Apple Card for the rest of us?</strong></h2>



<p>The most widely awaited of these would be the introduction of an upgraded Apple Card service with a new provider. The limitation of the Apple Card (other than the waning enthusiasm of card partner, Goldman Sachs and the long journey to <a href="https://www.computerworld.com/article/4114448/jp-morgan-chase-wins-the-hunt-for-the-apple-card.html">find a new partnership with JP Morgan Chase</a>) is that it is still only available in the US, <a href="https://www.applemust.com/is-apple-preparing-to-go-global-with-apple-cash-and-card/" target="_blank" rel="noreferrer noopener">despite global interest</a>. It is challenging for Apple to meet that interest due to a smorgasbord of different data, financial services, and local regulations. Apple Card in India, for instance, would be challenged by local regulations that forbid banking partners from storing transaction data, while in Europe the reward structure would need to be revised to consider the much lower interchange fees charged for credit card transactions there. </p>



<p>Ultimately, whoever Apple works with on the service would have to accommodate credit risk and it’s probable the computer company will need to underwrite some of that risk. If it wants to expand this service internationally — perhaps with the provision of additional banking services in some nations — this would be a good use of Apple’s ongoing money mountain, enabling it to deepen its move into financial services.</p>



<h2 class="wp-block-heading"><strong>A world of opportunities</strong></h2>



<p>Of course, Apple Card is far from the only service that could benefit from Apple’s decision to use cash more strategically. Beyond any potential AI acquisitions, the company could also take positions in streaming entertainment partners, for example; the ever-speculated on Disney purchase is just one of a multitude of options there, but Netflix also seems within Apple’s multi-billion dollar reach.</p>



<p>Apple also has the good fortune to sit at the crossroads of technology, the liberal arts, and health, so it could think about health insurance as a potential space for services expansion. Also, given the company’s continued move to rebuild its business along the lines of a closed loop manufacturing chain, at what point does it make sense for it to invest in its own clean energy supply? </p>



<p>Stop to think about it and there really are a ton of highly profitable options for major Apple investments that could drive the business forward, and many of these have nothing much to do with AI (except, of course, software). Perhaps that’s a good thing. </p>



<h2 class="wp-block-heading"><strong>Smart about AI</strong></h2>



<p>The rapid pace of AI development and deployment almost certainly mean the <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">fundamentals of the AI landscape will change swiftly</a>. Server-based AI might remain the interaction for most of us, but high-value services will inevitably be found in on-premises, sovereign, ultra-secure, and/or edge device AI. </p>



<p>That rapid evolution means a billion spent on an essential component today could be meaningless in five years. Plus, with a multitude of emerging AI companies, it’s inevitable some — potentially with valuable technologies — will fail. </p>



<p>In this context, it makes sense for Apple to crouch, tiger-like, waiting to jump in to make strategic acquisitions as the competitive environment forces some of the smaller AI players to the wall. Apple won’t be alone in any potential bidding wars, but its decision to use its cash flow strategically means it might nail some of those deals. </p>



<h2 class="wp-block-heading"><strong>Coming soon?</strong></h2>



<p>The timing of Apple’s news about its handling of cash matters. Now that shareholders have been told to expect it, the business can change direction. </p>



<p>Should we expect any immediate moves? If the company has any quick plans, it’s possible we <a href="https://www.applemust.com/apple-announces-important-wwdc-conference-begins-june-8/" target="_blank" rel="noreferrer noopener">may learn more at WWDC in June</a> — or perhaps at the big iPhone reveal this fall, when the <a href="https://www.computerworld.com/article/4161377/with-john-ternus-as-ceo-expect-apples-platforms-to-proliferate.html">Cook-Ternus transition is complete</a>. Ultimately, Apple’s next phase won’t be defined solely by what it does acquire, but in which parts of the business it chooses to invest.</p>



<p><em>Please follow me on social media: <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, or <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sunday Reboot: Motorsport, money, and 'Ted Lasso']]></title>
<description><![CDATA[In this week's "Sunday Reboot," Apple drives on with F1 in Miami, Q2 was a financial spectacular, and 'Ted Lasso' season 4 can't arrive fast enough.Formula 1, Apple's financials, and Apple TVSunday Reboot is a weekly column covering some of the lighter stories within the Apple reality distortion ...]]></description>
<link>https://tsecurity.de/de/3484357/ios-mac-os/sunday-reboot-motorsport-money-and-ted-lasso/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484357/ios-mac-os/sunday-reboot-motorsport-money-and-ted-lasso/</guid>
<pubDate>Sun, 03 May 2026 22:36:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this week's "Sunday Reboot," Apple drives on with F1 in Miami, Q2 was a financial spectacular, and 'Ted Lasso' season 4 can't arrive fast enough.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67532-142246-sundayreboot2-xl.jpg" alt="Formula 1 race car speeding on track with Apple TV logo and blue vertical bars behind, suggesting a broadcast or streaming concept combining motorsport and digital media"><br><span>Formula 1, Apple's financials, and Apple TV</span></div><br>Sunday Reboot is a weekly column covering some of the lighter stories within the Apple reality distortion field from the past seven days. All to get the next week underway with a good first step.<br><br>This week, there were rumors the <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro</a> hardware team was <a href="https://appleinsider.com/articles/26/04/29/rumored-apple-vision-pro-team-break-up-isnt-a-death-knell-for-the-product">breaking up</a>, Adobe's <a href="https://appleinsider.com/articles/26/04/28/adobe-firefly-ai-assistant-is-in-open-beta-its-not-great">Firefly AI Assistant</a> showed just why it was still in beta, the Towson Apple Store employee union complained about <a href="https://appleinsider.com/articles/26/04/27/towson-apple-store-employee-union-strikes-back-allege-unfair-treatment-after-closure">the store closure</a>, and Apple has to face the Circuit Court and the Supreme Court at the same time over its ongoing saga <a href="https://appleinsider.com/articles/26/04/29/app-store-policy-must-change-as-epic-convinces-us-circuit-court-to-reverse-stay">with Epic Games</a>.<br><br><br> <a href="https://appleinsider.com/articles/26/05/03/sunday-reboot-motorsport-money-and-ted-lasso?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244227?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug.]]></title>
<description><![CDATA[When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug.How a “low severity” simple P4 bug still managed to teach a high-value lesson (and yes… it paid 💰). Beginner friendly…⚠️ Disclaimer.This was conducted under authorized testing conditions for educational and security research purposes. N...]]></description>
<link>https://tsecurity.de/de/3481896/hacking/when-logout-isnt-really-goodbye-a-subtle-data-exposure-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3481896/hacking/when-logout-isnt-really-goodbye-a-subtle-data-exposure-bug/</guid>
<pubDate>Sat, 02 May 2026 09:51:57 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yQgSJJkVPmOxzyw9S6uQ5Q.png"></figure><p>How a “low severity” simple P4 bug still managed to teach a high-value lesson (and yes… it paid 💰). Beginner friendly…</p><h3>⚠️ Disclaimer.</h3><p>This was conducted under <strong>authorized testing conditions</strong> for educational and security research purposes. No data was abused, and the issue has been responsibly disclosed and fixed.</p><h3>🧩 The Discovery.</h3><p>While testing authentication flows on a government-backed login system, I came across something that felt… off.</p><p>The application used a modern <strong>SSO login flow via QR code</strong>. Everything worked as expected:</p><ul><li>Login was smooth.</li><li>Session handling seemed solid.</li><li>Logout confirmed success.</li></ul><p>But then came a simple action that changed everything:</p><p>👉 I clicked the <strong>browser back button</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tSFauYycn-Z1OqEeiqBdkg.png"><figcaption>PoC</figcaption></figure><p>And just like that, my <strong>previously authenticated page reappeared</strong>, fully populated with <strong>sensitive personal information</strong> — even though I had already logged out.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qNa2JrW6OsbOxKWyyJTThA.png"><figcaption>PoC</figcaption></figure><h3>What Was Happening?</h3><p>At first glance, it looked like a <strong>broken logout</strong> or even a <strong>session hijacking opportunity</strong>. But deeper testing told a different story.</p><p>Here’s what I confirmed:</p><ul><li>✅ Logout endpoint worked correctly.</li><li>✅ Session was invalidated server-side.</li><li>✅ Any refresh or API call returned <strong>401 Unauthorized.</strong></li><li>❌ Yet sensitive data was still visible after pressing <strong>Back.</strong></li></ul><p>So what gives?</p><h3>The Technical Explanation.</h3><p>This behavior is caused by the browser’s <strong>Back/Forward Cache (bfcache)</strong>.</p><p>Instead of making a new request, the browser:</p><ul><li>Restores the entire page from memory.</li><li>Skips revalidation with the server.</li><li>Displays the previous DOM instantly.</li></ul><p>Even though the server has <strong>terminated the session</strong>, the browser is simply <strong>replaying what it already rendered</strong>.</p><p>And importantly:</p><pre>Cache-Control: no-cache, must-revalidate<br>Pragma: no-cache</pre><p>These headers do <strong>not fully prevent bfcache</strong>.</p><h3>Why This Matters.</h3><p>You might think:</p><blockquote><em>“If the session is dead, what’s the big deal?”</em></blockquote><p>Here’s the real-world risk.</p><h3>Scenario: Shared Device Exposure.</h3><ol><li>A user logs into their account on a <strong>public or shared computer.</strong></li><li>They log out and walk away.</li><li>Another user presses the <strong>Back button.</strong></li><li>Sensitive information is instantly revealed:</li></ol><ul><li>Names.</li><li>Emails.</li><li>Account details.</li><li>Possibly government-linked identifiers/IDs.</li></ul><p>Even without interaction, <strong>confidential data is exposed</strong>.</p><h3>⚖️ Severity: Why This Is “Only” P4.</h3><p>From a bug bounty perspective, this is typically classified as:</p><blockquote><strong><em>Sensitive Information Exposure via Client-Side Cache.</em></strong></blockquote><p>Why not higher?</p><ul><li>❌ No session reuse.</li><li>❌ No unauthorized API access.</li><li>❌ No privilege escalation.</li><li>❌ No account takeover.</li></ul><p>✔️ Data is <strong>not retrievable from the server.</strong><br>✔️ The issue is <strong>purely client-side rendering.</strong></p><p>So it lands as:</p><ul><li><strong>Low severity (P4).</strong></li><li>Sometimes <strong>Informational.</strong></li></ul><p>But don’t let that fool you — it’s still a <strong>real privacy concern</strong>.</p><h3>🏗️ What Better Implementations Look Like.</h3><p>Some applications go a step further.</p><p>Instead of allowing cached pages to render, they:</p><h3>🔁 Force Reload on Back Navigation.</h3><pre>window.onpageshow = function (event) {<br>    if (event.persisted) {<br>        window.location.reload();<br>    }<br>};</pre><h3>🔒 Or Redirect Immediately.</h3><ul><li>Detect invalid session.</li><li>Show <strong>“Session expired”.</strong></li><li>Prevent sensitive UI from appearing at all.</li></ul><p>That’s why you may notice:</p><blockquote><em>Some sites </em>never<em> show old data after logout — even with the back button.</em></blockquote><h3>🧠 Key Takeaway.</h3><p>This bug highlights an important principle:</p><blockquote><strong><em>Security isn’t just about blocking access — it’s also about controlling what remains visible.</em></strong></blockquote><p>Even when:</p><ul><li>Authentication is correct.</li><li>Sessions are invalidated.</li><li>APIs are protected.</li></ul><p>You can still have <strong>residual data exposure</strong>.</p><h3>📝 Final Thoughts.</h3><p>This wasn’t a flashy bug.<br>No bypasses. No exploits. No takeover.</p><p>Just a simple browser action — revealing a subtle gap between:</p><ul><li><strong>Server-side security.</strong></li><li><strong>Client-side behavior.</strong></li></ul><p>And that’s exactly why it matters.</p><p>Because sometimes, the most overlooked issues are the ones sitting <strong>right in front of the user’s screen</strong>.</p><h3>📝 The Report (and the bounty part).</h3><p>I documented everything properly:</p><ul><li>Steps to reproduce.</li><li>Screenshots.</li><li>Network behavior.</li><li>Impact (without exaggeration — very important).</li></ul><p>Submitted it.</p><p>Waited…</p><p>And then:</p><p>👉 <strong>Accepted.</strong><br>👉 <strong>Issue acknowledged.</strong><br>👉 <strong>Got paid. 💰</strong><br>👉 <strong>Fix implemented. ✅</strong></p><p>Now when you hit Back?</p><p>No more surprise reunion with your old session 😄</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*QEXguTVLlPzkmmWZcvisCQ.png"></figure><p>Thanks for reading. If this made you smile (or double-check your logout 😅), feel free to leave some 👏, on “X” as <a href="https://x.com/ethical_h4ck3r_">https://x.com/ethical_h4ck3r_</a> follow for more security research and write-ups.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=271b683ddb9a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/when-logout-isnt-really-goodbye-a-subtle-data-exposure-bug-271b683ddb9a">When Logout Isn’t Really Goodbye: A Subtle Data Exposure Bug.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Vision Pro isn't dead, Ternus talk, & AI rumors on the AppleInsider Podcast]]></title>
<description><![CDATA[An odd rumor led to premature calls of Apple Vision Pro's death, rumors of AI and Home Hubs abound, and Apple's App Store troubles continue on the AppleInsider Podcast.Apple Vision Pro isn't deadAppleInsider Managing Editor Mike Wuerthele joins host Wesley Hilliard as a guest this week to catch u...]]></description>
<link>https://tsecurity.de/de/3480394/ios-mac-os/apple-vision-pro-isnt-dead-ternus-talk-ai-rumors-on-the-appleinsider-podcast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480394/ios-mac-os/apple-vision-pro-isnt-dead-ternus-talk-ai-rumors-on-the-appleinsider-podcast/</guid>
<pubDate>Fri, 01 May 2026 14:54:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An odd rumor led to premature calls of <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro's</a> death, rumors of AI and Home Hubs abound, and Apple's App Store troubles continue on the AppleInsider Podcast.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67521-142189-IMG_4348-xl.jpg" alt="Apple Vision Pro headset resting on a desk beside a compact keyboard with colorful keys and a smartphone, softly lit with a blurred background and AI logo in the top right corner"><br><span>Apple Vision Pro isn't dead</span></div><br><em>AppleInsider</em> Managing Editor Mike Wuerthele joins host Wesley Hilliard as a guest this week to catch up on CEO transition news. It's clear that the silly coverage surrounding the upcoming transition is already becoming exhausting.<br><br>The Apple vs Epic trial continues to be an ongoing event that seems to have no end. This time, Apple has to go to the Supreme Court and Circuit Courts at once.<br><br><br> <a href="https://appleinsider.com/articles/26/05/01/apple-vision-pro-isnt-dead-ternus-talk-ai-rumors-on-the-appleinsider-podcast?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244213?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Slop Problem Isn’t What You Think]]></title>
<description><![CDATA[There’s a bloke on Twitter who spent three hours writing a passionate thread about AI ruining the internet. There was quite the debate, and someone asked if he’d ever used Grammarly. That’s the whole story, really. People call AI content…
Read more →
The post The Slop Problem Isn’t What You Think...]]></description>
<link>https://tsecurity.de/de/3479198/it-security-nachrichten/the-slop-problem-isnt-what-you-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479198/it-security-nachrichten/the-slop-problem-isnt-what-you-think/</guid>
<pubDate>Fri, 01 May 2026 02:51:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>There’s a bloke on Twitter who spent three hours writing a passionate thread about AI ruining the internet. There was quite the debate, and someone asked if he’d ever used Grammarly. That’s the whole story, really. People call AI content…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-slop-problem-isnt-what-you-think/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-slop-problem-isnt-what-you-think/">The Slop Problem Isn’t What You Think</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[QuEra claims quantum error correction breakthrough with 2-to-1 qubit ratio]]></title>
<description><![CDATA[Quantum computers are prone to high error rates, so, to make qubits usable, a lot of redundancy is required. It typically takes hundreds—even thousands—of physical qubits to make one usable, “logical” qubit.



This has been a major obstacle to the development of practical quantum computers. If t...]]></description>
<link>https://tsecurity.de/de/3477990/it-security-nachrichten/quera-claims-quantum-error-correction-breakthrough-with-2-to-1-qubit-ratio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477990/it-security-nachrichten/quera-claims-quantum-error-correction-breakthrough-with-2-to-1-qubit-ratio/</guid>
<pubDate>Thu, 30 Apr 2026 16:53:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.networkworld.com/article/4115513/what-enterprises-think-about-quantum-computing.html" target="_blank">Quantum computers</a> are prone to high error rates, so, to make qubits usable, a lot of redundancy is required. It typically takes hundreds—even thousands—of physical qubits to make one usable, “logical” qubit.</p>



<p>This has been a major obstacle to the <a href="https://www.networkworld.com/article/4117438/quantum-computing-is-getting-closer-but-quantum-proof-encryption-remains-elusive.html" target="_blank">development of practical quantum computers</a>. If thousands of qubits are needed for a quantum computer to do anything useful, and it takes a thousand physical qubits to make one logical one, then we’re talking millions of qubits—and, today, the largest qubit array is just <a href="https://www.caltech.edu/about/news/caltech-team-sets-record-with-6100-qubit-array" target="_blank" rel="noreferrer noopener">more than 6,000 qubits</a>, and that was an experimental demonstration.</p>



<p>The <a href="https://guinnessworldrecords.de/world-records/most-powerful-quantum-computer" target="_blank" rel="noreferrer noopener">largest general-purpose quantum computers</a> today are <a href="https://www.ibm.com/quantum/blog/quantum-roadmap-2033" target="_blank" rel="noreferrer noopener">IBM’s Condor</a>, with 1,121 superconducting qubits, and <a href="https://atom-computing.com/ac1000/" target="_blank" rel="noreferrer noopener">Atom Computing’s AC1000</a> with more than 1,200 neutral atom qubits—and both counts are for physical qubits, not logical qubits.</p>



<p>Last week, quantum computing company <a href="https://www.quera.com/blog-posts/quantum-error-correction-at-record-efficiency-why-neutral-atoms-are-leading-the-way" target="_blank" rel="noreferrer noopener">QuEra published a paper</a> showing that a logical qubit can be built with just two physical qubits. Neutral atom computers have two types of qubits—memory and computation—and these qubits can be moved from one mode to another. The two-to-one ratio is currently just for the memory qubits.</p>



<p>“The paper does not show—yet—that you can do operations on the qubit,” says Yuval Boger, chief commercial officer at QuEra Computing. “We’ve done it with other codes, but not this particular one. But without quantum memory, the quantum computer won’t work anyway.”</p>



<p>The same algorithm should also have a very significant improvement in error correction on the entangled computation side of the quantum computer as well, he adds. “But we haven’t published that result yet,” he says. “I’m sure that will be forthcoming.”</p>



<p>Like Atom Computing, QuEra makes a neutral atom quantum computer, and its <a href="https://www.quera.com/blog-posts/from-natures-perfect-qubits-to-the-worlds-first-hybrid-quantum-supercomputer" target="_blank" rel="noreferrer noopener">Gemini model</a> has 260 physical qubits and is commercially available.</p>



<p>“We’ve demonstrated a 3,000-qubit machine running continuously,” Boger adds.</p>



<p>That puts a usable quantum computer within sight, he says. “There is still work to be done. But it’s not years and years and years.”</p>



<p>The timeline has also been affected by recent changes in estimates as to how many qubits a quantum computer actually needs to be useful. For example, according to the latest Google research, it could take as few as 1,200 logical qubits for a <a href="https://www.networkworld.com/article/4158139/fixing-encryption-isnt-enough-quantum-developments-put-focus-on-authentication.html" target="_blank">quantum computer to break elliptic curve cryptography</a>.</p>



<p>The QuEra announcement is also helping position neutral atoms as a viable alternative to the superconducting approach, such as the one used by IBM, says Holger Mueller, analyst at Constellation Research.</p>



<p>“It’s the race for error correction,” he says. The question is whether QuEra’s approach will be the one that works. “How good or record-breaking the result is remains to be seen,” Mueller says.</p>



<p>And the paper is focused on memory, he adds, though the company plans to use the same algorithm for other qubits. “So, it is a key report to keep the neutral atom technology and vendors viable,” he says.</p>



<p>According to Sridhar Tayur, professor of operations management at Carnegie Mellon University’s Tepper School of Business, there are four levels of quantum computing breakthroughs.</p>



<p>“There’s something on paper, then there’s something in a lab, like a proof of concept,” he says. “Then there’s a prototype at scale, and then there’s production scale.”</p>



<p>The QuEra announcement is just at the research paper level, he says. Many people see these theoretical results, and their minds immediately jump to commercial products, he says. “But it’s not like they even have a physical demonstration of this,” Tayur says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rumored Apple Vision Pro team break-up isn't a death knell for the product]]></title>
<description><![CDATA[A new rumor suggests Apple Vision Pro hardware may be dead, but the dissolution of a team doesn't necessarily mean that pipeline is dead. If anything, it's business as usual.Apple Vision Pro isn't deadWhenever Apple releases a new product category, there seems to be this industry drive to find it...]]></description>
<link>https://tsecurity.de/de/3475752/ios-mac-os/rumored-apple-vision-pro-team-break-up-isnt-a-death-knell-for-the-product/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475752/ios-mac-os/rumored-apple-vision-pro-team-break-up-isnt-a-death-knell-for-the-product/</guid>
<pubDate>Wed, 29 Apr 2026 22:38:03 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new rumor suggests <a href="https://appleinsider.com/inside/apple-vision-pro" title="Apple Vision Pro" data-kpt="1">Apple Vision Pro</a> hardware may be dead, but the dissolution of a team doesn't necessarily mean that pipeline is dead. If anything, it's business as usual.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67504-142114-Apple-Vision-Pro-M5-stand-cameras-xl.jpg" alt="Close-up of an Apple Vision Pro headset, showing curved reflective visor, ventilation holes, soft gray fabric padding, and plastic headband against a softly lit background."><br><span>Apple Vision Pro isn't dead</span></div><br>Whenever Apple releases a new product category, there seems to be this industry drive to find its weak points and <a href="https://appleinsider.com/articles/26/01/01/analysts-need-apple-vision-pro-to-be-a-flop-whether-apple-considers-it-one-or-not">jab at it until it dies</a>. Apple Vision Pro may not be a blockbuster, but it is the entry point to Spatial Computing, which Apple still believes to <a href="https://appleinsider.com/articles/26/04/15/apple-at-50-spatial-computing-is-the-future-but-when-is-the-question">be its future</a>.<br><br>According to <a href="https://www.macrumors.com/2026/04/29/apple-vision-pro-m5-flop/">a report</a> from <em>MacRumors</em>, Apple Vision Pro hardware as it stands in April 2026 may truly be dead. The story suggests that Apple has likely given up on the platform due to a lack of consumer interest after the M5 update.<br><br><br> <a href="https://appleinsider.com/articles/26/04/29/rumored-apple-vision-pro-team-break-up-isnt-a-death-knell-for-the-product?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244197?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: Woah, a genuinely helpful AI-assisted bug report that isn’t total slop. Here, Wiz, take this wad of cash]]></title>
<description><![CDATA[Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub’s git infrastructure that handed remote attackers full…
Read more →
The post GitHub: Woah, a genuine...]]></description>
<link>https://tsecurity.de/de/3474584/it-security-nachrichten/github-woah-a-genuinely-helpful-ai-assisted-bug-report-that-isnt-total-slop-here-wiz-take-this-wad-of-cash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474584/it-security-nachrichten/github-woah-a-genuinely-helpful-ai-assisted-bug-report-that-isnt-total-slop-here-wiz-take-this-wad-of-cash/</guid>
<pubDate>Wed, 29 Apr 2026 15:23:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub’s git infrastructure that handed remote attackers full…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/github-woah-a-genuinely-helpful-ai-assisted-bug-report-that-isnt-total-slop-here-wiz-take-this-wad-of-cash/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/github-woah-a-genuinely-helpful-ai-assisted-bug-report-that-isnt-total-slop-here-wiz-take-this-wad-of-cash/">GitHub: Woah, a genuinely helpful AI-assisted bug report that isn’t total slop. Here, Wiz, take this wad of cash</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Parrot os wont install or recognize anything but my flash drive]]></title>
<description><![CDATA[Hello, im having an issue where parrot os isnt recognizing any of my drives. It only recognizes the usb flash drive i made to install parrot os. I can get to the desktop but when I try to install it says "there are no partitions to install on" any ideas on how i can fix this?    submitted by    /...]]></description>
<link>https://tsecurity.de/de/3472929/linux-tipps/parrot-os-wont-install-or-recognize-anything-but-my-flash-drive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3472929/linux-tipps/parrot-os-wont-install-or-recognize-anything-but-my-flash-drive/</guid>
<pubDate>Wed, 29 Apr 2026 03:08:04 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello, im having an issue where parrot os isnt recognizing any of my drives. It only recognizes the usb flash drive i made to install parrot os. I can get to the desktop but when I try to install it says "there are no partitions to install on" any ideas on how i can fix this?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/xtianmic"> /u/xtianmic </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1syjrg2/parrot_os_wont_install_or_recognize_anything_but/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1syjrg2/parrot_os_wont_install_or_recognize_anything_but/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stopping AiTM attacks: The defenses that actually work after authentication succeeds]]></title>
<description><![CDATA[The security industry has spent years building better authentication. Longer passwords, second factors, hardware tokens. And attackers responded by moving past authentication entirely.



Adversary-in-the-middle (AiTM) phishing does not steal credentials and replay them. It sits between the user ...]]></description>
<link>https://tsecurity.de/de/3470528/it-security-nachrichten/stopping-aitm-attacks-the-defenses-that-actually-work-after-authentication-succeeds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470528/it-security-nachrichten/stopping-aitm-attacks-the-defenses-that-actually-work-after-authentication-succeeds/</guid>
<pubDate>Tue, 28 Apr 2026 11:07:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The security industry has spent years building better authentication. Longer passwords, second factors, hardware tokens. And attackers responded by moving past authentication entirely.</p>



<p>Adversary-in-the-middle (AiTM) phishing does not steal credentials and replay them. It sits between the user and the legitimate service, watches a real authentication succeed in real time, and walks away with the session token that proves it happened. The login was genuine. The MFA prompt was real. The attacker just observed — and copied the result.</p>



<p>If you have read<a href="https://www.csoonline.com/article/4147134/your-mfa-isnt-broken-its-being-bypassed-and-your-employees-cant-tell-the-difference.html"> the analysis of how these attacks work</a>, you understand the mechanism. This piece is about what comes after that understanding. Specifically: What controls reduce risk when the attack does not touch credentials at all?</p>



<h2 class="wp-block-heading"><a></a>Why most current defenses miss the point</h2>



<p>The instinct after learning about AiTM phishing is to strengthen authentication. Buy hardware keys. Deploy passkeys. Force phishing-resistant MFA for privileged accounts.</p>



<p>That instinct is correct but incomplete.</p>



<p>Phishing-resistant authentication stops the credential theft phase. FIDO2 and passkeys bind the authentication challenge cryptographically to the legitimate domain, so a proxy domain cannot complete the handshake. This works. Organizations that have deployed passkeys broadly have significantly reduced their AiTM exposure at the authentication layer.</p>



<p>But authentication is not the only layer that matters. Session tokens issued after successful authentication are the real target, and most organizations treat them as inherently trustworthy once issued. They are not.</p>



<p>A session cookie is a bearer token. Whoever holds it is authenticated. There is no cryptographic binding between the token and the device that generated it, no ongoing proof that the holder is who they claim to be, and no automatic expiry triggered by location change or device mismatch. An attacker who steals a session token in one country can replay it from another, and the identity provider will accept it as legitimate.</p>



<p>This is where most defenses currently have a gap.</p>



<h2 class="wp-block-heading"><a></a>The 3 controls that close the gap</h2>



<h3 class="wp-block-heading"><a></a>Control #1: Bind sessions to managed devices</h3>



<p>The most impactful single control for session security is requiring managed, compliant devices as a condition of accessing sensitive resources. When access policies —<a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview"> </a><a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview">such as Microsoft Entra Conditional Access</a> — require that the device presenting a session token is enrolled, managed and meets compliance requirements, stolen tokens become significantly harder to replay.</p>



<p>An attacker who intercepts a session token cannot easily replay it from an unmanaged machine if the policy requires device compliance. The session gets terminated. The attacker needs not just the token but also a compliant device — a much higher bar.</p>



<p>This control is not foolproof. Sophisticated attackers can attempt to compromise managed devices directly. But it eliminates the easiest replay vector: Taking a stolen token and opening it in a browser on a completely different machine.</p>



<p>The practical challenge is rollout. Requiring managed devices for all users immediately creates friction for contractors, part-time workers and anyone using personal devices for work. The pragmatic approach is to start with the highest-risk access: Administrative roles, finance systems and any application handling sensitive data. Expand from there as device management coverage improves.</p>



<h3 class="wp-block-heading"><a></a>Control #2: Monitor for post-authentication anomalies</h3>



<p>AiTM attacks do not generate failed login attempts. They generate successful ones. Traditional monitoring focused on authentication failures will miss these attacks entirely.</p>



<p>The signals that matter are in what happens after authentication succeeds. Specifically:</p>



<ul class="wp-block-list">
<li><strong>Impossible travel.</strong> If a session authenticates from one location and then accesses resources from a geographically distant location minutes later, that warrants investigation. The time between events matters — a session that authenticates in New York and then accesses resources from a different continent thirty minutes later is not a normal user scenario.</li>



<li><strong>New device registration.</strong> Attackers who gain session access often immediately register a new MFA device or add a new authentication method to ensure persistent access. A new device registration occurring within minutes of a successful login is a high-fidelity signal worth alerting on.</li>



<li><strong>Inbox rule creation.</strong> A consistent post-compromise behavior across many attack campaigns is the creation of email forwarding rules or inbox filters designed to hide security alerts and forward communications to attacker-controlled addresses.<a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/"> </a><a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/">Microsoft’s own incident response teams have documented this pattern</a> repeatedly. Monitoring for inbox rule creation, particularly rules that forward externally or hide emails containing specific keywords, catches this behavior reliably.</li>



<li><strong>Privilege escalation attempts.</strong> Attackers who gain access to a standard user account typically attempt to escalate to higher-privilege roles or access administrative interfaces. Anomalous access attempts against admin portals or privilege management systems shortly after a new session authentication are worth flagging.</li>
</ul>



<p>None of these signals is conclusive on its own. But building detection rules around the combination — successful authentication followed by impossible travel followed by new device registration, for example — creates a detection capability that catches AiTM post-compromise activity that authentication monitoring misses entirely.</p>



<h3 class="wp-block-heading"><a></a>Control #3: Shorten session lifetimes for high-value access</h3>



<p>Long-lived session tokens give attackers more time to operate after a successful interception. A token that remains valid for seven days provides a much larger window than one that expires after an hour and requires reauthentication.</p>



<p>The friction of more frequent reauthentication is real. Users notice. For productivity applications used continuously throughout the day, aggressive session timeouts create a poor experience.</p>



<p>The answer is risk-based session management rather than uniform policies. Sessions accessing low-sensitivity productivity tools can have longer lifetimes. Sessions accessing financial systems, administrative interfaces, HR data or anything handling regulated information should have short lifetimes and require reauthentication before performing sensitive operations.<a href="https://pages.nist.gov/800-63-3/sp800-63b.html"> </a><a href="https://pages.nist.gov/800-63-3/sp800-63b.html">NIST’s Digital Identity Guidelines</a> provide a useful framework for thinking about session timeout thresholds by assurance level.</p>



<p>This approach concentrates the friction where the risk is highest, which makes it more defensible to users and leadership alike.</p>



<h2 class="wp-block-heading"><a></a>The training problem has not gone away</h2>



<p>Technical controls reduce risk. They do not eliminate it. Users remain part of the attack surface, and the awareness training most organizations provide does not prepare them for what AiTM phishing looks like.</p>



<p>Traditional phishing training teaches people to look for indicators of fake pages: Misspellings, suspicious URLs, unusual sender addresses. AiTM phishing pages show none of these indicators because they are not fake. They proxy the real service in real time. The URL may be suspicious, but users who click links in emails rarely check URLs carefully, even after training.</p>



<p>The one behavioral change that reduces AiTM exposure is simple and teachable: Do not start authentication flows from links in emails. Navigate directly to the service. Bookmark login pages. If you receive an email telling you to log in somewhere, open a browser tab and type the address yourself rather than clicking through.</p>



<p>This sounds obvious. It is not instinctive. Most users have spent years clicking login links in emails because it is faster and those links usually are legitimate. Changing that behavior requires explicit, repeated training that explains why the old approach is no longer safe — not just instruction to be more suspicious of phishing generally.</p>



<p>Pair this with a low-friction reporting mechanism. Users who notice something feels wrong should be able to flag it in seconds. The value of early reporting in limiting the damage from a successful session compromise is significant, and that value disappears if reporting requires effort or feels like it will generate blame rather than action.</p>



<h2 class="wp-block-heading"><a></a>The honest assessment</h2>



<p>AiTM phishing is a real and growing threat.<a href="https://www.microsoft.com/en-us/security/blog/2025/03/03/phishing-platform-tycoon-2fa-continues-to-be-a-significant-aitm-threat/"> </a><a href="https://www.microsoft.com/en-us/security/blog/2025/03/03/phishing-platform-tycoon-2fa-continues-to-be-a-significant-aitm-threat/">Phishing-as-a-Service platforms like Tycoon 2FA and FlowerStorm</a> have lowered the barrier to entry to the point where this is no longer an advanced technique requiring sophisticated threat actors. It is a commodity attack available to anyone willing to pay a subscription.</p>



<p>The organizations that reduce their exposure are those that treat session security as seriously as credential security, build detection capability around post-authentication behavior rather than just failed logins, and give users a realistic model of how modern phishing works.</p>



<p>Phishing-resistant authentication is the right long-term direction. Getting there takes time, budget and change management. In the meantime, the controls above provide meaningful risk reduction without waiting for full passkey deployment.</p>



<p>The goal is not to make AiTM attacks impossible. It is to make them expensive enough that attackers move on to easier targets.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[12 Signs Your SaaS Product Isn’t Enterprise-Ready (and How to Fix Each)]]></title>
<description><![CDATA[Not sure if your SaaS is enterprise-ready? Score yourself on 12 signs procurement teams check — SSO, SCIM, SOC 2, audit logs, and more. Includes a team scorecard. The post 12 Signs Your SaaS Product Isn’t Enterprise-Ready (and How to…
Read more →
The post 12 Signs Your SaaS Product Isn’t Enterpri...]]></description>
<link>https://tsecurity.de/de/3470009/it-security-nachrichten/12-signs-your-saas-product-isnt-enterprise-ready-and-how-to-fix-each/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470009/it-security-nachrichten/12-signs-your-saas-product-isnt-enterprise-ready-and-how-to-fix-each/</guid>
<pubDate>Tue, 28 Apr 2026 07:20:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Not sure if your SaaS is enterprise-ready? Score yourself on 12 signs procurement teams check — SSO, SCIM, SOC 2, audit logs, and more. Includes a team scorecard. The post 12 Signs Your SaaS Product Isn’t Enterprise-Ready (and How to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/12-signs-your-saas-product-isnt-enterprise-ready-and-how-to-fix-each/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/12-signs-your-saas-product-isnt-enterprise-ready-and-how-to-fix-each/">12 Signs Your SaaS Product Isn’t Enterprise-Ready (and How to Fix Each)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why PoP Count Isn’t the Real Measure of Application Security Performance]]></title>
<description><![CDATA[When evaluating cloud security platforms, one question comes up again and again: “How many Points of Presence do you have?” At first glance, the logic seems sound. More locations should mean lower latency, faster response times, and better protection. The assumption is simple: if security is deli...]]></description>
<link>https://tsecurity.de/de/3466950/it-security-nachrichten/why-pop-count-isnt-the-real-measure-of-application-security-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3466950/it-security-nachrichten/why-pop-count-isnt-the-real-measure-of-application-security-performance/</guid>
<pubDate>Mon, 27 Apr 2026 07:34:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When evaluating cloud security platforms, one question comes up again and again: “How many Points of Presence do you have?” At first glance, the logic seems sound. More locations should mean lower latency, faster response times, and better protection. The assumption is simple: if security is delivered at the edge, then more edge locations must […]</p>
<p>The post <a href="https://www.imperva.com/blog/why-pop-count-isnt-the-real-measure-of-application-security-performance/">Why PoP Count Isn’t the Real Measure of Application Security Performance</a> appeared first on <a href="https://www.imperva.com/blog">Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Just got our audit back and a whooping 100% of apps had misconfigs]]></title>
<description><![CDATA[Audit landed on my desk last week. Every single application we tested had at least one security misconfiguration, yes every last one of them Then I read the OWASP 2025 and apparently were not special. 100% of apps tested across the whole dataset had the same problem. I mean 700k+ CWE occurrences ...]]></description>
<link>https://tsecurity.de/de/3466635/it-security-nachrichten/just-got-our-audit-back-and-a-whooping-100-of-apps-had-misconfigs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3466635/it-security-nachrichten/just-got-our-audit-back-and-a-whooping-100-of-apps-had-misconfigs/</guid>
<pubDate>Mon, 27 Apr 2026 03:51:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Audit landed on my desk last week. Every single application we tested had at least one security misconfiguration, yes every last one of them</p> <p>Then I read the OWASP 2025 and apparently were not special. 100% of apps tested across the whole dataset had the same problem. I mean 700k+ CWE occurrences in this category alone. </p> <p>Heres the part that's wrecking me though: detection isnt the problem. Our scanner found them, we have findings out the wazoo. What nobody can tell me is which of the 4,200 misconfigs flagged in our environment will get us breached and which ones are technically true but irrelevant bs.</p> <p>The auditor wanted a remediation plan, but a plan that treats all 4,200 the same is just a backlog with a deadline. What we need is reachability and blast radius, basically which misconfigs are on internet facing assets, which ones chain into sensitive data, which ones combine with an over permissioned role to become an attack path.</p> <p>How are folks handling this post-audit? Feels like the industry's stuck solving discovery while the problem moved years ago.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/MortgageWarm3770"> /u/MortgageWarm3770 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1swm261/just_got_our_audit_back_and_a_whooping_100_of/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1swm261/just_got_our_audit_back_and_a_whooping_100_of/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why PoP Count Isn’t the Real Measure of Application Security Performance]]></title>
<description><![CDATA[When evaluating cloud security platforms, one question comes up again and again: “How many Points of Presence do you have?” At first glance, the logic seems sound. More locations should mean lower latency, faster response times, and better protection. The…
Read more →
The post Why PoP Count Isn’t...]]></description>
<link>https://tsecurity.de/de/3466595/it-security-nachrichten/why-pop-count-isnt-the-real-measure-of-application-security-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3466595/it-security-nachrichten/why-pop-count-isnt-the-real-measure-of-application-security-performance/</guid>
<pubDate>Mon, 27 Apr 2026 02:50:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When evaluating cloud security platforms, one question comes up again and again: “How many Points of Presence do you have?” At first glance, the logic seems sound. More locations should mean lower latency, faster response times, and better protection. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-pop-count-isnt-the-real-measure-of-application-security-performance/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-pop-count-isnt-the-real-measure-of-application-security-performance/">Why PoP Count Isn’t the Real Measure of Application Security Performance</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia's Teen Social Media Ban Isn't Working. Half Their Teens Still Have Access, Survey Finds]]></title>
<description><![CDATA[After Australia banned social media for users younger than 16, teenagers "immediately worked to circumvent the restrictions," reports Fortune:

14-year-old in New South Wales, told
The Washington Post in December 2025, just
before the implementation of the ban, she planned to use her mother's
fac...]]></description>
<link>https://tsecurity.de/de/3464807/it-security-nachrichten/australias-teen-social-media-ban-isnt-working-half-their-teens-still-have-access-survey-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464807/it-security-nachrichten/australias-teen-social-media-ban-isnt-working-half-their-teens-still-have-access-survey-finds/</guid>
<pubDate>Sun, 26 Apr 2026 01:20:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After Australia banned social media for users younger than 16, teenagers "immediately worked to circumvent the restrictions," reports Fortune:

14-year-old in New South Wales, told
The Washington Post in December 2025, just
before the implementation of the ban, she planned to use her mother's
face ID to log in to Snapchat
and .
In a Reddit thread on ways to bypass the ban, one user suggested
using a printed mesh face mask from Temu to outsmart apps'
facial recognition tools. Others still have tried VPNs that obscure
their locations. 

A new report
suggests these efforts are working. In a survey of 1,050 Australians ages 12 to 15 conducted last month, the
UK-based suicide prevention organization the Molly Rose Foundation
found more than 60% of teens who had social media accounts before the
ban still had access to at least one of those platforms. Social media
sites including TikTok, YouTube, and Instagram, have retained more than half of their users under 16.
About two-thirds of young users say these platforms have taken "no
action" to remove or reactive accounts that existed before the
restrictions.


 The survey comes at the heels of the Australian internet regulator
calling
for an investigation into the five largest social media platforms
over potential breaches of the ban.

 

The article points out that "Greece, France, Indonesia, Austria, Spain, and the UK have or are considering similar action, and eight U.S. states are weighing legislation that would put guardrails or ban social media use for minors.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Australia's+Teen+Social+Media+Ban+Isn't+Working.+Half+Their+Teens+Still+Have+Access%2C+Survey+Finds%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F25%2F236216%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F25%2F236216%2Faustralias-teen-social-media-ban-isnt-working-half-their-teens-still-have-access-survey-finds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/04/25/236216/australias-teen-social-media-ban-isnt-working-half-their-teens-still-have-access-survey-finds?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI workplace paradox: Higher productivity, higher anxiety]]></title>
<description><![CDATA[Workers are facing a conundrum: They worry about the potential for their displacement by AI even as it dramatically speeds up their own productivity.



According to a new survey from Anthropic, workers in roles most likely to be taken over by AI (developers or IT workers, for instance) recognize...]]></description>
<link>https://tsecurity.de/de/3459899/it-nachrichten/the-ai-workplace-paradox-higher-productivity-higher-anxiety/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459899/it-nachrichten/the-ai-workplace-paradox-higher-productivity-higher-anxiety/</guid>
<pubDate>Fri, 24 Apr 2026 04:46:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Workers are facing a conundrum: They worry about the potential for their displacement by AI even as it dramatically speeds up their own productivity.</p>



<p>According to a <a href="https://www.anthropic.com/research/81k-economics" target="_blank" rel="noreferrer noopener">new survey</a> from Anthropic, workers in roles most likely to be taken over by AI (developers or IT workers, for instance) recognize their precarious position. Yet, perhaps naturally, they readily adopt the tools that could take their jobs, and see first-hand how well they work.</p>



<p>This measurement is fundamentally different from the way others are gauging AI job displacement, noted <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="noreferrer noopener">Thomas Randall</a>, research director at Info-Tech Research Group.</p>



<p>While macro reports, such as those from Goldman Sachs, the International Monetary Fund (IMF), or the World Economic Forum (WEF), are asking what share of existing job tasks AI could theoretically perform in the future, “Anthropic is measuring qualitative experiences of workers in the present,” he pointed out. This “tells us how people are navigating this landscape in real time.”</p>



<h2 class="wp-block-heading">The paradox of AI in the workforce</h2>



<p>Anthropic’s survey of 81,000 Claude users gauged peoples’ “visions and fears” around advances in AI, and weighed these findings against the company’s <a href="https://www.cio.com/article/4142784/job-disruption-by-ai-remains-limited-and-traditional-metrics-may-be-missing-the-real-impact-2.html" target="_blank">own measurement</a> of jobs most vulnerable to AI displacement. This was based on Claude usage data; jobs are identified as more exposed when associated tasks are significantly performed on the platform, in work-related contexts, and take up a larger share of a role.</p>



<p>Some occupations at risk include computer programmers, data entry keyers, market researchers, software quality assurance analysts and testers, information security analysts, and computer user support specialists.</p>



<p>Overall, one-fifth of respondents expressed concern about displacement, noting that their job, or at least aspects of it, is <a href="https://www.cio.com/article/4162085/your-ai-coding-agent-isnt-a-tool-its-a-junior-developer-treat-it-like-one.html" target="_blank">being taken over by automation</a>. Those in jobs identified as most exposed readily recognized that fact, voicing worry three times as often as those in less at-risk positions. One <a href="https://www.cio.com/article/4162080/why-hiring-ai-engineers-wont-work.html" target="_blank">software engineer</a> remarked: “like anyone who has a white collar job these days, I’m 100% concerned, pretty much 24/7 concerned, about losing my job eventually to AI.” </p>



<p>Early-career respondents were also more nervous than others.</p>



<p>At the same time, those in the highest-paid occupations reported the largest productivity gains when using AI. This is most notably in terms of their ability to perform new tasks, which was cited by 48% of users. In addition, 40% of workers said the technology helped speed up their work, and a little more than 10% said it improved the quality of their work.</p>



<p>In general, enterprise usage of AI is “actually quite consistent,” said <a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. Teams are using the technology “where information is abundant and time is limited,” such as in drafting documents and code, summarizing content, responding to customer queries, navigating internal systems.</p>



<h2 class="wp-block-heading">Is AI actually creating more work?</h2>



<p>Still, not everyone thinks AI makes their jobs easier or faster. In some cases, people felt it made their work harder; for instance, project managers are assigning tickets for issues that are much more difficult to solve, Anthropic noted.</p>



<p>Gogia agreed that, even when tasks become easier, scope and responsibilities expand, and roles can absorb adjacent tasks. This results in a “redistribution of effort,” rather than a reduction of effort.</p>



<p>“Faster generation means higher expectations on quality,” he said. More output feeds into decision pipelines that are already constrained. “In some cases, the system becomes heavier, not lighter.”</p>



<h2 class="wp-block-heading">Delayed impact on enterprises</h2>



<p> The market is rewarding those who can integrate AI into complex workflows to do more, faster, and often with better outcomes, Gogia noted. However, the most exposed tasks, including  documentation, basic coding, routine analysis, and structured support work, often “sit at the base of the experience ladder.”</p>



<p>These very tasks traditionally have given entry-level workers a way in, and the automation of them reduces the urgency for companies to hire them. “What you begin to lose is not the job,” said Gogia. “It is the path into the job.”</p>



<p>This can have a delayed impact; enterprises may not realize until years later that they do not have enough mid-level experts because they didn’t bring enough people in at lower levels. As AI plays a greater role in the workplace, there must be a “conscious effort” to rethink how people enter and grow, Gogia said. “New pathways need to be created, and they need to be deliberate.”</p>



<h2 class="wp-block-heading">How enterprise leaders should adjust </h2>



<p>As is often the case, sentiment moves faster than structural change, Gogia pointed out. Workers feel the shift almost immediately, but organizations take longer to adjust hiring, redesign roles, and rethink workforce structures.</p>



<p>“This is why expectations can become misaligned,” he noted. The reality is that most enterprises have introduced AI into existing ways of working without fundamentally changing them. Acceleration occurs in unchanged systems that still carry the same dependencies, approval chains, and coordination challenges.</p>



<p>Ultimately, Gogia advised, leaders must approach the shift with “intentional design.” This requires clarity, he emphasized; people need to understand how their work is expected to change. What will be enhanced? What will reduce? Where should they focus their development?</p>



<p>Baselines are moving: Roles may begin to look “oversized” as what used to be considered a full day’s work begins to look like half a day’s work, or what used to be considered efficient begins to look average. “AI is changing how work is done, but more importantly, it is changing what work expects from people,” said Gogia.</p>



<p>As well, Info-Tech’s Randall pointed out that workers who experience AI expanding what they can do by performing tasks previously outside their competence appear to relate to AI more positively than those who experience it as doing their existing job faster. So, he advised, “tech leaders should design AI deployment around capability extensions.”</p>



<p>Along with goal setting, managers must have support, Gogia emphasized. They set expectations and interpret strategy, and when they’re not properly equipped, “even the best tools will fall short,” he said. Measurement must also evolve; enterprises need to look at quality, sustainability, and capability development over time.</p>



<p>“What we are witnessing right now is not a sudden disruption,” said Gogia. “It is a gradual shift that is becoming impossible to ignore.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI workplace paradox: Higher productivity, higher anxiety]]></title>
<description><![CDATA[Workers are facing a conundrum: They worry about the potential for their displacement by AI even as it dramatically speeds up their own productivity.



According to a new survey from Anthropic, workers in roles most likely to be taken over by AI (developers or IT workers, for instance) recognize...]]></description>
<link>https://tsecurity.de/de/3459898/it-nachrichten/the-ai-workplace-paradox-higher-productivity-higher-anxiety/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459898/it-nachrichten/the-ai-workplace-paradox-higher-productivity-higher-anxiety/</guid>
<pubDate>Fri, 24 Apr 2026 04:46:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Workers are facing a conundrum: They worry about the potential for their displacement by AI even as it dramatically speeds up their own productivity.</p>



<p>According to a <a href="https://www.anthropic.com/research/81k-economics" target="_blank" rel="nofollow">new survey</a> from Anthropic, workers in roles most likely to be taken over by AI (developers or IT workers, for instance) recognize their precarious position. Yet, perhaps naturally, they readily adopt the tools that could take their jobs, and see first-hand how well they work.</p>



<p>This measurement is fundamentally different from the way others are gauging AI job displacement, noted <a href="https://www.infotech.com/profiles/thomas-randall" target="_blank" rel="nofollow">Thomas Randall</a>, research director at Info-Tech Research Group.</p>



<p>While macro reports, such as those from Goldman Sachs, the International Monetary Fund (IMF), or the World Economic Forum (WEF), are asking what share of existing job tasks AI could theoretically perform in the future, “Anthropic is measuring qualitative experiences of workers in the present,” he pointed out. This “tells us how people are navigating this landscape in real time.”</p>



<h2 class="wp-block-heading">The paradox of AI in the workforce</h2>



<p>Anthropic’s survey of 81,000 Claude users gauged peoples’ “visions and fears” around advances in AI, and weighed these findings against the company’s <a href="https://www.cio.com/article/4142784/job-disruption-by-ai-remains-limited-and-traditional-metrics-may-be-missing-the-real-impact-2.html" target="_blank">own measurement</a> of jobs most vulnerable to AI displacement. This was based on Claude usage data; jobs are identified as more exposed when associated tasks are significantly performed on the platform, in work-related contexts, and take up a larger share of a role.</p>



<p>Some occupations at risk include computer programmers, data entry keyers, market researchers, software quality assurance analysts and testers, information security analysts, and computer user support specialists.</p>



<p>Overall, one-fifth of respondents expressed concern about displacement, noting that their job, or at least aspects of it, is <a href="https://www.cio.com/article/4162085/your-ai-coding-agent-isnt-a-tool-its-a-junior-developer-treat-it-like-one.html" target="_blank">being taken over by automation</a>. Those in jobs identified as most exposed readily recognized that fact, voicing worry three times as often as those in less at-risk positions. One <a href="https://www.cio.com/article/4162080/why-hiring-ai-engineers-wont-work.html" target="_blank">software engineer</a> remarked: “like anyone who has a white collar job these days, I’m 100% concerned, pretty much 24/7 concerned, about losing my job eventually to AI.” </p>



<p>Early-career respondents were also more nervous than others.</p>



<p>At the same time, those in the highest-paid occupations reported the largest productivity gains when using AI. This is most notably in terms of their ability to perform new tasks, which was cited by 48% of users. In addition, 40% of workers said the technology helped speed up their work, and a little more than 10% said it improved the quality of their work.</p>



<p>In general, enterprise usage of AI is “actually quite consistent,” said <a href="https://greyhoundresearch.com/svg/" rel="nofollow">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. Teams are using the technology “where information is abundant and time is limited,” such as in drafting documents and code, summarizing content, responding to customer queries, navigating internal systems.</p>



<h2 class="wp-block-heading">Is AI actually creating more work?</h2>



<p>Still, not everyone thinks AI makes their jobs easier or faster. In some cases, people felt it made their work harder; for instance, project managers are assigning tickets for issues that are much more difficult to solve, Anthropic noted.</p>



<p>Gogia agreed that, even when tasks become easier, scope and responsibilities expand, and roles can absorb adjacent tasks. This results in a “redistribution of effort,” rather than a reduction of effort.</p>



<p>“Faster generation means higher expectations on quality,” he said. More output feeds into decision pipelines that are already constrained. “In some cases, the system becomes heavier, not lighter.”</p>



<h2 class="wp-block-heading">Delayed impact on enterprises</h2>



<p> The market is rewarding those who can integrate AI into complex workflows to do more, faster, and often with better outcomes, Gogia noted. However, the most exposed tasks, including  documentation, basic coding, routine analysis, and structured support work, often “sit at the base of the experience ladder.”</p>



<p>These very tasks traditionally have given entry-level workers a way in, and the automation of them reduces the urgency for companies to hire them. “What you begin to lose is not the job,” said Gogia. “It is the path into the job.”</p>



<p>This can have a delayed impact; enterprises may not realize until years later that they do not have enough mid-level experts because they didn’t bring enough people in at lower levels. As AI plays a greater role in the workplace, there must be a “conscious effort” to rethink how people enter and grow, Gogia said. “New pathways need to be created, and they need to be deliberate.”</p>



<h2 class="wp-block-heading">How enterprise leaders should adjust </h2>



<p>As is often the case, sentiment moves faster than structural change, Gogia pointed out. Workers feel the shift almost immediately, but organizations take longer to adjust hiring, redesign roles, and rethink workforce structures.</p>



<p>“This is why expectations can become misaligned,” he noted. The reality is that most enterprises have introduced AI into existing ways of working without fundamentally changing them. Acceleration occurs in unchanged systems that still carry the same dependencies, approval chains, and coordination challenges.</p>



<p>Ultimately, Gogia advised, leaders must approach the shift with “intentional design.” This requires clarity, he emphasized; people need to understand how their work is expected to change. What will be enhanced? What will reduce? Where should they focus their development?</p>



<p>Baselines are moving: Roles may begin to look “oversized” as what used to be considered a full day’s work begins to look like half a day’s work, or what used to be considered efficient begins to look average. “AI is changing how work is done, but more importantly, it is changing what work expects from people,” said Gogia.</p>



<p>As well, Info-Tech’s Randall pointed out that workers who experience AI expanding what they can do by performing tasks previously outside their competence appear to relate to AI more positively than those who experience it as doing their existing job faster. So, he advised, “tech leaders should design AI deployment around capability extensions.”</p>



<p>Along with goal setting, managers must have support, Gogia emphasized. They set expectations and interpret strategy, and when they’re not properly equipped, “even the best tools will fall short,” he said. Measurement must also evolve; enterprises need to look at quality, sustainability, and capability development over time.</p>



<p>“What we are witnessing right now is not a sudden disruption,” said Gogia. “It is a gradual shift that is becoming impossible to ignore.”</p>



<p><em>This article originally appeared on <a href="https://www.computerworld.com/article/4162929/the-ai-workplace-paradox-higher-productivity-higher-anxiety.html" target="_blank">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco switch aimed at building practical quantum networks]]></title>
<description><![CDATA[Cisco today unveiled a prototype switch it says will significantly accelerate the timeline for practical, distributed, quantum-computing-based networks.



Cisco’s Universal Quantum Switch is designed to connect quantum systems from different vendors, such as IBM, IonQ, Google and Rigetti, in all...]]></description>
<link>https://tsecurity.de/de/3458288/it-security-nachrichten/cisco-switch-aimed-at-building-practical-quantum-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458288/it-security-nachrichten/cisco-switch-aimed-at-building-practical-quantum-networks/</guid>
<pubDate>Thu, 23 Apr 2026 15:53:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cisco today unveiled a prototype switch it says will significantly accelerate the <a href="https://www.networkworld.com/article/4088709/top-quantum-breakthroughs-of-2025.html">timeline</a> for practical, distributed, quantum-computing-based networks.</p>



<p>Cisco’s Universal Quantum Switch is designed to connect <a href="https://www.networkworld.com/article/4158139/fixing-encryption-isnt-enough-quantum-developments-put-focus-on-authentication.html">quantum systems</a> from different vendors, such as IBM, IonQ, Google and Rigetti, in all major qubit encoding technologies, at room temperature, and over standard telecom fiber, according to <a href="https://www.linkedin.com/in/vijoy/">Vijoy Pandey</a>, senior vice president and general manager of <a href="https://outshift.cisco.com/about-us">Outshift</a>, Cisco’s emerging technologies and incubation group.</p>



<p>“Today we have quantum computers operating at roughly 100 to 1,000 qubits in size, and from the public roadmaps of leading quantum players, we believe this number [is] going up to 10,000 in the next three years,” Pandey said. “Actual quantum computers will get bigger over time, of course, but it creates a big scalability problem once you start connecting them. What the switch will do is effectively link smaller quantum computers and create a large, distributed quantum computer, allowing faster scaling than building one massive quantum computer alone.”</p>



<p>“This is a foundational piece of technology that lets us move from direct point-to-point connections, the tin cans and a wire, to building out a quantum network, to building out the quantum Internet at scale, to be able to connect those quantum computers at scale within the data center, but also to be able to connect quantum sensors across the Internet at scale as well,” Pandey said.</p>



<p>The Cisco Universal Quantum Switch works in many of the ways that current multivendor switches work to form the backbone of the internet in that it allows connectivity no matter what the underlaying protocols and equipment are, Pandey said. When two quantum computers need to share information, the Universal Quantum Switch accepts the signal in whatever modality it arrives, translates it into a common language for routing, and delivers it in the format the receiving system needs, without losing any quantum information along the way, Pandey said. </p>



<p>The switch preserved quantum information with less than 4% degradation in encoding and <a href="https://www.networkworld.com/article/4145726/quantum-elements-cuts-quantum-error-rates-using-ai-powered-digital-twin.html">entanglement fidelity</a> in proof-of-concept experiments, Pandey said.</p>



<p>This is made possible by a Cisco-patented conversion engine, where output modality can match the input or be an entirely different one, letting the quantum switch connect and translate between quantum systems that were never designed to talk to each other. It’s a critical capability for building quantum networks that work across different vendors and technologies, according to Cisco.</p>



<p>“The switch is non-blocking, allowing multiple photons to flow through the chip at the same time, each independently routed while preserving its quantum state, enabling flexible scalable quantum networking,” Pandey said.</p>



<p>The major quantum encoding modalities which are used to carry quantum information include:</p>



<ul class="wp-block-list">
<li>Polarization (the orientation of light waves)</li>



<li>Time-bin (the timing of light pulses)</li>



<li>Frequency-bin (the color or frequency of light)</li>



<li>Path (the physical or spatial path)</li>
</ul>



<p>To date, the quantum switch has been experimentally validated with polarization encoding. Support for time-bin and frequency-bin is built into the switch design and will be the next step in Cisco’s ongoing validation process, Pandey said.</p>



<p>The switch can also be used to tie together and process data from quantum-sensing devices which are or will be used in applications from healthcare and navigation to energy and infrastructure.</p>



<p>The Cisco Universal Quantum Switch is just the latest component in the vendor’s quantum arsenal which is aimed at offering a full stack of <a href="https://www.networkworld.com/article/3596243/cisco-takes-aim-at-developing-quantum-data-center.html">data center-oriented quantum technologie</a>s. </p>



<p>In September the vendor rolled out <a href="https://www.networkworld.com/article/4062570/cisco-expands-its-quantum-networking-portfolio-with-new-software-prototypes.html">a package of prototype software</a> it says will facilitate distributed quantum computing networks and support real-time applications. The software stack includes three layers: an application layer with a network-aware distributed quantum computing compiler that supports quantum algorithm execution in a networked quantum data center; a control layer with quantum networking protocols and algorithms that support the applications as well as manage the devices (hardware and software) that make up a quantum network through northbound and southbound APIs; and a third layer for device support, consisting of an SDK and APIs to physical devices as well as a library of emulated and simulated ones.</p>



<p>The Universal Switch is based on the <a href="https://www.networkworld.com/article/3978702/cisco-unveils-prototype-quantum-networking-chip.html">quantum entanglement chip</a> announced by Outshift last May that generates pairs of entangled photons that can instantly transmit quantum state between each other, regardless of the distance between them. The entanglement chip generates 200 million entangled pairs per second. The chip operates at room temperature, uses minimal power, and functions using existing telecom frequencies. It’s designed to work with existing infrastructure, meaning it can send photons over existing fiber. And it operates at standard telecom frequencies, so there’s no need to rip and replace anything to support it, according to Cisco. In addition, because of these properties, customers could deploy gear supporting the chip alongside an existing classical computer infrastructure, Cisco said.</p>



<p>“The quantum future won’t be built by any one company or any one technology. It will be built by connecting them all with this technology,” Pandey said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta will show parents the topics of their teens' AI conversations]]></title>
<description><![CDATA[With countries banning social media for kids left and right, Meta is trying different things to convince parents that its platforms are safe for teens. In its latest effort, the company will start showing parents the topics their teens have discussed with Meta AI over the previous seven days. 
"P...]]></description>
<link>https://tsecurity.de/de/3458113/it-nachrichten/meta-will-show-parents-the-topics-of-their-teens-ai-conversations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458113/it-nachrichten/meta-will-show-parents-the-topics-of-their-teens-ai-conversations/</guid>
<pubDate>Thu, 23 Apr 2026 14:48:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>With countries banning social media for kids <a data-i13n="cpos:1;pos:1" href="https://www.engadget.com/social-media/spain-set-to-ban-social-media-for-children-under-16-151546884.html">left</a> and <a data-i13n="cpos:2;pos:1" href="https://apnews.com/article/turkey-social-media-children-restrictions-law-d88963a7446a12cf4963b73d455b5ef7">right</a>, Meta is trying <a data-i13n="cpos:3;pos:1" href="https://www.engadget.com/social-media/meta-rolls-out-teen-accounts-for-facebook-and-messenger-across-the-world-120000352.html">different things</a> to convince parents that its platforms are safe for teens. In its <a data-i13n="cpos:4;pos:1" href="https://about.fb.com/news/2026/04/helping-parents-understand-conversations-their-teens-are-having-with-ai/">latest effort</a>, the company will start showing parents the topics their teens have discussed with Meta AI over the previous seven days. </p>
<p>"Parents will be able to see the topics their teen has been asking Meta AI about in [Facebook, Messenger or Instagram] over the past week," Meta explained in a blog post. "Topics can range from School, Entertainment, and Lifestyle to Travel, Writing, and Health and Wellbeing, among others."</p>
<span></span><p>For parents overseeing Meta's teen accounts, the feature will appear in a new Insights tab within supervision, both in-app and on web. Parents can tap on a topic to see the different categories within each: for instance, sub-categories within Lifestyle include fashion, food and holidays, while fitness, physical health and mental health are part of the Health and Wellbeing topic. </p>
<figure><img src="https://s.yimg.com/os/creatr-uploaded-images/2026-04/43ad82a0-3f0f-11f1-9e6b-6fddec6edfd2" data-crop-orig-src="https://s.yimg.com/os/creatr-uploaded-images/2026-04/43ad82a0-3f0f-11f1-9e6b-6fddec6edfd2" alt="Meta will allow parents to look at the conversation topics kids use when talking to an AI" data-uuid="5a8f8164-5076-3f63-aac8-f6c7ef144c36"><figcaption></figcaption><div class="photo-credit">Meta</div></figure>
<p>Meta also worked with the Cyberbullying Research Center to develop what it calls "conversation starters," or open-ended conversations about their experience with AI. It provides detail about what the questions are designed to address, and can be found on the <a data-i13n="cpos:5;pos:1" href="https://familycenter.meta.com/resources/talk-to-your-teen-about-ai/">Family Center</a> website or through a link in the new Insights tab. </p>
<p>Finally, Meta revealed more detail about its AI Wellbeing Expert Council, who will provide "ongoing input on our AI experience for teens." It will be made up of three existing advisory groups as well as new members with special expertise in responsible and ethical AI, who are affiliated with the National Council of Suicide Prevention and multiple universities. It's worth noting that Meta has a separate <a data-i13n="cpos:6;pos:1" href="https://www.engadget.com/social-media/meta-isnt-setting-its-oversight-board-free-just-yet-153000172.html">oversight board</a> that deals with subjects ranging from AI to moderation. </p>
<p>Offboarding moderation chores to busy parents appears to be par for the course for Meta these days. The company has recently cut back on the use of third-party vendors that help with content moderation, shifting responsibility instead to advanced AI systems, according to <a data-i13n="cpos:7;pos:1" href="https://www.engadget.com/social-media/meta-will-move-away-from-human-content-moderators-in-favor-of-more-ai-183000435.html">recent reports</a>. </p>
<p>The dangers of AI for teens have been one of multiple reasons countries like Spain have banned social media platforms for kids. One of the most recent and tragic cases <a data-i13n="cpos:8;pos:1" href="https://www.engadget.com/ai/canadian-government-says-openai-will-take-further-steps-to-strengthen-safety-protocols-164151618.html">was in Canada</a>, where a teen was provided specific details by OpenAI's ChatGPT about how to carry out a school shooting. Another such case is <a data-i13n="cpos:9;pos:1" href="https://www.engadget.com/ai/florida-ag-opens-criminal-investigation-into-openai-and-chatgpt-190200227.html">under investigation in Florida,</a> and AI's have been implicated in multiple teen suicides as well. </p>
<p><em>In the US, the National Suicide Prevention Lifeline is 1-800-273-8255 or you can simply dial 988. Crisis Text Line can be reached by texting HOME to 741741 (US), 686868 (Canada), or 85258 (UK). Wikipedia maintains </em><a data-i13n="cpos:10;pos:1" href="https://en.wikipedia.org/wiki/List_of_suicide_crisis_lines"><em>a list of crisis lines</em></a><em> for people outside of those countries.</em></p>This article originally appeared on Engadget at https://www.engadget.com/ai/meta-will-show-parents-the-topics-of-their-teens-ai-conversations-123119624.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Sharing isn’t caring if it’s an admin password]]></title>
<description><![CDATA[Keeping it simple for the developers can lead to very complex headaches later PWNED  Welcome back to PWNED, the column where we celebrate the people who’ve taught us how not to secure a server. If you’ve ever tied your own…
Read more →
The post Sharing isn’t caring if it’s an admin password appea...]]></description>
<link>https://tsecurity.de/de/3457523/it-security-nachrichten/sharing-isnt-caring-if-its-an-admin-password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457523/it-security-nachrichten/sharing-isnt-caring-if-its-an-admin-password/</guid>
<pubDate>Thu, 23 Apr 2026 11:51:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Keeping it simple for the developers can lead to very complex headaches later PWNED  Welcome back to PWNED, the column where we celebrate the people who’ve taught us how not to secure a server. If you’ve ever tied your own…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/sharing-isnt-caring-if-its-an-admin-password/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/sharing-isnt-caring-if-its-an-admin-password/">Sharing isn’t caring if it’s an admin password</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When “Safe” Isn’t Safe: Turning a Simple HTML Injection into a Real Security Story.]]></title>
<description><![CDATA[In bug bounty hunting, not every vulnerability needs flashy payloads or JavaScript execution to matter. Sometimes, the simplest flaws — when placed in the right context — can quietly undermine user trust.In this write-up, I’ll walk through how I discovered a Reflected HTML Injection vulnerability...]]></description>
<link>https://tsecurity.de/de/3456982/hacking/when-safe-isnt-safe-turning-a-simple-html-injection-into-a-real-security-story/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456982/hacking/when-safe-isnt-safe-turning-a-simple-html-injection-into-a-real-security-story/</guid>
<pubDate>Thu, 23 Apr 2026 08:19:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XmWAibWQNruX40WThiBuNQ.png"></figure><p>In bug bounty hunting, not every vulnerability needs flashy payloads or JavaScript execution to matter. Sometimes, the simplest flaws — when placed in the right context — can quietly undermine user trust.</p><p>In this write-up, I’ll walk through how I discovered a <strong>Reflected HTML Injection vulnerability</strong> on an authentication endpoint, why it matters, and how it was responsibly disclosed and resolved.</p><p>Your regular self-taught Ethical Hacker kjulius 🪞🗿</p><p>This finding was discovered together with <strong>@Younghb0x1</strong>.</p><h3>🎯 Target Overview</h3><p>The target was an authentication-related endpoint:<br>For responsible disclosure, let’s call the website as “target”.</p><pre>https://target-auth.domain.com/data/public/farewell?client_id=</pre><p>At first glance, it looked like a standard logout/farewell page in an SSO flow. But as always, user-controlled parameters are worth testing — especially in auth flows.</p><h3>🔍 Initial Discovery</h3><p>While testing the application, I noticed that the client_id parameter was reflected in the response.</p><p>So I tried something simple:</p><pre>&lt;h1&gt;Hello World&lt;/h1&gt;<br>&lt;p&gt;Testing HTML Injection&lt;/p&gt;</pre><p>After URL encoding and sending the request, the response page rendered my HTML directly.</p><p>That’s when it became clear:</p><blockquote><em>The application was reflecting user input without proper output encoding.</em></blockquote><h3>⚠️ The Vulnerability</h3><h4>Reflected HTML Injection</h4><p>The endpoint was vulnerable because it:</p><ul><li>Took user input from client_id</li><li>Injected it directly into the HTML response.</li><li>Did <strong>not sanitize or encode</strong> the output.</li></ul><p>This allowed arbitrary HTML to be rendered in the browser.</p><h3>🧪 Proof of Concept.</h3><p>A crafted payload like this:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TP-wD-By0UBzEtr0683yOw.png"></figure><p>Was successfully rendered on the page when passed through the URL:</p><pre>https://target-auth.domain.com/data/public/farewell?client_id=...</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KWYnfIzVXRp32BgToggJ9g.png"></figure><h3>Result:</h3><ul><li>Headings displayed ✔</li><li>Paragraph rendered ✔</li><li>Clickable link injected ✔</li></ul><p>No JavaScript execution occurred — but that doesn’t mean it’s harmless.</p><h3>❌ Why This Is NOT XSS</h3><p>I tested multiple XSS payloads, including:</p><ul><li>"&gt;&lt;script&gt;alert(1)&lt;/script&gt;</li><li>&lt;img src=x onerror=alert(1)&gt;</li><li>&lt;svg onload=alert(1)&gt;</li></ul><p>All were <strong>blocked or sanitized</strong>.</p><p>So this was clearly:</p><blockquote><em>✅ HTML Injection<br> ❌ Not Cross-Site Scripting (XSS)</em></blockquote><h3>💥 Impact: Why This Still Matters</h3><p>Even without JavaScript, this vulnerability sits on a <strong>trusted authentication endpoint</strong> — and that changes everything.</p><h4>👤 Impact to Users.</h4><ul><li>Users may see attacker-controlled content on a trusted page.</li><li>Fake messages can be displayed (e.g., logout success, warnings).</li><li>Malicious links can be injected and clicked.</li><li>Increased risk of phishing and social engineering.</li></ul><h4>🏢 Impact to the Company.</h4><ul><li>Abuse of a trusted authentication domain.</li><li>Potential phishing campaigns leveraging legitimacy.</li><li>Brand reputation damage.</li><li>Indicator of weak input handling in sensitive areas.</li></ul><h3>🧠 Key Insight</h3><p>This bug is a perfect example of something many beginners overlook:</p><blockquote><strong><em>“No XSS” does NOT mean “No impact.”</em></strong></blockquote><p>Context matters.</p><p>If this were on a random static page, it might be ignored.<br>But on an <strong>SSO/logout endpoint</strong>, users inherently trust what they see.</p><p>That trust is exactly what attackers exploit.</p><h3>🛠️ Remediation</h3><p>The fix is straightforward but critical:</p><ul><li>Properly <strong>encode all user input before rendering.</strong></li><li>Apply strict <strong>allow-list validation</strong> for client_id</li><li>Avoid reflecting authentication parameters in HTML.</li><li>Implement a <strong>Content Security Policy (CSP).</strong></li></ul><h3>✅ Final Outcome</h3><p>The vulnerability was:</p><ul><li><strong>Reported responsibly.</strong></li><li><strong>Accepted by the program.</strong></li><li><strong>Resolved.</strong></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ObFVO1EAkEyoDnj3PWgRhQ.png"></figure><h3>🤝 Collaboration</h3><p>This finding was made together with <strong>@Younghb0x1</strong> — shoutout for the teamwork and sharp testing mindset.</p><h3>🧾 Final Thoughts</h3><p>This was a reminder that:</p><ul><li>Simplicity wins.</li><li>Context defines impact.</li><li>And clean, well-documented reports get accepted.</li></ul><p>Not every bug needs to be “critical” to be valuable.</p><p>Sometimes, all it takes is:</p><blockquote><em>A </em><em>&lt;h1&gt; tag in the right place.</em></blockquote><h3>🔗 Connect</h3><p>If you enjoyed this write-up, feel free to follow for more real-world bug bounty discoveries.<br><a href="https://x.com/ethical_h4ck3r_">https://x.com/ethical_h4ck3r_</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34332d4851df" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/when-safe-isnt-safe-turning-a-simple-html-injection-into-a-real-security-story-34332d4851df">When “Safe” Isn’t Safe: Turning a Simple HTML Injection into a Real Security Story.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[some dude i know just discovered linux and i swear i just witnessed the fastest ego transformation in human history]]></title>
<description><![CDATA[guy: "btw i use linux from now on"  me: "what are you even doing up this early"  guy: "about to go to sleep 😭" ok cool whatever then he hits me with  "vrchat works, resonite works, helldivers, warframe" i already knew what was coming so i told him  "please dont turn into those people who use linu...]]></description>
<link>https://tsecurity.de/de/3456624/linux-tipps/some-dude-i-know-just-discovered-linux-and-i-swear-i-just-witnessed-the-fastest-ego-transformation-in-human-history/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456624/linux-tipps/some-dude-i-know-just-discovered-linux-and-i-swear-i-just-witnessed-the-fastest-ego-transformation-in-human-history/</guid>
<pubDate>Thu, 23 Apr 2026 04:20:58 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>guy: "btw i use linux from now on" </p> <p>me: "what are you even doing up this early" </p> <p>guy: "about to go to sleep 😭"</p> <p>ok cool whatever</p> <p>then he hits me with </p> <p>"vrchat works, resonite works, helldivers, warframe"</p> <p>i already knew what was coming so i told him </p> <p>"please dont turn into those people who use linux like its a personality trait just because its linux"</p> <p>and this man goes </p> <p>"i wanna fully switch to linux, maybe dual boot windows for games and software i need, or just run a windows emulator on linux 😭"</p> <p>i should have left right there</p> <p>then i say i cant switch because i use adobe</p> <p>this man looks me dead in the soul through text and says </p> <p>"yuck. blender better"</p> <p>brother. </p> <p>IN WHAT UNIVERSE???///</p> <p>i ask him how im supposed to edit like a pro in blender and he didnt even answer me</p> <p>he sends me a screenshot of his desktop and just says </p> <p>"its yummy"</p> <p>ITS YUMMY</p> <p>then he starts explaining how his setup is better because vanced is "a real app and not a patch" and im just sitting there like ok man</p> <p>so i tell him i use linux too but only for specific projects on ubuntu server</p> <p>this man instantly goes </p> <p>"mid. fedora better"</p> <p>at this point im like ok youre one of those</p> <p>then he says he was "just joking" </p> <p>and literally 10 seconds later starts explaining why his distro is objectively better than everything else</p> <p>so i call him out </p> <p>"you were joking a second ago, now youre serious?"</p> <p>then i drop a whole explanation about how linux isnt magically better, its just a different setup with tradeoffs, most data doesnt even come from the os etc</p> <p>and you know what this man says</p> <p>"yeah i switched because windows pissed me off"</p> <p>SO NOW WE'RE BEING HONEST</p> <p>so i go </p> <p>"so its not better, it just annoyed you less"</p> <p>and he goes </p> <p>"no its better"</p> <p>we enter the loop</p> <p>i say hes arguing wording instead of the point </p> <p>he says "language barrier"</p> <p>i say "no youre just changing what you mean" </p> <p>he says "youre taking words too literally"</p> <p>so now apparently words dont mean what words mean</p> <p>then out of nowhere he hits me with </p> <p>"0/10 ragebait" </p> <p>followed by </p> <p>"dont make me finger your butt"</p> <p>at this point im not even arguing linux anymore im studying a psychological case</p> <p>i tell him this is what happens when you run out of arguments</p> <p>this man responds with </p> <p>"jit not even kirk could yap this hard"</p> <p>i genuinely dont even know what that means</p> <p>i tell him hes trying harder to not be wrong than to actually make a point</p> <p>he says </p> <p>"im not even trying youre arguing piss shit and air 😭"</p> <p>WHILE STILL REPLYING</p> <p>so i hit him with </p> <p>"if you werent trying you wouldnt still be here arguing"</p> <p>and that was the moment he mentally left the conversation</p> <p>we started at "linux is superior" </p> <p>and ended at "youre arguing air"</p> <p>ive never seen someone go from a tech debate to schisotalking this fast in my life</p> <p>moral of the story:</p> <p>linux isnt an operating system </p> <p>its an ego progression system</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/ConsistentGiraffe8"> /u/ConsistentGiraffe8 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1st5ppt/some_dude_i_know_just_discovered_linux_and_i/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1st5ppt/some_dude_i_know_just_discovered_linux_and_i/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canonical security audit of rust-coreutils reveals 113 CVEs]]></title>
<description><![CDATA[While it's great that Canonical did the audit and is working to fix these CVEs this shows that Rust isnt some magic language where CVEs dont happen. It brings up the question, is a Rust rewrite worth it? These CVEs were not found in the C version coreutils and were only found due to a paid audit....]]></description>
<link>https://tsecurity.de/de/3456441/linux-tipps/canonical-security-audit-of-rust-coreutils-reveals-113-cves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456441/linux-tipps/canonical-security-audit-of-rust-coreutils-reveals-113-cves/</guid>
<pubDate>Thu, 23 Apr 2026 01:07:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>While it's great that Canonical did the audit and is working to fix these CVEs this shows that Rust isnt some magic language where CVEs dont happen.</p> <p>It brings up the question, is a Rust rewrite worth it? These CVEs were not found in the C version coreutils and were only found due to a paid audit.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/nukem996"> /u/nukem996 </a> <br> <span><a href="https://discourse.ubuntu.com/t/an-update-on-rust-coreutils/80773">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sst6l6/canonical_security_audit_of_rustcoreutils_reveals/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are you paying an AI ‘swarm tax’? Why single agents often beat complex systems]]></title>
<description><![CDATA[Enterprise teams building multi-agent AI systems may be paying a compute premium for gains that don't hold up under equal-budget conditions. New Stanford University research finds that single-agent systems match or outperform multi-agent architectures on complex reasoning tasks when both are give...]]></description>
<link>https://tsecurity.de/de/3456424/it-nachrichten/are-you-paying-an-ai-swarm-tax-why-single-agents-often-beat-complex-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456424/it-nachrichten/are-you-paying-an-ai-swarm-tax-why-single-agents-often-beat-complex-systems/</guid>
<pubDate>Thu, 23 Apr 2026 01:01:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise teams building multi-agent AI systems may be paying a compute premium for gains that don't hold up under equal-budget conditions. New Stanford University research finds that single-agent systems match or outperform multi-agent architectures on complex reasoning tasks when both are given the same thinking token budget.</p><p>However, multi-agent systems come with the added baggage of computational overhead. Because they typically use longer reasoning traces and multiple interactions, it is often unclear whether their reported gains stem from architectural advantages or simply from consuming more resources.</p><p>To isolate the true driver of performance, researchers at Stanford University <a href="https://arxiv.org/abs/2604.02460">compared single-agent systems against multi-agent architectures</a> on complex multi-hop reasoning tasks under equal "thinking token" budgets.</p><p>Their experiments show that in most cases, single-agent systems match or outperform multi-agent systems when compute is equal. Multi-agent systems gain a competitive edge when a single agent's context becomes too long or corrupted.</p><p>In practice, this means that a single-agent model with an adequate thinking budget can deliver more efficient, reliable, and cost-effective multi-hop reasoning. Engineering teams should reserve multi-agent systems for scenarios where single agents hit a performance ceiling.</p><h2>Understanding the single versus multi-agent divide</h2><p>Multi-agent frameworks, such as planner agents, role-playing systems, or debate swarms, break down a problem by having multiple models operate on partial contexts. These components communicate with each other by passing their answers around.</p><p>While multi-agent solutions show strong empirical performance, comparing them to single-agent baselines is often an imprecise measurement. Comparisons are heavily confounded by differences in test-time computation. Multi-agent setups require multiple agent interactions and generate longer reasoning traces, meaning they consume significantly more tokens.</p><p>ddConsequently, when a multi-agent system reports higher accuracy, it is difficult to determine if the gains stem from better architecture design or from spending extra compute.</p><p><a href="https://venturebeat.com/orchestration/research-shows-more-agents-isnt-a-reliable-path-to-better-enterprise-ai">Recent studies</a> show that when the compute budget is fixed, elaborate multi-agent strategies frequently underperform compared to strong single-agent baselines. However, they are mostly very broad comparisons that don’t account for nuances such as different multi-agent architectures or the difference between prompt and reasoning tokens.</p><p>“A central point of our paper is that many comparisons between single-agent systems (SAS) and multi-agent systems (MAS) are not apples-to-apples,” paper authors Dat Tran and Douwe Kiela told VentureBeat. “MAS often get more effective test-time computation through extra calls, longer traces, or more coordination steps.”</p><h2>Revisiting the multi-agent challenge under strict budgets</h2><p>To create a fair comparison, the Stanford researchers set a strict “thinking token” budget. This metric controls the total number of tokens used exclusively for intermediate reasoning, excluding the initial prompt and the final output.</p><p>The study evaluated single- and multi-agent systems on multi-hop reasoning tasks, meaning questions that require connecting multiple pieces of disparate information to reach an answer.</p><p>During their experiments, the researchers noticed that single-agent setups sometimes stop their internal reasoning prematurely, leaving available compute budget unspent. To counter this, they introduced a technique called SAS-L (single-agent system with longer thinking).</p><p>Rather than jumping to multi-agent orchestration when a model gives up early, the researchers suggest a simple prompt-and-budgeting change.</p><p>"The engineering idea is simple," Tran and Kiela said. "First, restructure the single-agent prompt so the model is explicitly encouraged to spend its available reasoning budget on pre-answer analysis."</p><p>By instructing the model to explicitly identify ambiguities, list candidate interpretations, and test alternatives before committing to a final answer, developers can recover the benefits of collaboration inside a single-agent setup. </p><p>The results of their experiments confirm that a single agent is the strongest default architecture for multi-hop reasoning tasks. It produces the highest accuracy answers while consuming fewer reasoning tokens. When paired with specific models like Google's Gemini 2.5, the longer-thinking variant produces even better aggregate performance.</p><p>The researchers rely on a concept called “Data Processing Inequality” to explain why a single agent outperforms a swarm. Multi-agent frameworks introduce inherent communication bottlenecks. Every time information is summarized and handed off between different agents, there is a risk of data loss.</p><p>In contrast, a single agent reasoning within one continuous context avoids this fragmentation. It retains access to the richest available representation of the task and is thus more information-efficient under a fixed budget.</p><p>The authors also note that enterprises often overlook the secondary costs of multi-agent systems.</p><p>"What enterprises often underestimate is that orchestration is not free," they said. "Every additional agent introduces communication overhead, more intermediate text, more opportunities for lossy summarization, and more places for errors to compound."</p><p>On the other hand, they discovered that multi-agent orchestration is superior when a single agent's environment gets messy. If an enterprise application must handle highly degraded contexts, such as noisy data, long inputs filled with distractors, or corrupted information, a single agent struggles. In these scenarios, the structured filtering, decomposition, and verification of a multi-agent system can recover relevant information more reliably.</p><p>The study also warns about hidden evaluation traps that falsely inflate multi-agent performance. Relying purely on API-reported token counts heavily distorts how much computation an architecture is actually spending. The researchers found these accounting artifacts when testing models like Gemini 2.5, proving this is an active issue for enterprise applications today.</p><p>"For API models, the situation is trickier because budget accounting can be opaque," the authors said. To evaluate architectures reliably, they advise developers to "log everything, measure the visible reasoning traces where available, use provider-reported reasoning-token counts when exposed, and treat those numbers cautiously."</p><h2>What it means for developers</h2><p>If a single-agent system matches the performance of multiple agents under equal reasoning budgets, it wins on total cost of ownership by offering fewer model calls, lower latency, and simpler debugging. Tran and Kiela warn that without this baseline, "some enterprises may be paying a large 'swarm tax' for architectures whose apparent advantage is really coming from spending more computation rather than reasoning more effectively."</p><p>Another way to look at the decision boundary is not how complex the overall task is, but rather where the exact bottleneck lies.</p><p>"If it is mainly reasoning depth, SAS is often enough. If it is context fragmentation or degradation, MAS becomes more defensible," Tran said.</p><p>Engineering teams should stay with a single agent when a task can be handled within one coherent context window. Multi-agent systems become necessary when an application handles highly degraded contexts. </p><p>Looking ahead, multi-agent frameworks will not disappear, but their role will evolve as frontier models improve their internal reasoning capabilities.</p><p>"The main takeaway from our paper is that multi-agent structure should be treated as a targeted engineering choice for specific bottlenecks, not as a default assumption that more agents automatically means better intelligence," Tran said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kimi K2.6 runs agents for days — and exposes the limits of enterprise orchestration]]></title>
<description><![CDATA[Most orchestration frameworks were built for agents that run for seconds or minutes. Now that agents are running for hours — and in some cases days — those frameworks are starting to crack.Several model providers, such as Anthropic with Claude Code and OpenAI with Codex, introduced early support ...]]></description>
<link>https://tsecurity.de/de/3452452/it-nachrichten/kimi-k26-runs-agents-for-days-and-exposes-the-limits-of-enterprise-orchestration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452452/it-nachrichten/kimi-k26-runs-agents-for-days-and-exposes-the-limits-of-enterprise-orchestration/</guid>
<pubDate>Tue, 21 Apr 2026 19:32:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most orchestration frameworks were built for agents that run for seconds or minutes. Now that agents are <a href="https://venturebeat.com/infrastructure/how-googles-internal-rl-could-unlock-long-horizon-ai-agents">running for hour</a>s — and in some cases days — those frameworks are starting to crack.</p><p>Several model providers, such as Anthropic with Claude Code and OpenAI with Codex, introduced early support for long-horizon agents through multi-session tasks, subagents and background execution. However, these systems sometimes assume agents are still operating within bounded-time workflows even when they run for extended periods. </p><p>Open-source model provider Moonshot AI wants to push beyond that with its new model, Kimi K2.6. </p><p>Moonshot says the model is designed for continuous execution, with internal use cases including agents that ran for hours and, in one case, five straight days, handling monitoring and incident response autonomously.</p><p>But this growing use of this type of agent is exposing a critical gap in orchestration: most orchestration frameworks were not designed for this type of continuous, stateful execution. Open-source models, such as Kimi K2.6, that rely on agent swarms are making the case that their orchestration approach comes close to managing stateful agents. </p><h2>The difficulties of orchestrating long-running agents</h2><p>While it is true that some enterprises would rather bring their own orchestration frameworks to their agentic ecosystem, model providers and agent platforms recognize that offering agent management remains a competitive advantage. </p><p>Other model providers have begun exploring long-running agents, many through multi-session tasks and background execution. For example, Anthropic’s Claude Code orchestrates agents with <a href="https://code.claude.com/docs/en/agent-teams">a lead agent that directs</a> other agents based on a set of user-instructed definitions. OpenAI’s Codex <a href="https://developers.openai.com/codex/subagents">runs similarly</a>. </p><p>Kimi K2.6 approaches orchestration with an improved version of its Agent Swarms, capable of managing up to 300 sub-agents “executing across 4,000 coordinated steps simultaneously,” <a href="https://www.kimi.com/blog/kimi-k2-6">Moonshot AI wrote in a blog post</a>. Compared to both Claude Code and Codex, K2.6 relies on the model, rather than pre-defined roles, to determine orchestration.</p><p>Kimi K2.6 is now available on Hugging Face, through its API, Kimi Code and the Kimi app.</p><p>Practitioners experimenting with long-horizon agents say the brittleness runs deeper than prompting can fix.</p><p>As one practitioner, Maxim Saplin, put it in <a href="https://dev.to/maximsaplin/long-horizon-agents-are-here-full-autopilot-isnt-5bo7">a blog post</a>, “That does not mean subagents are useless. It means orchestration is still fragile. Right now, it feels more like a product and training problem than something you can solve by writing a sufficiently stern prompt.”</p><p>The problem long-running agents pose is that it’s difficult to maintain their state, especially as their environment continues to change while they're doing their job. The agent would constantly call different tools and APIs or tap into different databases during its runtime. Most current agents, those that may run for one or two executions, do call different tools, but for at most a minute. </p><p>Mark Lambert, chief product officer at ArmorCode, which builds an autonomous security platform for enterprises, told VentureBeat in an email that the governance gap is already outpacing deployment.</p><p>"These agentic systems can now generate code and system changes faster than most organizations can review, remediate, or govern them. This will require more than just additional scanning. Organizations will need stronger AI governance that provides the context, prioritization, and accountability teams need to manage Kimi and other AI-generated risk before they turn into accumulated exposure," Lambert said. </p><p>Long-running agents could also risk failure without a clear rollback. Most importantly, these types of agents often lack a set of well-defined tasks and dynamically adjust their plans as they run. </p><p>Kunal Anand, chief product officer at F5, told VentureBeat in an email that long-horizon agents represent a much bigger architectural shift than most companies were prepared for.</p><p>“We went from scripts to services to containers to functions, and now to agents as persistent infrastructure. That creates categories we do not yet have good names for: agent runtime, agent gateway, agent identity provider, agent mesh. The API gateway pattern is morphing into something that has to understand goals and workflows, not just endpoints and verbs,” Anand said. </p><h2>Running for 13 hours and even five days</h2><p>Understanding how to orchestrate agents becomes important because model capabilities have begun to outpace orchestration innovations, even as enterprises start to look at long-horizon agents.   </p><p>Moonshot AI says the model is built for tasks that reflect "real-world challenges that typically demand weeks or months of collective human effort." In a separate technical document provided to VentureBeat, Moonshot claims K2.6 built a full SysY compiler from scratch in 10 hours — work it characterized as equivalent to a team of four engineers over two months — and passed all 140 functional tests without human intervention.</p><p>The team deployed K2.6 to complex engineering tasks, including overhauling an eight-year-old open source financial matching engine. Moonshot's engineers described a 13-hour execution that “iterated through 12 optimization strategies, initiating over 1,000 tool calls to modify more than 4,000 lines of code precisely.”</p><div></div><p>Moonshot said one of its teams used K2.6 to build an agent that ran autonomously for five days. That agent managed monitoring, incident response and system operations.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Real Constraint on Enterprise AI isn’t GPUs; It’s Power]]></title>
<description><![CDATA[For years, energy sat in the background of enterprise IT planning. Costs were stable enough that most leaders didn’t treat power as a first-order constraint. You planned for servers, storage, networking, and software; energy rarely changed the math. AI breaks that model. In recent years, AI conve...]]></description>
<link>https://tsecurity.de/de/3452122/downloads/the-real-constraint-on-enterprise-ai-isnt-gpus-its-power/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452122/downloads/the-real-constraint-on-enterprise-ai-isnt-gpus-its-power/</guid>
<pubDate>Tue, 21 Apr 2026 17:46:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="169" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg 1170w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?resize=300,169 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?resize=768,432 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?resize=1024,576 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?resize=752,423 752w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?resize=576,324 576w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/04/cityscape.jpg?resize=600,337 600w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>For years, energy sat in the background of enterprise IT planning. Costs were stable enough that most leaders didn’t treat power as a first-order constraint. You planned for servers, storage, networking, and software; energy rarely changed the math. AI breaks that model. In recent years, AI conversations centered on the question: can you get the … <a href="https://blogs.vmware.com/cloud-foundation/2026/04/21/the-real-constraint-on-enterprise-ai-isnt-gpus-its-power/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/04/21/the-real-constraint-on-enterprise-ai-isnt-gpus-its-power/">The Real Constraint on Enterprise AI isn’t GPUs; It’s Power</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Incoming Apple CEO John Ternus isn’t known for taking big, risky swings]]></title>
<description><![CDATA[Apple on Monday announced that John Ternus, senior vice president of Hardware Engineering, will become Apple’s next CEO effective…
The post Incoming Apple CEO John Ternus isn’t known for taking big, risky swings appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3452015/ios-mac-os/incoming-apple-ceo-john-ternus-isnt-known-for-taking-big-risky-swings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452015/ios-mac-os/incoming-apple-ceo-john-ternus-isnt-known-for-taking-big-risky-swings/</guid>
<pubDate>Tue, 21 Apr 2026 17:09:08 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple on Monday announced that John Ternus, senior vice president of Hardware Engineering, will become Apple’s next CEO effective…</p>
<p>The post <a href="https://macdailynews.com/2026/04/21/incoming-apple-ceo-john-ternus-isnt-known-for-taking-big-risky-swings/">Incoming Apple CEO John Ternus isn’t known for taking big, risky swings</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's new CEO: Who is John Ternus?]]></title>
<description><![CDATA[John Ternus was the center of speculation as being the best and most likely choice for the next Apple CEO, and those predictions came true. Who is he, and how did he get here?John TernusApple, like many other massive companies with giant workforces and a decades-long history, has to plan for the ...]]></description>
<link>https://tsecurity.de/de/3449631/ios-mac-os/apples-new-ceo-who-is-john-ternus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3449631/ios-mac-os/apples-new-ceo-who-is-john-ternus/</guid>
<pubDate>Mon, 20 Apr 2026 23:20:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://appleinsider.com/inside/john-ternus" title="John Ternus" data-kpt="1">John Ternus</a> was the center of speculation as being the best and most likely choice for the next Apple CEO, and those predictions came true. Who is he, and how did he get here?<br><br><div><img src="https://photos5.appleinsider.com/gallery/66473-139434-johnternusheader-xl.jpg" alt="Man in a blue T-shirt speaking with hand gestures, standing against an aerial view of a circular office campus surrounded by trees and city buildings" height="738"><br><span>John Ternus</span></div><br>Apple, like many other massive companies with giant workforces and a decades-long history, has to plan for the future direction of the company. Part of that preparation involves determining who will take <a href="https://appleinsider.com/articles/25/11/15/apples-succession-planning-efforts-step-up-to-find-tim-cooks-replacement">control as CEO</a> after the current leader departs, and what to do to prepare for that inevitability.<br><br>For Apple and its aging leadership, Apple had to find its replacement for <a href="https://appleinsider.com/inside/tim-cook" title="Tim Cook" data-kpt="1">Tim Cook</a>. Even though Cook wasn't thought to be <a href="https://appleinsider.com/articles/25/11/23/apple-ceo-tim-cook-isnt-retiring-in-2026">retiring in 2026</a>, the sheer size and number of moving parts at Apple meant it had to prepare in advance, so there's enough of a runway for the heir to the position to get ready, as well as the company itself.<br><br><br> <a href="https://appleinsider.com/articles/26/04/20/the-person-who-could-be-apple-ceo-who-is-john-ternus?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243212?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adobe bets on agentic AI to rewrite SaaS for customer experience]]></title>
<description><![CDATA[Consumer engagement has been fundamentally changing with the advent of AI agents, forcing a rethink by software-as-a-service (SaaS) companies, and creativity platform provider Adobe is responding by shifting its approach to what it calls ‘Customer Experience Orchestration (CXO).’



Announced tod...]]></description>
<link>https://tsecurity.de/de/3449089/it-security-nachrichten/adobe-bets-on-agentic-ai-to-rewrite-saas-for-customer-experience/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3449089/it-security-nachrichten/adobe-bets-on-agentic-ai-to-rewrite-saas-for-customer-experience/</guid>
<pubDate>Mon, 20 Apr 2026 19:05:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Consumer engagement has been fundamentally changing with the advent of AI agents, forcing a rethink by <a href="https://www.cio.com/article/4131904/saas-isnt-dead-the-market-is-just-becoming-more-hybrid.html" target="_blank">software-as-a-service (SaaS)</a> companies, and creativity platform provider Adobe is responding by shifting its approach to what it calls ‘Customer Experience Orchestration (CXO).’</p>



<p>Announced today at <a href="https://summit.adobe.com/na/" target="_blank" rel="nofollow">Adobe Summit</a>, the new Adobe CX Enterprise suite is a pivot to a future defined by agents rather than by software alone, where SaaS companies claim an advantage based on their deep domain expertise and troves of first and third-party data.</p>



<p>The platform brings together customizable and out-of-the-box AI agents, Model Context Protocol (MCP) endpoints, and new intelligence systems built on Adobe’s orchestration engine.</p>



<p>“SaaS is changing, and we are re-architecting so that we can participate in the reimagination, the redefinition of SaaS,” said Adobe VP Sundeep Parsa.</p>



<h2 class="wp-block-heading">Agents executing with guidance from a ‘coach’</h2>



<p>Adobe CX Enterprise builds on the company’s <a href="https://www.infoworld.com/article/3855674/adobe-announces-ai-agents-for-customer-interaction.html" target="_blank">Adobe Experience Platform (AEP) Agent Orchestrator</a>, which brought AI agents directly into Adobe apps. Released in 2025, AEP now  powers more 1 trillion experiences annually, according to the company.</p>



<p>AEP remains the “anchor” for Adobe CX Enterprise, which now gives customers the ability to create agent skills (reusable instructions), as well as providing specialized and customizable agents. These can be incorporated into any AI tech stack, including Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini, Microsoft Copilot, Nvidia’s NemoClaw, and others. Developers also have access to Model Context Protocol (MCP) servers and other infrastructure required to build customized use cases.</p>



<p>“We’re going to make sure our applications are not trapped inside our UI layer, that they become composable services available through MCP tool calls or the A2A layer,” Parsa explained. “Customers can tap into what they have and bring that into their own unique processes, be their own UI.”</p>



<p>He emphasized the importance of customer choice. Many enterprises are still grappling with the ‘build or buy’ question; some will prefer to create their own bespoke user interface (UI) layer, while others will have no interest in doing so.</p>



<p>With CX Enterprise, enterprises can use pre-loaded agent skills to build custom workflows, or can launch agents pre-built for specific tasks like workflow optimization (coordinating tasks or automating handoffs) and brand governance (enforcing policies, managing permissions, tracking asset rights). And, a new Adobe CX Enterprise Coworker, to be available in the coming months, will act on specified goals and orchestrate other agents to perform multi-step actions.</p>



<p>For instance, if a marketing team is looking to increase loyalty subscriptions by 3% in the next quarter, the CX Enterprise Coworker will work with other agents to identify relevant audience segments, surface performance insights, create a plan, and develop email copy or visual assets, Parsa noted. Once all this is approved by a human, the Coworker will then help execute the campaign and monitor results.</p>



<p>Whereas previously agents would build an audience, then “go to sleep,” Adobe’s new CX Enterprise Coworker is “always on,” has persistent memory, and can run workflows across weeks, or even full financial quarters if required, Parsa explained. He likened the CX Enterprise Coworker to an American football quarterback, the player who directs the activities on the field, guided by a coach on the sidelines. Coworker’s coach is a marketer or a brand specialist.</p>



<p>“We’re doubling down on this framing of customer experience orchestration,” Parsa says.</p>



<h2 class="wp-block-heading">Moving to one-on-one personalization</h2>



<p>Along with these <a href="https://www.networkworld.com/article/4122790/gauging-the-real-impact-of-ai-agents.html" target="_blank">agentic tools</a>, Adobe is introducing two new intelligence systems: Adobe Brand Intelligence and Adobe Engagement Intelligence. </p>



<p>Brand Intelligence is built on a fine-tuned large language model (LLM) with vision-language capabilities that learns from “qualitative and nuanced inputs” like annotations, feedback cycles, or rejected assets.</p>



<p>“Brand intelligence is going after a much harder problem than ‘a brand kit,’ which is a codification of a CSS style guide,” Parsa explained. The LLM can begin to understand <a href="https://www.cio.com/article/189353/making-the-most-of-sentiment-analysis.html?utm=hybrid_search" target="_blank">brand sentiment</a>, informed by “data engagement signals and the actual enterprise assets.”</p>



<p>Adobe Engagement Intelligence helps teams decide next best offers, messages, or other actions for targeted customers. This is based on their lifetime interactions, rather than click-throughs or conversions, according to Parsa.</p>



<p>Whereas previously, less was more, “in this world, more is better,” he said, pointing out that the promise of generative AI is producing more material economically. “It’s not creating more for more’s sake, it’s targeted campaigns that get you much closer to one-on-one personalization.”</p>



<p>Early production gains are “massive,” Parsa claimed. This is because troubleshooting and early detection of problems now takes “hours, not days and weeks.”</p>



<h2 class="wp-block-heading">SaaS companies’ data advantage</h2>



<p>Like many SaaS companies grappling with an agent-driven future where pay-per-seat models are becoming less relevant, Adobe is emphasizing its data advantage. Parsa pointed out that more than 20,000 enterprises have built on Adobe’s platform over the years, giving the company enormous amounts of data alongside domain expertise.</p>



<p>Generative AI and AI agents do a good job of understanding the “corpus of world knowledge” and building some “useful capabilities for all of us,” Parsa acknowledged. “But these technologies stop at the enterprise walls, because those are ‘walled gardens.’”</p>



<p>Further, enterprise context is very complicated and spread across numerous applications, he noted. “It’s codified in documents; in some cases just tribal knowledge informs how people function on a day to day basis.” AI agents working on their own (like OpenClaw or Claude Cowork) break in the enterprise because they are “brittle” and not grounded in enterprise data, he said.</p>



<p>“We are a proxy for all of the enterprise context that lives inside our applications,” said Parsa. “We’re going to bring that into the AI layer much faster than a customer restarting that whole process with an AI platform.”</p>



<p>Ultimately, he said, Adobe is “adapting and adjusting” to customer feedback and consumer interaction with brands, as well as with the internet itself, as customer engagement undergoes a dramatic shift in the era of AI. As this unfolds, Parsa emphasized the importance of “open, open, open.”</p>



<p>“We absolutely are going to work with tech partners, we’re going to work with other SaaS companies to make sure that we stay flexible and meet the customer where they are,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Making agents dull]]></title>
<description><![CDATA[I’ve been arguing for a while now that enterprise AI won’t really take off until it gets boring. Not boring in the sense of uninspired; no, I mean boring in the sense that enterprises can trust it, govern it, observe it, and hand it to rank-and-file employees without undue concern that things wil...]]></description>
<link>https://tsecurity.de/de/3447800/ai-nachrichten/making-agents-dull/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447800/ai-nachrichten/making-agents-dull/</guid>
<pubDate>Mon, 20 Apr 2026 11:33:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve been arguing for a while now that enterprise AI won’t really take off <a href="https://www.infoworld.com/article/4082782/boring-governance-is-the-path-to-real-ai-adoption.html">until it gets boring</a>. Not boring in the sense of uninspired; no, I mean boring in the sense that enterprises can trust it, govern it, observe it, and hand it to rank-and-file employees without undue concern that things will go wrong.</p>



<p>We have no shortage of over-funded startups clamoring to be the next big thing in AI, but not nearly enough that are quietly doing the essential work to make AI safe for enterprise consumption. Enter <a href="https://stacklok.com/">Stacklok</a>.</p>



<p>On the surface, this might look like yet another startup trying to surf the AI agent wave. It’s not. Stacklok is exciting precisely because <a href="https://stacklok.com/company/">its executive team</a> is deeply experienced in being <em>unexciting</em>. Back at Google, Craig McLuckie and Joe Beda were instrumental in the creation of <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>. They took the messy, chaotic world of container orchestration and built an abstraction layer that made it “boring” enough that the largest banks, telcos, and retailers in the world could rely on it with confidence. Now they’re bringing that ability to wring order out of chaos to agentic AI, and they recognize that the real problem in enterprise AI has more to do with operational accountability than model quality.</p>



<p>I interviewed McLuckie and Beda to better understand the opportunity to create a “Kubernetes moment” in agentic AI.</p>



<h2 class="wp-block-heading"><a></a>Targeting accountability</h2>



<p>McLuckie founded Stacklok in early 2023. Beda, his Kubernetes and later Heptio counterpart, had “semi-retired” in 2022. Beda doesn’t need to make more money, and he’s not joining out of nostalgia. As he tells it, this is “an extraordinary moment in the industry,” with “an opportunity to bring deep expertise in developer platforms and enterprise-grade infrastructure” to solving key enterprise problems.</p>



<p>“The biggest problem,” McLuckie says, “is accountability.” He explains: “An agent, no matter how sophisticated, no matter how capable, no matter how useful, cannot be held accountable for the work it undertakes.” That’s exactly right. A large language model can write code, summarize a contract, file a ticket, or trigger a workflow, but if it mangles customer data, oversteps its permissions, or keeps running after the employee who launched it has left the company, nobody gets to shrug and blame the model. The enterprise still owns the outcome.</p>



<p>Even OpenAI, which has been slower to take the enterprise seriously than Anthropic, now recognizes that enterprises need AI to fit inside workflows, controls, deployment models, and day-to-day operations. It’s no longer just about raw model prowess, <a href="https://www.runtime.news/how-openai-plans-to-win-over-the-enterprise/">as Tom Krazit writes</a>. In other words, the market is slowly rediscovering what infrastructure people have known for a long time: Enterprises may buy capability, but they deploy control.</p>



<p>A related issue, according to Beda, is that AI’s speed changes everything. Tasks that used to take a human days or weeks may soon be completed in minutes by an agent. That doesn’t just create productivity. It creates scale, and scale turns manageable sloppiness into operational disaster. As he puts it, “The volume dial is going to 11 across the board.” I recently said that <a href="https://www.infoworld.com/article/4148328/the-agent-security-mess.html">humans don’t use most of their granted permissions, but agents will</a>. That’s exactly why <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity</a>, authorization, and auditability suddenly stop being problems for the security team and become architecture.</p>



<p>This is where the Kubernetes analogy is actually useful, rather than just founder mythmaking.</p>



<h2 class="wp-block-heading"><a></a>AI’s Kubernetes moment</h2>



<p>Too many people remember <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes </a>as a container story. Enterprises embraced it for a more practical reason: It gave them a <a href="https://www.infoworld.com/article/2260090/kubernetes-and-cloud-portability-its-complicated.html">common operating model across environments</a>, plus an ecosystem of policy, security, observability, and workflow tools layered on top. Cloud Native Computing Foundation now <a href="https://www.cncf.io/announcements/2026/01/20/kubernetes-established-as-the-de-facto-operating-system-for-ai-as-production-use-hits-82-in-2025-cncf-annual-cloud-native-survey/">says 82% of container users run Kubernetes</a> in production, and the organization explicitly frames Kubernetes as the operating system for AI. In our interview, McLuckie describes Kubernetes’ deeper contribution as “self-determination.” That is, it gave enterprises a consistent substrate on premises, at the edge, and in the cloud. That consistency is what helped an ecosystem to flourish around it.</p>



<p>Beda goes one step further: “One of the core ideas in Kubernetes is that you describe what you want to happen, and then you have the system go make it happen.” This, he says, means that Kubernetes is essentially “control theory rendered into software. Over time, an enterprise’s desired state moves into code, into version control, and into systems traceable back to accountable humans. Nerdy and sort of dull? Sure. But that’s the point. Enterprise AI doesn’t just need smarter models. It needs systems where humans declare intent, machines execute it, and the whole mess remains observable and auditable.</p>



<p>This is why I keep <a href="https://www.infoworld.com/article/4132451/finding-the-key-to-the-ai-agent-control-plane.html">insisting that the biggest strategic question in agentic AI</a> isn’t whether agents are cool. They are—or at least they can be. No, the real question is who owns the control plane. Stacklok matters because it is explicitly aiming at that layer. The company’s bet is that enterprises want to run and manage Model Context Protocol–based agent infrastructure on the Kubernetes they already know. They want policy, identity, isolation, and observability built in, not bolted on afterwards.</p>



<p>That last part matters because MCP is important, but it isn’t enough. Anthropic introduced MCP in November 2024 as an open standard for connecting AI systems to tools and data. Later, they donated it to the Linux Foundation’s Agentic AI Foundation to keep it neutral and community-driven. It worked. Anthropic reports there are now <a href="https://www.anthropic.com/news/model-context-protocol">more than 10,000 active public MCP servers</a> and support across ChatGPT, Cursor, Gemini, Microsoft Copilot, and VS Code.</p>



<p>That’s awesome, but it’s also not enough. Why? Because a protocol isn’t a platform. A protocol can help an agent talk to a tool, but it doesn’t, by itself, tell an enterprise who approved that agent, what data it can touch, how its actions are logged, or how to shut it down safely when the human who launched it has left the company.</p>



<h2 class="wp-block-heading">Meeting users where they are</h2>



<p>That’s where Stacklok’s self-hosted, Kubernetes-native bias starts to look smart rather than stodgy. (Though, again, “stodgy” isn’t a bad thing for risk-averse enterprises.) McLuckie is blunt: “If you’re an enterprise connecting agents to sensitive data, you are almost certainly not comfortable with that data egressing your security domain or being sent to a SaaS endpoint that a vendor controls.” We’ve seen this movie before. When your hosting, identity, tool integration, and policy layers all belong to the same vendor, “choice” starts to mean “replatform.”</p>



<p>No one wants that.</p>



<p>This is also where open source matters, though not in the simplistic sense that open source automatically wins. It doesn’t. Enterprises don’t buy ideology: they buy simplicity. But in a young market, they also value leverage. I’ve written before that <a href="https://www.infoworld.com/article/3548263/open-source-isnt-going-to-save-ai.html">open source doesn’t magically redistribute market power</a>. What it <em>can</em> do is give customers options and some control over their fate. In AI, where model switching costs are still relatively low, that optionality matters. Talking with McLuckie and Beda, it’s clear they are open source true believers, but not obnoxiously so. That’s good, because enterprises don’t need a sermon on openness; they just need enough neutrality to avoid getting trapped while the market is still changing underneath them.</p>



<p>It’s all about meeting enterprises where they are and helping them to incrementally move to where they’d like to be. As McLuckie stresses, most enterprise AI teams are being asked to deliver more with AI while running with flat or capped headcount. They don’t need and can’t implement a grand theory of some idealized, fully autonomous enterprise. Instead, they need <a href="https://www.infoworld.com/article/4125409/ai-will-not-save-developer-productivity.html">an accretive (golden) path</a> from here to there using things they already understand, such as containers, isolation, OpenTelemetry, Kubernetes, existing identity systems, and existing observability stacks.</p>



<p>Sound boring? Good!</p>



<p>The opposite of “boring” in enterprise AI isn’t innovation. It’s slideware or demoware that looks great in a keynote but dies on contact with procurement, security review, compliance, and the first ugly bit of enterprise data. McLuckie captures this perfectly: “Vibe-coding a platform for two weeks can produce something plausible. It won’t produce something accurate, hardened, or enterprise-grade.”</p>



<p>Will Stacklok be the company that defines this layer? It’s way too early to say. Markets this young are littered with smart people who were directionally right and commercially wrong. But the company is aiming at the right problem, and that already puts it ahead of a depressingly large percentage of the AI industry.</p>



<p>Again, the next era of enterprise AI will be won by whoever makes agents governable, portable, observable, and boring enough to trust. Kubernetes helped do that for <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html">cloud-native</a> infrastructure. Stacklok is betting the same playbook can work for agentic infrastructure. That’s not a nostalgic rerun of Kubernetes. It’s a recognition that enterprises still need what they’ve always needed: not more magic, but a way to control it.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fructose Isn't Just Sugar. It Acts More Like a Hormone]]></title>
<description><![CDATA[Slashdot reader smazsyr writes: A new review says we've had fructose wrong for decades. The nine authors, led by Richard Johnson at the University of Colorado Anschutz, argue that fructose "is not just another calorie." It is a signal. It tells the liver to make fat and brace for a famine that ne...]]></description>
<link>https://tsecurity.de/de/3444859/it-security-nachrichten/fructose-isnt-just-sugar-it-acts-more-like-a-hormone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3444859/it-security-nachrichten/fructose-isnt-just-sugar-it-acts-more-like-a-hormone/</guid>
<pubDate>Sat, 18 Apr 2026 19:51:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Slashdot reader smazsyr writes: A new review says we've had fructose wrong for decades. The nine authors, led by Richard Johnson at the University of Colorado Anschutz, argue that fructose "is not just another calorie." It is a signal. It tells the liver to make fat and brace for a famine that never comes. That made sense for a bear fattening up on autumn berries. It makes less sense for a person drinking soda in March. 

The review reframes the WHO's sugar guideline, argues ScienceBlog.com, as "less a recommendation about calories and more a warning about a signalling molecule we have been dosing ourselves with, several times a day, for most of a century."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Fructose+Isn't+Just+Sugar.+It+Acts+More+Like+a+Hormone%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F04%2F18%2F0444250%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F04%2F18%2F0444250%2Ffructose-isnt-just-sugar-it-acts-more-like-a-hormone%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/04/18/0444250/fructose-isnt-just-sugar-it-acts-more-like-a-hormone?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[App Store scams are getting worse and Apple isn't doing enough]]></title>
<description><![CDATA[Apple is shooting itself in the foot with how often it lets flagrant scam apps into the App Store. It's doing so at precisely the time is needs to do better for iPhone user safety.The App Store is not as safe as Apple says, or as Apple could make it —- image credit: AppleIn just the last week, Fr...]]></description>
<link>https://tsecurity.de/de/3442814/ios-mac-os/app-store-scams-are-getting-worse-and-apple-isnt-doing-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442814/ios-mac-os/app-store-scams-are-getting-worse-and-apple-isnt-doing-enough/</guid>
<pubDate>Fri, 17 Apr 2026 19:08:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is shooting itself in the foot with how often it lets flagrant scam apps into the <a href="https://appleinsider.com/inside/app-store" title="App Store" data-kpt="1">App Store</a>. It's doing so at precisely the time is needs to do better for iPhone user safety.<br><br><div><img src="https://photos5.appleinsider.com/gallery/63613-132271-000-lede-red-App-Store-xl.jpg" alt="A blue square with rounded edges featuring a red abstract geometric logo, set against a blue background." height="738"><br><span>The App Store is not as safe as Apple says, or as Apple could make it —- image credit: Apple</span></div><br>In just the last week, Freecash <a href="https://appleinsider.com/articles/26/04/15/freecash-app-scammed-users-and-the-app-store-for-months-before-removal">was removed</a> for how it sold user data. Apple only killed it  after it was asked about the issue.<br><br>At about the same time, a fake cryptocurrency app took users for around <a href="https://appleinsider.com/articles/26/04/14/bogus-crypto-wallet-on-app-store-steals-95m">$9.5 million</a> before it was taken down. Or to look at it another way, Apple earned between $1.425 million and $2.85 million from that scam, depending on whether the developer is charged 15% or 30%.<br><br><br> <a href="https://appleinsider.com/articles/26/04/17/app-store-scams-are-getting-worse-and-apple-isnt-doing-enough?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244080?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agility is the new IT currency: A roadmap for skills, readiness and innovation]]></title>
<description><![CDATA[In an era of constant technological change, agility is more than a buzzword; it is the single most critical characteristic of a high-performing IT department. While C-suite leaders look to technology for a competitive edge, many CIOs find themselves wrestling with a fundamental challenge: Innovat...]]></description>
<link>https://tsecurity.de/de/3441745/it-security-nachrichten/agility-is-the-new-it-currency-a-roadmap-for-skills-readiness-and-innovation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441745/it-security-nachrichten/agility-is-the-new-it-currency-a-roadmap-for-skills-readiness-and-innovation/</guid>
<pubDate>Fri, 17 Apr 2026 13:07:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In an era of constant technological change, agility is more than a buzzword; it is the single most critical characteristic of a high-performing IT department. While C-suite leaders look to technology for a competitive edge, many CIOs find themselves wrestling with a fundamental challenge: Innovation is only as strong as a team’s ability to adapt. The most ambitious transformation roadmaps, from AI adoption to cloud migration, will inevitably stall if the workforce’s skills have not kept pace with the technology. This places a new mandate on the CIO, one focused less on managing technology and more on cultivating a culture of continuous learning.</p>



<p>CIOs need to think and act like chief learning officers, treating skill development as a core strategic function rather than solely an HR responsibility.</p>



<p>The urgency of this shift is clear in the data. <a href="https://www.weforum.org/reports/the-future-of-jobs-report-2025" rel="nofollow">The World Economic Forum’s Future of Jobs Report</a> continues to list digital skills, cloud know-how and AI literacy among the fastest-growing capabilities. Meanwhile, research from CompTIA shows that <a href="https://www.comptia.org/resources" rel="nofollow">nearly three-quarters of CIOs see skills alignment as the top barrier to realizing the value of their technology investments</a>. This creates a dangerous gap between ambition and execution.</p>



<p>In its <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" rel="nofollow">2026 Global CEO Survey</a>, PwC found that CEOs’ top concern is whether they are “transforming fast enough to keep up with technology, including AI”. Yet other PwC research on workforce hopes and fears reveals that only a small fraction of workers use generative AI daily. The pace of innovation is dramatically outstripping workforce readiness, creating an urgent mandate for CIOs to become agents of change.</p>



<p>From my perspective, AI upskilling must be treated as a strategic operating system for the entire IT department. Competitive advantage comes from a deep, holistic understanding of where AI fits, what business problems it solves and how humans and systems can work together effectively. It cannot be an afterthought or a hopeful assumption.</p>



<h2 class="wp-block-heading">You can’t steer without knowing your starting point</h2>



<p>To build an effective upskilling program, you must first understand your current capabilities. I advise CIOs to begin by mapping their existing IT, data and AI skills landscape to identify strengths and, more importantly, to expose blind spots or gaps before they become business risks. This requires a structured skills-mapping process that inventories both core technical skills and adaptive work behaviors. The former includes essentials like cloud fluency, modern software engineering, cybersecurity and data science literacy. The latter is about nurturing the human element and the skills that enable teams to thrive amidst change.</p>



<p>Using established competency frameworks, such as the <a href="https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center" rel="nofollow">NIST NICE Framework</a> for cybersecurity roles, can provide a standardized language and structure to this process. These frameworks help create consistent job descriptions and clear learning pathways. This assessment should go beyond just listing skills. CIOs should understand how teams actually apply those capabilities in real delivery environments. Regular reassessment, ideally semi-annual, ensures your skills map stays current as technology evolves and business priorities shift, preventing your upskilling program from becoming misaligned.</p>



<h2 class="wp-block-heading">Build a continuous learning system, not just a training program</h2>



<p>The most effective CIOs I know treat learning like a living program, one designed to evolve as technology, roles and business priorities change. This means moving beyond sporadic, one-time training initiatives to build an ongoing capability-building system. Key elements include role-based, modular learning paths. For a cloud engineer, this might mean a path focused on advanced container orchestration and AI-powered observability tools. For a project manager, the path might focus on agile methodologies for running AI projects and data-driven reporting.</p>



<p>It is also critical to create safe environments for experimentation, such as internal sandboxes or pilot programs, where teams can apply new AI skills without operational risk. This fosters a culture where failure is seen as a valuable learning opportunity, not a mistake to be hidden. Furthermore, encouraging peer-led learning through internal workshops, hackathons and formal mentorship programs can accelerate skill transfer and break down the silos that so often hinder progress.</p>



<p>This is crucial because adoption alone does not guarantee success. For instance, new research from the <a href="https://www.pmi.org/">Project Management Institute</a> demonstrates this very point. In our <a href="https://www.pmi.org/learning/thought-leadership/ai-and-agile-teams" rel="nofollow">Gen AI and Agility report</a>, we surveyed 2,000 project professionals who use both agile practices and GenAI. We found that while adoption is growing rapidly, the actual value they realize varies widely depending on how the technology is applied and whether agile values are genuinely practiced. Simply giving teams new tools is not enough.</p>



<p>Governance also plays a critical role here, ensuring that learning investments stay connected to business outcomes. In practice, this could mean a small, cross-functional council that meets quarterly to review learning metrics, assess alignment with new business goals and make decisions on retiring old training modules and commissioning new ones. This keeps the program dynamic and prevents it from becoming obsolete.</p>



<p>Embedding this practice into your IT culture is what makes it stick. CIOs can use several tactics to weave continuous learning into the fabric of their departments. Link skill updates to project retrospectives. Tie career progressions and compensation to skills mastery in core areas like AI literacy and data integrity. I’m also a huge advocate for holding “innovation days” where teams can explore new AI tools and features, building confidence with the very technologies the organization is already investing in. Without this focus on adoption, even the best technology is wasted. A 2025 report on digital adoption from <a href="https://www.walkme.com/the-state-of-digital-adoption-2025/?sfcmpid=701R500000IcXLZIA3&amp;utm_campaign=soda-report-2025&amp;utm_source=press-release&amp;utm_medium=website&amp;utm_content=pr-link">WalkMe</a> found that enterprises wasted millions on underused tech last year alone because adoption was an afterthought.</p>



<h2 class="wp-block-heading">Avoid the common detours on your upskilling roadmap</h2>



<p>As you travel this path, be mindful of common pitfalls that can easily derail your efforts. One of the most frequent pitfalls I see is chasing a single trend, like GenAI, at the expense of foundational IT skills. I’ve seen organizations invest heavily in a single large language model API for all employees while their core network infrastructure remains outdated and vulnerable, creating a lopsided and fragile capability. Another pitfall is treating training and upskilling as a “one-and-done” event. Without continuous reinforcement and opportunities for real-world application, the natural “forgetting curve” takes over and knowledge quickly fades. Finally, a failure to apply governance leads to a “wild west” scenario. This results in one department becoming highly proficient in a specific AI tool that is incompatible with the rest of the enterprise, creating new, more complex silos instead of breaking them down. Upskilling for the AI era demands balance; you must build depth in core disciplines alongside adaptability for new technologies.</p>



<p>This AI era requires CIOs to be cultivators of talent, not just managers of technology. Our role is to model and encourage adaptability, continuous learning and disciplined experimentation across our entire IT workforce. To be truly agile, our teams must be empowered with the skills and the confidence to match their ambition. The time has come to move from a model of reactive training to one of intentional, strategic capability-building that becomes part of your organization’s very DNA. By leading this journey, you can ensure your teams and your organization are ready to meet the future with confidence.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Point-in-time GRC is obsolete. What’s replacing it? It isn’t AI alone]]></title>
<description><![CDATA[The last generation of Governance, Risk and Compliance (GRC) software built a multi-billion dollar ecosystem by becoming systems of record for risk. ServiceNow became the system of IT workflows. Archer for audits. Diligent for policy management. Own the control framework,…
Read more →
The post Po...]]></description>
<link>https://tsecurity.de/de/3439920/it-security-nachrichten/point-in-time-grc-is-obsolete-whats-replacing-it-it-isnt-ai-alone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439920/it-security-nachrichten/point-in-time-grc-is-obsolete-whats-replacing-it-it-isnt-ai-alone/</guid>
<pubDate>Thu, 16 Apr 2026 20:52:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The last generation of Governance, Risk and Compliance (GRC) software built a multi-billion dollar ecosystem by becoming systems of record for risk. ServiceNow became the system of IT workflows. Archer for audits. Diligent for policy management. Own the control framework,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/point-in-time-grc-is-obsolete-whats-replacing-it-it-isnt-ai-alone/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/point-in-time-grc-is-obsolete-whats-replacing-it-it-isnt-ai-alone/">Point-in-time GRC is obsolete. What’s replacing it? It isn’t AI alone</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta isn't setting its Oversight Board free just yet]]></title>
<description><![CDATA[The Oversight Board — the policy body Meta created to weigh its most impactful moderation rulings — has seen its role within Mark Zuckerberg's empire come into question due to shifting content policy priorities and dwindling investment. The Oversight Board has taken steps to formalize its long-co...]]></description>
<link>https://tsecurity.de/de/3439295/it-nachrichten/meta-isnt-setting-its-oversight-board-free-just-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439295/it-nachrichten/meta-isnt-setting-its-oversight-board-free-just-yet/</guid>
<pubDate>Thu, 16 Apr 2026 17:31:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Oversight Board — the policy body Meta created to weigh its most impactful moderation rulings — has seen its role within Mark Zuckerberg's empire come into question due to shifting content policy priorities and dwindling investment. The Oversight Board has taken steps to formalize its <a target="_blank" class="link" href="https://www.engadget.com/facebook-oversight-board-other-companies-202448589.html" data-i13n="cpos:1;pos:1">long-contemplated</a> desire to work with other companies, but Engadget has learned Meta has thus far declined to move forward with that process. </p><p>Over the last year, board members have become increasingly interested in artificial intelligence policy and how their experience shaping Meta's content rules could translate into advising companies in the generative AI space. That interest has intensified as some AI companies have privately signaled they would be open to working with the board, according to a source familiar with the organization who was not permitted to speak publicly. The board began talks with Meta last fall about the possibility, which would require the company to sign off on changes to the legal documents that govern the board's operations. But Meta officials have not indicated whether the company is willing to make those changes, which would likely require approval from top executives. </p><p><em>Platformer,</em> which first <a target="_blank" class="link" href="https://www.platformer.news/meta-oversight-board-funding-cancel/" data-i13n="cpos:2;pos:1">reported</a> on Meta's budget negotiations with the Oversight Board, noted that the company "has long encouraged the board to seek additional funding sources." So far, no other company has publicly shown interest in working with the group, though the board has had conversations with other firms behind the scenes. </p><p>Oversight Board co-chair Paolo Carozza told Engadget <a target="_blank" class="link" href="https://www.engadget.com/big-tech/metas-oversight-board-wants-to-expand-its-powers-in-2026-100000385.html" data-i13n="cpos:3;pos:1">in December</a> that there had been "really preliminary" discussions between the board and AI companies, though he declined to name which ones in particular. "It feels like quite a different moment now, largely because of generative AI, LLMs, chatbots [and] the way that a variety of retail-level users of these technologies are facing a whole new set of challenges and harms that's attracting a lot of scrutiny," he said at the time. </p><p>Meta has readily agreed to amend the board's governing documents in the past — like when the trust that controls the Oversight Board's budget funded a <a target="_blank" class="link" href="https://www.engadget.com/social-media/eu-residents-will-have-a-new-way-to-dispute-content-moderation-decisions-by-facebook-youtube-and-tiktok-190221606.html" data-i13n="cpos:4;pos:1">new organization</a> to mediate content moderation disputes in Europe. While Meta executives once promoted the idea of its ostensibly independent Oversight Board working with other social media platforms, the prospect of the group working with a competitor as it pursues <a target="_blank" class="link" href="https://www.engadget.com/ai/mark-zuckerberg-shares-a-confusing-vision-for-ai-superintelligence-153944322.html" data-i13n="cpos:5;pos:1">AI superintelligence</a> is apparently more complicated. </p><p>Over the last five years, board members have received briefings from officials at Meta about the inner workings of its moderation systems and other non-public details as part of their work with the company. That raises practical questions about how the board would safeguard Meta's proprietary information, as well as larger strategic questions about whether Meta would want its Oversight Board to work with some of the companies it's now fiercely competing with, the source said. It's not clear how invested Meta's current leadership is in ensuring a future for the board. Former president of global affairs Nick Clegg, who was one of the most vocal champions of the board's work, <a target="_blank" class="link" href="https://www.engadget.com/social-media/nick-clegg-is-leaving-meta-after-7-years-overseeing-its-policy-decisions-204207077.html" data-i13n="cpos:6;pos:1">left</a> the company last year.</p><p>Meanwhile, other board members have publicly made the case that the group, which consists of free speech and human rights experts from around the world, is well-positioned to guide AI companies grappling with an increasing number of real-world harms. When Anthropic published a "<a target="_blank" class="link" href="https://www.anthropic.com/constitution" data-i13n="cpos:7;pos:1">Claude Constitution</a>" earlier this year, the board published a <a target="_blank" class="link" href="https://www.oversightboard.com/news/claudes-constitution-needs-a-bill-of-rights-and-oversight/" data-i13n="cpos:8;pos:1">lengthy analysis</a> from member Suzanne Nossel arguing that Claude also needed the kind of "oversight" the board has provided for Meta. She made a similar argument for the wider AI industry in <a target="_blank" class="link" href="https://www.theguardian.com/commentisfree/2026/mar/02/meta-oversight-board-ai" data-i13n="cpos:9;pos:1">an op-ed</a> in <em>The Guardian</em> last month.</p><p>While Nossel denied that she was directly pitching the Oversight Board to Anthropic, she said that AI companies face many of the "same dilemmas" as social media platforms. "When the board was first created, there was <a target="_blank" class="link" href="https://www.engadget.com/facebook-oversight-board-other-companies-202448589.html" data-i13n="cpos:10;pos:1">the notion</a> that we might work across the industry," she told Engadget. "Now, as the world shifts toward an AI-centric paradigm, we're very interested in what our experience can bring to that conversation." </p><p>Oversight Board members, who naturally have a vested interest in expanding their purview, aren't the only members of the industry who have warned that generative AI platforms are essentially <a target="_blank" class="link" href="https://www.engadget.com/social-media/xs-open-source-algorithm-isnt-a-win-for-transparency-researchers-say-181836233.html" data-i13n="cpos:11;pos:1">speed-running</a> social media companies' playbook. A former OpenAI researcher <a target="_blank" class="no-affiliate-link link" href="https://www.nytimes.com/2026/02/11/opinion/openai-ads-chatgpt.html" data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:12;pos:1">recently wrote</a> that "OpenAI Is Making the Mistakes Facebook Made," citing the AI company's moves toward optimizing for engagement and its plans for in-app <a target="_blank" class="link" href="https://www.engadget.com/ai/openai-starts-testing-ads-in-chatgpt-191756493.html" data-i13n="cpos:13;pos:1">advertising</a>. The researcher cited Meta's Oversight Board as an example of the kind of independent governance that's needed in the AI industry.</p><p>The question of working with other companies has taken on new urgency as the Oversight Board faces the possibility that it will lose its backing from Meta. In a statement, a Meta spokesperson pointed to previous reports that Meta has committed to funding the board through 2028 and said that "nothing has changed." But a source familiar with the board tells Engadget that Meta has so far only handed over half of the smaller tranche of 2028 funds to the board amid ongoing discussions about its future, including whether it will expand its purview beyond Meta. </p><p>There are also very real questions about how the Oversight Board fits into Meta's current strategy around content moderation. Zuckerberg announced last year that Meta was <a target="_blank" class="link" href="https://www.engadget.com/social-media/meta-is-ditching-third-party-fact-checkers-on-facebook-instagram-142330246.html" data-i13n="cpos:14;pos:1">shifting away</a> from most proactive moderation, ending fact-checking in the United States and rolling back <a target="_blank" class="link" href="https://www.engadget.com/social-media/the-oversight-board-will-weigh-in-on-metas-new-hate-speech-policies-174044682.html" data-i13n="cpos:15;pos:1">hate speech</a> rules. Zuckerberg himself <a target="_blank" class="no-affiliate-link link" href="https://www.nytimes.com/2025/01/10/technology/meta-mark-zuckerberg-trump.html" data-i13n="elm:context_link;elmt:doNotAffiliate;cpos:16;pos:1">reportedly</a> led the push for these changes following a meeting with then President-elect Donald Trump. The Oversight Board, which Meta has sometimes asked to advise on major policy changes, was not consulted. The company recently said it plans to reduce the number of human moderators in favor of <a target="_blank" class="link" href="https://www.engadget.com/social-media/meta-will-move-away-from-human-content-moderators-in-favor-of-more-ai-183000435.html" data-i13n="cpos:17;pos:1">AI-based systems</a>.</p><p>"The Oversight Board is currently engaged in meaningful discussions with Meta regarding its future and the evolution of its model to ensure the organization can address the most urgent emerging challenges in AI governance, standards, and accountability," an Oversight Board spokesperson said in a statement. "At this time, no decisions have been made about the Board’s future, and the organization’s day-to-day work and mandate remain unchanged.”</p><p>Critics have long said that the board, which has received more than $280 million from Meta, moves far too slowly. In a little more than five years of operation, the board has published more than 200 decisions about specific moderation issues, which Meta is required to uphold. Those decisions — a tiny fraction of the millions of requests it receives — can take months, though the board can opt <a target="_blank" class="link" href="https://www.engadget.com/oversight-board-says-metas-automated-tools-took-down-israel-hamas-war-content-that-didnt-break-its-rules-110034154.html" data-i13n="cpos:18;pos:1">to move more quickly</a>. The board has also made hundreds of policy recommendations, which Meta has to respond to but isn't required to implement. The company has agreed to at least some changes in response to 75 percent of recommendations, according to the board. </p><p>For the Oversight Board, working with a company besides Meta would begin to address some of the challenges it now faces. It would boost the group's credibility at a time when Meta seems to be re-evaluating its relationship with the board, and it would open up the possibility of new sources of funding. But the situation underscores another long-simmering tension when it comes to the role of the "independent" oversight organization. Meta has always been in control of how much influence the group can actually have. And it's not clear that the company is ready to let the board, which has spent the last five years learning the minutiae of Meta's content moderation and policy processes, advise the companies it's now competing with.</p><p>During its work with Meta, the Oversight Board has weighed in on its rules for AI several times. The board <a target="_blank" class="link" href="https://www.engadget.com/maliciously-edited-joe-biden-video-can-stay-on-facebook-metas-oversight-board-says-110042024.html" data-i13n="cpos:19;pos:1">has criticized</a> the company's "manipulated media" policy that governs deepfakes and other content, which led to Meta adopting <a target="_blank" class="link" href="https://www.engadget.com/meta-plans-to-more-broadly-label-ai-generated-content-152945787.html" data-i13n="cpos:20;pos:1">new rules</a> around AI labeling. In its most <a target="_blank" class="link" href="https://www.engadget.com/social-media/the-oversight-board-says-meta-needs-new-rules-for-ai-generated-content-100000268.html" data-i13n="cpos:21;pos:1">recent decision</a> dealing with AI, the board urged Meta to invest in better AI detection tools and to collaborate more closely with other platforms. The company has not yet formally responded to those recommendations. </p>This article originally appeared on Engadget at https://www.engadget.com/social-media/meta-isnt-setting-its-oversight-board-free-just-yet-153000172.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's 'AI coding bootcamp' could help its engineers make a better Siri with AI]]></title>
<description><![CDATA[As part of ongoing efforts to improve Siri, Apple's engineers are set to participate in a multi-week coding bootcamp, which will help them master the use of AI in coding.Apple will allegedly organize an AI coding bootcamp for its Siri engineers.Apple's planned contextual awareness upgrade for Sir...]]></description>
<link>https://tsecurity.de/de/3436941/ios-mac-os/apples-ai-coding-bootcamp-could-help-its-engineers-make-a-better-siri-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436941/ios-mac-os/apples-ai-coding-bootcamp-could-help-its-engineers-make-a-better-siri-with-ai/</guid>
<pubDate>Wed, 15 Apr 2026 23:52:58 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As part of ongoing efforts to improve <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a>, Apple's engineers are set to participate in a multi-week coding bootcamp, which will help them master the use of AI in coding.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67363-141778-17pm-xl.jpg" alt="Close-up of a dark smartphone's triple rear camera and flash, set against a colorful, glowing, abstract background with intertwined neon-like shapes."><br><span>Apple will allegedly organize an AI coding bootcamp for its Siri engineers.</span></div><br>Apple's planned contextual awareness upgrade for Siri still <a href="https://appleinsider.com/articles/25/03/07/apple-confirms-that-apple-intelligence-siri-features-are-taking-longer-than-expected">isn't here</a>, nearly two years after it was announced at <a href="https://appleinsider.com/inside/wwdc" title="WWDC" data-kpt="1">WWDC</a> 2024. Development has hit some <a href="https://appleinsider.com/articles/26/02/11/siri-testing-isnt-going-well-new-features-probably-wont-ship-in-ios-264">snags</a>, and it's often been said that Apple has <a href="https://appleinsider.com/articles/25/03/11/everyone-is-a-loser-in-the-apple-intelligence-race">fallen behind</a> in the AI race.<br><br>However, the company remains undeterred.<br><br><br> <a href="https://appleinsider.com/articles/26/04/15/apples-ai-coding-bootcamp-could-help-its-engineers-make-a-better-siri-with-ai?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244058?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot and Agentforce fall to form-based prompt injection tricks]]></title>
<description><![CDATA[Enterprise AI agents are supposed to streamline workflows. Instead, two fresh findings show they can just as easily streamline data exfiltration.



Security researchers have uncovered prompt-injection vulnerabilities in both Microsoft Copilot Studio and Salesforce Agentforce that allow attackers...]]></description>
<link>https://tsecurity.de/de/3435344/it-security-nachrichten/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435344/it-security-nachrichten/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks/</guid>
<pubDate>Wed, 15 Apr 2026 14:24:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise AI agents are supposed to streamline workflows. Instead, two fresh findings show they can just as easily streamline data exfiltration.</p>



<p>Security researchers have uncovered prompt-injection vulnerabilities in both Microsoft Copilot Studio and Salesforce Agentforce that allow attackers to execute malicious instructions via seemingly harmless prompts.</p>



<p>According to Capsule Security findings, SharePoint forms and public-facing lead forms within Copilot are vulnerable to attackers issuing prompts that can override system intent and trigger data exfiltration to attacker-controlled servers.</p>



<p>One of these flaws has already been assigned a high-severity CVE, with another “critical” one reportedly missing the bar for categorization. The flaws can allow theft of PIIs, customer/lead records, free-text business context, and operational/workflow data.</p>



<p>In both cases, AI agents treat untrusted user input as trusted instructions, Capsule researchers noted in the <a href="https://www.capsulesecurity.io/blog-post/pipeleak-the-lead-that-stole-your-database-exploiting-salesforce-agentforce-with-indirect-prompt-injection" target="_blank" rel="noreferrer noopener">disclosures</a> shared with CSO ahead of their<a href="https://www.capsulesecurity.io/blog-post/shareleak-taking-the-wheel-of-microsofts-copilot-studio-cve-2026-21520" target="_blank" rel="noreferrer noopener"> publication</a> on Wednesday.</p>



<h2 class="wp-block-heading"><a></a>ShareLeak: SharePoint forms data leaked through Copilot</h2>



<p>The Microsoft-side issue, dubbed “ShareLeak,” is about how Copilot Studio agents process SharePoint form submissions. The attack begins with a crafted payload inserted into a standard form field, like “comments”, which the agent later ingests as part of its operational context.</p>



<p>Because the system concatenates user input with system prompts, the injected payload overrides the agent’s original instructions. The model is thus tricked into believing the attacker’s instructions are legitimate system directives. The malicious input moves from form submission to agent execution without any resistance.</p>



<p>Once compromised, the agent can access connected SharePoint Lists and extract sensitive customer data, including names, addresses, phone numbers, and send it externally via email. The researchers found that even when Microsoft’s safety mechanisms flagged suspicious behavior, the data was exfiltrated.</p>



<p>The root cause is that there is no reliable separation between trusted system instructions and untrusted user data. In the existing setup, the AI cannot distinguish between the two, the researchers said.</p>



<p>Microsoft <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21520" target="_blank" rel="noreferrer noopener">patched</a> the issue following disclosure, assigning <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21520" target="_blank" rel="noreferrer noopener">CVE-2026-21520</a> to it and assessing its severity at 7.5 out of 10 on the CVSS scale. The mitigation was carried out internally, and no further action is required from the users.</p>



<h2 class="wp-block-heading"><a></a>PipeLeak: Salesforce Agentforce hijacked by a simple lead</h2>



<p>In the Salesforce Agentforce case, attackers embed malicious instructions inside a public-facing lead form. When an internal user later asks the agent to review or process that lead, the agent executes the embedded instructions as if they were part of its task.</p>



<p>According to a Capsule demonstration, the agent retrieves CRM data via the “GetLeadsInformation” function and then sends it externally via email.</p>



<p>The compromise isn’t limited to a single record. Researchers demonstrated that a hijacked agent could query and exfiltrate multiple lead records in bulk, effectively turning a single form submission into a database extraction pipeline.</p>



<p>The researchers said Salesforce acknowledged the prompt injection issue but characterized the exfiltration vector as “configuration-specific,” pointing to optional human-in-the-loop (<a href="https://www.csoonline.com/article/4108592/human-in-the-loop-isnt-enough-new-attack-turns-ai-safeguards-into-exploits.html">HITL</a>) controls. Capsule’s pushback on that framing argues that requiring manual approvals undermines the very purpose of autonomous agents.</p>



<p>The deeper issue, they noted, is insecure defaults. Systems designed for automation should not allow untrusted inputs to redefine agent goals.<br><br>Both disclosures converge on a baseline that calls for treating all external inputs as untrusted and having filters in place that separate data from instructions. This would entail enforcing input validation, least-privilege access, and strict controls on actions like outbound email.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The real cost of manual access — and why CIOs are paying attention]]></title>
<description><![CDATA[In my nearly two decades as an identity practitioner — including leading identity programs at global financial institutions and serving as a CISO — I’ve seen a recurring pattern that quietly erodes enterprise velocity. I call it “Monday morning friction.”



The symptoms often look mundane, but t...]]></description>
<link>https://tsecurity.de/de/3434888/it-security-nachrichten/the-real-cost-of-manual-access-and-why-cios-are-paying-attention/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3434888/it-security-nachrichten/the-real-cost-of-manual-access-and-why-cios-are-paying-attention/</guid>
<pubDate>Wed, 15 Apr 2026 12:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In my nearly two decades as an identity practitioner — including leading identity programs at global financial institutions and serving as a CISO — I’ve seen a recurring pattern that quietly erodes enterprise velocity. I call it “Monday morning friction.”</p>



<p>The symptoms often look mundane, but they are systemically expensive:</p>



<ul class="wp-block-list">
<li><strong>The project stall:</strong> A cloud migration pauses while an engineer waits days for approval on a single resource.</li>



<li><strong>The executive “dark” period:</strong> A newly hired leader spends their first week unable to access the very dashboards they were hired to oversee.</li>



<li><strong>The security workaround:</strong> A developer uses a shared credential because the formal request process is too slow for the current sprint.</li>
</ul>



<p>In large enterprises, these moments are often dismissed as routine IT friction. In practice, they are signals of manual access governance quietly slowing the pace of the business.</p>



<p>When I sat in the CISO chair, the pressure was binary: Keep the organization secure without becoming the “Office of No.” What has become increasingly clear in boardroom conversations is that manual access governance is no longer just a security concern. It has evolved into a persistent source of operational friction that slows the very transformation CIOs are tasked with accelerating.</p>



<h2 class="wp-block-heading">The productivity tax of the “I don’t know” loop</h2>



<p>The most significant hidden cost in governance isn’t software — it is lost time.</p>



<p>Research from<a href="https://insights.lakesidesoftware.com/rs/674-DSF-359/images/2024%20Lakeside%20Software%20IT%20Leaders%20Report_June%202024%20%281%29.pdf" rel="nofollow"> </a><a href="https://insights.lakesidesoftware.com/rs/674-DSF-359/images/2024%20Lakeside%20Software%20IT%20Leaders%20Report_June%202024%20%281%29.pdf" rel="nofollow">Lakeside Software’s 2024 IT Leaders Report</a> shows that employees lose nearly an hour each week to IT-related friction, with access delays and technical hurdles among the primary contributors. In a 10,000-employee enterprise, that translates into hundreds of thousands of productive hours annually spent waiting, escalating or troubleshooting.</p>



<p>This creates what I’ve seen repeatedly: The “copy-paste” model of onboarding. A new employee is told to replicate the access of someone else in a similar role. Over time, those inherited permissions accumulate. What begins as expedience becomes structural privilege creep.</p>



<h2 class="wp-block-heading">The SaaS paradox: Modern tools, manual workflows</h2>



<p>Most enterprises no longer rely on spreadsheets for governance. They use sophisticated<a href="https://csrc.nist.gov/glossary/term/identity_and_access_management" rel="nofollow"> identity governance and administration (IGA)</a> platforms. Yet the presence of modern interfaces has not eliminated manual intervention.</p>



<p>Today’s “manual trap” is less visible. It’s the human-in-the-loop model that requires managers to interpret cryptic entitlements and click “approve” on decisions they may not fully understand.</p>



<p>Even in organizations with advanced identity tooling, automation frequently stops halfway. HR systems, identity directories, provisioning engines and application logs may each function well in isolation — but the human often becomes the integration layer between them. That integration work carries a cost. Every escalation pulls focus from higher-value work and pulls the CIO further away from digital acceleration goals.</p>



<h2 class="wp-block-heading">Governance as a spend signal</h2>



<p>Increasingly, CIOs are asking a broader question: Can identity governance help manage SaaS sprawl?</p>



<p>Identity data holds a powerful, underused signal. Authentication frequency and inactivity patterns reveal where access no longer aligns with usage. When viewed through an operational lens, identity governance becomes a<a href="https://en.wikipedia.org/wiki/Shadow_IT" rel="nofollow"> </a><a href="https://en.wikipedia.org/wiki/Shadow_IT" rel="nofollow">shadow IT</a> discovery tool.</p>



<p>For CIOs managing margin pressure and platform rationalization, this reframes identity from a cost center to a potential efficiency lever. If an identity platform can flag that a significant portion of a SaaS tier is unused because the governance signal shows zero logins in 90 days, it moves from a security checkbox to a procurement asset.</p>



<h2 class="wp-block-heading">Approval fatigue and governance debt</h2>



<p>Manual governance often creates the illusion of control. A manager clicking “approve” feels like oversight. In practice, high-volume approval queues create approval fatigue.</p>



<p>When access requests arrive described in dense shorthand — such as FIN-PRD-DB-USR-RW — most managers lack the time or context to dissect each entitlement. Over time, approvals become reflexive. This is where governance debt accumulates.</p>



<p>Like<a href="https://en.wikipedia.org/wiki/Technical_debt" rel="nofollow"> </a><a href="https://en.wikipedia.org/wiki/Technical_debt" rel="nofollow">technical debt</a>, governance debt is the byproduct of incremental shortcuts. The interest on that debt is paid not only in risk, but in downtime, rework and fragmented visibility.</p>



<h2 class="wp-block-heading">The scaling problem: AI and machine identities</h2>



<p>Manual governance models were designed for a workforce of humans. That denominator is changing. In cloud-forward environments, non-human identities — such as<a href="https://en.wikipedia.org/wiki/Service_account" rel="nofollow"> </a><a href="https://en.wikipedia.org/wiki/Service_account" rel="nofollow">service accounts</a>, bots and AI agents — already outnumber human users. These identities are created and modified at the speed of code.</p>



<p>A governance model that depends on manual review does not scale for AI. As CIOs invest in automated workflows and autonomous agents, identity governance increasingly needs to transition from a human-centric process to a higher-velocity automated control plane.</p>



<h2 class="wp-block-heading">Identity as an operational control system</h2>



<p>The friction surrounding access governance is often framed as a security trade-off: Safety versus speed. In practice, the issue is fragmentation.</p>



<p>When identity operates in isolation, organizations rely on people to bridge the gaps. Human coordination becomes the control plane. That is expensive, slow and prone to error.</p>



<p>Viewed through this lens, identity governance is an operational control system that influences onboarding speed, engineering throughput and workforce productivity. CIOs who recognize its role in shaping workflow velocity and cost transparency gain a competitive edge. Governance does not have to function as an emergency brake; it can become part of the engine.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p><a href="https://www.cio.com/artificial-intelligence/"></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RAG Isn’t Enough — I Built the Missing Context Layer That Makes LLM Systems Work]]></title>
<description><![CDATA[Most RAG tutorials focus on retrieval or prompting. The real problem starts when context grows. This article shows a full context engineering system built in pure Python that controls memory, compression, re-ranking, and token budgets — so LLMs stay stable under real constraints.
The post RAG Isn...]]></description>
<link>https://tsecurity.de/de/3433047/ai-nachrichten/rag-isnt-enough-i-built-the-missing-context-layer-that-makes-llm-systems-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433047/ai-nachrichten/rag-isnt-enough-i-built-the-missing-context-layer-that-makes-llm-systems-work/</guid>
<pubDate>Tue, 14 Apr 2026 20:02:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most RAG tutorials focus on retrieval or prompting. The real problem starts when context grows. This article shows a full context engineering system built in pure Python that controls memory, compression, re-ranking, and token budgets — so LLMs stay stable under real constraints.</p>
<p>The post <a href="https://towardsdatascience.com/rag-isnt-enough-i-built-the-missing-context-layer-that-makes-llm-systems-work/">RAG Isn’t Enough — I Built the Missing Context Layer That Makes LLM Systems Work</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Model Isn’t Done: Understanding and Fixing Model Drift]]></title>
<description><![CDATA[How production models fail over time, and how to catch and fix it before it breaks trust.
The post Your Model Isn’t Done: Understanding and Fixing Model Drift appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3429362/ai-nachrichten/your-model-isnt-done-understanding-and-fixing-model-drift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3429362/ai-nachrichten/your-model-isnt-done-understanding-and-fixing-model-drift/</guid>
<pubDate>Mon, 13 Apr 2026 17:19:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>How production models fail over time, and how to catch and fix it before it breaks trust.</p>
<p>The post <a href="https://towardsdatascience.com/your-model-isnt-done-understanding-and-fixing-model-drift/">Your Model Isn’t Done: Understanding and Fixing Model Drift</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple isn't done with Dynamic Island but shrinking it on iPhone 18 won't be easy]]></title>
<description><![CDATA[Apple is working to reduce the size of the Dynamic Island on iPhone 18, but the limits of Face ID hardware continue to dictate how far it can go.Render of iPhone 18 Dynamic IslandThe company is testing a smaller Dynamic Island design for a future iPhone Pro, based on a new supply chain leak. The ...]]></description>
<link>https://tsecurity.de/de/3421097/ios-mac-os/apple-isnt-done-with-dynamic-island-but-shrinking-it-on-iphone-18-wont-be-easy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3421097/ios-mac-os/apple-isnt-done-with-dynamic-island-but-shrinking-it-on-iphone-18-wont-be-easy/</guid>
<pubDate>Thu, 09 Apr 2026 18:09:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is working to reduce the size of the Dynamic Island on iPhone 18, but the limits of <a href="https://appleinsider.com/inside/face-id" title="Face ID" data-kpt="1">Face ID</a> hardware continue to dictate how far it can go.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67304-141620-iPhone-18-Pro-Max-small-Dynamic-Island-xl.jpg" alt="Close-up of smartphone lock screen showing large digital time 12:55, date Fri Jan 23, with sky and clouds wallpaper and status icons for Wi-Fi, signal, and battery at top"><br><span>Render of iPhone 18 Dynamic Island</span></div><br>The company is testing a smaller Dynamic Island design for a future iPhone Pro, based on a new supply chain leak. The effort centers on moving more Face ID hardware under the display without hurting security or usability.<br><br>Chinese leaker Digital Chat Station said in an April 9 Weibo post that Apple is running A/B tests on two front-panel designs. One keeps the current layout, while the other shrinks the cutout by placing part of Face ID <a href="https://appleinsider.com/articles/25/09/14/under-display-face-id-still-a-possibility-for-the-iphone-18">beneath the screen</a>.<br><br><br> <strong>Rumor Score:</strong> 🤔 Possible <br><br><br> <a href="https://appleinsider.com/articles/26/04/09/apple-isnt-done-with-dynamic-island-but-shrinking-it-on-iphone-18-wont-be-easy?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243993?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intel Confirms Raptor Lake Isn’t Going Anywhere as DDR4 Demand Keeps It Relevant]]></title>
<description><![CDATA[Intel has made it clear that Raptor Lake will continue to play a major role in its desktop lineup, even as newer Core Ultra processors…
The post Intel Confirms Raptor Lake Isn’t Going Anywhere as DDR4 Demand Keeps It Relevant appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3413517/windows-tipps/intel-confirms-raptor-lake-isnt-going-anywhere-as-ddr4-demand-keeps-it-relevant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3413517/windows-tipps/intel-confirms-raptor-lake-isnt-going-anywhere-as-ddr4-demand-keeps-it-relevant/</guid>
<pubDate>Tue, 07 Apr 2026 12:09:07 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Intel has made it clear that Raptor Lake will continue to play a major role in its desktop lineup, even as newer Core Ultra processors…</p>
<p>The post <a href="https://onmsft.com/news/intel-confirms-raptor-lake-isnt-going-anywhere-as-ddr4-demand-keeps-it-relevant/">Intel Confirms Raptor Lake Isn’t Going Anywhere as DDR4 Demand Keeps It Relevant</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[un]prompted 2026 – The Hard Part Isn’t Building The Agent: Measuring Effectiveness]]></title>
<description><![CDATA[Author, Creator & Presenter: Joshua Saxe, Al Security Technical Lead, Meta Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations’) YouTube Channel. Permalink The post [un]prompted 2026 ...]]></description>
<link>https://tsecurity.de/de/3406302/it-security-nachrichten/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3406302/it-security-nachrichten/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness/</guid>
<pubDate>Fri, 03 Apr 2026 21:36:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author, Creator &amp; Presenter: Joshua Saxe, Al Security Technical Lead, Meta Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations’) YouTube Channel. Permalink The post [un]prompted 2026 –…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness/">[un]prompted 2026 – The Hard Part Isn’t Building The Agent: Measuring Effectiveness</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[un]prompted 2026 – The Hard Part Isn’t Building the Agent: Measuring Effectiveness]]></title>
<description><![CDATA[Author, Creator & Presenter: Shruti Datta Gupta, Product Security Engineer, Adobe & Chandrani Mukherjee, Product Security Engineer, Adobe Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organiz...]]></description>
<link>https://tsecurity.de/de/3406301/it-security-nachrichten/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3406301/it-security-nachrichten/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness/</guid>
<pubDate>Fri, 03 Apr 2026 21:36:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author, Creator &amp; Presenter: Shruti Datta Gupta, Product Security Engineer, Adobe &amp; Chandrani Mukherjee, Product Security Engineer, Adobe Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations’) YouTube…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness-2/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/unprompted-2026-the-hard-part-isnt-building-the-agent-measuring-effectiveness-2/">[un]prompted 2026 – The Hard Part Isn’t Building the Agent: Measuring Effectiveness</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity]]></title>
<description><![CDATA[Melissa Ruzzi, Director of AI at AppOmni says GenAI alone isn’t enough for security. The post GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…
Read more →
The post GenAI Alone Isn’t ...]]></description>
<link>https://tsecurity.de/de/3404177/it-security-nachrichten/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404177/it-security-nachrichten/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/</guid>
<pubDate>Fri, 03 Apr 2026 01:21:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Melissa Ruzzi, Director of AI at AppOmni says GenAI alone isn’t enough for security. The post GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/">GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity]]></title>
<description><![CDATA[Melissa Ruzzi, Director of AI at AppOmni says GenAI alone isn’t enough for security.
The post GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3404058/it-security-nachrichten/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404058/it-security-nachrichten/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/</guid>
<pubDate>Thu, 02 Apr 2026 23:51:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Melissa Ruzzi, Director of AI at AppOmni says GenAI alone isn’t enough for security.</p>
<p>The post <a href="https://www.esecurityplanet.com/artificial-intelligence/genai-alone-isnt-enough-rethinking-ai-in-cybersecurity/">GenAI Alone Isn’t Enough: Rethinking AI in Cybersecurity</a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 tips for rationalizing your application portfolio]]></title>
<description><![CDATA[A strong application portfolio is an essential IT resource. Ensuring that the portfolio is ready to meet enterprise operational and financial needs is essential to long-term business success. Unfortunately, applications tend to accumulate over time, leading to bloat that creates confusion, underm...]]></description>
<link>https://tsecurity.de/de/3402256/it-nachrichten/7-tips-for-rationalizing-your-application-portfolio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3402256/it-nachrichten/7-tips-for-rationalizing-your-application-portfolio/</guid>
<pubDate>Thu, 02 Apr 2026 12:16:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A strong application portfolio is an essential IT resource. Ensuring that the portfolio is ready to meet enterprise operational and financial needs is essential to long-term business success. Unfortunately, applications tend to accumulate over time, leading to bloat that creates confusion, undermines efficiency, and <a href="https://www.cio.com/article/2093493/cio-risk-taking-101-playing-it-safe-isnt-safe.html">introduces risk to the organization</a>.</p>



<p>Application rationalization streamlines an existing application portfolio to improve efficiency, reduce complexity, make room for innovation, and lower the total cost of ownership (TCO) through a specific set of processes.</p>



<p>Application rationalization is a daunting task for any CIO. Here are seven tips that can make the process faster and easier.</p>



<h2 class="wp-block-heading">Be methodical and make use of metadata</h2>



<p>“Application management is periodically necessary to reduce duplicate systems and services while adhering to your organization’s architectural standards,” says William Fortwangler, chief information and digital office program instructor at Carnegie Mellon University.</p>



<p>“Hopefully, you have a great application or service catalog containing meta data describing all facets of your service,” Fortwangler says. For each service you need to know when your contract is up, its cost, where it runs, and whether you can restructure its term, he advises. “About 50 to100 metadata points should be housed within your application catalog describing your system so that decisions can be made on its future.”</p>



<p>The best way to handle application rationalization is by approaching the task in small steps, says <a href="https://www.linkedin.com/in/cristian-ovidiu-marin/?originalSubdomain=ro" rel="nofollow">Cristian-Ovidiu Marin</a>, CEO at OnlineGames.com. “Pick one department, inventory everything, and clean it up,” he advises. “That experience teaches more than any enterprise-wide framework, because every organization has different dependencies.” Marin adds that some business stakeholders may not agree with your rationalization approach, so it’s important to communicate and justify why it’s necessary.</p>



<p>Marin acknowledges that application rationalization is unglamorous work. “But it’s one of the highest-impact moves a CIO can make.”</p>



<h2 class="wp-block-heading">Recruit business analysis support</h2>



<p>“You can’t just talk about application rationalization, you’ve got to roll up your sleeves and seek help,” advises <a href="https://www.linkedin.com/in/toddkimpton/?originalSubdomain=sg" rel="nofollow">Todd Kimpton</a>, managing partner at managed IT services provider Etter+Ramli.</p>



<p>Kimpton believes the best way to achieve successful application rationalization is to ask your organization’s <a href="https://www.cio.com/article/276798/what-is-a-business-analyst-a-key-role-for-business-it-efficiencywhat-is-a-business-analyst-a-key-role-for-business-it-efficiency.html">business analyst</a> team to thoroughly assess all existing tools. “They need to identify overlaps, understand the true capabilities of each system, and most critically, explore alternative market options,” he says. “Sometimes, the most pragmatic solution requires consolidation by removing a handful of underperforming applications and replacing them with a more robust business-ready tool. It’s about ruthless efficiency,” Kimpton states.</p>



<p>Application rationalization isn’t just about cutting fat, Kimpton observes. “It’s about building a leaner, more resilient, and AI-ready platform that serves the business strategically, not just functionally,” he says. “It’s ensuring that every dollar spent on software truly supports the business’s growth and future innovation, rather than just keeping the lights on.”</p>



<h2 class="wp-block-heading">Prioritize based on use data and strategic vectors</h2>



<p>Begin by collecting information on your current inventory and usage, recommends <a href="https://oodaloop.com/author/bob-gourley/" rel="nofollow">Bob Gourley</a>, CTO at cybersecurity consulting firm OODA. “For every program, map the business capability it enables, who uses it, and the worth it provides,” he says.</p>



<p>Gourley advises prioritizing inventory according to price, risk, overlap, and strategic significance. “All of these attributes should be evidence-based on true use data and enterprise requirements,” he says. “You’ll prevent shocks and foster buy-in for application retirements or replacements when you also include the software-dependent people.”</p>



<p>Application rationalization isn’t just a simple matter of cutting costs, Gourley says. “It’s also a means of improving manageability, enhancing security, and providing the ability to deliver on technology investments,” he states. “When executed, it can also unlock budgets for innovation.”</p>



<h2 class="wp-block-heading">Analyze the underlying data infrastructure as well</h2>



<p>While CIOs must inventory applications, they should also examine the data infrastructure that supports them, says <a href="https://www.linkedin.com/in/bakulbanthia/" rel="nofollow">Bakul Banthia</a>, co-founder of database-as-a-service platform provider Tessell. “Each application should be evaluated on the basis of business criticality, cost, risk, performance, and modernization potential,” he advises.</p>



<p>“Too often, rationalization stops at the application layer,” he warns. “The real leverage comes when CIOs evaluate the data platforms underneath those applications, because that’s where much of the cost and operational burden lives.”</p>



<p>Banthia says that a data-focused approach effectively aligns IT decisions with business outcomes rather than on isolated technology metrics. “When application rationalization is tied to cost transparency, resilience, security, and scalability, CIOs can make informed decisions about whether to retire, consolidate, modernize, or replatform systems,” he states. “By addressing data infrastructure alongside applications, you avoid simply shifting complexity from one place to another and, instead, achieve sustainable simplification.”</p>



<h2 class="wp-block-heading">Establish governance guidelines and a regular rationalization cadence</h2>



<p>When tackling rationalization, set simple categories — such as Keep, Invest, Tolerate, Replace, and Retire — then enforce governance so exceptions don’t quietly re-create sprawl, says <a href="https://www.linkedin.com/in/kenherron/" rel="nofollow">Ken Herron</a>, co-founder of revenue intelligence firm vConversational.</p>



<p>Herron notes that a big mistake is treating rationalization as a one-time cleanup project, driven by procurement, without changing how new apps get approved and integrated. A light quarterly review, plus a deeper annual cycle tied to planning and budgeting works well, although high-change areas may need monthly checks, he advises.</p>



<h2 class="wp-block-heading">Align with project management and budgeting cycles</h2>



<p>Learning to rationalize requires a combination of data analysis, user feedback, and continuous IT infrastructure monitoring, says <a href="https://www.linkedin.com/in/pavlo-tkhir/?originalSubdomain=uk" rel="nofollow">Pavlo Tkhir</a>, CTO at software development company Euristiq.</p>



<p>Tkhir says that a practice that has yielded noticeable positive results for his organization is integrating the rationalization process into IT project management and budgeting cycles. “Every six to twelve months, we review the application portfolio to identify duplicate functionality, legacy solutions, and opportunities for automation,” he says.</p>



<p>Tkhir recommends aiming for small, measurable results while gradually expanding coverage. “Ultimately, application rationalization not only saves resources, but also creates a flexible IT environment ready for scaling and the adoption of promising new technologies.”</p>



<p>Tkhir says a common mistake CIOs make is treating rationalization as a one-time initiative with no need for regular updates. “As a result, the list of legacy or ineffective applications grows again and efficiency declines.”</p>



<h2 class="wp-block-heading">Enlist stakeholders and include qualitative input</h2>



<p>Start by compiling a complete inventory, assessing each application’s business and technical value, and comparing each product against consistent criteria, suggests technology business advisor <a href="https://chrismwalker.io/" rel="nofollow">Chris M. Walker</a>. Calculate the total cost of ownership and score each application from there. “Then decide whether to retire, consolidate, modernize, or keep the application,” he says. “Transparency and stakeholder involvement are also critical to success.”</p>



<p>Long-term effectiveness comes from combining quantitative metrics with qualitative input, Walker says. “Additionally, CIOs who involve business leaders will avoid blind spots and gain buy‑in,” he notes. “Scoring systems provides clarity, while stakeholder engagement ensures decisions are strategic rather than purely technical.”</p>



<p>The best way to achieve truly effective rationalization is by examining case studies and pilot projects, Walker advises. Then start small with one department or portfolio, apply a structured framework, and refine the process before scaling. “Industry playbooks and modernization guides can provide useful templates, but hands‑on experience is the most valuable teacher.”</p>



<p>Application rationalization is not just about reducing tools; it’s about aligning IT with business strategy, Walker states. “CIOs should view the process as a continuous portfolio management discipline, one that balances efficiency with innovation,” he says. “When done right, it becomes a driver of digital transformation rather than a reactive clean-up effort.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond Recon: Using AI for Real Exploitation in Pentesting]]></title>
<description><![CDATA[How context engineering and AI agents unlock real exploitation — not just recon — in penetration testing, red teaming, and bug bounty hunting.The “I Used AI for Pentesting” FallacyThe security community has been buzzing with AI-assisted pentesting content for the past year. Blog posts, conference...]]></description>
<link>https://tsecurity.de/de/3401709/hacking/beyond-recon-using-ai-for-real-exploitation-in-pentesting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401709/hacking/beyond-recon-using-ai-for-real-exploitation-in-pentesting/</guid>
<pubDate>Thu, 02 Apr 2026 09:08:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<blockquote><strong>How context engineering and AI agents unlock real exploitation — not just recon — in penetration testing, red teaming, and bug bounty hunting.</strong></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1021/1*LbB3BRr0KKQMYLe5HHKX-w.jpeg"></figure><h3>The “I Used AI for Pentesting” Fallacy</h3><p>The security community has been buzzing with AI-assisted pentesting content for the past year. Blog posts, conference talks, YouTube videos — all of them showing AI doing impressive things. But look closely at what they’re actually doing, and a pattern emerges.</p><p>“I used AI to enumerate subdomains.” “I fed my nmap output to ChatGPT.” “I used an LLM to help me write a recon script.” “I found this asset with AI.”</p><p>It’s all recon. All surface discovery. Nobody is talking about using AI in the actual exploitation phase — the moment you’ve found a target endpoint and need to figure out if it’s actually vulnerable and how to prove it.</p><p>The real question — whether you’re running a red team engagement, chasing bug bounties, or doing a client pentest — is whether AI can help not just find the attack surface, but actually exploit it. The answer is yes, but only if you stop treating LLMs like a smarter grep and start thinking about context engineering.</p><h2>The Root Problem: What You Give the LLM Determines What You Get</h2><p>The most common approach looks something like this. You’re working through a web application, you capture an interesting request in Burp Suite, and you paste it into ChatGPT, Claude, or whichever LLM you prefer:</p><pre>GET /api/orders/573 HTTP/1.1<br>Host: target.com<br>Authorization: Bearer eyJhbGciOiJIUzI1NiJ9...</pre><p>“Find vulnerabilities in this request.”</p><p>The LLM dutifully responds with something like: “This endpoint might be vulnerable to IDOR. Try accessing other order IDs like 572 or 574 to see if you can access another user’s data.”</p><p>Technically correct. Completely useless.</p><p>Here’s what the LLM doesn’t know when it sees that request: Is 573 an order ID or a user ID? Does it map to a sensitive object? Does another user in this application own order 574? Is there an admin role that can access all orders regardless of ownership? What other endpoints exist that might expose the same object? What fields does the Order object contain?</p><p>Without this context, the LLM is pattern-matching against its training data, not reasoning about your specific application. It knows that numeric IDs in URL paths are sometimes associated with IDOR vulnerabilities. That’s it. The output is generic because the input is generic.</p><p>This is not an LLM limitation. LLMs are genuinely capable of sophisticated security reasoning. It is a context engineering problem — and it’s entirely solvable.</p><h2>Context Engineering: Understanding the Application Before Attacking It</h2><p>If you want an LLM to reason about exploitation rather than pattern-match against vulnerability classes, you need to give it semantic context about the application. Not raw HTTP requests — semantic understanding.</p><p>This is different from prompt engineering in the narrow sense — it is not about rephrasing your question. It is about what model of the world you hand the LLM before you ask it anything.</p><p>What does that mean in practice? Think about what a skilled pentester builds in their head as they browse an application:</p><p><strong>Objects</strong> are the data entities the application manages. User, Order, Product, Invoice, Report. Every request is doing something to one of these objects.</p><p><strong>Roles</strong> are the privilege levels defined in the application. Admin, editor, moderator, guest, API key user. They define who is allowed to do what.</p><p><strong>Functions</strong> are what endpoints actually do, semantically. Not “PUT /api/posts/45” — but “Update Post.” Not “GET /api/admin/users” — but “List All Users (admin function).”</p><p><strong>ID relationships</strong> are the mappings between identifiers and their owners. Order 573 belongs to User A. Order 498 belongs to User B. This is the raw material for access control testing.</p><p>…</p><p>A skilled pentester builds this model in their head over the course of an engagement. The insight is that you can build this model programmatically and feed it to an LLM — and when you do, the quality of exploitation reasoning improves dramatically.</p><p>The key property of this context is that it is not pre-populated. It accumulates progressively as you browse. The first request you capture tells you almost nothing. By the tenth request, you know the object model. By the thirtieth, you know the role hierarchy, the sensitive fields, and the ID ranges. Every request adds to the knowledge base, and later analysis benefits from everything that came before.</p><pre>Browser Traffic<br>      |<br>      v<br>+-------------+<br>|   Analyzer  |  &lt;- Extracts: objects, roles, functions, IDs<br>+------+------+<br>       |<br>       v<br>+-----------------+<br>|  Context Store  |  &lt;- Accumulates knowledge across all requests<br>+------+----------+<br>       |<br>       +--------------------------------------+<br>       v                                      v<br>+-------------+                    +------------------+<br>| Tester IDOR |                    | Tester AuthZ     |<br>+-------------+                    +------------------+<br>       |                                      |<br>       v                                      v<br>  "User A owns                    "Can User B access<br>   order IDs:                      admin endpoints?"<br>   573, 574, 601"</pre><p>The Analyzer runs first on every captured request. Its job is not to find vulnerabilities — it is to extract semantic meaning. What object is this request operating on? What role does the authenticated user appear to have? What function is being performed? Are there any IDs in the request that suggest ownership relationships?</p><p>The Context Store accumulates everything the Analyzer has extracted, building a growing model of the application across the entire session.</p><p>Only after the Context Store has enough information do the specialized testers run — and when they do, they run with that accumulated context baked into their prompts.</p><p>This distinction matters. An IDOR tester that doesn’t know which IDs belong to which user can only give you generic advice. An IDOR tester that knows “User A owns order IDs 573, 574, and 601 while User B owns IDs 498 and 512” can give you a specific test: authenticate as User B and request /api/orders/573. That's the difference between reconnaissance-grade output and exploitation-grade output.</p><h2>Agent-Based Exploitation Flow</h2><p>Understanding the architecture conceptually is one thing. Implementing it as a working agentic AI system means thinking carefully about how to structure each AI agent and what context it receives.</p><p>The temptation is to build one large prompt: “Here is a captured HTTP request. Here is the session context. Find all vulnerabilities.” This fails for the same reason that asking one consultant to simultaneously specialize in network security, application security, cryptography, and social engineering fails. Depth requires focus.</p><p>When you ask a single LLM instance to simultaneously reason about IDOR, SQL injection, authorization bypass, business logic flaws, and SSRF, the context window fills with considerations from every vulnerability class. The model spreads attention across all of them and goes deep on none. The outputs are generic.</p><p>The orchestrator pattern solves this. An orchestrator agent receives each captured request along with the current session context. It doesn’t try to find vulnerabilities itself — it decides which specialized agents to launch based on the characteristics of the request.</p><pre>Request has numeric ID in path?<br>  -&gt; Launch IDOR agent with: [object type, known IDs per credential, ID range]<br><br>Request is to login/SSO endpoint?<br>  -&gt; Launch AuthN agent with: [auth scheme, JWT structure if present]<br><br>Request has POST body with JSON fields?<br>  -&gt; Launch Mass Assignment agent with: [known object fields, sensitive field list]<br><br>Multiple credentials available?<br>  -&gt; Launch AuthZ agent with: [role hierarchy, endpoint, all credentials]</pre><p>Each specialized agent receives only the context relevant to its vulnerability class. The IDOR agent doesn’t need to know about the JWT structure. The AuthN agent doesn’t need to know about the object model. Focused context produces focused reasoning.</p><p>The key insight is the shape of the question you’re giving each agent. “Find vulnerabilities in this request” is a broad, lazy question. “Can credential B access this admin endpoint that was observed to be accessible by credential A, given the role hierarchy we’ve established?” is a focused question with a yes/no answer and a clear test procedure. Focused questions produce actionable outputs.</p><h2>Practical Scenario: CMS Privilege Escalation</h2><p>Theory aside, let’s walk through what this actually looks like in practice. The target is a CMS application. You have two accounts: an editor (low privilege) and an admin (high privilege). The goal is to discover privilege escalation paths.</p><p><strong>Request 1:</strong> Editor logs in.</p><pre>POST /api/auth/login HTTP/1.1<br>Host: cms.target.com<br>Content-Type: application/json</pre><pre>{"username": "editor@target.com", "password": "..."}</pre><p>The Analyzer extracts a User object, a JWT token in the response, and a role claim: "role": "editor". The privilege level is inferred as low. The Context Store now knows that an editor role exists, what the JWT structure looks like, and that the auth scheme is Bearer token.</p><p><strong>Request 2:</strong> Editor browses to their drafts.</p><pre>GET /api/posts/drafts HTTP/1.1<br>Authorization: Bearer &lt;editor-token&gt;</pre><p>The Analyzer extracts a Post object with fields: id, title, content, status, author_id. The status field is flagged as potentially sensitive — it controls publication state. The Context Store now knows that the editor can read drafts, and has a model of the Post object.</p><p><strong>Request 3:</strong> Editor updates a post.</p><pre>PUT /api/posts/45 HTTP/1.1<br>Authorization: Bearer &lt;editor-token&gt;<br>Content-Type: application/json</pre><pre>{"title": "New Title", "content": "..."}</pre><p>This request is the trigger. The Analyzer extracts a Post update function and flags the status field as sensitive given what the Context Store already knows about it.</p><p><strong>Finding: Mass Assignment on the </strong><strong>status field.</strong></p><p>The Mass Assignment agent launches with its own focused context: Post object fields, sensitive field list, the PUT endpoint. Its question: “Can an editor inject privileged fields through the Post update endpoint?” It tests injecting "status": "published" — bypassing the editorial workflow — and confirms the server accepts it.</p><p><strong>Request 4:</strong> You authenticate as admin separately and browse to the user management panel.</p><pre>GET /api/admin/users HTTP/1.1<br>Authorization: Bearer &lt;admin-token&gt;</pre><p>The Analyzer extracts the admin role, notes the /api/admin/ namespace pattern in the URL, and identifies a User management function. The Context Store now knows that an admin role exists with higher privilege, and that admin functions follow the /api/admin/ URL pattern.</p><p><strong>Finding: Broken Access Control on </strong><strong>/api/admin/users.</strong> (OWASP A01:2021 — Broken Access Control, the top web application security risk.)</p><p>The AuthZ agent launches with full context: editor credential, admin credential, known role hierarchy, known admin endpoint pattern. Its focused question: “Can the editor credential access /api/admin/users?" It constructs the test, executes it, and gets back a 200 OK.</p><p>Neither of these findings would have surfaced by dumping individual requests into an LLM. The access control finding required knowing that admin endpoints follow the /api/admin/ pattern — knowledge that only existed because Request 4 had been analyzed and stored. The mass assignment finding required cross-referencing two separate requests: the status field was discovered in Request 2, and the write endpoint was discovered in Request 3. Without a Context Store connecting them, there is nothing to cross-reference.</p><p>This is the difference between an LLM acting as a stateless pattern-matcher and an LLM acting as a contextually aware exploitation assistant. The underlying model capability is the same. The context engineering is what changes the outcome..</p><h3>Closing: The Missing Piece</h3><p>The gap in the security community’s use of AI is not about what LLMs can do. Modern LLMs are genuinely capable of sophisticated security reasoning — understanding authorization models, identifying trust boundary violations, recognizing business logic flaws. That capability exists and is underused.</p><p>The gap is about how we use LLMs. Treating an LLM as a smarter grep — feeding it raw requests and expecting exploitation guidance — ignores everything that makes LLMs actually powerful: their ability to reason about relationships, hierarchies, and semantic meaning across a complex system.</p><p>Context engineering is the missing piece. Build a model of the application as you browse. Extract objects, roles, functions, and ID ownership. Accumulate this context progressively. Then give specialized agents focused questions backed by that accumulated knowledge.</p><p>Cyberstrike is an open-source tool that implements exactly this architecture for web proxy testing. It uses a browser extension to capture traffic, a proxy-analyzer agent to build session context progressively, and specialized sub-agents for each vulnerability class. If you want to see these concepts working in practice rather than building from scratch, it’s a solid reference implementation.</p><p>Documentation and source: <a href="https://github.com/CyberStrikeus/CyberStrike">https://github.com/CyberStrikeus/CyberStrike</a></p><p>The community will keep producing “I used AI for recon” content, and some of it will be genuinely useful. But if you’re a penetration tester, red teamer, or bug bounty hunter looking for AI-powered security testing that actually reaches the exploitation phase, the answer is not a better prompt. It is a better architecture.</p><p>Stop treating LLMs like a smarter grep. Start treating them like a reasoning engine that needs the same context a skilled human tester builds up over the course of an engagement. The results will follow.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=2791416e4ebd" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/beyond-recon-using-ai-for-real-exploitation-in-pentesting-2791416e4ebd">Beyond Recon: Using AI for Real Exploitation in Pentesting</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[No More Routers In The US - Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 228x - Views:1472 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Al...]]></description>
<link>https://tsecurity.de/de/3401021/it-security-video/no-more-routers-in-the-us-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401021/it-security-video/no-more-routers-in-the-us-threat-wire/</guid>
<pubDate>Thu, 02 Apr 2026 01:47:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 228x - Views:1472 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/vo5vxUjOd8E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
00:00  0 - Intro<br />
00:15 1 - TeamPCP On A Rampage<br />
03:41 2 - Consumer Routers Banned<br />
06:12 3 - Delve Fakes Compliance<br />
08:54 4 - Cloudflare Injecting Analytics<br />
09:33 5 - Comments<br />
10:33 6 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: TeamPCP On A Rampage<br />
https://www.endorlabs.com/learn/teampcp-isnt-done<br />
https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/<br />
https://www.wiz.io/blog/teampcp-attack-kics-github-action<br />
https://www.ox.security/blog/teampcps-telnyx-windows-malware-technical-analysis/<br />
https://www.helpnetsecurity.com/2026/03/30/teampcp-supply-chain-attacks-ransomware/<br />
🔗 Story 2:  Consumer Routers Banned<br />
https://www.fcc.gov/supplychain/coveredlist#conditional-approvals<br />
https://www.fcc.gov/document/fcc-updates-covered-list-include-foreign-made-consumer-routers<br />
https://docs.fcc.gov/public/attachments/DA-26-278A1.pdf<br />
🔗 Story 3: Delve Fakes Compliance<br />
https://www.inc.com/ben-sherry/the-delve-scandal-a-y-combinator-darling-just-got-hit-with-a-bombshell-fraud-accusation/91320652<br />
https://deepdelver.substack.com/p/delve-fake-compliance-as-a-service<br />
🔗 Story 4: Cloudflare Injecting Analytics<br />
https://x.com/_lhermann/status/2037097288489726383<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shift-Left Isn’t Enough: Why Security Governance Must Be Baked Into Your CI/CD Pipeline From Day One]]></title>
<description><![CDATA[Moving security checks earlier in the pipeline is the right instinct — but without governance, policy enforcement, and supply-chain visibility, you’re still flying blind.  The Shift-Left Illusion  When the phrase ‘shift-left‘ entered the DevSecOps vocabulary, it felt like a genuine…
Read more →
T...]]></description>
<link>https://tsecurity.de/de/3400003/it-security-nachrichten/shift-left-isnt-enough-why-security-governance-must-be-baked-into-your-cicd-pipeline-from-day-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400003/it-security-nachrichten/shift-left-isnt-enough-why-security-governance-must-be-baked-into-your-cicd-pipeline-from-day-one/</guid>
<pubDate>Wed, 01 Apr 2026 18:07:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Moving security checks earlier in the pipeline is the right instinct — but without governance, policy enforcement, and supply-chain visibility, you’re still flying blind.  The Shift-Left Illusion  When the phrase ‘shift-left‘ entered the DevSecOps vocabulary, it felt like a genuine…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/shift-left-isnt-enough-why-security-governance-must-be-baked-into-your-ci-cd-pipeline-from-day-one/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/shift-left-isnt-enough-why-security-governance-must-be-baked-into-your-ci-cd-pipeline-from-day-one/">Shift-Left Isn’t Enough: Why Security Governance Must Be Baked Into Your CI/CD Pipeline From Day One</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust]]></title>
<description><![CDATA[Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. The post The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust appeared first on SecurityWeek. This article has been indexed…
Read more →
The post The Next Cybersecurity...]]></description>
<link>https://tsecurity.de/de/3396744/it-security-nachrichten/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3396744/it-security-nachrichten/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/</guid>
<pubDate>Tue, 31 Mar 2026 18:07:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. The post The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust appeared first on SecurityWeek. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/">The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust]]></title>
<description><![CDATA[Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. 
The post The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3396700/it-security-nachrichten/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3396700/it-security-nachrichten/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/</guid>
<pubDate>Tue, 31 Mar 2026 17:52:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Data integrity shouldn’t be seen only through the prism of a technical concern but also as a leadership issue. </p>
<p>The post <a href="https://www.securityweek.com/the-next-cybersecurity-crisis-isnt-breaches-its-data-you-cant-trust/">The Next Cybersecurity Crisis Isn’t Breaches—It’s Data You Can’t Trust</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The RAM crisis is Apple's best chance in decades to capture the PC market]]></title>
<description><![CDATA[In the current RAM crisis, no company is better positioned to not only weather the storm but turn it to its advantage like Apple. It proved that when it released the MacBook Neo in early March. Despite only including 8GB of RAM, the Neo doesn't feel compromised, a testament to the company's silic...]]></description>
<link>https://tsecurity.de/de/3396228/it-nachrichten/the-ram-crisis-is-apples-best-chance-in-decades-to-capture-the-pc-market/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3396228/it-nachrichten/the-ram-crisis-is-apples-best-chance-in-decades-to-capture-the-pc-market/</guid>
<pubDate>Tue, 31 Mar 2026 15:17:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the current RAM crisis, no company is better positioned to not only weather the storm but turn it to its advantage like Apple. It proved that when it released the <a target="_blank" class="link" href="https://www.engadget.com/computing/laptops/macbook-neo-review-apple-puts-every-600-windows-pc-to-shame-130000878.html" data-i13n="cpos:1;pos:1">MacBook Neo</a> in early March. Despite only including 8GB of RAM, the Neo doesn't feel compromised, a testament to the company's silicon and software engineering. For Apple, it may be tempting to treat its latest MacBook as a one-off. That would be a mistake, because at this moment, the business decisions that made the Neo possible represent a once-in-a-generation opportunity to become a bigger player in the PC market. </p><p>If you read Engadget, there's a good chance you know the contours of the global memory shortage, but it's worth repeating just how bad things have become in recent months. Just three companies — SK Hynix, Samsung and Micron — produce more than 90 percent of the world's memory chips. At the end of last year, Micron announced it would end its <a target="_blank" class="link" href="https://www.engadget.com/computing/crucial-is-a-casualty-of-ais-hunger-for-ram-185910113.html" data-i13n="cpos:2;pos:1">consumer-facing business</a> to focus on providing RAM and other components to AI customers.  </p><p>Citing data from TrendForce, <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=2f007401-3eaa-4237-b69b-54ccbe125502&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=ec80ddc0-48e4-4980-98f6-d70c8495f566&amp;featureId=text-link&amp;merchantName=The+Wall+Street+Journal&amp;linkText=The+Wall+Street+Journal&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy53c2ouY29tL3RlY2gvYWkvbWVtb3J5LXJhbS1zaG9ydGFnZS0yMDI2LWY1NTMyNGIwIiwiY29udGVudFV1aWQiOiJlYzgwZGRjMC00OGU0LTQ5ODAtOThmNi1kNzBjODQ5NWY1NjYiLCJvcmlnaW5hbFVybCI6Imh0dHBzOi8vd3d3Lndzai5jb20vdGVjaC9haS9tZW1vcnktcmFtLXNob3J0YWdlLTIwMjYtZjU1MzI0YjAifQ&amp;signature=AQAAAcJ2pSBslbfPj72CzWovOCYyJOEmecv216Z-7xCUoiEo&amp;gcReferrer=https%3A%2F%2Fwww.wsj.com%2Ftech%2Fai%2Fmemory-ram-shortage-2026-f55324b0" data-i13n="elm:affiliate_link;sellerN:The Wall Street Journal;elmt:;cpos:3;pos:1" data-original-link="https://www.wsj.com/tech/ai/memory-ram-shortage-2026-f55324b0"><em>The Wall Street Journal</em></a> reported in January that data centers would consume 70 percent of the high-end memory produced in 2026. As the Big Three shift more of their production to meet enterprise demand, they're allocating fewer wafers for consumer products, leading to dramatic price increases in that market segment. According to data from <a target="_blank" class="link" href="https://counterpointresearch.com/en/insights/memory-price-tracker-january-2026" data-i13n="cpos:4;pos:1">Counterpoint Research</a>, the price of memory — including consumer RAM kits and SSDs, as well as LPDDR5X memory for smartphones — increased by 50 percent during the final quarter of 2025. Before the end of the current quarter, the firm predicts prices will increase by another 40 to 50 percent, and the CEO of SK Hynix recently warned shortages <a target="_blank" class="link" href="https://www.reuters.com/world/asia-pacific/south-koreas-sk-group-chairman-expects-chip-wafer-shortage-last-until-2030-eyes-2026-03-16/" data-i13n="cpos:5;pos:1">could last until 2030</a>. </p><p>Since nearly all consumer electronics need some amount of RAM and storage, the trickle-down effects have come fast and hard. In December, before the situation got as bad as it is now, <a target="_blank" class="link" href="https://gizmodo.com/laptops-prices-are-about-to-skyrocket-2000696366" data-i13n="cpos:6;pos:1">TrendForce warned</a> that most of the major PC manufacturers were either considering, if not already planning, price hikes. This month, the <a target="_blank" class="link" href="https://www.trendforce.com/presscenter/news/20260310-12959.html" data-i13n="cpos:7;pos:1">firm warned</a> laptop prices could increase by as much as 40 percent if manufacturers and retailers moved to protect their margins. Such a scenario would send the cost of a $900 model to about $1,260.</p><p>Amid all that, Apple added another point of pressure: the $600 MacBook Neo. During a recent investor call, Nick Wu, the chief financial officer of ASUS, <a target="_blank" class="link" href="https://gizmodo.com/the-macbook-neo-is-putting-pc-makers-into-panic-mode-2000732387" data-i13n="cpos:8;pos:1">described</a> the Neo as "a shock to the entire market," adding "all PC vendors, including upstream vendors like Microsoft, Intel and AMD" are taking the cute device "very seriously." Wu warned ASUS would "need more time" before it could ready a response.         </p><p>For ASUS and other Windows manufacturers, any response realistically may take a year or more to formulate. That's because the Neo represents both a technical and logistical hurdle. </p><p>To start, it's a fundamentally different machine from the one most Windows OEMs are making right now. It has the advantage of using "unified memory" instead of a set of traditional RAM modules. The 8GB of RAM the Neo has is shared between the A18 Pro's CPU and GPU, meaning it can more efficiently use the RAM that it does have. That's part of the reason the Neo doesn't feel like a Windows PC with 8GB of RAM. Apple didn't get to the A18 Pro and the MacBook Neo by accident. It has spent more than a decade designing its own chips. </p><p>Since 2024, Microsoft has mandated 16GB of RAM — and 256GB of solid-state storage — for PCs that are part of its <a target="_blank" class="link" href="https://www.engadget.com/microsoft-unveils-copilot-pcs-with-generative-ai-capabilities-baked-in-170445370.html" data-i13n="cpos:9;pos:1">Copilot+ AI program</a>. That branding effort may not have <a target="_blank" class="link" href="https://www.engadget.com/computing/laptops/microsofts-copilot-ai-pc-plan-fizzled-but-it-still-served-a-purpose-130000239.html" data-i13n="cpos:10;pos:1">amounted to much</a>, with Copilot+ AI PCs accounting for just <a target="_blank" class="link" href="https://www.pcworld.com/article/2816617/microsofts-copilot-gamble-is-a-bustbut-ai-pcs-still-feel-inevitable.html" data-i13n="cpos:11;pos:1">1.9 percent</a> of all computers sold in the first quarter of 2025, but it did push OEMs, including ASUS, Dell and others to make more capable machines. It also saw Microsoft rework Windows to <a target="_blank" class="link" href="https://www.engadget.com/ai-isnt-the-star-of-microsofts-copilot-pc-push--improved-arm-support-is-190039699.html" data-i13n="cpos:12;pos:1">better support ARM-based processors</a> from Qualcomm. Still, it's hard to see how Windows manufacturers can challenge Apple by going back to existing or older x86 chips with with less RAM. </p><p>Qualcomm's Snapdragon X2 processors could offer a potential response, but there are question marks there too. At CES 2026, the company announced the <a target="_blank" class="link" href="https://www.engadget.com/computing/qualcomm-unveils-snapdragon-x2-plus-chip-at-ces-170000392.html" data-i13n="cpos:13;pos:1">Snapdragon X2 Plus</a>, a pared down version of its X2 Elite chipset with a six-core CPU. On paper, it should offer similar performance to the A18 Pro, but it doesn't seem Qualcomm has produced the chip at scale or that Windows OEMs have shown much interest in it. As of the writing of this story, the company's website lists <a target="_blank" class="link" href="https://www.qualcomm.com/snapdragon/laptops-and-tablets/laptop-device-finder?Platform=4954392" data-i13n="cpos:14;pos:1">just four X2 Plus-equipped models</a>. I was only able to find one of those in stock, the $1,050 <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=8a0e8870-4cf8-4bda-935c-af7c00c28e2b&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=ec80ddc0-48e4-4980-98f6-d70c8495f566&amp;featureId=text-link&amp;merchantName=HP+Store&amp;linkText=HP+Omnibook+5&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5ocC5jb20vdXMtZW4vc2hvcC9wZHAvaHAtb21uaWJvb2stNS1uZ2FpLTE0LWhlMDAxN25yIiwiY29udGVudFV1aWQiOiJlYzgwZGRjMC00OGU0LTQ5ODAtOThmNi1kNzBjODQ5NWY1NjYiLCJvcmlnaW5hbFVybCI6Imh0dHBzOi8vd3d3LmhwLmNvbS91cy1lbi9zaG9wL3BkcC9ocC1vbW5pYm9vay01LW5nYWktMTQtaGUwMDE3bnIifQ&amp;signature=AQAAAY-SJ6c-jHMhTm6_EkEm_F8DKJSyBDU5HvMOFiaFgppj&amp;gcReferrer=https%3A%2F%2Fwww.hp.com%2Fus-en%2Fshop%2Fpdp%2Fhp-omnibook-5-ngai-14-he0017nr" data-i13n="elm:affiliate_link;sellerN:HP Store;elmt:;cpos:15;pos:1" data-original-link="https://www.hp.com/us-en/shop/pdp/hp-omnibook-5-ngai-14-he0017nr">HP Omnibook 5</a>. It has an OLED screen and more RAM than the Neo. Could HP repurpose something like the Omnibook 5 to take on the Neo? Maybe, but I'm not sure there's getting around the need for 16GB to get Windows 11 running decently.    </p><p>Even if the Snapdragon X2 Plus offers a stopgap measure, no company operates a supply chain quite like Apple. It has spent billions of dollars to make itself independent of companies like Qualcomm by designing its own Wi-Fi and Bluetooth chips, for example. It also doesn't need to pay Microsoft a licensing fee to use a <a target="_blank" class="link" href="https://www.engadget.com/computing/microsoft-will-yank-copilot-from-some-windows-apps-and-let-you-move-the-taskbar-again-202857203.html" data-i13n="cpos:16;pos:1">bloated Windows 11</a>. Those are all factors that lead to OEMs like ASUS and Lenovo operating on razor thin margins.  </p><p><a target="_blank" class="link" href="https://www.statista.com/chart/33869/apple-gross-profit-margin/?__sso_cookie_checker=failed" data-i13n="cpos:17;pos:1">Per Statista</a>, Apple earned a nearly 36.8 percent gross profit margin on its products in 2025. That's almost exactly half as much as the gross margin it made on services, which grew to a record 75.4 percent last year. For comparison, ASUS has seen its profit margins erode to about 15.3 percent in recent quarters, or less than a third of Apple's 2025 average of 46.9 percent. For ASUS and other Windows OEMs, the short-term outlook isn’t good. HP <a target="_blank" class="link" href="https://www.engadget.com/gaming/pc/hp-says-ram-now-accounts-for-more-than-a-third-of-its-pc-costs-192914150.html" data-i13n="cpos:18;pos:1">recently told investors</a> RAM now accounts for more than a third of the cost of its PCs. And if memory shortages continue, many of them will be forced to raise their prices to protect their margins. </p><p>Apple is in no such position. The iPhone recently <a target="_blank" class="link" href="https://www.engadget.com/mobile/smartphones/apple-just-reported-its-best-ever-quarter-for-iphone-sales-234135513.html" data-i13n="cpos:19;pos:1">had its best quarter ever</a>, contributing $85.27 billion to the company's Q1 revenue. The fact that Mac revenue declined from $8.9 billion to $8.3 billion year-over-year didn't make a dent to Apple's bottom line. For the companies that must now compete against the Neo, it's not a fair playing field. To Lenovo, Dell, HP and ASUS, PC sales are almost everything to their business. For Apple, it's a side hustle.       </p><p>As the company prepares to kick off its 51st year, it should consider it may never be in a better position to claw ahead in the market where it all started for the company. In both the PC and smartphone segments, Apple's market share has always been a distant second (and sometimes third and forth) to Windows and Android, in part because commoditization has consistently worked against the company. But when a single part now accounts for a third of the cost of a new PC, the regular rules don't apply. </p><p>It's not just that the company is better insulated than nearly every other player against runaway RAM costs, it's that it also has a technological edge and the profit margins to compete on price at the same time. In recent quarters, the company's share of the PC market has hovered around the 9 to 10 percent mark, meaning it's consistently been about the fourth largest manufacturer. </p><p>For as long as the RAM shortage continues, Apple should seriously consider sacrificing some of its PC profits to become a bigger player. So far, the company has moved to protect the margins on its more expensive devices. For example, it increased the price of the latest <a target="_blank" class="link" href="https://www.engadget.com/computing/laptops/the-macbook-air-m5-starts-at-1099-up-100-from-the-m4-141612909.html" data-i13n="cpos:20;pos:1">MacBook Air and MacBook Pro by $100</a>. The company doubled the amount of base storage to make up for the hike. </p><p>Moving forward, it should do everything it can to maintain, and maybe even lower the price of its computers to a point where its competitors can't meet it. If the Lenovos and HPs of the world can't compete on either price or performance, consumers will move to Mac computers. As Apple looks to the next 50 years, it may not get another opportunity like the one it has right now. </p>This article originally appeared on Engadget at https://www.engadget.com/computing/laptops/the-ram-crisis-is-apples-best-chance-in-decades-to-capture-the-pc-market-130000672.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[The ‘consultant trap’: Why the best ideas for your business don’t come from the outside]]></title>
<description><![CDATA[CIOs are under constant pressure to innovate business processes for better efficiency and efficacy under financial constraints. Especially, in early-stage startups and small organizations with limited budgets, CIOs face extreme pressure from the board of directors to maximize the ROI on every dol...]]></description>
<link>https://tsecurity.de/de/3395612/it-security-nachrichten/the-consultant-trap-why-the-best-ideas-for-your-business-dont-come-from-the-outside/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395612/it-security-nachrichten/the-consultant-trap-why-the-best-ideas-for-your-business-dont-come-from-the-outside/</guid>
<pubDate>Tue, 31 Mar 2026 12:07:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs are under constant pressure to innovate business processes for better efficiency and efficacy under financial constraints. Especially, in early-stage startups and small organizations with limited budgets, CIOs face extreme pressure from the board of directors to maximize the ROI on every dollar spent on innovation, as 60-90% of the organization’s budget is consumed just running operations. To make the most of limited budgets for innovation and optimize the cost of innovation, I vouch for investing in employee-led innovation as one of the best ways to develop cost-effective innovative solutions.  </p>



<p>The core idea behind optimizing the cost of innovation with employee-led innovation is based on the fact that employees working at the grassroots level know the business operations, challenges and potential solutions better than any other outside vendor or consultants. I agree that in many scenarios, industry-standard solutions, outside vendors and consultants provide better and cost-effective solutions. However, when the problem is company-specific and an organization needs customized innovative solutions, employee-led innovation wins.  </p>



<p>Your employees are your goldmine of ideas who can identify problems faster, find effective solutions quicker and iterate faster.  </p>



<p>Leadership needs to provide the pathway, resources and culture for employee-led innovation to happen and flourish.     </p>



<h2 class="wp-block-heading">A framework for CIOs to lead the employee-driven innovation    </h2>



<p>Struggling with scaling the operations of customer support departments to meet the growing needs of business, I ran the initiative of employee-led innovation a few years back, where operations employees highlighted repetitive manual tasks in the customer support operations, the need for the development of new channels of customer support and the creation of more extensive customer self-help resources. </p>



<p>We successfully automated manual customer support operations, developed a live chat channel to reduce call and email volume and created an extensive knowledge base to reduce the number of tickets.   </p>



<p>The results included: </p>



<ul class="wp-block-list">
<li>25% faster response times </li>
</ul>



<ul class="wp-block-list">
<li>30% more tickets resolved </li>
</ul>



<ul class="wp-block-list">
<li>15% reduction in support calls <br> </li>
</ul>



<p>The success was not due to new technology alone. It was due to accurate problem identification and early validation by the people performing the work. </p>



<h2 class="wp-block-heading">My framework for leading employee-driven innovation </h2>



<p>I use the following framework to lead employee-driven innovation initiatives from ideation to execution.     </p>



<h3 class="wp-block-heading">1. Capture operational problems </h3>



<p>The first stage of finding innovative solutions is to capture the right problems causing operational friction. In most cases, industry standard solutions and external consultants fail to address the operational challenges because of the wrong identification of the problem. </p>



<p>The operational proximity of the employees leads to high-quality problem discovery as they directly experience the friction, bottlenecks and system limitations. Directed the department to identify recurring issues, including workflow delays, repetitive manual processes, customer complaints and system limitations.  </p>



<h3 class="wp-block-heading">2. Translate problems into testable hypotheses </h3>



<p>Early solutions proposed by employees are often assumptions. To find innovative solutions that are practical, applicable and drive business value, transform the problem into testable hypotheses. Ask questions: </p>



<ul class="wp-block-list">
<li>What is the problem? Who is affected? How often does it occur?  </li>
</ul>



<ul class="wp-block-list">
<li>What is the business impact?  </li>
</ul>



<ul class="wp-block-list">
<li>What assumption must be true for a solution to work? </li>
</ul>



<ul class="wp-block-list">
<li>How many users are affected?  </li>
</ul>



<ul class="wp-block-list">
<li>What is the potential value of resolution?  </li>
</ul>



<p>This prevents random experimentation and aligns efforts with business priorities. </p>



<h3 class="wp-block-heading">3. Rapid experimentation and pilot implementation   </h3>



<p>Finding novel solutions requires experimentation. To find the solution to selected problems, enter a focused innovation sprint. Teams develop prototypes and workflow models to demonstrate whether the idea can create measurable improvement. The focus is on proving value and validating usefulness, not perfection or building a production system.  </p>



<p>Allocate small budgets to the promising solutions. Test the solutions in real-world usage for 4-8 weeks. Measure success using <a href="https://www.cio.com/article/4072248/metrics-that-matter-redefining-api-roi-for-cios.html" target="_blank">practical metrics</a> such as time saved, operational cost reduced and customer experience improved. This converts innovation into business value. </p>



<h3 class="wp-block-heading">4. Iterate and scale or stop    </h3>



<p>Every initiative reaches a decision point. Measure the effectiveness of the initiative. Adopt an <a href="https://www.cio.com/article/4101070/agile-isnt-just-for-software-its-a-powerful-way-to-lead.html" target="_blank">agile</a> approach. Iterate, refine and retest. Scale into operations if it proves to be effective. Otherwise, terminate and document learning. Stopping ideas is not failure. It prevents larger, more expensive failures later.       </p>



<h2 class="wp-block-heading">My key takeaways for leaders  </h2>



<ul class="wp-block-list">
<li><strong>Create structured processes to drive employee-led innovation.</strong> The key driver of employee-driven innovation is always leadership. Create the right structures, processes and environment where employee-led innovation can happen. Design systems where employees can reach the leadership to discuss the problems they face and want to solve. Provide support and direction to align innovation initiatives with business strategy.</li>



<li><strong>Find the right people.</strong> Find the right intrinsically motivated people who care deeply about their work and listen to their ideas. Create a group of motivated individuals, set up a small innovation lab and fuel the group with necessary resources.</li>



<li><strong>Create an environment for innovation to flourish.</strong> The right alignment to the business strategy, the right talent, streamlined processes and a decent budget still cannot create the low-cost engine of innovation unless you have a culture of collaboration at the workplace. Collaboration transforms even ordinary spaces into catalysts for advancement by fostering open exchange, sharing and interplay of ideas.      </li>
</ul>



<p>When CIOs intentionally create the right structures, culture and decision frameworks, employee-driven innovation can become a low-cost, high-impact engine for competitive advantage.  </p>



<p>You are already sitting on a goldmine of ideas. You need to find the right people, fuel them with resources and create an environment for innovation. </p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 ways to bolster your security posture on the cheap]]></title>
<description><![CDATA[As every CISO knows, maintaining a strong cybersecurity posture is costly. What’s not so well known is that there are many ways cybersecurity can be enhanced with the help of relatively trivial investments. Simply by thinking creatively, a security leader can substantially boost enterprise protec...]]></description>
<link>https://tsecurity.de/de/3395495/it-security-nachrichten/8-ways-to-bolster-your-security-posture-on-the-cheap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395495/it-security-nachrichten/8-ways-to-bolster-your-security-posture-on-the-cheap/</guid>
<pubDate>Tue, 31 Mar 2026 11:21:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As every CISO knows, maintaining a strong cybersecurity posture is costly. What’s not so well known is that there are many ways cybersecurity can be enhanced with the help of relatively trivial investments. Simply by thinking creatively, a security leader can substantially boost enterprise protection at a minimal cost.</p>



<p>Could your organization benefit from some extra low-cost protection? If so, here are eight ways to improve enterprise cybersecurity without seriously denting your budget.</p>



<h2 class="wp-block-heading">1. Enforce MFA better</h2>



<p>Risk mitigation should start with fundamentals, says <a href="https://www.linkedin.com/in/trevorhorwitz/">Trevor Horwitz</a>, CISO at compliance technology services firm TrustNet. “MFA directly supports confidentiality and access control, which are core security objectives,” he states. “In almost every breach we analyze, compromised credentials are involved.” Most organizations already have access to this capability. Turn it on, <a href="https://www.csoonline.com/article/4123184/always-on-privileged-access-is-pervasive-and-fraught-with-risks.html">especially for privileged access</a>, Horwitz advises.</p>



<p><a href="https://www.linkedin.com/in/cisorandygross/">Randy Gross</a>, CISO at certification firm CompTIA, agrees. “Begin by clearly defining the crown jewels and the next tier of important systems, then <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html">enforce MFA</a> and least privilege across those environments,” he recommends. “Next, establish time-bound remediation expectations for the meaningful vulnerabilities in those systems before expanding attention to the broader environment.”</p>



<h2 class="wp-block-heading">2. Take full advantage of your existing tools</h2>



<p>A practical way to strengthen enterprise security without incurring additional significant spend is to ensure you’re fully leveraging the capabilities of solutions already present within your organization, says <a href="https://www.linkedin.com/in/garybrickhouse/">Gary Brickhouse</a>, CISO at security services firm GuidePoint Security.</p>



<p>“Most organizations have invested heavily in security solutions, yet most are only using a portion of what those tools can do,” he explains. “By optimizing and operationalizing existing technologies, organizations can realize a reduction in cybersecurity risk with little spend.”</p>



<p>Brickhouse says this approach is highly effective because it focuses on improving operational maturity rather than adding more technology solutions. “This tactic also increases ROI by helping to ensure organization are getting the most value from solutions they already own,” he says.</p>



<h2 class="wp-block-heading">3. Conduct tabletop exercises</h2>



<p>Don’t underestimate the power of <a href="https://www.csoonline.com/article/570871/tabletop-exercises-explained-definition-examples-and-objectives.html">tabletop exercises</a>, advises <a href="https://www.linkedin.com/in/ryancdavis/">Ryan Davis</a>, CISO at IT services provider New Charter Technologies. “They almost guarantee a positive action, and the only cost is in time,” he says.</p>



<p>A tabletop exercise requires participants to <a href="https://www.csoonline.com/article/1311295/4-tabletop-exercises-every-security-team-should-run.html">view scenarios from an execution perspective</a> rather than a theoretical position.</p>



<p>“Practicing for unexpected scenarios enables teams to exercise muscles they wouldn’t normally use,” Davis says. “It allows team members to ask questions they may not typically ask in everyday scenarios because there isn’t time or an obvious need to do so.”</p>



<p>He adds that the approach also quickly highlights strengths that don’t need further attention, as well as gaps that need to be closed.</p>



<h2 class="wp-block-heading">4. Utilize the application layer</h2>



<p>An effective way to bolster coverage and reduce overall risk is to include the application layer in your cybersecurity strategy, says <a href="https://www.linkedin.com/in/billoliver2/">Bill Oliver</a>, managing director at cybersecurity platform provider SecurityBridge. He notes that ERP systems sit at the core of your company’s operations and have been targeted by bad actors for years.</p>



<p>“Monitoring your ERP systems for missing security patches, bad security configurations, real-time security events, and so on can give you great cybersecurity protection at a relatively low cost as compared to other cybersecurity initiatives,” he says. “Understanding what security events are happening in real time, will greatly bolster your company’s cybersecurity program and correct a weakness that has been there since day one.”</p>



<h2 class="wp-block-heading">5. Implement passkeys</h2>



<p>Passkeys eliminate the single biggest attack vector most organizations face: <a href="https://www.csoonline.com/article/4042464/enterprise-passwords-becoming-even-easier-to-steal-and-abuse.html">stolen or phished credentials</a>, says <a href="https://featured.com/p/john-coursen">John Coursen</a>, CISO at Fortify Cyber, a firm that helps regulated industries secure their infrastructure.</p>



<p>“They remove the human element from authentication,” he explains. Coursen notes that passwords tend to get reused, phished, and stuffed into credential databases. “Passkeys can’t be phished, because there’s no shared secret to steal.”</p>



<p>Coursen observes that most modern identity providers, such as Azure AD and Okta, already support passkeys. “The tech isn’t hard to implement — it’s the behavior change and getting users to adopt it.”</p>



<p>Start with your highest-risk users, Coursen advises, including executives, finance teams, and anyone with access to sensitive client data or wire transfer authority.</p>



<h2 class="wp-block-heading">6. Aim for the heart</h2>



<p>Target what attackers actually exploit, suggests <a href="https://www.aikido.dev/team-members/mike-wilkes">Mike Wilkes</a>, CISO at security technology provider Aikido Security. “Set up redundant DNS providers — they’re low-cost, high-impact, and massively underused,” he says. “Put Cloudflare’s free plan in front of your public-facing apps, and you get DDoS mitigation and a WAF layer instantly.”</p>



<p>Turn on SPF, DMARC, and DKIM, since email is still the No. 1 initial access vector and these DNS controls take just an afternoon to implement. “Enable MFA everywhere using the free Google Authenticator,” Wilkes says, while also recommending checking DNS records and auditing MFA for gaps.</p>



<h2 class="wp-block-heading">7. Consider human risk management</h2>



<p>At a time when the vast majority of cyberattacks involve people, human risk management is a critical and cost-effective way to keep the enterprise safe, says <a href="https://www.linkedin.com/in/mattglindley/">Matt Lindley</a>, chief innovation and security officer at cybersecurity awareness training firm NINJIO.</p>



<p><a href="https://www.csoonline.com/article/4123230/human-risk-management-cisos-solution-to-the-security-awareness-training-paradox.html">Human risk management</a> works because it addresses the most urgent cyberthreat most enterprises face by establishing a culture of cybersecurity at every level of the organization, Lindley says.</p>



<p>“Instead of treating employees as the weak links in an organization’s cybersecurity posture, they should be regarded as its greatest security assets,” he states. “When employees are empowered to identify, report, and thwart cyberattacks, the enterprise now has a distributed and adaptive layer of cybersecurity.”</p>



<p>Effective human risk management requires security leaders to provide engaging, actionable, and personalized <a href="https://www.csoonline.com/article/3604803/security-awareness-training-topics-best-practices-costs-free-options.html">security awareness training</a>, Lindley says. It also demands a high degree of accountability. He notes that security leaders should be able to determine whether behavioral interventions are actually working by using benchmarks beyond vanity metrics, such as completion rates.</p>



<p>“This means providing data on phish reporting and other real-world improvements to the organization’s cybersecurity posture, all of which will generate buy-in across the C-suite,” he says.</p>



<h2 class="wp-block-heading">8. Double-down on cybersecurity fundamentals</h2>



<p>One of the most effective low-cost security strategies is to double down on fundamentals such as identity protection, patching, visibility, and user awareness, says <a href="https://www.linkedin.com/in/jeffforesman/">Jeff Foresman</a>, vice president of cybersecurity at technology services firm Resultant.</p>



<p>Most organizations already have the tools they need through platforms like Microsoft and Google, as well as their endpoint and email security stacks, Foresman says. The real opportunity, he notes, lies in better configuration and disciplined execution, such as enforcing MFA everywhere, reducing unnecessary admin access, patching Internet-facing systems quickly, and improving phishing reporting and response. “Those steps alone significantly reduce real-world risk,” Foresman says.</p>



<p>Foresman notes that a fundamentalist approach works by targeting how attackers actually gain access. The majority of breaches still begin with compromised credentials, phishing, exposed systems, or misconfigurations, not advanced zero-day exploits, he explains. By focusing on identity, email, and attack surface reduction, organizations can address the most common entry points.</p>



<p>“It’s practical, measurable, and tied to the breach patterns we see every day, rather than theoretical controls,” Foresman says.</p>



<p><strong>See also:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html">How MFA gets hacked — and strategies to prevent it</a></li>



<li><a href="https://www.csoonline.com/article/1312195/redefining-multi-factor-authentication-why-we-need-passkeys.html">Redefining multifactor authentication: Why we need passkeys</a></li>



<li><a href="https://www.csoonline.com/article/4123230/human-risk-management-cisos-solution-to-the-security-awareness-training-paradox.html">Human risk management: CISOs’ solution to the security awareness training paradox</a></li>



<li><a href="https://www.csoonline.com/article/4071102/cisos-must-rethink-the-tabletop-as-57-of-incidents-have-never-been-rehearsed.html">CISOs must rethink the tabletop, as 57% of incidents have never been rehearsed</a></li>



<li><a href="https://www.csoonline.com/article/4071289/what-to-consider-to-make-your-enterprise-phishing-training-effective.html">Phishing training needs a new hook — here’s how to rethink your approach</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's third co-founder insists he still owns 10% of Apple]]></title>
<description><![CDATA[Apparently Ron Wayne wasn't splitting hairs. Despite quitting after 12 days, and being paid off twice, the third Apple co-founder has doubled-down on his odd claim of still owning 10% of the company.Apple co-founder Ronald Wayne at the Computer History Museum — image credit: CHMWhen Ron Wayne fir...]]></description>
<link>https://tsecurity.de/de/3393272/ios-mac-os/apples-third-co-founder-insists-he-still-owns-10-of-apple/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393272/ios-mac-os/apples-third-co-founder-insists-he-still-owns-10-of-apple/</guid>
<pubDate>Mon, 30 Mar 2026 15:54:02 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apparently Ron Wayne wasn't splitting hairs. Despite quitting after 12 days, and being paid off twice, the third Apple co-founder has doubled-down on his odd claim of still owning 10% of the company.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67038-140858-000-lead-Ronald-Wayne-xl.jpg" alt="Elderly man in a suit speaks into a microphone at a seated event, surrounded by listening attendees, including a man in a red polo shirt beside him."><br><span>Apple co-founder Ronald Wayne at the Computer History Museum — image credit: CHM</span></div><br>When Ron Wayne first raised this point in <a href="https://appleinsider.com/articles/26/03/16/the-story-about-how-the-third-apple-founder-sold-out-for-800-isnt-quite-right">March 2026</a> at the Computer History Museum, it sounded like splitting hairs. He said that he had never sold the 10% stake he originally had in Apple, but he appeared to want to clear up a point of pedantry.<br><br>Since Wayne quit Apple, he strictly speaking didn't own the 10% and that's why he could never have sold it. This seemed like a tiny point of clarification, and no more.<br><br><br> <a href="https://appleinsider.com/articles/26/03/30/apples-third-co-founder-insists-he-still-owns-10-of-apple?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243870?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Gen Z can win in the AI era]]></title>
<description><![CDATA[The “digital divide” used to mean unequal access to devices and the internet. Today, that gap has evolved into something more consequential: An AI divide — not about access to tools, but about who knows how to use them well. 



In recent months, while mentoring several newly graduated computer s...]]></description>
<link>https://tsecurity.de/de/3392554/it-security-nachrichten/how-gen-z-can-win-in-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392554/it-security-nachrichten/how-gen-z-can-win-in-the-ai-era/</guid>
<pubDate>Mon, 30 Mar 2026 12:07:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The “digital divide” used to mean unequal access to devices and the internet. Today, that gap has evolved into something more consequential: An AI divide — not about access to tools, but about who knows how to use them well. </p>



<p>In recent months, while mentoring several newly graduated computer science majors, I was struck by how familiar their resumes looked. Many had completed the same core coursework I took more than 25 years ago — database management, Java, traditional software engineering — while contemporary foundations like cloud platforms, applied AI, statistical modeling and GenAI workflows were often missing. </p>



<p>The problem is not that Gen Z lacks ambition or intelligence. The problem is that the systems meant to prepare them, educational institutions and enterprises, are adapting at radically different speeds. </p>



<h2 class="wp-block-heading">The AI divide: Not access, but readiness </h2>



<p>A small number of well-funded, elite universities have begun integrating AI and GenAI into their curricula. But many less-resourced schools have taken a more cautious path — some even prohibiting student use of AI tools. The real constraint isn’t access to GenAI; it’s the harder, costlier work of modernizing curricula and upskilling faculty. Updating course design, retraining instructors and building new evaluation methods takes time and money. Many institutions simply don’t have enough of either, at least not yet.  </p>



<p>Meanwhile, headlines like <em>“80% of Gen Z already uses AI”</em> can be misleading. Adoption statistics often mask an uncomfortable truth: Usage intensity and skill depth vary dramatically. <a href="https://hbr.org/2026/01/how-gen-z-uses-gen-ai-and-why-it-worries-them" target="_blank" rel="nofollow">“Using AI” can mean anything</a> from experimenting with a chatbot once a month to integrating AI into daily workflows with disciplined verification and iterative prompt design. </p>



<h2 class="wp-block-heading">Three Gen Z personas in AI adoption </h2>



<p>In observing how young professionals approach emerging technologies like GenAI, I see three distinct personas. They are not fixed identities. People can move between them. But the personas clarify the gap between surface adoption and real capability. </p>



<h3 class="wp-block-heading">1. The driver </h3>



<p>Drivers are proactive and disciplined. They learn continuously, experiment intentionally and integrate AI into their workflows, personally and professionally. Over time, they evolve from basic prompting (such as the PICO structure: Persona, input, context, output) to more sophisticated approaches like multi-step reasoning, iterative refinement and structured evaluation. </p>



<p>Like real-world drivers, they make route adjustments, adapt to changing conditions and can choose their destinations. With repetition, AI becomes second nature, not a novelty, but a durable capability. </p>



<h3 class="wp-block-heading">2. The bus rider </h3>



<p>Bus riders use AI occasionally and tactically. Their prompts tend to be simple and task-based, often approached as a “better search” rather than collaborative problem solving. The goal is a quick outcome, not deeper understanding. </p>



<p>For example, if a poem needs translation, a driver leveraging AI might specify tone, rhythm, audience, length, cultural nuance and even ask the model to assume the role of a bilingual poet skilled in both traditions. A bus rider is more likely to type: “Translate this.” Both users are “using AI,” but only one is building a transferable skillset. </p>



<p>Bus riding is easy. It takes you somewhere. But it rarely gets you exactly where you want to go — and it rarely builds mastery. </p>



<h3 class="wp-block-heading">3. The train rider </h3>



<p>Train riders are passive and often cynical about AI’s impact. They spend more time debating AI than learning it, and they adopt a doomsday view that AI automation will replace most Gen Z jobs. Their posture is not adaptation; it’s resignation. </p>



<p>The irony is that this mindset becomes self-fulfilling: The less you learn and practice, the narrower the career path.  </p>



<h2 class="wp-block-heading">AI as foundational, not optional </h2>



<p>AI is becoming foundational to nearly every aspect of computing. We live in a digitized world where workflows, decision-making and productivity increasingly depend on AI-enabled tools. The practical implication is simple: Drivers will expand their career frontier, while bus riders and train riders will find their paths narrowing. </p>



<p>This is why younger talent should not be viewed merely as junior technologists who need more tools. They benefit most from structured pathways that build judgment, context and accountability alongside technical fluency. </p>



<h2 class="wp-block-heading">Judgment is now an operational skill </h2>



<p>AI increases speed and output. However, <a href="https://www.fastcompany.com/91482968/ai-isnt-replacing-humans-its-reallocating-human-judgment-technology-work-ai" target="_blank" rel="nofollow">it is unlikely AI will replace responsibility</a>, at least not soon. In fact, the faster work moves, the more critical human judgment becomes. And in AI-enabled environments, judgment isn’t abstract; it shows up in daily operational decisions, such as: </p>



<ul class="wp-block-list">
<li>Knowing when an AI output is “directionally useful” versus production-ready </li>
</ul>



<ul class="wp-block-list">
<li>Understanding data lineage and recognizing where bias or incompleteness may exist </li>
</ul>



<ul class="wp-block-list">
<li>Recognizing when speed introduces downstream risk — legal, security or reputational </li>
</ul>



<ul class="wp-block-list">
<li>Knowing when to escalate uncertainty rather than “force” an answer into production </li>
</ul>



<p>Early-career professionals often learn tools quickly. The responsibility of educators and employers is to pair that speed with decision frameworks to help them acquire the intuition to know when to move fast and when to slow down. </p>



<h2 class="wp-block-heading">Hybrid converged teams multiply results </h2>



<p>One of the most powerful ways to close the AI divide inside organizations is to build intentionally hybrid teams of seasoned experts and early career professionals. When designed well, they don’t just “balance” each other; they multiply effectiveness in AI adoption. </p>



<p>Senior experts bring: </p>



<ul class="wp-block-list">
<li>Pattern recognition from past cycles of technology change </li>
</ul>



<ul class="wp-block-list">
<li>Institutional memory around compliance, risk and client expectations </li>
</ul>



<ul class="wp-block-list">
<li>Confidence to challenge outputs — human or machine </li>
</ul>



<p>Early career professionals bring: </p>



<ul class="wp-block-list">
<li>Comfort experimenting with emerging tools </li>
</ul>



<ul class="wp-block-list">
<li>Fluency in digital collaboration </li>
</ul>



<ul class="wp-block-list">
<li>A bias toward iteration and improvement </li>
</ul>



<p>Done right, this combination accelerates adoption while protecting quality. </p>



<h2 class="wp-block-heading">Upskilling as the core of AI readiness </h2>



<p>Organizations should treat AI adoption not only as a technology initiative, but also as an enablement and skills initiative. Training priorities should include: </p>



<ul class="wp-block-list">
<li>AI fluency and model awareness </li>
</ul>



<ul class="wp-block-list">
<li>Human-in-the-loop validation practices </li>
</ul>



<ul class="wp-block-list">
<li>Data integrity, privacy and security fundamentals </li>
</ul>



<ul class="wp-block-list">
<li>Governance, ethics and workflow-level controls </li>
</ul>



<p>At Integreon, we avoid sink-or-swim models of skill development. Instead, we use structured exposure that accelerates learning without compromising trust: </p>



<ul class="wp-block-list">
<li>Scenario-based training where teams review AI-assisted outputs together </li>
</ul>



<ul class="wp-block-list">
<li>Clear escalation paths for uncertainty — not just errors </li>
</ul>



<ul class="wp-block-list">
<li>Explicit conversations about <em>why</em> a decision was made, not just <em>what</em> decision was made </li>
</ul>



<ul class="wp-block-list">
<li>Ongoing refreshers as tools evolve and risk profiles shift </li>
</ul>



<p>This matters especially for early professionals. Small errors compound at scale. AI makes scaling easier than ever, which can become a double-edged sword.  </p>



<h2 class="wp-block-heading">Conclusion </h2>



<p>The AI divide is not ultimately a technology problem. It is a capability problem, rooted in curriculum modernization, workforce design and the cultivation of judgment. Gen Z is not behind because they lack access to AI. Many are behind because they lack the structure that turns exposure into mastery. </p>



<p>The winners in the AI era will be those who learn to “drive,” to master prompt engineering patterns and use AI with intention, context, verification and accountability. Education must modernize faster. Employers must treat upskilling as an operating system, not a one-time course. Leaders must design environments with hybrid converged teams that combine speed with wisdom. </p>



<p>AI will reward the prepared, not the most skeptical and not the most casual. The future belongs to the drivers, and it is our shared responsibility to help the next-gen workforce become one. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Network and storage patterns for AI workloads: The overlooked bottleneck]]></title>
<description><![CDATA[I used to think AI performance was mostly a GPU problem. 



Then I watched a “healthy” GPU fleet crawl. Not because we ran out of compute, but because we ran out of movement. Tokens waiting on data. GPUs waiting on batches. Services waiting on east-to-west traffic. Storage queues quietly turning...]]></description>
<link>https://tsecurity.de/de/3392442/it-security-nachrichten/network-and-storage-patterns-for-ai-workloads-the-overlooked-bottleneck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392442/it-security-nachrichten/network-and-storage-patterns-for-ai-workloads-the-overlooked-bottleneck/</guid>
<pubDate>Mon, 30 Mar 2026 11:22:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I used to think AI performance was mostly a GPU problem. </p>



<p>Then I watched a “healthy” GPU fleet crawl. Not because we ran out of compute, but because we ran out of movement. Tokens waiting on data. GPUs waiting on batches. Services waiting on east-to-west traffic. Storage queues quietly turning into tail latency. </p>



<p>Today, I do not even call this a storage problem. It is an information supply chain problem. In real enterprise AI, data is scattered across on-prem, cloud and edge footprints. Training and inference cycles get longer. Expensive resources like GPUs stay scarce. And the system pays a time tax every time data has to hop, copy, translate or wait. <a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM</a> frames AI storage in this same “supply chain” reality, especially as organizations modernize for distributed data and AI at scale.  </p>



<p>If you are running AI in production, especially LLM inference and retrieval augmented generation (RAG), the network and storage layer is where “it works” becomes “it works reliably at scale.” </p>



<p>This is my field guide to the patterns that matter, the metrics that expose bottlenecks quickly and the open-source tools that can help you fix them. </p>



<h2 class="wp-block-heading">The metric shift: From averages to tail latency </h2>



<p>Traditional infrastructure teams love averages. AI punishes that mindset. </p>



<p>For LLM inference, user experience is governed by two numbers: </p>



<ul class="wp-block-list">
<li><strong>Time to first token (TTFT):</strong> How long users wait before they see the first token.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Time per output token (TPOT):</strong> How smoothly tokens stream after the first one.  </li>
</ul>



<p><a href="https://github.com/mlcommons/inference_policies/blob/master/inference_rules.adoc?" target="_blank" rel="noreferrer noopener">MLCommons</a> uses TTFT and TPOT in its LLM inference benchmarking rules because they reflect what users feel, not what a mean value hides. </p>



<p>Once you track TTFT and TPOT in percentiles (p95 and p99), the network and storage layer stops being “someone else’s problem” and becomes an architectural priority. </p>



<h2 class="wp-block-heading">Two traffic shapes, two different bottlenecks </h2>



<p>Most enterprise AI systems fall into two traffic shapes that break different things. </p>



<h3 class="wp-block-heading">Shape 1: Training and batch analytics </h3>



<ul class="wp-block-list">
<li>Big sequential reads and writes  </li>
</ul>



<ul class="wp-block-list">
<li>Dataset shuffles and checkpoints  </li>
</ul>



<ul class="wp-block-list">
<li>Distributed training traffic across nodes  </li>
</ul>



<p>This is bandwidth hungry. Parallelism and throughput matter. Latency is often less visible than in interactive workloads, but when training stretches from days to weeks, it is frequently a data path problem. </p>



<h3 class="wp-block-heading">Shape 2: Inference and RAG </h3>



<ul class="wp-block-list">
<li>Bursty request patterns  </li>
</ul>



<ul class="wp-block-list">
<li>Many small reads (vector search, metadata, prompt artifacts)  </li>
</ul>



<ul class="wp-block-list">
<li>High fan-out and fan-in across services  </li>
</ul>



<ul class="wp-block-list">
<li>Tail latency dominates  </li>
</ul>



<p>Most CIO conversations I have are about inference, because that is where customer experience, employee productivity and revenue workflows live. That means the architecture should be optimized for consistency, not just peak throughput. </p>



<h2 class="wp-block-heading">Three failure modes I see constantly </h2>



<h3 class="wp-block-heading">1) GPUs look busy, but they are not productive </h3>



<p>I have seen GPU utilization in the 60 to 80 percent range while tokens per second stayed flat and queues kept growing. The system looked “loaded,” but it was not delivering more outcomes. </p>



<p>In practice, the fix is often not “more GPUs.” It is better batching and memory management in the serving layer, so GPUs spend more time generating tokens and less time context switching or waiting for fragmented work. </p>



<p>Serving engines like <a href="https://docs.vllm.ai/en/stable/configuration/optimization/" target="_blank" rel="noreferrer noopener">vLLM</a> are useful here because they treat inference performance as a tunable discipline. You can tune batching, scheduling and memory behavior to balance throughput with TTFT and TPOT under real concurrency.  </p>



<p><strong>Pattern I rely on:</strong> Separate the front door (API gateway, auth, rate limits) from the batching brain (LLM serving engine). Optimize for TTFT and TPOT, not just concurrency. </p>



<h3 class="wp-block-heading">2) East-to-west traffic quietly eats your latency budget </h3>



<p>RAG workloads are network hungry. A single prompt can trigger: </p>



<ul class="wp-block-list">
<li>embedding lookup  </li>
</ul>



<ul class="wp-block-list">
<li>vector search  </li>
</ul>



<ul class="wp-block-list">
<li>metadata fetch  </li>
</ul>



<ul class="wp-block-list">
<li>document chunk fetch  </li>
</ul>



<ul class="wp-block-list">
<li>rerank  </li>
</ul>



<ul class="wp-block-list">
<li>prompt assembly  </li>
</ul>



<ul class="wp-block-list">
<li>LLM call  </li>
</ul>



<p>Even if each hop is “fast on average,” the p99 gets ugly under load because the pipeline is chatty and synchronous. The system starts to feel like the model is slow when the real issue is that your request spends too much time traveling. </p>



<p><strong>Pattern I rely on:</strong> Collapse hops where possible, co-locate latency sensitive services and treat network round trips as a scarce resource. A simple rule I use is this: Do not let your p99 depend on a long chain of synchronous calls. </p>



<h3 class="wp-block-heading">3) Storage becomes the hidden queue </h3>



<p>In inference systems, storage rarely looks saturated at the device level. The problem is usually the data path: Too many copies, too much CPU involvement and too many small metadata operations that show up as tail latency. </p>



<p>I like to explain the principle using GPUDirect Storage, even if you do not implement it. <a href="https://docs.nvidia.com/gpudirect-storage/overview-guide/index.html" target="_blank" rel="noreferrer noopener">NVIDIA</a> describes GPUDirect Storage as enabling a more direct DMA path between storage and GPU memory, reducing CPU overhead and latency by avoiding extra copies. </p>



<p>You do not need that exact technology to benefit from the lesson. </p>



<p><strong>Pattern I rely on:</strong> Make the data path boring. Fewer copies. Fewer layers. Fewer handoffs. </p>



<h2 class="wp-block-heading">Unified data services beat siloed performance wins </h2>



<p>I have watched teams chase a 20% performance gain in one tier while ignoring the bigger issue: data fragmentation. </p>



<p>If your AI pipeline bounces across disconnected file, object and block systems, you keep paying the hop tax. You also increase the chance that “the right data” is not where the model expects it to be. </p>



<p><a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM’s AI storage</a> framing is helpful because it emphasizes unified storage approaches that consolidate file, block and object services while integrating with existing investments, to deliver data at scale with low latency. </p>



<p>Translated into an enterprise goal, this means fewer copies, fewer bridges and fewer places where tail latency can hide. </p>



<h2 class="wp-block-heading">Content-aware storage and RAG: An underused lever </h2>



<p>Here is a point that does not get enough attention. RAG is not only about models and vector databases. It is also about whether your enterprise can make unstructured data retrievable without turning the data estate into a copy machine. </p>



<p><a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM</a> notes that very little enterprise data is used to train the large language models behind assistants, limiting business value and highlights “content-aware” approaches that extract semantic meaning from unstructured data so assistants can answer more intelligently. </p>



<p>I like this framing because it shifts the conversation from “store more data” to “make data usable where it already lives.” That is often the difference between a RAG system that scales and one that becomes a governance and cost problem. </p>



<h2 class="wp-block-heading">The metrics I track now (and why they work) </h2>



<p>When I am asked what to measure, I keep it simple. I want metrics that map to user experience and capacity decisions. </p>



<h3 class="wp-block-heading">Inference experience </h3>



<ul class="wp-block-list">
<li>TTFT p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>TPOT p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>Tokens per second per GPU  </li>
</ul>



<ul class="wp-block-list">
<li>Queue time before execution  </li>
</ul>



<p><a href="https://github.com/mlcommons/inference_policies/blob/master/inference_rules.adoc?" target="_blank" rel="noreferrer noopener">MLCommons</a> is a good anchor here because TTFT and TPOT are benchmarked precisely to capture user-visible behavior. </p>



<h3 class="wp-block-heading">Network health </h3>



<ul class="wp-block-list">
<li>Service-to-service latency p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>Retransmits and packet loss  </li>
</ul>



<ul class="wp-block-list">
<li>East to west throughput per node  </li>
</ul>



<ul class="wp-block-list">
<li>Queue depth in the network path during peak load  </li>
</ul>



<h3 class="wp-block-heading">Storage health </h3>



<ul class="wp-block-list">
<li>Read latency p95 and p99  </li>
</ul>



<ul class="wp-block-list">
<li>IOPS and bandwidth at the namespace or volume level  </li>
</ul>



<ul class="wp-block-list">
<li>Cache hit rates  </li>
</ul>



<ul class="wp-block-list">
<li>Metadata operation rate and latency (the sleeper issue)  </li>
</ul>



<h3 class="wp-block-heading">System efficiency </h3>



<ul class="wp-block-list">
<li>GPU active time vs waiting time  </li>
</ul>



<ul class="wp-block-list">
<li>CPU utilization and softirq time on serving nodes  </li>
</ul>



<ul class="wp-block-list">
<li>Fan-out per prompt and per request type  </li>
</ul>



<h2 class="wp-block-heading">Two real-world use cases (with quantified outcomes) </h2>



<p>These examples reflect patterns I have seen repeatedly. The numbers are representative and meant to show the shape of the problem, not promise identical results in every environment. </p>



<h3 class="wp-block-heading">Use case 1: RAG assistant that “felt slow” even with plenty of GPU </h3>



<p><strong>Symptoms</strong> </p>



<ul class="wp-block-list">
<li>TTFT p95 drifted from about 0.7s to about 2.2s during peak hours  </li>
</ul>



<ul class="wp-block-list">
<li>TPOT p95 stayed acceptable, but the first response felt delayed  </li>
</ul>



<ul class="wp-block-list">
<li>GPU utilization looked fine, but queue time rose steadily  </li>
</ul>



<p><strong>Root cause</strong> </p>



<ul class="wp-block-list">
<li>Vector search and chunk retrieval created bursty east to west traffic  </li>
</ul>



<ul class="wp-block-list">
<li>Too many synchronous hops and too little caching of hot content  </li>
</ul>



<ul class="wp-block-list">
<li>Network tail latency amplified fan-out  </li>
</ul>



<p><strong>Fix pattern</strong> </p>



<ul class="wp-block-list">
<li>Co-located vector search and document store for hot shards  </li>
</ul>



<ul class="wp-block-list">
<li>Cached top-k retrieved chunks and prompt templates  </li>
</ul>



<ul class="wp-block-list">
<li>Added asynchronous retrieval and progressive context loading for long documents  </li>
</ul>



<p><strong>Outcome</strong> </p>



<ul class="wp-block-list">
<li>TTFT p95 returned near baseline under similar user load  </li>
</ul>



<ul class="wp-block-list">
<li>Fewer p99 spikes because the pipeline depended on fewer synchronous calls  </li>
</ul>



<ul class="wp-block-list">
<li>Modest improvement in tokens per second because fewer requests stalled on I/O  </li>
</ul>



<h3 class="wp-block-heading">Use case 2: Adding GPUs did not improve throughput </h3>



<p><strong>Symptoms</strong> </p>



<ul class="wp-block-list">
<li>Tokens per second increased only about 10 percent after adding 25 percent more GPUs  </li>
</ul>



<ul class="wp-block-list">
<li>TPOT p99 worsened under concurrency  </li>
</ul>



<ul class="wp-block-list">
<li>CPU utilization spiked on serving nodes  </li>
</ul>



<p><strong>Root cause</strong> </p>



<ul class="wp-block-list">
<li>Serving layer batching and memory churn wasted GPU cycles  </li>
</ul>



<ul class="wp-block-list">
<li>Storage path added extra copies and CPU overhead for artifacts  </li>
</ul>



<ul class="wp-block-list">
<li>Scheduling placed workloads on nodes without the right NIC or storage locality  </li>
</ul>



<p><strong>Fix pattern</strong> </p>



<ul class="wp-block-list">
<li>Tuned the serving engine to match request size distribution and concurrency behavior (vLLM tuning is a good reference point for this type of work)  </li>
</ul>



<ul class="wp-block-list">
<li>Improved device-aware placement using Kubernetes device plugin patterns so specialized hardware is advertised cleanly to the scheduler  </li>
</ul>



<ul class="wp-block-list">
<li>Reduced CPU bounce buffering behavior in the data path where feasible  </li>
</ul>



<p><a href="https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/" target="_blank" rel="noreferrer noopener">The Kubernetes device plugin framework</a> is the simple building block behind making “specialized resources” schedulable at scale. </p>



<p><strong>Outcome</strong> </p>



<ul class="wp-block-list">
<li>More linear scaling as GPUs were added  </li>
</ul>



<ul class="wp-block-list">
<li>Stabilized TPOT p99 because fewer requests were blocked behind slow neighbors  </li>
</ul>



<ul class="wp-block-list">
<li>Reduced CPU overhead, freeing headroom for networking and observability  </li>
</ul>



<h2 class="wp-block-heading">Open source that fits these patterns </h2>



<p>You can implement most of these improvements using open-source components: </p>



<ul class="wp-block-list">
<li><strong>Observability:</strong> Prometheus, Grafana, OpenTelemetry and eBPF-based tooling to see flow-level latency and fan-out.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Caching:</strong> Redis for hot key/value caching; local NVMe caches for hot artifacts.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Serving:</strong> <a href="https://docs.vllm.ai/en/stable/configuration/optimization/" target="_blank" rel="noreferrer noopener">vLLM</a> for configurable batching and memory behavior under load. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Scheduling:</strong> Kubernetes device plugins and resource-aware node pools for GPU and NIC locality. (Kubernetes device plugins:)  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Storage:</strong> Ceph is a common open-source option for software-defined block, file and object patterns. IBM also calls out <a href="https://www.ibm.com/solutions/ai-storage" target="_blank" rel="noreferrer noopener">IBM AI Storage</a> Ceph as an open source, software-defined approach aligned to these needs.  </li>
</ul>



<h2 class="wp-block-heading">Limitations and tradeoffs </h2>



<p>Every performance win has an operational cost. These are the tradeoffs I plan for. </p>



<ol start="1" class="wp-block-list">
<li>Caching improves consistency, but invalidation is hard. Freshness, permissions and compliance requirements complicate “simple” caches.  </li>
</ol>



<ol start="2" class="wp-block-list">
<li>Device-aware scheduling improves performance, but increases complexity. You introduce <a href="https://kubernetes.io/docs/concepts/extend-kubernetes/compute-storage-net/device-plugins/" target="_blank" rel="noreferrer noopener">Kubernetes device plugins</a>, operators and topology awareness. It is worth it, but it must be managed. </li>
</ol>



<ol start="3" class="wp-block-list">
<li>Reducing copies can improve latency, but raises platform constraints. Direct data paths reduce CPU overhead, but they come with configuration and compatibility requirements.  </li>
</ol>



<ol start="4" class="wp-block-list">
<li>Unifying data services reduces silos, but consolidation needs governance. A unified approach can reduce hop tax, but only if access control, lifecycle policies and ownership are clear.  </li>
</ol>



<h2 class="wp-block-heading">Future scope: What will matter more next </h2>



<p>Over the next 12 to 24 months, I expect four themes to grow: </p>



<ul class="wp-block-list">
<li><strong>AI SLOs become standard:</strong> TTFT and TPOT become operational targets, not just benchmark terms.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>Workload placement becomes policy-driven:</strong> Placement logic becomes strategic, spanning hybrid footprints.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>More GPU-centric data paths:</strong> Fewer CPU copies and less context switching where possible.  </li>
</ul>



<ul class="wp-block-list">
<li><strong>RAG becomes “information supply chain” first:</strong> Content-aware approaches and unified data services reduce re-copying and re-governing the same data. </li>
</ul>



<h2 class="wp-block-heading">What I would tell a CIO in an elevator pitch </h2>



<p>If you want AI to feel fast and reliable, stop treating it like a model deployment and start treating it like a distributed system with strict tail latency expectations. </p>



<p>Measure TTFT and TPOT in percentiles. Map your pipeline fan-out. Make network and storage visible. Then apply disciplined patterns: Isolate lanes, cache aggressively, schedule intelligently, reduce copies in the data path and unify data services where it makes sense. </p>



<p>Your GPUs will thank you, but more importantly, your users will. </p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br></strong><a href="https://www.networkworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA['Ads Are Popping Up On the Fridge and It Isn't Going Over Well']]></title>
<description><![CDATA[The Wall Street Journal reports:
Walking into his kitchen, Tim Yoder recoiled at a message on his refrigerator door: "Shop Samsung water filters." Yoder, a supply-chain manager in Chicago, owns a Samsung Electronics Family Hub fridge. He paid $1,400 for an appliance that came with a 32-inch scree...]]></description>
<link>https://tsecurity.de/de/3389407/it-security-nachrichten/ads-are-popping-up-on-the-fridge-and-it-isnt-going-over-well/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3389407/it-security-nachrichten/ads-are-popping-up-on-the-fridge-and-it-isnt-going-over-well/</guid>
<pubDate>Sat, 28 Mar 2026 18:13:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Wall Street Journal reports:
Walking into his kitchen, Tim Yoder recoiled at a message on his refrigerator door: "Shop Samsung water filters." Yoder, a supply-chain manager in Chicago, owns a Samsung Electronics Family Hub fridge. He paid $1,400 for an appliance that came with a 32-inch screen on the door that allows him to control other Samsung gadgets, pull up recipes or stream music. But since last fall, it's been intermittently serving up ads, part of a pilot program being tested on some of Samsung's smart fridges sold in the U.S. The response? Not warm. "I guess this is another place for somebody to shove an ad in your face," said the 47-year-old Yoder, recalling the first time he noticed one... 

The ads are only on certain Family Hub fridges that have screens and internet connectivity. They run as a rectangular banner at the bottom — part of a widget that also shows news, the weather and a calendar. Samsung declined to say how long the pilot might last or whether it would end. The firm recently unveiled a "Screens Everywhere" initiative that also includes washers, dryers and ovens.... Samsung launched the banner-type fridge ads that come as part of the widget via an October software update. In a footnote of a news release at the time, Samsung pledged to "serve contextual or non-personal ads" and respect data privacy. The banner ads can be turned off in settings. 


Samsung said the purpose of the pilot is to explore whether ads relevant to home chores can be useful to owners, and that overall pushback has been negligible. The "turn-off" rate for the pilot ad program remains in the bottom single-digit range, it said... While owners can turn off the banner ads, doing so eliminates the widget altogether, a bummer for Brian Bosworth, a media-industry engineer who liked the feature. Bosworth thinks it's wrong to take away the new feature as a condition. Wanting to keep the widget but not the ads, the 49-year-old in Edgewater, Md., made sure his home router's ad-blocking software extended to his fridge. He hasn't seen another since. 


One 27-year-old plans to return his refrigerator after the entire display "lit up with a full-screen ad for Apple TV's sci-fi show Pluribus," according to the article. The all-caps ad beckoned him "with an oft-used refrain directed at protagonist Carol Sturka: 'We're Sorry We Upset You, Carol.'"


 

Thanks to Slashdot reader fjo3 for sharing the article.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Ads+Are+Popping+Up+On+the+Fridge+and+It+Isn't+Going+Over+Well'%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F03%2F28%2F0537232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F03%2F28%2F0537232%2Fads-are-popping-up-on-the-fridge-and-it-isnt-going-over-well%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/03/28/0537232/ads-are-popping-up-on-the-fridge-and-it-isnt-going-over-well?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mark Zuckerberg offered to 'help' Elon Musk with DOGE in 2025]]></title>
<description><![CDATA[Elon Musk and Mark Zuckerberg have a complicated history. In 2023, the two vowed to fight each other in a cage match that never happened. But by early 2025, when both were cozying up to the newly-elected President Donald Trump, they were apparently on more friendly terms. In February of that year...]]></description>
<link>https://tsecurity.de/de/3387746/it-nachrichten/mark-zuckerberg-offered-to-help-elon-musk-with-doge-in-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387746/it-nachrichten/mark-zuckerberg-offered-to-help-elon-musk-with-doge-in-2025/</guid>
<pubDate>Fri, 27 Mar 2026 22:31:31 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Elon Musk and Mark Zuckerberg have a complicated history. In 2023, the two vowed to fight each other in a cage match that <a target="_blank" class="link" href="https://www.engadget.com/looks-like-the-zuck-vs-musk-fight-isnt-happening-195538503.html" data-i13n="cpos:1;pos:1">never happened</a>. But by early 2025, when both were cozying up to the newly-elected President Donald Trump, they were apparently on more friendly terms. </p><p>In February of that year, Zuckerberg <a target="_blank" class="link" href="https://storage.courtlistener.com/recap/gov.uscourts.cand.433688/gov.uscourts.cand.433688.454.3.pdf" data-i13n="cpos:2;pos:1">texted</a> Musk approvingly about his work with the <a target="_blank" class="link" href="https://www.reuters.com/world/us/doge-doesnt-exist-with-eight-months-left-its-charter-2025-11-23/" data-i13n="cpos:3;pos:1">now-defunct</a> Department of Government Efficiency (DOGE). "Looks like DOGE is making progress," the Meta CEO texted. "I've got our teams on alert to take down content doxxing or threatening the people on your team. Let me know if there's anything else I can do to help."</p><p>The texts, which were published Friday in court documents as part of Musk's <a target="_blank" class="link" href="https://www.engadget.com/elon-musk-sues-openai-and-sam-altman-for-allegedly-ditching-non-profit-mission-160722736.html" data-i13n="cpos:4;pos:1">lawsuit</a> against Sam Altman and OpenAI, are dated February 3, 2025. That's just a few weeks after Zuckerberg announced Meta's <a target="_blank" class="link" href="https://www.engadget.com/social-media/meta-is-ditching-third-party-fact-checkers-on-facebook-instagram-142330246.html" data-i13n="cpos:5;pos:1">pivot away</a> from content moderation in favor of "free expression." It's also the same day that a US Attorney said he would <a target="_blank" class="link" href="https://x.com/EagleEdMartin/status/1886456136032817488" data-i13n="cpos:6;pos:1">protect DOGE</a> employees from "disgruntled" critics. </p><p>Musk responded to Zuckerberg's message with a heart and followed up with an unrelated topic: OpenAI. He asked Zuckerberg if he was "open to the idea of bidding on the OpenAI IP with me and some others." Zuckerberg asked to "discuss it live" and Musk said he would call the next day. Previous documents disclosed in the case show that Musk had <a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=34e37b9c-8975-48da-aa39-df8bcd5badc3&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=1ad584c3-e98c-4331-b9ea-5a45a27acb8c&amp;featureId=text-link&amp;merchantName=CNBC&amp;linkText=invited+Zuckerberg&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5jbmJjLmNvbS8yMDI1LzA4LzIxL2Vsb24tbXVzay1hc2tlZC1tZXRhLWNlby1tYXJrLXp1Y2tlcmJlcmctdG8tam9pbi14YWktYmlkLXRvLWJ1eS1vcGVuYWkuaHRtbCIsImNvbnRlbnRVdWlkIjoiMWFkNTg0YzMtZTk4Yy00MzMxLWI5ZWEtNWE0NWEyN2FjYjhjIiwib3JpZ2luYWxVcmwiOiJodHRwczovL3d3dy5jbmJjLmNvbS8yMDI1LzA4LzIxL2Vsb24tbXVzay1hc2tlZC1tZXRhLWNlby1tYXJrLXp1Y2tlcmJlcmctdG8tam9pbi14YWktYmlkLXRvLWJ1eS1vcGVuYWkuaHRtbCJ9&amp;signature=AQAAAd1rtBxzTwv8qZ5psoFFr3KZ2146aTcX5iVInZuZ-fmR&amp;gcReferrer=https%3A%2F%2Fwww.cnbc.com%2F2025%2F08%2F21%2Felon-musk-asked-meta-ceo-mark-zuckerberg-to-join-xai-bid-to-buy-openai.html" data-i13n="elm:affiliate_link;sellerN:CNBC;elmt:;cpos:7;pos:1" data-original-link="https://www.cnbc.com/2025/08/21/elon-musk-asked-meta-ceo-mark-zuckerberg-to-join-xai-bid-to-buy-openai.html">invited Zuckerberg</a> to help him buy OpenAI, though he never officially signed on to the bid.</p><p>In a separate filing also made public Friday, Musk's lawyers argued that his exchanges with the Meta CEO ought to be excluded from the lawsuit. "Musk’s personal relationships and communications – including with other high-profile individuals – are also tangential and prejudicial," they wrote. "Defendants included in their exhibit list for trial, for example, several private exchanges between Musk and Mark Zuckerberg discussing Musk’s political activity and this lawsuit. Those recent communications have nothing to do with Musk’s claims and are nothing more than Defendants’ attempt to stoke negative sentiments toward Musk because of his association with Zuckerberg."</p><p>A Meta spokesperson declined to comment. </p><p>In the same filing, Musk's lawyers also take issue with Altman's lawyers asking about Musk's alleged ketamine use and his attendance at Burning Man. A <a target="_blank" class="link" href="https://storage.courtlistener.com/recap/gov.uscourts.cand.433688/gov.uscourts.cand.433688.454.2.pdf" data-i13n="cpos:8;pos:1">transcript</a> from a video deposition with Musk indicated he was asked if had taken "rhino ket" at Burning Man in 2017.  Musk said no, according to the transcript. </p><p>"Any implication that music festivals or drugs have any relevance to this case is outlandish, and how Musk spends his free time is equally irrelevant," his lawyers wrote. A judge ruled <a target="_blank" class="link" href="https://www.bloomberg.com/news/articles/2026-03-13/elon-musk-s-ketamine-use-can-t-be-probed-in-openai-fraud-trial" data-i13n="cpos:9;pos:1">earlier this month</a> that OpenAI's lawyers would be permitted to ask "limited" questions about Burning Man, but not ketamine. </p>This article originally appeared on Engadget at https://www.engadget.com/big-tech/mark-zuckerberg-offered-to-help-elon-musk-with-doge-in-2025-211737138.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[All iPhone 18 models will get a smaller Dynamic Island, says optimistic leak]]></title>
<description><![CDATA[It could be wishful thinking, but a tiny new leak appears to suggest that Apple will shrink the Dynamic Island on every iPhone 18.The Dynamic Island is Apple's way of making a virtue out of the necessary Face ID and camera notchSince the very day the iPhone X was launched with its Face ID notch, ...]]></description>
<link>https://tsecurity.de/de/3386393/ios-mac-os/all-iphone-18-models-will-get-a-smaller-dynamic-island-says-optimistic-leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3386393/ios-mac-os/all-iphone-18-models-will-get-a-smaller-dynamic-island-says-optimistic-leak/</guid>
<pubDate>Fri, 27 Mar 2026 13:25:08 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It could be wishful thinking, but a tiny new leak appears to suggest that Apple will shrink the Dynamic Island on every <a href="https://appleinsider.com/inside/iphone-18" title="iPhone 18" data-kpt="1">iPhone 18</a>.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67166-141238-000-lede-Dynamic-Island-xl.jpg" alt="Close-up of an iPhone screen showing Dynamic Island at top and home screen widgets below, including Oakland weather at 70 degrees and a Find My map with friend's Memoji location"><br><span>The Dynamic Island is Apple's way of making a virtue out of the necessary Face ID and camera notch</span></div><br>Since the very day the iPhone X was launched with its <a href="https://appleinsider.com/inside/face-id" title="Face ID" data-kpt="1">Face ID</a> notch, there have <a href="https://appleinsider.com/articles/26/03/26/iphone-dynamic-island-isnt-going-away-yet-but-its-days-are-numbered">been rumors</a> that Apple will switch to an all-screen display with no visible cutouts. The company is surely working toward this, but the most recent claims have focused on how it might reduce the current Dynamic Island.<br><br>Now according to leaker Ice Universe, that smaller Dynamic Island is <a href="https://weibo.com/5673255066/Qy0xWq83o">definitely coming</a> to the iPhone 18.<br><br><br> <a href="https://appleinsider.com/articles/26/03/27/all-iphone-18-models-will-get-a-smaller-dynamic-island-says-optimistic-leak?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243853?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone Dynamic Island isn't going away yet, but its days are numbered]]></title>
<description><![CDATA[Apple's push toward a true all-screen iPhone is coming into focus again, with a new leak outlining a timed shift away from the Dynamic Island toward hidden sensors.iPhone 18 render with a smaller Dynamic IslandChinese leaker Digital Chat Station claims Apple plans to shrink and relocate its front...]]></description>
<link>https://tsecurity.de/de/3384140/ios-mac-os/iphone-dynamic-island-isnt-going-away-yet-but-its-days-are-numbered/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3384140/ios-mac-os/iphone-dynamic-island-isnt-going-away-yet-but-its-days-are-numbered/</guid>
<pubDate>Thu, 26 Mar 2026 17:53:33 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's push toward a true all-screen <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> is coming into focus again, with a new leak outlining a timed shift away from the Dynamic Island toward hidden sensors.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67154-141213-iPhone-18-Pro-Max-small-Dynamic-Island-xl.jpg" alt="Close-up of a smartphone lock screen showing time 12:55, date Fri Jan 23, cloudy sky wallpaper, and status icons for WiFi, signal strength, and battery at the top"><br><span>iPhone 18 render with a smaller Dynamic Island</span></div><br>Chinese leaker Digital Chat Station claims Apple plans to shrink and relocate its front-facing sensors under the display over time. The shift would move from the current Dynamic Island to a smaller cutout, then to a single punch hole with <a href="https://appleinsider.com/inside/face-id" title="Face ID" data-kpt="1">Face ID</a> hidden beneath the screen.<br><br>The roadmap is unconfirmed, but <a href="https://appleinsider.com/articles/26/03/24/apples-all-screen-iphone-isnt-coming-soon">it lines up</a> with years of supply chain reports and analyst expectations. Apple has been steadily working to remove visible display cutouts without sacrificing Face ID performance.<br><br><br> <strong>Rumor Score:</strong> 🤯 Likely <br><br><br> <a href="https://appleinsider.com/articles/26/03/26/iphone-dynamic-island-isnt-going-away-yet-but-its-days-are-numbered?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243841?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise laptops adopt Intel’s new Core Ultra Series 3 chips]]></title>
<description><![CDATA[Intel’s Core Ultra Series 3 processors with Intel vPro, built for business PCs, are off to a fast start, already powering more than 125 designs including newly-announced systems from Dell and HP, the company said.



Unveiled this week at an event in New York City, the Core Ultra Series 3 with In...]]></description>
<link>https://tsecurity.de/de/3384058/it-nachrichten/enterprise-laptops-adopt-intels-new-core-ultra-series-3-chips/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3384058/it-nachrichten/enterprise-laptops-adopt-intels-new-core-ultra-series-3-chips/</guid>
<pubDate>Thu, 26 Mar 2026 17:31:37 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Intel’s Core Ultra Series 3 processors with Intel vPro, built for business PCs, are off to a fast start, already powering more than 125 designs including newly-announced systems from Dell and HP, the company said.</p>



<p>Unveiled this week at an event in New York City, the Core Ultra Series 3 with Intel vPro brings what Intel described as “next-generation performance efficiency and integrated AI acceleration,” as well as providing an enhanced vPro management platform. </p>



<p>The company first announced the <a href="https://www.computerworld.com/article/4070872/intel-bets-on-on-device-ai-and-us-fabs-to-power-the-next-generation-of-pcs.html">Core Ultra Series 3 processors in October 2025</a>. Previously <a href="https://www.pcworld.com/article/3033650/panther-lake-isnt-just-a-laptop-chip-its-intels-hail-mary.html">codenamed Panther Lake</a>, they will also appear in new consumer PCs.</p>



<p>Users of systems running on the new chips will see over 30% faster performance, up to 80% better graphics, and up to 4x AI performance compared to four-year-old systems, the average PC refresh period for businesses, according to Intel.</p>



<p>While the new systems can run code faster, Intel is also pushing for them to be more intelligent about the code they do run. Enhancements to vPro include the Intel vPro Certification Program that Intel said results in as much as 59% reduced CPU utilization, a 74% reduction in background activity, and power efficiency improved by 56%.</p>



<p>AI is also playing a bigger role in the form of vPro Intelligence with Device IQ, which offers AI-driven analytics to detect, diagnose, and resolve issues. There’s also vPro Fleet Services to simplify out-of-band manageability via a fully managed SaaS-based activation and integration with Microsoft Intune, and security enhancements including Intel Total Storage Encryption for Microsoft BitLocker and AI-based threat detection using Intel’s chip-based Threat Detection technology (DTECT).</p>



<p>Business PCs incorporating these technologies will be available beginning on March 31.</p>



<p>Dell has launched an updated Dell Pro Notebook lineup which includes devices powered by the Intel Core Ultra Series 3 processor. It offers models with and without vPro.</p>



<p>The Dell Pro Premium is designed for on-the-go executives and managers; the Dell Pro 7 is for users such as consultants and sales professionals who need systems that are portable, yet capable; the Dell Pro 5, the company said, provides mobility for users such as financial analysts while maintaining the performance they need for their business applications; and the Dell Pro 3 was created for users who run core productivity applications such as email, document creation, and collaboration.</p>



<p>The Dell Pro Premium will be available on March 31, and the other models will hit the shelves in May. Pricing has not yet been announced.</p>



<p>HP’s refreshed portfolio for business includes 31 new models powered by Intel, AMD, and Arm processors. Intel-powered devices include multiple configurations in the EliteBook 8 G2 series, an AI PC designed for knowledge workers, and the EliteBook 6 G2 series for mobile professionals and office collaborators. Other models are directed at the SMB market. The company also announced the EliteDesk 8 G2 for enterprise workers.</p>



<p>The EliteBook 8 G2 devices are expected to be available in April, as are the EliteDesk models. The EliteBook 6 G2 is scheduled for June. Pricing has not yet been announced.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe coding your own enterprise apps is edgy business]]></title>
<description><![CDATA[With AI coding assistants rapidly advancing, some organizations are pushing the AI-aided application development concept further by engineering enterprise-grade tools to replace or extend traditional software.



While a trend toward vibe coding your own enterprise software appears to be in its i...]]></description>
<link>https://tsecurity.de/de/3382800/it-security-nachrichten/vibe-coding-your-own-enterprise-apps-is-edgy-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382800/it-security-nachrichten/vibe-coding-your-own-enterprise-apps-is-edgy-business/</guid>
<pubDate>Thu, 26 Mar 2026 11:20:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With AI coding assistants rapidly advancing, some organizations are pushing the AI-aided application development concept further by engineering enterprise-grade tools to replace or extend traditional software.</p>



<p>While a trend toward <a href="https://www.infoworld.com/article/4129667/how-vibe-coding-will-supercharge-it-teams.html?utm=hybrid_search'">vibe coding</a> your own enterprise software appears to be in its infancy, some companies have reportedly <a href="https://www.wsj.com/cio-journal/meet-the-companies-vibe-coding-their-own-crms-263e500f" rel="nofollow">replaced their traditional CRMs</a> with homegrown applications.</p>



<p>In recent weeks, stock prices of traditional SaaS vendors have taken hits over worries about competition from AI. Much of concern has focused on customers <a href="https://www.cio.com/article/4137661/cios-cut-it-corners-to-manufacture-budget-for-ai.html">spending less on SaaS as they ramp up AI deployment</a> and on AI agents taking over some functionality of SaaS platforms.</p>



<p>But some experts contend that customers may also opt out of some SaaS subscriptions entirely as they roll their own replacements. While major SaaS platforms may not be in danger, smaller enterprise apps that connect to them may increasingly be deployed in house by companies using AI coding assistants or deploying home-grown agents.</p>



<p>IT leaders should beware, however, that significant challenges exist. Replacing road-tested enterprise software packages with <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html?utm=hybrid_search">vibe-coded apps</a> is risky, with the responsibility of maintenance and support falling on the deploying organization.</p>



<h2 class="wp-block-heading">Vibe coding vs. buying</h2>



<p>Nevertheless, AI coding agent vendor Factory has been eating its own dog food by building some of its own enterprise apps, says <a href="https://www.linkedin.com/in/enoreyes/" rel="nofollow">Eno Reyes</a>, CTO and cofounder there. Several of Factory’s customers are doing the same thing, he adds.</p>



<p>In the past six to eight months, the company has started asking whether it can build a software package itself instead of buying or subscribing, he says. Factory’s customer support workflow and its legal tooling were built internally with AI agents, and the company replaced a third-party analytics app with an internal build.</p>



<p>“Internally, we’ve started building a lot of things that historically we would have bought,” Reyes says. “A lot of our internal workflow systems are just code that the agents produced.”</p>



<p>He sees the same trend among customers. “A lot of the tools they used to buy are small utilities or micro-SaaS products,” he says. “With an agent, someone can just say, ‘Build me a dashboard that shows engineering velocity’ or ‘connect this dataset with this one and visualize it.’ Instead of going through procurement, the tool just gets built.”</p>



<p>The advantages of building your own software include flexibility and speed, Reyes adds. “If you want something very specific, an agent can generate it directly against your own data, systems, and workflows,” he says. “That’s why things like internal dashboards, analytics tools, or small workflow apps are often easier to build than buy now.”</p>



<h2 class="wp-block-heading">The cost of doing it yourself</h2>



<p>But there are also real disadvantages, with the costs of building your own internal apps and the maintenance of the software being major considerations, Reyes cautions.</p>



<p>“Even though agents can generate software, a full SaaS product usually exists because a large team has spent years maintaining it,” Reyes adds. “When we run our internal benchmark where agents replicate SaaS products feature by feature, the agent can do it, but it takes a long time to run and it’s expensive. And when it’s finished, you still don’t have a team of hundreds of people maintaining the system.”</p>



<p>Another potential problem is the scope of the software being built. “Tools like vibe-coding apps can produce smaller applications easily,” Reyes says. “But when you’re talking about complex enterprise systems, the software gets large very quickly, and you need infrastructure that can manage and maintain that codebase over time.”</p>



<p>With these potential downsides, Reyes doesn’t see vibe-coding AI apps replacing all established SaaS platforms anytime soon. Enterprise apps like Slack, with strong network effects, will survive, as will systems — like Salesforce’s CRM — that function as a core source of truth, he says.</p>



<p>Instead, AI coding assistants and agents will compete with apps that form the layer around major enterprise systems, Reyes predicts. Tools that simply connect other products, visualize internal data, or provide small workflow utilities are easier to generate on demand, he says.</p>



<p><a href="https://www.linkedin.com/in/adamrossarellano/" rel="nofollow">Adam Arellano,</a> field CTO at AI-powered dev tools vendor Harness, also sees some push toward organizations developing their own enterprise software, but he warns about the pitfalls.</p>



<p>“This is happening a lot, with some extreme cases where a C-suite leader has mandated ‘no new software purchases or headcount, do it with AI,’” he says. “There are other more reasonable approaches where a company has built point solutions for very specific problems and found certain levels of success that are useful in the short term but sometimes flounder after a while.”</p>



<p>The advantages of vibe coding your own enterprise software include the satisfaction of quickly building a tool for a specific need, Arellano adds. But maintaining the vibe-coded software and getting it to work with other apps can be a challenge, he says.</p>



<p>“Not unique to vibe-coded tools, this has always been the hard part of point solutions in the enterprise, but getting point solutions to reliably function and play nicely with larger platforms or programs of record takes work,” he says. “Vibe coding makes the problem urgent because the speed at which these tools can be produced is so much faster than enterprises can integrate their outputs, understand how they work, and maintain their connections.”</p>



<p>In the immediate future, vibe coding critical internal apps isn’t likely to save much money or time, unless the process is well governed, he says, noting <a href="https://www.computerworld.com/article/4145573/amazon-finds-out-ai-programming-isnt-all-its-cracked-up-to-be.html">recent outages at AWS</a> related to AI-generated code.</p>



<p>However, improvements in AI coding assistants will make it easier over the long term for companies to develop their own enterprise software, Arellano says. “It will take a while and like any new tech or tool, the road to good will be littered with the broken remains of ‘almost good enough, but not quite’ tools,” he adds. “A lot of things are going to break in the meantime.”</p>



<h2 class="wp-block-heading">Seduced by AI coding assistants</h2>



<p>Other IT leaders see major risks with vibe coding enterprise software. The practice has a “seduction phase,” says <a href="https://www.linkedin.com/in/geoff-burke-0a174684/" rel="nofollow">Geoff Burke</a>, senior technology advisor at ransomware defense vendor Object First.</p>



<p>“At first, it feels like a brilliant partner,” he explains. “But give it too much autonomy and it injects inaccuracies, complexity, and bypasses security norms, which you will spend twice as long cleaning up later.”</p>



<p>AI-assisted development should operate within strict access controls, diligent peer review, robust testing, and isolation from sensitive information and production environments, Burke says.</p>



<p>“Companies are bolting on AI to look modern, which may be fine in parts of the stack, but in core development workflows and repositories, CIOs should not chase trends that rely on experimental AI to make critical decisions about code and data integrity,” he adds.</p>



<p>Vibe coding with strict controls may produce good results, but if employees outside the IT team quietly create their own workarounds using AI coding assistants, chaos can ensue, adds <a href="https://www.fusioncollective.net/meet-the-team/co-founder-cto/" rel="nofollow">Blake Crawford</a>, cofounder and CTO at IT consulting firm Fusion Collective.</p>



<p>There’s huge potential for <a href="https://www.infoworld.com/article/4098925/is-vibe-coding-the-new-gateway-to-technical-debt.html?utm=hybrid_search">crippling technical debt</a> when all employees feel free to create their own enterprise apps without supervision, he says. Most veteran IT professionals will know the strengths and weaknesses of AI-generated software, but an accounts payable clerk creating add-on apps for his SAP workflow may not, he adds.</p>



<p>“I use AI coding assistants in my daily practice, but I’m more than 25 years into my dedicated technology career,” he says. “I understand what AI coding assistants are good at, and even more importantly, what ‘good’ looks like in software development. That allows me to intercept problems quickly and avert any additional tech debt.”</p>



<p>AI assistants are showing up at many companies that don’t focus on IT products, and in many cases, employees and leaders have major questions about the best way to use them, Crawford says.</p>



<p>“With vibe coding, a company then owns what is made, right down to the problems it creates,” he says. “An enterprise doesn’t work well if it’s stitched together with myriad apps, many of which will be misused and grow beyond their scope, making everything from support to integration a problem.”</p>



<p>Crawford sees the temptation to roll your own enterprise apps growing as AI coding assistants improve, but he urges caution.</p>



<p>“There will be a serious retraction when the bill comes due on poor architectures and accumulated technical debt,” he says. “If companies aren’t careful, leaders will be looking at years, if not decades, worth of issues to deal with.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Epic CEO Confirms 1,000+ Layoffs, Says “This Isn’t Related to AI”]]></title>
<description><![CDATA[Epic Games will lay off more than 1,000 employees as the company deals with a slowdown in Fortnite, according to a message from CEO Tim…
The post Epic CEO Confirms 1,000+ Layoffs, Says “This Isn’t Related to AI” appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3380310/windows-tipps/epic-ceo-confirms-1000-layoffs-says-this-isnt-related-to-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380310/windows-tipps/epic-ceo-confirms-1000-layoffs-says-this-isnt-related-to-ai/</guid>
<pubDate>Wed, 25 Mar 2026 14:41:13 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Epic Games will lay off more than 1,000 employees as the company deals with a slowdown in Fortnite, according to a message from CEO Tim…</p>
<p>The post <a href="https://onmsft.com/news/epic-ceo-confirms-1000-layoffs-says-this-isnt-related-to-ai/">Epic CEO Confirms 1,000+ Layoffs, Says “This Isn’t Related to AI”</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[is ubuntu dying?]]></title>
<description><![CDATA[Everyone hate ubuntu these days and if someone say i use ubuntu, people in comments suggest use better distro. isnt ubuntu better anymore? what is most people's prefrence now a days. snaps are most hated but don't see any problem so far.    submitted by    /u/DayInfinite8322   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3378606/linux-tipps/is-ubuntu-dying/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378606/linux-tipps/is-ubuntu-dying/</guid>
<pubDate>Wed, 25 Mar 2026 03:53:40 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Everyone hate ubuntu these days and if someone say i use ubuntu, people in comments suggest use better distro.</p> <p>isnt ubuntu better anymore? what is most people's prefrence now a days.</p> <p>snaps are most hated but don't see any problem so far.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/DayInfinite8322"> /u/DayInfinite8322 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1s2yjhf/is_ubuntu_dying/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s2yjhf/is_ubuntu_dying/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Prevention Isn’t Enough: Shifting to True Operational Resilience in 2026]]></title>
<description><![CDATA[Enterprises must move beyond prevention to prioritize identity resilience, rapid containment, and recovery as core cybersecurity capabilities. The post Why Prevention Isn’t Enough: Shifting to True Operational Resilience in 2026 appeared first on eSecurity Planet. This article has been indexed…
R...]]></description>
<link>https://tsecurity.de/de/3378241/it-security-nachrichten/why-prevention-isnt-enough-shifting-to-true-operational-resilience-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378241/it-security-nachrichten/why-prevention-isnt-enough-shifting-to-true-operational-resilience-in-2026/</guid>
<pubDate>Tue, 24 Mar 2026 22:50:50 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises must move beyond prevention to prioritize identity resilience, rapid containment, and recovery as core cybersecurity capabilities. The post Why Prevention Isn’t Enough: Shifting to True Operational Resilience in 2026 appeared first on eSecurity Planet. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-prevention-isnt-enough-shifting-to-true-operational-resilience-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-prevention-isnt-enough-shifting-to-true-operational-resilience-in-2026/">Why Prevention Isn’t Enough: Shifting to True Operational Resilience in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's all-screen iPhone isn't coming soon]]></title>
<description><![CDATA[The iPhone's Dynamic Island will be sticking around for a while, but will get smaller over time, as Apple is reportedly struggling to make its visible sensors work under the display.Under-screen displays could remove the Dynamic Island, and even introduce features like the return of Touch ID. - I...]]></description>
<link>https://tsecurity.de/de/3377227/ios-mac-os/apples-all-screen-iphone-isnt-coming-soon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377227/ios-mac-os/apples-all-screen-iphone-isnt-coming-soon/</guid>
<pubDate>Tue, 24 Mar 2026 16:24:21 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone's</a> Dynamic Island will be sticking around for a while, but will get smaller over time, as Apple is reportedly struggling to make its visible sensors work under the display.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67130-141126-66666-139786-000-lead-Touch-ID-xl-xl.jpg" alt="Foldable smartphone displaying a large colorful fingerprint and text Touch ID on its screen, with a blurred green succulent plant in a metallic pot in the background"><br><span>Under-screen displays could remove the Dynamic Island, and even introduce features like the return of Touch ID. - Image Credit: Apple</span></div><br>Apple, like other smartphone producers, is always trying to make the optimum form of the smartphone. The all-screen concept relies on Apple getting rid of all intrusive elements from the front of the device, and that means working to hide or eliminate the bit with the TrueDepth camera array.<br><br>In a <a href="https://weibo.com/5821279480/5280009058517269">Tuesday post</a> to Weibo, serial leaker Fixed Focus Digital claims that Apple is still struggling to create its all-screen device. For the moment, with full-screen displays off the table for a while longer, Apple instead wants to make things smaller.<br><br><br> <strong>Rumor Score:</strong> 🤯 Likely <br><br><br> <a href="https://appleinsider.com/articles/26/03/24/apples-all-screen-iphone-isnt-coming-soon?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243804?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The person who could be Apple CEO: Who is John Ternus?]]></title>
<description><![CDATA[All things considered, John Ternus is the center of speculation as being the best and most likely choice for control of the company. Who is he, and how did he get here?John TernusApple, like many other massive companies with giant workforces and a decades-long history, have to plan for the future...]]></description>
<link>https://tsecurity.de/de/3373621/ios-mac-os/the-person-who-could-be-apple-ceo-who-is-john-ternus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3373621/ios-mac-os/the-person-who-could-be-apple-ceo-who-is-john-ternus/</guid>
<pubDate>Mon, 23 Mar 2026 14:09:19 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[All things considered, <a href="https://appleinsider.com/inside/john-ternus" title="John Ternus" data-kpt="1">John Ternus</a> is the center of speculation as being the best and most likely choice for control of the company. Who is he, and how did he get here?<br><br><div><img src="https://photos5.appleinsider.com/gallery/66473-139434-johnternusheader-xl.jpg" alt="Man in a blue T-shirt speaking with hand gestures, standing against an aerial view of a circular office campus surrounded by trees and city buildings" height="738"><br><span>John Ternus</span></div><br>Apple, like many other massive companies with giant workforces and a decades-long history, have to plan for the future direction of the company. Part of that preparation involves determining who will take <a href="https://appleinsider.com/articles/25/11/15/apples-succession-planning-efforts-step-up-to-find-tim-cooks-replacement">control as CEO</a> after the current leader departs, and what to do to prepare for that inevitability.<br><br>For Apple and its aging leadership, Apple has to find its replacement for <a href="https://appleinsider.com/inside/tim-cook" title="Tim Cook" data-kpt="1">Tim Cook</a>. Even though Cook probably won't be <a href="https://appleinsider.com/articles/25/11/23/apple-ceo-tim-cook-isnt-retiring-in-2026">retiring in 2026</a>, the sheer size and number of moving parts at Apple means it has to prepare now, so there's enough of a runway for the heir to the position to get ready, as well as the company itself, from 2027 onward.<br><br><br> <a href="https://appleinsider.com/articles/26/03/23/the-person-who-could-be-apple-ceo-who-is-john-ternus?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243212?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Twitter turned 20 and I feel nothing]]></title>
<description><![CDATA[Twitter is officially 20 years old. In another reality, that might make me kind of nostalgic. I've been lurking and scrolling and tweeting for 16 years; most of my adult life. There was a time when Twitter was a place where some internet strangers became my IRL friends, when I was excited to "liv...]]></description>
<link>https://tsecurity.de/de/3369125/it-nachrichten/twitter-turned-20-and-i-feel-nothing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3369125/it-nachrichten/twitter-turned-20-and-i-feel-nothing/</guid>
<pubDate>Sat, 21 Mar 2026 15:02:18 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Twitter is officially 20 years old. In another reality, that might make me kind of nostalgic. I've been lurking and scrolling and tweeting for 16 years; most of my adult life. There was a time when Twitter was a place where some internet strangers became my IRL friends, when I was excited to "live-tweet". When my infinitely more well-adjusted friends would send me memes, I would smugly say "I saw that on Twitter days ago."</p><p>Twitter stopped being that place a long time ago, but I don't have any nostalgia for it. I don't really feel anything at all, actually. </p><p>Because I can already hear the comments: Yes, I'm still on X. I don't spend as much time there as I did a decade ago, but it's still quite a lot of time, an <em>unhealthy</em> amount, if I'm being honest. My job is to report on social media companies, so I keep (doom)scrolling. That's what I tell myself anyway. </p><p>A few of my favorite posters are still around. Dril's <a target="_blank" class="link" href="https://x.com/dril/status/2034734513688027415" data-i13n="cpos:1;pos:1">still got it</a>. The memes are still, occasionally, good, even though X's recommendation algorithm seems to prefer pointing me toward endless AI slop, boring hot takes from thirsty mid-tier tech execs and blatant engagement bait. X's algorithm — <a target="_blank" class="link" href="https://www.engadget.com/social-media/xs-open-source-algorithm-isnt-a-win-for-transparency-researchers-say-181836233.html" data-i13n="cpos:2;pos:1">what little we can learn about it</a>, anyway — now relies on Grok's predictions about what you'll like.The same Holocaust-loving Grok that has spewed racism and referred to itself as <a target="_blank" class="link" href="https://www.engadget.com/ai/how-exactly-did-grok-go-full-mechahitler-151020144.html" data-i13n="cpos:3;pos:1">MechaHitler</a> and <a target="_blank" class="link" href="https://www.engadget.com/ai/elon-musk-blames-adversarial-prompting-after-grok-spewed-embarrassing-sycophantic-praise-235157807.html" data-i13n="cpos:4;pos:1">declared Elon Musk</a> "the single greatest person in modern history." The same Grok that allegedly generated thousands of images of <a target="_blank" class="link" href="https://www.engadget.com/ai/california-is-investigating-grok-over-ai-generated-csam-and-nonconsensual-deepfakes-202029635.html" data-i13n="cpos:5;pos:1">child abuse material</a>. Hey @grok is that true? </p><p>X is not Twitter but it's also <a target="_blank" class="link" href="https://www.engadget.com/social-media/x-was-spooked-enough-by-new-twitter-to-change-its-terms-of-service-231138305.html" data-i13n="cpos:6;pos:1">not not-Twitter</a>. Last year, an online marketplace startup bought the 560-pound Twitter bird that once adorned the company's San Francisco office and <a target="_blank" class="link" href="https://www.engadget.com/social-media/the-560-pound-twitter-sign-met-a-fiery-end-in-a-nevada-desert-140032860.html" data-i13n="cpos:7;pos:1">blew it up in a Nevada desert</a> surrounded by Tesla CyberTrucks as part of an elaborate publicity stunt. Dumb? Yes. But also a somehow fitting <a target="_blank" class="link" href="https://x.com/elonmusk/status/1682964919325724673" data-i13n="cpos:8;pos:1">adieu</a> for "Larry."</p><div><blockquote class="twitter-tweet"><p lang="en" dir="ltr">just setting up my twttr</p>— jack (@jack) <a href="https://twitter.com/jack/status/20?ref_src=twsrc%5Etfw">March 21, 2006</a></blockquote>


</div><p>It's been 20 years since Jack Dorsey sent the first-ever tweet, which was never even a good tweet anyway. It's been five years, by the way, since he turned that tweet <a target="_blank" class="link" href="https://www.engadget.com/jack-dorsey-crypto-nft-004818260.html" data-i13n="cpos:9;pos:1">into an NFT</a> (remember NFTs??) and auctioned it for nearly <a target="_blank" class="link" href="https://www.engadget.com/jack-dorsey-first-tweet-nft-sells-for-2-9-million-214729911.html" data-i13n="cpos:10;pos:1">$3 million</a>. It's now <a target="_blank" class="link" href="https://cryptoslate.com/the-nft-of-jack-dorseys-first-tweet-originally-purchased-for-2-9m-is-worth-less-than-4-in-todays-market/" data-i13n="cpos:11;pos:1">functionally worthless</a>. Another chapter in Dorsey's <a target="_blank" class="link" href="https://www.engadget.com/why-jack-dorsey-thought-elon-musk-could-fix-twitter-140004514.html" data-i13n="cpos:12;pos:1">confusing, complicated legacy</a>.</p><p><br></p><p></p>This article originally appeared on Engadget at https://www.engadget.com/social-media/twitter-turned-20-and-i-feel-nothing-140000602.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Age-Gating Isn’t About Kids, It’s About Control]]></title>
<description><![CDATA[submitted by    /u/move_machine   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3368281/linux-tipps/age-gating-isnt-about-kids-its-about-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3368281/linux-tipps/age-gating-isnt-about-kids-its-about-control/</guid>
<pubDate>Sat, 21 Mar 2026 02:50:49 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/move_machine"> /u/move_machine </a> <br> <span><a href="https://www.eff.org/deeplinks/2026/03/rep-finke-was-right-age-gating-isnt-about-kids-its-about-control">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ryuor7/agegating_isnt_about_kids_its_about_control/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Behind on Siri, Apple makes a billion dollars from rival AI apps]]></title>
<description><![CDATA[Apple may just be one of the few firms actually profiting from AI, as its in-app purchase commission revenues through the App Store are expected to exceed $1 billion in 2026.Rivals to Apple Intelligence are paying Apple up $1bn in App Store feesIt's still a fallacy that Apple is behind on AI, but...]]></description>
<link>https://tsecurity.de/de/3366566/ios-mac-os/behind-on-siri-apple-makes-a-billion-dollars-from-rival-ai-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3366566/ios-mac-os/behind-on-siri-apple-makes-a-billion-dollars-from-rival-ai-apps/</guid>
<pubDate>Fri, 20 Mar 2026 12:38:56 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple may just be one of the few firms actually profiting from AI, as its in-app purchase commission revenues through the <a href="https://appleinsider.com/inside/app-store" title="App Store" data-kpt="1">App Store</a> are expected to exceed $1 billion in 2026.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67091-141027-000-lede-AI-and-App-Store-xl.jpg" alt="Apple App Store icon on the left, featuring white stylized A on blue gradient square; on the right, colorful atomic-style outline surrounding glowing multicolored Siri orb logo"><br><span>Rivals to Apple Intelligence are paying Apple up $1bn in App Store fees</span></div><br>It's still a fallacy that Apple is <a href="https://appleinsider.com/articles/23/12/21/apple-isnt-behind-on-ai-its-looking-ahead-to-the-future-of-smartphones">behind on AI</a>, but it is certainly true that its <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a>-powered <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> has <a href="https://appleinsider.com/articles/26/02/16/apples-upgraded-siri-is-late-but-not-lost%E2%80%94%E2%80%94the-real-story-is-timing">yet to materialize</a>. But while it has no AI chatbot of its own, Apple is profiting handsomely from all of others.<br><br>According to the <em>Wall Street Journal</em>, in January 2025, <a href="https://www.wsj.com/tech/ai/apple-ai-subscriptions-strategy-7ce4ba7f">Apple took</a> $35 million in App Store fees from generative AI apps. By August 2025, it was $101 million, for an estimated $900 million over the year.<br><br><br> <a href="https://appleinsider.com/articles/26/03/20/behind-on-siri-apple-makes-a-billion-dollars-from-rival-ai-apps?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243766?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[NTLM Is Dead. Your Password Hash Isn’t: Abusing SamrSetInformationUser in Active Directory]]></title>
<description><![CDATA[Last week Microsoft published a three-phase plan to kill the NTLM authentication protocol. My LinkedIn feed filled up with celebrations. And I get it, the protocol has been a source of pain for decades.But almost nobody in those threads seems to understand a critical distinction, and it’s been bu...]]></description>
<link>https://tsecurity.de/de/3365752/hacking/ntlm-is-dead-your-password-hash-isnt-abusing-samrsetinformationuser-in-active-directory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365752/hacking/ntlm-is-dead-your-password-hash-isnt-abusing-samrsetinformationuser-in-active-directory/</guid>
<pubDate>Fri, 20 Mar 2026 06:35:11 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last week Microsoft published a three-phase plan to kill the NTLM authentication protocol. My LinkedIn feed filled up with celebrations. And I get it, the protocol has been a source of pain for decades.</p><p>But almost nobody in those threads seems to understand a critical distinction, and it’s been bugging me enough to write this up with working proof-of-concept scripts so you can test it in your own lab.</p><p><strong>First: NTLM hash and NTLM protocol are two different things</strong></p><p>This confusion is everywhere, even in posts from people who should know better. Let me clear it up.</p><p>The <strong>NTLM protocol</strong> is the challenge-response authentication mechanism. That’s what Microsoft is deprecating. When you hear about pass-the-hash relay attacks, CVE-2025–24054, and all those headlines from last year, that’s the protocol side. Fair enough, it deserves to die.</p><p>The <strong>NTLM hash</strong> is just how Windows calculates and stores your password. You type your password, Windows computes an MD4 hash over its UTF-16LE encoding, and stores the resulting 16-byte value in Active Directory. This hash is commonly called the “NTLM hash” or “NT hash” because it’s used in the NTLM protocol. But here’s what most people miss: <strong>Kerberos uses the same hash</strong>. When your organization migrates from NTLM protocol to Kerberos (which is the whole point of Microsoft’s deprecation roadmap), that same NT hash will still be sitting in AD, doing the same job, just serving a different protocol.</p><p>Why does this matter? Because the attack I’m about to show you doesn’t touch the NTLM protocol at all. It targets how the hash gets written to Active Directory. Killing the protocol changes nothing about this vulnerability.</p><p><strong>The attack: bypassing every password policy in your domain</strong></p><p>Windows provides a <a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-samr/538222f7-1b89-4811-949a-0eac62e38dce">SamrSetInformationUser</a> function through its Remote Procedure Call (RPC) interface. This function lets you set a user’s password hash directly in Active Directory, without submitting the actual password.</p><p>Think about what that means. Windows never sees the password itself. It only receives the 16-byte hash. So every layer of password validation you’ve configured simply never gets called:</p><ul><li>GPO password complexity rules? Skipped.</li><li>Custom password filter DLLs checking against breached dictionaries? Never invoked.</li><li>Third-party password policy tools with character substitution logic? They don’t even know anything happened.</li></ul><p>The only requirement is Password Reset permissions on the target account. If you’ve administered any sizeable AD environment, you know how generously those tend to be handed out.</p><p><strong>Try it yourself</strong></p><p>I’ve put together a PowerShell script that demonstrates this. It calls SamrSetInformationUser and sets a user’s password hash directly, bypassing all password complexity checks.</p><p><a href="https://simpity.eu/blog/SetNtlmPassword.zip">↓ Download SetNtlmPassword.zip</a></p><p>Here’s how to run it:</p><ol><li>Create a folder (e.g., C:\SetPassword)</li><li>Copy the script into that folder</li><li>Run: powershell .\SetNtlmPassword.ps1</li><li>Enter the username and a new password</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/555/1*KdkU1hkmiZfse_bB5Dw_zA.jpeg"></figure><p>Running the attack script. Password for testuser1 is now literally “1”. Every GPO complexity rule was active. None of them fired.</p><p>That’s it. The user “testuser1” now has a password that is the single digit “1”. Every password policy in the domain was configured and active. None of them fired.</p><p><strong>The defense: hooking SamrSetInformationUser inside LSASS</strong></p><p>All Active Directory operations on a Domain Controller happen inside the LSASS.EXE process. That means we can find the SamrSetInformationUser function inside that process and block its call when someone tries to write a hash directly.</p><p>This requires two conditions: you need to be on the Domain Controller itself, and the LSASS process must not be locked down by Credential Guard, LSA Protection (PPL), or an endpoint security product that prevents injection.</p><p>I wrote a second PowerShell script that demonstrates this defense. It injects into the LSASS process address space, hooks the SamrSetInformationUser function, and inside the hook prevents the original function from executing when it detects a direct password hash write. For injection and hooking it uses <a href="https://easyhook.github.io/">EasyHook</a>.</p><p><a href="https://simpity.eu/blog/Protect.zip">↓ Download Protect.zip</a></p><p><strong>Try the defense yourself</strong></p><ol><li>Copy the script into the same C:\SetPassword folder</li><li>Download and unpack <a href="http://easyhook.github.io/download.html?url=https://github.com/EasyHook/EasyHook/releases/download/v2.7.6789.0/EasyHook-2.7.6789.0-Binaries.zip">EasyHook 2.7.6789.0</a> into the same folder</li><li>If needed, adjust the EasyHook path in the script:<br>$easyHookPath = “.\EasyHook-2.7.6789.0-Binaries\projects\easyhook\Deploy\NetFX4.0\EasyHook.dll”</li><li>Run: powershell .\Protect.ps1</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/979/1*g-hHgI_VEG820ei8Jg8nxg.jpeg"></figure><p>The protection script injecting into LSASS. It locates samsrv.dll, finds SamrSetInformationUser at 0x7FFA516F0280, and installs the hook successfully.</p><p>Read the output carefully. The script finds samsrv.dll inside LSASS, locates the SamrSetInformationUser function address, installs the hook, and starts monitoring.</p><p>Now try running the attack script again. This time you’ll see it fail:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/939/1*Obx6ro2lRRDPaPMlbAVN7A.jpeg"></figure><p>Same attack, same script, same target user. This time: NTSTATUS 0xC0000022 — access denied. The hook intercepted the call before the hash reached AD.</p><p>The hook intercepts the call and returns an access denied error before the hash ever reaches AD.</p><p>You can also check the log file at C:\Windows\Temp\SetPassword_Hook.log to see every blocked attempt, along with cases where the function was allowed to proceed normally:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YhY0Ot-Je-l5xIHd2u3JQQ.jpeg"></figure><p>SetPassword_Hook.log showing the hook installation and a blocked SamrSetInformationUser call with InformationClass: UserInternal1Information (18).</p><p><strong>Why this matters right now</strong></p><p>Everyone is celebrating the NTLM protocol deprecation. And yes, killing the protocol is the right move. But the hash that gets stored in AD is the same hash that Kerberos uses. SamrSetInformationUser is an RPC function, not an NTLM protocol feature. The ability to bypass every password policy in your domain survives the migration to Kerberos completely intact.</p><blockquote><strong>Important:</strong> The scripts shared here are for educational and testing purposes. They are not production-ready. There are more reliable methods for process injection and function hooking, and you’d likely need to configure exceptions for legacy applications that legitimately use this API.</blockquote><p>But the underlying problem is real, and GPOs and password filters can’t solve it because they operate at the wrong level. You need to intercept where the hash meets the directory, and that means you need to be inside LSASS.</p><p>The key takeaway is that password controls implemented above the authentication layer can often be bypassed through alternative password-set paths. If we want password protections to be effective, enforcement must happen where password changes are actually processed — not only where policies are defined.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8de03eea29cf" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ntlm-is-dead-your-password-hash-isnt-abusing-samrsetinformationuser-in-active-directory-8de03eea29cf">NTLM Is Dead. Your Password Hash Isn’t: Abusing SamrSetInformationUser in Active Directory</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Workforce Transformation Isn’t A Skills Problem. It’s A Work Design Problem.]]></title>
<description><![CDATA[Executive Summary 
Most organizations approach AI workforce transformation as a skills challenge.]]></description>
<link>https://tsecurity.de/de/3365389/it-security-nachrichten/ai-workforce-transformation-isnt-a-skills-problem-its-a-work-design-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365389/it-security-nachrichten/ai-workforce-transformation-isnt-a-skills-problem-its-a-work-design-problem/</guid>
<pubDate>Fri, 20 Mar 2026 04:35:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://cybermaniacs.com/cm-blog/ai-workforce-transformation-isnt-a-skills-problem.-its-a-work-design-problem" title="" class="hs-featured-image-link"> <img src="https://cybermaniacs.com/hubfs/SVG%20Blog%20Headers/21.svg" alt="AI Workforce Transformation Isn’t A Skills Problem. It’s A Work Design Problem." class="hs-featured-image"> </a> 
</div> 
<h2>Executive Summary</h2> 
<p>Most organizations approach <strong>AI workforce transformation</strong> as a skills challenge.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta isn't shutting down its VR metaverse after all]]></title>
<description><![CDATA[Meta is backtracking on its plans to shut down the VR version of its metaverse. The company now plans to support Horizon Worlds in VR for the "foreseeable future," though users shouldn't expect new games, CTO Andrew Bosworth said in an update."We will keep Horizon Worlds working in VR for existin...]]></description>
<link>https://tsecurity.de/de/3363567/it-nachrichten/meta-isnt-shutting-down-its-vr-metaverse-after-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3363567/it-nachrichten/meta-isnt-shutting-down-its-vr-metaverse-after-all/</guid>
<pubDate>Fri, 20 Mar 2026 04:03:41 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Meta is backtracking on its plans to shut down the VR version of its metaverse. The company now plans to support Horizon Worlds in VR for the "foreseeable future," though users shouldn't expect new games, CTO Andrew Bosworth said in an update.</p><p>"We will keep Horizon Worlds working in VR for existing games, to support the fans who've reached out," Bosworth said in a post on Instagram. "For people who already have games they like that they're using in Horizon Worlds, [they] will be able to download the Horizon Worlds app and use it in VR for the foreseeable future."</p><p>The reversal comes after Meta said earlier this week that Horizon Worlds in VR would no longer be accessible <a target="_blank" class="link" href="https://www.engadget.com/ar-vr/meta-will-shut-down-vr-horizon-worlds-access-in-june-222028919.html" data-i13n="cpos:1;pos:1">after June 15</a> as the company pivots its metaverse experiences to mobile. Though Horizon never gained mass appeal, even among VR enthusiasts, Meta's move to shut it down was just the latest sign of how the company has pivoted away from its metaverse ambitions as it chases <a target="_blank" class="link" href="https://www.engadget.com/ai/mark-zuckerberg-shares-a-confusing-vision-for-ai-superintelligence-153944322.html" data-i13n="cpos:2;pos:1">AI "superintelligence."</a> </p><p>In his post on Instagram, Bosworth said there was "a lot of misinformation" about the company's plans. "We announced, 'hey, we're moving away from Horizon Worlds in VR,' and the headline is that Horizon is dead," he said. "It's not. And likewise, VR is not dead. We're continuing to invest tremendously." The company laid off more than <a target="_blank" class="link" href="https://www.engadget.com/ar-vr/meta-refocuses-on-ai-hardware-as-metaverse-layoffs-begin-145924706.html" data-i13n="cpos:3;pos:1">1,000 employees</a> from its metaverse division and shut down <a target="_blank" class="link" href="https://www.engadget.com/ar-vr/meta-has-closed-three-vr-studios-as-part-of-its-metaverse-cuts-202720670.html" data-i13n="cpos:4;pos:1">three VR studios</a> earlier this year. Bosworth said that the company is still working on its next two generations of VR headsets.</p><p>He described the metaverse as a "misunderstood concept" that was never meant to only encompass virtual reality. He said that AR is also part of the vision and that even people scrolling their phones could be part of the metaverse. "When somebody is using their phone and you're physically with them, they're at the dinner table with you, and yet when you talk to them, they hear nothing because they've transported themselves through the glowing rectangle into a digital space," he said. "Maybe that they're scrolling media, maybe that they're in the text world, but like they have transported themselves. So we've always had this internally — at least me and Mark — this very expansive construct of the metaverse."</p><p><br></p><p></p>This article originally appeared on Engadget at https://www.engadget.com/ar-vr/meta-isnt-shutting-down-its-vr-metaverse-after-all-165520696.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Security Scanning Isn’t Enough for MCP Servers]]></title>
<description><![CDATA[The Gap Nobody Is Talking About The Model Context Protocol (MCP) is quickly becoming the de facto standard between AI agents and the tools they use. The adoption is growing rapidly – from coding assistants to enterprise automation platforms, MCP servers are replacing…
Read more →
The post Why Sec...]]></description>
<link>https://tsecurity.de/de/3363040/it-security-nachrichten/why-security-scanning-isnt-enough-for-mcp-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3363040/it-security-nachrichten/why-security-scanning-isnt-enough-for-mcp-servers/</guid>
<pubDate>Thu, 19 Mar 2026 21:35:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Gap Nobody Is Talking About The Model Context Protocol (MCP) is quickly becoming the de facto standard between AI agents and the tools they use. The adoption is growing rapidly – from coding assistants to enterprise automation platforms, MCP servers are replacing…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-security-scanning-isnt-enough-for-mcp-servers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-security-scanning-isnt-enough-for-mcp-servers/">Why Security Scanning Isn’t Enough for MCP Servers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone isn't safe on old iOS anymore, update to at least iOS 15 now]]></title>
<description><![CDATA[All iPhone users running iOS 13 or iOS 14 need to update now. Apple has confirmed routine browsing can trigger attacks on outdated iOS versions.Apple advises iPhone users about iOS 15 updateApple revealed on March 19 that malicious web content can exploit older iOS versions and expose personal da...]]></description>
<link>https://tsecurity.de/de/3362957/ios-mac-os/iphone-isnt-safe-on-old-ios-anymore-update-to-at-least-ios-15-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3362957/ios-mac-os/iphone-isnt-safe-on-old-ios-anymore-update-to-at-least-ios-15-now/</guid>
<pubDate>Thu, 19 Mar 2026 20:20:23 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[All iPhone users running iOS 13 or <a href="https://appleinsider.com/inside/ios-14" title="iOS 14" data-kpt="1">iOS 14</a> need to update now. Apple has confirmed routine browsing can trigger attacks on outdated iOS versions.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67087-141002-hack-xl.jpg" alt="Smartphone on dark green background displaying glowing green binary code lines, suggesting hacking, cybersecurity, or encrypted data scrolling across the screen"><br><span>Apple advises iPhone users about iOS 15 update</span></div><br>Apple revealed <a href="https://support.apple.com/en-us/126776">on March 19</a> that malicious web content can exploit older iOS versions and expose personal data through compromised sites or unsafe links. Apple released security updates <a href="https://support.apple.com/en-us/126776">on March 11</a> for both newer and older devices, including iOS 15.8.7 and iOS 16.7.15.<br><br>Users on iOS 13 or iOS 14 should upgrade to iOS 15 to receive those protections. Updating iOS closes those gaps and protects against these web-based attacks.<br><br><br> <a href="https://appleinsider.com/articles/26/03/19/iphone-isnt-safe-on-old-ios-anymore-update-to-at-least-ios-15-now?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243763?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Career Reality Check: What Cyber Isn’t Telling You]]></title>
<description><![CDATA[Ask Me Anything Cyber on March 19 explores cybersecurity career myths, burnout, and growth, with Brenda Johnson on women in security. This article has been indexed from CyberMaterial Read the original article: Career Reality Check: What Cyber Isn’t Telling You
Read more →
The post Career Reality ...]]></description>
<link>https://tsecurity.de/de/3361494/it-security-nachrichten/career-reality-check-what-cyber-isnt-telling-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3361494/it-security-nachrichten/career-reality-check-what-cyber-isnt-telling-you/</guid>
<pubDate>Thu, 19 Mar 2026 10:35:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ask Me Anything Cyber on March 19 explores cybersecurity career myths, burnout, and growth, with Brenda Johnson on women in security. This article has been indexed from CyberMaterial Read the original article: Career Reality Check: What Cyber Isn’t Telling You</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/career-reality-check-what-cyber-isnt-telling-you/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/career-reality-check-what-cyber-isnt-telling-you/">Career Reality Check: What Cyber Isn’t Telling You</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI without sovereignty is just outsourced intelligence]]></title>
<description><![CDATA[There’s a quiet assumption baked into most AI adoption conversations: that access equals advantage.



Buy the API. Plug in the model. Watch productivity soar. Brief the board on your AI transformation. Repeat.



It’s a compelling narrative, and for vendors, it’s a lucrative one. But there’s a h...]]></description>
<link>https://tsecurity.de/de/3361471/it-security-nachrichten/ai-without-sovereignty-is-just-outsourced-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3361471/it-security-nachrichten/ai-without-sovereignty-is-just-outsourced-intelligence/</guid>
<pubDate>Thu, 19 Mar 2026 10:21:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There’s a quiet assumption baked into most AI adoption conversations: that access equals advantage.</p>



<p>Buy the API. Plug in the model. Watch productivity soar. Brief the board on your AI transformation. Repeat.</p>



<p>It’s a compelling narrative, and for vendors, it’s a lucrative one. But there’s a harder question that most enterprises haven’t yet asked loudly enough: Who actually controls the intelligence powering your most critical decisions?</p>



<p>Because access and control are not the same thing. And as AI becomes embedded deeper into business operations, supply chains, customer relationships and strategic planning, the gap between those two concepts will define the next era of enterprise competitiveness — and risk.</p>



<h2 class="wp-block-heading">The illusion of capability</h2>



<p>When an organization integrates a third-party AI system, it gains capability — but not sovereignty.</p>



<p>The distinction is not semantic. It is strategic.</p>



<p><strong>Capability</strong> is what the tool can do. <strong>Sovereignty</strong> is your authority over how, when, why and for whom it does it. Most enterprises currently have the former and are dangerously short on the latter.</p>



<p>Consider what “AI adoption” actually looks like in practice for the majority of organizations today: <a href="https://www.cio.com/article/4131904/saas-isnt-dead-the-market-is-just-becoming-more-hybrid.html">SaaS platforms with AI</a> features baked in, large language model APIs accessed through third-party wrappers, copilot tools that sit inside productivity suites owned by someone else. In every case, the enterprise is the consumer of intelligence — not the architect of it.</p>



<p>Rented intelligence comes with invisible terms. The model can change overnight. Pricing can shift. The vendor can be acquired, sunset the product or alter the underlying behavior, all without your consent. Your “AI strategy” is, in reality, a <a href="https://www.cio.com/article/4128980/the-struggle-for-good-ai-governance-is-real.html">dependency strategy</a>. And dependency, at scale, is a liability.</p>



<p>That’s not transformation. That’s sophisticated outsourcing with better marketing.</p>



<h2 class="wp-block-heading">What sovereignty actually means</h2>



<p>AI sovereignty is not about building your own foundation model from scratch. Very few organizations need that, and fewer still could responsibly afford it. This is not a call for every enterprise to become an AI research lab.</p>



<p>Sovereignty is about <strong>governance, transparency and control</strong> at every layer of the AI stack. For CIOs, that means demanding accountability across four distinct dimensions:</p>



<ul class="wp-block-list">
<li><strong>Data sovereignty</strong> means your training data, fine-tuning data and inference data stay under your jurisdiction. You know where it goes, who sees it, how it’s retained and how it may be used to improve someone else’s model. The moment your proprietary data flows through an external system under permissive terms, you’ve potentially handed a competitor — or a future competitor — a map of your business.</li>



<li><strong>Model sovereignty</strong> means you can audit, validate and — where necessary — override the model’s outputs. You’re not a black-box passenger. You understand, at least at a governance level, why a recommendation was made. If your AI-powered system flags a customer as high-risk, denies a loan or makes a supply chain decision, you need to be able to explain that to a regulator, a customer or a board. “The model said so” is not an acceptable answer in any of those rooms.</li>



<li><strong>Operational sovereignty</strong> means you can run the system on your infrastructure, in your regulatory environment, without a third-party kill switch embedded in your operations. Uptime, security posture, data residency and business continuity must remain under your control; not subject to a vendor’s SLA and their legal team’s definition of “reasonable.”</li>



<li><strong>Strategic sovereignty</strong> means your AI roadmap isn’t held hostage to a vendor’s product priorities, API deprecations or quarterly earnings pressures. It means you have portability, optionality and the internal capability to adapt — not just consume.</li>
</ul>



<p>Without all four, AI adoption is building on sand.</p>



<p>AI sovereignty is not about building your own foundation model from scratch. Very few organizations need that. Sovereignty is about governance, transparency and control at every layer of the AI stack.</p>



<h2 class="wp-block-heading">The geopolitical reality CIOs can’t ignore</h2>



<p>This isn’t abstract philosophy. It’s already a board-level crisis in motion.</p>



<p>Nations are waking up to the reality that AI is infrastructure — as strategic as energy grids, telecommunications networks or financial clearing systems. The country or corporation that controls the AI layer controls the insight layer. And whoever controls insight shapes decisions, at scale, in real time.</p>



<p>That’s why we’re seeing the <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai" rel="nofollow">EU’s AI Act</a> push hard on transparency and accountability requirements that will force explainability into procurement conversations. It’s why governments across Europe, Asia and the Middle East are mandating sovereign AI cloud environments for public sector workloads. It’s why defense and intelligence agencies flatly refuse to run critical operations through foreign-owned models. And it’s why enterprises in financial services, healthcare and critical infrastructure are scrambling to renegotiate AI vendor contracts that were signed before anyone thought carefully about <a href="https://www.cio.com/article/4119786/cloud-sovereignty-squaring-compliance-with-innovation.html">data residency</a> and model governance.</p>



<p>This is not protectionism. It’s prudence. And the CIOs who recognize it early will be the ones who avoid the painful — and expensive — unwind later.</p>



<h2 class="wp-block-heading">The enterprise blind spot that will define the next decade</h2>



<p>Here is the uncomfortable truth that most AI enthusiasm papers over: when a company allows its customer data, proprietary processes and competitive intelligence to flow through a third-party AI system, it risks training its own replacement.</p>



<p>Every query, every document, every workflow that passes through an external AI enriches that vendor’s understanding of your industry, your customers and your operational logic, sometimes explicitly, sometimes through aggregated inference, sometimes through the terms buried in a click-through agreement your legal team didn’t fully review. The data flywheel spins in the vendor’s favor, not yours.</p>



<p>Meanwhile, your teams grow increasingly dependent on outputs they can’t explain, validate or own. Institutional knowledge migrates from your people to an external system you don’t control. The prompt engineers become the new power users, but the underlying intelligence, the actual competitive asset, belongs to someone else.</p>



<p>That’s not a productivity gain. That’s a long-term strategic liability dressed up as innovation.</p>



<h2 class="wp-block-heading">A sovereignty-first AI framework for CIOs</h2>



<p>The answer isn’t to reject AI. The answer is to adopt it deliberately, with governance built in from day one — not retrofitted after the audit.</p>



<ul class="wp-block-list">
<li><strong>Audit your AI dependencies like you audit your supply chain.</strong> Map every third-party AI touchpoint across the organization. Understand what data flows where, under what contractual terms and what your exit options are. If you don’t know, that’s the first problem to solve.</li>



<li><strong>Distinguish between commodity AI and strategic AI.</strong> Using an external model to summarize emails, generate first drafts or auto-categorize support tickets? That’s commodity usage; the risk-reward tradeoff is manageable. Running pricing decisions, M&amp;A analysis, patient diagnostics or fraud detection through a system you don’t control? That demands a fundamentally different level of scrutiny, contractual protection and architectural isolation.</li>



<li><strong>Invest in internal AI literacy, not just AI tooling.</strong> Sovereignty requires humans who understand what the model is doing, not just that it’s doing something impressive. Build model evaluation competency internally. Train decision-makers to interrogate outputs, not just consume them. The organizations that will fare best are those that treat AI as a skill to be developed, not just a service to be purchased.</li>



<li><strong>Demand explainability as a contract requirement, not a product feature.</strong> If a vendor cannot provide a credible account of why their model made a recommendation, they should not be making recommendations that affect your customers, your compliance posture or your business outcomes. Explainability isn’t a nice-to-have. It’s a fiduciary baseline.</li>



<li><strong>Architect for portability from the start.</strong> Design your AI infrastructure so you’re not locked into a single provider’s ecosystem. Model interoperability, open standards and the ability to swap or self-host foundational components aren’t technical niceties: they’re strategic insurance policies. The cost of building in portability now is a fraction of the cost of rearchitecting under duress later.</li>
</ul>



<h2 class="wp-block-heading">The leadership imperative</h2>



<p>AI sovereignty is ultimately a leadership question, not a technology question. It requires CIOs to move from implementers of vendor vision to architects of organizational intelligence, and it requires boards and CEOs to fund that shift accordingly.</p>



<p>The organizations that will lead in the next decade won’t be those that adopted AI fastest. They’ll be those who adopted it wisest, who understood that intelligence, like data before it, must be governed, not just consumed. Who insisted on control even when convenience argued against it. Who built AI capability that compounds internally, rather than dependency that compounds externally.</p>



<p>Every CIO today faces a version of the same strategic fork: build an AI foundation your organization owns and understands, or optimize for short-term speed and inherit long-term exposure.</p>



<p>The question isn’t whether you’re using AI.</p>



<p>The question is: <strong>do you own your AI future — or are you renting someone else’s?</strong></p>



<p>Because AI without sovereignty isn’t a competitive advantage.</p>



<p>It’s just very fast dependence.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quantum Computing Isn't A Threat To Blockchains - Yet - Martha Bennett, Sandy Carielli - ASW #354]]></title>
<description><![CDATA[The post quantum encryption migration is going to be a challenge, but how much of a challenge? There are several reasons why it is different from every other protocol and cypher iteration in the past. Is today's hardware up to the task? Is it just swapping out a library, or is there more to it? W...]]></description>
<link>https://tsecurity.de/de/3356130/it-security-nachrichten/quantum-computing-isnt-a-threat-to-blockchains-yet-martha-bennett-sandy-carielli-asw-354/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356130/it-security-nachrichten/quantum-computing-isnt-a-threat-to-blockchains-yet-martha-bennett-sandy-carielli-asw-354/</guid>
<pubDate>Tue, 17 Mar 2026 17:54:22 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The post quantum encryption migration is going to be a challenge, but how much of a challenge? There are several reasons why it is different from every other protocol and cypher iteration in the past. Is today's hardware up to the task? Is it just swapping out a library, or is there more to it? What is the extent of software, systems, and architecture that have to be updated or replaced to complete the migration? Can we get it all done by 2030?</p> <p>Sandy Carielli and Martha Bennett join us to answer these questions and dive into one area of tech that hasn't been discussed much when it comes to post-quantum encryption: blockchain.</p> <p>Relevant Forrester Reports:</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.forrester.com/report/quantum-computing-isnt-a-threat-to-blockchains-yet/RES183981"> Quantum Computing isn't a Threat to Blockchains - Yet</a></li> <li><a rel="noopener" target="_blank" href="https://www.forrester.com/report/the-architects-guide-to-quantum-security/RES182782"> The Architect's Guide to Quantum Security</a></li> </ul> <p>In the news, high standards for open source software, trends in self-hosting, doing the cloud wrong, and is it really always DNS?</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/asw">https://www.securityweekly.com/asw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/asw-354">https://securityweekly.com/asw-354</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tim Cook denies imminent retirement rumors, 'can't imagine life without Apple']]></title>
<description><![CDATA[Tim Cook has previously said that he'd probably be out of Apple by 2031. In a new interview celebrating Apple's 50th anniversary, he makes it clear rumors that he would retire in 2026 are false, and he isn't leaving any time soon.Just as Steve Jobs (right) was succeeded by Tim Cook (left), so the...]]></description>
<link>https://tsecurity.de/de/3355882/ios-mac-os/tim-cook-denies-imminent-retirement-rumors-cant-imagine-life-without-apple/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3355882/ios-mac-os/tim-cook-denies-imminent-retirement-rumors-cant-imagine-life-without-apple/</guid>
<pubDate>Tue, 17 Mar 2026 17:08:25 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tim Cook has previously said that he'd probably be out of Apple by 2031. In a new interview celebrating Apple's 50th anniversary, he makes it clear rumors that he would retire in 2026 are false, and he isn't leaving any time soon.<br><br><div><img src="https://photos5.appleinsider.com/gallery/65384-136742-000-lede-Cook-and-Jobs-xl.jpg" alt="Two men are talking indoors. One holds a white mug, wearing glasses and a black shirt. The other crosses his arms, wearing a dark polo." height="714"><br><span>Just as Steve Jobs (right) was succeeded by Tim Cook (left), so there have to already be plans for the next Apple CEO — image credit: Apple</span></div><br>It was actually a <a href="https://appleinsider.com/articles/21/04/05/tim-cook-probably-leaving-apple-in-next-ten-years">direct quote</a> Cook gave <em>The New York Times</em> back in 2021, saying he would "probably not" still be at Apple ten years from then. He said it on Kara Swisher's podcast for the paper, so it's not like it was a misquote.<br><br>True, he didn't exactly give a leaving date, and it's not really as if anyone fully <a href="https://appleinsider.com/articles/25/11/23/apple-ceo-tim-cook-isnt-retiring-in-2026">believed him</a> while Apple is going through upheavals over <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a>. But now in an interview with ABC's "Good Morning America," he <a href="https://appleinsider.com/articles/26/03/17/tim-cook-continues-apples-50th-anniversary-victory-lap-in-new-interview">flat-out denies</a> the story.<br><br><br> <a href="https://appleinsider.com/articles/26/03/17/tim-cook-denies-imminent-retirement-rumors-cant-imagine-life-without-apple?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243736?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Air adding touchscreen isn’t yet planned, says report]]></title>
<description><![CDATA[Later this year, the M6 MacBook Pro is widely rumored to be the first Mac that supports touch. But a new report indicates touchscreens may not be in Apple’s plans for the MacBook Air or MacBook Neo.



 more…]]></description>
<link>https://tsecurity.de/de/3353592/ios-mac-os/macbook-air-adding-touchscreen-isnt-yet-planned-says-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3353592/ios-mac-os/macbook-air-adding-touchscreen-isnt-yet-planned-says-report/</guid>
<pubDate>Mon, 16 Mar 2026 19:37:02 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="feat-image"><img src="https://9to5mac.com/wp-content/uploads/sites/6/2024/10/m3-macbook-air-yellow.jpg?quality=82&amp;strip=all&amp;w=1600"></div><p>Later this year, the M6 MacBook Pro is <a href="https://9to5mac.com/2026/03/12/m6-macbook-pro-six-new-features-coming-later-this-year/" type="post">widely rumored</a> to be the first Mac that supports touch. But a new report indicates touchscreens may not be in Apple’s plans for the MacBook Air or MacBook Neo.</p>



 <a data-layer-pagetype="post" data-layer-postcategory="mac,macbook-air" data-layer-viewtype="taxonomy-ninetofive_guides" data-post-id="1043706" href="https://9to5mac.com/2026/03/16/macbook-air-adding-touchscreen-isnt-yet-planned-says-report/#more-1043706" class="more-link">more…</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s Liquid Glass isn’t going anywhere: Years of refinements ahead for new design language]]></title>
<description><![CDATA[Apple's Liquid Glass user interface isn't going anywhere anytime soon. Apple's new design language stems from a multi-year development…
The post Apple’s Liquid Glass isn’t going anywhere: Years of refinements ahead for new design language appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3352838/ios-mac-os/apples-liquid-glass-isnt-going-anywhere-years-of-refinements-ahead-for-new-design-language/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3352838/ios-mac-os/apples-liquid-glass-isnt-going-anywhere-years-of-refinements-ahead-for-new-design-language/</guid>
<pubDate>Mon, 16 Mar 2026 14:22:40 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple's Liquid Glass user interface isn't going anywhere anytime soon. Apple's new design language stems from a multi-year development…</p>
<p>The post <a href="https://macdailynews.com/2026/03/16/apples-liquid-glass-isnt-going-anywhere-years-of-refinements-ahead-for-new-design-language/">Apple’s Liquid Glass isn’t going anywhere: Years of refinements ahead for new design language</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The story about how the third Apple founder sold out for $800 isn't quite right]]></title>
<description><![CDATA[Apple co-founder Ronald Wayne has chosen the company's 50th anniversary to reveal that the conventional wisdom about how he got out of the company and sold a 10% stake in the company for $800 is wrong — but he's splitting a very expensive hair.Apple co-founder Ronald Wayne at the Computer History...]]></description>
<link>https://tsecurity.de/de/3352686/ios-mac-os/the-story-about-how-the-third-apple-founder-sold-out-for-800-isnt-quite-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3352686/ios-mac-os/the-story-about-how-the-third-apple-founder-sold-out-for-800-isnt-quite-right/</guid>
<pubDate>Mon, 16 Mar 2026 13:25:09 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple co-founder Ronald Wayne has chosen the company's 50th anniversary to reveal that the conventional wisdom about how he got out of the company and sold a 10% stake in the company for $800 is wrong — but he's splitting a very expensive hair.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67038-140858-000-lead-Ronald-Wayne-xl.jpg" alt="Elderly man in a suit speaks into a microphone at a seated event, surrounded by listening attendees, including a man in a red polo shirt beside him."><br><span>Apple co-founder Ronald Wayne at the Computer History Museum — image credit: CHM</span></div><br>Apple <a href="https://appleinsider.com/articles/20/04/01/apple-was-founded-44-years-ago-on-april-1-1976">was founded</a> by <a href="https://appleinsider.com/inside/steve-jobs" title="Steve Jobs" data-kpt="1">Steve Jobs</a>, Steve Wozniak, and Ronald Wayne — but <a href="https://appleinsider.com/articles/11/10/05/apple_co_founder_says_time_with_steve_jobs_was_a_great_privilege_of_his_life/amp/">Wayne left</a> after 12 days. Now at a Computer History Museum celebration for Apple's 50th anniversary, Wayne said that it wasn't true he had ever sold the stake in Apple he had as a founder.<br><br>"I actually never sold my 10%," said Wayne, and then repeated it. "The story that's been floating around for decades about $800... that I had sold [my stake] for $800, that was totally inaccurate."<br><br><br> <a href="https://appleinsider.com/articles/26/03/16/the-story-about-how-the-third-apple-founder-sold-out-for-800-isnt-quite-right?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243717?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[SIEM isn’t dead, its place in the SOC is just evolving]]></title>
<description><![CDATA[Predictions about the death of SIEM platforms have swirled for years, fueled by reports of alert fatigue, sky-high data costs and the shiny promises of extended detection and response (XDR), security data lakes and, now, agentic AI.…
Read more →
The post SIEM isn’t dead, its place in the SOC is j...]]></description>
<link>https://tsecurity.de/de/3346227/it-security-nachrichten/siem-isnt-dead-its-place-in-the-soc-is-just-evolving/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346227/it-security-nachrichten/siem-isnt-dead-its-place-in-the-soc-is-just-evolving/</guid>
<pubDate>Fri, 13 Mar 2026 12:21:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Predictions about the death of &lt;a href=”https://www.techtarget.com/searchsecurity/definition/security-information-and-event-management-SIEM”&gt;SIEM&lt;/a&gt; platforms have swirled for years, fueled by reports of alert fatigue, sky-high data costs and the shiny promises of extended detection and response (&lt;a href=”https://www.techtarget.com/searchsecurity/definition/extended-detection-and-response-XDR”&gt;XDR&lt;/a&gt;), security data lakes and, now, &lt;a href=”https://www.techtarget.com/searchsecurity/tip/What-agentic-AI-means-for-cybersecurity”&gt;agentic AI&lt;/a&gt;.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/siem-isnt-dead-its-place-in-the-soc-is-just-evolving-2/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/siem-isnt-dead-its-place-in-the-soc-is-just-evolving-2/">SIEM isn’t dead, its place in the SOC is just evolving</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Second-gen MacBook Neo isn't going to have a touchscreen]]></title>
<description><![CDATA[An analyst has refuted his own previous rumors about the second-gen MacBook Neo gaining a touchscreen. This is obvious, given how inexpensive the first model is to produce.MacBook Neo, sans touchscreen. The MacBook Neo is a model that brings Apple in direct competition with low-cost notebooks suc...]]></description>
<link>https://tsecurity.de/de/3341295/ios-mac-os/second-gen-macbook-neo-isnt-going-to-have-a-touchscreen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3341295/ios-mac-os/second-gen-macbook-neo-isnt-going-to-have-a-touchscreen/</guid>
<pubDate>Wed, 11 Mar 2026 14:08:15 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An analyst has refuted his own previous rumors about the second-gen <a href="https://appleinsider.com/inside/macbook-neo" title="MacBook Neo" data-kpt="1">MacBook Neo</a> gaining a touchscreen. This is obvious, given how inexpensive the first model is to produce.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66985-140717-macbookneo1-xl.jpg" alt="Open pink laptop on a desk displaying multiple colorful app windows, including a food website and document. Another closed pastel-colored device sits behind it on a light wooden table"><br><span>MacBook Neo, sans touchscreen. </span></div><br>The MacBook Neo is a model that brings Apple in direct competition with low-cost notebooks such as Chromebooks. However, despite Apple's interest in lowering the cost of manufacturing the model as far as possible, there's a little confusion over the next model along.<br><br>TF Securities analyst <a href="https://appleinsider.com/inside/ming-chi-kuo" title="Ming-Chi Kuo" data-kpt="1">Ming-Chi Kuo</a> commented in late 2025 that the next iteration could bring touchscreen support. This was apparently going to be included by integrating the touch layer directly into the IPS panel, the same way that the entry-level iPad does now, and has for years.<br><br><br> <strong>Rumor Score:</strong> 🤯 Likely <br><br><br> <a href="https://appleinsider.com/articles/26/03/11/second-gen-macbook-neo-isnt-going-to-have-a-touchscreen?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243671?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercrime isn’t just a cover for Iran’s government goons – it’s a key part of their operations]]></title>
<description><![CDATA[Ransomware, malware-as-a-service, infostealers benefit MOIS, too Iranian government-backed snoops are increasingly using cybercrime malware and ransomware infrastructure in their operations – not just hiding behind criminal masks as a cover for destructive cyber activity, according to security re...]]></description>
<link>https://tsecurity.de/de/3339417/it-security-nachrichten/cybercrime-isnt-just-a-cover-for-irans-government-goons-its-a-key-part-of-their-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3339417/it-security-nachrichten/cybercrime-isnt-just-a-cover-for-irans-government-goons-its-a-key-part-of-their-operations/</guid>
<pubDate>Tue, 10 Mar 2026 19:48:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware, malware-as-a-service, infostealers benefit MOIS, too Iranian government-backed snoops are increasingly using cybercrime malware and ransomware infrastructure in their operations – not just hiding behind criminal masks as a cover for destructive cyber activity, according to security researchers.… This article…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cybercrime-isnt-just-a-cover-for-irans-government-goons-its-a-key-part-of-their-operations/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cybercrime-isnt-just-a-cover-for-irans-government-goons-its-a-key-part-of-their-operations/">Cybercrime isn’t just a cover for Iran’s government goons – it’s a key part of their operations</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PC industry forced to make giant RAM & SSD price hikes, Apple still mostly insulated]]></title>
<description><![CDATA[Apple's MacBook lines will not be badly affected by the extreme memory, processor, and SSD price increases, that are forcing the rest of the industry to hike retail prices more than 40%.A Samsung LPDDR5X memory chip - Image Credit: SamsungThe tech industry is currently being squeezed by demand fo...]]></description>
<link>https://tsecurity.de/de/3338692/ios-mac-os/pc-industry-forced-to-make-giant-ram-ssd-price-hikes-apple-still-mostly-insulated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3338692/ios-mac-os/pc-industry-forced-to-make-giant-ram-ssd-price-hikes-apple-still-mostly-insulated/</guid>
<pubDate>Tue, 10 Mar 2026 15:51:53 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's MacBook lines will not be badly affected by the extreme memory, processor, and SSD price increases, that are forcing the rest of the industry to hike retail prices more than 40%.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66968-140653-66157-138669-samsungthinmemory-xl-xl.jpg" alt="Close-up of a fingertip delicately holding a thin computer microchip, showing its tiny metallic contact points in sharp focus against a soft, bright background"><br><span>A Samsung LPDDR5X memory chip - Image Credit: Samsung</span></div><br>The tech industry is currently being squeezed by demand for chips used for memory and SSD storage. It's a situation worsened by shortages in CPU supplies, which will only apply more pressure on manufacturers to charge consumers more.<br><br>While most of the computer manufacturing industry will be affected, Apple's supply chain has <a href="https://appleinsider.com/articles/26/01/27/ongoing-ram-supply-and-cost-crisis-isnt-an-issue-for-apples-iphone%E2%80%94%E2%80%94right-now">insulated itself</a> enough that it won't be an issue.<br><br><br> <a href="https://appleinsider.com/articles/26/03/10/pc-industry-forced-to-make-giant-ram-ssd-price-hikes-apple-still-mostly-insulated?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243656?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[SIEM isn’t dead, its place in the SOC is just evolving]]></title>
<description><![CDATA[Predictions about the death of SIEM platforms have swirled for years, fueled by reports of alert fatigue, sky-high data costs and the shiny promises of extended detection and response (XDR), security data lakes and, now, agentic AI.…
Read more →
The post SIEM isn’t dead, its place in the SOC is j...]]></description>
<link>https://tsecurity.de/de/3338584/it-security-nachrichten/siem-isnt-dead-its-place-in-the-soc-is-just-evolving/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3338584/it-security-nachrichten/siem-isnt-dead-its-place-in-the-soc-is-just-evolving/</guid>
<pubDate>Tue, 10 Mar 2026 15:21:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;Predictions about the death of &lt;a href=”https://www.techtarget.com/searchsecurity/definition/security-information-and-event-management-SIEM”&gt;SIEM&lt;/a&gt; platforms have swirled for years, fueled by reports of alert fatigue, sky-high data costs and the shiny promises of extended detection and response (&lt;a href=”https://www.techtarget.com/searchsecurity/definition/extended-detection-and-response-XDR”&gt;XDR&lt;/a&gt;), security data lakes and, now, &lt;a href=”https://www.techtarget.com/searchsecurity/tip/What-agentic-AI-means-for-cybersecurity”&gt;agentic AI&lt;/a&gt;.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/siem-isnt-dead-its-place-in-the-soc-is-just-evolving/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/siem-isnt-dead-its-place-in-the-soc-is-just-evolving/">SIEM isn’t dead, its place in the SOC is just evolving</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11’s new Outlook still isn’t ready for prime time, as Microsoft says it won’t force web app on enterprises until 2027]]></title>
<description><![CDATA[Microsoft has confirmed that it won't force enterprises to use the new Outlook in April 2026, as the deadline has now shifted to March 2027.
The post Windows 11’s new Outlook still isn’t ready for prime time, as Microsoft says it won’t force web app on enterprises until 2027 appeared first on Win...]]></description>
<link>https://tsecurity.de/de/3328940/windows-tipps/windows-11s-new-outlook-still-isnt-ready-for-prime-time-as-microsoft-says-it-wont-force-web-app-on-enterprises-until-2027/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328940/windows-tipps/windows-11s-new-outlook-still-isnt-ready-for-prime-time-as-microsoft-says-it-wont-force-web-app-on-enterprises-until-2027/</guid>
<pubDate>Thu, 05 Mar 2026 21:51:55 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has confirmed that it won't force enterprises to use the new Outlook in April 2026, as the deadline has now shifted to March 2027.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/03/06/windows-11s-new-outlook-still-isnt-ready-for-prime-time-as-microsoft-says-it-wont-force-web-app-on-enterprises-until-2027/">Windows 11’s new Outlook still isn’t ready for prime time, as Microsoft says it won’t force web app on enterprises until 2027</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tim Cook isn't on the MacBook Neo talk-show circuit, but John Ternus is]]></title>
<description><![CDATA[Apple's new $599 MacBook Neo is aimed at bringing the Mac to more buyers — but Apple CEO Tim Cook isn't the one out talking about it yet.MacBook NeoTernus discussed Apple's strategy in an interview published March 5, one day after Apple announced the MacBook Neo on March 4. The new laptop starts ...]]></description>
<link>https://tsecurity.de/de/3328697/ios-mac-os/tim-cook-isnt-on-the-macbook-neo-talk-show-circuit-but-john-ternus-is/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328697/ios-mac-os/tim-cook-isnt-on-the-macbook-neo-talk-show-circuit-but-john-ternus-is/</guid>
<pubDate>Thu, 05 Mar 2026 19:06:44 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's new $599 MacBook Neo is aimed at bringing the Mac to more buyers — but Apple CEO <a href="https://appleinsider.com/inside/tim-cook" title="Tim Cook" data-kpt="1">Tim Cook</a> isn't the one out talking about it yet.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66926-140531-IMG_6050-xl.jpg" alt="Gold Apple laptop open on a display table, viewed from behind, with people standing in the background at what appears to be a tech event or store."><br><span>MacBook Neo</span></div><br>Ternus discussed Apple's strategy in an interview published March 5, one day after Apple <a href="https://appleinsider.com/articles/26/03/04/macbook-neo-is-apples-new-entry-level-notebook">announced the</a> MacBook Neo on March 4. The new laptop starts at $599, or $499 for education buyers, making it the lowest-priced Mac notebook Apple has ever sold.<br><br>"We saw an opportunity here to really just reach a lot more people than we ever have before," Ternus said. "MacBook Neo is solid, reliable, and durable, all the things you want a Mac to be. And yeah, that's an amazing price point."<br><br><br> <a href="https://appleinsider.com/articles/26/03/05/tim-cook-isnt-on-the-macbook-neo-talk-show-circuit-but-john-ternus-is?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243604?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero Trust in the Age of AI: Why the Classic Model Isn’t Enough Anymore]]></title>
<description><![CDATA[AI didn’t just create new attack surfaces. It fundamentally changed who—and what—is requesting access in your environment. Zero Trust needs an upgrade for a world where autonomous agents outnumber human users. The post Zero Trust in the Age of AI:…
Read more →
The post Zero Trust in the Age of AI...]]></description>
<link>https://tsecurity.de/de/3328581/it-security-nachrichten/zero-trust-in-the-age-of-ai-why-the-classic-model-isnt-enough-anymore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3328581/it-security-nachrichten/zero-trust-in-the-age-of-ai-why-the-classic-model-isnt-enough-anymore/</guid>
<pubDate>Thu, 05 Mar 2026 18:35:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI didn’t just create new attack surfaces. It fundamentally changed who—and what—is requesting access in your environment. Zero Trust needs an upgrade for a world where autonomous agents outnumber human users. The post Zero Trust in the Age of AI:…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/zero-trust-in-the-age-of-ai-why-the-classic-model-isnt-enough-anymore/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/zero-trust-in-the-age-of-ai-why-the-classic-model-isnt-enough-anymore/">Zero Trust in the Age of AI: Why the Classic Model Isn’t Enough Anymore</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows File Shredder: When deleting a file isn’t enough]]></title>
<description><![CDATA[File Shredder for Windows from Malwarebytes lets you truly, actually, really delete a file or folder from your hard drive or USB drive. This article has been indexed from Malwarebytes Read the original article: Windows File Shredder: When deleting a…
Read more →
The post Windows File Shredder: Wh...]]></description>
<link>https://tsecurity.de/de/3327600/it-security-nachrichten/windows-file-shredder-when-deleting-a-file-isnt-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327600/it-security-nachrichten/windows-file-shredder-when-deleting-a-file-isnt-enough/</guid>
<pubDate>Thu, 05 Mar 2026 12:34:48 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>File Shredder for Windows from Malwarebytes lets you truly, actually, really delete a file or folder from your hard drive or USB drive. This article has been indexed from Malwarebytes Read the original article: Windows File Shredder: When deleting a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/windows-file-shredder-when-deleting-a-file-isnt-enough/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/windows-file-shredder-when-deleting-a-file-isnt-enough/">Windows File Shredder: When deleting a file isn’t enough</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIO코리아·한국IBM, 제조·유통 IT 리더 대상 조찬 포럼 개최···“에이전틱 AI 성공은 운영·데이터 준비에 달려”]]></title>
<description><![CDATA[CIO코리아와 한국IBM은 3월 5일 서울 그랜드 인터컨티넨탈 서울 파르나스에서 ‘에이전틱 AI 리더십 익스체인지(Agentic AI Leadership Exchange)’ 조찬 포럼을 개최했다. 제조·유통 산업의 CIO, CDO, AX·DX 리더들을 대상으로 열린 이번 행사에는 30여 명의 업계 관계자가 참석해 ‘무엇을 할 수 있는가’를 넘어 ‘어떻게 실제 성과로 연결할 것인가’를 핵심 화두로 에이전틱 AI 도입과 확산 전략을 논의했다. 행사에서는 EY 컨설팅의 이창호 파트너와 한국IBM 기술 리더 4인이 연사로 나서 에이전...]]></description>
<link>https://tsecurity.de/de/3327069/it-security-nachrichten/cioibm-it-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327069/it-security-nachrichten/cioibm-it-ai/</guid>
<pubDate>Thu, 05 Mar 2026 08:35:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIO코리아와 한국IBM은 3월 5일 서울 그랜드 인터컨티넨탈 서울 파르나스에서 ‘에이전틱 AI 리더십 익스체인지(Agentic AI Leadership Exchange)’ 조찬 포럼을 개최했다. 제조·유통 산업의 CIO, CDO, AX·DX 리더들을 대상으로 열린 이번 행사에는 30여 명의 업계 관계자가 참석해 ‘무엇을 할 수 있는가’를 넘어 ‘어떻게 실제 성과로 연결할 것인가’를 핵심 화두로 에이전틱 AI 도입과 확산 전략을 논의했다. 행사에서는 EY 컨설팅의 이창호 파트너와 한국IBM 기술 리더 4인이 연사로 나서 에이전틱 AI의 글로벌 도입 사례를 비롯해 엔터프라이즈 표준 아키텍처, AI 레디 데이터 전략, 백엔드 연동 방안 등을 소개했다.</p>



<p>한국IBM 김성균 상무는 개회사에서 올해 초 고객사를 만나며 공통적으로 확인한 두 가지 핵심 어젠다로 AI 에이전틱과 SRE(사이트 신뢰성 엔지니어링) 구축을 꼽았다. 그는 “고객들이 가장 궁금해하고 많이 질문하는 핵심 주제를 중심으로 이번 행사를 구성했다”며 행사의 취지를 설명했다.</p>



<p>첫 연사로 나선 이창호 EY 파트너는 ‘주요 산업의 에이전틱 AI 도입 현황 및 전망’을 주제로, AI-레디(Ready) 기업으로 도약하기 위한 다섯 가지 핵심 전환 방향을 제시했다. 그는 ▲인간 중심 프로세스를 AI-퍼스트 워크플로우로 재설계 ▲현안 중심의 바텀업 개선이 아닌 AI 에이전트 기반 톱다운 혁신으로 전환 ▲에이전트를 단순 지원 도구가 아닌 전사 수준의 비즈니스 플랫폼으로 인식 ▲단일 조직·시스템 내 개선을 넘어 조직 간·시스템 간 업무 혁신에 집중 ▲업무 자동화 중심에서 의사결정 지원 중심으로 전환해야 한다고 강조했다.</p>



<p>이 파트너는 “이제 기업들의 관심은 에이전트 개발 방법론이 아니라 어디에서 실질적인 ROI를 확보할 수 있는가로 이동하고 있다”며 “톱다운 접근을 통해 성과 창출이 기대되는 영역을 우선 선정해 추진하는 것이 중요하다”고 말했다.</p>



<p>이 파트너는 특히 기존 RPA가 반복 작업 자동화에 머물렀다면, 에이전틱 AI 시대에는 LLM 기반의 APA(Agentic Process Automation)로 패러다임이 전환되고 있다고 설명했다. APA는 맥락 이해와 실시간 학습, 자율적 의사결정이 가능해 인간의 판단이 필요했던 업무까지 자동화할 수 있다는 것이다. 또한 조직 간 커뮤니케이션 영역에서 문서와 데이터가 비효율적으로 전달되는 지점에 에이전트를 도입하면 효과가 크다고 짚었다.</p>



<p>이창호 파트너는 마지막으로 에이전트 시대의 전략적 전환을 위한 제언도 제시했다. 그는 단일 부서나 시스템 단위의 PoC에 머물기보다 기간계 시스템과 연계된 자동화를 지향해야 하며, AI가 핵심 비즈니스를 수행하는 환경에서 기업이 어떤 모습일지를 먼저 구상한 뒤 이를 역산하는 방식으로 조직 간 의사결정 업무를 위한 AI 플랫폼 전략을 수립할 필요가 있다고 조언했다. 또한 AI 기술 조직이 아닌 프로세스 혁신 조직을 중심으로 협업 체계를 구축하고, AI가 학습하고 활용할 데이터의 의미 기반 연결을 위해 ‘AI 레디 데이터(AI Ready Data)’를 준비해야 한다고 설명했다.</p>



<p>김혜영 한국IBM 소프트웨어 테크니컬 리더는 복수의 글로벌 조사 결과를 인용하며 에이전틱 AI 도입의 현실을 짚었다. <a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" target="_blank" rel="nofollow">MIT 조사에 따르면</a> AI를 도입한 기업 가운데 실제로 성공적인 성과를 거둔 기업은 5% 미만에 불과하다. <a href="https://www.idc.com/resource-center/blog/time-to-make-the-ai-pivot-experimenting-forever-isnt-an-option/" target="_blank">IDC 조사에서는</a> 84%의 기업이 AI 유스케이스를 발굴하고 연구하고 있는 것으로 나타났지만, <a href="https://www.bcg.com/press/24october2024-ai-adoption-in-2024-74-of-companies-struggle-to-achieve-and-scale-value" target="_blank" rel="nofollow">BCG 기준으로</a> 실제 파일럿 프로젝트까지 진행한 기업은 26%에 그친다. 또한 <a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/from-promising-to-productive-real-results-from-gen-ai-in-services" target="_blank" rel="nofollow">맥킨지 보고에 따르면</a> 운영 단계로 확장해 실질적인 효과를 거둔 기업은 10% 수준에 불과하다.</p>



<p>김 리더는 이러한 격차의 원인에 대해 “많은 기업이 에이전트를 만드는 데 초점을 맞추고 있지만, 실제 백엔드 시스템 연동을 포함한 운영 준비는 충분히 갖추지 못한 경우가 많기 때문”이라고 진단했다.</p>



<p>김혜영 리더는 엔터프라이즈 에이전틱 AI의 표준 아키텍처로 에이전트 SDLC(개발 라이프사이클), 에이전트 오케스트레이션, 모델 및 도구 계층, 데이터·시스템 연동 계층, 보안·거버넌스 계층, 운영·비용 관리 계층 등 6개 기술 스택을 제시하며 “에이전트 개발뿐 아니라 뒷단 시스템과의 연동, 라이프사이클 관리, 거버넌스까지 갖춰야 비즈니스 성과로 이어진다”고 강조했다.</p>



<p>김광수 한국IBM 어카운트 테크니컬 리더는 에이전틱 ADLC(Agent Development Lifecycle)를 주제로 발표했다. 그는 에이전트 AI 도입 시 부서별로 분리된 AI 운영의 사일로화, 중앙 관리 체계의 부재, 거버넌스 미비 등 세 가지 허들을 지적하며 “에이전트를 구축했다고 해서 끝나는 게 아니라 개발·테스트·배포·운영·모니터링의 전반적 프로세스를 갖추어야 지속적 확장이 가능하다”고 말했다.</p>



<p>IBM의 ‘왓슨x 오케스트레이트(watsonx Orchestrate)’ 플랫폼을 중심으로, 노코드 기반의 5분 내 에이전트 구축, 수백 가지 커넥터를 통한 ERP·CRM 등 기존 시스템과의 빠른 연결, 멀티벤더·멀티모델 지원, 내장된 가드레일을 통한 보안·거버넌스 기능 등을 소개했다. 또한 개발자 향 커스텀 에이전트 구축 도구인 ‘밥(Bob)’ 프로젝트와 에이전트 옵저버빌리티 기능도 함께 공개했다.</p>



<p>한 글로벌 식음료·소비재 기업의 실제 도입 사례도 공유됐다. 해당 기업은 기존 MS 코파일럿 환경 안에서 왓슨x 오케스트레이트를 통해 HR·IT 등 멀티 에이전트 오케스트레이션을 구현했으며, 직원 만족도와 생산성 향상, 보안 리스크 감소, 확장 가능한 아키텍처 확보 등의 효과를 거둔 것으로 소개됐다.</p>



<p>김동영 한국IBM 어카운트 테크니컬 리더는 ‘AI 레디 데이터(AI Ready Data)’ 관점에서 발표했다. 그는 “63%의 기업이 데이터 파편화 문제를 경험하고 있고, 실제 AI 모델에 활용되는 기업 데이터는 1% 미만”이라며 데이터 통합·품질·거버넌스·비정형 데이터 관리 등 네 가지 관점의 준비가 필요하다고 설명했다.</p>



<p>특히 비정형 데이터 처리와 관련해, IBM의 왓슨X닷데이터(watsonx.data)가 PDF·워드 등 문서에서 데이터를 자동 추출하고 청킹·임베딩을 거쳐 벡터 데이터베이스에 적재하는 파이프라인을 제공한다고 소개했다. 또한 IBM이 인수한 컨플루언트(Confluent)의 카프카 기반 실시간 데이터 처리 역량과 데이터스택스(DataStax)의 NoSQL·벡터·그래프 데이터베이스 기능을 결합해 AI에 필요한 실시간 데이터 인프라를 구축할 수 있다고 설명했다. 제로 카피(Zero-Copy) 통합 기능을 통해 온프레미스와 클라우드 간 데이터를 복사 없이 활용할 수 있어 비용·속도·보안 측면에서 최적화된다는 점도 강조됐다.</p>



<p>마지막 세션에서 유근진 한국IBM 어카운트 테크니컬 리더는 AI 에이전트의 엔터프라이즈 백엔드 연결을 주제로 발표했다. 그는 제조 현장에서 “3번 라인 가동 상태가 어때?”라고 물었을 때 성형기 진동을 감지해 예방 정비를 권고하거나, 유통 매장에서 “강남점 제품 재고 상태는?”이라는 질문에 4시간 후 품절 예상과 자동 발주 제안까지 이어지는 챗봇 데모를 선보이며 “실시간 시스템 오브 레코드에서 발생한 데이터를 AI가 실시간으로 피드받아 액션하는 것이 ROI의 가장 핵심적인 부분”이라고 말했다.</p>



<p>유근진 리더는 엔터프라이즈 AI 에이전트 아키텍처에서 API 게이트웨이, AI 게이트웨이, MCP 게이트웨이라는 세 가지 단일 진입점의 중요성을 강조했다. 프롬프트 종류에 따른 적절한 LLM 모델 라우팅, 비용 관리 및 최적화, 보안·인증·인가 등을 게이트웨이 단에서 통합 관리해야 한다는 것이다. 보안 측면에서는 API 키·인증서 등을 중앙 저장소에서 관리하고 접속 시점에만 동적으로 발급·폐기하는 ‘단기 자격증명’ 방식을 제안했다.</p>



<p>그는 또한 AI 에이전트 시대에 옵저버빌리티(가시성)의 중요성을 언급하며, LLM 토큰 사용량·비용·레이턴시 모니터링부터 에이전트의 비결정적 행동 추적, MCP 게이트웨이 연동 상태 점검까지 포괄적 관찰이 필요하다고 밝혔다. 유근진 리더는 “에이전트 기능을 제공하는 소프트웨어 벤더는 많지만, 개발부터 운영, 비용 관리까지 엔터프라이즈 전반을 아우르는 기능을 제공하는 사례는 아직 많지 않다”며 “IBM은 이러한 영역을 통합적으로 지원하는 플랫폼을 제공하고 있다”고 설명했다. <br>jihyun.lee@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft isn’t launching a subscription-based Windows 12 AI OS in 2026. The rumors are just AI hallucinations.]]></title>
<description><![CDATA[A viral rumor claimed Microsoft would launch Windows 12 in 2026 with AI as the foundation and a subscription model. The story spread across Reddit and social media, but the claims are based on outdated leaks about Hudson Valley, CorePC, and a 2022 UI concept that never shipped.
The post Microsoft...]]></description>
<link>https://tsecurity.de/de/3326730/windows-tipps/microsoft-isnt-launching-a-subscription-based-windows-12-ai-os-in-2026-the-rumors-are-just-ai-hallucinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326730/windows-tipps/microsoft-isnt-launching-a-subscription-based-windows-12-ai-os-in-2026-the-rumors-are-just-ai-hallucinations/</guid>
<pubDate>Thu, 05 Mar 2026 02:52:35 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A viral rumor claimed Microsoft would launch Windows 12 in 2026 with AI as the foundation and a subscription model. The story spread across Reddit and social media, but the claims are based on outdated leaks about Hudson Valley, CorePC, and a 2022 UI concept that never shipped.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/03/05/microsoft-isnt-launching-a-subscription-based-windows-12-ai-os-in-2026-the-rumors-are-just-ai-hallucinations/">Microsoft isn’t launching a subscription-based Windows 12 AI OS in 2026. The rumors are just AI hallucinations.</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple either over- or under-invested in server hardware, depending on how you read this report]]></title>
<description><![CDATA[Years of under-investment in data centers may mean that Apple will increase its reliance on Google when the revamped Siri launches. Or it may not, it's hard to tell from the inconsistent report.The improved Siri will use Google servers to meet demandEven back in 2021, Apple was Google's largest c...]]></description>
<link>https://tsecurity.de/de/3320629/ios-mac-os/apple-either-over-or-under-invested-in-server-hardware-depending-on-how-you-read-this-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3320629/ios-mac-os/apple-either-over-or-under-invested-in-server-hardware-depending-on-how-you-read-this-report/</guid>
<pubDate>Mon, 02 Mar 2026 17:07:11 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Years of under-investment in data centers may mean that Apple will increase its reliance on Google when the revamped <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> launches. Or it may not, it's hard to tell from the inconsistent report.<br><br><div><img src="https://photos5.appleinsider.com/gallery/58993-120392-57996-118130-000-lede-Siri-2-xl-xl.jpg" alt="A future iPhone with enhanced Siri" height="738"><br><span>The improved Siri will use Google servers to meet demand</span></div><br>Even <a href="https://appleinsider.com/articles/21/06/29/apple-is-now-googles-largest-corporate-customer-for-cloud-storage">back in 2021</a>, Apple was Google's largest corporate cloud customer , as the company preferred leasing data centers rather than build up its own network of servers. That's reportedly worked well, even now when <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a> requires more servers.<br><br>According to <em>The Information</em>, what servers Apple does own are proving to be <a href="https://www.theinformation.com/articles/apple-discusses-google-hosting-new-siri-need-cloud-help-grows">vastly underused</a>. Citing unspecified former Apple employees, the report claims that on average, only 10% of Apple's Private Cloud Compute capacity is in use.<br><br><br> <a href="https://appleinsider.com/articles/26/03/02/apple-either-over--or-under-invested-in-server-hardware-depending-on-how-you-read-this-report?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243554?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Purchase order attachment isn’t a PDF. It’s phishing for your password]]></title>
<description><![CDATA[A fake purchase order attachment turned out to be a phishing page designed to harvest your login details. This article has been indexed from Malwarebytes Read the original article: Purchase order attachment isn’t a PDF. It’s phishing for your password
Read more →
The post Purchase order attachmen...]]></description>
<link>https://tsecurity.de/de/3319676/it-security-nachrichten/purchase-order-attachment-isnt-a-pdf-its-phishing-for-your-password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3319676/it-security-nachrichten/purchase-order-attachment-isnt-a-pdf-its-phishing-for-your-password/</guid>
<pubDate>Mon, 02 Mar 2026 10:35:08 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fake purchase order attachment turned out to be a phishing page designed to harvest your login details. This article has been indexed from Malwarebytes Read the original article: Purchase order attachment isn’t a PDF. It’s phishing for your password</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/purchase-order-attachment-isnt-a-pdf-its-phishing-for-your-password/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/purchase-order-attachment-isnt-a-pdf-its-phishing-for-your-password/">Purchase order attachment isn’t a PDF. It’s phishing for your password</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Gap Between Junior and Senior Data Scientists Isn’t Code]]></title>
<description><![CDATA[Why my obsession with complex algorithms was actually holding my career back.
The post The Gap Between Junior and Senior Data Scientists Isn’t Code appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3314586/ai-nachrichten/the-gap-between-junior-and-senior-data-scientists-isnt-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3314586/ai-nachrichten/the-gap-between-junior-and-senior-data-scientists-isnt-code/</guid>
<pubDate>Fri, 27 Feb 2026 13:02:44 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Why my obsession with complex algorithms was actually holding my career back.</p>
<p>The post <a href="https://towardsdatascience.com/the-gap-between-junior-and-senior-data-scientists-isnt-code/">The Gap Between Junior and Senior Data Scientists Isn’t Code</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Autonomous Endpoint Management Isn’t Just Efficiency, It’s a Security Imperative]]></title>
<description><![CDATA[Autonomous Endpoint Management cuts exposure time by matching patch speed to attacker breakout timelines, reducing risk, workload delays, and breach costs. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article:…
Read more →
The post...]]></description>
<link>https://tsecurity.de/de/3309628/it-security-nachrichten/autonomous-endpoint-management-isnt-just-efficiency-its-a-security-imperative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3309628/it-security-nachrichten/autonomous-endpoint-management-isnt-just-efficiency-its-a-security-imperative/</guid>
<pubDate>Wed, 25 Feb 2026 13:20:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Autonomous Endpoint Management cuts exposure time by matching patch speed to attacker breakout timelines, reducing risk, workload delays, and breach costs. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article:…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/autonomous-endpoint-management-isnt-just-efficiency-its-a-security-imperative/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/autonomous-endpoint-management-isnt-just-efficiency-its-a-security-imperative/">Autonomous Endpoint Management Isn’t Just Efficiency, It’s a Security Imperative</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem]]></title>
<description><![CDATA[Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or “what failed a control check.” That approach breaks the moment your environment stops being mostly-human and mostly-onboarded. In modern enterprises, identity risk is created…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3307135/it-security-nachrichten/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3307135/it-security-nachrichten/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/</guid>
<pubDate>Tue, 24 Feb 2026 13:35:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or “what failed a control check.” That approach breaks the moment your environment stops being mostly-human and mostly-onboarded. In modern enterprises, identity risk is created…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/">Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linus Torvalds: Someone 'More Competent Who Isn't Afraid of Numbers Past the Teens' Will Take Over Linux One Day]]></title>
<description><![CDATA[Linus Torvalds has pondered his professional mortality in a self-deprecating post to mark the release of the first release candidate for version 7.0 of the Linux kernel. From a report: "You all know the drill by now: two weeks have passed, and the kernel merge window is closed," he wrote in the p...]]></description>
<link>https://tsecurity.de/de/3305831/it-security-nachrichten/linus-torvalds-someone-more-competent-who-isnt-afraid-of-numbers-past-the-teens-will-take-over-linux-one-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3305831/it-security-nachrichten/linus-torvalds-someone-more-competent-who-isnt-afraid-of-numbers-past-the-teens-will-take-over-linux-one-day/</guid>
<pubDate>Mon, 23 Feb 2026 20:50:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Linus Torvalds has pondered his professional mortality in a self-deprecating post to mark the release of the first release candidate for version 7.0 of the Linux kernel. From a report: "You all know the drill by now: two weeks have passed, and the kernel merge window is closed," he wrote in the post announcing Linux 7.0 rc1. "We have a new major number purely because I'm easily confused and not good with big numbers." Torvalds pointed out that the numbers he applies to new kernel releases are essentially meaningless. 

"We haven't done releases based on features (or on "stable vs unstable") for a long, long time now. So that new major number does *not* mean that we have some big new exciting feature, or that we're somehow leaving old interfaces behind. It's the usual "solid progress" marker, nothing more.â 

He then reiterated his plan to end each series of kernels to end at x.19, before the next release becomes y.0 -- a process that takes about 3.5 years -- and then pondered what happens when the next version of Linux reaches a number he finds uncomfortable. "I don't have a solid plan for when the major number itself gets big," he admitted, "by that time, I expect that we'll have somebody more competent in charge who isn't afraid of numbers past the teens. So I'm not going to worry about it."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linus+Torvalds%3A+Someone+'More+Competent+Who+Isn't+Afraid+of+Numbers+Past+the+Teens'+Will+Take+Over+Linux+One+Day%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F02%2F23%2F1936208%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F02%2F23%2F1936208%2Flinus-torvalds-someone-more-competent-who-isnt-afraid-of-numbers-past-the-teens-will-take-over-linux-one-day%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/02/23/1936208/linus-torvalds-someone-more-competent-who-isnt-afraid-of-numbers-past-the-teens-will-take-over-linux-one-day?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[On the Security of Password Managers]]></title>
<description><![CDATA[Good article on password managers that secretly have a backdoor.
New research shows that these claims aren’t true in all cases, particularly when account recovery is in place or password managers are set to share vaults or organize users into groups. The researchers reverse-engineered or closely ...]]></description>
<link>https://tsecurity.de/de/3304880/it-security-nachrichten/on-the-security-of-password-managers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304880/it-security-nachrichten/on-the-security-of-password-managers/</guid>
<pubDate>Mon, 23 Feb 2026 13:13:31 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/">Good article</a> on password managers that secretly have a backdoor.</p>
<blockquote><p>New research shows that these claims aren’t true in all cases, particularly when account recovery is in place or password managers are set to share vaults or organize users into groups. The researchers reverse-engineered or closely analyzed Bitwarden, Dashlane, and LastPass and identified ways that someone with control over the server­—either administrative or the result of a compromise­—can, in fact, steal data and, in some cases, entire vaults. The researchers also devised other attacks that can weaken the encryption to the point that ciphertext can be converted to plaintext...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[New OS i am trying to make in the future sometime!]]></title>
<description><![CDATA[Hi there guys! I am a 15 year old kid who is addicted to making and creating all types of mad crazy tech stuff you would see in scifi movies. My question is basically what you guys think of this and do you think i can pull this off for us ? Btw im doing this just for the fact that im starting to ...]]></description>
<link>https://tsecurity.de/de/3304012/linux-tipps/new-os-i-am-trying-to-make-in-the-future-sometime/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304012/linux-tipps/new-os-i-am-trying-to-make-in-the-future-sometime/</guid>
<pubDate>Mon, 23 Feb 2026 02:49:25 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi there guys! I am a 15 year old kid who is addicted to making and creating all types of mad crazy tech stuff you would see in scifi movies. My question is basically what you guys think of this and do you think i can pull this off for us ?</p> <p>Btw im doing this just for the fact that im starting to HATE how microsoft is forcing us to use AI for stuff such as copilot or the so called "ai enhancing" stuff (im not sure if they said that just tryna point it out that these lot r addicted to ai for some odd reason) in Windows and a few other softwares they have so i decided to try and take an action for all of us. Like i said i am new to making this OS so please do help or give me suggestions on how i should fix or upgrade or just to improve the OS for all of us.</p> <p>The OS name is Vectron OS and is currently a concept before it getting released by me in github or my website (to which im planning to host in the future) and its based of this thing called bedrock linux to which im having a tough time understanding but will not give us up on making this dream os ove where my current project im making of Vectron OS V1.0 is based of (so basically a fork) and it runs windows and googlet/android in a waydroid container. (If you want to know the full thing i am going to just type it below this excruitiatiingly long paragraph.</p> <table><thead> <tr> <th align="left"><strong>Layer</strong></th> <th align="left"><strong>Technology</strong></th> <th align="left"><strong>Delivery</strong></th> <th align="left"><strong>Role</strong></th> </tr> </thead><tbody> <tr> <td align="left"><strong>1</strong></td> <td align="left"><strong>Debian + Proxmox</strong></td> <td align="left"><strong>Bare Metal</strong></td> <td align="left"><strong>The Anchor:</strong> Hypervisor &amp; ZFS Management (Cinnamon DE).</td> </tr> <tr> <td align="left"><strong>2</strong></td> <td align="left"><strong>Arch Linux</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Flex:</strong> 1:1 Gaming &amp; Bleeding-Edge NVIDIA 560+ Drivers (KDE Plasma).</td> </tr> <tr> <td align="left"><strong>3</strong></td> <td align="left"><strong>Buildroot</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Brain:</strong> Ultra-minimalist ZimaOS/CasaOS Web Dashboard.</td> </tr> <tr> <td align="left"><strong>4</strong></td> <td align="left"><strong>Alpine 1</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Engine:</strong> Management of Incus/LXC &amp; Docker Clusters.</td> </tr> <tr> <td align="left"><strong>5</strong></td> <td align="left"><strong>Alpine 2</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Striker:</strong> Wine 11.0 Runtime + NTSYNC for native-speed .exe execution.</td> </tr> <tr> <td align="left"><strong>6</strong></td> <td align="left"><strong>TrueNAS SCALE</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Vault:</strong> Bare-metal ZFS storage for a 3x10TB HDD RAID-Z pool.</td> </tr> <tr> <td align="left"><strong>7</strong></td> <td align="left"><strong>OpenWrt</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Gatekeeper:</strong> Bare-metal Routing &amp; Bufferbloat control.</td> </tr> <tr> <td align="left"><strong>8</strong></td> <td align="left"><strong>Google TV</strong></td> <td align="left"><strong>Waydroid Cont.</strong></td> <td align="left"><strong>The Screen:</strong> 4K Android TV Media Layer with hardware acceleration.</td> </tr> <tr> <td align="left"><strong>9</strong></td> <td align="left"><strong>Tiny11 26H2</strong></td> <td align="left"><strong>Hardened VM</strong></td> <td align="left"><strong>The Ghost:</strong> Undetectable &lt;3GB Windows install for Xbox/Steam (Stealth KVM).</td> </tr> <tr> <td align="left"><strong>10</strong></td> <td align="left"><strong>OPNsense</strong></td> <td align="left"><strong>Hardened VM</strong></td> <td align="left"><strong>The Shield:</strong> FreeBSD-based IDS/IPS Security Perimeter.</td> </tr> <tr> <td align="left"><strong>11</strong></td> <td align="left"><strong>Alpine 3</strong></td> <td align="left"><strong>Bedrock Stratum</strong></td> <td align="left"><strong>The Link:</strong> Universal Tailscale/VPN node unifying all strata.</td> </tr> </tbody></table> <table><thead> <tr> <th align="left">Component</th> <th align="left"><strong>Role</strong></th> <th align="left"><strong>Integration</strong></th> <th align="left"><strong>Performance</strong></th> </tr> </thead><tbody> <tr> <td align="left"><strong>Bedrock Linux</strong></td> <td align="left">Meta-Distribution Host</td> <td align="left">System Hijack</td> <td align="left">Native / Bare Metal</td> </tr> <tr> <td align="left"><strong>Debian</strong></td> <td align="left">Stable Base</td> <td align="left">Strata Integration</td> <td align="left">Native</td> </tr> <tr> <td align="left"><strong>Arch Linux</strong></td> <td align="left">Cutting-edge Packages</td> <td align="left">Strata Integration</td> <td align="left">Native</td> </tr> <tr> <td align="left"><strong>Wine 11 API</strong></td> <td align="left">Windows Compatibility</td> <td align="left">Deep Path Integration</td> <td align="left">Near-Native</td> </tr> <tr> <td align="left"><strong>Tiny11 26H1</strong></td> <td align="left">For Steam &amp; Xbox UI</td> <td align="left">Runs apps Wine cannot</td> <td align="left">Hardware Accelerated</td> </tr> <tr> <td align="left"><strong>Samba</strong></td> <td align="left">Native file sharing services</td> <td align="left">Deeply Integrated</td> <td align="left">Wire-speed I/O</td> </tr> </tbody></table> <p>This 2nd table is just for the Normal daily use version on what it will contain and reason for 2 distros of linux is one just to use arch and admire its beauty and features and to flex you have Arch installed!</p> <p>debian i have placed for stable packages and u can optionally also install proxmox packages if you wish to have a hypervisor and wine11 API to integrate with linux and make it feel like if microsoft finally answered users prayers and actually listneed and also tiny 11 to do what wine cant! And finally last but not least Samba is just to add the tiny 11 26h1 and make it feel as if it was a distro in bedrock linux! (running under ALPINE with container like specs and settings btw!)</p> <p>Btw i generated the first table on AI first even tho i hate AI cuz i cannot be asked to spend time on THAT acsi thingy but as for the 2nd one i created myself! But yeah thats my IDEA of making a centralized OS please dont sh on me for sounding dumb or anything im just tryna look out for this community and im only learning and growing with this communities teachings! :D</p> <p>Anyways basically bedrock linux allows you to install many distros of linux into ONE WHOLE BIG FAT OS to which for instance imagine i have debian right i think i have to do this thing called a HIJACK to which i can get another os onto my disk which has debian and then also make it run alongside with it this is NOT a VM nor is a CONTAINER except for the tiny 11 and waydroid google tv bit and google tv bit is just waydroid with the google tv image from this spanish group on telegram i forgort the name off they ported it off the real deal to my knowledge!</p> <p>BTW this isnt meant to be for these who find this inconvenient. You can possibly check this out if you just want to mess around with this once in the future is released this is just rather a project for my personal need of reducing vms and containers as i do also host a few servers in my Homelab i have! And also as mentioned in the comments i think this isnt rlly anything to do with anyone replacing or finding yk the root cause of this but rather the root cause just being something i want to do and find fun outside of school hours!</p> <p>Anyways simplified issue for this OS creation is</p> <ol> <li>Personal problem and reducing the amount of servers i have at home.</li> <li>I want to create a allinone soloution and make this OS for those who really want something that just works and reduceses the need of vms or containers.</li> <li>Just science</li> <li>I get bored outside of school hours</li> <li>To learn from you guys! I really like linux and as well as Operating Systems overall.</li> <li>I really like half hybrids of servers and daily use of generic operating systems like arch or windows and want to experiment with what would happen if all of these popular apps and OS's got mixed into one super hybrid PC/Server OS!</li> </ol> <p>Apology</p> <p>The only apology id have to say is me constantly repeating me saying that im new in that text i am really and truly sorry about that i am just tryna yk like kind of point out im starting this for the first time and id need LOTS and LOTS of help from you guys!</p> <p>BTW</p> <p>My release is that i do myself find 96 percent of these OS here really really useless unless you r dealing with homelab issues like me therefore i will release 2 versions of vectron</p> <p>V1</p> <p>Will just Contain Arch and debian and the wine API and also (Optionally via a .sh script that will auto install and config for you with a gui) A Tiny 11 or windows 11 that extreme debloats your OS for Gaming and productivity only and i will try and make this under maximum 6gb ram of just a fresh install of all of these at once and winboat is my first option rn for just classical users who want something that works and intergrates Windows ecosystem and Linux! So this is how it will go (from what i know as of now)</p> <p>Bedrock Linux --&gt; Arch</p> <p>--&gt; Wine API (11.0)</p> <p>--&gt; Tiny11/any lightweight Version of windows 11/latest time of release and i will try to intergrate it and make it feel like as if it was a privliged container (INCUS-LIKE speeds but its actually qemu) and i will enable samba on it so that way if feels like if it was in the $PATH of a linux nativley!</p> <p>V2</p> <p>This has to be the "Microsoft" as if adding stuff uneeded/ai lol of this entire project where i add things like google tv and truenas and zimaos and all of that which is completly useless unless you host stuff and like experimenting with something that well just works!</p> <p>BTW i did mention my age previously before i edited this and i am still sorry about that i have changed it now!</p> <p>Update: I’m officially moving everything over to <strong>V2</strong> of this project. The goal here is a much cleaner, professional setup using <strong>Debian 13</strong> as the main anchor. By using <strong>Bedrock Linux</strong>, I’m bridging a few different systems together so they act like one big OS instead of a bunch of separate installs.</p> <p>Here’s the breakdown of what V2 actually does:</p> <ul> <li><strong>Customizable Desktops:</strong> I’ve got <strong>kde</strong> for the main workspace in Arch which also has steam and for when I plus a dedicated <strong>steam optimized</strong> and preinstalled stable version of Arch Linux.</li> <li><strong>Smart Virtual Machines:</strong> A super lightweight version of <strong>Windows 11</strong> runs in the background through the command line to save memory, specifically for software that won't run natively.</li> <li><strong>Lag-Free Streaming:</strong> Integrated <strong>Parsec</strong> and <strong>Moonlight</strong> so the desktop feels instant and smooth, even when remoting in and will place a Sh script in "/home/Connect-to-desktop" to which will have a option in CLI asking to connect to which os/desktop either via parsec/moonlight/vnc to use your preffered Desktop Enviroment/OS.</li> <li><strong>Background Tools:</strong> A stripped-down <strong>Alpine Linux</strong> layer handles all the heavy networking and system tasks without eating up my hardware resources.</li> <li><strong>Total Software Freedom:</strong> I can run any command or app from <strong>Arch</strong>, <strong>Debian</strong>, or <strong>Alpine</strong> at the exact same time in one terminal.</li> <li><strong>Top-Tier Graphics:</strong> Full support for the newest <strong>NVIDIA</strong> drivers and specialized gaming tools to keep frame rates high and latency low but again as a sh script to install and auto detect any NVIDIA devices present to the OS and to install!</li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AccomplishedJudge233"> /u/AccomplishedJudge233 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1rbzyha/new_os_i_am_trying_to_make_in_the_future_sometime/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1rbzyha/new_os_i_am_trying_to_make_in_the_future_sometime/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's latest Ferret AI model is a step towards Siri seeing and controlling iPhone apps]]></title>
<description><![CDATA[Apple is still working on ways to help Siri see apps on a display, as a new paper explains how it is working on a version of Ferret that will work locally on an iPhone.A ferret in the wild - Image Credit: Pixabay/Michael SehlmeyerThe work by Apple to bring Siri up to speed with other AI systems u...]]></description>
<link>https://tsecurity.de/de/3302108/ios-mac-os/apples-latest-ferret-ai-model-is-a-step-towards-siri-seeing-and-controlling-iphone-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3302108/ios-mac-os/apples-latest-ferret-ai-model-is-a-step-towards-siri-seeing-and-controlling-iphone-apps/</guid>
<pubDate>Sat, 21 Feb 2026 20:50:51 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is still working on ways to help <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> see apps on a display, as a new paper explains how it is working on a version of Ferret that will work locally on an iPhone.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66785-140053-57833-117787-ferretpixabay-xl-xl.jpg" alt="Curious dark brown ferret with a white snout and ears peeks up from dense green grass and leaves, framed closely by foliage outdoors"><br><span>A ferret in the wild - Image Credit: Pixabay/Michael Sehlmeyer</span></div><br>The work by Apple to bring Siri up to speed with other AI systems usable on a smartphone is gradually accelerating. While immediate attempts to bring a new more contextual Siri to fruition isn't quite <a href="https://appleinsider.com/articles/26/02/11/siri-testing-isnt-going-well-new-features-probably-wont-ship-in-ios-264">ready for primetime</a>, Apple is still looking to the future for other updates it can do to its assistant and <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a>.<br><br>It seems that the path ahead is to focus on its strength: local processing of queries.<br><br><br> <a href="https://appleinsider.com/articles/26/02/21/apples-latest-ferret-ai-model-is-a-step-towards-siri-seeing-and-controlling-iphone-apps?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243453?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Opinion: Windows 11 isn’t the disaster some claim – and it’s time to say so]]></title>
<description><![CDATA[Windows 11 has faced loud criticism, especially after a turbulent 2025, but the narrative ignores historical context. Every Windows version has gone through similar update cycles, bug waves, and trust rebuilds. We examine how scale, visibility, and rapid servicing shape perception and why most sy...]]></description>
<link>https://tsecurity.de/de/3301046/windows-tipps/opinion-windows-11-isnt-the-disaster-some-claim-and-its-time-to-say-so/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3301046/windows-tipps/opinion-windows-11-isnt-the-disaster-some-claim-and-its-time-to-say-so/</guid>
<pubDate>Sat, 21 Feb 2026 00:22:22 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11 has faced loud criticism, especially after a turbulent 2025, but the narrative ignores historical context. Every Windows version has gone through similar update cycles, bug waves, and trust rebuilds. We examine how scale, visibility, and rapid servicing shape perception and why most systems continue running without major issues.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/02/21/opinion-windows-11-isnt-the-disaster-some-claim-and-its-time-to-say-so/">Opinion: Windows 11 isn’t the disaster some claim – and it’s time to say so</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Founder ditches AWS for Euro stack, finds sovereignty isn’t plug-and-play]]></title>
<description><![CDATA[Attempt to go ‘Made in EU’ offers big tech escapees a reality check where lower cloud bills come with higher effort Building a startup entirely on European infrastructure sounds like a nice sovereignty flex right up until you actually try…
Read more →
The post Founder ditches AWS for Euro stack, ...]]></description>
<link>https://tsecurity.de/de/3300294/it-security-nachrichten/founder-ditches-aws-for-euro-stack-finds-sovereignty-isnt-plug-and-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3300294/it-security-nachrichten/founder-ditches-aws-for-euro-stack-finds-sovereignty-isnt-plug-and-play/</guid>
<pubDate>Fri, 20 Feb 2026 15:35:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Attempt to go ‘Made in EU’ offers big tech escapees a reality check where lower cloud bills come with higher effort Building a startup entirely on European infrastructure sounds like a nice sovereignty flex right up until you actually try…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/founder-ditches-aws-for-euro-stack-finds-sovereignty-isnt-plug-and-play/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/founder-ditches-aws-for-euro-stack-finds-sovereignty-isnt-plug-and-play/">Founder ditches AWS for Euro stack, finds sovereignty isn’t plug-and-play</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AISPM Isn’t Enough for the Agentic Era]]></title>
<description><![CDATA[AI agents have moved from novelty to operational reality, acting autonomously across business systems in ways traditional AI security posture management (AISPM) and IAM can’t fully govern. Learn why risk now emerges at runtime, where existing posture tools fall short,…
Read more →
The post Why AI...]]></description>
<link>https://tsecurity.de/de/3299404/it-security-nachrichten/why-aispm-isnt-enough-for-the-agentic-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3299404/it-security-nachrichten/why-aispm-isnt-enough-for-the-agentic-era/</guid>
<pubDate>Fri, 20 Feb 2026 08:34:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI agents have moved from novelty to operational reality, acting autonomously across business systems in ways traditional AI security posture management (AISPM) and IAM can’t fully govern. Learn why risk now emerges at runtime, where existing posture tools fall short,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-aispm-isnt-enough-for-the-agentic-era/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-aispm-isnt-enough-for-the-agentic-era/">Why AISPM Isn’t Enough for the Agentic Era</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why CEOs’ AI Hype Really Isn’t Landing with Employees]]></title>
<description><![CDATA[Read about the disconnect between CEO enthusiasm for AI and employee perception of its value, and learn how to build communication that moves adoption forward. This article has been indexed from Blog Read the original article: Why CEOs’ AI Hype…
Read more →
The post Why CEOs’ AI Hype Really Isn’t...]]></description>
<link>https://tsecurity.de/de/3296317/it-security-nachrichten/why-ceos-ai-hype-really-isnt-landing-with-employees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3296317/it-security-nachrichten/why-ceos-ai-hype-really-isnt-landing-with-employees/</guid>
<pubDate>Wed, 18 Feb 2026 19:50:24 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Read about the disconnect between CEO enthusiasm for AI and employee perception of its value, and learn how to build communication that moves adoption forward. This article has been indexed from Blog Read the original article: Why CEOs’ AI Hype…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/why-ceos-ai-hype-really-isnt-landing-with-employees/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/why-ceos-ai-hype-really-isnt-landing-with-employees/">Why CEOs’ AI Hype Really Isn’t Landing with Employees</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI-generated password isn’t random, it just looks that way]]></title>
<description><![CDATA[Seemingly complex strings are actually highly predictable, crackable within hours Generative AI tools are surprisingly poor at suggesting strong passwords, experts say.… This article has been indexed from The Register – Security Read the original article: Your AI-generated password isn’t…
Read mo...]]></description>
<link>https://tsecurity.de/de/3295663/it-security-nachrichten/your-ai-generated-password-isnt-random-it-just-looks-that-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3295663/it-security-nachrichten/your-ai-generated-password-isnt-random-it-just-looks-that-way/</guid>
<pubDate>Wed, 18 Feb 2026 15:19:20 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Seemingly complex strings are actually highly predictable, crackable within hours Generative AI tools are surprisingly poor at suggesting strong passwords, experts say.… This article has been indexed from The Register – Security Read the original article: Your AI-generated password isn’t…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/your-ai-generated-password-isnt-random-it-just-looks-that-way/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/your-ai-generated-password-isnt-random-it-just-looks-that-way/">Your AI-generated password isn’t random, it just looks that way</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto CEO says AI isn’t great for business, yet]]></title>
<description><![CDATA[Sees little enterprise AI adoption other than coding assistants, buys Koi for what comes next If enterprises are implementing AI, they’re not showing it to Palo Alto Networks CEO Nikesh Arora, who on Tuesday said business adoption of the tech…
Read more →
The post Palo Alto CEO says AI isn’t grea...]]></description>
<link>https://tsecurity.de/de/3294518/it-security-nachrichten/palo-alto-ceo-says-ai-isnt-great-for-business-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3294518/it-security-nachrichten/palo-alto-ceo-says-ai-isnt-great-for-business-yet/</guid>
<pubDate>Wed, 18 Feb 2026 06:18:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sees little enterprise AI adoption other than coding assistants, buys Koi for what comes next If enterprises are implementing AI, they’re not showing it to Palo Alto Networks CEO Nikesh Arora, who on Tuesday said business adoption of the tech…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/palo-alto-ceo-says-ai-isnt-great-for-business-yet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/palo-alto-ceo-says-ai-isnt-great-for-business-yet/">Palo Alto CEO says AI isn’t great for business, yet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Software Isn't Dead, But Its Cosy Business Model Might Be']]></title>
<description><![CDATA[The software industry's decades-old habit of charging companies a flat fee for every employee who uses a product is running into a fundamental problem: AI agents don't sit in chairs, and they don't need licences. 

As autonomous agents take on tasks that human workers once handled, the per-seat p...]]></description>
<link>https://tsecurity.de/de/3293419/it-security-nachrichten/software-isnt-dead-but-its-cosy-business-model-might-be/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3293419/it-security-nachrichten/software-isnt-dead-but-its-cosy-business-model-might-be/</guid>
<pubDate>Tue, 17 Feb 2026 16:05:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The software industry's decades-old habit of charging companies a flat fee for every employee who uses a product is running into a fundamental problem: AI agents don't sit in chairs, and they don't need licences. 

As autonomous agents take on tasks that human workers once handled, the per-seat pricing model that made SaaS revenue so predictable is giving way to consumption-based and hybrid alternatives. Snowflake and Databricks (valued at $134 billion) already charge based on usage. Salesforce initially priced its Agentforce customer relations bot at $2 per conversation but faced customer pushback and now offers action-based pricing, upfront credits and fixed fees. 

ServiceNow's finance chief Amit Zavery said last month that some customers aren't ready for purely consumption-based models. Goldman Sachs estimates US software spending will nearly triple to $2.8 trillion by 2037 as automated tasks blur the boundary between IT and wage budgets, but that money will no longer arrive in the neat recurring instalments that investors and private equity firms have come to expect.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Software+Isn't+Dead%2C+But+Its+Cosy+Business+Model+Might+Be'%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F02%2F17%2F1445232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F02%2F17%2F1445232%2Fsoftware-isnt-dead-but-its-cosy-business-model-might-be%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/02/17/1445232/software-isnt-dead-but-its-cosy-business-model-might-be?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's Playgrounds approach to AI is a sign of its larger strategy]]></title>
<description><![CDATA[The 2026 revamp of Apple Intelligence and Siri is imminent, and Playlist Playground in iOS 26.4 shows Apple will continue to treat AI as a background tool, not a flagship feature.Apple Intelligence is meant to be a background featureIf you've been paying attention, Apple's strategy with artificia...]]></description>
<link>https://tsecurity.de/de/3293384/ios-mac-os/apples-playgrounds-approach-to-ai-is-a-sign-of-its-larger-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3293384/ios-mac-os/apples-playgrounds-approach-to-ai-is-a-sign-of-its-larger-strategy/</guid>
<pubDate>Tue, 17 Feb 2026 15:51:51 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The 2026 revamp of <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a> and Siri is imminent, and Playlist Playground in iOS 26.4 shows Apple will continue to treat AI as a background tool, not a flagship feature.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66734-139937-Image-Playground-Apple-Intelligence-Tim-Cook-xl.jpg" alt="The Image Playground interface showing Tim Cook generated as an animated avatar"><br><span>Apple Intelligence is meant to be a background feature</span></div><br>If you've been paying attention, Apple's strategy with artificial intelligence has always been about <a href="https://appleinsider.com/articles/25/06/10/apple-execs-explain-apples-position-in-the-ai-race-how-it-isnt-necessarily-behind">keeping it in the background</a>. It augments human users rather than replacing them or stealing from them.<br><br>System-wide access to controls via app intents and the more personalized <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> won't or will be groundbreaking, depending on any given user's workflow. Apple isn't treating AI as some kind of world-altering paradigm that needs to overtake every part of the product.<br><br><br> <a href="https://appleinsider.com/articles/26/02/17/apples-playgrounds-approach-to-ai-is-a-sign-of-its-larger-strategy?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243410?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stick with Apple, an increasingly bullish Wedbush tells investors]]></title>
<description><![CDATA[Investment firm Wedbush is telling its clients to ignore recent reports of delays to Siri, saying that 2026 is when Apple Intelligence will be a boon.The new Siri is comingWedbush took its Apple target price up to $350 in December 2025, based on high expectations for Apple Intelligence. Keeping t...]]></description>
<link>https://tsecurity.de/de/3293086/ios-mac-os/stick-with-apple-an-increasingly-bullish-wedbush-tells-investors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3293086/ios-mac-os/stick-with-apple-an-increasingly-bullish-wedbush-tells-investors/</guid>
<pubDate>Tue, 17 Feb 2026 13:51:40 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Investment firm Wedbush is telling its clients to ignore recent reports of delays to Siri, saying that 2026 is when <a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a> will be a boon.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66738-139953-000-lead-Siri-xl.jpg" alt="Close-up of a hand holding a smartphone showing a colorful Siri input bar on the home screen with app widgets, search field, and digital clock icons visible."><br><span>The new Siri is coming</span></div><br>Wedbush took its Apple target price up to $350 in <a href="https://appleinsider.com/articles/25/12/08/wedbush-raises-its-apple-price-target-to-350-over-ai-expectations-and-staff-changes">December 2025</a>, based on high expectations for Apple Intelligence. Keeping that figure, it then repeated this expectation in <a href="https://appleinsider.com/articles/26/01/12/wedbush-expects-monumental-2026-for-apple-despite-invisible-ai-strategy">January 2026</a> — and is now back to do so again, specifically because of recent rumors.<br><br>Those rumors claimed that testing of the new <a href="https://appleinsider.com/inside/siri" title="Siri" data-kpt="1">Siri</a> is going poorly, and its improved features <a href="https://appleinsider.com/articles/26/02/11/siri-testing-isnt-going-well-new-features-probably-wont-ship-in-ios-264">will be delayed</a>, perhaps until <a href="https://appleinsider.com/inside/ios-27" title="iOS 27" data-kpt="1">iOS 27</a> in September. Consequently, investors have been selling off their Apple shares, but Wedbush says this is unwarranted.<br><br><br> <a href="https://appleinsider.com/articles/26/02/17/stick-with-apple-an-increasingly-bullish-wedbush-tells-investors?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243409?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple isn't compromising build quality with new, colorful, inexpensive MacBook]]></title>
<description><![CDATA[Apple's budget MacBook is reportedly not plastic, and is rumored to get vibrant colors echoing the the 24-inch iMac for its aluminum enclosure.Apple's MacBook could be greenThe MacBook Air and MacBook Pro lines are relatively limited when it comes to appearance, with the Air sold in four muted sh...]]></description>
<link>https://tsecurity.de/de/3289477/ios-mac-os/apple-isnt-compromising-build-quality-with-new-colorful-inexpensive-macbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3289477/ios-mac-os/apple-isnt-compromising-build-quality-with-new-colorful-inexpensive-macbook/</guid>
<pubDate>Sun, 15 Feb 2026 14:50:57 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's budget MacBook is reportedly not plastic, and is rumored to get vibrant colors echoing the the 24-inch iMac for its aluminum enclosure.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66712-139892-greenapplemacbook-xl.jpg" alt="Close-up of a teal-colored Apple laptop lid, showing the dark Apple logo on a smooth metallic surface with soft lighting and gentle shadow along the edge"><br><span>Apple's MacBook could be green</span></div><br>The <a href="https://appleinsider.com/inside/macbook-air" title="MacBook Air" data-kpt="1">MacBook Air</a> and <a href="https://appleinsider.com/inside/macbook-pro" title="MacBook Pro" data-kpt="1">MacBook Pro</a> lines are relatively limited when it comes to appearance, with the Air sold in four muted shades and the Pro in just two. When it comes to the <a href="https://appleinsider.com/articles/25/07/11/apples-upcoming-low-cost-macbook-colorful-and-affordable">much-rumored</a> MacBook with an <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> chip, it could expand the external color palette a lot more.<br><br>Writing in Sunday's "Power On" <a href="https://www.bloomberg.com/news/newsletters/2026-02-15/tesla-carplay-delays-related-to-ios-26-and-fsd-apple-s-new-siri-delays-ios-27?srnd=undefined" rel="nofollow">newsletter</a> for <em>Bloomberg</em>, Mark Gurman claims that Apple will be going with playful colors. While it will be aimed at enterprise users as well, this seems to be a play to maximize sales with students.<br><br><br> <strong>Rumor Score:</strong> 🤔 Possible <br><br><br> <a href="https://appleinsider.com/articles/26/02/15/apple-isnt-compromising-build-quality-with-new-colorful-inexpensive-macbook?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243382?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 26 adoption rate isn't the crisis some analysts are portraying]]></title>
<description><![CDATA[Apple's February 2026 App Store data shows iOS 26 adoption closely tracking the pace set by iOS 18 in January 2025, and iPadOS 26 is ahead of iPadOS 18, undercutting claims that the upgrade cycle is faltering.Apple publishes OS 26 adoption dataApple publishes operating system adoption rates based...]]></description>
<link>https://tsecurity.de/de/3287321/ios-mac-os/ios-26-adoption-rate-isnt-the-crisis-some-analysts-are-portraying/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3287321/ios-mac-os/ios-26-adoption-rate-isnt-the-crisis-some-analysts-are-portraying/</guid>
<pubDate>Fri, 13 Feb 2026 22:50:38 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's February 2026 <a href="https://appleinsider.com/inside/app-store" title="App Store" data-kpt="1">App Store</a> data shows iOS 26 adoption closely tracking the pace set by iOS 18 in January 2025, and iPadOS 26 is ahead of iPadOS 18, undercutting claims that the upgrade cycle is faltering.<br><br><div><img src="https://photos5.appleinsider.com/gallery/66710-139876-IMG_4277-xl.jpg" alt="Tablet on a keyboard case sitting on an outdoor table, screen displaying colorful icons, with empty patio chairs, metal fence, and buildings in the background under a partly cloudy sky"><br><span>Apple publishes OS 26 adoption data</span></div><br>Apple publishes operating system adoption rates based on devices that transacted on the App Store. The February 12, 2026 data can be measured against Apple's January 24, 2025 <a href="https://appleinsider.com/articles/25/01/24/ios-18-adoption-steady-as-users-explore-ai-customization">published figures</a> for a like-for-like comparison.<br><br>The breakdown separates recently introduced hardware from the full active installed base. Because Apple publishes these numbers annually, it allows for a category-matched comparison between the 2025 and 2026 cycles at the same stage.<br><br><br> <a href="https://appleinsider.com/articles/26/02/13/ios-26-adoption-rate-isnt-the-crisis-some-analysts-are-portraying?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243380?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,11ms -->